I would like to thank the Deputy for her question. The Government strongly supports the EU’s competitiveness agenda. Simplification is a key enabler of this. Both the Letta and Draghi reports underlined the need to reduce the regulatory and administrative burden on EU companies, particularly SMEs.
The European Commission put forward ten separate simplification Omnibus packages in 2025. Each package usually contains several legislative proposals relevant to multiple Government Departments. My Department has been coordinating Ireland’s approach across Government to these packages.
The digital simplification Omnibus package was published by the European Commission on 19 November last year. In the lead up its publication, Ireland strongly encouraged an ambitious digital simplification package that can support the EU’s strategic positioning as the location of choice for trustworthy digital innovation, while maintaining a central focus on protecting data privacy and fundamental rights of citizens.
The proposals are a first step, and an important element of the overall approach to improving competitiveness at an EU level, in line with the Draghi Report and related work. By reducing barriers to investment and innovation, balanced with clear and predictable protections for citizens, we can unlock growth opportunities from the rapid acceleration of technological developments.
Ireland recognises the importance of regulation to ensure markets operate efficiently and fairly, and to protect consumers. In this context, it is important that regulations are targeted and proportionate to the policy objective, whether it is to protect consumers and citizens, or to promote competition and innovation. Ireland has therefore advocated for a dynamic, ambitious and risk-based approach, focused on removing regulatory overlaps, reducing administrative burdens, and supporting compliance.
It will also be important to future-proof our EU digital regulatory framework, with the overall aim of increasing the coherence and effectiveness of the EU Digital rulebook. This means ensuring that forthcoming digital regulations are developed with the same objectives around simplification, harmonisation and coherence strongly to the fore. In this context, Ireland is also very supportive of the broader review of the digital rulebook that will be provided by the Fitness Check of the Digital Acquis.
The package contains two separate legislative proposals, which aim to simply and streamline the EU’s AI Act, the EU’s data rulebook and cybersecurity incident reporting. As regards the proposed changes to the AI Act specifically, they respond to practical implementation challenges highlighted by stakeholders and are aimed at increasing certainty for regulators, businesses and citizens, reducing compliance costs and administrative burdens, and supporting innovation whilst maintaining protections. By reducing barriers to investment and innovation, balanced with clear and predictable protections for citizens, we can unlock growth opportunities from the rapid acceleration of technological developments.
The Department of Enterprise, Tourism and Employment has lead responsibility for national implementation of the EU AI Act and is working closely with other departments and regulators to ensure comprehensive and robust implementation of the Act.
It is important to note that the digital simplification Omnibus package must now proceed through the EU’s ordinary legislative procedure, requiring review and approval by both the European Parliament and the Council. Ireland is actively contributing to these discussions and is consulting with relevant stakeholders.
Supplementary Q&As
Is simplification not just deregulation?
Let me be very clear.
The position of the Irish Government is that simplification has to be about better regulation, not deregulation.
We need to reduce the regulatory burden, in particular for SMEs, while maintaining high ambition in terms of environmental protection and other standards.
It is important for our legislative approach to be in line with core better regulation principles and the inter-institutional agreement on better law-making, while prioritising smarter, simpler and more streamlined regulations.
Can you provide more detail on the concrete changes proposed to the AI Act?
The package includes proposed measures to streamline the operation of the EU AI Act, including: linking the implementation timeline of high-risk rules to the availability of standards; extending SME regulatory simplifications to small mid-caps; requiring the Commission and the Member States to foster AI literacy instead of enforcing unspecified obligation on providers and deployers of AI systems in this respect, while training obligations for high-risk deployers remain; increasing flexibility in post-market monitoring by removing the mandatory harmonised plan; reducing the registration requirements for AI systems in high-risk areas when used only for narrow or procedural tasks; centralising the oversight of many General Purpose AI-based and platform-embedded systems within the EU AI Office; expanding the regulatory sandboxes and real-world testing, including an EU-level sandbox, and clarifying the interactions between the AI Act and other EU laws.
A key challenge faced by Member States and businesses included the delay in the availability of technical standards and other support tools, such as guidance and codes of practice, that are necessary for the provision, use and regulation of compliant AI systems.
Ireland has welcomed the EU’s focus on simplification, having consistently advocated for targeted and proportionate regulation, ensuring the right balance between stimulating innovation, boosting competitiveness, and enforcing regulation when necessary.
How is implementation of the AI Act progressing domestically?
The EU Artificial Intelligence (AI) Act entered into force on 2 August 2024 and is designed to provide a high level of protection for people’s health and safety, and their fundamental rights, to promote responsible uses of trustworthy and ethical AI. The provisions of the EU AI Act apply in a phased manner over the period to August 2027.
The Department of Enterprise, Tourism and Employment has lead responsibility for national implementation of the EU AI Act and is working closely with other departments and regulators to ensure comprehensive and robust implementation of the Act. Government designated its national competent authorities during 2025, and the enforcement powers for competent authorities under the AI Act come into effect on the 2nd of August 2026.
