Legislation · European Union · EU Directive & Regulation (COM(2025) 836 final · COM(2025) 837 final)

EU Digital Omnibus Package (COM(2025) 836 and COM(2025) 837)

On 19 November 2025 the European Commission published a simplification package known as the Digital Omnibus. It is not one instrument but two independent proposals: COM(2025) 836 final on artificial intelligence and COM(2025) 837 final on data legislation. The first has now been adopted; the second is still only a proposal, and conflating the two is the most common error in circulating commentary.

In progressIn force · AI half: signed 08.07.2026, awaiting OJ publication · Data half: not in force (proposal)Source · COM(2025) 836 final and COM(2025) 837 final, 19.11.2025 · OJ publication pendingThreshold · EU-facing AI providers and GDPR-caught controllers
In summary

The Digital Omnibus is not a single instrument. The AI half (COM(2025) 836) has completed the legislative process and the final act was signed on 08.07.2026; publication in the Official Journal, and with it the assignment of a regulation number, is still awaited. The data and GDPR half (COM(2025) 837) is a proposal sitting in Council: no general approach, no Parliament position, no trilogue, and nothing in it is law (as of July 2026). On AI, the only thing that moved is the high-risk timetable.

Who does it affect?

AI providers and deployers

For systems placed on the EU market the high-risk deadline has moved, while the other obligations stay where they were.

Companies caught by the GDPR

Nothing in the data protection and cookie rules has changed; the proposal has not been adopted.

Anyone planning a compliance programme

The package calls for tracking two files separately, not for planning against one deferred date.

Key Obligations
  • 01Screening for prohibited practices must continue; the prohibitions applicable since 02.02.2025 are untouched by this package.
  • 02The high-risk system inventory should be rebased on the new dates: 02.12.2027 standalone, 02.08.2028 embedded.
  • 03Generative AI content marking must be in place by 02.12.2026 for systems placed on the market before 02.08.2026.
  • 04The existing GDPR and cookie programme should run unchanged; the data half has not been adopted.

Overview

On 19.11.2025 the European Commission published a simplification package under the name Digital Omnibus. It is not one instrument but two independent proposals: COM(2025) 836 final on artificial intelligence and COM(2025) 837 final on data legislation. The two files are today in entirely different places; treating them as one measure is the standard error in circulating commentary.

The AI half has completed the legislative process: the final act was signed on 08.07.2026 and publication in the Official Journal is awaited (as of July 2026). The data half remains a proposal in Council, and nothing in it is law.

Scope: one name, two files

COM(2025) 836 amends the AI Act (Regulation (EU) 2024/1689) and Regulation (EU) 2018/1139. COM(2025) 837 would amend the GDPR, the ePrivacy Directive, the Data Act, the Data Governance Act, the Open Data Directive, the Free Flow of Non-Personal Data Regulation and NIS2, and repeal the P2B Regulation. A shared package name does not mean a shared timetable.

The AI half — adopted

The only date that moved is the start of high-risk system obligations. That date was 02.08.2026; it is now 02.12.2027 for standalone (Annex III) high-risk systems and 02.08.2028 for high-risk systems embedded in regulated products (Annex I). The mechanism ties the deferral to confirmed availability of harmonised standards, with those dates operating as backstops.

Providers of generative AI systems already on the market before 02.08.2026 get a six-month transition for content marking: the date is 02.12.2026. A new prohibition covers AI practices generating non-consensual intimate or sexual imagery and child sexual abuse material, applying from December 2026. Enforcement becomes more centralised: the AI Office will supervise AI systems integrated into very large online platforms and search engines, and systems built on general-purpose models where system and model share a provider. The binding AI literacy obligation on providers and deployers gives way to a duty on the Commission and Member States to promote it. Administrative relief follows: SME measures extended to small mid-caps, one application for designating conformity assessment bodies, registration relief for systems self-assessed as non-high-risk on narrow or procedural task grounds, wider testing sandboxes, and limited processing of special-category data for bias detection.

The text is signed but not published, so no regulation number exists; it is assigned on publication (as of July 2026).

The data and GDPR half — proposal only

COM(2025) 837 was proposed by the Commission and has not been adopted. It sits in the Council working party: no general approach; rapporteurs appointed in Parliament’s joint ITRE and LIBE committees but no committee report adopted; no trilogue. The European Economic and Social Committee gave its opinion on 18.03.2026; the Committee of the Regions adopted its position on 07.05.2026.

