{"id":118420,"date":"2025-11-17T01:45:09","date_gmt":"2025-11-17T00:45:09","guid":{"rendered":"https:\/\/ceadigilaw.org\/digital-omnibus-parte-ii\/"},"modified":"2026-07-17T17:01:15","modified_gmt":"2026-07-17T15:01:15","slug":"digital-omnibus-parte-ii","status":"publish","type":"post","link":"https:\/\/ceadigilaw.org\/en\/blog\/digital-omnibus-parte-ii\/","title":{"rendered":"DIGITAL OMNIBUS (Part II)."},"content":{"rendered":"<p id=\"ember50\" class=\"ember-view reader-text-block__paragraph\">By <a class=\"seVZkUMdlXHExvaoRUqmIRWAjXpYSHRBY \" href=\"https:\/\/www.linkedin.com\/in\/antoniotejedaencinas\/\" target=\"_self\" data-test-app-aware-link=\"\"><strong>Antonio Tejeda Encinas<\/strong><\/a> | CEO <a class=\"seVZkUMdlXHExvaoRUqmIRWAjXpYSHRBY \" href=\"https:\/\/www.linkedin.com\/company\/metachannelcorporation\/\" target=\"_self\" data-test-app-aware-link=\"\"><strong>Meta Channel Corporation<\/strong><\/a> | President <a class=\"seVZkUMdlXHExvaoRUqmIRWAjXpYSHRBY \" href=\"https:\/\/www.linkedin.com\/company\/ceadigilaw\/\" target=\"_self\" data-test-app-aware-link=\"\"><strong>Comite Euro Americano de Derecho Digital -CEA Digital Law<\/strong><\/a><\/p>\n<h3 id=\"ember51\" class=\"ember-view reader-text-block__heading-3\">THE EUROPEAN AI ACT, THE DIGITAL OMNIBUS AND THE REALITY EUROPE CAN NO LONGER IGNORE (PART II)<\/h3>\n<p id=\"ember52\" class=\"ember-view reader-text-block__paragraph\">If yesterday, in my article &#8220;<a class=\"seVZkUMdlXHExvaoRUqmIRWAjXpYSHRBY \" href=\"https:\/\/www.linkedin.com\/pulse\/ai-act-europeo-el-digital-omnibus-y-la-realidad-que-tejeda-encinas-vcvzf\" target=\"_self\" data-test-app-aware-link=\"\"><strong>The European AI Act, the Digital Omnibus and the reality Europe can no longer ignore<\/strong><\/a>&#8220;, I explained how the Omnibus has once again overtaken a market that is not yet ready, today I want to dwell on the immediate consequence of all that.<\/p>\n<h3 id=\"ember53\" class=\"ember-view reader-text-block__heading-3\">The Digital Services Omnibus does not come alone<\/h3>\n<p id=\"ember54\" class=\"ember-view reader-text-block__paragraph\">It is the gateway to a second regulatory wave that will unfold between 2025 and 2026 and that will once again strain the same structural fracture: Europe legislates as if all companies were multinationals, but expects the same level of compliance from those that are not.<\/p>\n<p id=\"ember55\" class=\"ember-view reader-text-block__paragraph\">Between 2025 and 2026, what is coming is not new regulation: it is regulatory convergence. For the first time, the AI Act, DORA, MiCA, ESG and AML will demand simultaneous, intertwined compliance. They are not isolated pieces you can solve sequentially: they are a mesh that only works if you manage it as a system.<\/p>\n<p id=\"ember56\" class=\"ember-view reader-text-block__paragraph\">In yesterday&#8217;s analysis of the Omnibus, the pattern was already visible: rules that get ahead of the market&#8217;s real operational capacity, requirements designed for giant structures, and fine print that makes no distinction between those with a global compliance department and those simply trying not to sink while they grow.<\/p>\n<p id=\"ember57\" class=\"ember-view reader-text-block__paragraph\">The problem is that the Omnibus is not an exception. It arrives in parallel with the full application of DORA, the implementation of the AI Act, the rollout of MiCA, the new sustainability and ESG reporting standards, and the strengthening of the anti-money laundering (AML) framework. Together, they form a mesh that can only be managed well by those who were already living in multinational mode before all this.<\/p>\n<h3 id=\"ember58\" class=\"ember-view reader-text-block__heading-3\">Three market levels, a single regulation<\/h3>\n<p id=\"ember59\" class=\"ember-view reader-text-block__paragraph\">To understand who can withstand that mesh and who cannot, it is not enough to talk about &#8220;SMEs&#8221; or &#8220;innovative companies&#8221;. It is a convenient but useless label. What matters is not formal size, but real structure. And there, whether we like it or not, the market operates on three levels.<\/p>\n<p id=\"ember60\" class=\"ember-view reader-text-block__paragraph\"><strong>First level: startups and early-stage companies.<\/strong> Speed, iteration, product. And almost no internal regulatory armor. When the Omnibus or the AI Act demand traceability, data governance or sophisticated internal controls, the requirement goes far beyond what a minimal structure can absorb without compromising its own survival.<\/p>\n<p id=\"ember61\" class=\"ember-view reader-text-block__paragraph\"><strong>Second level: exposed mid-caps.