Subscribe on LinkedIn

The Commission Already Wears Too Many Hats. Now It Wants to Be a Standards Body Too?

On 2 June 2026, the Commission convenes its first stakeholder workshop on machine-readable opt-out protocols for AI training data, co-chaired by the Director of the AI Office and the Director of the Media Policy Directorate of DG CNECT. The process follows a stakeholder consultation that ran from December 2025 to January 2026 and drew 153 responses. Its purpose is to produce a list of “generally agreed” machine-readable opt-out solutions under Measure 1.3(1)(b) of the copyright chapter of the GPAI Code of Practice that signatories, and other GPAI model providers, would be expected to respect. Only a short notice was given for the first workshop’s ambitious objectives. The agenda was consequential; the preparation time was not.

Even more concerning than the rushed process is the fact that the Commission appears to be adding a new role to its existing portfolio. In a November 2025 paper on EU digital competitiveness, the Brussels think tank CERRE identified a structural problem at the heart of European regulation. The Commission, it argued, accumulates roles that should be held separately: legislator, enforcer, evaluator, geopolitical actor. Evaluating legislation you wrote biases the assessment. Enforcing rules you designed creates reluctance to admit they are wrong. CERRE recommended either strong internal separation or, more ambitiously, breaking the Commission into distinct entities for each function. Through this process, the Commission appears to be adding de facto standard-setter to that list.

The Commission’s own Note for Participants is careful to insist that “the procedure… is not a standard-setting process” but rather an effort to reach general agreement among stakeholders in the absence of recognised industry standards. That distinction is thinner than it appears. A Commission-published list of approved compliance tools, tied to obligations under Article 53(1)(c) of the AI Act, functions as a de facto standard regardless of what the covering note calls it. Doth the Lady protest too much?

GSM Was the Exception, Not the Template

The Commission’s landmark moment in technology standardisation is GSM. The Global System for Mobile Communications, developed through ETSI in the 1980s and mandated across Europe in the early 1990s, became a genuine global standard. It succeeded because it was technically mature, commercially backed by manufacturers with a shared interest in a single market, and developed through a legitimate standardisation process with broad industry participation. It was adopted, not imposed on an unwilling or simply unaware ecosystem.

GSM casts a long shadow. It is the example Commission officials reach for when they want to demonstrate that European regulatory coordination can shape global technology. What tends to get left out of that account is the rest of the ledger.

The Multiplexed Analogue Components standard (MAC, and its variants D-MAC, D2-MAC and HD-MAC) was mandated by EU Directive in 1986 as the stepping stone to European HDTV. It was designed to protect European television manufacturers and create a transition pathway before digital television arrived. A Council Directive in 1992 doubled down, mandating HD-MAC for HDTV transmissions and D2-MAC for widescreen satellite broadcasts, and requiring all new television equipment to carry decoders. The standard was abandoned by 1993. The market had moved to digital systems it had not waited for the Commission to endorse.

Digital Audio Broadcasting tells a parallel story. DAB was developed through the EUREKA-147 project and positioned in the 1990s as the obvious successor to FM radio in Europe. The Commission backed it. Manufacturers produced receivers. Some member states invested in infrastructure. The technology was not wrong, exactly, but the assumptions embedded in the mandate were. Internet streaming arrived. Podcasting arrived. The DAB receivers mandated for new cars from 2020 onwards are receiving broadcasts that a significant portion of the intended audience had already decided to consume differently. Across several EU member states, including Spain and Portugal, DAB infrastructure was never built at meaningful scale. The standard succeeded where the market had already moved toward it, and stalled everywhere else.

The pattern is clear enough. When the Commission has moved to endorse technology standards ahead of genuine market adoption, in sectors where the technical landscape was still shifting, the results have been at best mixed and at worst wasteful. The preconditions for GSM’s success were technical maturity, broad commercial alignment, and process legitimacy. In the MAC and DAB cases none of those conditions held. The current text and data mining (TDM) opt-out process shares more with the latter than the former.

