The Digital Omnibus at a glance
On 19 November 2025, the European Commission published its so-called Digital Omnibus proposals: the Digital Omnibus Regulation Proposal (“Data Omnibus”) and the Digital Omnibus on AI Regulation Proposal (“AI Omnibus”). The Digital Omnibus package reflects the Commission’s ambitious efforts to simplify digital regulation in the EU and has been the definitive hot topic for AI and privacy professionals this year.
The package includes amendments to the Artificial Intelligence Act (“AI Act”), the General Data Protection Regulation (“GDPR”), the Data Act, the ePrivacy and NIS2 Directives, as well as certain related regulations. An overview of the key elements of the Digital Omnibus is presented in the table below:

While the Data Omnibus, as a whole, covers a broader range of digital regulation, the AI Omnibus and its amendments to the AI Act were particularly consequential and time-sensitive. Many organisations spent early 2026 managing, and arguably struggling with, urgent compliance projects to meet their obligations under the AI Act by the initial key deadline of 2 August 2026. Therefore, the simplifications and deadline reliefs brought through the adoption of the AI Omnibus this summer were highly welcomed by the European market. In this article, we take a closer look at how the AI Omnibus realigned the AI Act and its regulation of AI development and use in the EU.
Recalibration of AI rules
The AI Omnibus marks an effort to recalibrate the AI Act’s regulatory approach to AI and is a key part of the European Commission’s broader objective to streamline EU legislation and improve the competitiveness of the EU market. In essence, it is a direct response to rather vocal criticism alluding to unreasonable administrative burdens under the AI Act and related risks of the EU falling behind in the global AI race.
First and foremost, the key element of the AI Omnibus is the pushback on the AI Act’s application timeline. The AI Act entered into force already in August 2024 but was designed to start applying in phases – giving organisations time to prepare for its requirements. While its first phase of obligations became applicable in February 2025 (namely, bans of certain AI systems and AI literacy requirements), the primary focus has been on the AI Act’s ‘main application deadline’ of 2 August 2026. As of that date, requirements on so-called high-risk AI systems, i.e., the bulk of obligations under the AI Act, as well as the Act’s substantial transparency rules were set to begin to apply.
However, this deadline came under heavy criticism from market participants contending that the timeline was not fully realistic. For high-risk AI, the key argument was that the original application dates were unreasonable given the absence of relevant harmonised standards, common specifications and supporting guidelines required from the EU level. On this basis, high-risk AI rules were afforded rather significant deadline extensions under the AI Omnibus: from the initial 2 August 2026 to 2 December 2027 for so-called standalone high-risk systems (Annex III of the AI Act: biometrics, critical infrastructure, education, HR and certain essential private and public services and processes) and from the initial 2 August 2027 to 2 August 2028 for regulated products (Annex I of the AI Act: AI systems constituting a product covered by EU sectoral safety legislation or a safety component thereof). For transparency rules, the application of the so-called watermarking requirements for synthetic content was granted a grace period as regards pre-existing systems (placed on the market before 2 August 2026), delaying application from 2 August 2026 to 2 December 2026 in order to provide relevant AI providers with sufficient time to adapt and minimise market disruption.
Beyond timelines, the AI Omnibus granted compliance reliefs under the AI Act. Firstly, certain reliefs initially reserved for SMEs, including simplified technical documentation, were extended to so-called small mid-cap enterprises. Secondly, and as a particular point of contention in the legislative negotiations, the interplay between the AI Act and existing EU product safety legislation was adjusted. The business community had been actively advocating for regulated, sector-specific machinery and devices – most notably, industrial machines and medical devices – to be excluded from the scope of the AI Act. These efforts were partially successful, as the machinery sector was essentially carved out from the AI Act’s direct applicability.
However, other industries, such as the medical device sector, were disappointed to learn that they were not granted such an exclusion. As a result, for other regulated sectors than machinery, relevant AI systems require compliance efforts under both existing sector-specific legislation and the AI Act – although such systems of course benefit from the aforementioned deadline push to 2 August 2028. Additionally, the Commission was empowered to adopt delegated acts to limit the application of AI Act requirements where reasonable to avoid regulatory overlaps. Moreover, the specifications introduced by the AI Omnibus to the concept of a ‘safety component’ may allow providers of certain AI systems to avoid the high-risk category: according to the adjusted definition, merely assisting, performance optimising, automation, and similar non-safety features are not automatically considered high risk.
The AI Omnibus did not only bring regulatory reliefs, as the EU legislators also agreed to expand the list of prohibited AI practices during the legislative negotiations. Namely, there was a broad consensus among legislators and the wider public that so-called ‘AI nudifiers’ – AI systems involving the generation or manipulation of realistic intimate or sexually explicit imagery of individuals without their consent – as well as systems involving child sexual abuse material (“CSAM”) pose an unacceptable risk to fundamental rights. Therefore, the AI Omnibus added such systems to the AI Act’s prohibited category, effective as of 2 December 2026.
