January 2026 Blog

AI Act 2.0? – Proposed amendments to the AI Act following the proposal for the Digital Omnibus Regulation on AI

One of two proposed regulations presented by the EU Commission on November 19, 2025, as part of the “Digital Omnibus Package,” deals with amendments to Regulation (EU) 2024/1689 (AI Act). But is this proposal really an “AI Act 2.0” – or rather a series of targeted fine-tuning measures to the current AI Act?

Background and objective of the proposal

The Digital Omnibus is part of the Commission's broader agenda to reduce regulatory burdens on European companies. The proposed changes aim to cut red tape, remove barriers to innovation, and, in particular, ease the burden on small and medium-sized enterprises (SMEs). The omnibus approach makes it possible to bundle related changes together rather than launching isolated individual amendments. In addition to the changes to the AI Act itself, the Digital Omnibus also addresses the interfaces with other legal acts, in particular the relationship with the GDPR, the Digital Services Act (DSA), the Digital Markets Act (DMA), and sector-specific regulations such as the Medical Devices Regulation or DORA. The aim is to reduce overlaps, avoid duplication of checks, and create coherent supervisory structures.

An overview of the main proposed amendments to the AI Act

With its proposed amendments to the AI Act, the EU Commission is responding to initial experiences with the AI Act in practice and, specifically, to criticism from industry and member states that the AI Act in its original form is too complex, too bureaucratic, and hardly manageable for SMEs. The targeted simplification measures are intended to make the European AI ecosystem more competitive without undermining the protection goals of the regulation.

These measures include, in particular:

  • Temporal flexibility and standardization with regard to high-risk AI systems: In the future, the start of application of the regulations for high-risk AI systems is to be linked to the actual availability of harmonized standards and support instruments. The Commission will confirm the availability of these support measures by means of a formal decision. Thereafter, transition periods of six months for Annex III systems and twelve months for Annex I systems will apply – but no later than December 2, 2027, and August 2, 2028, respectively. This will ensure that regulated entities have the necessary technical guidance before compliance obligations take effect.
  • Transition period for generative AI: Providers of generative AI systems that were placed on the market before August 2, 2026, will be granted a six-month transition period until February 2, 2027, to implement the labeling requirements for synthetic content (Art. 50 (2) AI Act).
  • Relief for small and medium-sized enterprises: The existing relief for small and medium-sized enterprises (SMEs) will be extended to small mid-cap companies (SMCs). This includes simplified documentation requirements and proportionate sanctions, taking into account economic capacity, and the option to implement certain elements of the quality management system in a simplified form.
  • Reorientation of skills promotion: The previous (unspecific) obligation for all providers and operators to ensure that their staff have sufficient AI skills (cf. Art. 4 AI Act) will be fundamentally redesigned. As this blanket approach has proven ineffective and places an additional compliance burden on smaller companies in particular, the binding obligation is to be replaced by a recommendation obligation on the part of the Member States and the Commission to encourage providers and operators to promote AI competence through training, information resources, and the exchange of best practices. In this respect, the obligation to promote AI literacy will in future lie with the Commission and the Member States. However, this will not affect the training obligations for operators of high-risk AI systems.
  • Administrative simplifications: Another proposal is to make post-market surveillance requirements more flexible by removing the harmonized monitoring plan and reducing the registration burden for providers whose systems are used in high-risk areas but only perform narrowly defined or procedural tasks.

Specifically, this means:

  • The registration requirement for AI systems in the EU database will be restricted: Providers will no longer be required to register systems that they have classified as non-high-risk in accordance with Article 6(3). However, the documentation requirement will remain in place.
  • The obligation to draw up a harmonized post-market surveillance plan will be removed. Instead, the Commission will publish guidelines that give providers more flexibility in designing their post-market surveillance systems.
  • Centralized supervision by the AI Office: The Office for Artificial Intelligence (“AI Office”) will be given extended supervisory powers. It will have exclusive responsibility for compliance with the AI Act with regard to AI systems based on general-purpose models (GPAI) or integrated into very large online platforms and search engines.The AI Office will have all the powers of a market surveillance authority, including the ability to impose sanctions. Data protection simplifications and innovation promotion: The processing of special categories of personal data will be permitted under appropriate safeguards for bias detection and correction.
  • A new Article 4a of the AI Act creates, for the first time, a clear legal basis for the processing of special categories of personal data for the purpose of detecting and correcting bias. This option applies to all providers and operators of AI systems and models, provided that strict safeguards are complied with.
  • In addition, AI real-world laboratories are to be used more intensively (which should also reinforce and promote the national draft of the Real-World Laboratory Act already presented on May 30, 2025), with the AI Office also providing an EU-wide real-world laboratory from 2028. SMEs will be given priority access to this. In addition, testing under real-world conditions is to be extended to high-risk AI systems covered by harmonization legislation.
  • Coherence of the legal framework: Targeted adjustments are intended to clarify the interaction between the AI Act and other EU legislation and to optimize procedures for improved implementation.

Assessment and outlook

Reactions to the Digital Omnibus have been mixed. Proponents welcome the reduction in bureaucracy and see it as a necessary step toward strengthening European competitiveness in the global AI race. Critics, on the other hand, warn of a weakening of the level of protection even before the AI Act has been fully implemented; consumer protection and civil rights organizations in particular are watching developments with skepticism.

From a legal perspective, it should be noted that the basic architecture of the AI Act – with its risk-based approach, prohibitions, and high-risk regime – remains untouched and that the changes primarily concern the implementation modalities and the proportionality of the obligations.

It should also be noted that this is currently only a proposal: the entire Digital Omnibus Package is currently going through the European legislative process. Following its submission by the Commission in November last year (2025), it is now up to the European Parliament and the Council, and experience shows that changes are still to be expected in the trilogue.

Companies should therefore follow developments closely and keep their compliance planning flexible. Final adoption is not expected until the middle of the year (2026) at the earliest. Despite these uncertainties, it is advisable to analyze now which of the proposed changes would affect your own AI systems and compliance structures and to set up processes in such a way that they function both under the current AI Act and under an amended version.

Conclusion: Evolution instead of revolution

It would ultimately be an exaggeration to speak of an “AI Act 2.0.” The proposal does not change the basic concept of the AI Act, but rather adjusts it in important areas and is described by the EU Commission itself as a “simplification package.” The goal is clear: less bureaucracy, more innovation – without lowering protection standards.

For companies, this means that the AI Act remains the authoritative reference for AI compliance in Europe, but the specific obligations could be less burdensome in some areas than originally feared. Careful monitoring of the legislative process and a flexible compliance strategy are essential in this dynamic environment.

References
(European Commission, Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL amending Regulations (EU) 2024/1689 and (EU) 2018/1139 with regard to simplifying the implementation of harmonized rules for artificial intelligence (Digital Omnibus Regulation on AI), available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52025PC0836&qid=1769188058655 )

Subscribe to GvW Newsletter

Subscribe to our GvW Newsletter here - and we will keep you informed about the latest legal developments!