European Union - Digital Regulation Simplification (2025)

Digital Omnibus Package — Simplifying EU Digital Rules on AI, Cybersecurity, and Data

European Union

RAI-EU-NA-DOPSEXX-2025
Under Review(Under Review)
BillGovernance and OversightData Protection and PrivacyCybersecurity and Model Security
Export PDF

The European Commission's Digital Omnibus Package, announced on November 19, 2025, aims to simplify and streamline EU digital regulations on AI, cybersecurity, and data protection. The package reduces administrative burdens by at least 25% (35% for SMEs) by 2029, potentially saving businesses up to €5 billion in compliance costs while maintaining high protection standards.

Summary

On November 19, 2025, the European Commission unveiled a comprehensive Digital Omnibus Package designed to simplify Europe's digital regulatory framework across three critical areas: artificial intelligence, cybersecurity, and data protection. This seventh omnibus legislative proposal represents one of the most wide-ranging revisions of EU digital rules since the GDPR entered into force in 2018. The package introduces targeted amendments to the AI Act, GDPR, Data Act, and cybersecurity directives (NIS2, DORA, CER) with the goal of reducing administrative complexity while maintaining high standards of protection.

Key measures include simplifying high-risk AI system compliance by allowing companies up to 16 months to implement requirements once support tools and standards are available, introducing a single-entry point for cybersecurity incident reporting across multiple regulations, and clarifying data processing rules for AI model training. The Commission estimates these changes will reduce administrative burdens by a minimum of 25% overall and 35% for SMEs by the end of 2029, saving businesses up to €5 billion annually.

The package also introduces European Business Wallets to enable secure digital document signing and information exchange, potentially unlocking €150 billion in annual savings. A new Data Union Strategy expands access to high-quality datasets for AI development through data labs and support mechanisms. The proposals include targeted exemptions for SMEs from certain Data Act cloud-switching obligations and expanded exemptions for small mid-cap entities from AI Act requirements. After formal presentation, the package will proceed through the ordinary legislative procedure in the European Parliament and Council, where substantive amendments are expected before final adoption.

Full article

Read full text ↗

Overview

The Digital Omnibus Package, formally announced by the European Commission on November 19, 2025, represents a major competitiveness-driven simplification effort targeting Europe's digital regulatory framework. This seventh omnibus legislative proposal introduces comprehensive amendments to existing regulations on artificial intelligence, cybersecurity, and data protection with the explicit goal of reducing administrative burdens for businesses while maintaining the EU's high standards for fundamental rights and consumer protection. The initiative affects key digital legislation including the AI Act, GDPR, Data Act, and multiple cybersecurity directives including NIS2, DORA, and the Critical Entities Resilience Directive. The Commission estimates that these streamlining measures will reduce compliance costs by up to €5 billion by 2029, with administrative burden reductions of at least 25% overall and 35% specifically for small and medium-sized enterprises. The package also introduces European Business Wallets and a Data Union Strategy, which could unlock an additional €150 billion in annual savings through digitized business processes and improved data access for AI development.

Definitions

The Digital Omnibus Package does not introduce entirely new definitions but rather refines and clarifies existing terms across multiple legislative instruments. High-risk AI systems retain their AI Act definition but benefit from clarified compliance timelines tied to the availability of harmonized standards. Personal data breach reporting under GDPR is narrowed to focus on breaches posing "high risk to data subjects," creating a new threshold for mandatory reporting. Single-entry point is introduced as a unified platform for cybersecurity incident reporting across multiple regulatory frameworks (NIS2, DORA, GDPR, CER, and the EU Digital Identity Regulation). SMEs and small mid-cap entities receive expanded definitions for exemption purposes, particularly under the Data Act's cloud-switching provisions and the AI Act's compliance requirements. Legitimate interest grounds for data processing are expanded to explicitly include AI model training activities. Cookie consent fatigue is addressed through new exemptions for cookies used for aggregated audience measurement and security purposes. Data Union is introduced as a strategic framework to unlock access to high-quality datasets through data labs and expanded access tools for AI developers.

