The EU Digital Omnibus: What SaaS and Software Companies Need to Know Now

Dr. Eduard Hofert
Dr. Eduard Hofert
20.08.2026

Key Takeaways

  • The Data Act has applied since September 2025. New from September 2026: Connected products and related services must implement "access by design," with user data accessible and portable by default.
  • The GDPR is set to become more workable: AI training could be based on legitimate interest, and cookie consent could soon be managed directly in the browser.
  • Cybersecurity: A central EU-wide reporting portal is meant to consolidate parallel reporting obligations under the GDPR, NIS 2, and DORA.
  • The AI Act gets firm deadlines: High-risk AI systems must be compliant by December 2, 2027 (standalone) or August 2, 2028 (embedded in regulated products).
  • The Digital Omnibus is still moving through the legislative process. The trilogue is underway, and agreement is expected before the summer 2026 recess.

The EU Digital Omnibus: What SaaS and software companies need to know now

How the EU is reorganizing its digital rulebook, and what companies should watch now

SaaS providers and software companies have spent the past several years adapting to the AI Act, the Data Act, the DSA, the NIS 2 Directive, DORA, and the Cyber Resilience Act. The list of regulations touching day-to-day business keeps growing. Depending on how a service and its feature set are classified, a company can fall under several regulatory regimes at once. And just as the first compliance structures are in place, the EU Commission is following up with the "Digital Omnibus."

What does this legislative package mean for your own practice? Which changes are taking shape, and where do risks remain?

This article gives SaaS providers and software companies a practical breakdown.

Where things stand

2026 is shaping up as the year in which core European digital regulation is fleshed out and applied, and regulatory density is rising noticeably. In parallel, the European Commission has published the "Digital Omnibus" alongside two flanking initiatives: the Data Union Strategy, meant to foster a single European data space, and the "European Business Wallet" initiative, intended to give companies a standardized digital identity and simplified access to government services. Together, these proposals aim to reshape how companies comply with European data regulation and to strengthen the digital single market.

One important caveat up front: These rules are not yet in force. This is a legislative proposal that still has to be negotiated and adopted by the European Parliament and the Council. Specific deadlines, standards, and responsibilities therefore remain partly open.

At the same time, the proposals clearly show the direction in which the EU wants to harmonize its digital rulebook, reduce duplicate regulation, and make implementation more practicable for companies, all without lowering the level of protection. That already gives a clear signal for what to watch on your product and compliance roadmap.

What is the Digital Omnibus?

The Digital Omnibus is not an entirely new body of law with standalone, directly applicable obligations. It is an amending regulation designed to better connect the many existing digital regulations (such as the AI Act and the Data Act), reduce overlapping requirements, and make implementation more workable for companies. The point is not a new substantive direction, but technical and organizational simplification.

The discussions focus, among other things, on adjusting deadlines, sharpening obligations, standardizing key definitions, aligning parallel compliance requirements, and easing the burden on small and mid-sized companies.

The goal is to avoid duplicate regulation and disproportionate burdens without lowering the standard of protection itself.

For SaaS and software companies this matters a great deal, because depending on how a service is classified (hosting service, data processing service, related service, AI provider, and so on), different regulatory regimes apply, some with substantial compliance obligations.

The four areas that matter most for SaaS and software companies

For SaaS providers, four topic areas are especially relevant: data use and data access, data protection and consent, cybersecurity reporting, and the supervisory structures for AI.

I. Data Act: Clear rules for data access and cloud switching

For SaaS providers, the Data Act is particularly relevant in two scenarios.

1. SaaS as a "related service"

If a SaaS service is functionally linked to a connected product and enables or substantially extends its use, it qualifies as a "related service" under the Data Act, with the consequence that the provider acts as a data holder. That means:

· Users must be given legally secured access to product and service data, including real-time retrieval and technical interfaces.

· Data must be provided in a structured, commonly used, machine-readable format.

· Access must be simple, secure, and free of charge.

· Technical and contractual barriers must not obstruct data sharing.

2. Protection of trade secrets

The Digital Omnibus draft strengthens the protective mechanisms: Data holders may refuse to share data where there is a high risk that trade or business secrets could be disclosed in third countries with an inadequate level of protection. That refusal remains limited to narrow exceptions and must be justified.

