📌 A new regulatory mood in European Union

Over the past months, the European regulatory landscape has begun to shift in ways that are subtle in form but significant in substance. There have been no dramatic announcements, no headline-grabbing reversals. Instead, the change is carried by a calm vocabulary simplification, alignment, burden reduction. Beneath these neutral terms lies a deeper movement that deserves attention.

The Omnibus initiative linked to the CSRD, which seeks to narrow sustainability reporting requirements, is one early sign. The leaked evolution of the GDPR and the AI Act through the Digital Omnibus package is another. Each reform looks limited when taken alone but together, they outline a quiet recalibration of how Europe regulates or would like to regulate in the future : lighter on process, more tolerant of risk and more focused on competitiveness than in previous years.

📉➡️📈 The competitive pressure behind the regulatory shift

This recalibration is not happening without rationale or in isolation. The United States is moving toward a more permissive approach to technology and data, signalling a competitive push rather than a protective one. In Europe, discussion on competitiveness including the work led by Mario Draghi[1] insist on removing obstacles and accelerating innovation. The political message is clear : maintaining Europe’s position requires making its regulatory model more agile.

The Digital Omnibus package must be read in this context. Officially a technical clean-up, it touches the foundations principles of the GDPR, the ePrivacy framework, the Data Governance Act, and the AI Act. These changes may appear technical, but they reshape the regulatory landscape that organisations have been adapting to, and investing heavily in, for almost a decade.

🛡️🔍 GDPR: Quiet changes with significant consequences

The GDPR is the area where the shift is most visible. The intention is to offer relief to organisations overloaded with documentation and risk assessments. Some proposals, however, alter more than administrative tasks. By revisiting what counts as identifiable or sensitive data, the reform could exclude information traditionally protection under EU data rules. For organisations, this means lighter obligations. For individuals, it means a narrower shield than before.

Another change narrows the practical exercise of data subject rights. If these rights can only used for strictly data-protection-related purposes, their availability in contexts such as employment disputes, investigations or litigation becomes uncertain. The proportionality argument is understandable, but the operational outcome is clear: less leverage for individuals, and fewer situation where rights offer effective protection.

🤖 Data and AI : A more permissive interface

The most strategic development concerns personal information used in AI. The proposals introduce a more permissive environment for training and improving AI systems, including some use of sensitive data under defined conditions. Safeguards remain, but the overall direction is unmistakable: enabling AI development by loosening certain boundaries that were once rigid.

This shift is particularly impact because organizations have invested heavily, both financially and structurally, in the original GDPR framework. Governance models, tooling, records of processing (ROPAs), DPIA methodologies and internal controls were built around broad definitions and strict interpretations. A sudden narrowing of scope risks leaving organizations with frameworks that are no longer aligned with regulatory reality.

⚙️ AI Act : A parallel transformation

The AI Act is undergoing similar adjustments. Implementation challenges have exposed gaps: missing standards, uneven readiness across Member States, and uncertainty for smaller actors. The Omnibus seeks to ease these pressures by simplifying documentation, reducing monitoring burdens and extending privileges to medium-sized companies.

A dedicated basis for using sensitive data to detect or correct discrimination marks another notable shift. Bias mitigation often requires confronting exactly the information that is hardest to process lawfully. This new path acknowledges that the AI Act and GDPR must evolve together, but it also widens access to highly protected data categories.

⚠️ A Subtle but Structural Retreat

Individually, these updates may look reasonable. Together, they amount to a structural retreat from some of Europe’s strictest regulatory positions of the past decade. Not a dismantling, but a meaningful rollback. A quieter form of deregulation driven only by competitiveness concerns.

For organisations, the implications are substantial :

  • Less documentation, more flexibility for AI development, and clearer testing pathways
  • A renewed need to rethink governance, as the assumptions that everything falls under the GDPR becomes less certain
  • An even closer intertwining of data governance and AI governance.

🧭 A New Regulatory Chapter

Europe is entering a new phase : more agile, more competitive but also more fragile from a individuals rights protection perspective. Whether this balance succeeds will depend on how these adjustments are implemented and how organisations, regulators and citizens respond.

What is certain is that the digital regulatory environment of the coming years will look different from that of the past decade. This evolution will shape the conditions in which European innovation and compliance will operate but with potential consequences that deserve close attention.

🚀 If your organisation is navigating these evolving regulatory developments and seeking clarity on practical and strategic impacts, we stand ready to support you ! Let’s discuss

#ArtificialIntelligence #AIRegulation #DataProtection #AIAct #GDPR #EUCompliance #Omnibus #DigitalRegulation #GRC #GovernanceRiskCompliance


[1] Draghi, M. (2024) – A competitiveness strategy for Europe. European Commission, Brussels (available here: Link to the report)