Governance and Institutional Framework

The Digital Omnibus establishes a more centralized and streamlined governance structure for digital regulation across the EU. The European AI Office will take on expanded oversight responsibilities for high-risk AI systems, providing centralized support tools, guidance, and standards that trigger compliance timelines. National Data Protection Authorities (DPAs) maintain their supervisory roles under GDPR but will operate through a new unified incident reporting platform that consolidates notifications across multiple legal frameworks. The ENISA (European Union Agency for Cybersecurity) will manage the single-entry point for cybersecurity incidents, serving as the technical backbone for coordinated reporting under NIS2, DORA, CER, and GDPR breach notification requirements. A new Data Act Legal Helpdesk will provide specialized guidance to SMEs navigating data sharing and cloud-switching obligations. The Commission establishes data labs as institutional mechanisms to facilitate secure access to high-quality datasets for AI training while ensuring trade secret protection and data sovereignty. Member States retain implementation authority for directives while benefiting from harmonized enforcement tools and standardized reporting interfaces that reduce fragmentation in cross-border digital operations.

Key Focus Areas

The Digital Omnibus Package focuses on four primary objectives: administrative burden reduction, legal clarity, SME support, and competitiveness enhancement. Administrative simplification targets compliance processes that have proven particularly burdensome, such as cybersecurity incident reporting across multiple overlapping frameworks and duplicative AI system documentation requirements. The package introduces a single-entry point that allows entities to fulfill reporting obligations under NIS2, DORA, GDPR, CER, and the EU Digital Identity Regulation through one interface, potentially cutting reporting effort in half for most organizations. AI Act amendments give companies up to 16 months to comply with high-risk system requirements once harmonized standards and Commission support tools are available, addressing concerns about premature compliance deadlines. GDPR modifications extend breach notification timelines from 72 to 96 hours and limit mandatory reporting to breaches posing high risk to data subjects, reducing notification volume while maintaining protection for serious incidents. Cookie consent requirements are modernized to exempt aggregated audience measurement and security-purpose cookies, addressing widespread "consent fatigue" that degrades user experience. The Data Act receives targeted amendments exempting SMEs and small mid-caps from cloud-switching obligations for contracts concluded before September 12, 2025, and for custom-made or ecosystem-specific services. AI literacy obligations shift from individual organizations to EU and national authorities, reducing training burdens. Personal data processing for AI model training receives explicit legitimate interest grounds, providing legal certainty for this critical use case. European Business Wallets enable fully digital, legally binding business interactions across borders, while the Data Union Strategy democratizes access to high-quality training data for AI developers through secure data labs and expanded access mechanisms.

Implementation Framework

The Digital Omnibus Package follows the ordinary legislative procedure, requiring approval by both the European Parliament and the Council of the EU before entering into force. Following the Commission's formal presentation on November 19, 2025, the proposals enter the co-decision process where substantive amendments are anticipated during parliamentary committee reviews and Council working group negotiations. Upon final adoption, regulations (such as amendments to the AI Act, GDPR, and Data Act) will apply directly in all Member States, while directive amendments (such as NIS2 modifications) will require transposition into national law within prescribed timeframes. The implementation timeline for specific provisions varies by measure: high-risk AI system compliance obligations trigger "up to 16 months" after the European AI Office publishes necessary harmonized standards and support tools, providing flexible implementation periods tied to practical readiness rather than fixed dates. The single-entry point for cybersecurity incident reporting will require technical platform development coordinated by ENISA before becoming operational, likely involving a phased rollout across Member States. GDPR amendments, once adopted, will apply immediately as changes to an existing regulation, though the 96-hour breach notification timeline will replace the current 72-hour requirement prospectively. Data Act exemptions for SMEs and small mid-caps apply retroactively to contracts concluded on or before September 12, 2025, providing legal certainty for existing commercial relationships. European Business Wallets will require implementing acts specifying technical standards, interoperability requirements, and security protocols before widespread deployment. The overall administrative burden reduction target of 25% (35% for SMEs) sets 2029 as the deadline for measuring impact, suggesting full implementation of all package elements by that date.

