Prefer to listen? Click play for AI narration

If your business spent the last few years building a GDPR programme, 2026 is the year the ground started moving again. Between the European Commission's Digital Omnibus and a substantial rewrite of the EU AI Act's timeline, the rulebook European SMBs worked hard to learn is being redrawn in real time.

There is one thing almost every summary of this gets wrong, though, and it will cost you if you plan around it. The Digital Omnibus is not one law. It is two separate files moving at completely different speeds β€” and only one of them has actually landed.

The Digital Omnibus is two files, not one

When the Commission published the Digital Omnibus package on 19 November 2025, it split the work in two:

Almost every "what's changing in GDPR" article you'll read conflates the two. The practical consequence is real: businesses are deferring AI Act work that is now genuinely deferred (fine), while simultaneously planning cookie banner rebuilds around a mechanism that is currently not in the text at all (not fine).

What is already law: the AI Act deadlines that moved

If you use or deploy AI in hiring, credit scoring, education, essential services or similar contexts, you were staring down 2 August 2026. That deadline is gone.

2 Dec 2027
Annex III high-risk deadline (was 2 Aug 2026)
2 Aug 2028
Annex I product-embedded AI (was 2 Aug 2027)
2 Aug 2027
Member states must have sandboxes running
16 months
Extra runway for standalone high-risk systems

Standalone high-risk systems under Annex III β€” recruitment and worker-management tools, creditworthiness assessment, access to essential public and private services, biometric categorisation, education scoring β€” now have until 2 December 2027. That is a 16-month extension, granted largely because the harmonised technical standards that were supposed to make compliance achievable arrived late.

AI embedded in regulated products under Annex I moves to 2 August 2028. AI systems used by public authorities have until 2 August 2030 regardless of category.

Alongside the delay came genuine simplification, and two pieces matter for smaller organisations:

There is also a new "small mid-cap" category β€” under 750 employees and €150M turnover β€” that gets access to simplified compliance templates and to the regulatory sandboxes. If you sit between the SME threshold and that ceiling, this is the first time the AI Act has offered you anything.

Free tool Not sure whether your system is Annex III high-risk? The classification is something you're expected to have documented either way. Run the decision tree β†’

What did not move β€” and one new prohibition with no grace period

The delay is narrower than the headlines suggest. Three things stayed exactly where they were:

  1. Article 50 transparency duties still applied from 2 August 2026. If your chatbot talks to customers, or you generate synthetic media, people have to be told. This was never part of the high-risk package. The one concession: providers of generative AI systems already on the market before 2 August 2026 have until 2 December 2026 for the machine-readable marking requirements under Article 50(2).
  2. The Article 5 prohibitions remain in force β€” they have applied since February 2025.
  3. Two new prohibitions take effect on 2 December 2026, with no transition period at all. AI systems that generate or manipulate child sexual abuse material, and systems that generate realistic intimate imagery of an identifiable person without their explicit consent, are banned outright.

That second prohibition is broader than it first appears, and it is the one most likely to catch an ordinary business by surprise. It does not only target purpose-built "nudifier" apps. It reaches providers of general-purpose generative image, video and audio models where such output is a reasonably foreseeable and reproducible outcome and the provider has not put reasonable safeguards in place. If you build on top of a generative model and expose it to users, the question of whose safeguards apply is one worth asking your vendor in writing.

πŸ“˜
Compliance Field Kit Β· €39
Both halves of the Omnibus, explained without the scare tactics

Seven plain-English guides for small European teams β€” including Digital Omnibus Explained and EU AI Act, Without the Scare Tactics, which takes the ten myths small teams keep hearing (starting with the €35M figure that does not apply to most of them) and gives the real answer. Instant download, one payment.

See the Field Kit β†’

The GDPR half: still a proposal, and partly stalled

Now the part that is not settled, and where planning ahead is genuinely risky.

The Data Omnibus proposed several changes that would matter a great deal to SMBs. The record-keeping exemption under Article 30(5) would rise from fewer than 250 employees to fewer than 750, subject to financial ceilings, and the blanket disqualification for any processing of special category data would be replaced with a risk-based test. That piece has institutional support and is the most likely to survive close to its current form.

