Technology · Digital regulation
EU delays high-risk AI rules to 2027 in Digital Omnibus package
The European Commission has proposed postponing stricter obligations for high-risk artificial intelligence systems by two years, while allowing anonymised personal data to train models and cutting cookie consent requirements.
The European Commission unveiled its long-awaited Digital Omnibus package on Wednesday, proposing a two-year delay to the strictest obligations of the AI Act for high-risk systems and a loosening of data protection rules that have governed the bloc since the General Data Protection Regulation took effect in 2018. The move marks the most significant retreat from the EU's original digital regulatory architecture since the AI Act entered into force in August 2024.
What the Digital Omnibus changes
The reform package amends the AI Act, the GDPR, the ePrivacy Directive and several sector-specific regulations. Its centrepiece is the postponement of risk-management, data-governance and human-oversight requirements for high-risk AI systems, covering areas such as recruitment, credit scoring, critical infrastructure and law enforcement, from August 2025 to August 2027. The Commission also proposes a legal basis for processing anonymised personal data to train AI models, a reduction in the documentation burden for small and medium-sized enterprises, and a simplification of cookie consent mechanisms that have become ubiquitous across European websites.
Henna Virkkunen, the Commissioner for Tech Sovereignty, Security and Democracy, framed the package as a competitiveness measure. "We have talent, infrastructure, a large internal single market. But our companies, especially our start-ups and small businesses, are often held back by layers of rigid rules," she said. The Commission estimates that compliance costs for SMEs could fall by up to 30 per cent under the simplified regime, though no independent verification of that figure has been published.
Industry reaction: relief but not satisfaction
The Computer & Communications Industry Association (CCIA), whose members include Google, Apple, Meta, Amazon and Microsoft, welcomed the direction but said the package falls short. In a statement, the lobby group argued that the Omnibus "misses critical opportunities to raise the outdated compute threshold for identifying AI models which pose a 'systemic risk'" and fails to fix "problematic wording on the extraterritoriality of copyright provisions, which conflicts with EU and international principles." The compute threshold, set at 1025 floating-point operations in the original AI Act, determines which general-purpose models face the most stringent obligations; industry has argued it captures models that pose no systemic risk.
Other industry voices were more positive. The European Digital SME Alliance, which represents smaller technology firms, said the documentation reductions would "make a tangible difference" for companies that lack dedicated compliance teams. However, several national industry federations, including Germany's Bitkom and France's Numeum, have yet to publish formal positions, suggesting they are still analysing the 300-page legislative text.
Privacy advocates call it a capitulation
The response from civil society was scathing. Max Schrems, whose organisation NOYB has brought landmark cases against Facebook and Google over data transfers, described the reforms as "the biggest attack on Europe's digital rights in years." He disputed the Commission's assertion that fundamental rights remain protected, arguing that the anonymisation exception for AI training creates a loophole that will be exploited given the well-documented difficulties of true anonymisation at scale. Research from Imperial College London and the Catholic University of Leuven has shown that even heavily anonymised datasets can often be re-identified when combined with auxiliary information.
Gianclaudio Malgieri, associate professor of law and technology at Leiden University, placed the package in a broader doctrinal shift. "If adopted as they stand, these reforms risk moving the EU model closer to a more permissive, industry-driven approach to AI and data use, at the very moment when the world is watching Europe to see whether it can offer a real alternative," he said. Malgieri noted that the GDPR's purpose-limitation principle, data collected for one purpose cannot be repurposed without fresh consent, is effectively being overridden for AI development, a precedent that could extend to other emerging technologies.
The political context: transatlantic pressure
The Omnibus does not arrive in a vacuum. Since returning to the White House in January 2025, the Trump administration has made EU technology regulation a explicit target of trade policy. The US Trade Representative's 2025 National Trade Estimate Report devoted twelve pages to the AI Act, the Digital Markets Act and the Digital Services Act, characterising them as "discriminatory barriers to digital trade." In March, the administration threatened Section 301 tariffs on European digital services unless the Commission provided "meaningful relief" for US companies. While the Commission denies a direct causal link, the timing, eight months before the original high-risk compliance deadline, is conspicuous.
European Parliament sources indicate that the centre-right European People's Party, the largest group in the hemicycle, pushed privately for the delay after hearing from constituents in the German and French automotive and manufacturing sectors. The Greens and the Left group have vowed to oppose the package, but they lack the numbers to block it alone. The decisive vote will likely fall to the liberal Renew Europe group and the conservative European Conservatives and Reformists, both of which have signalled openness to targeted simplification but not to a wholesale weakening of rights protections.
What the AI Act originally required
To understand the scale of the change, it helps to recall the AI Act's risk pyramid. Unacceptable-risk systems, social scoring, real-time biometric identification in public spaces, are banned outright. High-risk systems, which include AI used in education, employment, essential public services, law enforcement and migration, must comply with a suite of obligations: risk-management systems, data-governance measures, technical documentation, record-keeping, transparency to users, human oversight, and accuracy, robustness and cybersecurity standards. Providers must also register their systems in an EU database and affix a CE mark. The original timeline gave providers of high-risk systems 24 months from entry into force, until 2 August 2025, to comply. The Omnibus pushes that to 2 August 2027.
The Act also created a category of general-purpose AI models with systemic risk, defined by the compute threshold mentioned above. Those models face additional obligations including model evaluation, systemic risk assessment and mitigation, incident reporting, and cybersecurity protection. The Omnibus does not alter the systemic-risk threshold, a point of frustration for CCIA and other industry groups.
Data protection: the anonymisation loophole
The GDPR permits processing of personal data only on one of six lawful bases, with consent and legitimate interest the most common. Anonymised data falls outside the Regulation's scope entirely. The Omnibus proposes a new article clarifying that anonymisation for AI training constitutes a compatible purpose under Article 6(4) GDPR, effectively allowing companies to repurpose vast datasets collected for other reasons, customer service logs, transaction histories, sensor data, without seeking fresh consent. The Commission argues that technical standards for anonymisation, to be developed by the European Data Protection Board, will prevent abuse. Critics counter that the Board's guidelines are non-binding and that enforcement resources are already stretched.
The cookie consent simplification is perhaps the most visible change for ordinary users. The ePrivacy Directive, implemented nationally across the EU, requires informed consent for non-essential cookies. The result has been a proliferation of consent banners that many users click through without reading. The Omnibus proposes a "consent fatigue" exemption: websites would no longer need to request consent for analytics cookies that do not track individuals across sites, and a browser-based signal, similar to the Global Privacy Control standard, would replace per-site banners for other categories. The European Data Protection Supervisor has warned that this may contravene the Charter of Fundamental Rights' guarantee of data protection.
SME relief: real or rhetorical?
The Commission's impact assessment claims that SMEs spend an average of 2.3 per cent of annual turnover on digital compliance, compared with 0.8 per cent for large enterprises. The Omnibus introduces a tiered documentation regime: micro-enterprises (fewer than ten employees) would be exempt from technical documentation requirements for high-risk AI entirely; small enterprises (fewer than fifty) would submit simplified dossiers; medium enterprises (fewer than 250) would follow the current regime but with extended deadlines. Industry groups caution that the tiered approach creates cliff effects at each threshold and that many SMEs operate in supply chains where large customers will demand full compliance regardless of the legal minimum.
Sources
People mentioned
Organisations
European Commission · Computer & Communications Industry Association · NOYB, European Center for Digital Rights · Leiden University