Praxikon

Digital Omnibus AI Act: historical proposal analysis

ยทยท12 min read

Current status, reviewed 30 July 2026: this article preserves the debate around the original Commission proposal as historical background. Regulation (EU) 2026/1744 was published on 24 July 2026 and entered into force on 27 July 2026. The final law keeps a direct Article 4 duty, retains a simplified Article 49 registration route, and fixes the core high-risk application dates at 2 December 2027 for Annex III and 2 August 2028 for Annex I. See the current Digital Omnibus guide or the official regulation.

On 19 November 2025, the European Commission published the Digital Omnibus on AI proposal. It sought to simplify the AI Act and make its implementation more proportionate. This article records the proposal, the political debate and the reactions at that stage. References below to proposed changes are historical unless a final outcome is stated.

The political backdrop: why now?

The ink on the AI Act was barely dry when the first cracks appeared. Not in the law itself, but in the political landscape surrounding it.

In September 2024, Mario Draghi presented his now-famous report on European competitiveness. The message was unsparing: the EU is falling further behind the US and China, particularly in advanced technologies. Regulation was seen by more than 60% of EU companies as an obstacle to investment, with 55% of SMEs flagging regulatory obstacles as their greatest challenge. The Draghi report became the intellectual foundation for a broader deregulation agenda.

Simultaneously, major tech companies โ€” Meta, Amazon, Apple and others โ€” launched an aggressive lobbying campaign. Their message: the AI Act "threatens innovation" and is "too expensive" to comply with. The Trump administration added external pressure through the American AI Action Plan, which explicitly called for removing "red tape" and pressured the EU to relax digital rules.

๐Ÿ’ก Key point The Digital Omnibus proposal was not born out of technical necessity, but political pressure. The Draghi report, industry lobbying, and geopolitical tensions created a perfect storm for deregulation โ€” before most AI Act obligations had even taken effect.

Internally, things weren't running smoothly either. The designation of national supervisory authorities was proceeding slowly, the development of harmonised standards by CEN-CENELEC was falling behind, and companies complained about having to comply with rules for which the practical tools were still missing. That last point โ€” the absence of standards โ€” was a legitimate concern. But the Commission leveraged it as a catalyst for something much broader than a deadline extension.

What the original proposal put on paper

On 19 November 2025, the Commission presented its Digital Omnibus package as part of a broader Digital Package, alongside the Data Union Strategy and European Business Wallets. The package consists of two legislative proposals: a general Digital Omnibus (amending the GDPR, ePrivacy Directive, and NIS2 among others) and a specific Digital Omnibus on AI that amends the AI Act.

The ambition is significant: the Commission aims to reduce administrative burdens for businesses by at least 25%, and for SMEs by 35%, by the end of 2029. Expected savings: at least six billion euros.

But the devil, as always, is in the details. Here are the key changes:

1. Original proposal for AI literacy (Article 4)

The original AI Act required providers and deployers of AI systems to ensure their staff had a sufficient level of AI literacy. The Commission proposal would have removed that direct duty and shifted responsibility to the Commission and Member States, which would encourage providers and deployers to take measures.

Final outcome: Regulation (EU) 2026/1744 keeps a direct duty on providers and deployers to take proportionate measures supporting the development of AI literacy. It does not require them to guarantee that every person reaches a fixed level.

2. Original proposal for registration (Article 49)

Under the original AI Act, providers of AI systems falling under Annex III had to register in the EU database even if they concluded that their system was not high-risk via Article 6(3). The Commission proposal would have deleted Article 49(2).

Final outcome: Regulation (EU) 2026/1744 retains this registration route and simplifies the information that providers must submit.

3. Limited deferral for marking of existing generative AI (Article 50(2))

AI systems generating synthetic audio, images, video, or text must mark their output in a machine-readable format using watermarks or metadata. The Article 50 transparency obligations themselves have applied since 2 August 2026 and are not deferred. Only generative AI systems placed on the market before 2 August 2026 receive a limited transition period for marking: the May 2026 political agreement set that date at 2 December 2026.

4. Special category data processing expanded (new Article 4a)

The current AI Act permits the use of special category personal data (such as ethnicity or health data) for bias detection in high-risk AI systems, provided this is "strictly necessary." The Omnibus proposal extends this to all AI systems and lowers the threshold from "strictly necessary" to "necessary."

