If your business spent the last few years building a GDPR programme, 2026 is the year the ground started moving again. Between the European Commission's Digital Omnibus and a substantial rewrite of the EU AI Act's timeline, the rulebook European SMBs worked hard to learn is being redrawn in real time.
There is one thing almost every summary of this gets wrong, though, and it will cost you if you plan around it. The Digital Omnibus is not one law. It is two separate files moving at completely different speeds β and only one of them has actually landed.
The Digital Omnibus is two files, not one
When the Commission published the Digital Omnibus package on 19 November 2025, it split the work in two:
- The AI Omnibus β amendments to the EU AI Act. This is finished. The Council gave final approval on 29 June 2026 and it was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. The deadlines below are law, not proposals.
- The Data Omnibus β amendments to GDPR, the ePrivacy Directive, NIS2 and the Data Act. This is still in negotiation, and several of its most talked-about provisions were deleted from the Council's own working text in June 2026.
Almost every "what's changing in GDPR" article you'll read conflates the two. The practical consequence is real: businesses are deferring AI Act work that is now genuinely deferred (fine), while simultaneously planning cookie banner rebuilds around a mechanism that is currently not in the text at all (not fine).
What is already law: the AI Act deadlines that moved
If you use or deploy AI in hiring, credit scoring, education, essential services or similar contexts, you were staring down 2 August 2026. That deadline is gone.
Standalone high-risk systems under Annex III β recruitment and worker-management tools, creditworthiness assessment, access to essential public and private services, biometric categorisation, education scoring β now have until 2 December 2027. That is a 16-month extension, granted largely because the harmonised technical standards that were supposed to make compliance achievable arrived late.
AI embedded in regulated products under Annex I moves to 2 August 2028. AI systems used by public authorities have until 2 August 2030 regardless of category.
Alongside the delay came genuine simplification, and two pieces matter for smaller organisations:
- The "safety component" definition was narrowed. A component now only pulls a system into high-risk territory if its intended purpose is preventing or mitigating risks to health and safety. AI used purely for user assistance, performance optimisation or convenience is out. A recommendation engine tuning throughput on a production line is no longer swept in by default.
- AI literacy softened from a guarantee to an effort. Article 4 previously required you to ensure a sufficient level of AI literacy among staff. You now need to support its development. That is a meaningful difference for a twelve-person company with no training department β though note the obligation itself has applied since February 2025 and did not go away.
There is also a new "small mid-cap" category β under 750 employees and β¬150M turnover β that gets access to simplified compliance templates and to the regulatory sandboxes. If you sit between the SME threshold and that ceiling, this is the first time the AI Act has offered you anything.
What did not move β and one new prohibition with no grace period
The delay is narrower than the headlines suggest. Three things stayed exactly where they were:
- Article 50 transparency duties still applied from 2 August 2026. If your chatbot talks to customers, or you generate synthetic media, people have to be told. This was never part of the high-risk package. The one concession: providers of generative AI systems already on the market before 2 August 2026 have until 2 December 2026 for the machine-readable marking requirements under Article 50(2).
- The Article 5 prohibitions remain in force β they have applied since February 2025.
- Two new prohibitions take effect on 2 December 2026, with no transition period at all. AI systems that generate or manipulate child sexual abuse material, and systems that generate realistic intimate imagery of an identifiable person without their explicit consent, are banned outright.
That second prohibition is broader than it first appears, and it is the one most likely to catch an ordinary business by surprise. It does not only target purpose-built "nudifier" apps. It reaches providers of general-purpose generative image, video and audio models where such output is a reasonably foreseeable and reproducible outcome and the provider has not put reasonable safeguards in place. If you build on top of a generative model and expose it to users, the question of whose safeguards apply is one worth asking your vendor in writing.
Seven plain-English guides for small European teams β including Digital Omnibus Explained and EU AI Act, Without the Scare Tactics, which takes the ten myths small teams keep hearing (starting with the β¬35M figure that does not apply to most of them) and gives the real answer. Instant download, one payment.
The GDPR half: still a proposal, and partly stalled
Now the part that is not settled, and where planning ahead is genuinely risky.
The Data Omnibus proposed several changes that would matter a great deal to SMBs. The record-keeping exemption under Article 30(5) would rise from fewer than 250 employees to fewer than 750, subject to financial ceilings, and the blanket disqualification for any processing of special category data would be replaced with a risk-based test. That piece has institutional support and is the most likely to survive close to its current form.
The rest is a different story:
- Cookie consent reform is out of the Council's working text. The single-click reject button, the six-month moratorium after a refusal, and the browser-level preference signals were all deleted from the presidency's compromise text in June 2026 after member states could not agree. Even that pared-back text failed to reach a qualified majority.
- The AI legitimate-interest clarification went with it. The language explicitly confirming that Article 6(1)(f) can support AI training was removed in the same round. Organisations relying on legitimate interest for AI processing are exactly where they were in November 2025: it works if the balancing test is genuinely done and documented, and there is still no express provision saying so.
