CSRD and ESRS After the Omnibus
It is a Monday in March 2026, and a controller forwards you a one-line email from the CFO: "Saw the Omnibus passed. Good news, we are out of CSRD, right? Stop the project." You read it twice. Then you pull the headcount file and the audited turnover line, and your stomach drops, because the company has 4,200 employees and EUR 1.1 billion in revenue. You are not out. You are squarely, unmistakably in scope, and the person who signs the statement just told the board the opposite.
The Omnibus Narrowed CSRD, It Did Not Kill It
Through late 2025 and early 2026, one word did more damage to disclosure planning than any regulation: Omnibus. The European Commission's simplification package was reported in the trade press, in board decks, and in nervous hallway conversations as if it had repealed the Corporate Sustainability Reporting Directive outright. It did not. The package became Directive (EU) 2026/470, published on 26 February 2026 and in force from 18 March 2026. It narrowed the population of companies that must report. It did not abolish the obligation, the European Sustainability Reporting Standards behind it, or the external assurance that sits on top of it.
This distinction is not pedantic. If you are an AI-aware sustainability professional, the single most expensive mistake you can make in 2026 is to repeat a headline instead of checking a threshold. The Omnibus changed who reports. For the companies still in scope, it arguably raised the stakes, because the population that remains is the largest undertakings, the ones where a botched or restated disclosure is not a compliance footnote but a board-level event that lands in the financial press.
The Omnibus did not get you off the hook. It made the hook bigger for the companies still hanging on it.
So the first job of this lesson is to kill a rumor and replace it with two numbers and two dates you can defend. The rumor is "CSRD is dead." The truth is that CSRD survived a real simplification, the scope test is now sharper, and the clock that matters runs to a specific 2027 date. Everything else in your reporting year hangs off getting that right.
It helps to understand why the rumor spread so fast. Through 2025 the political debate around the Omnibus was loud and the outcome was genuinely uncertain. Trade headlines compressed a complicated legislative process into single sentences, and "EU rolls back sustainability rules" reads very differently from "EU narrows the population of CSRD reporters while preserving the obligation for the largest undertakings." The first version travels. The second version is the one you have to act on. An AI summarizer fed those headlines will faithfully reproduce the compression, which is exactly why you cannot let a model's one-line gloss stand in for reading the directive. The summary inherits the headline's bias, and the headline was built for clicks, not for a scope decision.
There is also a reason the per-filer stakes rose. When a wide band of medium-sized companies was in scope, a single weak disclosure was one of thousands and rarely newsworthy. When the population narrows to the largest undertakings, each filer is more visible, more scrutinized, and more likely to have investors, lenders, and journalists reading the report closely. A restatement at that tier is not a quiet correction. It is a story. The narrowing concentrated both the obligation and the attention, and the team that treats the disclosure casually because "fewer companies have to do it" has misread the direction of the risk entirely.
Who Is Still In Scope: The Two-Part Test
Under Directive (EU) 2026/470, the core scope test for a large undertaking is now a logical AND, not an OR. A company is in scope when it has more than 1,000 employees AND more than EUR 450 million in turnover. Both conditions must be true. A company with 1,500 employees but EUR 200 million in turnover does not meet the test on these two criteria. A company with 800 employees and EUR 900 million in turnover does not meet it either. The "more than 1,000 employees" condition and the "more than EUR 450 million turnover" condition have to be satisfied together.
This is a deliberate raising of the bar. The earlier CSRD scope swept in a much wider band of medium-sized companies. The Omnibus pushed the threshold up so that the directive captures the largest undertakings, the ones with the resources to produce an audit-grade disclosure and the systemic footprint to justify the regulatory attention. The phrase you will hear from policymakers is "focus the obligation where it matters most." For you, the operational translation is simpler: check both numbers, in writing, before you tell anyone they are in or out.
Listed SMEs Were Exempted
One of the clearest changes is that listed small and medium-sized enterprises were exempted from the mandatory CSRD regime. Under the prior trajectory, listed SMEs were heading toward a proportionate version of the obligation. The Omnibus removed them from the mandatory population. This matters because many sustainability teams spent 2024 and 2025 building toward a listed-SME timeline that no longer binds them. If that is your company, the disclosure does not vanish from your life entirely, because customers, lenders, and investors may still ask for the data on a voluntary basis, but the legal mandate under CSRD is no longer the thing driving your deadline.
