On 8 July 2026, the Digital Omnibus Regulation on AI was adopted to simplify the Artificial Intelligence Act (“AI Act”) and ease the burden on companies in the EU, giving them more time to innovate and scale. The Commission hopes the simplifications will reduce bureaucracy and make existing rules more practical. Following sustained criticism of the AI Act’s original regulatory framework due to its scope and multitude of technical requirements, the Commission’s digital package – which includes its digital omnibus – seeks to streamline the regulation of artificial intelligence (“AI”), cybersecurity and data. As the Commission tacks towards innovation, the German legislature has followed suit with the new Act Implementing the Artificial Intelligence Act (Gesetz zur Durchführung der Verordnung über künstliche Intelligenz) and the Federal Testing Act (Bundeserprobungsgesetz).
Reasons for revising the AI Act
European digital law is becoming increasingly complex. A plethora of new rules, including those under the AI Act (Regulation (EU) 2024/1689), the Data Act (Regulation (EU) 2023/2854) and the Cyber Resilience Act (Regulation (EU) 2024/2847), mean companies now face an elaborate network of interrelated obligations that are not only linked in terms of content and timelines but also challenging to implement in practice.
The AI Act of 13 June 2024, which entered into force on 1 August 2024, creates a single market for trustworthy and human-centric AI within the EU. It aims to promote innovation and the use of AI while ensuring a high level of protection for health, safety and fundamental rights. The Act is to be implemented in stages, and it was originally envisaged that all provisions would apply by 2 August 2027 at the latest.
As per its AI Continent Action Plan and Apply AI Strategy, the European Commission is committed to a clear, practical and innovation-friendly implementation of the AI Act.
However, a public consultation revealed numerous issues that could hinder the timely implementation of certain key provisions of the Act, e.g. the designation or establishment of notifying authorities under Article 28(1) and the obligation under Article 4 (old version) to bring about AI literacy. Likewise, the deadlines for application of the rules set out in Article 113, letter (c) (old version) in connection with high-risk AI systems appeared overly ambitious.
Delays of this kind could significantly increase compliance costs for companies and public authorities and impede innovation processes.
Against this backdrop, the Commission presented a digital omnibus proposal on 19 November 2025 for a regulation to simplify EU digital legislation, including specific amendments to the AI Act to address the identified challenges. The European Commission is also prioritising issuing a series of guidelines aimed at optimising compliance with the Act. The digital omnibus joins the other omnibus packages proposed by the European Commission to streamline EU rules (e.g. the omnibus initiatives to simplify the CBAM Regulation and the EU Corporate Sustainability Due Diligence Directive as well as the omnibus package to boost defence readiness).
Revised implementation period for high-risk AI systems
The digital omnibus extends the implementation period for certain rules governing high-risk AI systems (Chapter III, Sections 1-3). The Commission believes that delays in important preparations – such as the establishment of harmonised standards, common specifications and national authorities – could lead to practical obstacles. Consequently, the new rules may not be implemented as scheduled and compliance costs could become unnecessarily high. The Commission has therefore concluded that the original date of application is no longer justified. By extending the corresponding deadlines, the Commission is giving companies the time they need to adapt to and complay with their obligations under the AI Act.
Letter (c) of Article 113 AI Act, which regulates the Act’s entry into force and application, has been revised. It now provides that the rules governing high-risk AI systems in Chapter III, Sections 1, 2 and 3 will apply as follows:
- for AI systems classified as high-risk systems under Article 6(2) and Annex III, from 2 December 2027;
- and for AI systems classified as high-risk systems under Article 6(1) and Annex I, from 2 August 2028.
Expansion of regulatory simplifications to small mid-cap enterprises (SMCs)
Companies that outgrow the definition of micro, small and medium-sized enterprises (“SMEs”) – known as small mid-caps (“SMCs”) – play a central role in the European Union’s economy. Their higher pace of growth and tendency to innovate and digitise to a greater extent mean that they face challenges similar to those of SMEs in terms of administrative burden. The Commission therefore saw a need to ensure proportionality and provide targeted support to SMCs.
To meet that need, the digital omnibus places particular emphasis on this group of companies (see Article 1(2), letter (g) AI Act). Furthermore, binding definitions of SMEs and SMCs have now been introduced in Article 3 AI Act.
The proposal also contains simplifications with regard to the technical documentation required under Article 11 AI Act. In future, SMEs and SMCs will be permitted to submit certain elements of technical documentation in a simplified manner, and the Commission will establish and provide a simplified technical documentation form for this. Concurrently, the competent EU authorities are to give special attention to SMEs and SMCs and ensure that monitoring activities and any penalties imposed remain proportionate (see the new Article 95(4), Article 99(1) and Article 99(6a) AI Act).
