The Digital Omnibus was presented as housekeeping: one package to simplify overlapping digital rules, reduce reporting burden and give industry a coherent rulebook. What it actually was, from the day it was tabled, is two very different pieces of law wearing one name — and they have been treated very differently ever since.

The AI half moved through the institutions in eight months, which for EU legislation is a sprint. The data half — which touches the GDPR, the ePrivacy Directive and the Data Act — has not cleared a single stage beyond being proposed. If you only remember one thing from this page: the deadline changes are law, and the GDPR changes are not.

DIGITAL OMNIBUS ON AICOM(2025) 836 · 2025/0359(COD)IN FORCEProposal19 NOV 25Council13 MAR 26ParliamentMAR 26Trilogue7 MAY 26Adopted29 JUN 26In force27 JUL 26DIGITAL OMNIBUS ON DATACOM(2025) 837 · 2025/0360(COD)STILL A PROPOSALProposal19 NOV 25CouncilVOTE PULLEDParliament1,750 AMDTSTrilogueAdoptedIn force
Fig. 1 — The same package, tabled the same day, at the same six stages of the ordinary legislative procedure. The AI file cleared all of them. The data file cleared one: its Council mandate vote was pulled when member states could not agree, and its Parliament committees are still working through the amendments.
In force

Digital Omnibus on AI

COM(2025) 836 · 2025/0359(COD)

Amends the AI Act. Postpones the high-risk regime, adds a prohibition, leaves the transparency tier alone, and hands the AI Office sharper supervisory teeth.

Adopted
29 Jun 2026
Published
24 Jul 2026
In force
27 Jul 2026
Now cited as
(EU) 2026/1744
Proposal

Digital Omnibus on data

COM(2025) 837 · 2025/0360(COD)

Would amend the GDPR, fold the ePrivacy cookie rules into it, and merge the Data Governance Act, the Open Data Directive and the free-flow regulation into a single Data Act. None of it applies.

Council mandate
Vote pulled
Committees
ITRE · LIBE
Amendments
1,750+
Trilogue
Not started

The half that is law

Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force three days later. Its headline effect is a deferral — but the deferral is much narrower than the coverage suggested, and what it left untouched matters more than what it moved.

20252026202720282029TODAYHELDuntouched by the omnibusProhibited practicesArt. 52 FEB 25AI literacyArt. 42 FEB 25General-purpose modelsCh. V2 AUG 25TransparencyArt. 502 AUG 26MOVEDthe whole point of the fileHigh-risk, standaloneAnnex III2 AUG 262 DEC 27High-risk, embeddedAnnex I2 AUG 272 AUG 28NEWadded in trilogueIntimate-image & CSAM banArt. 52 DEC 26
Fig. 2 — Every AI Act commencement date, and the two that moved. Hollow marks the date that was vacated; the dashed run is the distance the deadline travelled. Four obligations did not move at all — and three of those four were already in force before the omnibus was even adopted.

What moved

Chapter III — the high-risk regime, and the most expensive part of the Act to comply with — slid by more than a year in each of its two flavours. Standalone high-risk systems under Annex III, the list that covers AI in employment, education, creditworthiness, critical infrastructure and law enforcement, went from 2 August 2026 to 2 December 2027. High-risk systems embedded in products already regulated under EU product-safety law — medical devices, machinery, toys — went from 2 August 2027 to 2 August 2028.

The mechanism is worth noting, because it changed during negotiation. The Commission had proposed tying the start to readiness — the obligations would bite once the supporting harmonised standards and guidance actually existed. The co-legislators replaced that with fixed calendar dates. A conditional trigger would have been more honest about the state of the standards; a fixed date is something a compliance programme can be planned against. The second consideration won.

What held

The prohibitions, AI literacy, the general-purpose model rules and — the one most often misread — the Article 50 transparency obligations were all left where they were. Transparency has applied since 2 August 2026.

“The AI Act has been delayed” is the sentence this package produced, and for the transparency tier it is simply false. If you ship anything that talks to a person or generates content, your date has already passed.

What was added

A deregulatory package ended up creating a new prohibition. Trilogue added AI systems designed to generate or manipulate non-consensual intimate imagery and child sexual abuse material to the Article 5 list of banned practices, applying from 2 December 2026. Prohibitions carry the Act's heaviest penalties, and this is the first addition to that list since the Act was written.

The same date carries a much quieter change: generative systems already on the market before 2 August 2026 were given a four-month grace period, to 2 December 2026, for the machine-readable marking of their output. That grace covers the marking obligation only. The duty to tell a person they are talking to a machine had no grace period at all.

