{"id":38611,"date":"2025-11-17T08:32:37","date_gmt":"2025-11-17T08:32:37","guid":{"rendered":"https:\/\/metachannelcorp.com\/digital-omnibus-part-ii\/"},"modified":"2026-08-03T11:35:47","modified_gmt":"2026-08-03T11:35:47","slug":"digital-omnibus-part-ii","status":"publish","type":"post","link":"https:\/\/metachannelcorp.com\/en\/perspectives\/digital-omnibus-part-ii\/","title":{"rendered":"DIGITAL \u00d3MNIBUS (part II)"},"content":{"rendered":"<p>\u00a0<\/p>\n<p id=\"ember48\" class=\"ember-view reader-text-block__paragraph\">By <a class=\"qnYTlArzYtboRwdjbntMpxxVLYbykXIogw \" tabindex=\"0\" href=\"https:\/\/www.linkedin.com\/in\/antoniotejedaencinas\/\" target=\"_self\" data-test-app-aware-link=\"\"><strong>Antonio Tejeda Encinas<\/strong><\/a> | CEO <a class=\"qnYTlArzYtboRwdjbntMpxxVLYbykXIogw \" tabindex=\"0\" href=\"https:\/\/www.linkedin.com\/company\/metachannelcorporation\/\" target=\"_self\" data-test-app-aware-link=\"\"><strong>META Channel Corporation<\/strong><\/a> | President <a class=\"qnYTlArzYtboRwdjbntMpxxVLYbykXIogw \" tabindex=\"0\" href=\"https:\/\/www.linkedin.com\/company\/ceadigilaw\/\" target=\"_self\" data-test-app-aware-link=\"\"><strong>Comit\u00e9 Euro Americano de Derecho Digital \u2014 CEA Digital Law<\/strong><\/a><\/p>\n<h3 id=\"ember49\" class=\"ember-view reader-text-block__heading-3\">EUROPEAN AI ACT, THE DIGITAL OMNIBUS AND THE REALITY THAT EUROPE CAN NO LONGER IGNORE (PART II)<\/h3>\n<p id=\"ember50\" class=\"ember-view reader-text-block__paragraph\">Yes yesterday, in my article &#8220;<a class=\"qnYTlArzYtboRwdjbntMpxxVLYbykXIogw \" tabindex=\"0\" href=\"https:\/\/www.linkedin.com\/pulse\/ai-act-europeo-el-digital-omnibus-y-la-realidad-que-tejeda-encinas-vcvzf\" target=\"_self\" data-test-app-aware-link=\"\"><strong>European AI Act, the Digital Omnibus and the reality that Europe can no longer ignore<\/strong><\/a>&#8220;, he explained how the Bus has once again overtaken a market that is not yet ready, today I want to focus on the immediate consequence of all that.<\/p>\n<h3 id=\"ember51\" class=\"ember-view reader-text-block__heading-3\">The Digital Services Omnibus does not arrive alone<\/h3>\n<p id=\"ember52\" class=\"ember-view reader-text-block__paragraph\">It is the gateway to a second regulatory wave that will be deployed between 2025 and 2026 and that will stress, once again, the same structural fracture: Europe legislates as if all companies were multinational, but expects the same level of compliance from those who are not.<\/p>\n<p id=\"ember53\" class=\"ember-view reader-text-block__paragraph\">Between 2025 and 2026, no new regulation arrives: regulatory convergence arrives. For the first time, IA Act, DORA, MiCA, ESG and AML will require simultaneous and intersecting compliance. They are not isolated pieces that you can solve sequentially: they are a mesh that only works if you manage it as a system.<\/p>\n<p id=\"ember54\" class=\"ember-view reader-text-block__paragraph\">In yesterday&#8217;s analysis of the Omnibus, the pattern was already seen: regulations that are ahead of the real operational capacity of the market, requirements designed for giant structures and small print that does not distinguish between those who have a global compliance department and those who are simply trying not to sink while growing.<\/p>\n<p id=\"ember55\" class=\"ember-view reader-text-block__paragraph\">The problem is that the Bus is no exception. It arrives in parallel with the full application of DORA, the implementation of the IA Act, the deployment of MiCA, the new sustainability and ESG reporting standards and the reinforcement of the anti-money laundering (AML) framework. Together, they form a mesh that can only be managed well by those who were already living in multinational mode before all this.<\/p>\n<h3 id=\"ember56\" class=\"ember-view reader-text-block__heading-3\">Three market levels, one regulation<\/h3>\n<p id=\"ember57\" class=\"ember-view reader-text-block__paragraph\">To understand who can support this mesh and who cannot, it is not enough to talk about &#8220;SMEs&#8221; or &#8220;innovative companies.&#8221; It&#8217;s a convenient but useless label. What matters is not the formal size, but the actual structure. And there, whether we like it or not, the market works on three levels.<\/p>\n<p id=\"ember58\" class=\"ember-view reader-text-block__paragraph\"><strong>First level: startups and companies in the early phase.<\/strong> Speed, iteration, product. And almost no internal regulatory shield. When the Omnibus or the IA Act require traceability, data governance or sophisticated internal controls, the requirement goes far beyond what a minimal structure can absorb without compromising its own survival.<\/p>\n<p id=\"ember59\" class=\"ember-view reader-text-block__paragraph\"><strong>Second level: exposed mid-caps.<\/strong> They are not small, they have clients, processes, sometimes an international presence. But they do not have a &#8220;multinational apparatus&#8221; behind them. They are the hardest hit by this model: too big to improvise, too small to replicate a global risk, legal and technology team in-house just to comply with the new regulatory ecosystem.