AI Act Omnibus

  • Author: Arno Schlösser, DP-Dock GmbH
  • Last updated: June 2026
  • Category: General Obligations, Data Security

The EU AI Act may have entered into force, but the regulatory framework surrounding AI is far from settled. In order to address this, the European Commission's proposed AI Act Omnibus package demonstrates that policymakers are already revisiting certain provisions to improve legal certainty, reduce unnecessary administrative burdens and better align the AI Act with existing legislation, particularly the GDPR.

For organisations developing, deploying or procuring AI systems/GPAI models, this is an important reminder that compliance cannot be approached as a one-time exercise. Since the GDPR and AI Act seemed to be contradictory in specific scenarios, the Omnibus aims to align data protection and use of AI. Generally, facilitating the overall understanding and implementation of data privacy is a great starting point to approach obligations under the AI Act.

A good example is proposed Article 4a, which addresses the processing of special categories of personal data for bias detection and mitigation. The proposal seeks to provide greater clarity on how organizations can assess and address discriminatory outcomes in AI systems while remaining compliant with data protection requirements. The AI Act here is no lex specialis, as in, the special rule here does not precedent over the other more general rules under the GDPR.

It is essential to understand key challenges of AI governance, like balancing fundamental rights such as privacy and data protection with the need to ensure fairness and non-discrimination in AI systems.

Another notable development is the proposed amendment to Article 27. Through the introduction of a new Article 27(4), the Commission aims to reduce duplication between the AI Act's Fundamental Rights Impact Assessment (FRIA) and the GDPR's Data Protection Impact Assessment (DPIA) by cross-referencing. For many organizations, this could eventually simplify compliance efforts, while at the same time, it underscores the increasingly close relationship between AI Act and GDPR compliance.

The Omnibus proposal also introduces the concept of Small Mid-Cap Companies (SMCs) in Article 3(14a). While much of the discussion around AI regulation has focused on SMEs and large enterprises, the inclusion of SMCs acknowledges that many growing businesses face similar compliance challenges. Companies are expected to undergo a self-assessment process to be able to demonstrate they fall under the idea of SMCs. This eases out specific compliance obligations like simpler technical documentation under Annex IV.

These proposals, which should be adopted by the 30th of July 2026, show that the AI regulatory landscape remains dynamic. Staying informed will be critical to identifying compliance risks, taking advantage of potential simplifications and ensuring that AI governance frameworks remain fit for purpose in a rapidly evolving regulatory environment. Furthermore, understanding the spirit and principles of the GDPR is crucial to grasping the idea of the AI Act properly.

Please reach out to us with any questions you may have – under our DPO services, we provide advice for GDPR obligations and be able to see the interactions between digital laws in the EU.

EU Artificial Intelligence Act
© Konsta / stock.adobe.com | #1055333911

Privacy settings

We use cookies on our website. Some of them are essential, while others help us improve this website and your experience.

In this overview you can select and deselect individual cookies of a category or entire categories. You will also receive more information about the cookies available.
Group essential
Name Matomo
Technical name
Provider
Expire in days 72
Privacy policy
Use Use without cookies
Allowed
Group external media
Name Calendly
Technical name __cf_bm,__cfruid,OptanonConsent
Provider Calendly LLC
Expire in days 365
Privacy policy
Use To arrange appointments via the provider Calendly
Allowed
Name Contao CSRF Token
Technical name csrf_contao_csrf_token
Provider Contao
Expire in days 0
Privacy policy
Use Serves to protect the website from cross-site request forgery attacks. After closing the browser, the cookie is deleted again.
Allowed
Name Contao HTTPS CSRF Token
Technical name csrf_https_contao_csrf_token
Provider Contao
Expire in days 0
Privacy policy
Use Serves to protect the encrypted website (HTTPS) against falsification of cross-site requests. After closing the browser the cookie is deleted again
Allowed
Name PHP SESSION ID
Technical name PHPSESSID
Provider Contao
Expire in days 0
Privacy policy
Use PHP cookie (programming language), PHP data identifier. Contains only a reference to the current session. There is no information in the user's browser saved and this cookie can only be used by the current website. This cookie is used all used in forms to increase usability. Data entered in forms will be e.g. B. briefly saved when there is an input error by the user and the user receives an error message receives. Otherwise all data would have to be entered again
Allowed