European Commission Split Digital Omnibus Package

Regulatory officials divided the proposal into two parts following security concerns raised by member states.

Updated on Oct. 6, 2026 in Cybersecurity

Isometric editorial illustration of two interlocking, matte geometric blocks in deep teal and mustard, representing divided policy frameworks.
The European Commission's Digital Omnibus package has been separated into two distinct proposals following security concerns from member states regarding unified infrastructure. AI Illustration. Upload story photo >

Live Poll

Do you believe centralized government reporting systems for businesses create more security risks than benefits?

Following a procedural separation of the Digital Omnibus package proposed in November 2025, the AI Digital Omnibus entered into force on July 27, 2026. The split aims to address security concerns regarding a centralised reporting platform while allowing less contentious measures to advance.

Why it matters

The procedural division addresses pushback from member states like France and Germany, who expressed security and interoperability concerns regarding a unified reporting infrastructure. By splitting the package, the Commission seeks to balance the need for streamlined reporting against national sovereignty and security requirements.

The European Commission estimates the single entry-point proposal would reduce corporate cyber incident reporting costs by 50% to 80%. Currently, 82% of entities must notify more than one authority, with 21% managing reports for five different agencies.

The players

European Commission

This is the executive branch of the European Union responsible for proposing legislation and implementing decisions.

European Parliament

This is the legislative body of the European Union directly elected by citizens to participate in the adoption of regulations.

Council of the European Union

This institution represents the member states and acts as a co-legislator alongside the European Parliament.

The details

The separation of the Digital Omnibus package into an AI-focused proposal and a Data Omnibus allows for the expedited adoption of AI regulations. The remaining Data Omnibus package is still undergoing negotiation between the European Parliament and the Council, with adoption anticipated no earlier than late 2026.

Timeline

  1. The European Commission proposed the Digital Omnibus Package in November 2025.

  2. The AI Digital Omnibus entered into force on July 27, 2026.

  3. The Data Omnibus is expected to be adopted by late 2026 at the earliest.

The Tech Race

The split of the Digital Omnibus package follows a trend of increasing regulatory scrutiny over centralized infrastructure and data interoperability within the European Union. This pivot reflects a broader shift toward balancing aggressive digital policy with the security concerns of individual member states.

Companies currently burdened by redundant reporting requirements may see a significant reduction in operational costs once a single entry-point system is fully implemented. Until the Data Omnibus is finalized, entities must continue to navigate existing, often overlapping, national reporting frameworks.

The takeaway

The move to split the Digital Omnibus package illustrates the practical challenges of standardizing security reporting in a complex multi-national regulatory environment. Organizations should prepare for a transition to unified reporting while remaining flexible during the current multi-authority compliance period.

What happens next

The Data Omnibus package remains under active negotiation, with expected adoption timelines currently projected for late 2026.

Further reading

For more on evolving data protection standards, visit the /tech/cybersecurity/ section.

Source note: This article includes information reported by Commercial Risk.

Live Poll

Do you believe centralized government reporting systems for businesses create more security risks than benefits?