Why The "AND" Matters For An AI Project
Here is where this becomes an AI lesson and not just a legal briefing. Imagine you ask a general-purpose model, "Is my company in scope for CSRD?" and you paste in a paragraph about your business. The model may produce a fluent, confident answer. It may even cite the Omnibus. But it does not know your exact headcount on the relevant date, it does not know your audited turnover, and it may be trained on pre-Omnibus scope rules that used different thresholds. A model that answers "yes, you are in scope" or "no, you are exempt" without those two specific, dated, audited figures is not giving you a disclosure decision. It is giving you a plausible sentence. The scope determination is a documented judgment that an assurer and a board will rely on, and it has to trace to your own books, not to a model's training data.
There is a subtler trap hiding in the headcount number itself. "More than 1,000 employees" sounds simple until you ask which employees, measured how, over what period, and across which entities of a group. A model will happily accept whatever number you hand it and reason from there, but the number you hand it is the whole game. A point-in-time headcount taken on a quiet day after a seasonal drop can read differently from an average over the financial year. A figure that excludes a recently acquired subsidiary can flip a borderline company from in to out. None of that nuance is visible to a chatbot reasoning from a single pasted figure. It is visible only to the professional who knows to ask the HR and finance teams for the right measure and to write down which measure was used and why. The discipline is not distrust of AI for its own sake. It is recognizing that the inputs to the scope test are themselves judgments, and a model cannot make those judgments for you.
ESRS, Datapoints, and Double Materiality
Once you are in scope, you do not report whatever you like. You report against the European Sustainability Reporting Standards, the ESRS. The ESRS are the rulebook that turns the CSRD obligation into specific, structured disclosures: what topics you must consider, what you must say about each, and in many cases the exact datapoint you must provide. A datapoint is the atomic unit of an ESRS disclosure, a single required piece of information, sometimes a number with a defined unit, sometimes a specified narrative, sometimes a yes or no. The ESRS define hundreds of them. The reason datapoints matter for an AI-assisted workflow is that each one is individually traceable: an assurer can point at a single datapoint and ask "where did this come from, and show me the basis," and "the AI drafted it" is never an acceptable answer.
Double Materiality: Two Lenses, One Assessment
The ESRS are built on double materiality, the concept that decides what you actually have to report. Double materiality means you assess each sustainability topic through two lenses. The first is impact materiality: how your company affects people and the environment, the outward-facing view. The second is financial materiality: how sustainability matters affect your company's financial position and performance, the inward-facing view. A topic is material, and therefore reportable, if it is material under either lens. Climate change might be financially material because carbon pricing threatens your margins, and impact-material because your operations emit. A topic can be material on impact alone even if the financial consequence is distant.
The "why you care" is this: double materiality is the gate that determines the entire shape of your report. Get the materiality assessment wrong and you either over-report (wasted effort, more surface for an assurer to test) or under-report (an omission that becomes a finding). And because the assessment rests on judgment about hundreds of inputs, it is exactly the kind of place teams are tempted to let AI cluster, theme, and decide. AI can help organize the inputs. It cannot own the conclusion, and the basis for every material or not-material call has to be documented in a way an assurer can reconstruct.
A concrete way to feel the weight of double materiality is to notice what it does to the burden of proof. Under a single, financial-only lens, you could exclude a topic by arguing it has no near-term effect on the company's numbers. Under double materiality, that argument is not enough on its own, because a topic can still be reportable for its impact on people and the environment even when the financial consequence is remote. So the assessment forces you to consider topics you might prefer to set aside, and to write down a defensible reason whenever you conclude a topic is not material. That written reason is the artifact an assurer tests. When a model proposes that a topic is not material, the right response is not to accept or reject the label but to ask: on what basis, under which lens, and where is the evidence. The model's suggestion is the opening of the conversation, never the end of it.
The EFRAG Simplified ESRS Is Still In Flight
The standards themselves are being simplified in parallel with the scope change. EFRAG, the body that develops the ESRS for the Commission, released a simplified ESRS draft on 3 December 2025. As of mid-2026 that draft is still in flight: not yet final, not yet adopted into law. This is an unstable surface. If you are planning an AI-assisted disclosure workflow now, you build it against the standards as they stand while watching the EFRAG process, because a datapoint that exists today may be cut, merged, or reworded before the simplified set is final. Anchoring your tooling to a specific datapoint list without a way to update it is a trap.
The Transposition Clock Runs to 19 March 2027
A directive is not directly binding on your company the way a regulation is. It instructs member states to write the obligation into their own national law, a process called transposition. Directive (EU) 2026/470 sets the deadline for member states to transpose at 19 March 2027. Until your specific member state transposes, the precise national rules you will be measured against are not all locked. After transposition, the rules can vary in detail from one member state to another, because each national legislature implements the directive into its own framework.
For a multinational, this is the part that bites. You may have entities in several member states, each transposing on its own path toward the 19 March 2027 deadline, each potentially with local nuances. The practical consequence: do not assume a single, pan-EU rule set that you can hard-code into an AI workflow once and forget. Track transposition per member state where you have a reporting entity, and treat 19 March 2027 as the date by which the national picture should be clear, not the date everything was always settled.