3. SaaS as a "data processing service"

Most SaaS offerings that store, process, or provide data in a platform environment qualify as data processing services (cloud services) under the Data Act. For SaaS providers this means:

  • An obligation to design systems so customers can export their data in a practicable form and move it to another service.
  • Switching must not be obstructed by excessive switching fees or proprietary lock-in formats.

The Omnibus draft provides some relief here:

  • Smaller providers get longer transition periods and can structure exit procedures more pragmatically.
  • Switching obligations for highly customized SaaS services are set to be softened.

Further practical instruments of the Digital Omnibus in data law include:

  • Model contractual clauses for data access and use,
  • Standard contractual clauses for cloud service agreements, and
  • Improved access to high-quality datasets for AI training.

A note on deadlines: The Data Act has applied directly across the entire EU since September 12, 2025. One important exception is the "access by design" obligation: Connected products and related services only need to be designed by default so that product data is easily, securely, and freely accessible to users if they are newly placed on the market after September 12, 2026. The design obligation does not apply retroactively to existing products and services.

II. Cybersecurity: One central reporting portal for the entire EU

Today, companies must report security incidents under the GDPR, NIS 2, DORA, or sector-specific laws, often submitting the same information to different authorities.

The Digital Omnibus therefore proposes a single digital European reporting portal through which companies would report all cybersecurity-relevant incidents in one place. The portal is also meant to integrate certification information from the Cybersecurity Act.

For smaller companies (up to 250 employees), the draft also extends the reporting deadline to 120 hours.

Why this matters for SaaS companies: If you serve business customers in several EU countries, you benefit substantially from less fragmentation and the elimination of duplicate reporting obligations.

III. GDPR: Targeted changes for more workability

The core of the GDPR remains unchanged. The Omnibus draft aims at clarifications and simplifications:

1. Modernized cookie consent

Consent settings are to be managed directly in the user's browser or on their device. The goal: fewer banners, more usability.

2. AI training and legitimate interest

Under certain conditions, AI training could be based on Art. 6(1)(f) GDPR (legitimate interest), provided suitable technical and organizational measures are in place. Complementary guidelines on privacy-friendly training methods are to be published.

3. Simplified reporting obligations

Data breaches that pose no significant risk would no longer have to be reported to the supervisory authority; internal documentation would suffice. For companies with fewer than 250 employees and low risk, information and reporting obligations are to be simplified.

4. Uniform interpretation

Especially relevant for internationally active SaaS providers: A more uniform interpretation of the GDPR across all member states is meant to reduce legal uncertainty.

IV. AI Act: Predictability and a sharper risk focus

For SaaS and software companies, a key question is which obligations apply to high-risk AI systems. Here, the Digital Omnibus package has produced decisive political course-setting. On March 13, 2026, the Council of the European Union adopted its position on streamlining certain provisions of the AI Act, and the European Parliament has reached a political compromise as well. The two positions largely align on the central points, so a quick agreement is expected in the upcoming trilogue.

1. Firm deadlines for high-risk AI systems

Most relevant for companies is the introduction of clear, postponed application dates. The Commission's original proposal tied the high-risk obligations to the availability of the required EU standards, applying at the latest 16 months after their confirmation. The Council and Parliament have now replaced that approach with fixed application dates:

  • December 2, 2027, for standalone high-risk AI systems, and
  • August 2, 2028, for high-risk AI systems embedded in regulated products.

For SaaS providers offering AI functionality, that means more planning certainty for implementing risk management, technical documentation, data governance, logging mechanisms, and human oversight. Implementation planning can now be anchored to concrete dates.

2. Registration obligation and risk classification

Another change with real practical impact is the newly introduced (or rather reintroduced) obligation to register high-risk AI systems in the EU database. It applies in principle to every provider that classifies, or must classify, a system as high-risk AI. What's new: Providers that do not classify their system as high-risk will have to formally document and justify that assessment; a purely internal judgment without formal backing will no longer suffice.

For SaaS companies with AI functionality, this creates an additional documentation and justification obligation, even if they assume they fall outside the high-risk category.

3. Bias detection: Stricter requirements for sensitive data

The Commission's proposal created a new legal basis for processing sensitive data to detect and correct bias. The Council has tightened that proposal and reintroduced the principle of strict necessity for processing special categories of personal data.

