01 September 2026

A Frozen Clock and a Frozen Problem

The Digital Omnibus Missed an Opportunity to Fix the AI Act

Brussels, do we have a problem with the AI Act? My answer, in essence, was yes. Actually, more than one: overregulation and excessive demand on high-risk AI systems. In June 2026, when the European Parliament adopted the Digital Omnibus on AI, it seemed Brussels had answered my question in its own way. The language surrounding it – “simplification”, “burden reduction”, “protecting Europe’s competitiveness” – suggested that Mario Draghi’s words in its 2021 Report were somehow heeded. Sadly, the new changes are more cosmetic than real. In reality, Brussels only bought (itself) more time.

What Actually Changed with the Digital Omnibus

Compliance deadlines for standalone high-risk AI systems under Annex III of the Digital Omnibus on AI moved from August 2026 to December 2027, a seventeen-month reprieve. High-risk systems embedded as safety components under Annex I gained twelve months, from August 2027 to August 2028. The Article 50 transparency obligations were partially deferred for systems already on the market. The most visible new substantive amendment refers to the prohibition of AI systems designed to generate non-consensual intimate imagery, with compliance required by December 2026.

That last element deserves to be said plainly: it is a good rule, and it closes a real gap in the AI Act. It works as a reminder that the EU can still legislate on substance, not just on timing, when it chooses to. If the rest of the Omnibus had been drafted with that same instinct – identify a specific, demonstrable problem and fix it – this would have been a very different piece.

Why Moving the Deadline is not the Same as Solving the Problem

I have spent the last couple of years working through the AI Act’s architecture and implementation. Thus, I can say that the problematic points are not, for the most part, about timing, but about content, or, to make it trendier, about design. Let me give you some examples.

Article 40 allows providers of high-risk AI systems to demonstrate compliance through harmonised European standards rather than having to prove separately that they satisfy each of the AI Act’s technical and organisational requirements. This is a sensible idea in principle, as it creates a more predictable route to market. The difficulty is that CEN and CENELEC are still working through standards. Moreover, the standards are meant to apply “horizontally”, across sectors as different as healthcare, law enforcement, and education, with the practical result that a standard workable for one is close to meaningless for another.

Article 43 establishes the conformity assessment procedures that high-risk AI systems must undergo before being placed on the market. However, these procedures still have to be reconciled with parallel assessments under other EU regulations applicable to the same product, and notified bodies capable of running assessments across all of these regimes remain scarce. The recent amendments seek to reduce duplication by integrating the AI Act requirements into the conformity assessment carried out under the relevant Union harmonisation legislation and by enabling the same notified body to conduct that assessment. Yet this solution depends on the availability of notified bodies with the necessary competence and designation across the relevant regulatory regimes. The procedural simplification may therefore be considerable on paper, while its practical effectiveness will ultimately depend on whether a sufficient number of suitably qualified notified bodies is available.

Article 51 determines when a general-purpose AI model is presumed to present systemic risk by relying on a quantitative threshold based on training compute of 10²⁵ FLOPs. The rule appears precise, but its operational value is less obvious: only a limited number of frontier developers are realistically able to assess with confidence whether a model crosses that threshold.

Although the Digital Omnibus has streamlined parts of the AI Act’s implementation architecture and strengthened certain governance mechanisms, questions remain regarding the practical interaction between national authorities, market surveillance bodies, the AI Office and the AI Board, exactly as I flagged when reflecting on the Act shortly after it entered into force.

None of this is fixed by pushing dates. A provider who could not comply because a harmonised standard did not yet exist will, seventeen months from now, possibly still be waiting for that standard. A start-up unsure whether its model is subject to one conformity assessment regime or several may well remain unsure, only somewhat later. The Omnibus gives everyone more time to remain uncertain.

What About “Innovation Nurseries” (aka, “Regulatory Sandboxes”)?

If there was one part of this reform where I expected Brussels to actually engage with substance rather than dates, it was the regulatory sandbox regime (as per Article 3(55) of the AI Act, “a controlled framework set up by a competent authority which offers providers or prospective providers of AI systems the possibility to develop, train, validate and test, where appropriate in real-world conditions, an innovative AI system, pursuant to a sandbox plan for a limited time under regulatory supervision” I have argued before that sandboxes, as designed in the AI Act, promise more than they deliver. It is not clear which authority is meant to supervise a sandbox once its scope touches more than one regulation. The relationship between Article 59’s rules on the reuse of personal data within AI regulatory sandboxes and the GDPR’s own regime on “further processing” under Article 6(4) remains blurred. Article 59 seeks to facilitate the testing and development of innovative AI systems by allowing, under certain conditions, the reuse of personal data within sandbox environments. Yet the GDPR already imposes its own framework for assessing whether data collected for one purpose may lawfully be used for another. The precise interaction between these two regimes is far from clear. And, perhaps most tellingly, providers get very little in return for exposing themselves to this scrutiny: while Article 57(12) protects participants from administrative fines where they have acted in good faith and complied with the agreed sandbox plan, it does not shield them from liability for any harm caused, nor does it offer tax relief or comparable economic incentives. A regime that asks companies to volunteer for close regulatory attention while offering little beyond guidance is likely to struggle to attract participants.

