The European Union’s digital regulatory crossroads: simplification, increased flexibility, or deregulation?
Alejandro Padín, partner in charge of the Data Economy, Privacy and Cybersecurity practice at Garrigues
The legislative process surrounding the Digital Omnibus and AI Omnibus packages has placed a fundamental issue at the heart of the European debate: how to reduce burdens and gain competitiveness without eroding the trust, legal certainty and rights on which the EU model is built.
In the current era of technological development, businesses and citizens are not the only ones facing innovations that are transforming our lives and the way we work. The European Union is at a historic juncture where it must take decisions that will shape its future and in which the legislative and supervisory inertia of the past fifty years may no longer be tenable. It is time to change course, but to do so it is first necessary to decide both the direction to take and the speed at which to proceed.
The regulatory inertia of the EU
Since its creation, the EU has been working towards common objectives, in light of a series of social, economic and technological developments that have helped shape what is now a political and economic project of major global importance. To achieve these aims, the Union has generated a vast amount of legislation to support this common endeavor, that seeks to provide cohesion and coherence to the complex structure of the countries of which it is comprised.
The key aspects of digital legislation in the EU: fundamental rights
Since its creation, the EU has developed its regulatory framework across all areas based on a number of structural pillars that are in turn built on a set of fundamental rights shared by its citizens. Those fundamental rights are currently set out in the Charter of Fundamental Rights of the European Union, which has the same legal value as the Treaties and permeates Union Law as a whole. These rights include the inviolability of human dignity, respect for private and family life, the right to the protection of personal data, freedom of expression and information.
Vectors that drive a change of course
Over the past three decades or so, the emergence of the internet in everyday life has profoundly transformed individual and collective habits and methods of production, giving rise not only to new ways of doing business but also to entirely new business models that did not exist before. These changes have accelerated practically exponentially following the introduction and widespread availability of generative AI models and systems.
A key element in understanding the importance of this historic transformation from a European perspective is the fact that the most advanced technological innovations have been created by and remain under the ownership of, businesses and organizations based outside the EU and financed by non-EU capital. Citizens, businesses and the EU authorities have embraced and incorporated into their daily lives, technologies that originate predominantly from outside the EU and whose adoption now appears to be structural.
Regulatory crossroads
These technological developments have forced the EU to address a series of questions that can no longer be deferred and which had persisted for years but had been carefully avoided or elegantly sidestepped by the EU’s law-making structures. These questions are related to two aspects that are crucial for the progress of the Union and its sustainability over time: competitiveness and fundamental rights. Those questions could be framed as follows:
- Is the EU becoming less competitive than other jurisdictions because of overregulation?
- Is the EU overregulated?
- Does regulation undermine competitiveness?
- Does the EU want to protect its citizens fundamental rights at any cost and above all else, even if this reduces its ability to compete in other jurisdictions?
Other similar questions could be added to the list, but the contours of the debate are clear and the pace of technological progress means that the answers cannot be postponed any further. The difficult balance between competitiveness and protection of fundamental rights must be addressed and resolved, or the EU risks losing the opportunity of making its voice heard on the global stage.
The question is therefore not whether Europe should regulate or not, but whether it is capable of distinguishing between regulation that protects trust, the internal market and rights and regulation that creates friction, duplication and uncertainty without providing a comparable level of protection.
The EU’s response
With a view to moving forward with the answers and following the recommendations of the 2024 Draghi Report, the European Union has launched a significant number of legislative initiatives aimed at simplifying and streamlining the EU acquis across a range of areas. They are all referred to as “Omnibus proposals” because each of them contains proposed amendments to several rules related to a particular sector or policy area. Of the 12 Omnibus proposals, the one that interests us in the area of digitalization is Proposal VII, the Digital Omnibus, comprised of two proposed regulations: the Digital Omnibus to amend legislation relating to data, cybersecurity and privacy and the Digital Omnibus on AI, to amend the Artificial Intelligence Act (AI Act).
The aim of these amendments is, as the European Commission says, to simplify the legislative framework, reduce red tape and eliminate certain inconsistencies arising from the multiplicity of rules. We do not propose to examine the content of these two proposals in detail here, as we have already done so on the Garrigues Digital portal here and here. However, we would like to reflect on the current status of the processing of both proposals, which have progressed at different speeds, as well as their assessment by legal and economic stakeholders.
First, the AI Omnibus has undergone a fast-tracked legislative process. Following the end of the trilogue negotiations, the compromise text was approved by the European Parliament on June 16, 2026, endorsed by the Council on June 29, and is currently awaiting publication in the Official Journal of the European Union. By contrast, the Digital Omnibus remains at a significantly less advanced stage in the legislative process. The Council has yet to agree to a common position for the trilogue negotiations, and the Parliament is also still deliberating on the position it will take in those negotiations.
