Digital Omnibus: How the EU's Simplification Package Reduces AI Act Burden for Small and Mid-Size Companies

By Jurista.ai Editorial

The EU Rethinks AI Act Complexity

In May 2026, the European Commission reached political agreement on the Digital Omnibus, a legislative simplification package designed to reduce regulatory burden on European businesses without dismantling the core protections of EU digital regulation. For AI Act compliance, the Digital Omnibus introduces several meaningful changes that affect how small and medium-sized enterprises (SMEs) and small mid-cap companies (SMCs) approach their obligations.

The changes come at a critical time. With the 2 August 2026 enforcement deadline for high-risk AI systems approaching, many smaller organizations have expressed concern that the full weight of AI Act compliance is disproportionate to their resources and risk profiles. The Digital Omnibus responds directly to these concerns.

Key Changes for SMEs and SMCs

Extended Simplified Compliance

The AI Act originally included simplified compliance provisions for SMEs. The Digital Omnibus extends these same provisions to small mid-cap companies, defined as companies with fewer than 750 employees and an annual turnover below €150 million. This extension recognizes that mid-size companies face similar resource constraints as SMEs when building compliance programs.

The simplified provisions apply to specific elements of the quality management system (QMS) required under Article 17. The Commission will publish guidelines specifying which QMS elements may be complied with in a simplified manner. These guidelines are expected as part of the 2026 guidance package.

The key areas where simplification is expected include:

  • Documentation requirements for the QMS, potentially allowing for lighter record-keeping
  • Testing and validation procedures, potentially reducing the scope of mandatory pre-deployment testing
  • Post-market monitoring, potentially allowing for streamlined reporting mechanisms
  • Technical documentation, potentially permitting reduced detail in certain sections

Narrower High-Risk Classification

The Digital Omnibus also refines the criteria for what counts as a high-risk AI system. Under Article 6(2) of the AI Act, an AI system not listed in Annex III can still be classified as high-risk if it has significant impact on health, safety, or fundamental rights. The agreement narrows this catch-all provision, meaning fewer AI systems will automatically fall into the high-risk category.

Specifically, the changes are expected to:

  • Raise the threshold for what constitutes a “significant” impact on fundamental rights
  • Provide clearer criteria for when an AI system used as a safety component of a product should be classified as high-risk
  • Limit the cascading classification effect where AI systems become high-risk simply because they are integrated into products already subject to sectoral regulation

For organizations developing AI tools that sit at the boundary between high-risk and limited-risk, these changes could substantially reduce compliance costs.

Research and Development Exemptions

The Commission has signaled that stakeholders raised concerns about how the AI Act’s research exemptions in Article 2(6) and (8) apply in practice, particularly in pre-clinical research and product development for medicines and medical devices. The Digital Omnibus will prioritize clarifying these exemptions.

For organizations in the life sciences sector, this clarification could determine whether AI systems used in drug discovery, clinical trial optimization, and medical device development are subject to the full high-risk regime or qualify for reduced obligations.

What Does Not Change

It is important to understand what the Digital Omnibus does not modify:

  • The August 2026 deadline remains: High-risk system obligations still become enforceable on 2 August 2026. The simplified provisions reduce complexity, but they do not delay enforcement.

  • Prohibited practices remain prohibited: The ban on unacceptable-risk AI practices, effective since February 2025, is unchanged.

  • GPAI model obligations remain: The rules for general-purpose AI models, effective since August 2025, are not altered.

  • Maximum penalties remain unchanged: The fine structure under Article 99 is not modified. For SMEs and SMCs, the percentage-of-turnover formula still applies.

  • Fundamental rights protections remain: The core obligations to protect individuals from AI-related harms are not weakened. Simplification concerns process and documentation, not safety standards.

How to Benefit from Simplified Provisions

Step 1: Determine Your Company Status

First, confirm whether your organization qualifies as an SME or SMC under EU definitions. The SME definition depends on staff headcount and either annual turnover or balance sheet totals. The SMC definition, newly relevant under the Digital Omnibus, applies to companies with 250 to 749 employees and turnover below €150 million.

Organizations should document their qualification carefully, as national authorities may request evidence of size classification when evaluating compliance.

