The Digital Omnibus: What Is Actually Changing for Cookies, GDPR and the AI Act

The Digital Omnibus has been reported for months as a single deregulatory event, which has left many businesses waiting for a simplification that has only partly arrived. The accurate picture in August 2026 is that the package split. The AI part is law. The privacy and cookie part is not, and the provision most people were waiting for was removed from the Council’s own text in June.

That distinction decides what you should do this quarter. One half of the package gives you time you can plan around. The other half gives you nothing you can rely on, which means the cookie banner on your site still has to comply with the rules as they stand today.

What is actually decided

The AI track moved fastest. Parliament approved the Digital Omnibus on AI on 16 June 2026 by 423 votes to 57 with 174 abstentions, the Council gave final approval on 29 June, and the text entered into force on 27 July 2026.

The substance is a postponement of the heaviest obligations, not their removal.

ObligationWasNow
Standalone high-risk systems (Annex III)2 August 20262 December 2027
High-risk AI embedded in regulated products (Annex I)August 20272 August 2028
Article 50 transparency — chatbots, deepfake labelling2 August 2026Unchanged
Article 50(2) marking of AI-generated content, systems already on the market2 August 20262 December 2026
Prohibited practices, AI literacyAlready in forceUnchanged

The line that matters for ordinary websites is the third one. Transparency obligations were not delayed. If your site has a chatbot, an AI assistant or AI-generated imagery presented as real, the duty to say so applies now — the practical detail is in our note on who is responsible for chatbot disclosure.

What is not decided

The wider Digital Omnibus — the part touching GDPR, ePrivacy, NIS2 and DORA — is still in trilogue. Two proposed articles received most of the attention, and both are currently out of the Council’s text.

Article 88a would have moved consent for storing or reading information on a device out of the ePrivacy regime and into the GDPR, restructuring when consent is required at all. Article 88b would have made browser-level and system-level consent signals legally binding on the sites receiving them, which is the change that would genuinely have reduced banner fatigue.

Ambassadors failed to agree on 8 June 2026, and the presidency compromise deleted Articles 88a, 88b and 88c. Negotiations continue; whether the provisions return in some form is unknown at the time of writing.

The operational conclusion is unambiguous. Nothing has changed for cookie consent. A banner built today must still meet the requirements that apply today: no pre-ticked boxes, refusing must be as easy as accepting, no scripts before consent, and a real way to withdraw it. Any vendor selling you a “Digital Omnibus ready” banner is selling a position on a negotiation, not a compliance product.

What was in the privacy proposals, and why it matters even unadopted

It is still worth knowing what is being negotiated, because the direction of travel affects decisions with long lifespans.

  • Consent exemptions for low-risk measurement. The proposal contemplated allowing certain audience-measurement purposes without consent. If it survives, first-party analytics gets easier; if it does not, the cookieless approaches described in our note on measuring with less data remain the practical answer.
  • Machine-readable consent signals. The most consequential idea in the package: a browser-level choice that sites must respect. It would move consent from a per-site interruption to a user setting.
  • Narrowing of what counts as personal data in some pseudonymisation scenarios, which is contested precisely because it is consequential.
  • Adjustments to breach notification, including a single reporting entry point and a revised deadline.

None of this is law. All of it explains why any investment in consent infrastructure should favour flexible configuration over hard-coded rules.

Why the cookie part stalled and the AI part did not

The two tracks were separated deliberately, and that decision explains most of the outcome.

The AI postponement had an obvious constituency. Standards that high-risk systems were supposed to be measured against were not finished, so the original August 2026 date would have obliged companies to comply with requirements whose technical detail did not yet exist. Delaying an unworkable deadline is the rare change that industry, member states and regulators can all accept, and the parliamentary vote reflected that: 423 in favour against 57.

The privacy provisions had no equivalent consensus. Reopening consent rules touches a text that took years to negotiate, and any redrafting is read by one side as overdue simplification and by the other as the largest rollback of European data protection since the GDPR was adopted. Member states did not divide neatly, ambassadors could not agree on 8 June, and the presidency chose to move the file forward by removing the contested articles rather than by resolving them.

The practical lesson for planning is that technical fixes with a deadline attached move quickly through this process, while substantive changes to established rights move slowly or not at all. Anyone budgeting on the assumption that consent requirements will relax should treat that as a possibility with no date, not as a forecast.

