EDPB-EDPS Joint Opinion on Digital Omnibus on AI
EDPB-EDPS Joint Opinion 1/2026 on the Proposal for a Regulation as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)
European Union
RAI-EU-NA-WATCHDO-2026The EDPB-EDPS Joint Opinion 1/2026 evaluates the EU's 'Digital Omnibus on AI' proposal, stressing that simplification must uphold data protection and fundamental rights.
Summary
The EDPB-EDPS Joint Opinion 1/2026 assesses the EU Commission's 'Digital Omnibus on AI' proposal, which aims to simplify AI Act implementation. It emphasizes that simplification must not compromise fundamental rights, especially data protection and privacy. The Opinion provides recommendations on sensitive data processing for bias detection, AI system registration, regulatory sandboxes, and governance, guiding co-legislators to integrate data protection into the evolving AI regulatory framework.
Full article
Read full text ↗Overview
The EDPB-EDPS Joint Opinion 1/2026, issued on January 20, 2026, provides a critical assessment and set of recommendations concerning the European Commission's Proposal for a Regulation on the simplification of the implementation of harmonised rules on artificial intelligence, commonly referred to as the 'Digital Omnibus on AI'. This Proposal aims to amend existing EU legislation, specifically Regulation (EU) 2024/1689 (the 'AI Act') and Regulation (EU) 2018/1139, with the stated objective of streamlining and simplifying the application of AI-related rules across the European Union. The Joint Opinion underscores the commitment of both the European Data Protection Board and the European Data Protection Supervisor to ensuring that any simplification efforts do not inadvertently compromise fundamental rights, particularly the right to data protection and privacy, which are cornerstones of the EU's digital regulatory framework.
The core of the Joint Opinion revolves around balancing regulatory efficiency with robust safeguards for individuals. It acknowledges the legitimate goal of easing administrative burdens for operators in the AI ecosystem but firmly asserts that such simplification must not come at the expense of transparency, accountability, and the effective protection of personal data. The EDPB and EDPS scrutinize various proposed amendments, offering detailed insights and suggesting modifications to ensure alignment with the General Data Protection Regulation (GDPR) and other relevant data protection instruments. Their recommendations touch upon crucial aspects such as the processing of sensitive personal data for bias detection, the registration of AI systems, the functioning of AI regulatory sandboxes, and the overall governance and supervisory architecture for AI within the EU. This Opinion serves as a vital guide for EU co-legislators as they deliberate on the final form of the Digital Omnibus on AI, aiming to embed data protection principles deeply into the evolving AI regulatory landscape.
Definitions
Within the context of the EDPB-EDPS Joint Opinion 1/2026, several key terms are implicitly or explicitly defined through their application and the recommendations provided. The 'Digital Omnibus on AI' refers to the European Commission's Proposal for a Regulation designed to simplify the implementation of harmonised rules on artificial intelligence. This 'Omnibus' is understood as a legislative package intended to amend existing regulations, primarily the 'AI Act' (Regulation (EU) 2024/1689), to address practical challenges in its application. The term 'AI Act' itself denotes Regulation (EU) 2024/1689, which establishes harmonised rules for the development, placing on the market, and use of artificial intelligence systems in the European Union.
The Opinion also frequently references 'special categories of personal data', drawing directly from Article 9 of the GDPR, which includes data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation. The processing of such data, especially for 'bias detection and correction' in AI systems, is a central point of discussion, with the Opinion emphasizing the need for 'strict necessity' and clear circumscription to prevent abuse. 'High-risk AI systems' are those identified under the AI Act as posing significant risks to fundamental rights and safety, and the Opinion differentiates recommendations based on this classification. Furthermore, 'providers' and 'deployers' refer to the entities responsible for developing and placing AI systems on the market or using them, respectively, with specific obligations pertaining to each role. The Opinion also clarifies the roles of 'Market Surveillance Authorities (MSAs)' and 'Fundamental Rights Authorities/Bodies (FRABs)' in the AI governance framework, highlighting the importance of their cooperation and the independence of 'Data Protection Authorities (DPAs)'.