<\/strong> They are not small; they have clients, processes, sometimes an international presence. But they do not have a &#8220;multinational apparatus&#8221; behind them. They are the hardest hit by this model: too big to keep improvising, too small to replicate in-house a global risk, legal and technology team just to comply with the new regulatory ecosystem.<\/p>\n<p id=\"ember62\" class=\"ember-view reader-text-block__paragraph\"><strong>Third level: the multinationals.<\/strong> A good part of this regulation is written, de facto, for them. Distributed legal teams, constant monitoring of changes, the capacity to redesign operations in several jurisdictions at once. They are the only ones playing on a field designed to their measure.<\/p>\n<p id=\"ember63\" class=\"ember-view reader-text-block__paragraph\">The Omnibus and the 2025\u20132026 wave do nothing but widen this gap: the rule is homogeneous, the capacity to comply is not.<\/p>\n<h3 id=\"ember64\" class=\"ember-view reader-text-block__heading-3\">When five regulatory frameworks converge on a single operation<\/h3>\n<p id=\"ember65\" class=\"ember-view reader-text-block__paragraph\">Let us take a real case that is already happening: a European fintech offering automated investment services with crypto-assets.<\/p>\n<p id=\"ember66\" class=\"ember-view reader-text-block__paragraph\">It collects its users&#8217; personal data to profile them (GDPR). It uses artificial intelligence algorithms for risk scoring and investment recommendations (AI Act, high-risk system). It handles stablecoins and utility tokens (MiCA). It processes digital payments and manages an online platform with more than 10,000 active users per month (DSA). It has critical technological infrastructure for providing financial services (DORA). And it is obliged to report suspicious transactions and verify the origin of funds (AML\/CFT).<\/p>\n<p id=\"ember67\" class=\"ember-view reader-text-block__paragraph\">That company cannot address each rule separately.<\/p>\n<p id=\"ember68\" class=\"ember-view reader-text-block__paragraph\">It cannot have a &#8220;GDPR project&#8221; that ends in March, an &#8220;AI Act project&#8221; that starts in April and a &#8220;MiCA project&#8221; that kicks off in June. Because the five regulations affect the same data, the same processes, the same automated decisions and the same technological infrastructure.<\/p>\n<p id=\"ember69\" class=\"ember-view reader-text-block__paragraph\">If you design your data governance thinking only about the GDPR, you will have to redo it when you face the traceability requirements of the AI Act. If you implement cybersecurity controls thinking only about DORA, you will discover that MiCA&#8217;s risk management model demands something different. If you build your identity verification system thinking only about AML, you will find that the DSA has specific requirements on transparency in automated systems that you had not contemplated.<\/p>\n<p id=\"ember70\" class=\"ember-view reader-text-block__paragraph\"><strong>That is regulatory convergence: when complying well with one rule means having understood how it intersects with the other four.<\/strong><\/p>\n<p id=\"ember71\" class=\"ember-view reader-text-block__paragraph\">And this is not a theoretical problem. It is the daily reality of any financial, technology or digital services company operating in Europe from now on. We are not talking about exotic sectors: we are talking about fintechs, insurtech, SaaS platforms, marketplaces, cybersecurity companies, cloud providers, any business that uses AI to make automated decisions or that handles sensitive data at scale.<\/p>\n<p id=\"ember72\" class=\"ember-view reader-text-block__paragraph\">And the problem is not that it is difficult. It is that <strong>it requires a compliance architecture conceived as a system, not as a sum of parts<\/strong>.<\/p>\n<p id=\"ember73\" class=\"ember-view reader-text-block__paragraph\">That is exactly what the mid-market does not have. And what the big consulting firms do not know how to build for those who are not already multinationals.<\/p>\n<h3 id=\"ember74\" class=\"ember-view reader-text-block__heading-3\">The gap no one is covering<\/h3>\n<p id=\"ember75\" class=\"ember-view reader-text-block__paragraph\">Between these three levels, an operational space opens up that almost no one is covering. Not because talent is lacking, but because the current structure of the market prevents it from being covered through the classic models.