The European Commission's November 19 omnibus packages introduced two proposals that will reshape your approach to AI compliance. One targets the GDPR, while the other proposes delaying regulation of high-risk AI systems under the EU AI Act. If you're a Data Protection Officer (DPO), you've likely heard colleagues making assumptions about what this means. Most of those assumptions are wrong.
These myths persist because regulatory change creates uncertainty, and uncertainty breeds oversimplification. Your legal team wants clear answers. Your engineering leads want to know if they can pause compliance work. Your executives want to know if the AI Act "doesn't matter anymore." None of these narratives hold up under scrutiny.
Myth 1: The Delay Means High-Risk AI Systems Won't Be Regulated
Reality: The proposal delays enforcement timelines, not the regulatory framework itself. High-risk AI systems remain defined under the AI Act. The classification criteria haven't disappeared. What's changed is when certain obligations kick in, not whether they apply.
If you're deploying AI systems in employment screening, credit scoring, or law enforcement support, those use cases still fall under high-risk categories. The delay affects your compliance deadline, not your compliance obligation. You still need to understand which Article 6 systems you're running. You still need documentation showing how you identified them. The supervisory authority reviewing your practices in 2027 won't accept "we thought the delay meant it didn't apply" as a defense.
Myth 2: You Can Pause AI Governance Work Until the Delay Ends
Reality: Pausing now creates a compliance debt you can't repay quickly. High-risk AI compliance requires transparency documentation, human oversight protocols, accuracy testing, data quality assessments, and risk management systems. None of these materialize overnight.
If you wait until the delayed deadline approaches, you'll face the same problem organizations had with GDPR in 2017. They assumed six months was enough time to map processing activities, draft privacy notices, and implement appropriate technical and organizational measures. It wasn't. The organizations that started early had functioning compliance programs. The ones that waited had panic, incomplete records, and supervisory authority inquiries.
The delay gives you breathing room to build robust systems, not permission to ignore the work. Use it to pilot your risk classification process on a small set of AI systems. Test your human review procedures. Document your data quality checks. When enforcement begins, you want a mature program, not a rushed checklist.
Myth 3: GDPR Amendments and AI Act Changes Are Separate Tracks
Reality: The two proposals interact in ways that affect your compliance strategy now. The GDPR has always applied to AI systems that process personal data. Article 22 already restricts automated decision-making. Transparency obligations under Articles 13 and 14 already require explaining automated processing.
The omnibus packages signal that the Commission sees these frameworks as interconnected. Changes to GDPR could clarify how existing obligations apply to AI systems. Changes to the AI Act could create new touchpoints with your data protection program. If you're treating AI compliance as something your innovation team handles separately from privacy compliance, you're building silos that will fracture under regulatory pressure.
Your GDPR compliance program already includes elements the AI Act will reference: records of processing activities, data minimization practices, lawful basis assessments. When you document an AI system's purpose and lawful basis under Article 30, you're creating artifacts your AI Act compliance will need. When you conduct a legitimate interests assessment for an AI-driven analytics tool, you're doing work that overlaps with AI risk assessment. Don't duplicate effort by treating these as unrelated workstreams.
Myth 4: The Delay Reflects Weakening Political Will for AI Regulation
Reality: Regulatory delays often reflect calibration, not capitulation. Laura Caroli, a former AI Act negotiator, has noted the complexity surrounding these proposals. Complexity doesn't mean retreat. It means the Commission is balancing competing pressures: innovation concerns from industry, enforcement capacity constraints from member states, and ongoing questions about how to implement novel requirements.
What you're seeing isn't a signal that AI regulation is softening. It's a signal that the Commission is adjusting timelines to match implementation realities. Supervisory authorities need time to build expertise. Organizations need time to understand requirements. Delayed enforcement can produce stronger compliance if it's used for preparation rather than procrastination.
Watch what the Commission does with the delay period. If they issue guidance, create sandbox programs, or publish implementation templates, that's not weakness. That's regulatory infrastructure that will make enforcement more effective when it begins.
Myth 5: Your Current AI Inventory Is Sufficient for AI Act Compliance
Reality: Most AI inventories built for GDPR purposes won't meet AI Act requirements without significant expansion. Your Article 30 records document processing activities, controllers, processors, and categories of data subjects. That's essential but incomplete for AI Act purposes.
The AI Act requires you to know the specific AI technique used, the risk classification, the conformity assessment pathway, and the human oversight model. If your inventory lists "machine learning model for customer segmentation," you need more detail. What type of model? What's the decision impact? Who reviews outputs? What's your accuracy threshold?
You also need to track AI systems that don't process personal data but still fall under the AI Act. A quality control system using computer vision on manufacturing lines might not trigger GDPR if it doesn't identify workers, but it could still be high-risk under the AI Act depending on safety implications. Your inventory scope needs to expand beyond personal data processing.
What to Do Instead
First, treat the delay as a design phase, not a waiting period. Map your AI systems now using both GDPR and AI Act criteria. Identify gaps in your current documentation. Build templates that serve both frameworks.
Second, establish a cross-functional AI governance team that includes your DPO, legal counsel, IT security, and business unit leads. The delay gives you time to break down silos before enforcement pressure forces hasty coordination.
Third, pilot your compliance approach on one or two high-risk AI systems. Test your risk classification process. Document what works and what doesn't. When the delay ends, you'll have a proven methodology, not a theoretical framework.
Fourth, monitor the omnibus negotiation process. The proposals will evolve. Your compliance strategy should evolve with them. Subscribe to supervisory authority updates. Track guidance from the European Data Protection Board. Watch for implementation tools from the Commission.
The delay isn't a pause button. It's a runway. Use it to build systems that work, not to postpone decisions you'll regret later.



