Today, the Commission’s digital ombibus proposes to weaken GDPR protections and delay safeguards for high-risk AI systems. What does this actually mean?
The financial services sector is a rapid adopter of AI, and the implications are stark:
Changes to GDPR would allow inferred traits or derived information, including predicted health status, religion, sexual orientation, or political opinions, to be freely processed and used to train AI models under ‘legitimate interest’. These models, informed by inferred data, could then be used in financial services to make decisions.
A person could be denied a loan because of a biased AI model, or charged higher insurance premiums based on predicted health status, all without their knowledge or consent. The Omnibus proposal would enable previously restricted, sensitive data to determine high‑stakes financial outcomes.
Peter Norwood, Senior Research and Advocacy Officer
At the same time, the proposed ‘grace period for high-risk systems’, those used, for example, to determine credit scoring and insurance pricing, extends the window of harm to consumers.
In a report earlier this year, Finance Watch highlighted the exclusion risks of essential financial services by the use of AI in financial services, and these proposals would amplify that risk. The risks aren’t theoretical, they are happening now.
In a rapidly evolving AI environment, the European Commission must learn from the lessons of Omnibus I. A rushed-through, poorly consulted simplification package produces false outcomes and legal challenges. The EU can’t afford to dismantle years of delicate compromise for the sake of ‘simplification’.
Contact
For press enquiries or to receive our press releases via email, please contact:
Share
Get involved
You can help tip the balance! Strengthen our impact by joining our collective efforts.