The Great Shift: AI, the Web and Our Personal Data
Generative AI turns the web into both training material and a distribution channel. The GDPR does not prohibit AI or web scraping, but it requires a purpose, a lawful basis, proportionate collection, effective rights and accountable design.
A Silent Acceleration
Generative tools have made text, image, voice and video production nearly instantaneous. No robust method can establish one precise worldwide percentage of AI-generated web content, especially when human and machine contributions are intertwined.
The relevant question is therefore not only how much content is synthetic, but which personal data was used, who is responsible and how individuals can exercise control.
When the Web Becomes Training Material
Publicly accessible information may still be personal data. Web scraping is not prohibited as such, but purpose, lawful basis, necessity, reasonable expectations, sensitive data and safeguards must be assessed.
A robots.txt file is a relevant technical signal, not a universal GDPR objection mechanism. Its absence is not consent. Effective governance combines exclusions, filtering, provenance records, information and accessible rights channels.
The Difficult Right to Be Forgotten
Deleting the source may not remove copies, indexes or learned effects. Yet it is equally inaccurate to claim that every item is irreversibly dissolved into model weights. Memorisation, extraction and identifiability require a case-specific assessment.
Article 17 does not disappear after training. Depending on the circumstances, an effective response may concern source datasets, retrieval indexes, outputs, filters, unlearning or retraining. Privacy by design should anticipate these requests.
Collective Risks Without an Apocalypse Narrative
Research shows that indiscriminate recursive training on model-generated data can erode diversity and rare cases. This is a conditional scientific risk, not proof that every model must collapse.
Automation can also dilute responsibility and homogenise expression. Data quality, fairness, transparency, profiling risks and the ability to identify the source become central governance concerns.
GDPR and the AI Act
The AI Act and the GDPR are complementary. An AI label does not legalise unlawful data collection, and a GDPR lawful basis does not satisfy every AI Act obligation.
Content Credentials can provide verifiable provenance, but do not certify that a statement is true or exclusively human. Trust requires provenance, accountable actors, effective rights and careful design.
- Define purposes and responsibilities before collection;
- Document lawful basis, necessity, exclusions and retention;
- Assess memorisation, extraction and high-risk impacts;
- Provide information and workable access, objection and erasure channels.
Verified Official Sources
General Data Protection Regulation — EU Reference Legal Framework
Consult official source →Traitement de données personnelles dans le cadre du développement de modèles d'IA, évaluation du risque de mémorisation/extraction, anonymisation des pondérations, intérêt légitime et mesures d'atténuation (Avis Art. 64 du CEPD)
Consult official source →Web scraping pour l'entraînement de modèles d'IA générative, licéité (Art. 6), catégories particulières (Art. 9), transparence (Art. 14) et minimisation (version 1.0 adoptée le 7 juillet 2026, consultation publique ouverte jusqu'au 30 oct. 2026)
Consult official source →Cadre harmonisé de l'intelligence artificielle, notamment transparence de certains systèmes et contenus générés ou manipulés par IA (Article 50)
Consult official source →Finalité, qualification, base légale, réutilisation, web scraping, minimisation, information, droits, AIPD et protection des données dès la conception
Consult official source →Risque de dégradation lors d'un entraînement récursif indiscriminé sur des données produites par les générations précédentes de modèles
Consult official source →Standard technique de provenance vérifiable des contenus numériques ; ne constitue pas à lui seul une certification de vérité
Consult official source →See Also in the Legal Framework
Article 17 GDPR : The Right to Erasure and Lawful Exceptions
Conditions for applying Article 17 GDPR: 6 legitimate grounds for erasure, 5 statutory exceptions (freedom of expression...
Article 25 GDPR : Data Protection by Design and by Default Principles
Practical implementation of Article 25 GDPR and EDPB Guidelines 4/2019: integrating data protection principles upstream ...
EDPB Guidelines 03/2026: Web Scraping for Generative AI
Legal analysis of EDPB Guidelines 03/2026 (Draft Version 1.0 open for consultation until 30 Oct 2026): lawful grounds fo...