Monitoring and Evaluation

The Digital Omnibus Package incorporates multiple monitoring and evaluation mechanisms to track its effectiveness in reducing administrative burdens and improving legal clarity. The Commission commits to measuring administrative burden reduction against baseline compliance costs, targeting verifiable reductions of 25% overall and 35% for SMEs by the end of 2029. These metrics will be assessed through business surveys, compliance cost studies, and regulatory impact assessments conducted in coordination with Member States. The European AI Office will monitor uptake of harmonized standards and support tools for high-risk AI systems, tracking the lag between standard publication and the expiration of 16-month compliance windows to ensure companies have adequate implementation time. ENISA will evaluate the effectiveness of the single-entry point for cybersecurity incident reporting, measuring reductions in reporting time, error rates, and cross-border coordination delays compared to the previous fragmented system. National Data Protection Authorities will assess the impact of the narrowed GDPR breach notification threshold, analyzing whether the focus on "high risk" incidents improves resource allocation and response quality while maintaining adequate protection for data subjects. The Commission will track adoption rates of European Business Wallets, measuring transaction volumes, cross-border usage patterns, and estimated cost savings against the projected €150 billion annual benefit. Data Union Strategy success will be evaluated through metrics on dataset availability in data labs, AI developer participation rates, and the diversity of entities accessing shared data resources. Regular reporting requirements embedded in the amended regulations will generate compliance data for Commission reviews, while Member State implementation reports will track transposition progress and national-level enforcement patterns. The Commission may propose further amendments based on evaluation findings, maintaining the regulatory framework's adaptability to technological and market developments.

Penalties, Liability, and Appeals

The Digital Omnibus Package maintains the existing penalty frameworks of the underlying regulations it amends, without introducing new or modified sanction regimes. GDPR violations continue to carry administrative fines up to €20 million or 4% of total worldwide annual turnover (whichever is higher) for the most serious infringements, including failures to report high-risk personal data breaches through the new single-entry point platform. AI Act non-compliance remains subject to fines up to €35 million or 7% of total worldwide annual turnover for prohibited AI practices, and up to €15 million or 3% of turnover for violations of high-risk AI system obligations, even with the extended 16-month compliance windows. Data Act violations can result in penalties up to €20 million or 4% of annual turnover, though SMEs and small mid-caps benefit from exemptions that remove certain obligations entirely rather than reducing penalties. NIS2 Directive penalties, implemented through national law, typically range up to €10 million or 2% of total worldwide annual turnover, with Member States retaining discretion to set higher maximums. Appeals processes remain unchanged: parties subject to supervisory authority decisions under GDPR may seek judicial remedy in Member State courts, with ultimate recourse to the Court of Justice of the European Union (CJEU) on questions of EU law interpretation. AI Act enforcement decisions by national competent authorities or the European AI Office are similarly subject to judicial review in accordance with national administrative law and EU law principles. The single-entry point for incident reporting does not alter substantive penalty calculations but may affect procedural aspects of enforcement if a single notification satisfies obligations under multiple legal acts, potentially reducing instances of compounded penalties for reporting failures. Liability for harms caused by AI systems continues to follow the AI Act's liability framework and relevant national tort law, with the Digital Omnibus simplifications not affecting the underlying liability principles for AI-generated damages.

Relationship to Other Instruments

The Digital Omnibus Package amends and interacts with multiple existing EU legislative instruments, creating an interconnected framework for digital regulation. It directly amends the AI Act (Regulation 2024/1689) by extending compliance timelines for high-risk AI systems, expanding exemptions for small mid-caps, and transferring AI literacy obligations from organizations to authorities. It modifies the GDPR (Regulation 2016/679) by narrowing mandatory breach notification to high-risk incidents, extending reporting deadlines to 96 hours, inserting cookie consent exemptions for measurement and security purposes, and establishing legitimate interest grounds for AI training data processing. The Data Act (Regulation 2023/2854) receives targeted amendments creating exemptions from cloud-switching obligations for SMEs, small mid-caps, custom services, and pre-September 2025 contracts. The NIS2 Directive (Directive 2022/2555) is amended to establish the single-entry point for cybersecurity incident reporting, which also satisfies obligations under the DORA Regulation (Regulation 2022/2554), the Critical Entities Resilience Directive (Directive 2022/2557), and the EU Digital Identity Regulation. The package interacts with the ePrivacy Directive by moving certain cookie consent rules into the GDPR framework. It complements the Data Governance Act and Data Act by introducing the Data Union Strategy, which relies on existing data sharing frameworks while expanding access mechanisms through data labs. The European Business Wallets proposal builds on the eIDAS Regulation's trust services framework, extending digital signature and seal capabilities to business-to-business contexts. These amendments preserve the fundamental objectives and core obligations of each underlying instrument while streamlining implementation, reducing duplication, and improving cross-regulatory coherence.