Here, again, the Digital Omnibus has reset the clock, by moving the deadline for Member States to have at least one operational national sandbox running from August 2026 to August 2027. Moreover, at the substantive level, it launched a Union-level sandbox, run by the AI Office, with priority access reserved for SMEs, start-ups and small mid-cap enterprises. Again, on paper, this is a real answer to a real problem. Smaller developers were always going to struggle more with a patchwork of divergent national sandboxes than larger players.

Still, many of the earlier weaknesses persist, including questions about how the AI Office, data protection authorities and other competent authorities will interact in the supervision of this new EU-level sandbox. Indeed, the EDPB and the EDPS, in their 21 January 2026 joint opinion on the Digital Omnibus on AI, flagged that the new sandbox lacked an explicit requirement for data protection authority involvement in personal data processing.

The Call for “Trustworthy AI”

The European Commission has, since 2018, framed its entire approach to AI governance around the idea of trustworthy AI, a formula meant to signal that innovation and fundamental rights protection were not opposing forces but complementary goals, and above all a way to reinforce European values. Prima facie, it is a good formula but also one that only holds if both halves are actually being worked on. By emphasising fundamental rights at the expense of innovation, the AI Act risked undermining Europe’s prospects as a competitive AI ecosystem. A Union that regulates itself out of its own AI industry serves nobody, least of all the people the AI Act is meant to protect.

Then came the Digital Omnibus. I do not think the instinct behind it is wrong; however, its implementation still leaves us halfway there. The AI Act’s real difficulties are not a matter of dates, but of design: standards still unfinished, competences still disputed, thresholds still unworkable outside a handful of frontier labs. Moreover, buying time is not free. It leaves every one of those unresolved questions exactly where they were, only for longer, meaning that the industry it is meant to reassure keeps operating under the same uncertainty it was already struggling with.

Had Brussels taken more explicit innovation measures, this could easily have been perceived as a victory for industry and a defeat for fundamental rights (although, are we not, in one way or another, all fundamental rights advocates here?). A concession to profit and the tech lobby, right?

Well, I am not convinced that fundamental rights are better protected by rules that are so complex, uncertain or difficult to operationalise that their application becomes inconsistent. Quite the opposite: regulatory uncertainty tends to favour those with enough lawyers, money and time to navigate it.

And this brings us back to “trustworthy AI” – whatever exactly that expression is supposed to mean after all these years, and one Omnibus later. Trustworthy AI was never going to emerge simply from adding more rules, more procedures and more layers of compliance. If anything, a regulatory system so intricate that only the best-resourced actors can navigate it risks producing precisely the opposite result.

This reminds me of the Hatter’s watch, forever frozen at tea-time no matter whose hands turn it. The EU is not Wonderland, but resetting the AI Act’s clock has changed the deadlines while leaving its weaknesses frozen in time.


SUGGESTED CITATION  Raposo, Vera Lúcia: A Frozen Clock and a Frozen Problem: The Digital Omnibus Missed an Opportunity to Fix the AI Act, VerfBlog, 2026/9/01, https://verfassungsblog.de/a-frozen-clock-and-a-frozen-problem/, DOI: 10.59704/ef53235ea928b312.

Leave A Comment

WRITE A COMMENT

1. We welcome your comments but you do so as our guest. Please note that we will exercise our property rights to make sure that Verfassungsblog remains a safe and attractive place for everyone. Your comment will not appear immediately but will be moderated by us. Just as with posts, we make a choice. That means not all submitted comments will be published.

2. We expect comments to be matter-of-fact, on-topic and free of sarcasm, innuendo and ad personam arguments.

3. Racist, sexist and otherwise discriminatory comments will not be published.

4. Comments under pseudonym are allowed but a valid email address is obligatory. The use of more than one pseudonym is not allowed.




Explore posts related to this:
AI Act, AI systems, Digital Omnibus, EU