Step 2: Map Simplified Provisions to Your QMS

Once the Commission publishes the detailed guidelines on which QMS elements can be simplified, map these provisions to your existing compliance program. The simplified elements do not eliminate obligations entirely; they reduce the scope, detail, or formality required.

For example, while a large company might need a multi-hundred-page technical documentation file, an SME or SMC might be able to submit a more streamlined version focusing on the most critical safety and rights information.

Step 3: Engage with Your National Authority

National supervisory authorities are responsible for implementing the simplified provisions. Engage proactively with your national authority to understand how they interpret the simplified requirements. Some Member States may provide additional national-level simplification or guidance.

Early engagement is particularly important because authorities may differ in how they apply the simplified provisions. Understanding your authority’s expectations before the August deadline reduces the risk of compliance disputes later.

Step 4: Leverage Voluntary Tools

The Commission has developed several voluntary compliance tools alongside the Digital Omnibus:

  • The AI Act Service Desk: A single point of contact for questions about applying the AI Act, accessible through the Single Information Platform.
  • Voluntary post-market monitoring template: A standardized template for monitoring high-risk AI systems after deployment.
  • Fundamental rights impact assessment template: A voluntary template for deployers conducting assessments under Article 27.

These tools are designed to reduce the administrative burden of compliance, particularly for smaller organizations.

Impact on Different Sectors

The simplified provisions have varying impact across sectors:

Technology Startups

For AI startups, the extension of simplified provisions to SMCs is particularly significant. Many AI startups grow past the 250-employee SME threshold but still lack the compliance infrastructure of large enterprises. The SMC provisions bridge this gap, giving mid-size companies additional time and flexibility.

Healthcare and Life Sciences

The research exemption clarifications could be transformative for healthcare AI companies. If pre-clinical research and medical device development AI tools are clearly exempted from the high-risk regime, companies can accelerate development timelines while maintaining compliance for clinical-stage products.

Financial Services

AI systems used for credit scoring and financial risk assessment remain high-risk under Annex III. However, the narrower classification criteria may help financial institutions that deploy AI tools in adjacent areas, such as customer service or internal compliance monitoring, avoid over-classification.

Manufacturing

AI systems used as safety components in industrial machinery remain high-risk. But the clarification of what constitutes a safety component may help manufacturers avoid classifying general-purpose monitoring tools as high-risk simply because they operate in an industrial environment.

Timeline for Implementation

The Digital Omnibus political agreement was reached in May 2026. The legislative process for final adoption is ongoing, with formal adoption expected in the coming months. However, the Commission has signaled that the AI Office will begin applying the spirit of the simplification measures immediately through its guidance work.

Organizations should prepare for the simplified provisions now, rather than waiting for the formal legislative process to conclude. The August 2026 deadline will arrive before the Digital Omnibus is fully transposed, and authorities will likely apply the agreed simplification principles even before formal adoption.

Strategic Implications

The Digital Omnibus reflects a broader shift in EU digital policy. The initial wave of digital regulation, from GDPR through the AI Act, established comprehensive protections. The current phase focuses on simplification and practical implementation, responding to concerns that regulatory burden is stifling European innovation.

For organizations, this shift creates opportunities. Compliance is becoming more proportionate to organizational capacity, but the core requirement to build safe and trustworthy AI remains. Companies that invest in compliance now, even at the simplified level, will be better positioned than those that wait.

The organizations most at risk are not those that struggle with the simplified provisions, but those that assume the Digital Omnibus eliminates their obligations entirely. It does not. The AI Act remains in force, the enforcement deadline is real, and the penalties for non-compliance are substantial.

Conclusion

The Digital Omnibus provides meaningful relief for small and mid-size companies, but it is not a regulatory holiday. Organizations should use the simplified provisions strategically: reduce compliance overhead where possible, invest the savings in the most critical safety and transparency measures, and prepare for full enforcement on 2 August 2026.

Understanding which provisions apply to your organization, how to implement them, and how to document compliance is the practical challenge ahead. The resources are available. The question is whether your organization is using them.


Jurista.ai helps small and mid-size companies navigate simplified AI Act compliance provisions, identify applicable exemptions, and build proportionate compliance programs. Assess your compliance at jurista.ai.