Governance and Institutional Framework
The Joint Opinion extensively addresses the governance and institutional framework for AI within the European Union, particularly concerning the interplay between existing data protection authorities and new AI-specific bodies. It acknowledges the rationale behind a more centralized supervision by the proposed 'AI Office' for certain AI systems, such as general-purpose AI models or those integrated into very large online platforms. However, the EDPB and EDPS strongly recommend that the scope and exclusive competence of the AI Office must be clearly defined to avoid overlaps and ensure legal certainty. Crucially, they emphasize that national Data Protection Authorities (DPAs) must retain their ability to act and that there needs to be close coordination between the AI Office and DPAs to safeguard data protection principles effectively. This coordination is vital to ensure that the AI Office's activities respect the independence and powers of DPAs, which are enshrined in the EU's data protection framework.
Furthermore, the Opinion advocates for granting the EDPB an advisory role and observer status within the 'European Artificial Intelligence Board' (if established), underscoring the importance of integrating data protection expertise at the highest levels of AI governance. It also calls for further clarification regarding the division of oversight responsibilities between the EDPS and the AI Office, especially concerning AI systems used by EU institutions, to ensure consistent and effective supervision. The Opinion also supports streamlining cooperation between Fundamental Rights Authorities/Bodies (FRABs) and Market Surveillance Authorities (MSAs), recommending clarifications on the MSAs' role as administrative points of contact for requests to providers and deployers. This institutional clarity and robust cooperation are deemed essential for a coherent and rights-respecting implementation of the AI Act and the broader Digital Omnibus on AI, ensuring that fundamental rights are protected across the entire AI lifecycle.
Key Focus Areas
The EDPB-EDPS Joint Opinion 1/2026 highlights several critical areas of focus where the proposed Digital Omnibus on AI interacts significantly with data protection and fundamental rights. A primary concern is the processing of 'special categories of personal data' for the purpose of 'bias detection and correction' in AI systems. While supporting the principle of addressing bias, the Opinion insists that any extension of the legal basis for such processing must be strictly circumscribed and limited to cases where the risk of adverse effects caused by bias is sufficiently serious. For high-risk AI systems, the Opinion recommends maintaining the existing standard of 'strict necessity' for processing sensitive data, cautioning against any dilution of safeguards. This reflects a deep concern that broader allowances for processing sensitive data, even for a laudable goal like bias mitigation, could lead to potential abuses if not tightly controlled.
Another key focus area is the 'registration and documentation' requirements for AI systems. The EDPB and EDPS strongly oppose any proposal to remove the obligation for providers to register AI systems in the EU database, particularly for non-high-risk AI systems. They argue that such a removal would significantly weaken transparency and accountability, making it harder for authorities and the public to oversee the deployment and impact of AI. The Opinion also addresses the introduction of 'AI regulatory sandboxes', which are welcomed as tools to foster innovation. However, it stipulates that Data Protection Authorities (DPAs) must have mandatory involvement in these sandboxes, with clear mechanisms for GDPR cooperation, to ensure that experimentation with AI does not compromise data protection principles. Furthermore, the Opinion stresses the importance of 'AI literacy' among providers and deployers, recommending that obligations for staff training and awareness be maintained, even if complementary responsibilities are assigned to EU institutions or Member States. These focus areas collectively underscore the EDPB and EDPS's commitment to embedding data protection by design and default into the evolving AI regulatory landscape.
Implementation Framework
The implementation framework for the Digital Omnibus on AI, as assessed by the EDPB-EDPS Joint Opinion, emphasizes the need for a coherent and coordinated approach that respects existing legal structures, particularly the GDPR. The Opinion stresses that any simplification measures introduced by the Omnibus must not create ambiguities or undermine the established roles and responsibilities of Data Protection Authorities (DPAs). It calls for clear guidance on how the new provisions will interact with the GDPR, especially concerning data processing activities within AI systems. The EDPB and EDPS are actively working on joint guidelines with the European Commission to clarify the interplay between the GDPR and the AI Act, indicating a proactive stance on ensuring a smooth and legally sound implementation. This collaborative effort aims to provide practical advice to both AI developers and deployers, as well as to supervisory authorities, on how to navigate the complex regulatory landscape.
A significant aspect of the proposed implementation framework concerns the operationalization of AI regulatory sandboxes. While supporting their introduction to facilitate responsible innovation, the Opinion highlights the necessity of mandatory DPA involvement to ensure that data protection safeguards are integrated from the outset. This includes establishing clear GDPR cooperation mechanisms within the sandboxes, ensuring that any personal data processing activities are compliant with data protection law. Furthermore, the Opinion addresses the need for robust 'cooperation and mutual assistance' between Market Surveillance Authorities (MSAs) and Fundamental Rights Authorities/Bodies (FRABs), particularly in cross-border cases. It recommends adding details to the Proposal to ensure that MSAs provide information requested by FRABs without undue delay, fostering a collaborative enforcement environment. The overall implementation framework, as envisioned by the EDPB and EDPS, seeks to create an ecosystem where innovation is encouraged, but not at the expense of fundamental rights and robust data protection.
