Digital Omnibus
In November 2025, the European Commission proposed the EU Digital Omnibus, a legislative package aimed at simplifying and consolidating existing EU digital legislation, notably the AI Act and data, cybersecurity and privacy rules, including the General Data Protection Regulation (GDPR). The initiative seeks to improve the practical interaction between these regulatory frameworks, reduce administrative burdens and enhance regulatory coherence, while maintaining core protections and safeguards.
More specifically, the Digital Omnibus on AI focuses on targeted adjustments to the AI Act, including compliance timelines for high-risk AI systems, alignment with sectoral legislations such as the Medical Device and In-vitro Device Regulations (MDR/IVDR) and simplification measures for small and medium-sized enterprises (SMEs). On the other hand, the Digital Omnibus on Data, Cybersecurity and Privacy aims to clarify some aspects of the GDPR and related legislation, including the use of data for scientific research and AI training as well as to introduce a risk-based approach to data governance.
The Digital Omnibus is particularly relevant for radiology, which sits at the intersection of multiple EU regulatory frameworks governing medical devices, artificial intelligence and health data. Proposed changes may affect the development, validation and deployment of AI-enabled imaging tools, as well as the legal conditions for using large retrospective imaging datasets for research and innovation.
In this regard, the ESR AI Working group welcomed the European Commission’s efforts to refine and simply the AI Act as well as data protection rules (see ESR response to the European Commission Call for Evidence), but it also highlighted several essential considerations:
- In the Digital Omnibus on AI feedback, ESR emphasised the need to ensure the safe and effective use of AI in healthcare, particularly in medical imaging, by aligning and streamlining the AI Act with the forthcoming revision of the medical devices and in vitro diagnostic devices frameworks. More specifically, ESR called for more coordinated conformity assessment procedures to reduce unnecessary regulatory complexity while maintaining robust oversight and ensuring patient safety. The ESR also highlighted the need for clear guidelines on post-market monitoring.
- In the Digital Omnibus on Data, Cybersecurity and Privacy feedback, ESR called for legal certainty, proportionality, traceability of sensitive health data, as well as harmonised implementation across Member States.
At the political level, in May 2026, the Council of the European Union and the European Parliament found an agreement on the Digital Omnibus on AI, which entered into force on 27 July 2026. The new legal framework postponed the deadline for compliance with the AI Act for high-risk AI systems to 2 December 2027 for high-risk AI systems under Annex III and to 2 August 2028 for high-risk AI systems embedded in physical products under Annex I.
The Digital Omnibus on Data, Cybersecurity and Privacy is still being discussed by the European Parliament and the Council.
For more information, please visit the following links:
- Digital Omnibus on AI
- Press release – Digital Omnibus on AI
- EC Proposal for a Digital Omnibus on Data, Cybersecurity and Privacy
- EC Factsheet Digital Package
- ESR response to the Call for Evidence on the Digital Omnibus
- ESR response to the Digital Omnibus on AI Consultation
- ESR response to the EU Digital Omnibus on Data, Cybersecurity and Privacy Consultation