None of what follows is in force. On the GDPR: a narrowed definition of personal data resting on an entity-relative test, relief for low-risk processing, a legal basis for AI development and operation, and changes to data subject request handling and breach notification. On cookies: moving terminal-equipment consent rules out of the ePrivacy Directive into the GDPR through a new Article 88a, with machine-readable consent signals and broader exemptions for audience measurement and security. On the Data Act: consolidating the Data Governance Act, the Open Data Directive and the Free Flow of Non-Personal Data Regulation into one instrument. On NIS2: a single entry point for cybersecurity incident reporting. The P2B Regulation would be repealed. The GDPR and cookie elements are the most contested and may not survive in their current form.

What this means for Turkish companies

On AI, the AI Act continues to apply extraterritorially where you place AI systems on the EU market or their output is used there. Prohibited practices have applied since 02.02.2025 and general-purpose AI obligations since 02.08.2025; both are unaffected by this package. The only change is the high-risk timetable, which is breathing room for conformity assessment rather than a reprieve. Generative AI content marking still bites on 02.12.2026.

The critical point for Turkish exporters

On data and privacy, change nothing. Do not defer a cookie consent remediation or a GDPR programme on the strength of the Digital Omnibus: the data half is only a proposal, no rule has changed, and the cookie reform may never be adopted. The GDPR as currently in force applies in full, including the extraterritorial reach of Article 3(2) and the Chapter V transfer rules. Because there is no adequacy decision for Türkiye, standard contractual clauses remain necessary for personal data transferred from the EU to Türkiye.

In practice, cookie banners, privacy notices, data subject request procedures and transfer documentation should be built against the GDPR as it stands today. If the proposal is adopted they will need review, but that is at best a 2027 exercise.

Timeline and what to watch

On the AI half, publication in the Official Journal and entry into force are imminent, and the regulation number is assigned then. Watch whether the Commission confirms the availability of harmonised standards: if it does, the high-risk timetable could be pulled earlier than the 02.12.2027 backstop. On the data half, a Council general approach, a Parliament position and trilogue all lie ahead; realistic adoption is 2027 at the earliest. Product suppliers should also follow the proposed single NIS2 reporting entry point and how it would interact with their incident reporting duties.

Related content

For the underlying AI instrument see our AI Act record, and for the data rules in force today our GDPR record. The practical side is covered in our Artificial Intelligence and Data focus areas.

Entry into force & amendment history

  • 08.07.2026

    AI Omnibus signed

    The final act was signed; publication in the Official Journal and the assignment of a regulation number are still awaited.

  • 29.06.2026

    Council final adoption

    The Council gave its final adoption to the AI half of the package.

  • 16.06.2026

    Parliament plenary approval

    The European Parliament approved the text by 423 votes to 57, with 174 abstentions.

  • 19.11.2025

    Package published as two proposals

    The Commission published COM(2025) 836 and COM(2025) 837; the data half has not advanced beyond this stage.

This record is provided for general information and monitoring only; it does not constitute legal advice or create an attorney–client relationship. The official text in force is authoritative. Contact our team for a scope and compliance assessment specific to your company.
01

Related Practice Areas

We address this regulation together with our expertise in the following practice areas.

02

Focus & Sector Links

This regulation creates a cross-disciplinary focus with a greater impact on certain sectors.

DC
Related Desk · Regional

Data & Cybersecurity Desk

Integrated advice spanning multiple jurisdictions in KVKK and GDPR compliance, cross-border data transfer, and cyber incident response.

Explore the regional desk
03

How We Help on This Matter

We structure compliance with this instrument across both the Türkiye and DACH sides of your business.

AI inventory and classification

Mapping the systems you use and supply by role and risk class, then rebasing them on the new dates.

GDPR and cookie compliance

Reviewing notices, consent capture and data subject request handling against the rules currently in force.

Transfer documentation

Putting standard contractual clauses and supplementary measures in place for EU to Türkiye transfers.

Legislative tracking and reporting

Following the two files separately and giving management short, decision-ready updates.

All our services
Legislation · European Union

EU Digital Omnibus Package (COM(2025) 836 and COM(2025) 837) — obtain the right legal support.

Let us assess the impact of this regulation on your business and establish a practical compliance framework.