Kolsetu Logo
Back to Blog
Blog

Half an Omnibus

The EU says it simplified AI Act, GDPR, and cybersecurity reporting. Half of that's true. Here's which half, what still needs doing, and I do apologies in advance for the ranting.

Yves-Philipp RentschYves-Philipp Rentsch
11 min read
September 30, 2026

A quick note before we start swinging: none of this is against GDPR, the AI Act, the CRA, NIS2, or DORA on principle. They are good rules, built for real reasons, and I genuinely support them! What earns the jokes is the process: four overlapping report forms for one incident, and a portal that would fix exactly that, sitting stalled in committee. We are not seeing the end of the tunnel, we best case have an extension of the tunnel or a train racing towards us.

So, let's get started.

If you've seen headlines saying the EU "simplified" the AI Act, GDPR, and cybersecurity reporting all at once, that's not quite what happened, which will surprise absolutely nobody who's dealt with the EU before. One part of that story is done and in force, with actual dates attached. The other part is still a proposal sitting in negotiation, the EU legislation equivalent of that person who after gymnasium went for a soul finding gap year with daddy's credit card. If you're lucky, it was really worth it and we all benefit, but that chance is about as high as me comprehending quantum physics, and I've made my peace with both outcomes.

What the Digital Omnibus actually is

The Commission put forward one big package on 19 November 2025, aimed at cutting overlapping paperwork across the AI Act, GDPR, ePrivacy, the Data Act, NIS2, and DORA. The pitch was reasonable, refreshingly so for this sort of thing: right now, one security incident can trigger separate reports under NIS2, DORA, GDPR, and the CRA, each with its own form, its own deadline, its own font, presumably, because at this point nothing would surprise me. The Omnibus wants a single report, routed to whoever needs it. A genuinely good idea, the regulatory equivalent of someone finally suggesting the family WhatsApp doesn't need four separate group chats for the same argument, bless whoever proposed it.

Good idea. Big package. Then, under pressure from an approaching deadline nobody was going to hit, it split, like a couple filing for an amicable but rushed separation because one of them had somewhere urgent to be and the other one was still deciding what it wanted to do with its life, possibly over a gap year, possibly on daddy's credit card, we've been over this.

The part that's done

The AI Act half got peeled off and fast-tracked, because the original high-risk deadline, 2 August 2026, was closing in and essentially nobody was going to be ready, which the EU eventually noticed, several months later than everyone who actually had to comply with it did, in a display of institutional self-awareness roughly on par with a smoke alarm going off after the toast's already binned. That half moved fast by Brussels standards, which still means the better part of a year: political agreement 7 May, Council approval 29 June, in force 27 July 2026. Real dates, actual Official Journal publication, no more asterisks, which for EU legislation counts as a personality trait, and frankly a rare one.

  • Standalone high-risk systems under Annex III (hiring tools, credit scoring, biometric identification), originally due 2 August 2026, now have until 2 December 2027. Sixteen months of extra runway, granted with all the calm confidence of a regulator who set the original deadline without checking whether anyone could actually hit it, then acted surprised when nobody did, rather like scheduling a dinner party for eight and discovering, on the day, that the oven's never worked.
  • High-risk AI embedded in regulated products under Annex I (medical devices, machinery, toys with AI components) moves from 2 August 2027 to 2 August 2028. The toys got an extra year too. Somewhere a smart teddy bear is breathing a sigh of relief it does not yet have the capacity to feel, which is arguably the least concerning thing about a smart teddy bear.
  • National regulatory sandbox deadlines shift from 2 August 2026 to 2 August 2027. The sandboxes, ironically, needed their own extension to get built, roughly the legislative equivalent of a playground still under construction the week the ribbon cutting was scheduled. Somewhere, a very patient toddler is still waiting, and frankly has more patience with this process than I do.
  • Article 50 transparency obligations, telling users they're talking to a chatbot, labelling deepfakes, did not move. Still 2 August 2026. The one deadline the EU decided not to be generous about is the one asking companies to just be honest. Draw whatever conclusion you like, I certainly have, quietly, over tea.
  • AI literacy obligations survived an earlier draft that proposed cutting them entirely, then didn't. If a vendor told you that requirement quietly died in negotiations, they were either wrong or hoping you wouldn't check, and either way, fix that internally before an auditor does it for you, less politely and with a findings report attached, the compliance equivalent of your mother finding out from a neighbour.
  • A new provision lets providers process sensitive data specifically to detect and correct bias in their own systems, closing a gap where GDPR's Article 9 had, with characteristic EU efficiency, made it technically easier to accidentally build a discriminatory model than to legally check whether you had. Marvellous system, that.
  • Prohibited practices and GPAI obligations, live since February and August 2025 respectively, didn't move an inch. The relief only covers the deadlines that were provably unworkable, not a general amnesty for anyone hoping the whole Act got quietly shelved. It didn't. Nice try, though. A for effort.

The part that isn't

Here's where most of the confusion is coming from, including in vendor security questionnaires already assuming this exists. The other half of the Omnibus, the GDPR, ePrivacy, NIS2, and DORA amendments, including the single incident-reporting portal that would actually fix the four-forms-one-incident problem, is still being negotiated. Not adopted. Not in force. A proposal, exactly where it's been sitting since November, still finding itself while its more focused sibling got a job, a flat, and a fixed compliance date, and frankly the emotional distance between the two halves of this family is starting to show.

