EU Digital Omnibus centralizes AI enforcement
Brussels centralizes AI enforcement, delays obligations
Model Diplomat10 min readEurope

The EU's Digital Omnibus: Brussels gets more power, later
The EU's Digital Omnibus on AI delays high-risk obligations by 15-plus months while handing the AI Office exclusive enforcement authority over AI systems on the bloc's largest platforms — a centralization of power paired with a deferment of its use.
On July 8, 2026, the final act of the EU's Digital Omnibus on AI was signed, amending the AI Act barely two years after it entered the statute book — and the headline most observers reached for was "delay." High-risk AI obligations originally due August 2, 2026 were pushed to December 2, 2027 for standalone systems and August 2, 2028 for AI embedded in regulated products, a rollback framed as competitiveness relief under the Draghi and Letta agendas. The real structural move, though, runs in the opposite direction: the Omnibus centralizes enforcement authority over the largest AI platforms in the European Commission's AI Office, pulling supervisory power away from member-state regulators even as it postpones the obligations that would make that power meaningful. Brussels gets more jurisdiction and less immediate reason to use it.
What the Omnibus actually changed
The package, designated Omnibus VII, was proposed by the European Commission on November 19, 2025, and separated from the wider Digital Omnibus — which also targets the GDPR, ePrivacy Directive, the Data Act and the NIS2 cybersecurity directive — because of the approaching August 2026 deadline for high-risk AI rules, according to the Digital Watch Observatory. Negotiators reached political agreement in the early hours of May 7, 2026; the Parliament adopted the text on June 16, the Council gave final approval on June 29, and the act was signed on July 8, per the
Council of the EU.
The most-discussed elements are the deadline extensions and a new prohibition on AI-generated non-consensual intimate imagery and child sexual abuse material, effective December 2, 2026, as detailed by Licentium. Article 50 transparency obligations — labeling AI-generated content — still apply from August 2, 2026, with a grace period for legacy systems running to December 2, 2026. The AI literacy duty (Article 4) and prohibited-practices regime (Article 5) remain unchanged. Less attention has gone to Article 75, which reorganizes who enforces the AI Act — and that is where the architecture shifts.
The centralization play: Article 75
The amended Article 75(1) grants the AI Office — the Commission body established within DG CONNECT — exclusive competence to supervise and enforce the AI Act against two categories of AI system: those based on a general-purpose AI (GPAI) model where the model and the system share a provider, and those that constitute or are integrated into a designated Very Large Online Platform (VLOP) or Very Large Online Search Engine (VLOSE) under the Digital Services Act. The recitals describe this as "grant[ing] the Commission the powers of a competent market surveillance authority" wherever an AI system qualifies as a VLOP or VLOSE, or is embedded in one, per the EUR-Lex consolidated proposal and the
Council's final agreement document.
That is a significant jurisdictional transfer. Under the original AI Act, enforcement was to be split between national market surveillance authorities and the AI Office, with the Office's direct role largely confined to GPAI models. The Omnibus expands the Office's exclusive reach to cover AI systems operated on platforms the Commission already supervises under the DSA — the 19 designated VLOPs and VLOSEs designated in April 2023, covering 17 online platforms and two search engines, per the Commission's DSA enforcement page. The Commission gains "all of the powers of a market surveillance authority" under Regulation (EU) 2019/1020 — document requests, on-site inspections, and the ability to impose fines and periodic penalties up to the ceilings in Article 99 of the AI Act (7% of global annual turnover for non-compliance), according to the
Parliament's provisional agreement text. Under the DSA, the Commission can already impose fines up to 6% of global annual turnover on VLOPs.
The design also builds a bridge between the two regulatory regimes. For AI systems embedded in VLOPs, "the first point of entry for the assessment" will be the DSA's existing risk-assessment, mitigation and audit obligations (Articles 34, 35 and 37 of the DSA), "without prejudice to the AI Office's powers to investigate and enforce ex post" AI Act non-compliance, the Council text states. Commission services enforcing the DSA may seek the AI Office's opinion on parallel AI Act risk assessments — stitching together two enforcement streams that had run on separate tracks.
The recitals also preserve a narrow carve-out: the competent authority of the member state where a VLOP or VLOSE provider has its main establishment may exercise supervisory powers if the Commission has not initiated proceedings for the same infringement. But the default has flipped — the AI Office is now the primary enforcer, and national authorities act only if Brussels declines.