Monitoring and Evaluation
The EDPB-EDPS Joint Opinion places significant emphasis on robust monitoring and evaluation mechanisms to ensure the effective and rights-compliant application of the Digital Omnibus on AI. The Opinion implicitly calls for continuous oversight of how the simplified rules impact the protection of personal data and fundamental rights in practice. This includes monitoring the effectiveness of safeguards implemented for the processing of special categories of personal data for bias detection and correction, ensuring that the 'strict necessity' standard is consistently applied and that potential abuses are prevented. The EDPB and EDPS's strong stance against removing the obligation to register AI systems in the EU database, even for non-high-risk systems, directly relates to monitoring. Such registration is viewed as a crucial tool for transparency and accountability, enabling authorities and the public to track the deployment of AI systems and assess their compliance and impact over time.
Furthermore, the Opinion's recommendations regarding the involvement of Data Protection Authorities (DPAs) in AI regulatory sandboxes are designed to facilitate ongoing monitoring and evaluation of innovative AI solutions. By ensuring mandatory DPA involvement and clear GDPR cooperation mechanisms, the Opinion aims to establish a framework where new AI technologies are assessed for their data protection implications from their experimental stages. This proactive monitoring allows for early identification of potential risks and the development of appropriate mitigation strategies. The call for clarifying the roles and responsibilities within the AI governance structure, including the AI Office, DPAs, MSAs, and FRABs, is also integral to effective monitoring and evaluation. A clear division of labor and robust cooperation mechanisms are essential for comprehensive oversight, allowing for the systematic assessment of the AI Act's implementation and its amendments, and enabling timely adjustments to the regulatory framework if necessary to uphold fundamental rights.
Penalties, Liability, and Appeals
While the EDPB-EDPS Joint Opinion 1/2026 primarily focuses on recommendations for the content of the Digital Omnibus on AI, it implicitly addresses aspects related to penalties, liability, and appeals through its emphasis on accountability, transparency, and the independence of supervisory authorities. By advocating for the maintenance of robust registration obligations for AI systems, the Opinion indirectly strengthens the basis for enforcement and the imposition of penalties. If AI systems are not registered, it becomes significantly harder to identify responsible parties in cases of non-compliance, thereby undermining the effectiveness of any penalty regime. Similarly, the insistence on clearly defined roles for the AI Office, Data Protection Authorities (DPAs), and other supervisory bodies is crucial for establishing clear lines of accountability, which is a prerequisite for assigning liability and ensuring effective redress mechanisms.
The Opinion's concerns about delaying the application of key rules for high-risk AI systems also touch upon the effectiveness of future enforcement and potential liability. Delays could create periods of reduced oversight, potentially leading to situations where harmful AI systems are deployed without adequate safeguards, making it more challenging to hold responsible parties accountable. Furthermore, the emphasis on ensuring that proposed changes do not affect the independence and powers of DPAs is directly relevant to appeals processes. Independent DPAs are vital for individuals to exercise their right to lodge a complaint and seek effective judicial remedy against decisions concerning their data protection rights. Any weakening of DPA independence could therefore impede individuals' access to justice and their ability to appeal adverse decisions related to AI systems. The Joint Opinion, by strengthening the foundational elements of transparency, accountability, and independent oversight, lays the groundwork for a robust system of penalties, liability, and appeals within the AI regulatory landscape.
Relationship to Other Instruments
The EDPB-EDPS Joint Opinion 1/2026 is fundamentally shaped by its relationship to other key European Union legal instruments, most notably the General Data Protection Regulation (GDPR) and the AI Act (Regulation (EU) 2024/1689). The Opinion serves as a critical bridge between the established data protection framework of the GDPR and the emerging regulatory landscape for artificial intelligence. It consistently evaluates the proposed amendments in the Digital Omnibus on AI through the lens of GDPR compliance, ensuring that any simplification measures or new provisions do not undermine the high standards of data protection already in place. For instance, the recommendations concerning the processing of special categories of personal data for bias detection are directly informed by Article 9 of the GDPR, which sets strict conditions for such processing. The Opinion explicitly recalls that the EDPB and the European Commission are working on joint guidelines to clarify the interplay between the GDPR and the AI Act, highlighting the ongoing effort to harmonize these critical regulations.
