AI Governance & Data Protection  ·  18 September 2026

The Wall Nobody Was Watching

Article 88c got the redline everyone screenshotted. Article 9 got a pass.
By Alan Wright  ·  The Haunted Lighthouse Limited  ·  Peel, Isle of Man

This week LinkedIn discovered the Irish Presidency's compromise text on the EU's Digital Omnibus. H/t Johnny Ryan (ICCL), whose original post put the redline in front of enough people to trigger the reaction that followed, and the data protection crowd is, by its own admission, angrier than it has been in years. Ryan called the redline "insanity." Daragh O'Brien called it "diluting regulation and oversight to homeopathic levels." Nicholas Shaxson framed it as institutional capture, "shame, and the shamelessness, of Ireland and its captured, Trojan-Horse elites." The provision drawing the fire is the new Article 88c: a legitimate interest basis, under Article 6(1)(f) GDPR, for developing and operating AI systems and models on personal data, with the compromise text stripping out the balancing-test override that would otherwise let an individual's fundamental rights outweigh a controller's interest.

The anger is not misplaced. But it is aimed at the provision that has, if anything, had the most scrutiny applied to it. Successive Council compromise drafts have already cut 88c back once, at one point demoting it out of the operative text entirely into a non-binding recital, before the version in this week's redline restored it to a numbered article.

Sitting one article away, untouched by that same scrutiny, is the provision that should worry you more.

The wall Article 9 built

Article 9 GDPR is the strictest tier of the regulation: health data, ethnicity, sexual orientation, religious belief, trade union membership, genetic data. It exists because Europe has direct, living memory of what happens when institutions compile lists of who belongs to which category. Processing it has always required explicit consent or a narrow, named statutory exception. Nothing about "commercial convenience."

The Digital Omnibus proposes a new Article 9(2)(k), paired with Article 9(5), letting "residual" special category data sit inside AI training datasets where a controller could not reasonably have avoided collecting it, provided they try to avoid it, remove it if found, and otherwise ring-fence it from influencing outputs or reaching third parties.

As a piece in the European Law Blog lays out in detail, that framing does not survive contact with how it is actually drafted. Three problems, in order of how badly each one undercuts the "narrow, technical fix" pitch:

It borrows a definition built for the opposite purpose. Article 9(2)(k) does not define who qualifies for the exemption itself; it outsources that to the AI Act's Article 3(1) definition of an "AI system," a definition deliberately written broad so more systems fall under safety obligations. Recycled as an exemption gateway, the same breadth becomes a loophole. The authors' comparator is the cleanest illustration going: two companies process identical scraped text containing the same incidental health and religious-belief data, one using hand-coded classification rules, the other training a model on the same corpus. Only the second qualifies for the Article 9 carve-out. Same data, same individuals, same risk. The only thing that changed is the engineering method.

It covers more than its own justification admits. The exemption text covers "development and operation," but the Commission's own Recital 33 only makes the case for the development-stage problem, residual data turning up in training and testing sets. "Operation" is undefined and, on ordinary reading, covers live deployment, including special category data a user types into a prompt after release. The EDPB and EDPS flagged exactly this gap in their Joint Opinion 2/2026 and recommended excluding deployment-phase data explicitly.

The boundary it draws cannot be policed from outside the controller's own walls. The Omnibus creates two routes for special category data in AI: 9(2)(k) for accidental presence, and the AI Act's Article 4a for deliberate use in bias detection, which carries genuinely stronger conditions, strict necessity, retention limits, access restriction. But nothing requires a controller to record, at the point of collection, whether data arrived accidentally or was gathered on purpose. GPAI transparency duties under the AI Act cover broad source categories, not that level of detail, and don't apply to AI systems generally at all. So a controller questioned about a dataset can retroactively characterise the processing as "incidental" under the lenient route, sidestepping the stricter one, and nothing in either provision lets anyone disprove the account after the fact. Article 9(5)'s own safety net, "appropriate measures" to avoid collection, "disproportionate effort" before deletion becomes optional, is undefined with no independent verification required. The party best placed to judge its own effort as disproportionate is the only party making that judgment.

Put plainly: the Council has shown it is willing to scrutinise and cut back the article getting the public fight. It has not applied the same scrutiny to the article governing the most sensitive data in the regulation. That asymmetry is not incidental to the Theatre Pulldown framework this publication keeps returning to. It is the framework working exactly as described: the provision that gets the visible fight is not automatically the one that matters most, and an institution's willingness to be seen negotiating on one front tells you very little about what is happening, unexamined, on the next one over.

The exit closing at the same time

There is a second provision worth reading alongside Article 9, not because it touches AI training directly, but because it closes off the mechanism people actually use to check whether any of this is happening as claimed.

Article 12(5) GDPR currently lets controllers refuse "manifestly unfounded or excessive" access requests. The Digital Omnibus would let them additionally refuse requests made "for purposes other than the protection of personal data." The stated aim is curbing abusive requests. The EDPB and EDPS have objected that this misreads what the access right is for.

The concrete cases are the ones that matter. Gig economy workers and their representatives have used Article 15 access requests to obtain the data behind algorithmic management decisions, building unfair-dismissal cases against companies including Uber and Ola Cabs. Courts have explicitly rejected the argument that this is an "abuse" of the access right, even though the underlying motive is plainly labour litigation rather than data protection in the narrow sense. A reform that limits access requests to "data protection purposes only" would, on its face, close off exactly that use.

Read next to Article 9, the pattern sharpens. One provision loosens what institutions and AI developers can do with the most sensitive data in Europe. The other narrows the one legal lever ordinary people have used to find out what was actually done with their data once the automated system has already decided about them. Neither change requires new lobbying spend, a new scandal, or a new headline. They only require nobody outside the GDPR-literate minority reading the recital text closely enough to notice both are moving in the same direction at once.

Where this actually stands

Worth being precise about timing, since it cuts against any urgency framing and also removes any excuse for looking away. Article 4a of the AI Act, the bias-detection carve-out that carries the stronger safeguards, is done: Parliament and Council have both signed off, it is awaiting Official Journal publication. Articles 9(2)(k) and 9(5), the weaker provisions with real teeth, are much earlier in the process. Council is still working through Presidency compromise texts, Parliament has not adopted a position, trilogue negotiations with Parliament have not begun. Adoption is not expected before 2027.

The text is not close to final. Nothing procedural stands in the way of narrowing it before it becomes law. The opportunity the European Law Blog authors describe, a genuinely narrow exemption that solves the real, admitted technical problem without the practical conveniences this piece has walked through, has not yet passed.

It will, eventually, if the only scrutiny this file receives keeps landing on the article that already has plenty.


Sources


Editor's note: this piece extends the analytical framework set out in "The Theatre Pulldown", examining the gap between institutional governance claims and operational reality. H/t Johnny Ryan (ICCL) for surfacing the original redline on LinkedIn.

Questions about this analysis, or interested in working with The Haunted Lighthouse?
consultancy@haunted.lighthouse.co.im

The Sovereign Auditor covers digital sovereignty, cybersecurity governance, and data protection policy, with particular focus on Isle of Man jurisdiction and Crown Dependency issues.

Support independent analysis. Subscribe directly, or scan on your phone.

Payments via PayPal. Credentials delivered by email. No Substack. No Stripe. No middlemen.