The Department of Enterprise, Tourism and Employment, in collaboration with other relevant government departments, is currently developing primary legislation to provide for the national implementation and enforcement of the EU AI Act, and the establishment of a central coordinating Office.
How will the digital simplification Omnibus proposals impact the implementation of the AI Act domestically?
Some critical provisions of the AI Act have already come into force and are currently applicable, including prohibited AI practices, rules governing general purpose AI models, and requirements for the designation of national competent authorities. Additionally, key provisions remain scheduled to come into effect in August 2026 as originally planned, including the requirement to establish a national AI regulatory sandbox, and rules on penalties and enforcement measures.
Ireland must be positioned to implement these provisions on time to ensure effective regulatory oversight regardless of any proposed simplification measures.
The simplification proposals do not alter the Department of Enterprise, Tourism and Employment’s national implementation plan for the AI Act in Ireland. It remains the firm intention to have the primary legislation enacted before the 2 August 2026 deadline.
What is proposed in terms of simplification of the EU data rulebook?
The proposal merges four existing data-related acts into a single, consolidated instrument for Europe’s data economy. It incorporates elements of the Free Flow of Data Regulation, the Data Governance Act, and the Open Data Directive, into the Data Act, while simultaneously repealing those three instruments. This initiative aligns with the broader Data Union Strategy, which seeks to simplify and streamline the EU’s legislative framework. Among its aims, the proposal extends rules that facilitate compliance with EU data legislation for small and medium sized enterprises to also cover small mid-cap companies. It seeks to balance reduced administrative burdens with enhanced legal certainty and strengthened competitiveness, while also reinforcing safeguards against the risk of severe data leaks to third countries. In addition, it clarifies the scope of the business to government framework and reaffirms that the key provisions of the Data Act remain central to fostering a more open and competitive cloud environment.
The proposal also includes targeted amendments to the General Data Protection Regulation (GDPR) to harmonise, clarify and simplify certain rules to boost innovation and support compliance by organisations, while keeping intact the core of the GDPR, maintaining the highest level of personal data protection. It aims to clarify certain key definitions, for instance the notions of personal data; facilitate compliance, for instance by supporting controllers with respect to the criteria and means to determine whether data resulting from pseudonymisation does not constitute personal data; clarify certain aspects as to the processing of data for AI training and development; and address the lack of clarity about the conditions for scientific research by providing a definition of scientific research and clarifying that scientific research constitutes a “legitimate interest”.
The proposal also includes changes to the rules on “cookies” (e-privacy Directive). It seeks to simplify the interplay of the applicable rules whereby processing of personal data on and from terminal equipment should be governed only by GDPR. The proposal also paves the way for automated and machine-readable indications of individual choices and respect of those indications by website and mobile application providers and providers of mobile phone applications once standards are available. Where controllers ensure that their websites or mobile phone applications comply with such standards, they should benefit from a presumption of compliance.
What is Ireland’s position on the proposed changes to the EU data rulebook?
Ireland welcomes the proposed amalgamation of the Open Data Directive, the Free Flow of Non-Personal Data Regulation, the Data Governance and the Data Act into a single consolidated Data Act as it will streamline the data framework and provide greater clarity and alignment of the data rulebook. Ireland further believes that strong safeguards regarding the use of personal data should remain in place in alignment with core objectives of the GDPR. Essential principles of public trust, transparency, data protection and improved public outcomes and public good are central to any simplification package.
Discussions in the Council on these proposals are at an early stage, and we will continue to engage constructively in these discussions.
What is proposed in terms of simplification of Cyber Security Incident Reporting?
The proposal seeks to introduce a single-entry point through which entities can simultaneously fulfil their incident reporting obligations under multiple legal acts and to require ENISA, the EU agency for cybersecurity, to develop the single entry-point. It seeks to mandate the use of the single-entry point for a series of closely interconnected incident reporting obligations set in the NIS2 Directive, GDPR, DORA, eIDAS Regulation, and the CER Directive. Other sectoral reporting obligations, such as those set out in the framework of the network code on cybersecurity aspects of cross-border electricity flows (NCCS) and the relevant instruments for the aviation sector, would also be brought under the single-entry point through amendments to the respective delegated and implementing acts that establish the reporting obligations under those frameworks. The proposal also aims at streamlining the contents of reported information by introducing empowerments for several legal acts, where such do not exist - and the Commission is supposed to take due account of the experience gained and the common templates developed under DORA.
What is Ireland’s perspective on the proposed changes to cyber security incident reporting?
On cyber security, Ireland welcomes the efforts to simplify the reporting of incidents as the complexity of incident reporting has been repeatedly highlighted by stakeholders as a major issue, particularly for SMEs. However, we have concerns on the proposal to develop a single-entry point (SEP) for incident reporting across a number of legislative files including non cyber security ones such as GDPR. One key concern is the interoperability of a SEP with existing incident reporting mechanisms in Member States and concerns it may encroach upon National Security, causing delays and fragmentation in relation to critical information flows.
Discussions in the Council on these proposals are at an early stage, and we will continue to engage constructively in these discussions.