On 19 November, the European Commission unveiled its Digital Omnibus: a broad simplification package on AI, cybersecurity, and data which would impact a number of legislations, notably the AI Act, the GDPR, or the Data Act. While the Commission wants companies to “spend less time on administrative work and compliance and more time innovating and scaling-up”, critics point to a dangerous regulatory bonfire.

What’s Cooking?

Omnibus bills were mainly used to consolidate or simplify EU laws without changing their substance. The new “omnibus wave” shifts this tool toward substantial policy revisions — reopening recent legislation, skipping safeguards like consultations and impact assessments, and, according to legal experts, potentially breaching EU law and weakening the rule of law.

The Digital Omnibus signals a major pivot in tech policy. It aligns with a broader “simplification” (some would say deregulatory) push backed by the political right in the European Parliament, quite a few EU Member States, U.S. tech giants, and major European players such as Airbus, ASML and Mistral. It lands in a moment of geopolitical anxiety: rapid AI acceleration, Trump’s return to the White House, and Europe’s fear of falling behind.

Economic pressure adds urgency. Mario Draghi warned Europe faces an “existential” competitiveness threat without major reforms.

GDPR compliance makes data costs roughly 20% higher than in the U.S.

Europe operates under around 100 tech laws enforced by more than 270 regulators.

Critics see a different trend: a deregulatory slide. AccessNow argues the package “destroys fundamental rights safeguards.” AI Act rapporteur Brando Benifei warns of a “race-to-the-bottom agenda,” rejecting the idea that Europe must choose between innovation and accountability.

Data & Privacy: More Freedom?

The Digital Omnibus introduces substantial changes to data, privacy, and cyber laws. It proposes to update the GDPR and merge the Data Governance Act (2022), the Open Data Directive (2019) and the Free Flow of Non‑Personal Data Regulation (2018) into the Data Act.

Narrower definition of “personal data”. An organisation could treat data as “personal” only if that organisation has reasonable means to reasonably identify the individual from the data. Businesses may decide that certain data they hold is non-personal, for example by pseudonymisation, allowing easier reuse or sharing of personal data.

Easier use of personal data to train AI. The reform allows the processing of personal data for the development and operation of AI systems under certain conditions. As a result, your usage data from services or platforms could be re-used to train AI models without needing separate explicit consent.

Reduced obligation to inform about processing. Companies would be able to decide not to issue certain notifications about how your data is processed if they reasonably believe you already know how it’s being used — unless the data is transferred to another party, used for automated decision-making, or crosses borders.

AI Act: Hold & Rethink?

The AI Act (adopted in 2024) was seen as a case-in-point of excessive red tape. It was drafted before AI entered the mainstream with ChatGPT nearly three years ago, and it’s widely acknowledged that the final rush to approve it before the end of the previous legislature left little room for recalibration.

Industry voices have long argued the AI Act is too fragmented and impossible to implement on schedule. Standardisation bodies have already missed deadlines twice, and countries including France, Germany, Sweden and Poland deem the 2025 timeline “unworkable.”

The proposed changes to the AI Act aim to give regulators more time to define standards and governance, soften some requirements, and tailor obligations to the size of companies.

Changing timelines Companies that develop or deploy AI systems that may pose a risk to people’s health, safety and fundamental rights (i.e. “high risk”) were expected to meet their compliance obligations by mid-2026 under EU AI Act. The Digital Omnibus proposes to delay that deadline, giving extra time for companies to adapt, for standards to land, and for regulators to develop tools and guidance.

Expanding of the EU AI Office’s authority. The Digital Omnibus assigns the AI Office exclusive supervisory and enforcement competence AI systems based on general-purpose models. The EU AI Office would also extend to AI systems integrated into major online platforms and search engines under the DSA.

Less compliance requirements for small and mid caps. The Digital Omnibus introduces lighter compliance penalties and possibly lighter obligations for companies with up to 750 employees and under €150 million annual turnover. They will still need to meet key obligations; lighter penalties do not mean no obligations.

What’s Next

The political fight now shifts to Parliament and Council.

Centre-right groups will stress competitiveness; Greens, S&D and parts of Renew warn of eroded rights and weaker enforcement.

Member States are split: Germany and France lead the pro‑delay bloc; the Netherlands wants clarity without a full pause.

Once positions are set, trilogues with the Commission start in spring 2026 to forge a single text. If Parliament invokes the urgent procedure, a vote could land in the first half of 2026. Otherwise adoption won’t happen before mid to late 2026.