The promise of simplification and the reality on the ground
In autumn 2025 the European Commission presented a package to simplify the digital rulebook, often called the Digital Omnibus, with a clear message: the administrative burden on companies must come down. The ambition is to reduce the overall regulatory burden by around a quarter, and by even more for small and mid-sized companies, as part of a broader goal of billions in administrative savings towards the end of the decade. To a hard-pressed entrepreneur that sounds like welcome relief.
The reality is more layered. Even as individual requirements are simplified, the underlying problem remains that several frameworks overlap. The AI Act, the data protection regulation and cybersecurity rules often hit the same system and the same data at once, and the sum of the parts can feel heavier than any single rule on its own. This article explains what simplification actually means for smaller companies, where the burden nonetheless remains and how you avoid getting stuck between the ambition and the practice.
What the simplification actually contains
The simplification effort is less about abolishing obligations and more about easing how they are met. For smaller companies it is the practical reliefs that matter most.
Reliefs aimed at smaller companies
The AI Act already contains specific consideration for smaller players, including simplified technical documentation, access to regulatory sandboxes where new solutions can be tested in dialogue with authorities, and a penalty model where for smaller companies it is generally the lower of the fixed amount and the percentage that applies. The simplification package builds on that logic by trying to reduce the number of overlapping reporting requirements and make compliance more proportionate.
Why smaller is not the same as simple
A lighter burden does not mean it disappears. A growing company may still need to map its AI, classify risk, handle personal data lawfully and meet basic security requirements. Simplification moves the threshold but does not remove the need to understand which rules apply, and the mistake many make is to read headlines about less bureaucracy as a sign the issue can be set aside.
Where the burden remains: the overlap between frameworks
The real complexity arises at the intersection of several frameworks. A single customer-facing tool can simultaneously be an AI system under the AI Act, a processing of personal data under the data protection rules and part of a digital infrastructure covered by cybersecurity requirements. Each framework has its own logic, its own concepts and its own documentation requirements, and it is when they must be met at the same time that the work grows.
Studies of compliance work suggest that the combined burden can rise significantly precisely because of this overlap, even where individual requirements are manageable in themselves. For a small company without its own legal function, it is not a single requirement that becomes overwhelming, but understanding how the requirements connect and where they feed into one another.
A practical example: the startup that trusted the headlines
Imagine a startup with a handful of employees building an analytics service with an element of AI. The founders read that the EU wants to cut the administrative burden sharply for small companies and conclude they can postpone the legal side until they have grown.
When a larger customer begins a procurement, it asks for documentation on how the AI model is governed, how personal data is handled and how the service is secured. The startup then realises that simplification never freed them from having the basics in place, only made certain formal requirements lighter. They lack documentation, a personal-data practice that holds up and a clear picture of their role under the AI Act, and the deal is delayed while they catch up. An early, proportionate review would have given them exactly the foundation the customer asked for, without unnecessary overhead.
Common mistakes companies make
The first mistake is to read political announcements about simplification as an announcement that no obligations apply. Simplification changes how requirements are met, not whether they exist.
The second mistake is to handle the AI Act, data protection and cybersecurity in separate silos. Because they often hit the same systems, the work becomes both more expensive and more confusing if each rule is handled in isolation rather than in context.
The third mistake is to over-engineer. As damaging as ignoring the rules is building heavy bureaucracy that a small company neither needs nor can afford, when the legislator expressly offers proportionate and simplified routes.
Legal risks
The risk picture for smaller companies is twofold. On one side are the formal penalties under each framework, where both data protection and the AI Act carry meaningful maximum levels even if smaller companies usually meet the lower thresholds. On the other, and often more pressing, is the commercial risk: customers and investors who demand documentation and who pass over a supplier that cannot demonstrate order and control.
For a growing company it is rarely a regulator that first puts a finger on the gaps, but a counterparty in a deal or an investor in a due diligence. Having the basics in place is therefore as much a growth question as a compliance question.
Recommended actions
Start by mapping which frameworks actually reach you, and let a single review cover AI, data protection and security rather than three separate projects. That gives a combined picture of where requirements overlap and where you can use the simplified routes.
Use the reliefs available to smaller companies, including simplified documentation and any sandboxes, but still build the minimum level of documentation needed to answer a customer’s or investor’s questions. Keep the solution proportionate to the company’s size and risk, and revisit it as you grow, because both your business and the rules continue to change. Also confirm the exact requirements and deadlines for your particular situation, since the simplification package is still moving through the legislative process.
Frequently asked questions about the simplification of the digital rules
Does simplification mean that as a small company we can ignore the AI Act?
No. Simplification eases certain formal requirements and reporting burdens but does not remove the core obligations. Smaller companies have specific reliefs, but must still understand their role and meet the core requirements.
How much lower will the burden be for small and mid-sized companies?
The EU has stated goals of reducing the administrative burden by around a quarter overall and more for smaller companies. That is, however, a political ambition under implementation, and the actual effect depends on the final rules.
What is a regulatory sandbox and can it help us?
A sandbox is a controlled environment where a company can develop and test AI in dialogue with an authority. For smaller companies it can provide guidance and reduced uncertainty early, before a solution is rolled out broadly.
Why does the regulatory burden still feel heavy despite simplification?
Because several frameworks often hit the same system at once. It is the overlap between AI rules, data protection and security requirements that creates complexity, rather than any single requirement.
When should a growing company tackle these questions?
Earlier than it feels necessary. It is usually a customer or an investor, not an authority, that first asks for documentation, and by then the basics need to already be in place.
Summary
The simplification of the EU’s digital rules is real and welcome, but it is no free pass. For small and mid-sized companies the art lies in using the proportionate and simplified routes on offer, without either ignoring the requirements or building bureaucracy you do not need. Those who understand where the frameworks overlap can meet demands from customers and investors with confidence and turn compliance into a competitive advantage rather than a drag.
Lawgent helps growing companies navigate the overlap between the AI Act, data protection and cybersecurity requirements and build compliance that is right-sized for the company. We combine experienced business-law advice with AI-driven efficiency, so you get clear, practical guidance faster and more cost-effectively than at a traditional firm. Want to know which rules actually reach you and how to meet them proportionately? Contact Lawgent for a review.
