EU digital regulation · Analysis
Is the European model stable?
What the digital omnibus moves, and what it leaves alone
It is the first question a legislature outside the Union asks, and the honest answer is that the distinction lies elsewhere than most commentary places it. Since November 2025 the European Union has been rewriting parts of its own digital rulebook. One instrument has already been amended and its deadlines pushed back. A second package is proposed and contested. A third — the Digital Services Act — has not been touched at all. The useful question is not whether Europe is retreating. It is which layer is being revised, and at what speed.
Fatima Ghilassene, avocate at the Lille Bar — 8 September 2026
Already changed: the Union postponed its own AI Act
The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 with a staged timetable. On 19 November 2025 the Commission proposed to move part of it. The result, Regulation (EU) 2026/1744, was signed on 8 July 2026 and published in the Official Journal on 24 July 2026.
Two dates moved. Stand-alone high-risk systems listed in Annex III now become subject to the regime on 2 December 2027, instead of 2 August 2026. High-risk systems embedded in regulated products under Annex I move from 2 August 2027 to 2 August 2028. The transparency obligations of Article 50 — disclosure that content is artificial, marking of synthetic output — were not postponed and apply from 2 August 2026, with a four-month grace period, to 2 December 2026, for the marking of systems already on the market.
One detail of the negotiation matters more than the dates. The Commission had proposed to tie the new deadlines to the availability of harmonised technical standards — a conditional trigger. The co-legislators refused and fixed calendar dates instead. The stated reason for the delay was nevertheless that the standards were not ready.
The lesson for a jurisdiction copying the AI Act is narrow and practical: copy the second timetable, not the first, and before fixing any date, look at whether the conformity assessment infrastructure it presupposes — standards, notified bodies, testing capacity — exists at home. Europe legislated the timetable first and discovered the answer afterwards.
Proposed but not adopted: the data layer
The second instrument, proposed the same day, is the digital omnibus proper (COM(2025) 837 final, procedure 2025/0360(COD)). It is still at committee stage in the European Parliament: referral announced on 19 January 2026, rapporteurs appointed on 25 February 2026 for the industry and civil liberties committees, with the internal market and legal affairs committees giving opinions. Nothing in it is law.
Its reach is wide. It would amend the General Data Protection Regulation, the single digital gateway regulation, the regulation on data protection in the EU institutions, the Data Act, the ePrivacy Directive, NIS 2 and the directive on the resilience of critical entities. It would repeal four instruments outright: the regulation on the free flow of non-personal data, the platform-to-business regulation, the Data Governance Act and the Open Data Directive.
The proposals to the GDPR are the contested part. They include a clarification stating what is not personal data for a given entity, an exception for special categories of data processed residually in the development of an AI system, a breach notification duty triggered only by a likely high risk and extended from 72 to 96 hours, and the transfer of the rules on storing and reading information on terminal equipment out of the ePrivacy Directive into new GDPR articles.
The two European data protection authorities came out against the central element. In their Joint Opinion 2/2026, adopted on 10 February 2026, the European Data Protection Board and the European Data Protection Supervisor “strongly urge the co-legislators to not adopt the proposed changes to the definition of personal data”, holding that the amendment goes beyond a targeted modification, defines the concept negatively, and would narrow it.
For a country drafting now, the practical consequence is simple. Legislate against the GDPR as it stands, not against the proposal, and follow the file — because if the definition of personal data does move in the Union, a text that copied the current one will not thereby become wrong, but a text that anticipated the proposal may become orphaned.
Not touched: the Digital Services Act
The digital omnibus does not amend Regulation (EU) 2022/2065. It repeals the platform-to-business regulation partly on the ground that the Digital Services Act has largely overtaken its provisions.
That is the single most useful fact in the whole package for anyone examining the platform governance layer. The European simplification exercise consolidates toward the DSA, not away from it: obligations scattered across earlier instruments are being folded into the regime that already carries them, and the regime itself is left intact.
The qualification matters as much as the point. An absence of amendment in 2026 is not a guarantee for 2029. The DSA carries its own review clause, its enforcement is barely two years old, and the political pressure that produced the omnibus has not disappeared. What can be said is narrower and still worth saying: of the three layers, this is the one the Union has chosen not to reopen.
Drawing on a model that is still moving
Three layers, three speeds. Platform governance is the most stable of them. Artificial intelligence is the most volatile: its dates have already moved once, before the main obligations ever applied. Data protection is the most politically contested, and the one whose outcome is least predictable today.
A legislature that treats the three layers as one, in a single statute, inherits the instability of the fastest-moving one — even when it is writing its own rules rather than reproducing the European ones. Reopening a law to change a date is expensive everywhere, and in some parliaments it reopens everything else with it.
The drafting consequence follows from that. Put the principles and the obligations in the primary text, and put the parameters that are known to move — application dates, designation thresholds, technical annexes, lists of high-risk uses — in an instrument that can be changed without reopening the statute. The Union placed many of those parameters in the regulation itself, and had to adopt a second regulation to move two dates.
Three postures, and only one of them creates dependence
The instability described above matters very differently depending on what a country is trying to do, and the three postures are worth separating because they are routinely conflated.
Copying the text. Reproducing the European instrument, or something close to it, in domestic law. Here the revisions matter directly: a text copied from the 2024 version of the AI Act carries deadlines the Union has itself abandoned.
Aligning by reference. Providing that domestic law follows the European instrument as amended from time to time. This is the only one of the three that creates dependence, and its cost is constitutional rather than practical: it incorporates norms produced by an authority to which the State has conferred no competence, in whose deliberation it has no vote, and whose acts it cannot bring before a court. That is the reverse of the position of a Member State of the Union, which conferred the competence, takes part in exercising it through its government in the Council and its elected members in the Parliament, and may challenge the resulting act before the Court of Justice — which is why European law is not foreign law inside the Union, and why alignment by reference from outside is an operation of a wholly different nature.
Drawing on the model to build one’s own framework. This is the usual case, and the one in which the European revisions cease to be a risk and become material. A legislature that borrows the mechanisms — statements of reasons, internal complaint handling, ranking transparency, risk assessment for the largest services — while writing its own definitions, thresholds and institutions, is not exposed to what the Union amends. It is free to read the amendments as a record of what the first attempt got wrong: which deadlines proved unrealistic, which definitions had to be reopened, which obligations were absorbed into another instrument.
The risk in that third posture is elsewhere, and it is the subject of the companion note: mechanisms travel more easily than the institutional conditions that make them work. Borrowing the trusted flagger without the organisations that could act as one, or the risk assessment without an authority able to read it, produces a text that is formally in force and practically inert.
All sources cited here were verified on 8 September 2026 against primary sources: the texts and procedure files of the instruments concerned, and the joint opinion of the European Data Protection Board and the European Data Protection Supervisor. The digital omnibus is a pending legislative file; anyone relying on this note should check its current stage.
Read: what implementing the DSA actually requires