US companies have spent two years treating EU digital compliance as a set of fixed dates to race toward. The AI Act's high-risk obligations were coming in August 2026, the GDPR was a settled constraint, the Data Act had just begun to apply, and the cybersecurity regimes were stacking new reporting duties on top of one another. The European Commission's Digital Omnibus, proposed on 19 November 2025, resets that board.1Proposal for a Regulation as regards simplification of the digital legislative framework, COM(2025) 837 final (19 Nov 2025), and the accompanying Digital Omnibus on AI, COM(2025) 836 final. It is presented as simplification, with the Commission estimating at least EUR 5 billion in combined recurring and one-off savings by 2029 and, among the individual measures, more than EUR 800 million a year from modernizing the cookie rules.2Digital Omnibus (n 1), explanatory memorandum, for the EUR 5 billion and EUR 1 billion figures; European Commission "Digital Package" FAQ and press release IP/25/2718 (19 Nov 2025) for the cookie figure and the "up to EUR 5 billion" framing; all are the Commission's own estimates, non-binding. For a US planning team, the reset is real, but it is not uniform, and the shape of the risk is that the two halves of the package are at very different stages of becoming law.
The instinct to bank the whole package as relief, and to slow compliance spending across the board, is where the exposure sits. One half of the Omnibus is now adopted and its dates are fixed. The other half is a proposal that the co-legislators have not agreed and that the EU's data-protection bodies have asked to be reined in. A company that redesigns its AI-training legal basis or its consent banners around the proposed text is building to a draft that may narrow before it lands, if it lands at all.
1. Two Omnibuses, Two Speeds
The Digital Omnibus is not one instrument but two proposals published together. The first, the Digital Omnibus on AI, keeps to the AI rulebook, amending the AI Act together with the aviation Basic Regulation and, in the text as adopted, the Machinery Regulation as well.3Regulation (EU) 2024/1689 (AI Act) [2024] OJ L 2024/1689, Art. 6, Annex I, Annex III, Art. 50, Art. 113 (staggered application dates). The second, the broader Digital Omnibus Regulation, reaches across the GDPR, the ePrivacy Directive, the Data Act, and the cybersecurity and data-governance instruments in a single amending act. Reading them as one package is the first mistake, because their legislative fortunes diverged almost immediately.
The AI track moved with unusual speed. The Parliament and the Council fixed their negotiating mandates, a provisional agreement was reached on 7 May 2026, the Parliament approved the text on 16 June 2026, and the Council adopted it on 29 June 2026, concluding the legislative procedure. The amending regulation enters into force on the third day after its publication in the Official Journal, an urgency clause carried from the Commission's original proposal so that the rewritten timetable is in place before the AI Act's general application date. At that point the AI Act's own timetable is formally displaced. That track is, for practical purposes, settled law, and its dates are fixed.
The AI half of the Omnibus is adopted; its dates are fixed. The data-protection and cybersecurity half is still a Commission proposal in committee, unagreed by the co-legislators. Planning that treats the two as equally certain inverts the actual risk.
The broader Regulation is on a different clock. As of 30 June 2026 it remains in the parliamentary committee stage, with no committee report adopted and no Council general approach or plenary vote recorded. Its most consequential elements, the ones that would change what counts as personal data and how AI models may be trained, are precisely those that the European Data Protection Board and the European Data Protection Supervisor flagged in a joint opinion as going beyond a technical amendment.4EDPB-EDPS Joint Opinion 2/2026 on the Digital Omnibus (10 Feb 2026). A proposal carrying that kind of institutional resistance is not a safe foundation for a compliance redesign, and its timeline to adoption, if it is adopted in recognizable form, is open. The two speeds are the analytical key to the whole package: one part tells a company what the law now is, the other tells it only what the Commission would like the law to become.
