09/09/2026
Europe’s AI rulebook was supposed to do something ambitious: make artificial intelligence safer while making Europe more competitive. That balance has been challenging from the start. The AI Act introduced obligations for companies developing and deploying AI, while promising that clear rules would ultimately create trust and a level playing field. As implementation gets closer, a different problem is becoming harder to ignore: what happens when the rules themselves become too complicated to work as intended?
The Digital Omnibus was presented as part of the answer and yet it might have complicated things even further. It was adopted by the European Parliament in June 2026 and promised simplification, reduced administrative burdens and more breathing room for businesses and organisations.
A delay is not a solution
One of the Omnibus’ biggest changes is for several AI Act deadlines to be pushed back. For certain high-risk AI systems, compliance has moved from 2026 to 2027. Other high-risk systems get until 2028. Some transparency requirements have also been delayed. Some of the infrastructure needed to make the AI Act function is still being built. European standards are not yet fully in place and qualified bodies able to carry out conformity assessments remain limited. Moreover, companies can still face uncertainty about which rules and authorities apply to them. This is inconvenient for smaller organisations, as large technology companies can afford lawyers, compliance teams and consultants to work their way through complex regulatory frameworks, while a start-up or civil society organisation does not have the same resources. When regulation becomes difficult to navigate, complexity itself can become a barrier to participation.
A battle between “regulation” and “innovation”
The AI Act is often discussed as a battle between “regulation” and “innovation” but that framing misses the point: the question is 1) who can (realistically) comply with it, 2) who can understand it, and 3) who gets left out when the system becomes too difficult to navigate. AI systems increasingly affect access to education, employment, public services, policing and other areas of everyday life. If oversight depends on a complicated architecture that only well-resourced actors can navigate, the people most affected by these systems may have the least capacity to challenge them. Proper regulation therefore needs to be understandable, enforceable and most importantly, accessible.
Sandboxes could have been a real opportunity
The Digital Omnibus reform creates an EU-level regulatory sandbox, managed by the AI Office, with priority access for SMEs, start-ups and small mid-cap companies, and Member States also get more time to establish national sandboxes. The idea is promising, as instead of leaving companies to figure out the rules alone, sandboxes can bring regulators and developers together to test how regulation works in practice. Done properly, they could help identify problems before they become systemic ones.
Questions remain about how the AI Office will work with national authorities and data protection regulators. The European Data Protection Board and European Data Protection Supervisor have already raised concerns about the role of data protection authorities when personal data is processed in the EU sandbox. A sandbox should not become a regulatory shortcut but a place where regulators learn, companies receive meaningful guidance, and fundamental rights are properly tested in practice.
Europe should not have to choose between rights and innovation
There is a tendency to present any attempt to reduce regulatory burdens as a victory for industry and a threat to fundamental rights. Europe does need a competitive AI ecosystem that also protects fundamental rights. In fact, a regulatory system that is unpredictable or excessively burdensome can strengthen the position of precisely those actors regulation is supposed to hold accountable. The largest companies are often best equipped to absorb compliance costs: smaller competitors, researchers and civil society actors are not. However, the Digital Omnibus does contain some meaningful changes, for example, the new prohibition on AI systems designed to generate non-consensual intimate imagery, which addresses a concrete and growing harm. It shows what effective regulation can look like: identifying a real problem and putting meaningful protections in place. That should be the direction Europe takes next.
The Digital Omnibus has given Europe more time. The real test now is whether Brussels uses it to make the AI Act work better for everyone, not just those with the resources to navigate it.