{"id":261,"date":"2026-06-23T20:12:40","date_gmt":"2026-06-23T18:12:40","guid":{"rendered":"https:\/\/anvaconsulting.eu\/digital-omnibus-sto-znaci-za-ai-developere-i-ai-korisnike\/"},"modified":"2026-07-20T14:19:49","modified_gmt":"2026-07-20T12:19:49","slug":"digital-omnibus-what-it-means-for-ai-developers-and-ai-users","status":"publish","type":"post","link":"https:\/\/anvaconsulting.eu\/en\/digital-omnibus-what-it-means-for-ai-developers-and-ai-users\/","title":{"rendered":"\u201cDigital Omnibus\u201d \u2013 What It Means for AI Developers and AI Users"},"content":{"rendered":"<p>The EU is announcing the \u201cDigital Omnibus\u201d package as a set of alignments and simplifications across multiple digital\/regulatory frameworks (e.g. AI, data, cybersecurity, platforms, consumer protection).<\/p>\n<p><strong>Message to the market:<\/strong> expect more clarity in obligations, stronger enforcement, and better coordination of rules \u2014 especially where AI, privacy, cybersecurity, and liability overlap.<\/p>\n<p><em>Note: \u201cDigital Omnibus\u201d is still a proposal under development; specific obligations will depend on the final text and implementation timelines. However, preparation can (and should) start now \u2014 whether we like it or not, AI is already part of everyday business.<\/em><\/p>\n<h2 style=\"text-align: center;\">What this means if you develop AI (AI developer \/ provider)<\/h2>\n<h2>1. Compliance will not be \u201cone law = one checklist.\u201d<\/h2>\n<p>The biggest challenge is overlap: AI governance + GDPR + cybersecurity + consumer rules + IP.<br \/>\nThe Omnibus approach typically aligns obligations \u2014 so prepare integrated compliance, not isolated documents.<\/p>\n<h2>2. Documentation and auditability become core product assets.<\/h2>\n<p>It\u2019s not enough to \u201chave security\u201d \u2014 you must be able to prove: risk management, testing, data quality, design logic, oversight, and model changes (change management).<\/p>\n<h2>3. User transparency becomes a standard (not marketing).<\/h2>\n<p>Expect increased requirements to clearly communicate: what the tool does, its limitations, inappropriate use cases, risks, and how outputs are monitored\/corrected.<\/p>\n<h2>4. Contracts and role allocation: who is responsible for what.<\/h2>\n<p>If your tool is used in a \u201chigh-risk\u201d context, contracts must clearly define roles, configurations, instructions for use, user obligations, incident reporting, and audit rights.<\/p>\n<h2 style=\"text-align: center;\">What this means if you use AI tools (AI user \/ deployer)<\/h2>\n<h2>1. You can\u2019t say: \u201cit\u2019s not our tool, not our problem.\u201d<\/h2>\n<p>Users are increasingly expected to have their own framework: risk assessment, policies, employee training, and oversight (human-in-the-loop where needed).<\/p>\n<h2>2. Buying AI = buying regulatory risk.<\/h2>\n<p>Before procurement, you need at least basic vendor due diligence: security, privacy, data location, auditability, incident support, explainability\/transparency.<\/p>\n<h2>3. AI in HR, marketing, and customer support is a \u201cred zone.\u201d<\/h2>\n<p>These areas often involve personal data, profiling, automated decisions, and consumer communication \u2014 requiring clear rules: when AI can be used, how it is labelled, who approves it, and how outputs are validated.<\/p>\n<h2>4. Internal rules for prompts and data are a must-have.<\/h2>\n<p>Most incidents are not hacks \u2014 but employees entering sensitive data into tools. You need a policy: what is allowed, what is not, and how anonymisation\/pseudonymisation is handled.<\/p>\n<p><strong>Mini-checklist (for both groups): what to do now<\/strong><\/p>\n<ul>\n<li>Map where AI is used\/developed and what data flows in\/out<\/li>\n<li>Establish basic AI governance (ownership, approvals, tool\/model registry)<\/li>\n<li>Standardise risk assessments (use-case by use-case)<\/li>\n<li>Align vendor contracts: security, privacy, audit, incidents, subcontractors, data locations<\/li>\n<li>Train employees: \u201cAI do\u2019s &amp; don\u2019ts\u201d (especially HR\/marketing\/sales)<\/li>\n<li>Implement internal policies that clearly guide employees<\/li>\n<\/ul>\n<p><strong>3 short CTAs<\/strong><\/p>\n<ol>\n<li>Developing an AI tool? Let\u2019s create a quick AI compliance blueprint (documentation + contracts + risks).<\/li>\n<li>Using AI tools in your company? In 2 weeks, we set up AI policy, vendor checks, and team training.<\/li>\n<li>Subscribe to ANVA Sharing Business Tips &amp; Tricks: short, practical, and free \u2014 and for deeper preparation, join one of our ANVA LEGAL WORKSHOPS to learn what you need and what you can implement yourself<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>The EU is announcing the \u201cDigital Omnibus\u201d package as a set of alignments and simplifications across multiple digital\/regulatory frameworks (e.g. AI, data, cybersecurity, platforms, consumer protection). Message to the market: expect more clarity in obligations, stronger enforcement, and better coordination of rules \u2014 especially where AI, privacy, cybersecurity, and liability overlap. Note: \u201cDigital Omnibus\u201d is [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":259,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[20],"tags":[],"class_list":["post-261","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tips-tricks"],"acf":[],"_links":{"self":[{"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/posts\/261","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/comments?post=261"}],"version-history":[{"count":2,"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/posts\/261\/revisions"}],"predecessor-version":[{"id":264,"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/posts\/261\/revisions\/264"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/media\/259"}],"wp:attachment":[{"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/media?parent=261"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/categories?post=261"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/anvaconsulting.eu\/en\/wp-json\/wp\/v2\/tags?post=261"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}