On November 19, 2025, the European Commission announced a substantive package of regulatory revisions targeting two of the most consequential compliance frameworks affecting European and globally operating enterprises: the General Data Protection Regulation (GDPR) and the EU AI Act. The proposals, part of the broader Digital Omnibus initiative, are projected to generate up to €5 billion in compliance cost savings by 2029 — a signal that Brussels is recalibrating its approach to digital regulation without abandoning its underlying policy objectives.

For CFOs, General Counsel, and enterprise risk management leaders, this is not a moment to disengage. It is a moment to reassess timelines, restructure compliance programs, and identify where strategic advantage can be extracted from regulatory change.

Key Revisions: Delayed Timelines and Streamlined Obligations

The most operationally significant change is the delay of high-risk AI system obligations under the EU AI Act to August 2027, extended from the previously anticipated 2026 window. This affects organizations deploying AI in regulated domains such as credit scoring, recruitment, critical infrastructure, and healthcare — categories that carry the most demanding conformity assessment requirements.

Equally important, Article 5 prohibitions on unacceptable-risk AI systems have been fully enforceable since August 2, 2025, with penalties reaching €35 million or 7% of global annual turnover, whichever is higher. Boards should note that enforcement authority has been decentralized across Member State-designated authorities — many of which overlap with existing Data Protection Authorities (DPAs) — creating jurisdictional complexity for multi-market operators.

On the data privacy front, the Digital Omnibus proposals introduce a consolidated GDPR breach reporting mechanism with a unified 72–96 hour deadline and a single-entry point for notifications. Cookie consent frequency requirements are also being reduced, lowering friction for digital product teams while maintaining the spirit of user rights protection. These changes directly address implementation challenges that have disproportionately burdened mid-market firms operating across fragmented national enforcement regimes.

Enforcement Overlaps and Corporate Governance Implications

The intersection of AI Act supervision and GDPR enforcement creates a layered risk environment that demands coordinated corporate governance responses. Where an AI system processes personal data — which is the case for the majority of enterprise AI deployments — organizations face dual regulatory exposure: AI Act obligations administered by newly designated national authorities, and GDPR obligations enforced by DPAs, sometimes the same body.

The updated EU AI Act Compliance Checker (revised July 2025) provides refined guidance on obligations for high-risk system providers, deployers, and authorised representatives, including AI literacy requirements and fundamental rights impact assessments. For mid-market providers, this tool represents a practical starting point for gap analysis. For large enterprises, it should be integrated into existing enterprise risk management frameworks alongside AML controls, ESG reporting obligations, and third-party due diligence protocols.

General Counsel should also note the enhanced trade secret protections introduced under the Digital Omnibus package, which have direct relevance to AI model documentation, training data provenance, and intellectual property strategy in M&A contexts.

Implications for Business: Strategic Priorities Before 2027

The two-year window before high-risk AI obligations take full effect is not a compliance holiday — it is a structured opportunity. Decision-makers should prioritize the following:

  • AI system inventory and risk classification: Map all deployed and planned AI systems against the EU AI Act’s risk tiers. The 2027 deadline is closer than it appears when factoring in procurement cycles and vendor assessments.
  • Regulatory sandbox participation: Expanded sandboxes become operational from 2028, but engagement with national authorities should begin now to shape testing parameters and build regulatory relationships.
  • Unified breach response architecture: The consolidated GDPR reporting mechanism warrants a review of incident response protocols across legal, IT security, and communications functions.
  • Cross-framework compliance integration: Organizations subject to ESG reporting mandates, AML directives, and sector-specific AI rules (e.g., financial services under DORA) must ensure these frameworks are managed cohesively, not in silos.

Key Takeaway

The EU’s regulatory simplification agenda reflects a pragmatic adjustment — not a retreat. GDPR and AI Act compliance remain non-negotiable, but the revised timelines and consolidated mechanisms offer organizations a more navigable path to implementation. The firms that use this window to build robust, integrated compliance architectures will be better positioned not only to avoid enforcement risk, but to compete in markets where regulatory credibility is increasingly a differentiator. For boards and executive teams, the question is no longer whether to invest in compliance infrastructure — it is how to make that investment structurally durable.