
The European Commission’s digital and artificial intelligence omnibus proposals, issued on 19 November, aim to streamline EU regulations and reduce compliance costs, particularly in digital services and AI. The primary goal is to simplify and consolidate regulatory frameworks.
The digital omnibus proposes to streamline EU data regulations by repealing several existing laws, including the Platform-to-Business and Free Flow of Data regulations, the Open Data Directive, and the Data Governance Act. These regulations will be consolidated into the 2023 Data Act, which sets rules for data access and use by companies. The Data Act, effective since 12 September 2025, focuses on ‘product’ data generated by connected physical devices. However, the Data Act has several shortcomings. The vaguely defined ‘product data’ category has fragmented data markets and created legal uncertainty. Applying the Data Act to all non-personal data, rather than just product data, would have simplified the regulatory landscape. Additionally, the Data Act gives industry data holders control over data access, which can be anti-competitive. Users who paid for a device must pay again to share the data with third parties, except for smartphones. Other anti-competitive provisions, such as prohibiting companies from using data obtained from other companies to develop competing products or services, remain in place.
The Commission aims to address the reluctance of firms to share data for AI training by setting up data labs and common European data spaces. However, voluntary participation in these spaces is unlikely to overcome market failures. Firms need clear governance mechanisms to know who can access their data, for what purpose, and how costs and benefits are shared. The European Health Data Space Regulation mandates data sharing by medical service providers, maximizing the social value of health data. In contrast, the Common European Agricultural Data Space gives farmers exclusive rights to decide on data sharing conditions, contradicting the Data Act and failing to exploit the social value of farm data. This reveals a fundamental issue in EU data regulation: the lack of clarity around data access rights in digital settings where multiple parties contribute to co-generating data on platforms.
Regulatory Consolidation Around the Data Act
The digital omnibus proposes to streamline EU data regulations by repealing several existing laws, including the Platform-to-Business and Free Flow of Data regulations, the Open Data Directive, and the Data Governance Act. These regulations will be consolidated into the 2023 Data Act, which sets rules for data access and use by companies. The Data Act, effective since 12 September 2025, focuses on ‘product’ data generated by connected physical devices. However, the Data Act has several shortcomings. The vaguely defined ‘product data’ category has fragmented data markets and created legal uncertainty. Applying the Data Act to all non-personal data, rather than just product data, would have simplified the regulatory landscape. Additionally, the Data Act gives industry data holders control over data access, which can be anti-competitive. Users who paid for a device must pay again to share the data with third parties, except for smartphones. Other anti-competitive provisions, such as prohibiting companies from using data obtained from other companies to develop competing products or services, remain in place.
Data Protection Changes
The digital omnibus addresses consumer fatigue with GDPR privacy consent notices by proposing browser extensions that automate data sharing tasks. These extensions can opt-out of data sharing as the default setting for all webpages and can be made mandatory. However, media services are excluded from this provision, potentially distorting the online advertising market. More fundamental issues around consent for data collection and processing remain unaddressed. The GDPR’s negative economic impact on the EU includes reduced digital services investment, concentration of user data in big-tech firms, and increased prices for consumers. Individual privacy protection seems to conflict with economic welfare for society at large. Proposed changes to the GDPR include revising the definition of ‘personal data’ to exclude information unlikely to identify individuals and confirming that publicly available personal data on social media can be used to train AI models. This would expand the supply of training data, especially for small language communities in the EU.
The AI Act
The AI omnibus proposes changes to the EU AI Act, including postponing obligations for high-risk AI systems in areas like critical infrastructure, education, and law enforcement. This aims to design harmonized technical standards for assessing these obligations. However, rather than simplifying implementation, the AI omnibus adds new sources of uncertainty for AI investors. It promises more guidance to facilitate compliance with the AI Act, but developing and approving these guidelines will take several years, prolonging regulatory uncertainty. Precautionary measures for generative-AI models were added to the AI Act, but the Act is already behind the AI technology curve. Excessive precaution should be abandoned to give AI developers more room to experiment. The AI omnibus includes a provision for an “EU-level AI regulatory sandbox,” which should be broadened to enable model developers to experiment without immediately hitting regulatory constraints. This would mark a shift in EU AI regulation from a precautionary to a pro-innovation stance and could become the kernel of a single EU AI regime. Despite good intentions, the AI omnibus risks slowing down AI deployment in the EU by prolonging regulatory uncertainty. The situation with AI technology, models, and services will likely be very different in several years, making today’s regulatory regimes potentially irrelevant.