So the unified portal everyone's excited about doesn't exist yet. It might, eventually, on Brussels time, which is a unit of measurement somewhere between "soon" and "ask again next legislature," and bears roughly the same relationship to a calendar as "I'll be there in five minutes" does when it's your mate telling you. Real momentum, genuinely good idea, currently indistinguishable from vapourware if you're the one trying to build a compliance process around it today, and the closest thing to a punchline this whole package has, a fix everyone agrees is needed, sitting in a drawer while the fires it was meant to put out keep needing four separate extinguishers, purchased separately, from four different suppliers, none of whom talk to each other.

Why the split matters for anyone running compliance

Two mistakes are easy to make here, and both show up in actual risk registers, not just hypothetically.

The first is assuming relief where there isn't any. If your organisation is still filing incidents separately under NIS2, DORA, and GDPR because the unified portal hasn't materialised, that's not you falling behind, that's you correctly reading a document that says "proposal," which is more than can be said for some people. If anyone tells you they've switched to a single unified report, ask which regulation authorised that. The honest answer right now is none of them, and if they can't name one, they read a press release and mistook EU optimism for EU law, an extremely common and forgivable error, given how often the EU does the same thing to itself.

The second is assuming the whole package is still hypothetical because half of it is. If your AI governance calendar still has 2 August 2026 sitting on it, or your literacy training quietly stopped on a rumour, both are live obligations under the half that actually passed, in force since 27 July 2026. Check your tracker against that date, not the original deadline, and not the general vibe of "surely it's all been pushed back," which is doing a lot of unearned work in a lot of compliance functions right now, mostly by people who'd very much like it to be true and haven't gone looking for the part that proves it isn't. Hope is not a compliance strategy, however comforting it feels at 4pm on a Friday.

The practical move: for anything AI Act related, work from the amendment in force since 27 July 2026, cite the specific dates above, they're real. For anything about a unified incident report across NIS2, DORA, GDPR, and the CRA, keep every channel open and every deadline live until you see it published, not previewed, not "provisionally agreed," published. A press release is not a legal basis, however confidently it's written, and however many LinkedIn carousels have been built around it since, complete with a stock photo of someone pointing at a whiteboard.

Where this left us

We sit on both sides of this one, which is either an advantage or a headache depending on the week, and lately it's mostly been the latter with occasional flashes of the former. Kolsetu is Provider under the AI Act, because Elba goes out into the world under our name, and Deployer, because we use third-party AI tooling internally like everyone else pretending they don't. Most companies get to pick a seat. We got assigned both, and nobody asked if we wanted the extra homework, which is very on brand for this entire regulatory saga.

So when the Omnibus landed, it didn't just change a date on a slide somewhere, it meant re-running the actual classification work, across all deployment scenarios, checking which ones ever came near an Annex III category and which very much did not. We'd already done that exercise once, under the original August 2026 deadline, which meant redoing it wasn't starting from nothing, it was checking whether sixteen months of extra runway changed any answer we'd already committed to paper. It didn't, which was either reassuring or slightly anticlimactic, we've genuinely not decided which, and revisiting a finished classification memo purely to confirm it's still finished is a very specific kind of admin joy nobody warns you about going into compliance work, somewhere between filing your tax return early and being told the deadline moved anyway.

The Article 50 side stayed untouched by all of this, which we'd already built for and which nobody in Brussels felt like softening, so disclosure stays disclosure, no delay, no small print. We'd also already signed Section 1 of the EU's Code of Practice on Transparency back in July, which meant that particular box was ticked before the Omnibus even finished negotiating its own timeline, a rare case of being ahead of a deadline that then moved anyway, which is a strange kind of victory but we'll take it, mostly because victories in this line of work are rare enough that you don't get to be picky about their size, or indeed their timing.

None of that makes the second half of the Omnibus, the NIS2, DORA, and GDPR piece, any more finished than it is for anyone else. We're tracking it the same way we'd recommend you do: filing under every regime that currently requires it, watching for the actual Official Journal entry, and not touching a word of our incident reporting process until there's an obligation to touch it for. Restraint, in this case, being the only sensible policy, and also rather the point of the whole exercise.

So what do you actually do with this

Don't relax on anything until you've checked which track it's on. The AI Act amendments are law, use them, the deadline relief and the lighter registration are real and your organisation is entitled to both. The rest of the package, the part that would actually simplify your reporting obligations across multiple regimes at once, isn't law yet, so keep running the tedious four forms version until it is, and be the one person in the room who knows the difference when someone else confidently assumes otherwise. There's always one person in every incident call who insists the unified portal exists because they read a hopeful LinkedIn post in May. Don't let that be you, and don't let it be your DPO either, they've had a long enough year already without inheriting somebody else's optimism as fact. Half a simplification package is still, by definition, not simplified, and mistaking Brussels' good intentions for finished legislation is how organisations end up either missing a live obligation or building an entire process around a portal that, as of writing, is still a PDF, not a website. Rather like being promised the bathroom would be done by Christmas. Any Christmas, apparently. No further specificity offered.

About the Author

Yves-Philipp Rentsch

Yves-Philipp Rentsch

Yves-Philippe is Kolsetu's CISO and DPO with nearly two decades of experience in information security, business continuity, and compliance across finance, software, and fintech. Outside his day-to-day work, he enjoys writing about cybersecurity, data privacy, and the occasional industry rant - usually with the goal of making complex security topics a bit more understandable.

Recent Articles

Keep Exploring

Jump to related comparisons and industry pages for deeper context.

Get started today

Ready to put your
phones on autopilot?

See how Elba handles calls, WhatsApp, and SMS for regulated teams — no commitment required.