The wider EU stack and the Digital Omnibus

Lesson 6 of 6 in Governance, Enforcement, Penalties, and Sandboxes.

The AI Act never operates alone. Any real deployment sits inside a stack of EU laws that apply simultaneously, and the professional skill is reading the intersections: the same hiring system can owe an AI Act FRIA, a GDPR DPIA, worker-information duties, and — if it injures someone — a product-liability claim.

The deepest entanglement is with the GDPR. The FRIA (Art 27) explicitly builds on and complements the DPIA (GDPR Art 35) — where a DPIA already covers ground, the FRIA supplements it rather than repeating it. Article 86’s explanation right gap-fills behind GDPR Article 22, as you saw. Biometric systems trigger special-category processing rules the moment they touch Article 9 GDPR data. And AI Act Article 10(5) grants what the GDPR alone struggled to: a legal pathway to process special-category data for bias detection and correction in high-risk systems, ringed with safeguards (necessity, security, no transfer, deletion). The supervisors overlap too — the EDPB and EDPS police the data side, the EDPS doubles as the AI Act enforcer for EU institutions, and several Member States handed AI Act surveillance to their DPAs outright.

Where the AI Act meets its neighbours
InstrumentWhat it governsKey intersections with the AI ActWatch-outs

GDPR

Processing of personal data

FRIA ↔ DPIA; Art 86 ↔ Art 22 automated decisions; biometric special-category data; Art 10(5) bias-correction basis

Two regulators can investigate the same system for the same event — coordinate responses, never contradict yourself between filings

Digital Services Act

Online platforms and intermediaries

VLOP systemic-risk assessments cover recommender and generative-AI harms; recommender transparency; deepfake handling on platforms

A platform’s recommender may face DSA duties even where the AI Act treats it as minimal-risk

Product Liability Directive (EU) 2024/2853

No-fault liability for defective products — now explicitly including software and AI systems

Claimant-friendly disclosure orders and rebuttable presumptions of defectiveness/causation where technical complexity makes proof excessively difficult; AI Act non-compliance feeds defect arguments

This is where individual compensation lives — the AI Act itself awards none

Sector product law (MDR/IVDR, Machinery Reg 2023/1230)

Medical devices; machinery (applies from January 2027)

Annex I route: AI Act requirements verified inside the sectoral conformity procedure; Art 73 reporting deferred to sectoral vigilance except fundamental-rights incidents

One product, several regimes — align the technical files so they tell one story

Cyber Resilience Act & DSM copyright

Cybersecurity of products with digital elements; text-and-data-mining rules

Cyber certification can presume Art 15 conformity (Art 42(2)); GPAI copyright policies must honour DSM Art 4(3) TDM opt-outs

The GPAI training-data summary makes copyright compliance publicly inspectable

Finally, the Digital Omnibus — and the lesson it teaches about regulation as a living process. Under a “simplification” banner responding to competitiveness pressure, the Omnibus amended the AI Act’s application calendar before its centrepiece ever applied: Annex III high-risk rules deferred to 2 December 2027, Annex I high-risk to 2 August 2028, and the synthetic-content transparency compliance deadline set at 2 December 2026. The prohibitions, AI literacy, GPAI chapter, and the governance and penalties architecture you studied in this module were already in application and stayed put.

Read the Omnibus as regulatory politics, not housekeeping. The deferral is widely linked to the delay in harmonized standards — enforcing a rulebook whose compliance tooling doesn’t exist invites failure — but it also reflects a broader push to lighten EU digital regulation. For a governance professional the operational rule is: track the amendments, not the folklore. Half the AI Act summaries in circulation predate the Omnibus, and advice built on the original dates is now simply wrong.

Tool: Regulatory Time Machine — Scrub the compliance timeline 2024–2030 with the Omnibus toggle: see which obligations bit when — and which dates moved.

Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.