The European Commission’s proposed Digital Omnibus Package marks one of the most significant recalibrations of EU digital regulation since GDPR came into force in 2018. Driven in part by the Draghi Report’s call to restore European competitiveness, the package proposes targeted amendments to the General Data Protection Regulation (GDPR), the ePrivacy Directive, and the EU AI Act — with the stated aim of reducing compliance costs by up to 20% for mid-market and SME operators. For board members, General Counsel, and CFOs, the window between proposed reform and 2026 enforcement is not a pause — it is a critical planning interval.
What the Digital Omnibus Package Actually Changes
The Commission’s proposals are substantive, not cosmetic. Key revisions include a narrowing of the definition of personal data, expanded permissions for the use of pseudonymized data in AI training, and a relaxation of rules governing automated decision-making under Article 22 of GDPR — a provision that has long constrained AI deployment in credit scoring, HR screening, and insurance underwriting.
On the AI Act side, the package proposes postponing certain compliance deadlines and, notably, scrapping mandatory technical documentation requirements for SMEs operating non-high-risk AI systems. This signals meaningful relief for mid-market firms that have struggled to resource the documentation and conformity assessment obligations originally envisaged under the Act.
However, executives should resist interpreting deregulation as deferred urgency. The core architecture of the AI Act — including mandatory governance frameworks, high-risk system classification, and human oversight obligations — remains intact. Systems deployed in employment decisions, credit allocation, and critical infrastructure continue to carry the full weight of Article 10’s data governance mandates, which require quality-controlled training datasets, bias monitoring, and documented traceability.
The GDPR–AI Act Convergence: An Integrated Compliance Imperative
One of the most consequential — and underappreciated — dimensions of the current regulatory landscape is the deepening convergence between GDPR data privacy obligations and AI Act compliance requirements. These are no longer parallel workstreams. They are operationally interdependent.
High-risk AI systems processing personal data must simultaneously satisfy GDPR’s data minimization principles, lawful basis requirements, and data subject rights, while also meeting the AI Act’s Article 10 standards for dataset quality and bias controls. The emergence of Europrivacy certification — which integrates GDPR data minimization with AI risk management and governance — offers a structured pathway for organizations seeking to demonstrate regulatory alignment across both frameworks.
For enterprise risk management functions, this convergence demands a unified compliance architecture rather than siloed legal and technology teams. Organizations in sectors such as financial services, energy, and healthcare — where AI deployment in high-risk contexts is accelerating — face the most acute exposure. Fines under the AI Act can reach 3% to 6% of global annual turnover, while GDPR penalties remain capped at 4%, creating a compounding liability profile for non-compliant enterprises.
Implications for Business: Governance, Classification, and 2026 Readiness
The 2026 enforcement timeline for the majority of AI Act obligations is not distant. Organizations that have not yet initiated formal AI governance programs face a compressed runway. Decision-makers should prioritize the following actions:
- AI system inventory and risk classification: Map all deployed and in-development AI systems against the AI Act’s risk tiers. Employment screening tools, credit decision engines, and fraud detection systems are likely to qualify as high-risk under Annex III and require full conformity assessments.
- Data governance alignment: Audit training datasets for quality, representativeness, and bias controls in line with Article 10 mandates. Ensure GDPR lawful basis documentation is consistent with AI Act traceability requirements.
- Governance structure: Establish or formalize AI oversight roles — whether a dedicated AI Officer or an expanded remit for the DPO — with board-level visibility and escalation protocols.
- Certification strategy: Evaluate Europrivacy or equivalent certification as a risk mitigation and trust-building instrument, particularly for organizations operating across multiple EU jurisdictions or engaging in cross-border data transfers.
- SME and supply chain exposure: Even where direct obligations are reduced, large enterprises must assess AI Act compliance across their vendor and technology supply chains, as third-party system providers remain subject to provider-level obligations.
Key Takeaway
The EU Digital Omnibus Package reflects a genuine political shift toward competitiveness-oriented regulation, but it does not alter the fundamental compliance obligations facing enterprises deploying AI in high-risk domains. The proposed reforms reduce administrative friction at the margins — they do not eliminate the structural requirements for governance, transparency, and accountability that define the EU’s approach to responsible AI. For CFOs and General Counsel, the strategic imperative is clear: use the current reform interval to build integrated GDPR and AI Act compliance frameworks that are robust enough to withstand enforcement, and agile enough to adapt as the legislative text is finalized. Organizations that treat 2026 readiness as a board-level priority today will be materially better positioned than those that wait for final regulatory text before acting.