Changes relating to AI literacy
Article 4 AI Act already required all providers and deployers of AI systems to ensure the AI literacy of their staff. However, stakeholders’ experience showed that a one-size-fits-all solution does not work for all providers and deployers when it comes to promoting AI literacy and that it represents an additional compliance burden, particularly for smaller enterprises. AI literacy should nevertheless continue to be a strategic priority, regardless of regulatory obligations and potential sanctions.
The current vaguely worded obligation incumbent on enterprises to promote AI literacy has therefore been eased. Contrary to the Commission’s original proposal, providers and deployers continue to be obliged to take measures to support the development of their staff’s AI literacy, but are not required to guarantee a specific result. Accordingly, they are only required to take measures supporting their staff’s AI literacy to the extent possible.
The task of the Commission and the Member States will be to support and facilitate companies’ efforts by offering training or providing useful information, for example. Deployers of high-risk AI systems remain obligated to provide training themselves, however.
More flexibility for providers in post-market monitoring
The Commission no longer has the power previously afforded to it under Article 72(3) AI Act to adopt a harmonised template for a post-market monitoring plan, a move intended to give providers of high-risk AI systems increased flexibility in post-market monitoring and greater discretion to set up monitoring systems specifically tailored to their organisations. The Commission will publish guidance clarifying what providers need to do to comply with the new provisions.
Centralising supervision within the AI Office
The Commission’s AI Office has been given enhanced supervisory powers over general-purpose AI models. Except in certain special sectors, the AI Office now has exclusive supervisory competence. The Commission’s AI Office acts as the centre of AI expertise across the EU, promoting the development and implementation of AI solutions that benefit both society and the economy. The AI Office had already led the implementation of the AI Continent Action Plan and the Apply AI Strategy. To achieve the intended centralisation of supervision, Article 75 AI Act was fundamentally amended and the AI Office was granted the required authority.
The AI Office’s centralised position is reinforced by conferring on it the enforcement powers of a market surveillance authority (see the new Article 75a(1) AI Act). Exceptions to the AI Office’s exclusive competence apply to certain sectors requiring special supervision by national authorities, particularly in relation to AI systems intended to be used as safety components in critical infrastructure or to assist in the administration of justice in the Member State concerned.
The aim of the amendment is to ensure that companies only have to deal with a single regulator, rather than multiple national authorities. This centralised approach will enable the development of specialised expertise in AI systems within the Commission and ultimately alleviate the burden on national authorities. At the same time, it will also avoid diverging national enforcement actions and create legal certainty for deployers.
Facilitating compliance with data protection law
The introduction of a new Article 4a, replacing Article 10(5) AI Act, reates a legal basis that facilitates compliance with data protection law by allowing providers and deployers of AI systems and AI models to process special categories of personal data in exceptional cases for the purpose of ensuring bias detection and correction under certain conditions. This extends the legal basis previously available to providers of high-risk AI systems to all providers of AI systems.
Broader use of AI regulatory sandboxes
The use of AI regulatory sandboxes is to be expanded by requiring each Member State to establish at least one operational AI regulatory sandbox (see the revised Article 57(1) AI Act). Concurrently, the new Article 57(3a) gives the AI Office a legal basis on which to set up an AI regulatory sandbox at EU level for AI systems that fall within its exclusive supervisory competence. The regulation therefore clearly distinguishes the scope of the AI regulatory sandbox set up at Union level from that of the national AI regulatory sandboxes. Member States are free to strengthen cross-border cooperation between their regulatory sandboxes.
Germany’s new Act implementing the Artificial Intelligence Act obliges the Bundesnetzagentur to establish and operate at least one such AI regulatory sandbox. A further legal development in this context was the draft Regulatory Sandboxes Act (Reallabore-Gesetz), submitted to the Bundesrat on 30 May 2025, which the governing coalition intended to use to facilitate more frequent and improved use of regulatory sandboxes in all sectors. The German Bundestag has now passed this bill as the Federal Testing Act (Bundeserprobungsgesetz). The AI Act’s stronger emphasis on innovation has therefore provided important impetus at European level for developments in Germany.
The Commission’s power to adopt implementing acts specifying the detailed arrangements for the establishment, development, implementation, operation and supervision of AI regulatory sandboxes has been further specified. Further, pursuant to the amended Article 60(1) AI Act, real-world testing outside AI regulatory sandboxes — previously available only for high-risk AI systems listed in Annex III — has now been extended to high-risk AI systems covered by Union harmonisation legislation listed in Section A of Annex I. This revision will improve coordination among the Member States and ensure optimal use of resources.
Conclusion
The Commission’s overarching objective of better aligning AI regulation with real-world conditions and practical needs is to be broadly welcomed. Clarifying the Regulation makes the rules easier for businesses to understand and implement. SMEs and SMCs in particular stand to benefit from the digital omnibus, which takes special account of such companies’ weaker economic position when it comes to monitoring and penalties.
The amendments should not be seen as deregulation, but rather as concessions on a practical level. As the majority of corporate obligations remain unchanged, companies are well advised to review their particular obligations and keep an eye on which measures they have implemented and which they have not.