A directive tells the member states what to do. Your obligation becomes concrete only when your member state transposes it, and the clock for that runs to 19 March 2027.
A Worked Example: From an AI Answer to a Defensible Scope Memo
Watch the bad version first. A junior analyst, racing to answer the CFO's email, types into a chatbot: "We had a restructuring, headcount is around a thousand, revenue is roughly half a billion euros, did the Omnibus take us out of CSRD?" The model replies, fluently: "Based on the 2026 Omnibus reforms, companies below the large-undertaking thresholds are exempt. Given your figures, you are likely out of scope." The analyst pastes that into a reply to the CFO. The CFO tells the board. The project stops.
Now watch the informed professional turn that into something defensible. She does not ask the model for the verdict. She asks it to do the safe part of the work and refuses to let it do the dangerous part. First she pins the rule: the test is more than 1,000 employees AND more than EUR 450 million turnover, under Directive (EU) 2026/470. Then she pulls the actual figures from the source of truth, not the analyst's memory: the HR system shows an average of 1,180 employees over the financial year, and the audited financial statements show EUR 612 million in turnover. Both exceed the thresholds. The "around a thousand" and "roughly half a billion" in the analyst's prompt were both wrong, and both happened to sit right on the line.
She writes a one-page scope memo. It states the legal test and cites the directive. It states each figure, its source document, and the date. It records the conclusion: in scope as a large undertaking. It notes the transposition deadline of 19 March 2027 and flags that the relevant member state's national rules should be monitored. It names her as the preparer and routes it for sign-off. That memo is something an assurer can read and a board can rely on. The chatbot's "likely out of scope" was a sentence. The memo is a decision with a trail. The difference between them is the entire discipline this program teaches.
Notice what the AI was actually good for in the better version: restating the legal test in plain language, structuring the memo, and reminding her of the transposition date. It was not allowed anywhere near the conclusion, because the conclusion depends on two audited numbers that live in your systems, not in a model.
There is one more move the disciplined professional makes that is easy to miss. She does not file the memo and forget it. Scope is not a permanent status. A divestment can drop a company below a threshold next year; an acquisition or organic growth can push a borderline company over it. So the memo records this year's conclusion against this year's audited figures and commits to re-testing next year, rather than treating "in scope" as a fact carved in stone. This matters doubly during a period when the EFRAG simplified ESRS is still in flight and member-state transposition is still unfolding toward 19 March 2027. The regulatory surface is moving, your own figures are moving, and the only safe posture is to re-run the check each cycle and keep each year's memo on file. That habit, a fresh sourced determination every year, is what turns a one-time legal question into a repeatable control an assurer can rely on.
Step back and the pattern is the same one you will see in every lesson of this chapter. A regulatory fact arrives wrapped in a headline. The headline is wrong, or at least dangerously incomplete. The professional replaces it with the specific rule, the specific dated figures from the company's own records, and a written, signed conclusion that someone else could reconstruct. AI speeds the writing and the structuring; it never supplies the judgment or the evidence. Get that division of labor right for CSRD scope and you have learned the move that the rest of the regulatory landscape, ISSB, CBAM, and the assurance regime, will ask of you again and again.
Key Takeaways
- The Omnibus did not kill CSRD. Directive (EU) 2026/470, published 26 February 2026 and in force 18 March 2026, narrowed the population of reporters but kept the obligation, the ESRS, and external assurance intact.
- The core large-undertaking scope test is now a logical AND: more than 1,000 employees AND more than EUR 450 million in turnover. Both conditions must be true. Check both audited figures in writing before telling anyone they are in or out.
- Listed SMEs were exempted from the mandatory CSRD regime, so any plan built on a listed-SME timeline needs to be revisited.
- Member states must transpose the directive into national law by 19 March 2027. National rules can vary, so multinationals should track transposition per reporting entity rather than assuming one pan-EU rule set.
- ESRS are the rulebook; a datapoint is the atomic, individually traceable unit of disclosure; double materiality (impact plus financial) is the gate that decides what you must report.
- EFRAG's simplified ESRS draft, released 3 December 2025, is still in flight, so any AI workflow anchored to a fixed datapoint list needs a way to update as the standards change.
- A scope determination is a documented judgment that traces to your own audited books. A model that answers "in scope" or "exempt" without your specific dated figures is producing a plausible sentence, not a disclosure decision.
- AI is useful for restating the legal test, structuring the memo, and tracking dates. It must stay away from the conclusion, which rests on numbers an assurer will pull straight from your systems.
Skill.re