The rest of the package, briefly

Cookies and AI absorbed the attention, but the omnibus also touches operational obligations that matter to smaller organisations.

Incident reporting is the significant one. The proposals contemplate a single entry point for notifications that currently go to different authorities under different instruments — a genuine reduction in duplicated work for an organisation caught by more than one regime. Anyone already assembling incident procedures for supply chain reasons, as described in our note on how NIS2 arrives through a client’s contract, should write those procedures around what an incident is and who decides, rather than around which portal receives the form. The definitions are stable; the destinations are being renegotiated.

What to do this quarter

Five actions, ordered by how likely they are to matter.

  1. Verify the banner against current rules, not future ones. Open the site in a clean browser and check what loads before any click. Scripts firing before consent is the most common and most enforceable defect, and it is examined in our note on why symmetrical buttons are no longer enough.
  2. Audit AI disclosure now. Chatbot, AI search, generated images or copy presented as photography or authorship — Article 50 applies from August 2026 and was not postponed.
  3. Check whether anything you run is actually high-risk. Most business websites are not. Recruitment screening, credit scoring, education assessment and certain access-control uses are. If one applies, the extension to December 2027 is real breathing room — use it to document, not to defer.
  4. Mark AI-generated content before December 2026 where Article 50(2) applies to systems already on the market. This is the one deadline in the package that moved closer rather than further away for content already published.
  5. Write down what you use and why. Whatever the final text, every version of it expects a controller who can describe their processing. That inventory is the same one behind the internal rules set out in our note on AI governance worth writing down now.

What none of this changes

A useful counterweight to omnibus coverage: the obligations that generate almost all real enforcement against small and medium businesses are not in the package at all, and no version under discussion touches them.

You still need a lawful basis for each processing purpose, and “we have always collected it” is not one. You still have to answer access and deletion requests within a month, which is where most complaints against small companies begin — the workable process is described in our note on handling personal data requests. You still need a record of processing activities, a privacy notice that matches what the site actually does, and agreements with the processors you use. Security obligations are unchanged, and a breach caused by an unpatched plugin will be assessed under exactly the rules that applied last year.

This matters because attention is finite. An organisation that spends the next six months following trilogue coverage while its contact form emails personal data to a shared inbox has optimised for the wrong risk. Regulators act on complaints, and complaints come from people who asked for their data and got nothing, not from people offended by a banner design.

The practical hierarchy is therefore unchanged: get the basics documented and working, keep the consent layer configurable, and treat the omnibus as a scheduling input rather than as a reason to pause.

How to read the next twelve months

Three habits will save time as this continues to move.

Separate proposed from adopted. Most confusion in the last year came from reporting that treated a Commission proposal as a decision. A proposal is a starting position; the Council and Parliament routinely delete the most discussed parts of one, as they did in June.

Watch the dates rather than the direction. “Simplification” describes an intention. The only operational facts are the dates in the adopted text, and those are now: August 2026 for transparency, December 2026 for marking existing systems, December 2027 for standalone high-risk, August 2028 for embedded high-risk.

Do not rebuild twice. If a consent platform or an AI inventory is on your roadmap, build it to be reconfigured. The probability that the rules settle permanently within two years is low, and a design that assumes today’s text is a design that will be rewritten.

Key takeaways

  • The package split. The AI Omnibus is law and entered into force on 27 July 2026; the privacy and cookie part is still in trilogue.
  • High-risk deadlines moved: Annex III standalone systems to 2 December 2027, Annex I embedded systems to 2 August 2028.
  • Article 50 transparency was not delayed. Chatbot and deepfake disclosure applies from 2 August 2026; marking of AI content on systems already on the market applies from 2 December 2026.
  • The cookie provisions were deleted from the Council’s compromise text after ambassadors failed to agree on 8 June 2026. Nothing has changed for consent banners.
  • Ignore “Omnibus-ready” marketing. Compliance is measured against adopted law, not against a negotiating position.
  • Build for reconfiguration, because the rules will move again before they settle.

Contact us
to discuss your project

Fill out the form and we will contact you
to discuss the details of your project.

    Choose a convenient way to contact us:

    Telegram
    Viber
    E-mail