AI Act Omnibus
- Last updated: June 2026
- Category: General Obligations, Data Security
The EU AI Act may have entered into force, but the regulatory framework surrounding AI is far from settled. In order to address this, the European Commission's proposed AI Act Omnibus package demonstrates that policymakers are already revisiting certain provisions to improve legal certainty, reduce unnecessary administrative burdens and better align the AI Act with existing legislation, particularly the GDPR.
For organisations developing, deploying or procuring AI systems/GPAI models, this is an important reminder that compliance cannot be approached as a one-time exercise. Since the GDPR and AI Act seemed to be contradictory in specific scenarios, the Omnibus aims to align data protection and use of AI. Generally, facilitating the overall understanding and implementation of data privacy is a great starting point to approach obligations under the AI Act.
A good example is proposed Article 4a, which addresses the processing of special categories of personal data for bias detection and mitigation. The proposal seeks to provide greater clarity on how organizations can assess and address discriminatory outcomes in AI systems while remaining compliant with data protection requirements. The AI Act here is no lex specialis, as in, the special rule here does not precedent over the other more general rules under the GDPR.
It is essential to understand key challenges of AI governance, like balancing fundamental rights such as privacy and data protection with the need to ensure fairness and non-discrimination in AI systems.
Another notable development is the proposed amendment to Article 27. Through the introduction of a new Article 27(4), the Commission aims to reduce duplication between the AI Act's Fundamental Rights Impact Assessment (FRIA) and the GDPR's Data Protection Impact Assessment (DPIA) by cross-referencing. For many organizations, this could eventually simplify compliance efforts, while at the same time, it underscores the increasingly close relationship between AI Act and GDPR compliance.
The Omnibus proposal also introduces the concept of Small Mid-Cap Companies (SMCs) in Article 3(14a). While much of the discussion around AI regulation has focused on SMEs and large enterprises, the inclusion of SMCs acknowledges that many growing businesses face similar compliance challenges. Companies are expected to undergo a self-assessment process to be able to demonstrate they fall under the idea of SMCs. This eases out specific compliance obligations like simpler technical documentation under Annex IV.
These proposals, which should be adopted by the 30th of July 2026, show that the AI regulatory landscape remains dynamic. Staying informed will be critical to identifying compliance risks, taking advantage of potential simplifications and ensuring that AI governance frameworks remain fit for purpose in a rapidly evolving regulatory environment. Furthermore, understanding the spirit and principles of the GDPR is crucial to grasping the idea of the AI Act properly.
Please reach out to us with any questions you may have – under our DPO services, we provide advice for GDPR obligations and be able to see the interactions between digital laws in the EU.