International Alignment

The Digital Omnibus Package maintains the EU's position as a global standard-setter in digital regulation while addressing competitiveness concerns that have emerged from comparisons with other major jurisdictions. The streamlining measures respond to feedback from businesses operating across multiple regulatory regimes, particularly concerns that EU rules impose heavier compliance burdens than comparable frameworks in the United States, United Kingdom, or Asia-Pacific markets. By reducing administrative costs by up to €5 billion while maintaining substantive protections, the Commission aims to preserve the EU's high standards for fundamental rights, data protection, and AI safety while narrowing the compliance gap with less prescriptive international regimes. The AI Act amendments, particularly the extended compliance timelines and expanded SME exemptions, acknowledge criticism that the EU's risk-based approach imposes earlier and more detailed obligations than emerging frameworks like the U.S. AI Executive Order or the UK's pro-innovation approach. The single-entry point for cybersecurity incident reporting aligns with international best practices from jurisdictions that have consolidated reporting requirements, such as Australia's multi-sector Critical Infrastructure Centre. GDPR modifications introducing legitimate interest grounds for AI model training provide legal certainty comparable to the processing bases available under UK GDPR post-Brexit, addressing a competitive disadvantage for EU-based AI developers. The Data Union Strategy responds to calls for European data sovereignty while facilitating the cross-border data flows necessary for global AI competitiveness, balancing localization concerns with international research collaboration. European Business Wallets aim to create a digital business infrastructure competitive with commercial solutions from non-EU technology providers while ensuring interoperability and compliance with EU trust services standards. The package positions the EU as offering a "third way" in digital regulation: more protective than light-touch Anglo-American approaches, but more pragmatic and business-friendly than earlier iterations of EU digital rules. This positioning seeks to attract international investment while encouraging global adoption of EU-compatible standards through market influence rather than explicit extraterritorial application.

Implementation Timeline

EventDate/TimeframeDescription
Commission AnnouncementNovember 19, 2025Formal presentation of Digital Omnibus Package by the European Commission
Legislative Process BeginsNovember 2025 - ongoingOrdinary legislative procedure in European Parliament and Council, including committee reviews and working group negotiations
Expected Adoption2026 (estimated)Final approval by Parliament and Council after amendments and trilogue negotiations
Entry into Force20 days after publication in Official JournalRegulations apply directly; directives trigger Member State transposition deadlines
AI Act Compliance WindowUp to 16 months after standards publishedHigh-risk AI system compliance obligations begin after harmonized standards and support tools become available
Single-Entry Point OperationalTBD (post-adoption)ENISA develops and launches unified cybersecurity incident reporting platform
GDPR Amendments ApplicableImmediately upon entry into force96-hour breach notification timeline and high-risk threshold apply to new breaches
Data Act SME ExemptionsRetroactive to September 12, 2025Cloud-switching exemptions apply to contracts concluded on or before this date
European Business Wallets RolloutTBD (requires implementing acts)Technical standards and interoperability protocols must be specified before deployment
Administrative Burden Reduction TargetEnd of 2029Deadline for achieving 25% overall and 35% SME burden reduction measured against baseline