2. The AI Act Deferral: A Moved Calendar and a Changed File
The headline of the adopted AI track is time. The AI Act's obligations for high-risk systems, which were to apply from August 2026 and August 2027, are pushed back. Standalone high-risk systems listed in Annex III, the category that captures uses such as employment, biometrics, and critical infrastructure, now apply from 2 December 2027. High-risk systems that are safety components of products regulated under the Union harmonization legislation listed in Annex I, which is where medical devices and in vitro diagnostics sit, apply from 2 August 2028. The stated rationale is that the harmonized standards and support tools on which conformity depends are not yet in place, an echo of the pattern that has dogged other new-approach regimes.
For life-sciences companies the classification detail is the part that matters. An AI-enabled medical device or diagnostic does not sit in the Annex III bucket that most general commentary focuses on. Where the AI system is itself, or is a safety component of, a device regulated under the Medical Device Regulation or the In Vitro Diagnostic Regulation, and that device must undergo notified-body conformity assessment, the AI system is high-risk under Art. 6(1) AI Act and takes the later 2 August 2028 date; a self-certified lower-class device with an AI feature is not high-risk on this route at all.5Under Art. 6(1) AI Act, an AI system that is itself, or is a safety component of, an MDR (EU) 2017/745 or IVDR (EU) 2017/746 device is high-risk only where the device needs third-party (notified-body) assessment; such systems take the Annex I date of 2 Aug 2028. The adopted Digital Omnibus on AI narrows that gateway (Art. 3(14), Art. 6(1a) to (1c) AI Act) and adds a power to limit Art. 9 to Art. 15 and Art. 17 to Art. 25 AI Act where the Section A Annex I legislation already protects equivalently and the limitation would not reduce the AI Act's overall level of protection (Art. 2(13) AI Act). The adopted text also narrows the gateway itself, providing that an AI system used solely for non-safety-related aspects such as performance optimization or quality control does not qualify as a safety component unless its failure or malfunction would endanger health and safety, and tying the definition of a safety component to the component's intended purpose. Where a given diagnostic feature falls on that line is a question the new wording poses rather than answers. The later date is genuine additional runway for the dual MDR-and-AI Act conformity problem that a connected diagnostic already faces, a problem examined in the compliance cliffs confronting AI in pharmaceutical research and development. The runway is real, and the file that must land on it is not quite the file that was there before. The risk-management system, the training-data governance, the technical documentation, and the conformity assessment all survive, but the adopted text also empowers the Commission, by delegated act due in August 2027, to limit the AI Act's own requirements for products covered by the Section A Annex I legislation where that legislation already provides equivalent or higher protection and the limitation would not reduce the overall level of protection the AI Act provides, and it extends to small mid-cap companies the simplified Annex IV technical-documentation form that notified bodies must accept, a route small and medium enterprises already had, while naming both categories in the requirement that the quality-management system be scaled to the size of the provider's organization, which the Act already imposed on every provider and which the notified body still assesses. Whether a given device is reached by either turns on delegated acts that do not yet exist and on a size classification the AI Act has only just acquired.
Reading the deferral as a reprieve is the trap. A US firm that stood down its AI Act readiness program when the calendar slipped will find, at the new date, that the same body of work is due, now compressed against standards that arrive late and notified-body capacity that is still forming. For a provider outside the new small-enterprise and small mid-cap brackets, the amendment defers when the demonstration is required rather than reducing what must be demonstrated, and it fixes that timing to a date rather than to the actual availability of the standards, so a late standard does not buy a later deadline. The deferral also touches only the high-risk timetable: the prohibited-practice bans in force since February 2025 and the general-purpose-AI model obligations in force since August 2025 are unchanged by it.
