A reference for business leaders
Digital Omnibus
What changes and what matters.
Europe is revising its digital rulebook. Some AI rules have changed; wider changes to data, privacy and cybersecurity are still being negotiated. Understanding the distinction helps you decide what to act on, what to prepare for and what to watch.
For leaders across the UK and EU, and US companies operating in or selling into Europe. This reference provides the shared regulatory context for our advisory work.
Reviewed · Clive Struver, Silicon and Stone
One name. Two legislative tracks.
An omnibus amends several existing rules together. The Digital Omnibus is part of the EU’s effort to reduce administrative complexity and improve competitiveness. Its two tracks are moving at different speeds. Read the Commission’s overview.
Enacted
Digital Omnibus on AI
Regulation (EU) 2026/1744 entered into force on 27 July 2026. It amends the AI Act, including the timetable for high-risk systems. Entry into force and the date a particular duty applies are different milestones.
Under negotiation at this review
Data, privacy and cybersecurity
The broader proposal includes changes to GDPR, the Data Act and incident reporting. Parliament’s procedure is awaiting a committee decision. Proposed simplifications should not be treated as permissions already available.
Timeline and milestones
First, how the AI changes became law. Then, the main application dates to read against your systems and your role.
How we got here: November 2025 to July 2026
19 November 2025
Two proposals introduced
The Commission proposes changes to the AI Act and, in a separate legislative file, to data, privacy and cybersecurity rules. Source
7 May 2026
Political agreement on AI announced
Parliament and Council negotiators agree the AI changes. Political agreement precedes formal adoption and entry into force. Source
27 July 2026
AI Omnibus enters into force
Regulation (EU) 2026/1744 changes the AI Act. The broader Digital Omnibus remains a separate proposal. Source
2 August 2026
Article 50 transparency, GPAI enforcement, and penalties
These are in force now. The Omnibus did not move them.
Article 113, second paragraph · Official timeline
2 December 2026
New prohibitions, and machine-readable marking
Article 5(1)(ba) and (bb) — non-consensual intimate imagery and CSAM generation — begin to apply, together with the Article 5(1a) and (1b) qualifiers. Providers of systems generating synthetic audio, image, video, or text placed on the market before 2 August 2026 must comply with Article 50(2) by the same date.
Article 113, third paragraph, point (a); Article 111(4) · Official timeline
2 August 2027
National regulatory sandboxes operational
Article 57(1). Extended by the Omnibus from the original 2 August 2026 — this is a separate provision from the Annex III application date, and was not left unchanged.
Article 57(1) · Official timeline
2 December 2027
Standalone high-risk systems
Chapter III Sections 1–3 for AI systems classified as high-risk under Article 6(2) and Annex III, deferred by Regulation (EU) 2026/1744.
Article 113, third paragraph, point (c)(i) · Official timeline
2 August 2028
Embedded product-safety high-risk systems
Chapter III Sections 1–3 for AI systems classified as high-risk under Article 6(1) and Annex I, deferred by Regulation (EU) 2026/1744.
Article 113, third paragraph, point (c)(ii) · Official timeline
These are the main milestones, not a universal deadline for every AI system. Classification, operator role and transitional provisions matter. The December 2026 marking transition concerns certain systems placed on the market before 2 August 2026. Read the amending regulation.
The wider proposal: milestones still to come
Watch for Parliament’s position, the Council position, agreement on a final text, formal adoption and publication. There is no confirmed application date recorded here for the broader package. Check its current status.
More than a change of dates
AI: implementation and oversight
Alongside the high-risk timetable, the enacted changes address support for small mid-cap companies, testing and sandboxes, AI literacy, registration and AI Office supervision. A revised date is only one part of the assessment. Commission summary of the enacted changes.
Data and privacy: proposed simplification
The broader proposal would consolidate parts of the data framework into the Data Act, adjust aspects of cloud switching, and change elements of GDPR and cookie rules. These could affect data use, supplier contracts and portability; their final form remains unsettled. What the Commission proposes.
Cybersecurity: a proposed reporting entry point
A single entry point is proposed for overlapping incident reports under several EU laws. A simpler submission route would not itself remove the underlying reporting obligations. Incident-reporting proposal.
Where the debate matters
The European data protection authorities support some simplifications but object to the proposed narrowing of the definition of personal data. Treat disputed provisions as something to monitor, rather than an assumption on which to redesign your data practices. EDPB and EDPS assessment.
Read the rules against the business
A UK or US headquarters does not by itself settle EU exposure. Relevant connections include placing AI systems or models on the EU market, and certain uses of AI output in the EU. Establish your role and the scope before choosing a deadline. AI Act scope.
EU changes also need to be distinguished from the domestic requirements of the UK or US. The Omnibus does not replace that separate assessment.
Our practical interpretation
- You use AI across your organisation
- Start with a systems inventory, the purpose of each use and the evidence your vendors supply. Work out which transparency or high-risk questions actually arise.
- You supply software to European customers
- Distinguish your legal duties from the evidence a buyer needs to approve a purchase. A later application date may not change a customer’s current procurement requirements.
- You are choosing an architecture or cloud provider
- Map data flows, administrative access, key custody and exit options. Keep legal requirements, contractual commitments and strategic sovereignty preferences distinct; assess any wider sovereignty measures on their own basis.
How this informs our advisory work
This reference is available to everyone. In an engagement, we apply the relevant parts to your systems, evidence and decisions, within the scope we agree with you.
What does this mean for one decision?
Advisory Briefing
A focused interpretation of a regulatory change, a vendor claim or a question about your EU exposure.
Where are we exposed?
Exposure Diagnostic
Examine your systems, vendor evidence and dependencies. European Procurement Readiness is included where relevant to the agreed scope.
What should the board commit to?
Strategic Assessment
Translate requirements, procurement evidence gaps and regulatory uncertainty into investment priorities and an implementation roadmap. Where sovereignty is part of the decision, the scope extends to data flows, access, key custody and portability.
Sources and updates
The status above was reviewed on 9 September 2026. Source links let you check subsequent developments. The business examples are Silicon and Stone’s interpretation; the legislation and official procedures establish the legal position.
- European Commission: the two Digital Omnibus tracks
- European Commission: AI Omnibus enters into force
- EUR-Lex: Regulation (EU) 2026/1744
- European Commission: AI Act implementation timeline
- European Parliament: broader Digital Omnibus procedure
- European Commission: data, privacy and cybersecurity proposals
- EDPB and EDPS: support for simplification and concerns over privacy changes
- Council: political agreement on the AI Omnibus
- AI Act Service Desk: Article 2, scope
Review history
— Established the shared reference, separated enacted AI changes from the broader proposal, and checked the main application milestones against Commission guidance.