The Digital Omnibus is not a single instrument. The AI half (COM(2025) 836) has completed the legislative process and the final act was signed on 08.07.2026; publication in the Official Journal, and with it the assignment of a regulation number, is still awaited. The data and GDPR half (COM(2025) 837) is a proposal sitting in Council: no general approach, no Parliament position, no trilogue, and nothing in it is law (as of July 2026). On AI, the only thing that moved is the high-risk timetable.
AI providers and deployers
For systems placed on the EU market the high-risk deadline has moved, while the other obligations stay where they were.
Companies caught by the GDPR
Nothing in the data protection and cookie rules has changed; the proposal has not been adopted.
Anyone planning a compliance programme
The package calls for tracking two files separately, not for planning against one deferred date.
- 01Screening for prohibited practices must continue; the prohibitions applicable since 02.02.2025 are untouched by this package.
- 02The high-risk system inventory should be rebased on the new dates: 02.12.2027 standalone, 02.08.2028 embedded.
- 03Generative AI content marking must be in place by 02.12.2026 for systems placed on the market before 02.08.2026.
- 04The existing GDPR and cookie programme should run unchanged; the data half has not been adopted.
Overview
On 19.11.2025 the European Commission published a simplification package under the name Digital Omnibus. It is not one instrument but two independent proposals: COM(2025) 836 final on artificial intelligence and COM(2025) 837 final on data legislation. The two files are today in entirely different places; treating them as one measure is the standard error in circulating commentary.
The AI half has completed the legislative process: the final act was signed on 08.07.2026 and publication in the Official Journal is awaited (as of July 2026). The data half remains a proposal in Council, and nothing in it is law.
Scope: one name, two files
COM(2025) 836 amends the AI Act (Regulation (EU) 2024/1689) and Regulation (EU) 2018/1139. COM(2025) 837 would amend the GDPR, the ePrivacy Directive, the Data Act, the Data Governance Act, the Open Data Directive, the Free Flow of Non-Personal Data Regulation and NIS2, and repeal the P2B Regulation. A shared package name does not mean a shared timetable.
The AI half — adopted
The only date that moved is the start of high-risk system obligations. That date was 02.08.2026; it is now 02.12.2027 for standalone (Annex III) high-risk systems and 02.08.2028 for high-risk systems embedded in regulated products (Annex I). The mechanism ties the deferral to confirmed availability of harmonised standards, with those dates operating as backstops.
Providers of generative AI systems already on the market before 02.08.2026 get a six-month transition for content marking: the date is 02.12.2026. A new prohibition covers AI practices generating non-consensual intimate or sexual imagery and child sexual abuse material, applying from December 2026. Enforcement becomes more centralised: the AI Office will supervise AI systems integrated into very large online platforms and search engines, and systems built on general-purpose models where system and model share a provider. The binding AI literacy obligation on providers and deployers gives way to a duty on the Commission and Member States to promote it. Administrative relief follows: SME measures extended to small mid-caps, one application for designating conformity assessment bodies, registration relief for systems self-assessed as non-high-risk on narrow or procedural task grounds, wider testing sandboxes, and limited processing of special-category data for bias detection.
The text is signed but not published, so no regulation number exists; it is assigned on publication (as of July 2026).
The data and GDPR half — proposal only
COM(2025) 837 was proposed by the Commission and has not been adopted. It sits in the Council working party: no general approach; rapporteurs appointed in Parliament’s joint ITRE and LIBE committees but no committee report adopted; no trilogue. The European Economic and Social Committee gave its opinion on 18.03.2026; the Committee of the Regions adopted its position on 07.05.2026.
None of what follows is in force. On the GDPR: a narrowed definition of personal data resting on an entity-relative test, relief for low-risk processing, a legal basis for AI development and operation, and changes to data subject request handling and breach notification. On cookies: moving terminal-equipment consent rules out of the ePrivacy Directive into the GDPR through a new Article 88a, with machine-readable consent signals and broader exemptions for audience measurement and security. On the Data Act: consolidating the Data Governance Act, the Open Data Directive and the Free Flow of Non-Personal Data Regulation into one instrument. On NIS2: a single entry point for cybersecurity incident reporting. The P2B Regulation would be repealed. The GDPR and cookie elements are the most contested and may not survive in their current form.
What this means for Turkish companies
On AI, the AI Act continues to apply extraterritorially where you place AI systems on the EU market or their output is used there. Prohibited practices have applied since 02.02.2025 and general-purpose AI obligations since 02.08.2025; both are unaffected by this package. The only change is the high-risk timetable, which is breathing room for conformity assessment rather than a reprieve. Generative AI content marking still bites on 02.12.2026.
The critical point for Turkish exporters
On data and privacy, change nothing. Do not defer a cookie consent remediation or a GDPR programme on the strength of the Digital Omnibus: the data half is only a proposal, no rule has changed, and the cookie reform may never be adopted. The GDPR as currently in force applies in full, including the extraterritorial reach of Article 3(2) and the Chapter V transfer rules. Because there is no adequacy decision for Türkiye, standard contractual clauses remain necessary for personal data transferred from the EU to Türkiye.
In practice, cookie banners, privacy notices, data subject request procedures and transfer documentation should be built against the GDPR as it stands today. If the proposal is adopted they will need review, but that is at best a 2027 exercise.
Timeline and what to watch
On the AI half, publication in the Official Journal and entry into force are imminent, and the regulation number is assigned then. Watch whether the Commission confirms the availability of harmonised standards: if it does, the high-risk timetable could be pulled earlier than the 02.12.2027 backstop. On the data half, a Council general approach, a Parliament position and trilogue all lie ahead; realistic adoption is 2027 at the earliest. Product suppliers should also follow the proposed single NIS2 reporting entry point and how it would interact with their incident reporting duties.
Related content
For the underlying AI instrument see our AI Act record, and for the data rules in force today our GDPR record. The practical side is covered in our Artificial Intelligence and Data focus areas.
Entry into force & amendment history
- 08.07.2026
AI Omnibus signed
The final act was signed; publication in the Official Journal and the assignment of a regulation number are still awaited.
- 29.06.2026
Council final adoption
The Council gave its final adoption to the AI half of the package.
- 16.06.2026
Parliament plenary approval
The European Parliament approved the text by 423 votes to 57, with 174 abstentions.
- 19.11.2025
Package published as two proposals
The Commission published COM(2025) 836 and COM(2025) 837; the data half has not advanced beyond this stage.
Official Sources
EPRS briefing (PE 782.651) · European Parliament europarl.europa.euLegislative Train: Digital Omnibus on AI · European Parliament europarl.europa.eu