The historical parallel — and how it diverges
The structure mirrors, but inverts, the GDPR's one-stop-shop logic. Under the GDPR, the lead-authority model was designed to give companies a single interlocutor among national data protection authorities — a concession to industry that also limited the influence of any single member state. The AI Office expansion applies the same single-counterpart principle, but the counterpart is now the Commission itself, not a national authority. Where GDPR decentralized the lead to a member state, the Omnibus recentralizes it to Brussels for the systems that matter most to public discourse and consumer exposure.
The Lawfare analysis notes the AI Office already holds escalating powers over GPAI providers — demand documentation (Article 91), conduct independent evaluations with source-code access (Article 92), and require specific mitigations or market restrictions (Article 93). Those powers now extend across the largest consumer-facing AI deployments. The academic paper by Casey and Colonna on arX observes that "the ink had hardly dried on the Act before AI companies, innovation-oriented states started to attack new rules for hurting European competitiveness relative to China and US" — framing that the Omnibus explicitly adopts in its competitiveness recitals.
Who benefits, who loses
The winner is the Commission itself. The AI Office, which the Commission's own proposal estimated would need approximately 53 additional full-time equivalents, gains consolidated enforcement reach across the two regulatory regimes it already administers. National authorities lose discretion over the highest-visibility AI systems operating in their territories — a shift the Freshfields analysis frames as "clearer EU-wide rules and a single strategic enforcement focus" that may reduce fragmented national actions, but which also concentrates enforcement risk in a single institution's capacity and priorities.
For the designated VLOPs — including Meta's Facebook and Instagram, Alphabet's YouTube and Search, ByteDance's TikTok, and X — the trade is ambiguous. They face a heavier consolidated supervisor with cross-regulatory reach, but also a single enforcement counterpart rather than 27 potential national regulators. The same predictability calculus that made the DSA's centralized VLOP regime tolerable to large platforms applies here. The Computer & Communications Industry Association, whose members include Google, Apple and Meta, said the Omnibus "misses critical opportunities" to raise the GPAI compute threshold and fix copyright extraterritoriality wording — signaling that industry wanted more, not less, centralization, according to Al Jazeera.
The losers are clearest at the margins. Smaller AI developers and startups, who fall outside the AI Office's exclusive competence, remain under national supervision and face the heterogeneity the VLOPs escape. The Bertelsmann Stiftung's empirical study found that large firms can "absorb uncertainty and even leverage compliance as a competitive strength, while smaller actors face growing administrative barriers and reduced room for innovation" — a dynamic the Omnibus sharpens by centralizing the large-firm enforcement track while leaving smaller players in a fragmented national system. The Bertelsmann Stiftung study also notes that civil society organizations, initially critical of the AI Act, now "increasingly see themselves as guardians of the existing regulatory framework" as deregulatory pressure mounts.
The delay itself creates a two-tier market. Companies that had invested in early compliance now face 15-plus months of regulatory limbo in which less-prepared competitors can deploy high-risk systems under the AI Act's legacy-system grace provisions. DIGITALEUROPE told policymakers that compliance could cost companies in the region of EUR 3.3 billion a year across the EU, and that a company of around 50 employees developing an AI-based product could face initial compliance costs of between EUR 320,000 and EUR 600,000, per the Digital Watch Observatory reporting. Those figures framed the Commission's competitiveness rationale — but the delay rewards the laggards, not the firms that spent to meet the original August 2026 deadline.
Civil society: the legitimacy deficit
The Omnibus drew sharp opposition from digital rights groups whose support was instrumental in building the AI Act's political legitimacy. Max Schrems, founder of NOYB, called the reforms "the biggest attack on Europe's digital rights in years" and said the Commission's claim to "maintain the highest standards" was "clearly incorrect," per Al Jazeera. Amnesty Tech's programme director Damini Satija said the proposals would "tear apart accountability on digital rights" and "open the door to unlawful surveillance, discriminatory profiling in welfare and policing," as reported by
Amnesty International.
The European Parliament Research Service briefing catalogued the institutional concern: BEUC argued the proposals go "far beyond targeted modification," the European Data Protection Board and European Data Protection Supervisor cautioned that revisions to medical device rules "may render the AI Act's safeguards on high-risk AI systems inapplicable," and Corporate Europe Observatory with LobbyControl called the omnibus "an unprecedented attack on digital rights," according to the EPRS briefing. The CEPR/VoxEU column noted that the European Ombudsman had already highlighted "procedural shortcomings" in the Commission's legislative amendments, and that EDRi warned the Omnibus could trigger future challenges before the Court of Justice, per
CEPR.