<\/p>\n<p id=\"ember60\" class=\"ember-view reader-text-block__paragraph\"><strong>Third level: multinationals.<\/strong> For them, a good part of this regulation is written, de facto. Distributed legal teams, constant monitoring of changes, ability to redesign operations in several jurisdictions at once. They are the only ones who play on a field designed to suit them.<\/p>\n<p id=\"ember61\" class=\"ember-view reader-text-block__paragraph\">The Omnibus and the 2025\u20132026 wave only widen this gap: the standard is homogeneous, the capacity for compliance is not.<\/p>\n<h3 id=\"ember62\" class=\"ember-view reader-text-block__heading-3\">When five regulatory frameworks converge on the same operation<\/h3>\n<p id=\"ember63\" class=\"ember-view reader-text-block__paragraph\">Let&#8217;s take a real case that is already happening: a European fintech that offers automated investment services with cryptoassets.<\/p>\n<p id=\"ember64\" class=\"ember-view reader-text-block__paragraph\">Captures personal data of its users to profile them (RGPD). It uses artificial intelligence algorithms to make risk scoring and investment recommendations (AI Act, high-risk system). Manages stablecoins and utility tokens (MiCA). Processes digital payments and manages an online platform with more than 10,000 active users per month (DSA). It has critical technological infrastructure to provide financial services (DORA). And it is obliged to report suspicious transactions and verify the origin of funds (AML\/CFT).<\/p>\n<p id=\"ember65\" class=\"ember-view reader-text-block__paragraph\">That company cannot resolve each rule separately.<\/p>\n<p id=\"ember66\" class=\"ember-view reader-text-block__paragraph\">You can&#8217;t have a &#8220;RGPD project&#8221; that ends in March, a &#8220;AI Act project&#8221; that starts in April, and a &#8220;MiCA project&#8221; that starts in June. Because the five regulations affect the same data, the same processes, the same automated decisions and the same technological infrastructure.<\/p>\n<p id=\"ember67\" class=\"ember-view reader-text-block__paragraph\">If you design your data governance with only RGPD in mind, you&#8217;re going to have to redo it when faced with AI Act traceability requirements. If you implement cybersecurity controls with only DORA in mind, you will discover that the MiCA risk management model requires something different. If you build your identity verification system with only AML in mind, you will find that the DSA has specific requirements on transparency in automated systems that you had not considered.<\/p>\n<p id=\"ember68\" class=\"ember-view reader-text-block__paragraph\"><strong>That is regulatory convergence: when complying well with one standard implies having understood how it intersects with the other four.<\/strong><\/p>\n<p id=\"ember69\" class=\"ember-view reader-text-block__paragraph\">And this is not a theoretical problem. It is the daily life of any financial, technological or digital services company that operates in Europe from now on. We are not talking about exotic sectors: we are talking about fintechs, insurtech, SaaS platforms, marketplaces, cybersecurity companies, cloud providers, any business that uses AI to make automated decisions or that handles sensitive data at scale.<\/p>\n<p id=\"ember70\" class=\"ember-view reader-text-block__paragraph\">And the problem is not that it is difficult. The thing is <strong>requires a compliance architecture designed as a system, not as a sum of parts<\/strong>.<\/p>\n<p id=\"ember71\" class=\"ember-view reader-text-block__paragraph\">That&#8217;s exactly what the middle market doesn&#8217;t have. And what the large consulting firms do not know how to build for those who are not already a multinational.<\/p>\n<h3 id=\"ember72\" class=\"ember-view reader-text-block__heading-3\">The gap that no one is filling<\/h3>\n<p id=\"ember73\" class=\"ember-view reader-text-block__paragraph\">Between these three levels an operational space opens up that almost no one is covering. Not because there is a lack of talent, but because the current market structure prevents it from being covered from classic models.<\/p>\n<p id=\"ember74\" class=\"ember-view reader-text-block__paragraph\">Large consulting firms work with silo logic because they are designed to replicate multinational structures, not to create them from scratch. When your client already has a Chief Compliance Officer, a DPO, a CISO and a coordinated legal department, that model fits. When it doesn&#8217;t, you&#8217;re not buying solutions: you&#8217;re buying reports on why you need to hire more people.<\/p>\n<p id=\"ember75\" class=\"ember-view reader-text-block__paragraph\">It works when the client is already a corporation designed by compartments. But when the client is a startup or a mid-cap, that model stops fitting. Not only because of the cost: structurally it is not useful to transfer a multinational architecture to someone who is not built to sustain it.