Europe is downshifting on digital regulation

The EU is loosening its data and AI rules: flexibility for innovation, or a retreat under competitive pressure?

26.07.2026

Europe is downshifting on digital regulation

The GDPR and AI Act changes that have come onto the agenda recently are, in my view, a turning point in the history of Europe’s technology policy. The EU, which for years took the toughest stance against big tech, moving to an approach that eases data sharing, opens room for personal-data use in AI model training and lightens obligations, is not just a regulatory change but a change of mindset.

The timing of this shift is telling too. Loosening the rules in a period when AI is spreading so fast into daily life and business processes is both bold and risky. Bold, because it opens the way for innovation; risky, because it also loosens oversight of a still-immature technology. How Europe strikes this balance will set an example not only for itself but for the countries watching it.

Two big truths

In my view there are two basic reasons behind this move. First, Europe could no longer resist the pressure of economic growth; start-ups and technology companies had long said they couldn’t breathe under excessive regulation, and the Commission has finally begun to hear that voice. Second, falling behind in the AI race is now a concrete risk for the EU; unable to keep up with the pace of global players, Europe faces the necessity of opening room for innovation.

The main changes are as follows:

  • Sharing of anonymized data under GDPR is made easier.
  • AI companies are given more flexibility for model training with personal data.
  • Cookie notices are simplified.
  • The AI Act’s high-risk provisions are postponed; the burden on small and medium-sized companies is lightened.
  • An AI Office comes into play for central oversight.

Some of these steps genuinely support innovation; I’m convinced of that. But on the other hand, the limits of the digital-rights ecosystem Europe has long been proud of are being redrawn too. The question is: is the EU this time offering flexibility for innovation, or pulling back its defensive line under competitive pressure? We’ll see the answer clearly in the next few years.

This move should be read in a wider frame. AI is no longer only a technology but an economic power and a geopolitical arena of competition. Europe boasted for years of being a regulatory superpower; but this time it feels the pressure not of setting the rule, but of staying in the race. This turn toward flexibility is actually a clear example of how global competition shapes regulatory choices.

What it means for insurance

For the insurance industry the impact of these changes is far more critical. Easier data sharing can create great momentum for risk analytics, pricing models and fraud detection. Wider room for personal data in AI models can open the way for more advanced predictive systems, especially in health and motor insurance. And postponing the high-risk AI rules gives insurers the chance to roll out agentic AI, automated claims management and underwriting systems faster.

But there’s the other side of the coin. As all this happens, the balance between privacy and innovation in insurance becomes more sensitive than ever. Greater legal flexibility is a test that raises ethical responsibility as much as it is an opportunity for the industry. Because as access to data gets easier, the responsibility to use that data fairly and explainably grows heavier.

The reason this balance is especially sensitive in insurance is the nature of the data used. Health history, driving behavior, lifestyle; these are the most intimate data. As access to them gets easier, more precise pricing and better prediction become possible; but the same ease also enlarges the risk of discrimination and privacy violation. So loosening regulation, while opening room for the insurer, transfers the responsibility to the institution.

At this point the responsible-AI debate comes back into play. As the legal burden lightens, explainability and fairness shift from a requirement to a choice; and that choice will set the real difference. Because doing everything the rules allow and doing what’s right are not always the same. What will protect trust in the long run is not regulation’s lower bound, but the upper line the institution draws for itself.

This tension isn’t actually new; it was always at the heart of insurance. More data always means more precise pricing; but past a certain point, precision begins to erode solidarity and privacy. Loosening regulation leaves this line to institutions’ own conscience and strategy. So the real question becomes not what we can do but what we should do.

A note for Turkey

In short, the new EU approach can open the door to radical innovation in insurance technology; but used wrongly, it can also damage trust. For Turkey this process is worth watching closely: both as a reference point for the future of data-protection law (KVKK) and as a preview of how we’ll strike the balance between data and innovation. The lesson Europe draws from this test is a herald of the questions we, too, will need to debate.

Gencay Genç
Insurance broker and InsurTech founder · LinkedIn