Gianclaudio Malgieri, an associate professor of law and technology at Leiden University, told Al Jazeera the reforms "risk moving the EU model closer to a more permissive, industry-driven approach to AI and data use, at the very moment when the world is watching Europe to see whether it can offer a real alternative." The arXiv paper by Casey and Colonna argues the Omnibus signals that "robust rights-based AI governance is incompatible with competitiveness" — a framing that diminishes what they call the "cultural rationality" of the AI Act, which had functioned as evidence that comprehensive AI regulation was both possible and politically justifiable.
The geopolitical context
The Omnibus does not land in a vacuum. The Chatham House analysis published in April 2026 notes that the EU "temporarily watered down and delayed the implementation of its landmark AI Act, after member state concerns over the constraints placed on would-be European AI champions," and observes that the bloc is "increasingly embracing the idea that control over infrastructure, rather setting the rules, is the main source of influence and power in the digital economy." The Trump administration has made EU digital legislation part of the tariff conversation — a pressure vector the CSIS analysis of the AI Continent Action Plan flagged when noting that the Commission "toned down" explicit simplification language, potentially to "keep all the possible cards in its hands" in transatlantic negotiations.
The co-rapporteurs' transparency register records meetings with Google, Mistral AI, EDRi, noyb and the TIC Council during the negotiation, per the Digital Watch Observatory. National parliaments from Czechia, Italy, the Netherlands, Portugal, Romania, Germany, Poland and France submitted subsidiarity contributions — a signal that the centralization of enforcement was noticed at the member-state level. The European Central Bank was formally consulted and issued an opinion published in the Official Journal in April 2026, as required for measures affecting payments and financial infrastructure.
What to watch next
The regulation enters into force 20 days after publication in the Official Journal — expected before the original August 2, 2026 deadline. Three decision points follow:
- The Commission's implementing act on AI Office enforcement powers. Article 75(1a) empowers the Commission to adopt implementing acts defining the AI Office's enforcement powers, including its ability to impose penalties. The scope and safeguards in that act will determine whether the Office's centralized authority is matched by procedural rigor or left to administrative discretion.
- GPAI Code of Practice and systemic-risk threshold. The CCIA complaint that the Omnibus failed to update the compute threshold for systemic-risk GPAI models leaves the most commercially consequential classification decision unresolved. If frontier models cross the current threshold before December 2027, the AI Office's powers activate regardless of the high-risk delay.
- First VLOP AI Act investigation. The DSA's risk-assessment obligations (Articles 34, 35, 37) now serve as the "first point of entry" for AI systems on designated platforms. The first Commission decision that uses DSA audit findings to trigger AI Office enforcement will test whether the bridge between the two regimes holds — or whether platforms litigate the jurisdictional overlap.
The Bottom Line
The Digital Omnibus on AI is not deregulation — it is re-regulation with a deferral. The EU has given its own enforcement arm more power over more actors, then delayed the moment that power becomes operational by 15 months. The net effect is a concentrated enforcement authority sitting on top of a postponed obligation, which means the AI Office's first major test will come not from the high-risk regime but from the GPAI and DSA-adjacent powers it already holds. If the Commission uses the interim period to build capacity and issue the implementing act on enforcement powers, the delay will look like preparation. If it does not, it will look like capitulation dressed as simplification — and the civil society legitimacy that made the AI Act a global benchmark will be the first casualty.
Discover more

India
Congress Accuses Modi of Stalling Women's Law
Congress accuses Modi of stalling women's reservation law by linking it to delimitation, revealing a deeper electoral strategy.

India
Delhi CM Rekha Gupta Blasts Opposition's Delm
Delhi CM Rekha Gupta's remarks on women's quota defeat reveal BJP's strategy for the 2029 Lok Sabha elections, focusing on delimitation.
India
Rajnath Singh's Durga Squad for 2026 Polls
Rajnath Singh's Durga Squad promised women's safety in Bengal but has since disappeared from the agenda, revealing BJP's true priorities.

Conflict & Security
West Africa Food Crisis: Three Shocks in 2026
Conflict, climate extremes, and the Strait of Hormuz closure drive a severe food crisis in West and Central Africa, with fertilizer prices surging 80% and millions displaced.