The rest is a different story:

The operational proposals β€” extending breach notification from 72 to 96 hours, harmonising DPIA guidance across member states β€” are still on the table but unresolved. The EDPB and EDPS were more receptive to those, while insisting that independent regulators rather than the Commission should own the technical detail like breach templates and DPIA methodology.

The honest summary for an SMB: nothing in the GDPR half is something you can build against yet. Parliament's own impact study was due in October 2026, and final adoption before the end of 2026 looks unlikely β€” which makes real implementation a 2027 story at the earliest.

We covered this half in detail in Inside the EU's Digital Omnibus, including exactly which articles were deleted and when.

Where the money risk actually sits

A delayed deadline is not a delayed risk. The AI Act's penalty structure under Article 99 is unchanged, and it sits on top of GDPR rather than replacing it:

That middle tier is the one most SMBs should actually be thinking about, and it is where third-party AI vendors become your problem. If you deploy someone else's model, Article 25 governs what information has to pass between you β€” and "our vendor handles compliance" is not a documented position. It is an assumption. Ask for the technical documentation, the intended-purpose statement and the instructions for use, and keep them on file.

Meanwhile GDPR enforcement has not paused for any of this. Cumulative fines have passed €7.1 billion, daily breach notifications are running above 400 for the first time since 2018, and enforcement moved past Big Tech years ago β€” more fines have landed on small and mid-sized businesses since January 2023 than in the five years before it.

What to actually do between now and December 2027

Sixteen extra months is not sixteen months of nothing. It is time to do the work properly instead of in a panic. In priority order:

  1. Inventory your AI, including the tools nobody approved. You cannot classify what you have not listed. Shadow AI β€” the transcription tool one team signed up for, the model someone pasted customer data into β€” is where most SMB exposure actually lives, and it is invisible on an org chart.
  2. Classify each system against Annex III and document the reasoning, even when the answer is "not high-risk". The classification itself is something you are expected to be able to show. The narrowed safety-component definition means some systems that looked in scope in 2025 are now out β€” write down why.
  3. Put the December 2026 dates in the calendar now. The new Article 5 prohibitions and the Article 50(2) marking rules for synthetic media arrive with no runway. If you generate or manipulate images, video or audio in any customer-facing way, that is a this-quarter question, not a 2027 one.
  4. Get vendor documentation in writing before you need it. Article 25 obligations do not wait for the high-risk deadline, and the vendors best placed to answer will get slower as December 2027 approaches, not faster.
  5. Make your DPIA process real, because the FRIA builds on it. A Fundamental Rights Impact Assessment is much harder to construct on an empty foundation. If you don't have a working DPIA process, start there.
  6. Leave the cookie banner alone β€” except for the part that is already enforceable. Don't rebuild around single-click reject or browser signals; both are currently deleted from the negotiating text. Do make sure "reject" is genuinely as easy to find and click as "accept", because that is a dark-pattern enforcement expectation under GDPR as it stands today, Omnibus or no Omnibus.
  7. Hold your Article 30 records in good order and simply note where you'd land if the 750-employee threshold survives. Don't dismantle anything on the strength of a proposal.
Free tool Human oversight is the requirement regulators will ask you to evidence, not assert. This checklist covers what that evidence looks like. Open the AI oversight checklist β†’

The bottom line

Compliance is getting simpler in some places and stricter in others, and the businesses that come out ahead will be the ones tracking both rather than picking the half they prefer.

The AI Act half is done: real dates, real relief, and real new prohibitions arriving in December with no grace period. The GDPR half is unfinished and partly stalled β€” which means anyone selling you an urgent, Omnibus-driven overhaul of your cookie banner is selling you a rebuild of something that currently does not exist in the text.

If you're not certain which side of the Annex III line your systems fall on, or whether your existing GDPR documentation would survive first contact with a regulator, that is the question worth answering first. Book a free consultation with GDPRGard β†’

Sources

Share this article

Also read:

⚠️ This article is for informational purposes only and does not constitute legal advice. For complex compliance situations, consult a qualified data protection professional. GDPR and EU AI Act requirements are subject to ongoing regulatory guidance β€” verify current obligations with your legal adviser.