A Consultation That Reflects Who Responded

Before examining the proposed mechanisms, it is worth understanding whose views shaped the consultation’s conclusions. Of the 153 respondents to the December 2025 survey, approximately 60% were rightsholders, 7% were GPAI model providers, and 33% were other stakeholders. The consultation’s finding that TDMRep, C2PA TDM Assertions, and JPEG Trust Core Foundation V2 represent front runners capable of fulfilling the requirements of Measure 1.3(1)(b)  of the Copyright Chapter reflects that distribution. The Commission’s summary report circulated to the participants selected for the 2 June workshop acknowledges that GPAI model providers “adopt a critical stance compared to other stakeholders,” warning that the consultation “risks prematurely endorsing immature or untested solutions” that could “create legal uncertainty, technical complexity and compliance burdens.” That view, from the developers who would bear the compliance cost, represents seven percent of respondents. General agreement reached on those terms is not the same as broad consensus.

One clarification that the documents provide is worth stating plainly. Robots.txt is already secured. Under Measure 1.3(1)(a), Code signatories are already committed to employing web crawlers that respect robots.txt as specified in IETF RFC 9309. The question the June process is trying to answer is not whether robots.txt survives, but what sits alongside it under Measure 1.3(1)(b) as an intermediate solution pending the development of recognised international standards. That is a narrower question, and a more legitimate one, than picking a permanent replacement. But the answer still matters: whatever ends up on the Commission’s list risks carrying real compliance weight.

The Candidates Are Not Ready

The Commission appears to have identified three front runners: TDMRep, C2PA-based assertions developed through the C2PA (Coalition for Content Provenance and Authenticity) Authenticity Working Group (CAWG), and JPEG Trust Core Foundation V2. None meets the threshold of technical maturity, scalability, and open governance that would justify even an interim endorsement.

TDMRep is the most widely deployed of the surveyed protocols among rightsholders, though primarily within books and press publishing. Adoption among EU news publishers more broadly sits below three percent according to 2025 Reuters Institute data. GPAI model providers responding to the consultation were largely critical: the protocol requires checking multiple technical layers simultaneously, the metadata it relies on is static and routinely stripped during transmission, and it cannot distinguish between different types of crawlers.

C2PA was built to establish technical provenance, not to communicate legal rights ownership. The Commission’s own summary report acknowledges that rightsholders “saw the value of C2PA mainly as a provenance tool, noting that it does not have a particular opt-out functionality.” The TDM-related functionality sits in external extensions developed within the CAWG rather than in the core C2PA specification, raising governance questions the consultation does not resolve. There is also a GDPR dimension: using C2PA for opt-out purposes could require creators to link personal identification data to their published work as the price of exercising a legal right.

JPEG Trust v2 is in development, with no live deployments, and confined to the JPEG image ecosystem. It is structurally incomplete for multimodal AI training. The centralised registry proposals introduce a further order of risk: single-entity control over compliance infrastructure creates a single point of failure, and the Commission’s own consultation report notes that at least one such solution is reportedly “no longer available.” None of these problems appears to have been resolved between the consultation closing in January and the workshop convening in June.

Picking Winners Has Consequences

The Commission frames this as a facilitation exercise, helping the market converge on solutions that work. The effect would be different. Placing specific mechanisms on an official Commission-published list, tied to AI Act compliance, is not neutral even when labelled provisional. It would grant a regulatory imprimatur to the organisations that developed those mechanisms, create a compliance pathway running through commercial relationships rather than open standards, and foreclose space for alternatives that may prove more robust but need time and a level playing field to develop.

Several mechanisms under active discussion are commercially operated by private entities. If those mechanisms appear on a Commission list, AI developers operating in the EU would face a choice between entering commercial relationships with those entities or operating under legal uncertainty. That is a state-sanctioned competitive advantage granted to specific private ventures through a regulatory process. The Commission has stated commitments to technology neutrality and to open source as a driver of digital sovereignty. A list dominated by proprietary mechanisms would be inconsistent with both.