Beyond the GDPR and the AI Act, the Opinion also references Regulation (EU) 2018/1139, which is another piece of legislation that the Digital Omnibus on AI proposes to amend. This demonstrates the comprehensive approach taken by the EDPB and EDPS to assess the cumulative impact of the proposed changes across various relevant legal instruments. The emphasis on the independence and powers of Data Protection Authorities (DPAs) is rooted in their mandate under the GDPR and the Treaty on the Functioning of the European Union, ensuring that their oversight role is preserved and strengthened in the context of AI. Similarly, the call for cooperation between Market Surveillance Authorities (MSAs) and Fundamental Rights Authorities/Bodies (FRABs) reflects a broader commitment to upholding fundamental rights enshrined in the Charter of Fundamental Rights of the European Union. The Joint Opinion thus positions the Digital Omnibus on AI within a broader ecosystem of EU law, advocating for coherence, consistency, and the primacy of fundamental rights protection.
International Alignment
While the EDPB-EDPS Joint Opinion 1/2026 primarily focuses on the internal European Union regulatory framework, its recommendations inherently contribute to broader international alignment in AI governance and data protection. By advocating for robust data protection safeguards, transparency, and accountability within the EU's AI legislation, the Opinion helps to solidify the EU's position as a global leader in responsible AI development. The principles championed by the EDPB and EDPS, such as data protection by design, the need for strict necessity in processing sensitive data, and the importance of independent oversight, are increasingly recognized as best practices in international discussions on AI ethics and regulation. When the EU sets high standards for data protection and fundamental rights in AI, it often creates a 'Brussels effect,' influencing regulatory approaches in other jurisdictions that seek to engage with the EU market or emulate its regulatory frameworks.
The Opinion's emphasis on ensuring the independence of Data Protection Authorities (DPAs) and clarifying the roles of various supervisory bodies also contributes to international alignment by promoting good governance practices. Many international frameworks and conventions on data protection and human rights stress the importance of independent oversight bodies. By reinforcing these principles within the EU's AI regulatory architecture, the Joint Opinion indirectly supports the development of globally consistent and trustworthy AI ecosystems. Furthermore, as AI systems are often developed and deployed across borders, the EU's clear stance on issues like data quality, bias detection, and the rights of data subjects provides a benchmark for international partners. While the Opinion does not explicitly detail international cooperation mechanisms, its foundational principles are designed to create an AI environment that is compatible with global human rights and data protection standards, thereby fostering trust and facilitating cross-border collaboration in the responsible development and deployment of AI.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| European Commission issued Proposal for Digital Omnibus on AI | 2025-11-19 | Proposal for a Regulation amending Regulations (EU) 2024/1689 and (EU) 2018/1139. |
| Commission formally consulted EDPB and EDPS | 2025-11-25 | Consultation in accordance with Article 42(2) of Regulation (EU) 2018/1725. |
| EDPB-EDPS Joint Opinion 1/2026 Published | 2026-01-20 | Official publication of the Joint Opinion. |
| EU Co-legislators Deliberate on Proposal | Ongoing (post 2026-01-20) | The opinion informs legislative deliberations in the European Parliament and Member States. |
| Joint Guidelines on GDPR and AI Act issued | Later in 2026 | EDPB and European Commission working on these guidelines. |
Sources and References
| Source | Type |
|---|---|
| EDPB-EDPS Joint Opinion on the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) | European Data Protection Supervisor | official |
| Regulation (EU) 2024/1689 on Artificial Intelligence (AI Act) | official |
| Regulation (EU) 2016/679 (General Data Protection Regulation) | official |
| Regulation (EU) 2018/1139 on common rules in the field of civil aviation | official |
Requirements for a company
What an organisation has to do under EDPB-EDPS Joint Opinion on Digital Omnibus on AI, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
8- Preserve the independence and powers of Data Protection Authorities.EU co-legislators
- Avoid delaying the application of key rules for high-risk AI systems.EU co-legislators
- Ensure processing of sensitive personal data for bias detection is strictly necessary and clearly defined.Providers and deployers of AI systems
- Register AI systems in the EU database.Providers of AI systems (including non-high-risk)
- Ensure mandatory DPA involvement and clear GDPR cooperation mechanisms in AI regulatory sandboxes.Operators of AI regulatory sandboxes
- Clearly define the scope and exclusive competence of the AI Office.EU co-legislators
- +2 more in the table below
Must not do
0Nothing in this category.