To summarise, a comprehensive overview of the key amendments under the AI Omnibus is provided below:
|
Status in Autumn 2026: AI Omnibus in force
Despite extensive debates and challenges during the legislative process, the EU legislators finally came to a consensus on the AI Omnibus in May 2026, accepting the amendments to the AI Act as described above. In June, the European Parliament and Council gave their final approvals on the AI Omnibus, and it officially entered into force on 27 July 2026.
Despite the many extensions and reliefs now in force, it is important to note that certain essential obligations began to apply on the initial 2 August 2026 deadline. Namely, the various transparency obligations of the AI Act are now applicable (other than the abovementioned watermarking requirements for pre-existing systems) and require providers to inform individuals when they interact directly with an AI system and to mark AI-generated content, while deployers must disclose the use of emotion-recognition, biometric categorisation tools, deepfakes, and AI-generated public-interest texts published without human review. To support related efforts, the Commission, in the nick of time, published guidelines on the AI Act’s transparency requirements on 20 July as well as a Code of Practice on Transparency of AI-generated Content earlier in June. The late timing and content of these guidelines have been subject to some debate.
AI privacy aspects beyond the AI Omnibus
In terms of AI-related data protection aspects, the AI Omnibus expanded the right to process so-called special categories of personal data for bias detection and correction purposes. Bias controls specifically aim at ensuring that decision-making and similar AI-based processes are not inappropriately influenced by aspects relating to individuals’ sensitive characteristics, such as health, background, or sexual orientation. Related information typically constitutes special-category data under the GDPR requiring additional bases for its processing, which is why the AI Act provides a relevant legal basis applicable to bias detection and correction. Whereas initially the AI Act provided a basis for special-category processing only to providers of high-risk AI systems, the AI Omnibus expanded these processing rights, where necessary, to other than high-risk systems and to deployers of AI systems.
In addition to this data-protection-related amendment within the AI Omnibus itself, the Data Omnibus sets out certain amendments to the GDPR, which would provide further reliefs in the context of AI. Currently, identifying the appropriate legal basis for processing personal data in certain AI cases has posed a significant challenge for AI operators. The proposed reforms address two key areas. Firstly, the proposal introduces an additional basis for processing special-category data, recognising that such data may be unavoidably present in training, testing, or validation datasets, or remain embedded within AI systems or models even without intent. The exception would permit this kind of inadvertent processing where the controller has implemented effective technical and organisational measures to avoid processing such data and other related safeguards throughout the AI system’s lifecycle. Secondly, the Data Omnibus aimed to expressly acknowledge that the development and operation of AI systems constitute a legitimate interest as a general legal basis for processing personal data. However, based on legislative negotiations so far, the adoption of this second aspect appears uncertain.
While the AI Omnibus was subject to a more pressing legislative timetable, the same urgency does not apply to the proposed GDPR amendments under the Data Omnibus. Of the overall data-protection-related reforms in the Digital Omnibus proposals, only the expanded basis for processing special categories of personal data for bias detection and correction was included and agreed as part of the AI Omnibus package. The GDPR reforms advance within the separate Data Omnibus legislative track and proceed at a considerably slower pace. According to certain sources, adoption of a final text of the Data Omnibus could occur in early 2027 with entry into force between 2027 and 2028.
It is worth noting that, apart from the Digital Omnibus project, the GDPR has already been subject to earlier simplification efforts under the so-called Omnibus IV initiative. In summer 2026, a further political understanding was reached regarding the Omnibus IV, and adoption could occur in November 2026. This initiative is not specifically geared towards AI aspects but, instead, focuses on relieving organisations’ obligations to prepare so-called records of processing activities (GDPR Article 30).
How to prepare?
The AI Omnibus allows companies involved with AI to catch their breath and leverage the extended compliance deadlines. That being said, particularly in the context of high-risk AI systems, the extended enforcement timeline should not be taken as an invitation for organisations to be complacent. Since such relief regarding the timelines has been granted, the legislator and authorities can be assumed to expect credible compliance from organisations by the time the revised deadlines take effect. Therefore, organisations would be well advised to use the additional time to build robust internal compliance frameworks that are ready for deployment well ahead of the relevant deadlines.
It is also worth noting that the adoption of the AI Omnibus this summer does not represent the end of regulatory twists and turns for AI. Organisations operating with AI and data should, therefore, maintain a close watch on forthcoming developments, including the GDPR simplification proposals contained in the Data Omnibus, which have significant implications for AI development and deployment. Compliance regarding these matters should be seen as a continuous effort rather than a static, one-time exercise.
Our team is happy to discuss any questions you may have regarding the EU privacy, data and AI rules.
Contact