5. Deferred deadlines for high-risk AI (Article 113)

This is perhaps the most impactful change. Obligations for high-risk AI systems are linked to the availability of harmonised standards and other compliance tools:

Type of high-risk AIOriginal deadlineCommission proposalFinal law
Annex III systems2 August 2026Standards-linked mechanism2 December 2027 for the core obligations
Annex I systems (regulated products)2 August 2027Standards-linked mechanism2 August 2028 for the core obligations
Marking of existing generative AI (Art. 50(2))2 August 2026Transition for pre-August 2026 systems2 December 2026 for those existing systems

6. Conformity assessment: sectoral legislation takes precedence (Article 43)

For products falling under both sectoral legislation (such as medical devices) and the AI Act, providers must now follow the conformity assessment procedure of the sectoral legislation. AI Act requirements are integrated into it, rather than requiring two parallel assessments.

7. Centralisation of supervision at the AI Office

Supervision of AI systems based on general-purpose AI models (where the same provider develops both model and system) and systems integrated into very large online platforms (VLOPs/VLOSEs) is centralised at the Commission's AI Office.

8. Extended arrangements for SMEs and small mid-caps

Simplified compliance procedures previously available only to micro-enterprises are extended to all SMEs and small mid-cap companies (SMCs). This includes simplified technical documentation and proportionate penalties.

โš–๏ธ What's not addressed The proposal conspicuously leaves much unaddressed. Morrison & Foerster highlights: the unclear definition of "provider" (Art. 3(3)), the overlap between the fundamental rights impact assessment (Art. 27) and the DPIA under the GDPR, the overly narrow research exemption (Art. 2(8)), and the lack of a genuine conformity guarantee for AI sandboxes. The risk of national gold-plating via Article 82 also remains.

The reactions: three camps

The EDPB and EDPS: "support, provided that..."

On 20 January 2026, the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) published their Joint Opinion 1/2026. The tone is diplomatic but firm. They support the objective of simplification but raise concerns about virtually every concrete measure:

AI literacy: The supervisory authorities are "strongly against" converting the mandatory AI literacy obligation into a soft encouragement. AI literacy is crucial for understanding AI concepts, ethical and social awareness, and the protection of fundamental rights. New obligations for the Commission should complement, not replace, existing provider and deployer obligations.

Registration: The EDPB and EDPS advise against deleting the registration requirement. The change would "significantly undermine" provider accountability and create undesirable incentives to unduly claim exemptions. The projected savings are marginal and do not justify the loss of transparency.

Special category data: They acknowledge the importance of bias detection but insist on restoring the "strictly necessary" threshold and clear delimitation to situations where the risk of adverse effects is "sufficiently serious."

Deadlines: "Sincere concerns" about the delay, given the rapid evolution of the AI landscape. The co-legislators are called upon to maintain the original timeline for certain obligations โ€” particularly transparency requirements.

Civil society: "historic rollback"

133 civil society organisations and trade unions signed a joint statement even before publication calling on the Commission to halt the Omnibus proposal. EDRi (European Digital Rights) called the proposal "a major rollback of EU digital protections." The Civil Liberties Union for Europe was even more direct: the Omnibus "gives Big Tech exactly what it wanted" and undermines the EU's position as a global leader in technology regulation.

Corporate Europe Observatory documented how specific amendments could be traced back to lobbying points of major tech companies. A particular point of criticism: the Commission did not carry out an impact assessment when drafting the proposal, while claiming the changes would have "no impact on fundamental rights" โ€” precisely while fundamental rights protections were being weakened.

The Dutch government: critical but nuanced

On 12 December 2025, the Dutch cabinet published its BNC-fiche on the Omnibus AI and Omnibus Digital. The tone: supportive of the objective, critical of the execution.

The Netherlands recognises that reduced regulatory burden can benefit businesses, particularly SMEs. But the cabinet states that several changes would "substantially diminish" the level of data protection. The Hague specifically raises concerns about:

  • Personal data for AI training: the expanded use of (sensitive) personal data conflicts with fundamental rights and goes further than necessary for burden reduction
  • GDPR adjustments: relaxation of the "legitimate interest" processing ground and data breach notification weaken citizen protection
  • Centralisation of cyber reporting: the Netherlands fears national reporting systems will be bypassed and sensitive information about critical infrastructure will end up at the European level
  • Missing impact assessment: unclear what the proposals concretely deliver and what the consequences are

The cabinet wants "further clarity from the Commission" before reaching a definitive judgment.