Should do
2- Ensure staff involved with AI systems have sufficient AI literacy.Providers and deployers of AI systems
- Grant the EDPB an advisory role and observer status in the European Artificial Intelligence Board.EU co-legislators
Should not do
0Nothing in this category.
Who must do what
The obligations under EDPB-EDPS Joint Opinion on Digital Omnibus on AI, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | EU co-legislators | Preserve the independence and powers of Data Protection Authorities. “The emphasis on ensuring that proposed changes do not affect the independence and powers of DPAs is directly relevant to appeals processes.” | — | Penalties, Liability, and Appeals | Critical |
| 2 | EU co-legislators | Avoid delaying the application of key rules for high-risk AI systems. “The Opinion's concerns about delaying the application of key rules for high-risk AI systems also touch upon the effectiveness of future enforcement and potential liability.” | — | Penalties, Liability, and Appeals | Critical |
| 3 | Providers and deployers of AI systems | Ensure processing of sensitive personal data for bias detection is strictly necessary and clearly defined. “For high-risk AI systems, the Opinion recommends maintaining the existing standard of 'strict necessity' for processing sensitive data, cautioning against any dilution of safeguards.” | — | Key Focus Areas | Critical |
| 4 | Providers of AI systems (including non-high-risk) | Register AI systems in the EU database. “The EDPB and EDPS strongly oppose any proposal to remove the obligation for providers to register AI systems in the EU database, particularly for non-high-risk AI systems.” | Before placing on market | Key Focus Areas | Important |
| 5 | Operators of AI regulatory sandboxes | Ensure mandatory DPA involvement and clear GDPR cooperation mechanisms in AI regulatory sandboxes. “Data Protection Authorities (DPAs) must have mandatory involvement in these sandboxes, with clear mechanisms for GDPR cooperation...” | Before sandbox operation | Key Focus Areas | Important |
| 6 | EU co-legislators | Clearly define the scope and exclusive competence of the AI Office. “The EDPB and EDPS strongly recommend that the scope and exclusive competence of the AI Office must be clearly defined to avoid overlaps and ensure legal certainty.” | — | Governance and Institutional Framework | Important |
| 7 | Market Surveillance Authorities and EU co-legislators | Clarify MSAs' role as contact points and ensure timely information sharing with FRABs. “The Opinion also supports streamlining cooperation between Fundamental Rights Authorities/Bodies (FRABs) and Market Surveillance Authorities (MSAs), recommending clarifications on the MSAs' role as administrative points of contact...” | — | Governance and Institutional Framework | Important |
| 8 | EU co-legislators | Clarify oversight responsibilities between the EDPS and the AI Office for EU institutions' AI systems. “It also calls for further clarification regarding the division of oversight responsibilities between the EDPS and the AI Office, especially concerning AI systems used by EU institutions...” | — | Governance and Institutional Framework | Important |
| 9 | Providers and deployers of AI systems | Ensure staff involved with AI systems have sufficient AI literacy. “The Opinion stresses the importance of 'AI literacy' among providers and deployers, recommending that obligations for staff training and awareness be maintained...” | — | Key Focus Areas | Recommended |
| 10 | EU co-legislators | Grant the EDPB an advisory role and observer status in the European Artificial Intelligence Board. “Furthermore, the Opinion advocates for granting the EDPB an advisory role and observer status within the 'European Artificial Intelligence Board' (if established)...” | — | Governance and Institutional Framework | Recommended |
Related Regulations
Digital Omnibus Package — Simplifying EU Digital Rules on AI, Cybersecurity, and Data
European Union90% similar
Data Protection Commission Guidance on AI and Large Language Models
Ireland90% similar
AI Board Sixth Meeting - Implementation and Interoperability
European Union90% similar
European Commission Guidelines regarding prohibited AI practices (guidance on Article 5 prohibitions)
European Union88% similar
European Commission Guidelines regarding the definition of an 'AI system' (clarifying Article 3(1) of the AI Act)
European Union88% similar
© Regulations.AI — created on 26-Jan-2026 using Gemini 2.5 Flash · updated on 13-Jun-2026