Large technology companies, including Meta and Google, are building AI while working under European privacy law. The question is whether the European Union can keep strong data protection and still compete in AI.
GDPR
The General Data Protection Regulation is a base of global privacy rules since 2016. The law puts individual privacy first and requires consent before personal data is used, including to train AI. Protections are strong. That also makes powerful AI systems harder to build.
One example is Google’s Pathways Language Model 2, or PaLM 2. The Irish Data Protection Commission was investigating the model for possible GDPR violations. Meta paused AI training in Europe to avoid a conflict with the rules.
Without a wide set of European data, models trained elsewhere may miss European languages, culture, and ethical expectations. Companies in places with looser privacy rules can train on richer data and pull ahead. That gap is a risk to Europe’s economy and to its place in AI.
What the companies asked for
GDPR is one standard, but enforcement differs by member state, so companies face conflicting readings, slower work, and higher compliance cost. Meta, Google, and other technology leaders sent European regulators an open letter asking for harmonized rules: one clearer framework so they could build AI and still comply, and so models could be trained on European data and reflect European cultures.
The ethical question is still open: change AI development to fit privacy law, or change the rules to fit the technology. Both sides want a balance and have not found one.
Privacy and innovation
GDPR protects people in a data-heavy economy. Rules that are too tight could slow AI and leave Europe behind. A single framework could allow responsible development and still protect data, so technology built in Europe matches its standards and can still compete.
Clearer, shared rules could let privacy and AI progress sit together.
Back to the blog