Member News, News

NautaDutilh | The Digital Omnibus: What Changed, What Survived and What Remains Open?

Following the publication of the “Digital Omnibus” on 19 November 2025, the political promise of easing regulatory burdens and moving towards simplification was initially welcomed by the market. However, nearly a year on, the effects have yet to be felt by stakeholders, and may be further contained now that both the European Parliament and the Council have taken positions on the text.

In an urgent drive to relaunch the European economy, ease the regulatory burden on businesses, and compete with global digital powers, the EU embarked on an ambitious overhaul of several areas of its regulatory framework in early 2025, spanning defence, energy, chemicals, agriculture and technology.

The Council is looking to adopt all these Omnibus texts before the end of 2026. The last area is covered by the Digital Omnibus, which contains two separate acts: AI on the one hand, and data regulation (including the GDPR) on the other.

An agreed compromise text on AI

A provisional agreement of the ‘simplification of the implementation of harmonised rules on artificial intelligence’ was reached by the Council, Parliament and the Commission on 22 June 2026. This followed a first trilogue session that broke down in April 2026.

Concretely, compared with the Commission’s initial draft, the original ‘stop the clock’ mechanism – designed to delay the full entry into force of the AI Act on 2 August 2027 (including for high-risk AI systems coming into effect on 2 August 2026) – was watered down. Instead of entering into force once harmonised standards were formally confirmed, the compromise text provides a delay until 2 December 2027 for Annex III systems (covering standalone high-risk AI systems in areas such as recruitment, credit worthiness and access to essential services) and until 2 August 2028 for Annex I systems (covering systems embedded in regulated products such as medical devices and radio equipment).

Providers of generative AI systems must mark synthetic (i.e., AI-generated) content in a machine-read able way (known as watermarking, in order to make AI-generated content easily identifiable). Rather than applying from 2 August 2026, the final compromise settles on a four-month delay (instead of the initial six), meaning compliance is required by 2 December 2026.

The co-legislators also inserted a new prohibition under Article 5, applicable from 2 December 2026, targeting AI systems that generate non-consensual intimate imagery (to tackle ‘revenge porn’) or child sexual abuse material. The prohibition extends beyond systems designed for such purposes to any system where such an outcome is reasonably foreseeable and reproducible without significant technical modification, and where the system lacks adequate safeguards.

On AI literacy, the European Commission had proposed removing the binding AI literacy obligation under Article 4 entirely, replacing it with soft encouragement from public authorities. The agreed text retains the obligation but softens it, requiring providers and deployers to support the development of AI literacy among their staff rather than guaranteeing a defined level of competence.

Beyond these targeted changes, the AI Act’s fundamental architecture, its risk-based classification, conformity assessment regime, and governance framework, remain entirely intact. It should be noted in particular that transparency obligations under Article 50 of the AI Act remain applicable from 2 August 2026 and are nog affected by this compromise text.

A controversial leaked position from the council on data regulation

Unlike the AI part of the Digital Omnibus, the data regulation part is moving at a slower pace given the impacts it will have on existing enforcement trends, particularly in relation to the GDPR. The Council has made its position known through a leaked document dated 18 June 2026, followed by a publication on 22 June 2026 of their intended amendments.

The text still retains the change on the definition of personal data but adds a safeguard: where pseudonymised data is passed to a third party who might be able to re-identify the individual, both the transfer and the subsequent processing are treated as processing of personal data. This is designed to prevent organisations from using pseudonymisation to sidestep the GDPR by passing data to another party.

The Council wishes to retain the narrow lawful basis for the processing of biometric personal data for the purposes of one-to-one authentication (rather than identification) where the data and verification means stay under the data subject’s control. The Council added a recital-level clarification that better delimits the permitted use case, a drafting detail absent from the November proposal. Controllers are also expected to prefer non-biometric methods where these are equally effective. The Council introduced a new provision to allow international transfers of personal data in the context of data exchanges for tax purposes (e.g., FACTA or similar schemes), at the request of ‘several delegations’.

The new Recital 40b explicitly covers periodic and automated data exchanges under international tax cooperation agreements, including international agreements on tax cooperation as a valid public interest ground, even where data are exchanged on a periodic or automated basis. This sits in direct tension with the consistent position of the EDPB and national DPAs that Article 49 derogations are exceptional and cannot support systematic or repetitive transfers, and is likely to be tested against the forthcoming CJEU ruling on such matters.

The European Commission’s original plan was to lift the rules on terminal equipment and cookies out of the ePrivacy Directive and embed them directly into the GDPR via new Articles 88a and 88b. The Council changed direction: those rules should instead be addressed through an amendment to the ePrivacy Directive. This has practical consequences for how sanctions apply and which authority has competence, while also watering down the ‘browser-level’ consent mechanism whereby cookie banners would be automatically rejected or accepted according to the user’s preferred browser settings.

The European Parliament’s position is still outstanding, and the trilogue meetings will then iron out the final text. Until then, existing rules remain fully in force and supervisory authorities retain every power they currently have.

Conclusion

The Digital Omnibus is Europe’s most ambitious effort to recalibrate its digital regulatory framework since the original wave of legislation began in 2016. The European Commission estimates that the Omnibus could save businesses up to EUR 5 billion in administrative costs by 2029, and public administrations a further EUR 1 billion. However, those figures depend on a final text that does not yet exist and will take time to translate into tangible benefits for the relevant stakeholders – in contrast with the market’s demand for speed and its concern that simplification will be eroded during the legislative process.

 

 

Compliments of NautaDutilh – a member of the EACCNY