Digital Omnibus and AI Act: What Changes for Businesses

The European Parliament and the Council have reached a long-awaited political agreement on some of the key points of proposal COM/2025/836, the Digital Omnibus, which concerns the field of artificial intelligence and, in particular, the AI Act, the European regulation 2024/1689 governing the development and use of AI systems.


The AI Act sits at the center of a rather heated debate. Since its entry into force in August 2024, businesses and professionals have begun putting the regulation’s provisions into practice, encountering concrete application limits and operational difficulties along the way.
The proposal therefore addresses precisely these issues, introducing new simplifications for certain entities (Small Mid-Caps), clearer rules on bias and sensitive data, new prohibitions, revised deadlines, and a strengthened role for the AI Office in overseeing the most complex systems.

What is the Digital Omnibus?


The Digital Omnibus is a legislative package from the European Commission aimed at amending existing digital regulations and directives in order to streamline their functioning and reduce the administrative burden on businesses, citizens, and public administrations.
This fits within the broader effort undertaken by the European Commission to simplify and consolidate the digital acquis—the substantial body of digital-sector rules and regulations—with the goal of strengthening the European Union’s competitiveness on the global stage.

What the Digital Omnibus Provides for the AI Act

The Digital Omnibus in the AI domain, which will become law only after publication in the Official Journal of the EU, introduces the following changes in relation to the AI Act:

Simplifications extended to Small Mid-Caps

The facilitations already provided for SMEs, such as reduced technical documentation (Articles 11 and 17) and proportionate penalties, now also apply to small mid-cap companies.

AI Literacy: institutions step in too

The obligation to promote AI training no longer falls solely on providers and deployers. Institutions, the European Commission, and Member States will need to take action through concrete programs and tools, although internal operational responsibility remains with businesses.

Bias and sensitive data: a regulatory gap filled

The new Article 4-bis allows providers of high-risk AI systems to process special categories of data in order to detect and correct algorithmic bias, subject to an obligation of pseudonymization and subsequent deletion. GDPR protections remain fully applicable.
New prohibitions: nudification and synthetic material involving minors
Article 5 explicitly prohibits AI systems capable of generating sexually explicit material of identifiable individuals without their consent, as well as any synthetic sexual content involving minors. Providers must implement technical measures to prevent such uses.

Flexible deadlines, not eliminated

Obligations for high-risk systems will no longer take effect rigidly on August 2, 2026, but will instead be contingent on the availability of harmonized standards or Commission guidelines. However, final deadlines have been set:

  • December 2, 2027 (Annex III)
  • August 2, 2028 (Annex I).

AI Office: direct oversight of the most complex systems

The AI Office gains exclusive supervisory authority over vertically integrated GPAI systems and over systems embedded in large platforms already under DSA scrutiny (VLOPs and VLOSEs), with the ability to conduct conformity assessments before market entry.

How to Prepare for the AI Act

The Digital Omnibus introduces significant changes for anyone developing AI systems or using them in their business processes. The flexibility of the deadlines does not reduce the urgency: compliance pathways require structural time.


Waiting until deadlines approach exposes companies to the concrete risk of failing to complete the compliance process in time, with consequent exposure to penalties.

In addition, the AI Literacy obligation, already in force since February 2025, remains a requirement to be met: internal training also requires planning based on existing knowledge levels and cannot be improvised at the last minute.

An effective compliance process starts with mapping the AI systems in use (internal, embedded in products, or supplied by third parties) and conducting an assessment to identify the company’s role, its corresponding risk category, and priority actions, enabling it to proceed with documentation and procedural updates as well as staff training.

These are activities that require integrated expertise: legal, technological, and governance-related.

Our Firm assists businesses and organizations with analysis, regulatory compliance, and training activities related to the AI Act and artificial intelligence.

Our Firm assists businesses and organizations with analysis, regulatory compliance, and training activities related to the AI Act and artificial intelligence.

FAQs

We are equipped with a specialized software for the management of patents, design, trademark, copyright's portfolios" Battista Software Project" - Studio Brevetti Turini s.r.l. Project co-financed under Tuscany POR FESR 2014-2020

PORCreO Regione Toscana