Hello! Today is 24 November 2025, and here is the EU news you need this week. Feel free to share this newsletter with friends and colleagues, and follow us on LinkedIn.
Lorenzo Ancona is the founding editor of Artifacts, a newsletter on technology policy. He works at Tremau, a start-up helping online platforms with trust & safety and automating compliance with global regulations. He was born and raised in Rome and now lives in Paris.
Briefing Lorenzo Ancona
Digital Omnibus: Bonfire Or Spring Cleaning?
On 19 November, the European Commission unveiled its Digital Omnibus: a broad simplification package on AI, cybersecurity, and data which would impact a number of legislations, notably the AI Act, the GDPR, or the Data Act. While the Commission wants companies to “spend less time on administrative work and compliance and more time innovating and scaling-up”, critics point to a dangerous regulatory bonfire.
What’s Cooking?
Omnibus bills were mainly used to consolidate or simplify EU laws without changing their substance. The new “omnibus wave” shifts this tool toward substantial policy revisions — reopening recent legislation, skipping safeguards like consultations and impact assessments, and, according to legal experts, potentially breaching EU law and weakening the rule of law.
The Digital Omnibus signals a major pivot in tech policy. It aligns with a broader “simplification” (some would say deregulatory) push backed by the political right in the European Parliament, quite a few EU Member States, U.S. tech giants, and major European players such as Airbus, ASML and Mistral. It lands in a moment of geopolitical anxiety: rapid AI acceleration, Trump’s return to the White House, and Europe’s fear of falling behind.
Economic pressure adds urgency. Mario Draghi warned Europe faces an “existential” competitiveness threat without major reforms.
GDPR compliance makes data costs roughly 20% higher than in the U.S.
Europe operates under around 100 tech laws enforced by more than 270 regulators.
Critics see a different trend: a deregulatory slide. AccessNow argues the package “destroys fundamental rights safeguards.” AI Act rapporteur Brando Benifei warns of a “race-to-the-bottom agenda,” rejecting the idea that Europe must choose between innovation and accountability.
Data & Privacy: More Freedom?
The Digital Omnibus introduces substantial changes to data, privacy, and cyber laws. It proposes to update the GDPR and merge the Data Governance Act (2022), the Open Data Directive (2019) and the Free Flow of Non‑Personal Data Regulation (2018) into the Data Act.
Narrower definition of “personal data”. An organisation could treat data as “personal” only if that organisation has reasonable means to reasonably identify the individual from the data. Businesses may decide that certain data they hold is non-personal, for example by pseudonymisation, allowing easier reuse or sharing of personal data.
Easier use of personal data to train AI. The reform allows the processing of personal data for the development and operation of AI systems under certain conditions. As a result, your usage data from services or platforms could be re-used to train AI models without needing separate explicit consent.
Reduced obligation to inform about processing. Companies would be able to decide not to issue certain notifications about how your data is processed if they reasonably believe you already know how it’s being used — unless the data is transferred to another party, used for automated decision-making, or crosses borders.
AI Act: Hold & Rethink?
The AI Act (adopted in 2024) was seen as a case-in-point of excessive red tape. It was drafted before AI entered the mainstream with ChatGPT nearly three years ago, and it’s widely acknowledged that the final rush to approve it before the end of the previous legislature left little room for recalibration.
Industry voices have long argued the AI Act is too fragmented and impossible to implement on schedule. Standardisation bodies have already missed deadlines twice, and countries including France, Germany, Sweden and Poland deem the 2025 timeline “unworkable.”
The proposed changes to the AI Act aim to give regulators more time to define standards and governance, soften some requirements, and tailor obligations to the size of companies.
Changing timelines Companies that develop or deploy AI systems that may pose a risk to people’s health, safety and fundamental rights (i.e. “high risk”) were expected to meet their compliance obligations by mid-2026 under EU AI Act. The Digital Omnibus proposes to delay that deadline, giving extra time for companies to adapt, for standards to land, and for regulators to develop tools and guidance.
Expanding of the EU AI Office’s authority. The Digital Omnibus assigns the AI Office exclusive supervisory and enforcement competence AI systems based on general-purpose models. The EU AI Office would also extend to AI systems integrated into major online platforms and search engines under the DSA.
Less compliance requirements for small and mid caps. The Digital Omnibus introduces lighter compliance penalties and possibly lighter obligations for companies with up to 750 employees and under €150 million annual turnover. They will still need to meet key obligations; lighter penalties do not mean no obligations.
What’s Next
The political fight now shifts to Parliament and Council.
Centre-right groups will stress competitiveness; Greens, S&D and parts of Renew warn of eroded rights and weaker enforcement.
Member States are split: Germany and France lead the pro‑delay bloc; the Netherlands wants clarity without a full pause.
Once positions are set, trilogues with the Commission start in spring 2026 to forge a single text. If Parliament invokes the urgent procedure, a vote could land in the first half of 2026. Otherwise adoption won’t happen before mid to late 2026.
In Case You Missed It
GOLDEN POWERSThe Commission has launched an infringement proceeding against Italy over its expansive “golden power” laws, which let Rome block or condition foreign and even domestic mergers on national security grounds.
The Commission argues these powers, recently used to restrict UniCredit’s bid for Banco BPM, breach EU principles of free movement and establishment by allowing arbitrary economic intervention.
Initially created in 2012 to protect strategic sectors like defense and energy, the rules have been repeatedly expanded, now covering banking. The Commission also warned the law encroaches on the ECB’s supervisory role.
Italy has two months to address the concerns or face a possible action before the European Court of Justice. Rome pledged to cooperate and revise the framework.
TECHNOLOGY SUMMITAt the Berlin summit on European digital sovereignty on 18 November, France and Germany called for simplifying EU digital regulations, protecting sensitive data, and supporting fair competition in strategic digital sectors.
In addition to pushing for simplification of the EU’s regulatory landscape, France and Germany threw their weight behind a push to make Europe less dependent on U.S. technology companies.
A “working group” will work on defining “digital sovereignty”. With Austria already calling for digital sovereignty to be defined in an “open manner”, it seems the semantic debate could follow the same lines as the much-commented concept of “(open) strategic autonomy.”
“The summit showcased greater France-Germany alignment on strengthening Europe’s digital ecosystem to avoid becoming a digital colony of the US or China”, CEO and Founder of French cloud company Upsun Frédéric Plais told us. “There is now broad recognition that subsidies alone won’t suffice, as Europe lacks the necessary resources. The key is focusing European public and private procurement on proven European digital solutions, of which there are many.”
LAGARDE SPEAKS“Europe’s vulnerabilities stem from having a growth model geared towards a world that is gradually disappearing”, ECB President Christine Lagarde said at a conference in Frankfurt on 21 November.
Lagarde highlighted Europe’s vulnerabilities: declining export-led growth, dependency on foreign resources, and sluggish productivity. Yet Lagarde underscored strengths in domestic resilience: robust labor markets, investment in digital, and countercyclical fiscal policy.
She called to harness the untapped potential of Europe’s single market through mutual recognition, easier decision-making, and simplified EU-wide business frameworks to shift from being resilient but vulnerable to truly strong.
What We’ve Been Reading
- In the FT, Barney Jopson laments that Spain lacks serious policy debate, as polarisation and identity politics have sucked the oxygen out of public discourse.