The European Commission unveiled a digital omnibus package aimed at cutting compliance burdens for businesses while keeping core protections for data protection, cybersecurity, safety, and fairness intact. The proposal would simplify rules across AI, cyber, and data regulation, including delaying some obligations for high-risk AI systems until standards and support tools are ready, creating a single entry point for cybersecurity incident reporting, and making targeted adjustments to the GDPR and the Data Act. Brussels said the measures could save companies up to €5 billion in administrative costs by 2029, alongside broader plans such as a data union strategy to expand access to high-quality data for AI and strengthen safeguards for sensitive non-personal data.
In the United States, policy advocates renewed calls for Congress to pass the SECURE Data Act as a federal privacy framework to replace the current patchwork of state laws with a single national standard. The proposal would emphasize data minimization, require affirmative consent for sensitive personal information, add protections around automated profiling and children’s data, and rely on enforcement by the Federal Trade Commission and state attorneys general. Together, the developments reflect parallel efforts on both sides of the Atlantic to streamline digital compliance while establishing clearer privacy and data-governance rules for businesses and emerging technologies.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
As part of the same 2025-11-19 announcement, the European Commission said it had launched a digital fitness check and a public consultation under its broader competitiveness agenda. It also stated that the legislative proposals would proceed to the European Parliament and the Council.
On 2025-11-19, the European Commission announced a digital omnibus package to simplify AI, cybersecurity, data, and privacy compliance rules for EU businesses while maintaining protections for rights, safety, and fairness. The package included proposals such as delaying some high-risk AI compliance obligations until support tools and standards are available and creating a single-entry point for cybersecurity incident reporting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.