<\/p>\n<p id=\"ember76\" class=\"ember-view reader-text-block__paragraph\">The big consulting firms work with a silo logic because they are designed to replicate multinational structures, not to create them from scratch. When your client already has a Chief Compliance Officer, a DPO, a CISO and a coordinated legal department, that model fits. When they do not, you are not buying solutions: you are buying reports on why you need to hire more people.<\/p>\n<p id=\"ember77\" class=\"ember-view reader-text-block__paragraph\">It works when the client is already a corporation designed by compartments. But when the client is a startup or a mid-cap, that model no longer fits. Not only because of the cost: structurally, it is not useful to transplant a multinational architecture onto someone not built to sustain it.<\/p>\n<p id=\"ember78\" class=\"ember-view reader-text-block__paragraph\">And at the same time, the business fabric cannot afford to improvise or operate blindly. The regulatory wave arriving between 2025 and 2026 demands real capacity, not intention. It demands translating rules designed for the &#8220;global tier&#8221; into processes that are workable for companies that have to keep selling tomorrow.<\/p>\n<h3 id=\"ember79\" class=\"ember-view reader-text-block__heading-3\">Where META Channel Corporation operates<\/h3>\n<p id=\"ember80\" class=\"ember-view reader-text-block__paragraph\">That is where we operate. Not as a substitute for the big consulting firms, nor as a &#8220;low cost&#8221; solution. We operate with multinational logic without compartments, but without the inertias that make that model inaccessible to most of the market.<\/p>\n<p id=\"ember81\" class=\"ember-view reader-text-block__paragraph\">That allows us to work at both ends: both with companies moving operations above one million euros \u2014 where there is no longer any margin for regulatory errors \u2014 and with companies that are growing and need solid architecture before regulation catches up with them.<\/p>\n<p id=\"ember82\" class=\"ember-view reader-text-block__paragraph\">It is not a question of size. It is a question of structure, speed and real execution capacity.<\/p>\n<p id=\"ember83\" class=\"ember-view reader-text-block__paragraph\">And this new regulatory framework is making it clear: that combination is available almost nowhere. We work exactly there: on turning multinational-level requirements into real operability for companies that cannot stop to build a multinational.<\/p>\n<h3 id=\"ember84\" class=\"ember-view reader-text-block__heading-3\">The decision has already been made<\/h3>\n<p id=\"ember85\" class=\"ember-view reader-text-block__paragraph\">Europe has already made its decision: to legislate as if we all operated at multinational scale. What the market has not yet accepted is that this means only those able to execute at that level will survive, regardless of their formal size.<\/p>\n<p id=\"ember86\" class=\"ember-view reader-text-block__paragraph\">META Channel Corporation does not solve the problem of European overregulation.<\/p>\n<p id=\"ember87\" class=\"ember-view reader-text-block__paragraph\">It solves the problem of how to operate within it without breaking the company, and without having to become a multinational in order to comply with it.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Antonio Tejeda Encinas | CEO Meta Channel Corporation | President Comite Euro Americano de Derecho Digital -CEA Digital Law THE EUROPEAN AI ACT, THE DIGITAL OMNIBUS AND THE REALITY EUROPE CAN NO LONGER IGNORE (PART II) If yesterday, in my article &#8220;The European AI Act, the Digital Omnibus and the reality Europe can no [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":116383,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"wds_primary_category":0,"wds_primary_cea_women":0,"footnotes":""},"categories":[1102],"tags":[],"cea_women":[],"class_list":["post-118420","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-artificial-intelligence"],"acf":[],"_links":{"self":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts\/118420","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/comments?post=118420"}],"version-history":[{"count":1,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts\/118420\/revisions"}],"predecessor-version":[{"id":119249,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts\/118420\/revisions\/119249"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/media\/116383"}],"wp:attachment":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/media?parent=118420"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/categories?post=118420"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/tags?post=118420"},{"taxonomy":"cea_women","embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/cea_women?post=118420"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}