Policy & Regulation
European Parliament restricts AI use on work devices
The European Parliament has reportedly blocked lawmakers from using AI tools on work devices, citing security risks regarding potential data exposure to U.S. authorities.
The European Parliament has reportedly blocked lawmakers from using baked-in AI tools on their work devices. According to an internal email obtained by the news outlet Politico, the parliament’s IT department stated that it could not guarantee the security of data uploaded to the servers of AI companies. The IT department noted that the full extent of what information is shared with AI companies is still being assessed. Consequently, the email, which was seen by Politico, advised that “It is considered safer to keep such features disabled.” The restriction prevents lawmakers from utilizing integrated AI features on their official equipment due to these security risks, reflecting a cautious approach to data handling within the legislative body.
The decision highlights ongoing data privacy concerns within the 27-member state bloc. Uploading data to AI chatbots—such as those provided by Anthropic, Microsoft, and OpenAI—means U.S. authorities can demand that the companies running those chatbots turn over information about their users. This risk exists even as the European Commission, the executive body that oversees the 27-member state bloc, last year floated new legislative proposals aimed at relaxing its data protection rules. Those proposals were intended to make it easier for technology companies to train their AI models on European data, but the parliament’s recent move indicates caution regarding how U.S. authorities might access European data.
This caution is underscored by recent actions from the U.S. Department of Homeland Security. In recent weeks, the agency has sent hundreds of subpoenas—which are legal demands for information—demanding U.S. tech and social media giants turn over information about people, including Americans, who have been publicly critical of the Trump administration’s policies. Tech companies including Google, Meta, and Reddit complied in several cases, even though the subpoenas had not been issued by a judge and were not enforced by a court. The willingness of these companies to comply with non-judicial demands has intensified European concerns over the security of data processed by AI companies, especially when those companies are subject to U.S. legal demands.
Why it matters
The restriction highlights the growing friction between European data privacy standards and the reality of U.S. legal reach, where tech giants operating AI models remain subject to U.S. subpoenas that can bypass judicial oversight.