The regulation also widened the European AI Office's supervisory reach over systems built on general-purpose models and those integrated into very large online platforms, with powers to investigate, compel information, inspect, accept commitments and fine — up to 5% of average daily turnover. Centralised enforcement was not what industry was lobbying for, and it arrived in the same instrument as the relief.

The half that is not

The data proposal is where the genuinely structural changes live, and it is stuck. The Council's vote on a negotiating mandate was cancelled when member states could not close the open issues; work carried over to the Irish Presidency. In Parliament the file sits jointly with ITRE and LIBE — Aura Salla for the former, Marina Kaljurand for the latter — which discussed the draft report on 13 July 2026 and drew more than 1,750 amendments by the deadline two days later. There has been no trilogue.

That number is the tell. Seventeen hundred amendments is not a file being refined; it is a file whose premise is contested. The Commission frames it as simplification. A substantial bloc in Parliament, the European Data Protection Board and most digital-rights organisations read it as the largest rollback of EU data protection since the GDPR was written. Both readings are about the same nine provisions.

Here is what is actually on the table. None of this is in force, and the GDPR as you know it applies unchanged.

  • Art. 4A narrower definition of personal data

    Data stops being personal for a given entity if that entity has no reasonably likely means to identify anyone — even where someone else could. Identifiability becomes relative to the holder rather than absolute.

  • Art. 9Sensitive data caught incidentally

    Special-category data that turns up unavoidably in a training set would no longer trigger the full prohibition, provided safeguards limit collection and protect anyone identifiable. A separate carve-out covers biometric verification under the user's own control.

  • Art. 12Requests made for other reasons

    Controllers could refuse or charge for access requests clearly not made for data-protection purposes — extending the existing mechanism for manifestly unfounded or excessive requests.

  • Art. 22Automated decisions under a contract

    Automated decision-making necessary to perform a contract becomes permissible without first establishing that human involvement would be impractical.

  • Art. 33Breach notification, loosened and centralised

    The threshold rises from a risk to a high risk, the clock goes from 72 to 96 hours, and one EU entry point replaces notifying each authority separately.

  • Art. 35One DPIA list instead of 27

    A single EU-wide list of processing requiring an impact assessment, drawn up by the EDPB and adopted by the Commission, replacing the national lists.

  • Art. 88aCookie rules move into the GDPR

    Terminal-equipment consent leaves the ePrivacy Directive and lands in the GDPR. Refusing everything must be as easy as accepting — one click — and a refused request may not be put again for the same purpose for at least six months. Strictly necessary functions, first-party audience measurement and security are exempt.

  • Art. 88bSignals a site has to honour

    Machine-readable preferences expressed once in a browser, operating system or wallet, which websites would be obliged to respect — the end of asking every visitor on every site. Media providers could offer an alternative, such as a subscription, before treating the signal as final.

  • Art. 88cLegitimate interest for AI training

    An explicit basis for processing personal data to develop, test, train and operate AI models, conditioned on enhanced transparency and an unconditional right to object. This is the single most contested provision in the package.

Beyond the GDPR itself, the proposal would merge the Data Governance Act, the Open Data Directive and the free-flow-of-non-personal-data regulation into a single Data Act, repeal the P2B Regulation, and make targeted amendments to NIS2 — including a single entry point for incident reporting, which is the one idea in the package that almost nobody opposes.

Even on an optimistic path this lands slowly. The proposed timings are staggered: the cookie provisions would apply roughly six months after entry into force, while the browser-signal obligation carries a runway of around four years. Nothing here is a 2026 compliance problem.

What to actually do about it

Stripping out the noise, the package leaves three practical positions — and they are quite different from each other.

  • If you ship a chatbot, an assistant or anything generative: your obligation is live now. Article 50 has applied since 2 August 2026 and was not postponed. Disclose the AI interaction, and treat the machine-readable marking of generated output as a current requirement rather than a future one.
  • If you are building toward the high-risk regime: you have been handed roughly sixteen months, not a reprieve. The requirements are unchanged; only the date moved. December 2027 is the date to plan against, and the harmonised standards the deferral was meant to buy time for still have to arrive.
  • If you were waiting on the GDPR changes: stop waiting. Do not soften a consent flow, a breach process or a retention schedule on the strength of a proposal that has not cleared a single institution. If the cookie provisions survive in something like their current form they will be a welcome simplification — and that is a 2028 conversation at the earliest.

The uncomfortable summary is that the simplification package delivered its relief to the systems that pose the most risk and left the duties on everyday consumer-facing AI exactly where they were. Whether that is the right trade is a genuine argument. Whether it happened is not.

The other half of thisWhat this site itself has to comply withThe obligation ledger for the AI running here — what is met, what is partial, and what is deliberately not claimed.
Sources