Several changes on the AI track are not deferrals at all, and a planner who watches only the dates will miss them. The transparency duties for AI-generated and manipulated content under Art. 50 AI Act proceed on their original footing, applying from 2 August 2026 with only a four-month window, to 2 December 2026, for providers whose generative systems were already on the market to bring the machine-readable marking into line, so the duty to disclose synthetic media still arrives on its original schedule. A new prohibition targeting AI-generated non-consensual intimate imagery and child sexual abuse material was added to the Act's list of prohibited practices, with its own near-term transition. Registration obligations for certain non-high-risk systems are eased, small and medium enterprises gain quality-management-system flexibilities that were previously confined to micro-enterprises, and the AI Office is given a more central supervisory role over general-purpose-AI-based systems. A new provision allows the processing of special-category data to detect and correct bias outside the high-risk provider case, reaching providers and deployers of other AI systems and models as well as deployers of high-risk systems, on the conditions that already governed the provider derogation, a change that lowers a threshold rather than raising one. The net effect is a genuine re-shaping of the AI compliance calendar, not a wholesale retreat, and the items that did not move are as important to a plan as the ones that did.6Digital Omnibus on AI (n 1), as adopted: Art. 50 AI Act transparency retained, a new prohibited practice added to Art. 5 AI Act, plus the registration, SME quality-management, AI Office supervision, and bias-detection amendments.
3. The GDPR and ePrivacy Reset That Has Not Landed
The changes a US data or AI business would most want are on the slower track, and that is exactly why they should not yet be planned around. The Digital Omnibus Regulation proposes to write a contextual, relative test of identifiability into the GDPR's definition of personal data, so that information is not personal in the hands of an entity that lacks the means reasonably likely to be used to identify the individual.7Regulation (EU) 2016/679 (GDPR) [2016] OJ L119/1, Art. 4(1) (personal data), Art. 6(1)(f) (legitimate interests), Art. 9 (special categories), Art. 12(5) (manifestly unfounded or excessive requests), Art. 15 (access), Art. 33 (breach notification). The Commission presents this as a codification of the Court of Justice's ruling in the Single Resolution Board case, but the ruling is narrower than that framing suggests. The Court accepted that pseudonymized data are not personal data in all cases and for every person, and that the perspective from which identifiability is assessed turns on the circumstances of each processing operation. It then held that, for a controller's own duty to inform the data subject, identifiability falls to be assessed at the moment of collection and from the controller's position rather than the recipient's, and it set aside the General Court judgment that had reasoned the other way.8Case C-413/23 P European Data Protection Supervisor v Single Resolution Board, judgment of 4 September 2025, ECLI:EU:C:2025:645, decided under Regulation (EU) 2018/1725; the Court of Justice set aside the General Court judgment in Case T-557/20 and referred that case back. For a US company that processes large volumes of pseudonymized or telemetry data, a codified relative test would be valuable, and the same proposal adds a legitimate-interest footing for AI model training and a conditional derogation permitting some special-category data to be processed in AI development.
The difficulty is that these are the provisions least likely to survive intact. In their joint opinion, the EDPB and EDPS warned that the personal-data changes go beyond the Court's own reasoning and would significantly narrow the concept of personal data, and they objected to letting the Commission decide by implementing act what ceases to be personal data after pseudonymization. The Board's chair framed the point as a limit rather than a detail, cautioning that simplification cannot come at the expense of fundamental rights and that the changes risk significantly weakening individual protection.9EDPB-EDPS Joint Opinion 2/2026 (n 4); see also the accompanying EDPB statement by its Chair, Anu Talus (11 February 2026). When the Union's two data-protection bodies describe a proposal as lowering the level of protection, the co-legislators have both the political cover and the legal argument to narrow it, and the text that emerges from trilogue may look materially different from the one on the table now.
The cookie and ePrivacy elements sit in the same posture. The proposal would move the rule governing access to information on a user's device out of the ePrivacy Directive and into the GDPR so far as personal data are processed, leaving Art. 5(3) of the Directive to govern the residue, and would create consent exceptions for low-risk purposes such as aggregate statistics and security, alongside a duty to respect machine-readable preferences expressed through browser settings.10Directive 2002/58/EC (ePrivacy Directive) [2002] OJ L201/37, Art. 5(3) (storing or accessing information on terminal equipment); the Digital Omnibus would relocate and recast this rule within the GDPR framework so far as personal data are concerned. A US business drowning in consent-banner engineering has every reason to want this. But the reform is unadopted, and consent under the ePrivacy Directive as transposed by each Member State remains the law that binds as of 30 June 2026. Rebuilding a consent architecture around the proposed exceptions now would commit engineering to a rule the co-legislators have not enacted. The proposal also raises the personal-data breach notification window from 72 to 96 hours and raises the reporting threshold, and it would let a controller refuse a data-subject access request that amounts to an abuse of the right, but each of these, too, is a proposed change to be watched, not a rule to be relied on.
