EU AI Act Omnibus: What It Actually Means for NI and RoI Businesses

Illustrated coral folder and document titled EU AI Act Updates, the full picture for NI and RoI SMEs.
EU AI Act Omnibus: What It Actually Means for NI and RoI Businesses | Aiforya

EU AI Act Omnibus: What It Actually Means for NI and RoI Businesses

The EU AI Act Omnibus provisional agreement landed on 7 May 2026 and within hours, LinkedIn filled with carousels declaring rigid AI compliance “out” and celebrating relief for smaller organisations. Some of that is real. Parts of it are being overstated. And for businesses in Northern Ireland and the Republic of Ireland, the picture is more layered than most posts suggest.

Here is what actually changed, what has not, and why now is still exactly the right time to get your governance in order.


First, the important caveat

This is a provisional political agreement. It has not yet been formally adopted, and it has not been published in the Official Journal of the EU. Until both of those things happen, the current AI Act text remains in force.

Plans made now will be relevant regardless of when the text is finalised. The direction of travel is clear enough to act on.

So before you put any compliance plans on hold based on what you have read this week: do not.


What the Omnibus VII agreement actually says

1 High-risk AI deadlines have moved — but not gone

Stand-alone high-risk AI systems will now face full obligations from 2 December 2027. High-risk AI embedded in regulated products faces a later deadline of 2 August 2028. For most SMEs deploying general business tools, this matters less than it sounds. If you are using AI in HR decisions, credit scoring, or anything that could affect someone’s rights or access to services, high-risk classification may well apply to you.

2 SME relief now extends to small mid-caps

Previously, simplified documentation requirements and proportionate penalties applied to SMEs under 250 employees. The agreement extends those reliefs to small mid-cap companies of up to 500 employees. Lighter documentation does not mean no documentation. It means the compliance pathway is better sized for the resources you actually have.

3 Bias detection gets clearer legal footing

Special-category personal data may now be processed for bias detection and correction, but only where strictly necessary and subject to safeguards. It comes with conditions, not a blanket permission.

4 AI literacy obligations shift to Member States

The obligation to drive AI literacy moves primarily to the European Commission and Member States rather than sitting with individual providers and deployers. This reduces the direct burden on your organisation. It does not remove the need for your team to understand the AI tools they are using.

5 Registration is still required — and the loophole is closed

Providers must now register AI systems in the EU database even where they consider their system to be outside high-risk classification. The act of self-assessment does not exempt you from registration. This actually tightens things, not loosens them.

6 Transparency obligations move faster, not slower

Watermarking and provenance-labelling for AI-generated content is now expected by 2 December 2026. That is sooner than many had anticipated. If your firm produces AI-generated documents, reports, or communications, this applies to you.


The NI and RoI position is more complex than most posts acknowledge

Businesses in Northern Ireland operate in a genuinely dual-regulatory environment. UK GDPR, regulated by the ICO, applies to your processing of personal data in NI. EU GDPR, regulated by the Data Protection Commission in Dublin, applies if you are offering services to individuals in the Republic of Ireland or monitoring their behaviour. The EU AI Act will apply to you if your AI systems are deployed in the EU. For many NI firms with RoI clients, they are.

The UK adequacy decision, which allows data to flow freely between the EU and UK, was renewed in late 2025 and runs until December 2031. That is settled ground for now. It is not permanent, and it warrants monitoring.


What is happening on the UK side

While attention has been on the EU, the UK Data (Use and Access) Act has been quietly coming into force in stages since February 2026. For NI firms, the practical changes include:

Automated decision-making rules have been updated. Since 5 February 2026, organisations can use AI for automated decisions in more circumstances, but only with proper safeguards, the ability for individuals to request human intervention, and the ability to challenge decisions. If your firm uses AI tools that make or inform decisions about clients or employees, this applies now.

PECR fines have increased sharply. Maximum penalties under the Privacy and Electronic Communications Regulations have aligned with UK GDPR levels: up to £17.5 million or 4% of global annual turnover, up from a previous cap of £500,000. If you send marketing communications or use tracking technologies, the risk profile has changed significantly.

A new complaints-handling regime arrives in June 2026. From 19 June, organisations must have a formal process for handling data protection complaints, including acknowledging them within 30 days.

A new lawful basis is in development. “Recognised legitimate interest” for UK processors is coming, with ICO guidance expected through 2026. This will be relevant for NI firms seeking to use legitimate interests as a basis for AI-related processing.


The thing I keep coming back to

The Omnibus changes make compliance more proportionate. That is welcome. But proportionate is not the same as optional.

The narrative that “developers carry all the regulation” is one I hear regularly, and it is not accurate. Under both the EU AI Act and UK GDPR, deployers — the organisations that put AI tools to use — carry meaningful obligations. Those include understanding what the tool does, being able to explain decisions it informs, protecting the data it processes, and being able to demonstrate that governance is in place.

A solicitors’ firm using AI to draft correspondence, an accountancy practice using AI to flag client risks, a charity using AI to screen referrals — all deployers. Regulatory responsibility does not sit with the software vendor alone.


What this means if you are a small firm in NI or Ireland right now

You do not need to panic. But you do need to act. Three things are worth doing before the end of summer:

Understand what AI tools you are actually using. Many firms have staff using tools informally that the organisation has not assessed. That is where governance gaps tend to sit.

Know your data flows. If you have RoI clients, EU GDPR applies to that relationship. If you use US-based AI tools, there are data transfer considerations. These questions have answers — but only if you ask them.

Document your classification rationale. If you believe your AI use falls outside high-risk, write down why. The registration requirement now applies regardless, and the ability to evidence your reasoning matters under both the AI Act and GDPR.

Governance that is proportionate, practical, and documented is not a burden. It is what lets you use AI with confidence — and what lets your clients trust you when you do.

Not sure where your business stands? The free AI Readiness Check is the right starting point. No email required, no strings attached.

Take the free AI Readiness Check →

This piece was first published as a LinkedIn article on 11 May 2026.

Elodie Flenniau is the founder of Aiforya, an AI governance consultancy based in Belfast, Northern Ireland. She works with SMEs and charities across Northern Ireland and the Republic of Ireland. IAPP member.