post thumbnail

“Digital Omnibus” – What It Means for AI Developers and AI Users

23/06/2026

The EU is announcing the “Digital Omnibus” package as a set of alignments and simplifications across multiple digital/regulatory frameworks (e.g. AI, data, cybersecurity, platforms, consumer protection).

Message to the market: expect more clarity in obligations, stronger enforcement, and better coordination of rules — especially where AI, privacy, cybersecurity, and liability overlap.

Note: “Digital Omnibus” is still a proposal under development; specific obligations will depend on the final text and implementation timelines. However, preparation can (and should) start now — whether we like it or not, AI is already part of everyday business.

What this means if you develop AI (AI developer / provider)

1. Compliance will not be “one law = one checklist.”

The biggest challenge is overlap: AI governance + GDPR + cybersecurity + consumer rules + IP.
The Omnibus approach typically aligns obligations — so prepare integrated compliance, not isolated documents.

2. Documentation and auditability become core product assets.

It’s not enough to “have security” — you must be able to prove: risk management, testing, data quality, design logic, oversight, and model changes (change management).

3. User transparency becomes a standard (not marketing).

Expect increased requirements to clearly communicate: what the tool does, its limitations, inappropriate use cases, risks, and how outputs are monitored/corrected.

4. Contracts and role allocation: who is responsible for what.

If your tool is used in a “high-risk” context, contracts must clearly define roles, configurations, instructions for use, user obligations, incident reporting, and audit rights.

What this means if you use AI tools (AI user / deployer)

1. You can’t say: “it’s not our tool, not our problem.”

Users are increasingly expected to have their own framework: risk assessment, policies, employee training, and oversight (human-in-the-loop where needed).

2. Buying AI = buying regulatory risk.

Before procurement, you need at least basic vendor due diligence: security, privacy, data location, auditability, incident support, explainability/transparency.

3. AI in HR, marketing, and customer support is a “red zone.”

These areas often involve personal data, profiling, automated decisions, and consumer communication — requiring clear rules: when AI can be used, how it is labelled, who approves it, and how outputs are validated.

4. Internal rules for prompts and data are a must-have.

Most incidents are not hacks — but employees entering sensitive data into tools. You need a policy: what is allowed, what is not, and how anonymisation/pseudonymisation is handled.

Mini-checklist (for both groups): what to do now

  • Map where AI is used/developed and what data flows in/out
  • Establish basic AI governance (ownership, approvals, tool/model registry)
  • Standardise risk assessments (use-case by use-case)
  • Align vendor contracts: security, privacy, audit, incidents, subcontractors, data locations
  • Train employees: “AI do’s & don’ts” (especially HR/marketing/sales)
  • Implement internal policies that clearly guide employees

3 short CTAs

  1. Developing an AI tool? Let’s create a quick AI compliance blueprint (documentation + contracts + risks).
  2. Using AI tools in your company? In 2 weeks, we set up AI policy, vendor checks, and team training.
  3. Subscribe to ANVA Sharing Business Tips & Tricks: short, practical, and free — and for deeper preparation, join one of our ANVA LEGAL WORKSHOPS to learn what you need and what you can implement yourself