<\/p>\n<p id=\"ember76\" class=\"ember-view reader-text-block__paragraph\">And at the same time, the business community cannot afford to improvise or operate blindly. The regulatory wave that arrives between 2025 and 2026 requires real capacity, not intention. It requires translating standards designed for the &#8220;global tier&#8221; into acceptable processes for companies that have to continue selling tomorrow.<\/p>\n<h3 id=\"ember77\" class=\"ember-view reader-text-block__heading-3\">Where META Channel Corporation operates<\/h3>\n<p id=\"ember78\" class=\"ember-view reader-text-block__paragraph\">That&#8217;s where we operate. Not as a substitute for large consulting firms or as a &#8220;low cost&#8221; solution. We operate with a multinational logic without compartments, but without the inertia that makes that model inaccessible to the majority of the market.<\/p>\n<p id=\"ember79\" class=\"ember-view reader-text-block__paragraph\">This allows us to work at both extremes: both in companies that carry out operations above a million euros &#8211; where there is no longer room for regulatory errors &#8211; and in companies that are growing and need solid architecture before regulation reaches them.<\/p>\n<p id=\"ember80\" class=\"ember-view reader-text-block__paragraph\">It&#8217;s not a question of size. It is a question of structure, speed and real ability to execute.<\/p>\n<p id=\"ember81\" class=\"ember-view reader-text-block__paragraph\">And this new regulatory framework is making it clear: that combination is not available almost anywhere. We work exactly there: in converting multinational demands into real operations for companies that cannot stop to build a multinational.<\/p>\n<h3 id=\"ember82\" class=\"ember-view reader-text-block__heading-3\">The decision has already been made<\/h3>\n<p id=\"ember83\" class=\"ember-view reader-text-block__paragraph\">Europe has already made its decision: to legislate as if we all operated on a multinational scale. What the market has not yet come to terms with is that this means that only those who can execute at that level will survive, regardless of their formal size.<\/p>\n<p id=\"ember84\" class=\"ember-view reader-text-block__paragraph\">META Channel Corporation does not solve the problem of European overregulation.<\/p>\n<p id=\"ember85\" class=\"ember-view reader-text-block__paragraph\">It solves the problem of how to operate within it without breaking up the company, or having to become a multinational to be able to fulfill it.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u00a0 By Antonio Tejeda Encinas | CEO META Channel Corporation | President Comit\u00e9 Euro Americano de Derecho Digital \u2014 CEA&#8230;<\/p>\n","protected":false},"author":1,"featured_media":37629,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"wds_primary_category":0,"footnotes":""},"categories":[1843,1838,1840,1845],"tags":[2333,2033,1953,1875,1856,1957,2327,1922,2092,2065,2066,1864,1950,2004,1914,2248,2330,2102,2255,2366,2245,2345,2374,2006,2332,1851,1858,2264,2015,2023,2116,2392,1912],"class_list":["post-38611","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","category-cybersecurity-and-digital-resilience","category-global-expansion-and-strategy","category-regulation-and-compliance","tag-ai-regulation-europe","tag-ai-regulatory-compliance","tag-aml-cft","tag-antonio-tejeda-encinas","tag-cea-digital-law","tag-compliance-architecture","tag-crypto-asset-regulation-europe","tag-data-governance","tag-digital-companies-europe","tag-digital-services-act","tag-digital-services-omnibus","tag-dora","tag-european-ai-act","tag-european-compliance","tag-european-digital-law","tag-european-digital-market","tag-european-digital-regulation","tag-european-esg","tag-european-mid-caps","tag-european-over-regulation","tag-european-regulatory-framework-2025-2026","tag-european-regulatory-risk","tag-european-startups-regulation","tag-fintech-compliance","tag-fintech-regulation-europe","tag-meta-channel-corporation","tag-mica","tag-multinationals-and-regulation","tag-regulatory-consulting","tag-regulatory-convergence-europe","tag-regulatory-strategy","tag-regulatory-transformation","tag-technology-compliance"],"menu_order":0,"_links":{"self":[{"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/posts\/38611","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/comments?post=38611"}],"version-history":[{"count":1,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/posts\/38611\/revisions"}],"predecessor-version":[{"id":38932,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/posts\/38611\/revisions\/38932"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/media\/37629"}],"wp:attachment":[{"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/media?parent=38611"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/categories?post=38611"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/tags?post=38611"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}