Europe's AI Rules Just Got a Simplification Overhaul. Here's What Changes for Companies
Europe's approach to AI regulation is shifting from strict rules to practical clarity. The AI Omnibus, a package of amendments to the EU AI Act, has entered into force, introducing important changes designed to make compliance easier for companies navigating Europe's complex digital rulebook. Meanwhile, the European Commission is releasing detailed guidelines to clarify how AI regulations intersect with other major EU laws, addressing confusion that has plagued businesses since the AI Act took effect.
What Is the AI Omnibus and Why Does It Matter?
The AI Omnibus represents Europe's first major attempt to simplify its flagship AI regulation after real-world implementation revealed gaps and contradictions. Rather than waiting years for a complete overhaul, EU policymakers introduced targeted amendments to address the most contentious issues. The Commission is also working on a companion package called the Digital Omnibus, which is still being shaped by the Irish Presidency of the Council and members of Parliament as they work toward a trilogue, the final negotiation stage where the European Parliament, Council, and Commission reach agreement.
The simplification effort extends beyond just amending existing rules. The European Data Protection Board, the independent body that oversees data privacy across the EU, is launching a project to clarify how the General Data Protection Regulation (GDPR), which governs personal data, intersects with other EU digital laws. This includes the AI Act, the Digital Markets Act (which regulates large tech platforms), and the Digital Services Act (which sets safety standards for online platforms).
Which Intersection Points Are Creating the Most Confusion?
Two major areas of confusion have already surfaced. First, companies are struggling to understand how pseudonymized data, which has identifying information removed, should be treated under both the GDPR and the AI Act. Second, businesses are unclear about the rules governing how personal data can be used to train AI systems. These questions matter because they determine what data companies can legally use and how they must protect it.
The Commission has already released draft guidance on how the Digital Markets Act and the GDPR work together, and final guidelines on the interplay between the Digital Services Act and the GDPR were published recently. However, experts warn that further clarification may be needed soon, as new EU initiatives like the EU Kids Act and the upcoming Digital Fairness Act will create additional intersection points with both the GDPR and the Digital Services Act.
How to Navigate Europe's Evolving AI Compliance Landscape
- Monitor Guideline Releases: The European Data Protection Board and Commission are publishing guidance documents on how different EU laws interact. Companies should track these releases and update their compliance programs accordingly, as they provide official interpretations that regulators will use to enforce the rules.
- Prepare for Multiple Regulatory Layers: AI systems in Europe must comply with the AI Act, GDPR, Digital Services Act, Digital Markets Act, and potentially the EU Kids Act if they involve minors. Compliance teams should map which laws apply to their specific products and data practices rather than treating each law in isolation.
- Engage in the Legislative Process: The Digital Omnibus and other pending laws are still being negotiated. Companies with significant EU operations should participate in public consultations and industry working groups to help shape final rules before they become binding.
- Invest in Data Governance: The confusion around pseudonymized data and personal data use in AI training suggests that robust data governance frameworks will become essential. Companies should document how they collect, store, and use data for AI purposes to demonstrate compliance with multiple overlapping regulations.
What's Driving Europe's Shift Toward Simplification?
European Commission President Ursula von der Leyen has made simplification a priority, identifying AI as the "second tipping point of our times," alongside climate change. During her State of the Union speech in September, von der Leyen emphasized that Europe's approach to AI focuses on managing risks while preserving human agency and ensuring that AI brings benefits to society.
The simplification effort reflects a practical reality: the AI Act, which took effect in phases starting in 2024, created compliance challenges that many companies found difficult to navigate. Rather than abandoning the regulation, EU policymakers are refining it through targeted amendments and detailed guidance. This approach allows Europe to maintain its commitment to AI safety and accountability while making the rules more workable for businesses.
The Commission is using multiple tools to achieve this goal. Beyond the Omnibus amendments, it is issuing implementing and delegated acts that clarify how specific rules work in practice. For example, two implementing acts under the European Health Data Space were adopted in September, explaining how cross-border health data sharing will function and what metadata health data holders must provide.
"In Europe, AI is able to bring benefits because of the established guardrails and, most importantly, because the focus is on human agency," von der Leyen stated during her address.
Ursula von der Leyen, European Commission President
The challenge ahead is substantial. As new laws like the EU Kids Act and Digital Fairness Act move through the legislative process, they will create new intersection points with existing regulations. The European Data Protection Board and Commission will need to continue releasing guidance to help companies understand how to comply with multiple overlapping rules simultaneously. For now, businesses operating in Europe should view the Omnibus amendments and emerging guidelines as the beginning of a longer process of regulatory clarification rather than a final answer.