On 19 November 2025, the European Commission presented the Digital Omnibus package—proposals COM(2025) 835, 836 and 837. Behind this bureaucratic and seemingly technical label lies what is, in fact, the most ambitious and politically sensitive legislative project of the European Union’s new digital policy cycle. It is a “horizontal” reform package that simultaneously affects the main pillars of the EU’s single market for data: the GDPR, the AI Act, the Data Act and the Data Governance Act.
Brussels’ stated objective is crucial and responds to strong pressure from the business community: to reduce administrative burdens and compliance costs by 25% for large companies and by 35% for small and medium-sized enterprises (SMEs). The starting point is, after all, one of undeniable regulatory fragmentation. European businesses are required to navigate a complex landscape of approximately 100 laws focusing on the technology sector, while supervision is divided among more than 270 regulatory authorities across the 27 Member States. This inevitably creates overlaps, conflicts of jurisdiction and profound legal uncertainty.
However, as Member of Parliament Giulia Pastorella promptly pointed out, the proposal suffers from a methodological weakness: it combines within a single text three fundamentally different types of intervention. These include genuine measures of bureaucratic simplification—such as the establishment of a single portal for reporting cybersecurity incidents, intended to streamline the notification channels provided for under NIS2 and DORA—mere technical postponements of deadlines and, finally, a genuine structural reform of citizens’ rights.
The GDPR under pressure: redefining personal data
Unsurprisingly, the proposed amendments affecting the General Data Protection Regulation (GDPR) are the most controversial among legal scholars and academics. The proposal introduces a conceptual shift by adopting a markedly subjective criterion for the definition of “personal data” itself. Under this new approach, information would cease to be regarded as personal data where the specific entity holding it does not have reasonable economic or technological means of identifying the natural person concerned.
Supporters of the reform argue that privacy protection should safeguard real individuals against the concrete risks to which they are exposed, rather than protecting data in the abstract. This view would be consistent with a pragmatic interpretation of the case law of the Court of Justice of the European Union, particularly the Deloitte judgment.
By contrast, critics and consumer organisations see this aspect of the proposal as an extremely dangerous loophole. A concrete example illustrates the risk. A vast pseudonymised health database could be legally regarded as “anonymous” by the research company that created it and could therefore be freely traded on the market. A subsequent purchaser—such as a major banking group or insurance company—could combine these apparently anonymous data with the commercial databases already in its possession and thereby reconstruct the health profiles of individual citizens. This could lead to insurance policies or mortgages being denied on the basis of underlying medical vulnerabilities.
Constitutional law scholar Oreste Pollicino has described this development as a genetic mutation of the European model: a shift from preventive, objective and universal protection to a purely functional approach in which the scope of protection depends on the technological and economic power of the entity processing the information.
This is accompanied by a significant easing of procedural requirements. The threshold triggering the obligation to notify personal data breaches would rise from the existence of a general “risk” to that of a demonstrated “high risk”, while the notification deadline would be extended from 72 to 96 hours. In practice, this would reduce both the timeliness and the supervisory capacity of national data protection authorities.
The AI Act: a new timetable of strategic postponements
With regard to artificial intelligence, the provisional agreement reached on 7 May 2026 under Omnibus VII radically revised the timetable and the gradual implementation of the AI Act. The imminent and non-deferrable deadlines remain those originally established for 2025 in relation to unacceptable-risk systems—such as social-scoring systems and certain forms of real-time remote biometric identification—and to new general-purpose AI models entering the market for the first time.
For the remainder of the AI sector, however, a series of postponements has been introduced with the aim of giving the technology industry more time to adapt:
2 August 2026: the general transparency obligation for AI systems that interact directly with human beings formally becomes applicable.
2 December 2026: the obligation to label or watermark AI-generated content enters into force, together with an absolute prohibition on “nudifier” applications—software designed to create non-consensual pornographic material or artificial nude images.
2 August 2027: compliance obligations become applicable to widely deployed general-purpose AI models placed on the market before 2025, including the architectures underlying ChatGPT, Claude and Gemini.
2 December 2027: the stringent requirements governing stand-alone high-risk systems become binding, including systems used in sensitive areas such as biometrics, employment management and law enforcement.
2 August 2028: the obligations applicable to AI systems integrated as safety components into physical products and machinery enter into force, including advanced industrial robotics and life-saving medical devices.
On the one hand, these technical postponements are largely justified by the persistent delays affecting the preparation of harmonised technical standards by the European standardisation bodies CEN and CENELEC. On the other hand, legal scholars are concerned by the transfer of powers towards the political executive.
The European Commission will, in fact, be granted extensive powers to restrict certain obligations or introduce exemptions through delegated acts. This would concentrate effective governance around the AI Office while reducing parliamentary scrutiny.
The geopolitical dimension and the Italian case
No legal analysis of the Digital Omnibus can disregard the broader international macroeconomic context. Donald Trump’s return to the White House and the aggressive deregulatory and “exceptionalist” approach adopted by the US administration in the field of artificial intelligence are placing intense pressure on regulators in Brussels.
The infrastructure gap between the two sides of the Atlantic has now become enormous. According to current estimates, the United States will invest approximately five times more than the entire European Union in data centres and supercomputing by 2030.
The “simplification” introduced by the Digital Omnibus therefore risks being perceived by international observers not as an autonomous strategic choice, but as a partial diplomatic and economic retreat intended to reassure US Big Tech companies and encourage them to maintain their presence in Europe.
Within this complex macro-regional environment, Italy occupies a particularly delicate institutional position. Its national legislation on artificial intelligence—Law No. 132, definitively approved in September 2025—was intended to anticipate and strengthen the implementation of the relevant EU regulations. Yet it may already require substantial amendment, or even a complete rewrite, in light of the new temporal and substantive parameters introduced by the Omnibus package.
Italy may be required to redesign its domestic governance architecture from the ground up. It will be necessary to overcome the latent conflicts and overlaps among the existing independent authorities: AGCOM, responsible for media and market-related matters; the Italian Data Protection Authority, responsible for individual rights and personal data protection; and the National Cybersecurity Agency, responsible for infrastructure resilience.
These functions may have to converge towards the designation of a single national Digital Coordinator capable of engaging with the increasingly centralised governance infrastructure in Brussels.
Conclusions
Ultimately, the Digital Omnibus does not formally dismantle the protective architecture established by the AI Act or the GDPR, which remain the nominal cornerstones of European digital regulation. Nevertheless, it produces a silent, pragmatic and incremental erosion of some of their most stringent underlying principles.
Europe therefore faces its greatest and most dramatic political question: is it still possible to defend and finance a regulatory “third way” based on the primacy of fundamental human rights, or will global economic competition and severe geopolitical pressure force the continent gradually to sacrifice the historic protections afforded to its citizens?