EU Digital Omnibus on AI (adopted 2026-06)
Status at the cutoff: Parliament adopted the agreed text during its June 2026 plenary and the Council gave its final approval on 29 June 2026. The measure is adopted; Official Journal publication and entry into force follow. It must no longer be described as a pending Commission proposal.
Summary
Section titled “Summary”The Digital Omnibus Package, released by the Commission on 2025-11-19, is a simplification package spanning several digital laws. Its core rationale is to respond to industry concerns about “excessive regulatory complexity” and “insufficient preparedness for AI Act application.”
The most consequential change fixes later application dates for high-risk-system duties while preserving the AI Act’s risk-based structure.
Triggering context
Section titled “Triggering context”By 2025-07-10 (the AI Act’s original deadline for member states to designate national competent authorities), only 3 of 27 member states had completed all designations (Lithuania, Luxembourg, Malta). Key countries (Germany, France, Italy, Spain, Austria) had not.
Consequences:
- AI Act cannot effectively apply in 2026-08 without national enforcement bodies
- Industry (especially SMEs) faces intense compliance-time pressure
- U.S. political pressure (the Trump administration opposes the Brussels Effect and pushes for delay)
Core proposals
Section titled “Core proposals”1. Delay of AI Act high-risk provisions
Section titled “1. Delay of AI Act high-risk provisions”Chapter III duties for Annex III standalone high-risk use cases move to 2027-12-02. Duties for high-risk AI embedded in regulated products move to 2028-08-02.
Affected provisions:
- Article 6 high-risk classification
- Articles 8-15 high-risk obligation matrix
- Articles 17-27 provider / deployer obligations
- Articles 40-49 conformity assessment and registration
Not delayed:
- Article 5 prohibited list (already applicable 2025-02-02)
- Article 50 transparency obligations (scheduled 2026-08-02)
- Articles 51-56 GPAI obligations (already applicable 2025-08-02)
- GPAI obligations already applicable from 2025-08 remain in place
2. Simplified compliance burden
Section titled “2. Simplified compliance burden”- Simplified documentation for high-risk impact assessments
- Reduced field count for EU database registration
- More optional paths for conformity assessment
3. SME support
Section titled “3. SME support”- National regulatory-sandbox deadline moves to 2027-08-02
- Compliance-cost subsidies
- Simplified templates
4. Minor adjustments to other Digital legislation
Section titled “4. Minor adjustments to other Digital legislation”- Data Act implementation details
- DSA VLOP designation threshold review
- Cyber Resilience Act transition period
4. Protections and institutional clarification
Section titled “4. Protections and institutional clarification”- Adds prohibitions addressing AI systems that generate non-consensual sexual or intimate content and AI-generated CSAM.
- Retains high-risk database registration where a provider claims its system is exempt from high-risk classification.
- Clarifies AI Office supervision where the same provider develops a GPAI model and a downstream system, while preserving defined national-authority competences.
- Sets 2026-12-02 as the revised implementation deadline for synthetic-content transparency solutions.
Legislative procedure
Section titled “Legislative procedure”| Stage | Timing (estimated) |
|---|---|
| Commission proposal | 2025-11-19 ✅ |
| Political agreement | 2026-05-07 ✅ |
| Parliament plenary adoption | 2026-06 ✅ |
| Council final approval | 2026-06-29 ✅ |
| Official Journal publication / entry into force | follows legal-linguistic finalisation |
Controversy
Section titled “Controversy”Supporters (industry + some member states)
Section titled “Supporters (industry + some member states)”- Industry associations such as DigitalEurope: welcome the simplification
- Germany, France, Spain, Austria (non-designation states): need more time
- Meta, Google, Microsoft: publicly supportive
- U.S. government: actively pushing (a Trump diplomatic priority after EO 14179)
Opponents (civil society + some MEPs + some member states)
Section titled “Opponents (civil society + some MEPs + some member states)”- EDRi, Algorithm Watch, Access Now and other civil society groups: view this as a retreat of the Brussels Effect
- Part of the European Parliament’s GPAI coalition: Mueller, Benifei, and others publicly critical
- Nordic states (Sweden, Denmark, Finland): skeptical of the delay
Practical impact on companies
Section titled “Practical impact on companies”At the 30 June 2026 cutoff: companies can plan against fixed dates rather than a conditional Commission proposal. GPAI duties remain applicable; article 50 transparency obligations still begin in August 2026, with the Omnibus transition for technical implementation running to 2 December 2026. Standalone high-risk duties move to 2 December 2027 and product-embedded duties to 2 August 2028.
Relationship with other jurisdictions
Section titled “Relationship with other jurisdictions”- U.S. Trump AI Action Plan + EO 14365: push for EU-U.S. “deregulatory alignment”
- China’s AI Safety Governance Framework 2.0 (2025-09): China chose self-initiated acceleration of systematizing governance — a contrast with EU deferral
- UK: continues to support the AI Safety Institute path, distinct from the EU delay
Text and archives
Section titled “Text and archives”| Source | Link |
|---|---|
| Commission official press release | digital-strategy.ec.europa.eu |
| Council final approval, 29 June 2026 | consilium.europa.eu |
| Digital Omnibus comprehensive analysis | IAPP, Covington, WilmerHale, and others |
| IIEA EU digital agenda 2025-2026 | iiea.com/blog/eu-digital-policy-2025-2026 |
Version history
Section titled “Version history”| Date | Event |
|---|---|
| 2025-11-19 | Commission released the proposal |
| 2026-05-07 | Parliament and Council negotiators reached political agreement |
| 2026-06 | Parliament adopted the agreed text in plenary |
| 2026-06-29 | Council gave final approval |