The conflicting-signals problem also remains unresolved. If a domain-level instruction permits AI training and an embedded file-level assertion from a different mechanism forbids it, the developer has no clear path to compliance. The consultation’s summary report acknowledges that respondents raised “concern that the coexistence of multiple, non-interoperable protocols could lead to conflicting signals, increased compliance costs and legal uncertainty.” Multiplying recognised mechanisms before that question is settled does not reduce that uncertainty. It compounds it.

Digital Sovereignty Means More Openness, Not Less

There is a version of digital sovereignty that the Commission articulates and a version that this process risks producing. The articulated version is one where European developers have access to open infrastructure, where standards emerge from legitimate consensus processes, and where regulatory design expands rather than constrains the field of possible solutions. The version this process risks producing is one where European AI developers are required to navigate a proliferating set of EU-specific compliance requirements, some of which run through private commercial relationships, none of which interoperates cleanly, and all of which diverge from the global technical standards developing in parallel.

The open web is not a closed ecosystem. Whatever protocol infrastructure becomes embedded in how AI developers are expected to read permissions will propagate far beyond the signatories to the GPAI Code of Practice. Publishers who have never heard of Measure 1.3(1)(b) will find their content treated according to its logic. Developers building tools that have nothing to do with GPAI training will encounter the same signals. A process that convened 153 respondents, seven percent of whom were AI developers, is making decisions with consequences for the architecture of the entire web.

The IETF’s AIPREF working group is doing the legitimate standardisation work for machine-readable AI training preferences right now. That process is consensus-driven, internationally recognised, and engages both developers and rights holders. The Commission’s own consultation respondents noted that IETF-based work remains ongoing and supported incremental improvements developed through open international standardisation processes. The AI Act’s own standardisation logic anticipated a leading role for bodies such as CEN-CENELEC for complex technical guidance. A Commission-published list of opt-out mechanisms that diverges from whatever the IETF produces would not strengthen European digital sovereignty. It would create a compliance island that imposes costs on European developers and produces no commensurate benefit for rights holders.

AI development depends on access to large, diverse training datasets from the open web. Complicating that access with fragmented, immature, and EU-specific compliance requirements raises the barrier to entry for European developers relative to competitors in jurisdictions that have not introduced equivalent complexity. The Commission has identified European AI competitiveness as a strategic priority. The Competitiveness Compass and the AI Continent Action Plan both point in that direction. This process works against it.

What a Proportionate Process Looks Like

The Commission should treat the current workshop series as the genuine stocktaking exercise its own documents describe. That means commissioning independent, rigorous feasibility assessments of the proposed mechanisms, not relying on studies produced by the mechanisms’ own proponents or on a consultation where AI developers represented only seven percent of respondents. And it means referring the standardisation work to the bodies equipped to do it: primarily the IETF’s AIPREF working group.

In the interim, the Commission should affirm that AI developers operating within the TDM framework of the Copyright in the Digital Single Market  (CDSM) Directive, respecting existing web standards, including robots.txt under Measure 1.3(1)(a), and acting in good faith, retain legal certainty for their training activities. The current process has introduced ambiguity where there was relative clarity. Resolving that ambiguity by endorsing immature mechanisms under pressure of timeline does not serve developers, rights holders, or the broader goal of a functioning digital single market.

CERRE’s November 2025 paper argued that the Commission’s accumulation of roles, without separation or independent oversight, is one of the reasons delivering a competitiveness agenda has proven so difficult. Adding de facto standard-setter to that accumulation, in a domain where the technical work is already underway in the appropriate international bodies, does not fill a gap. It creates a new conflict of interest: the body that wrote the AI Act, that is now enforcing the Code of Practice, would also have selected the compliance tools. The Commission’s own note insists this is not standard-setting. The more productive question is whether the distinction between “facilitated general agreement” and standard-setting holds when the output is a Commission-published compliance list with legal consequences attached.

Written by Caroline De Cock, LL.M., Head of Research