Starting point: too much regulation, too little coordination
In recent years, the European Union has created an extensive digital regulatory framework. With the GDPR, AI Act, Data Act, Data Governance Act, NIS2, DORA, ePrivacy and other legal acts, the legislator is pursuing ambitious objectives: the protection of fundamental rights, secure digitalisation, trustworthy AI and a functioning data economy.
In practice, however, a structural problem has emerged: many of these regulatory frameworks are closely interconnected in substance, but use different terms, thresholds, deadlines and procedural logic.
For companies, this leads to parallel obligations, multiple risk analyses, duplicate reporting channels and considerable legal uncertainty at the interfaces — especially where data protection, AI, data use and IT security come together.
This is precisely where the Digital Omnibus and the Digital Omnibus AI, which the European Commission presented in November 2025, come in.
Unlike earlier digital legislation, they are not primarily aimed at creating new obligations, but at coordination, harmonisation and relief.
Adjustments to the AI Act: more time, more proportionality, more clarity
One focus of the Digital Omnibus is on changes to the AI Act, which is currently tying up considerable implementation resources in many companies.
Postponement of the timeline for high-risk AI
The obligations for providers and deployers of high-risk AI systems were originally set to apply from 2 August 2026. The Digital Omnibus now provides for this date to be postponed.
Two alternatives are being discussed:
- application only 6 to 12 months after approval of the relevant harmonised technical standards; or
- fixed later cut-off dates: December 2027 or August 2028 — depending on whether the high-risk system falls under Annex III or under the legal acts referred to in Annex I.
For companies, this primarily means greater planning certainty, more realistic implementation periods and a stronger orientation towards standards that are actually available.
Reduction of AI literacy obligations
A significant easing is also planned with regard to what is known as AI literacy. Instead of a legally binding obligation for providers and deployers, the European Commission and the Member States are to be required in future to promote AI literacy.
Companies are to be “encouraged” to take measures to ensure an appropriate level of AI literacy. For SMEs and mid-sized companies in particular, this reduces the immediate implementation pressure without taking the topic out of focus.
Strengthening and recalibrating the EU AI Office
The remit of the EU AI Office is to be expanded. In future, it is to act itself as the competent supervisory and enforcement authority where general-purpose AI models and AI systems based on them are developed by the same provider.
In this way, the legislator is responding to the growing market significance of integrated AI ecosystems and creating clearer responsibilities at European level.
Fewer registration obligations for systems that are not actually high-risk
In future, providers will no longer have to register an AI system in the public EU database if they use a system formally in a high-risk area, but have classified it in a traceable manner as not high-risk due to its specific use.
The documentation obligation remains in place — the evidence must be made available upon request. However, the administrative burden is significantly reduced.
More proportionate sanctions for small mid-caps
The Digital Omnibus expands the existing concept of proportionate sanctioning. The category of Small Mid-Caps (SMCs) is newly introduced: companies with up to 750 employees and less than EUR 150 million in annual turnover.
Lower and more graduated sanctions are to apply to these companies — an important signal for growth-oriented mid-sized businesses.
Newsletter
For your Inbox
Current updates and important information on topics such as data law, information security, technology, artificial intelligence, and much more. (only in German)
New legal basis for bias detection and correction
The introduction of a new Article 4a in the AI Act is particularly relevant in practice. It permits the processing of personal data — including special categories under Article 9 GDPR — solely for the purpose of bias detection and bias correction in AI systems.
Permissibility is subject to strict conditions:
- no equally effective alternative without sensitive data;
- pseudonymisation or technically highly restricted processing;
- strict access controls;
- erasure of the data once the purpose has been achieved;
- detailed documentation in the record of processing activities;
- no access by third parties.
In this way, the legislator creates, for the first time, a clear bridge between AI regulation and data protection law.
Changes to the Data Act: focus on emergencies and protected interests
The Data Act is also being fundamentally refined as part of the Digital Omnibus.
Recasting B2G data access
Access by public bodies to company data (B2G) is in future to be limited exclusively to public emergencies. The previously broad concept of “exceptional need” is being removed.
At the same time, the protection of trade secrets is being strengthened: companies may refuse disclosure where there is a high risk of misuse.
Compensation obligation and relief for small companies
For micro and small enterprises, it is clarified that they may request compensation when providing data in emergencies. In doing so, the legislator takes account of the economic burden on smaller market participants.
Removal of the smart contract provisions
The planned smart contract requirements in the Data Act (Article 36) are deleted in full. The background is concern about disproportionate technical and legal burdens for companies.
Cloud switching and grandfathering
A comprehensive grandfathering regime for legacy contracts is being introduced for cloud and data processing services.
Contracts concluded before or on 12 September 2025 — in particular for individually adapted services and for offerings from SMEs and SMCs — do not have to be renegotiated.
However, clauses that conflict with the requirements on switching and egress charges are void.
Consolidation of existing data regimes
Provisions from the Data Governance Act and the Open Data Directive are being integrated into the Data Act; in return, both instruments are to be repealed.
The aim is to create a more uniform and clearer data law architecture.
GDPR, ePrivacy and incident reporting: harmonisation instead of parallel structures
Clarifications in the GDPR
In future, greater emphasis is to be placed on which means of identification a specific controller can realistically use.
In addition, new and clearer legal bases are being created for data processing in connection with AI systems and biometric authentication.
The data protection impact assessment (DPIA) is to be harmonised across Europe: the EDPB is to specify central methods and lists, which will be implemented through implementing acts.
Consent and access to terminal equipment
The rules on access to the terminal equipment of natural persons are being moved entirely into the GDPR. ePrivacy will remain relevant only for non-personal data or non-human users.
New elements include:
- simple refusal of consent (“one click”);
- no renewed requests while consent is valid;
- blocking periods of at least six months after refusal;
- introduction of machine-readable consent and objection signals.
Controllers must support these signals 24 months after entry into force; browser providers (except SMEs) after 48 months.
Central incident reporting
Finally, a central single entry point at ENISA for incident notifications is planned.
Notifications under NIS2, DORA, GDPR, eIDAS, CER and CRA are to be bundled initially in a pilot phase.
Conclusion: simplification with strategic depth
The Digital Omnibus is not a dismantling of regulation, but an attempt to make existing obligations more practicable and more consistent.
For companies, new room for manoeuvre is opening up — while at the same time the need for an integrated view of data protection, AI, IT security and data strategy is increasing.
Those who review at an early stage which projects and structures are affected can not only reduce risks, but also use regulatory clarity specifically as a competitive advantage.
Schedule your initial consultation
Describe your situation to us in a no-obligation phone call, and our lawyers will work with you to find the best solution.