- Narrowing the definition of personal data drew the strongest pushback of all. In their Joint Opinion 2/2026 of 10 February 2026, the EDPB and EDPS urged co-legislators not to adopt it, warning it goes far beyond a targeted or technical amendment and would weaken established case law.
The operational proposals β extending breach notification from 72 to 96 hours, harmonising DPIA guidance across member states β are still on the table but unresolved. The EDPB and EDPS were more receptive to those, while insisting that independent regulators rather than the Commission should own the technical detail like breach templates and DPIA methodology.
The honest summary for an SMB: nothing in the GDPR half is something you can build against yet. Parliament's own impact study was due in October 2026, and final adoption before the end of 2026 looks unlikely β which makes real implementation a 2027 story at the earliest.
We covered this half in detail in Inside the EU's Digital Omnibus, including exactly which articles were deleted and when.
Where the money risk actually sits
A delayed deadline is not a delayed risk. The AI Act's penalty structure under Article 99 is unchanged, and it sits on top of GDPR rather than replacing it:
- Up to β¬35M or 7% of global annual turnover for prohibited practices under Article 5 β the tier the two new December 2026 prohibitions fall into
- Up to β¬15M or 3% for breaching obligations that apply to providers, deployers, importers and distributors β including the Article 25 value-chain duties covering what has to flow between you and your partners
- Up to β¬7.5M or 1% for supplying incorrect or misleading information to regulators
That middle tier is the one most SMBs should actually be thinking about, and it is where third-party AI vendors become your problem. If you deploy someone else's model, Article 25 governs what information has to pass between you β and "our vendor handles compliance" is not a documented position. It is an assumption. Ask for the technical documentation, the intended-purpose statement and the instructions for use, and keep them on file.
Meanwhile GDPR enforcement has not paused for any of this. Cumulative fines have passed β¬7.1 billion, daily breach notifications are running above 400 for the first time since 2018, and enforcement moved past Big Tech years ago β more fines have landed on small and mid-sized businesses since January 2023 than in the five years before it.
What to actually do between now and December 2027
Sixteen extra months is not sixteen months of nothing. It is time to do the work properly instead of in a panic. In priority order:
- Inventory your AI, including the tools nobody approved. You cannot classify what you have not listed. Shadow AI β the transcription tool one team signed up for, the model someone pasted customer data into β is where most SMB exposure actually lives, and it is invisible on an org chart.
- Classify each system against Annex III and document the reasoning, even when the answer is "not high-risk". The classification itself is something you are expected to be able to show. The narrowed safety-component definition means some systems that looked in scope in 2025 are now out β write down why.
- Put the December 2026 dates in the calendar now. The new Article 5 prohibitions and the Article 50(2) marking rules for synthetic media arrive with no runway. If you generate or manipulate images, video or audio in any customer-facing way, that is a this-quarter question, not a 2027 one.
- Get vendor documentation in writing before you need it. Article 25 obligations do not wait for the high-risk deadline, and the vendors best placed to answer will get slower as December 2027 approaches, not faster.
- Make your DPIA process real, because the FRIA builds on it. A Fundamental Rights Impact Assessment is much harder to construct on an empty foundation. If you don't have a working DPIA process, start there.
- Leave the cookie banner alone β except for the part that is already enforceable. Don't rebuild around single-click reject or browser signals; both are currently deleted from the negotiating text. Do make sure "reject" is genuinely as easy to find and click as "accept", because that is a dark-pattern enforcement expectation under GDPR as it stands today, Omnibus or no Omnibus.
- Hold your Article 30 records in good order and simply note where you'd land if the 750-employee threshold survives. Don't dismantle anything on the strength of a proposal.
The bottom line
Compliance is getting simpler in some places and stricter in others, and the businesses that come out ahead will be the ones tracking both rather than picking the half they prefer.
The AI Act half is done: real dates, real relief, and real new prohibitions arriving in December with no grace period. The GDPR half is unfinished and partly stalled β which means anyone selling you an urgent, Omnibus-driven overhaul of your cookie banner is selling you a rebuild of something that currently does not exist in the text.
If you're not certain which side of the Annex III line your systems fall on, or whether your existing GDPR documentation would survive first contact with a regulator, that is the question worth answering first. Book a free consultation with GDPRGard β
Sources
- EDPBβEDPS Joint Opinion 2/2026 on the Digital Omnibus (10 February 2026)
- EDPB β Digital Omnibus: support for simplification while raising key concerns
- EU AI Act β Article 99, Penalties
- EU AI Act β Annex III, High-risk AI systems
- European Commission β AI Act implementation timeline
- CMS GDPR Enforcement Tracker
Also read:
- Inside the EU's Digital Omnibus: what's actually changing for GDPR
- The AI Act delay doesn't cover your chatbot
- Why every SaaS company needs a DPIA before launching AI features