There are several reasons for the difference in pace. One of them is that the AI Omnibus only amends the AI Regulation, whereas the Digital Omnibus makes changes to a wide range of legislation, including the General Data Protection Regulation (GDPR), the NIS 2 Directive, the Data Act and the Data Governance Act. However, it not only makes amendments, but also repeals, streamlines and extends the legislation in force. The second main reason for the difference in pace is that the AI Omnibus makes amendments that affect a fundamental part of the AI Act, namely the rules governing high-risk AI systems. Since the mandatory application of those rules was scheduled for August 2, 2026 the proposed reforms could not wait, given the widespread lack of readiness for compliance.
The underlying issue and future challenges
However, the fundamental issue lies in the true nature of these two proposals and this is currently the focus of significant debate in the European Union: is this a case of regulatory simplification, increased flexibility, or genuine deregulation? It depends on who is answering the question. The institutions maintain that the proposals constitute a simplification aimed at unifying legislation, reducing the number of rules, and making them easier to understand, thereby facilitating compliance and reducing the associated costs.
Others argue that the proposed amendments provide increased flexibility, that they introduce elements that could allow greater scope for activities in the digital arena. Although the final texts of the Digital Omnibus have yet to be approved, the debate can already be seen in relation to the proposed amendment to the definition of “personal data” in Article 4 GDPR, which would move towards a subjective theory of personal data instead of the objective approach that currently prevails (there are genuine battles being fought over this point, and agreement remains some way off). Similar tensions can be seen in relation to the possibility of processing personal data for the training of AI systems, as well as in discussions surrounding the proposal for a single entry-point for reporting security incidents, with the apparent potential inconsistencies across different regulatory frameworks (privacy, cybersecurity, etc.).
However, what some describe as “flexibilization” others view as deregulation and those who do, have voiced strong criticism of the direction the EU appears to be taking. They argue that it is sacrificing the protection of fundamental rights in exchange for greater competitiveness or, in other words, for the benefit of companies’ economic performance.
The false dilemma between competitiveness and regulation
It could be argued that Europe’s competitiveness does not depend solely on whether there is more or less regulation. Europe’s technological gap is also attributable to other factors, such as the fragmentation of the Digital Single Market and shortcomings such as a lack of scale, investment in computing infrastructure and talent, or the limited uptake of innovative public procurement. The European Parliamentary Research Service precisely warns that simplifying digital legislation may not, in itself, be sufficient to boost innovation and competitiveness. It points instead to factors such as the fragmentation of the digital framework, the existence of differing timelines, authorities and enforcement procedures, as well as the absence of fully integrated digital and capital markets.
We must also bear in mind that simplification or increased flexibility can generate legal uncertainty, particularly if structural aspects of the regulation are amended in an isolated and uncoordinated manner (as is the case of the proposed amendment to the definition of “personal data” discussed in the article linked above).
In addition, fundamental rights are not at odds with competitiveness. A clear, proportionate and applicable regulation can be a competitive advantage if it generates trust, legal certainty and responsible adoption. Indeed, the Commission itself presents the Digital Omnibus as a way of reducing costs while maintaining the same objectives and turning responsible compliance into a competitive advantage. Viewing regulation as a lever for business is a novel approach that is possible in the area of digital economy which we will discuss in a future article.
A key decision for Europe’s future
As can be seen, these are far from straightforward times. Other global powers are aware of the situation and are taking advantage of it to pursue their own objectives on the geopolitical chessboard, seeking to influence the debate in directions that best serve their interests and distorting it to their advantage.
This summary of the situation paints a picture of where we stand today, with a future that is difficult to predict and that is subject to debates which will ultimately shape the decision that Europe chooses to steer in the future. If this debate is not resolved through a clear and firm decision, we run the risk of falling behind at this pivotal moment in history – a risk far greater than that posed by any supposed overregulation. But if we fail to make the right choice there is a very real risk that the EU will no longer be able to maintain its position as one of the leading players in the economy, society and politics throughout the remainder of the twenty-first century.
The decision facing the European Union should not be framed as a simple choice between protecting rights or competitiveness. The real challenge lies in identifying which part of the digital EU acquis provides trust, legal security and democratic legitimacy and which part generates burdens, duplication or uncertainty without delivering a comparable level of protection. Simplification must not come at the expense of safeguards; flexibility must not become deregulation by stealth and protecting rights must not prevent Europe from developing technological capabilities of its own. If Europe fails to strike that balance, the risk will not simply be of regulating too much or too little, but of losing the capacity to decide for itself what role it wishes to play in the global digital economy.