The Digital Omnibus on AI (AI Omnibus) has now been published in the EU’s statute book. This pushes back some of the application dates for the AI Act. So, what’s applicable now and when will the rest become applicable? This post gives an overview of key dates to be aware of and a timeline of when the obligations now become enforceable.
Rosie Nance
Record €18m fine for an IT service provider to the aviation sector – reuse of customer data
Spain’s data protection agency, the Agencia Española de Protección de Datos (AEPD), has fined Amadeus IT Group, S.A. (Amadeus) €18 million in relation to a traveller profiling pilot project. The enforcement decision, published in May 2026…
Is my use case a high-risk AI system? Applying the Commission’s guidelines and next steps
The EU Commission’s long-awaited guidelines on high-risk AI systems were published on 19 May 2026. This is the promised explainer on what is – and is not – a high-risk AI system under the EU AI Act.
The guidelines
The…
UK data protection complaints – new complaints handling obligations for controllers from 19 June
The changes to data controllers’ complaints handling obligations, made via the Data (Use and Access) Act, will come into force on 19 June 2026. These include a new obligation to acknowledge complaints within 30 days, respond without undue delay, and…
Agentic AI: the ICO’s early thoughts on the data protection implications
The ICO has kicked off 2026 with sharing its early thoughts on the data protection implications of agentic AI in its ICO tech futures: Agentic AI report. The report considers the novel data protection risks presented by agentic AI.
UK Cyber Security and Resilience Bill – new obligations for the data centre sector
This blog post includes headline points on new obligations for the data centre sector proposed under the Cyber Security and Resilience Bill, and existing obligations under the NIS Regulations.
NIS Regulations Keeling Schedule for the Cyber Security and Resilience Bill – changes to the UK’s cyber security law
The Cyber Security and Resilience Bill proposes changes to the UK’s NIS Regulations. Without a ‘Keeling Schedule’ marking up the amendments, these can be difficult to track. We have prepared a mark-up reflecting the proposed changes.
Changes to EU and UK data protection law – a tale of two GDPRs?
The EU Commission recently held a call for evidence on “simplification” of legislation in the data, cybersecurity, and AI space, ahead of a “Digital Omnibus” Act. These changes look to make the EU’s digital rulebook more innovation-friendly, supporting the Commission’s…
Pseudonymised data could fall outside data protection law – introducing the “means reasonably likely” assessment
The Court of Justice of the European Union (CJEU) has delivered its judgment on case C 413/23 P European Data Protection Supervisor (EDPS) v Single Resolution Board (SRB). The CJEU has confirmed that pseudonymised…
Explain yourself: The legal requirements governing explainability
Agentic AI brings the promise of AI making a range of decisions autonomously. It has been proposed as the way forward for some of the most impactful decisions in our lives: interacting with customers and actioning requests, triaging requests for…