๐Ÿ‡ณ๐Ÿ‡ฑ Dutch position summarised The cabinet wants the omnibuses to "simplify, clarify, and streamline" without undermining the objectives of the legislation โ€” protection of fundamental rights, safety, and privacy. A nuanced position that leaves room for negotiation but sets clear boundaries.

Where the legislative process ended

The proposal completed the legislative process in July 2026. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It is binding law, not a pending proposal. The final text differs materially from the original proposal on Article 4 and Article 49, so the current Digital Omnibus guide should be used for implementation decisions.

What does this mean for organisations?

The uncertainty is over. Organisations should plan against Regulation (EU) 2026/1744: continue Article 4 measures, preserve evidence, maintain the applicable Article 49 registration record, and work towards the fixed high-risk dates.

๐ŸŽฏ Practical advice: plan on the current law

Compliance officers: apply the amended AI Act. The prohibited-practice and GPAI rules remain in force, Article 4 still requires measures, and the high-risk dates are now fixed. The additional implementation time is a reason to phase the work pragmatically, not to pause it.

  • โœ… AI literacy: continue investing, regardless of the Omnibus. The EDPB/EDPS support enforcement. Moreover, it's good risk management.
  • โœ… Registration: register your systems proactively. If the requirement disappears, you've lost nothing. If it doesn't, you're prepared.
  • โœ… High-risk compliance: start gap analyses and risk assessments now. Even with a 16-month deferral, implementation time is tight.
  • โœ… Documentation: the documentation requirement for self-assessed non-high-risk systems remains in all scenarios.

Historical analysis: simplification or weakening?

Let's be honest: the AI Act did have implementation problems. Missing standards, undesignated national authorities, delayed guidelines โ€” these are real obstacles. Linking deadlines to the availability of standards is a defensible choice in itself.

But the proposal goes beyond pragmatic recalibration. Scrapping the AI literacy obligation is not simplification โ€” it's a fundamental policy change. Removing the registration requirement for systems that are potentially high-risk undermines the transparency the entire AI Act was built upon. And lowering the threshold for processing special category data from "strictly necessary" to "necessary" is a subtle but meaningful difference that opens the door to broader use.

The core problem is that the Commission conflates two very different objectives: implementation support (more time, better standards, practical guidelines) and regulatory relief (fewer obligations, lower thresholds, less transparency). The former is legitimate and welcome. The latter is a political choice dressed up as technical simplification.

Morrison & Foerster puts it aptly: "If even the Commission and standardisation organisations fail to meet their own clarification goals and deadlines, how can the industry be expected to comply with often complex and unclear requirements?" That's a fair point. But the solution is better support, not less protection.

Gleiss Lutz emphasises: "The proposed amendments should not be seen as deregulation, but rather as concessions on a practical level." That's the optimistic reading. The pessimistic reading โ€” and that of 133 civil society organisations โ€” is that this marks the beginning of a systematic dismantling of Europe's digital rights framework.

The final regulation landed between the original positions. It extended the high-risk timeline and reduced some administrative burden, while keeping a direct AI literacy duty and retaining a simplified registration route.

Conclusion: vigilance is warranted

The historical debate shows why proposal analysis must be separated from the binding text. For organisations, the message is now clear: implement the amended AI Act. The prohibitions and GPAI rules apply, Article 4 remains a direct measures duty, and the high-risk dates are fixed. Use the extra time to build evidence and controls properly.

As EDPB Chair Anu Talus put it: "Innovation and efficiency are crucial and can coexist with maintaining accountability of AI providers." That's not an impossible combination. It's precisely what the AI Act was designed for.


Want to prepare your organisation for the AI Act, regardless of what the Omnibus brings? Embed AI helps organisations with practical AI Act-readiness, from gap analysis to implementation.

Newsletter

Every Tuesday, the AI Act week ahead in 5 minutes

A practical briefing on deadlines, new guidance and enforcement, so you know what matters this week. No spam and you can unsubscribe in one click.

Practical and short ยท No spam ยท One-click unsubscribe