Cybersecurity

EU Parliament Blocks Built-in AI on Lawmakers' Devices

The European Parliament's IT department disabled built-in AI features on lawmakers' work devices, citing data security, training-data leakage, and US legal compulsion risks.

EU Parliament Blocks Built-in AI on Lawmakers' Devices — article cover

In mid-February 2026, a leaked internal email revealed that the European Parliament’s IT department has disabled the baked-in AI features on the government-issued work devices of lawmakers and their staff. Politico obtained the email; TechCrunch followed up. The stated reason is not a specific incident but a structural judgment: the parliament cannot guarantee the security of data uploaded to AI companies’ servers, the extent of what gets shared is “still being assessed,” and “it is considered safer to keep such features disabled.”

The affected product category covers mainstream cloud chatbots — Anthropic’s Claude, Microsoft’s Copilot, and OpenAI’s ChatGPT are all cited as examples. The irony is hard to miss: the legislature that regulates AI most aggressively anywhere just blocked AI from its own work devices. This is not a PR posture. It is a technical veto by an IT department over data flows and legal jurisdiction.

What Happened

Per Politico’s reporting and TechCrunch’s write-up, the outline is simple:

  • The parliament’s IT department disabled built-in AI features on issued work devices
  • The decision was communicated in an internal email, obtained by Politico
  • The official rationale: no guarantee of security for data uploaded to AI companies’ servers, with the scope of sharing “still being assessed”
  • The email’s conclusion: “It is considered safer to keep such features disabled”

Note the precision of the scope. This is not a blanket ban on AI services — it targets AI features that ship enabled and deeply integrated on the device. The threat model is about defaults: confidential correspondence ending up in the cloud without explicit, informed consent.

Why Block: Data Leaving the Building and US Jurisdiction

TechCrunch names two layers of structural risk. The first is training-data leakage: AI chatbots typically use user inputs to improve their models, which means one person’s sensitive data can resurface to other users through model outputs. The second is harder law: uploading confidential correspondence to an American company’s cloud chatbot means US authorities have legal instruments to compel those companies to hand over user information.

The second layer deserves unpacking. GDPR’s cross-border transfer framework is about levels of privacy protection; this is about foreign subpoena power. For a legislature, an exposed trail of member correspondence, lobbying records, and draft legislation within reach of US legal process is a risk no fine can price. Vendor-side product defenses do not answer it — OpenAI just shipped Lockdown Mode and Elevated Risk labels for ChatGPT, which target prompt injection and account compromise. But a subpoena is not an injection attack; no model hardening stops a court order.

The Broader Context: Europe’s Cracking Trust in US Tech

The decision does not stand alone. TechCrunch sets it against three threads. First, the 27-member bloc has the world’s strongest data protection rules, yet the European Commission floated proposals last year to relax them for AI training — criticized as caving to US tech giants. Second, several EU countries are rethinking their reliance on US tech firms, given their exposure to US law and the unpredictability of the current administration’s demands. Third, the US Department of Homeland Security recently sent hundreds of subpoenas seeking data on critics of government policy; Google, Meta, and Reddit complied in several cases, even though those subpoenas were not judge-issued or court-enforced.

Add the threads together and the parliament’s choice writes itself: once “will American companies hand over data” shifts from hypothetical to case-documented, the conservative move is to cut the data path at the source.

What It Means for Enterprises and Developers

Three direct conclusions. First, defaults are policy. The parliament is not blocking AI; it is blocking product design that ships confidential data to the cloud by default. If you sell into regulated industries, data flow must be an explicit choice, never an opt-out. Second, jurisdiction is a procurement spec. EU data on US suppliers equals US legal reach — expect that sentence to appear verbatim in enterprise procurement checklists from 2026 onward, and expect sovereign-AI vendors and on-premise deployments to keep converting headlines like this one into pipeline. Third, keep your security narrative matched to the threat model. Injection defenses, risk labels, and lockdown modes are worth building — they answer the “attacker” question. What the parliament signaled this week is a trust question about the vendor itself, and confusing the two in a sales deck will get caught by exactly the buyers who now care.

Sources

AI-assisted summary compiled from the sources above, reviewed by a human before publishing.

SHAREXEMAIL