Connect with us

Hi, what are you looking for?

AI Cybersecurity

European Commission Proposes Targeted Changes to AI, Cybersecurity, and Data Regulations

European Commission delays high-risk AI regulations by up to 16 months and consolidates data laws to streamline compliance and foster innovation across the EU

The European Commission has unveiled its Digital Omnibus on November 19, 2025, aiming to refine the EU’s digital regulatory framework. This initiative seeks to “simplify rules, streamline procedures, offer one-stop solutions, and remove overlaps and outdated provisions,” with a concentrated focus on three pivotal areas: AI, cybersecurity, and data.

Key Changes to the AI Framework

The proposed adjustments to the AI Act are particularly noteworthy. The Omnibus outlines changes across five primary areas:

  • Implementation Timing: The application of regulations for high-risk AI systems will be delayed by a maximum of 16 months. This adjustment recognizes the “challenge that the delay of standards and other support tools cause for the implementation of the AI Act.”
  • Simplification:
    • Extending certain simplifications, such as streamlined technical documentation, to small and mid-cap companies (SMCs) alongside SMEs.
    • Mandating the Commission and Member States to promote AI literacy and ensure ongoing support for businesses.
    • Removing the requirement for a harmonized post-market monitoring plan, thereby granting businesses greater flexibility.
    • Reducing the registration burden for AI systems deployed in high-risk sectors for functions deemed non-high-risk.
  • Governance Clarity: The AI Office will gain oversight of AI systems developed using general-purpose models, as well as those integrated into very large online platforms and search engines.
  • Support Compliance:
    • Allowing providers to process special categories of personal data for bias detection and correction, with appropriate safeguards.
    • Expanding the use of AI regulatory sandboxes and real-world testing, including the establishment of an EU-level regulatory sandbox by 2028 to aid in practical testing.
  • Procedural Operability: Clarifying how the AI Act interacts with other EU legislation.

The Commission asserts that these proposals will assist businesses in fulfilling their obligations while fostering innovation within the EU, thus facilitating the creation of a single market for trustworthy AI.

Cybersecurity Developments

On the cybersecurity front, the Omnibus tackles a prominent issue: the overlapping incident reporting requirements under laws such as NIS2, GDPR, and DORA. The introduction of a single-entry point for incident notifications—managed by ENISA—will enable organizations to submit notifications through one interface, ensuring that one set of information meets multiple reporting obligations.

Data Regulation Adjustments

In terms of data regulations, the Omnibus proposes significant modifications to the GDPR and the Data Act. Notably, it consolidates the Data Governance Act, the Free Flow of Non-Personal Data Regulation, and the Open Data Directive into a single Data Act. This consolidation aims to:

  • Target exemptions from cloud-switching rules specifically for SMEs and SMCs, as well as custom data processing service providers.
  • Eliminate mandatory registration and labeling for data intermediation service providers, thereby lowering market entry barriers.
  • Simplify the data altruism framework to facilitate easier sharing of data for the public good.
  • Streamline rules governing public sector data.
  • Clarify and limit the scope of business-to-government data sharing provisions.

Additionally, alongside the Digital Omnibus, the European Commission proposed to repeal the Platform-to-Business Regulation and introduce a Data Union Strategy designed to enhance data accessibility for AI across Europe. The establishment of European business wallets is also part of this initiative, aiming to simplify secure interactions between companies and public authorities across the EU.

Looking Ahead

These legislative proposals will now advance to the European Parliament and Council for approval. Concurrently, the Commission will conduct a Digital Fitness Check to evaluate the cumulative impact of these digital regulations and how they affect the EU’s competitiveness.

The current discourse raises the question of whether this is indicative of a shift from the “Brussels effect” to a “Washington effect,” suggesting a broader deregulatory trend. However, this interpretation may overlook the nuanced and technical nature of the proposals, which remain in their early stages pending approval. The adjustments primarily appear to be procedural refinements rather than a fundamental rethinking of the core architecture of the AI Act.

Ultimately, the adjustments signal a recognition of the complexities surrounding the implementation of AI regulations, acknowledging that robust enforcement will require time and a measured approach.

Rachel Torres
Written By

At AIPressa, my work focuses on exploring the paradox of AI in cybersecurity: it's both our best defense and our greatest threat. I've closely followed how AI systems detect vulnerabilities in milliseconds while attackers simultaneously use them to create increasingly sophisticated malware. My approach: explaining technical complexities in an accessible way without losing the urgency of the topic. When I'm not researching the latest AI-driven threats, I'm probably testing security tools or reading about the next attack vector keeping CISOs awake at night.

You May Also Like

AI Education

Educators must define the purpose of education to avoid AI tools like ChatGPT reducing student growth to just 20% of their potential learning outcomes.

AI Regulation

Congress is considering federal preemption of state AI laws to create a unified regulatory framework, preventing chaos from 50 different state regulations.

Top Stories

The EU's AI Act mandates strict regulations for high-risk AI systems, with full compliance required by August 2026, impacting tech firms across Europe.

AI Business

AI-driven telemedicine solutions significantly enhance healthcare accessibility, enabling remote diagnostics for underserved populations and predicting chronic disease risks before they manifest.

Top Stories

Amazon unveils a $50 billion initiative to enhance AI and supercomputing for federal agencies, adding 1.3 GW of computing power by 2026.

AI Research

UCLA Health researchers warn that AI stroke and seizure detection tools risk worsening health disparities, emphasizing the need for diverse training data to ensure...

AI Marketing

Mindtrip partners with The Bahamas to revolutionize travel with AI-driven itineraries, enabling personalized trip planning in seconds for seamless visitor experiences.

Top Stories

EU officials approve the AI Act, banning unacceptable AI systems and imposing fines up to €35 million, setting a global standard for AI regulation...

© 2025 AIPressa · Part of Buzzora Media · All rights reserved. This website provides general news and educational content for informational purposes only. While we strive for accuracy, we do not guarantee the completeness or reliability of the information presented. The content should not be considered professional advice of any kind. Readers are encouraged to verify facts and consult appropriate experts when needed. We are not responsible for any loss or inconvenience resulting from the use of information on this site. Some images used on this website are generated with artificial intelligence and are illustrative in nature. They may not accurately represent the products, people, or events described in the articles.