Sources and References

SourceType
European Commission Press Release IP/25/2718Primary Source
Commission News Article: Simpler Digital Rules to Help EU Businesses GrowPrimary Source
Digital Package FAQ - European CommissionPrimary Source
Digital Package Factsheet (FS/25/2719)Primary Source
European Business Wallets in a NutshellPrimary Source
Data Union in a NutshellPrimary Source
AI Act (Regulation 2024/1689)Legal Text
GDPR (Regulation 2016/679)Legal Text
Data Act (Regulation 2023/2854)Legal Text
NIS2 Directive (Directive 2022/2555)Legal Text
Bird & Bird: EU Digital Omnibus Package - Major Changes to the Data Act ProposedLegal Analysis
Gibson Dunn: EU Digital Omnibus Package – A First LookLegal Analysis
Addleshaw Goddard: EU Digital Omnibus Proposals to Reform Data and AI LawsLegal Analysis

Requirements for a company

What an organisation has to do under European Union - Digital Regulation Simplification (2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Under Review). These requirements apply once the instrument takes effect and may change before then.

Must do

7
  • Comply with AI Act requirements for high-risk systems.Providers of high-risk AI systems
  • Update breach notification procedures for GDPR high-risk incidents.All data controllers processing personal data
  • Transition to the single-entry point for cybersecurity incident reporting.Entities subject to NIS2, DORA, CER, and GDPR breach notification
  • Document legitimate interest assessments for AI model training data.Data controllers developing AI models
  • Verify eligibility for Data Act and AI Act exemptions.SMEs and small mid-cap entities
  • Implement or apply exemptions for Data Act cloud-switching obligations.Cloud service providers
  • +1 more in the table below

Must not do

0

Nothing in this category.

Should do

2
  • Consider adopting European Business Wallets for digital interactions.All businesses operating in the EU
  • Explore Data Union Strategy resources for AI training data.AI developers seeking training data

Should not do

0

Nothing in this category.

Who must do what

The obligations under European Union - Digital Regulation Simplification (2025), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Providers of high-risk AI systemsComply with AI Act requirements for high-risk systems.
AI Act amendments give companies up to 16 months to comply with high-risk system requirements once harmonized standards and Commission support tools are available.
Up to 16 months after standards publishedCritical
2All data controllers processing personal dataUpdate breach notification procedures for GDPR high-risk incidents.
GDPR modifications extend breach notification timelines from 72 to 96 hours and limit mandatory reporting to breaches posing high risk to data subjects.
Immediately upon entry into forceCritical
3Entities subject to NIS2, DORA, CER, and GDPR breach notificationTransition to the single-entry point for cybersecurity incident reporting.
The package introduces a single-entry point to fulfill reporting obligations under NIS2, DORA, GDPR, CER, and EU Digital Identity Regulation.
TBD (post-adoption)Critical
4Data controllers developing AI modelsDocument legitimate interest assessments for AI model training data.
Personal data processing for AI model training receives explicit legitimate interest grounds, providing legal certainty for this critical use case.
Immediately upon entry into forceImportant
5SMEs and small mid-cap entitiesVerify eligibility for Data Act and AI Act exemptions.
SMEs and small mid-cap entities receive expanded definitions for exemption purposes under the Data Act's cloud-switching and AI Act's compliance requirements.
Before applying exemptionsImportant
6Cloud service providersImplement or apply exemptions for Data Act cloud-switching obligations.
The Data Act receives targeted amendments exempting SMEs and small mid-caps from cloud-switching obligations for contracts concluded before September 12, 2025.
OngoingImportant
7Website operators using cookiesApply cookie consent exemptions for aggregated audience measurement and security.
Cookie consent requirements are modernized to exempt aggregated audience measurement and security-purpose cookies, addressing widespread 'consent fatigue'.
Immediately upon entry into forceImportant
8All businesses operating in the EUConsider adopting European Business Wallets for digital interactions.
European Business Wallets enable fully digital, legally binding business interactions across borders.
TBD (requires implementing acts)Recommended
9AI developers seeking training dataExplore Data Union Strategy resources for AI training data.
The Data Union Strategy democratizes access to high-quality training data for AI developers through secure data labs.
Recommended

© Regulations.AI · updated on 13-Jun-2026