For SaaS providers whose AI systems work with HR or health data, for example, this raises the bar for justifying training and bias correction under data protection law.

Other relevant changes

  • Simplified documentation for SMEs and small mid-caps, along with softer penalty frameworks, remain in the draft.
  • The deadline for setting up national AI regulatory sandboxes moves to December 2, 2027. The EU-wide sandbox program led by the AI Office, with priority access for startups, remains planned.
  • The AI Office's role as the central supervisory authority for GPAI models is being clarified, along with the exceptions in which national authorities remain competent.
  • Sectoral carve-outs with reduced compliance effort are planned for products already covered by harmonized single-market rules.
  • The Commission is also expected to issue guidelines to keep the administrative burden on deployers and providers of high-risk AI systems as low as possible. For SaaS providers whose systems are used in regulated industries in particular, this could make compliance planning easier.
  • The interplay with the Cyber Resilience Act remains: AI systems that meet its security requirements are to be deemed IT-secure automatically.

4. Role allocation remains decisive

Regardless of the procedural changes, careful role and risk classification remains indispensable for SaaS providers. Whenever a SaaS product offers AI functionality, the allocation of roles under the AI Act is critical: Who actually controls the AI system? Who is responsible for its use? In our blog post on the deemed-provider rule, we walk through role classification in typical SaaS scenarios and what to watch when SaaS-based AI systems are used for high-risk purposes.

What happens next?

The European Parliament's committees formally voted on the compromise on March 18, 2026, and the plenary adopted its negotiating mandate on March 26, 2026. The trilogue between Parliament, Council, and Commission has thus begun. Given how closely the two positions align, the trilogue is expected to conclude before the summer 2026 recess. The cornerstones outlined above are unlikely to change fundamentally in the remaining legislative process.

What companies should do now

Even though the Digital Omnibus has not yet been adopted (and existing obligations are neither repealed nor substantively weakened by it), the implementation effort will not shrink, but it will become more predictable. Existing obligations are being given firmer timelines and clearer structure.

For SaaS and software providers, the following steps are worth taking now:

1. Classify your SaaS service precisely: Different obligations apply depending on whether you qualify as a related service, a data processing service, a hosting provider, or an AI provider or deployer. Document which role your company plays in which context.

2. Run your AI role and risk classification: Clarify whether your company acts as the provider, deployer, or user of an AI system. Document your processes for quality assurance, human oversight, and model management. By 2026 at the latest, you need robust processes for risk management, documentation, and incident reporting.

3. Build internal compliance structures: Uniform documentation and reporting procedures, clear responsibilities, and aligned risk analyses form the foundation. Align existing data protection, IT security, and AI processes so they are compatible with the new system.

4. Track the Omnibus negotiations actively: Work the expected changes into your compliance roadmaps for the AI Act and NIS 2, and evaluate the impact on cloud contracts and exit provisions.

5. Coordinate across departments early: Close collaboration between legal, IT, product, and procurement lets you build regulatory requirements into development processes from the start.

Use the runway gained through the end of 2027 and 2028 strategically. A staged, resource-conscious approach works best: one that prioritizes the requirements that already apply today or will become applicable shortly. In many areas, the task is less about establishing new processes than about consistently implementing regulatory requirements that already exist. A solid foundation of that kind lets you integrate new requirements step by step as they become binding and prevents costly rework.

The bottom line for SaaS and software companies

The European legal framework for SaaS and software providers (with the Data Act, the DSA, and the AI Act) is already demanding, and it fundamentally shapes operations, data architecture, and vendor relationships. The Digital Omnibus draft adds clarity by harmonizing interfaces and providing transition periods and, in places, relief.

Important: The Digital Omnibus is still in the legislative process and has not yet been adopted. The specific changes and their reach remain open for now.

The strategic direction, however, is unmistakable: The EU is working toward a harmonized, more predictable, more innovation-friendly digital legal framework.

For SaaS and software providers, that means: Acting with foresight now creates a strategic advantage. Build internal compliance structures that are audit-ready, scalable, and adaptable, so new requirements can be integrated step by step as they become binding. Establishing a resilient foundation early not only avoids expensive rework later; it also builds trust with customers and partners in the European market.