4. One Incident Portal and a Trimmed Data Act
The part of the slower track with the clearest operational appeal for a US in-house team is the consolidation of cybersecurity reporting. A single security incident can trigger overlapping notification duties: a personal-data breach notification under the GDPR, an incident report under the NIS2 Directive, an ICT-incident report under the Digital Operational Resilience Act for financial-sector entities, and, for critical entities, a further track under the Critical Entities Resilience Directive.11Directive (EU) 2022/2555 (NIS2) [2022] OJ L333/80; Regulation (EU) 2022/2554 (DORA) [2022] OJ L333/1; Directive (EU) 2022/2557 (CER) [2022] OJ L333/164. The Digital Omnibus proposes a single reporting entry point, operated by the European Union Agency for Cybersecurity, so that one submission can feed the several regimes rather than obliging separate, differently timed filings. For a company that has watched a single event propagate across incompatible reporting calendars the appeal is obvious.
The appeal, again, is not the same thing as the law. The single entry point is part of the broader Regulation and shares its uncertain timeline, so the several reporting playbooks a company maintains cannot yet be retired. Building an incident-response process around a consolidated portal that does not yet exist would leave a gap on the day an actual incident triggers the duties that are in force now.
The Data Act elements are more incremental but point the same way. The proposal would remove the much-criticized essential requirements imposed on smart contracts that execute data-sharing agreements, exempt certain bespoke data-processing services under contracts concluded on or before 12 September 2025 from the switching obligations, and extend the simplified regime beyond small and medium enterprises to small mid-cap companies below a raised size threshold. It would also fold the Data Governance Act, the Free Flow of Non-Personal Data Regulation, and the Open Data Directive into a consolidated Data Act, and repeal the Platform-to-Business Regulation outright as largely superseded.12Regulation (EU) 2023/2854 (Data Act) [2023] OJ L 2023/2854, applicable from 12 Sep 2025; the Digital Omnibus would amend it and consolidate several adjacent data instruments into it. For US cloud and connected-device businesses this trims the edges of a regime whose core obligations remain in force in the meantime. The consolidation is architecture, and it may simplify the map considerably, but the map it would replace is the one that governs until the Regulation is adopted.
5. Strategic Considerations
The questions the Omnibus forces are not the ones its simplification framing invites. The first is which half of the package a given decision depends on. A plan that turns on the AI Act deadlines can be re-sequenced now against the 2 December 2027 and 2 August 2028 dates, with the life-sciences classification detail that puts AI-enabled devices on the later date rather than the earlier one. A plan that turns on the definition of personal data, the legal basis for training a model, the treatment of special-category data in AI development, or the shape of consent management depends on a proposal that is unagreed and actively contested, and the law that binds in the meantime is the one that proposal would replace.
The second is the cost of building to a draft. Redesigning a data architecture, a consent flow, or an incident-response process around the proposed text carries a rework risk if the co-legislators narrow it, and the EDPB and EDPS opinion signals that narrowing is a live possibility for the provisions US businesses value most.
The third is the interaction with sectoral law that the Omnibus does not touch. The AI Act deferral does not move the Medical Device Regulation, so a connected diagnostic still answers to its device timeline even as its AI obligations shift, and the adopted AI text's mechanisms for running the AI Act and sectoral conformity assessments as a single exercise change how they interlock rather than removing either. The fourth is the feedback into US governance. A deferred European deadline can quietly drop off a board-level risk register, and a proposed European relief can be over-weighted in planning; the first misreading resurfaces as a scramble against a deadline that only moved rather than vanished; the second, as a redesign built on a text that never passed. Underlying all of these is the timing caveat that a fast-moving file demands: the AI track is settled, but the broader Regulation's content and calendar can still change, and a plan made against it should be revisited as it advances. These questions require analysis tied to a company's specific systems, products, and exposure.