On January 21, 2026, the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) adopted Joint Opinion 1/2026 on the European Commission’s “Digital Omnibus on AI” proposal (2025/0359). The legislative opinion welcomes the goal of simplifying the AI Act’s implementation — and draws hard lines at the same time. Several simplification measures, the two authorities warn, could weaken fundamental-rights safeguards, reduce provider accountability, and create fresh legal uncertainty.
The context is the Digital Omnibus package the Commission tabled in November 2025, whose AI component would delay high-risk obligations, delete certain registration requirements, and widen the legal basis for processing sensitive personal data. The EDPB and EDPS are the gatekeepers of the GDPR system. A joint opinion is not binding, but it carries real weight with the European Parliament and the Council — especially where the AI Act and GDPR collide.
Flashpoint One: Special-Category Data on Too Broad a Legal Basis
The proposal’s new Article 4a extends the legal basis for processing special categories of personal data for bias detection and correction beyond high-risk AI systems to all AI systems and models, and beyond providers to deployers. The two authorities support the direction in principle — bias detection genuinely requires touching sensitive data — but insist the reliance be “clearly circumscribed.” Their recommendations: reinstate a “strictly necessary” standard in place of the proposal’s looser “necessary and proportionate” test, limit the ground to cases where the risk of adverse effects from bias is sufficiently serious, add concrete examples of qualifying non-high-risk systems, and clarify how the provision interacts with GDPR Articles 6 and 9.
For developers, that is an early signal. Even if the legal basis does widen, sensitive-data bias detection will be treated as high-risk in practice, and DPIAs plus GDPR analysis will remain part of the job.
Flashpoint Two: Deleting High-Risk Registration Hollows Out Accountability
The proposal would let providers skip registering their high-risk systems where they have concluded, under Article 6(3) of the AI Act, that an Annex III system is not in fact high-risk. The EDPB and EDPS are blunt: deletion would “significantly decrease the accountability of providers” and create an “undesirable incentive” to invoke the exemption unduly. They support easing administrative burdens — but not at the cost of the accountability trail.
The opinion flags other simplifications too. Extending SME privileges to small mid-cap companies (SMCs) draws a warning that headcount and company size do not correlate with the harm potential of the high-risk AI those entities offer. And on AI literacy, the two authorities outright oppose removing the employer duty, arguing that Commission and Member State obligations should complement organizational responsibilities rather than replace them.
Sandboxes and the Division of Labor: Draw the AI Office’s Powers Clearly
On EU-level AI regulatory sandboxes, the opinion welcomes their creation but notes the draft — unlike national sandboxes under Article 57(1) — provides no role for data protection authorities, and recommends giving the EDPB an advisory role and observer status at the AI Board. On the AI Office’s supervision of AI systems embedded in very large online platforms (VLOP/VLOSE), it warns that the “active cooperation” requirement may not preserve national authorities’ independent capacity to act, and calls for a clear delimitation of which general-purpose AI models trigger exclusive AI Office competence. For AI systems used by the EU institutions themselves, exclusive competence should stay with the EDPS under Article 74(9).
The Hidden Cost of Delayed Timelines
The proposal would extend high-risk obligations by up to 16 months and give Article 50(2) transparency obligations a six-month grace period, to February 2, 2027. The opinion spots a knock-on effect that is easy to miss: delay lets more high-risk systems escape the AI Act through the Article 111(2) legacy-systems exception, whose cut-off would slide from August 2, 2026 to December 2, 2027. The co-legislators, the two authorities urge, should keep the current timelines — above all for transparency requirements.
What It Means for Teams Deploying AI in the EU
Three judgments. First, do not treat the Digital Omnibus as a done deal: the proposal is still being negotiated under pointed supervisory criticism, so compliance planning should not assume the delays will enter into force. Second, any team whose bias detection touches sensitive data should adopt “strictly necessary” as the design standard now — it is cheaper than retrofitting later. Third, written classification records for high-risk determinations (the Annex III plus Article 6(3) path) remain the accountability core for the foreseeable future; until the registration question settles, keeping complete records is the only safe strategy.
Sources
- EDPB-EDPS Joint Opinion 1/2026 on the Digital Omnibus on AI — EDPB
- EDPB-EDPS publishes opinion on AI Digital Omnibus proposal — Matheson
- European Data Protection Authorities Issue Joint Opinion on the Digital Omnibus on AI — Covington
AI-assisted summary compiled from the sources above, reviewed by a human before publishing.
