PDF Kami EU-Hosted

Blog

The AI Act since 2 August 2026: what actually applies, and what it means for your documents

Where the EU AI Act really stands in September 2026 (transparency in force, high-risk pushed to 2027), and what it means when an AI reads or writes your documents.

For two years, 2 August 2026 was billed as the day the EU's AI regulation would apply in full. Five days before the deadline, Brussels moved the goalposts. Since then you'll have read both that "the AI Act has been postponed" and that "the AI Act is in force". Both are about three-quarters wrong.

Here's where the text actually stands as of 8 September 2026, with sources. Then what it means for two situations you're probably already in: a PDF tool offering to "summarise" or "translate" your document with AI, and a document you had ChatGPT, Claude or an agent write for you.

The real timeline

AI Act timeline after the July 2026 digital omnibus: prohibitions and AI literacy since February 2025, general-purpose AI models since August 2025, transparency and penalties since August 2026, content marking from 2 December 2026, Annex III high-risk pushed back to 2 December 2027, Annex I to 2 August 2028

What's postponed: high-risk. What isn't: everything else, and above all transparency, which is the part that concerns you.

Situation 1: an "AI" PDF tool reads your document

The big online converters have bolted on AI features: automatic summaries, translation, conversion to Markdown, Q&A over the document. iLovePDF, for one, lists an AI summary generator and a translation tool in its menu (tool page).

Here's what that means technically. Your document isn't just uploaded, processed and deleted any more. Its content is sent to a language model, often run by a third party (OpenAI, Anthropic, Google, or a hosted model), to be read and reworded. That's a different kind of processing from merging pages.

What the AI Act has added since 2 August:

What the AI Act doesn't change, and this is the point that matters: it does not govern the confidentiality of your file. That's still the GDPR's job (you're the controller for the data inside it; the service is merely a processor) and, if the model or the host is American, the CLOUD Act's. A "Summarise with AI" button on a converter is a third third party in the loop, under a third piece of legislation, for a document that may have had no business leaving your computer.

Situation 2: an AI wrote your document

The flip side of the same regulation: more and more documents — minutes, reports, specifications, letters — are written by an assistant or an agent, often delivered as Markdown and then converted to PDF.

Article 50 separates two actors. The provider of the generative system (OpenAI, Anthropic, Google, Mistral and the rest) must technically mark what it produces; systems already on the market have until 2 December 2026. The deployer — that's you, when you use the tool — has to disclose in one specific case only, and with an exception that changes everything in practice.

The exact rule, and its exception

Article 50(4), in its consolidated version of 27 July 2026, targets a deployer who has an AI generate or manipulate text published to inform the public on matters of public interest. In that case, they must disclose that the text was artificially generated or manipulated.

Then comes the exception. The obligation does not apply where the content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication.

In other words, the regulation doesn't ask you to say how the text was written. It asks you to say whether nobody is answering for it. The test isn't the tool. It's responsibility.

Article 50(4) decision tree: AI-generated text published to inform the public on a matter of public interest must carry an "AI-generated" disclosure unless a human who holds editorial responsibility has reviewed, corrected and approved it

What it means in practice

You have an AI churn out blog posts and publish them as they come, with no review, no fact-checking and no name behind them: the "AI-generated content" disclosure is due the moment the subject counts as informing the public — news, health, law, finance, consumer affairs, safety. A company blog that explains the GDPR or compares tools is in this category.

You have an AI write a first draft, then a human reviews it, checks every claim, corrects it and signs it — or the company explicitly takes editorial responsibility: no disclosure needed. The AI was a writing tool, like a spell-checker or a translator; what gets published is content someone answers for.

Internal minutes, a quote, a letter to a client: out of scope. The text isn't meant to inform the public.

A deepfake, a synthetic image or video: separate regime (paragraph 4, first sentence). Disclosure is mandatory except for artistic or satirical uses, with no equivalent editorial exception.

"Human review" isn't defined word for word, but the spirit is clear: read it and take responsibility for what it says. Clicking "publish" isn't editorial control. A review that checks the facts, fixes the errors and puts someone's signature on the line is. Evidence of that process — who reviewed, when, what was changed — is what an authority will ask you for if it comes knocking.

Two practical consequences

The takeaway

The AI Act doesn't say where your file goes; it says what you must be told when an AI touches it. The GDPR says who's responsible. The CLOUD Act says who can demand it. The three texts stack, and all three apply to a document the moment it leaves your machine for a server, a cloud or a model.

A document that never leaves has no AI provider, no processor and no host. To merge, compress, split or convert — or to lay out what an AI has written — PDFKami does the job in your browser, with no model reading your file and without it ever leaving your computer. For the operations that genuinely need an AI, you now know which questions to ask before you click.

FAQ

Has the AI Act been postponed?

Partly. Only the high-risk obligations have been pushed back (Annex III to 2 December 2027, Annex I to 2 August 2028). The prohibitions, AI literacy, the obligations on large models, transparency and penalties all apply.

Is a PDF converter with a "summarise with AI" button covered by the AI Act?

Yes, under the transparency rules: you must be told an AI is involved, and generated content must be identifiable. The confidentiality of the file itself is a GDPR matter and, depending on the host, a CLOUD Act one.

Do I have to say a blog post was written by an AI?

Yes, if it's published to inform the public on a matter of public interest and nobody has reviewed it. No, if a human has reviewed it, corrected it and holds editorial responsibility for the publication (Article 50(4)). For internal use, the question doesn't arise.

What does "holding editorial responsibility" mean?

That an identified person or organisation answers for what's published: they've checked it and they carry the consequences. It's that process, documented, that exempts you from the disclosure.

Is converting AI-generated text to PDF covered by the AI Act?

No. The conversion involves no AI system. It's the generation of the text that's regulated.

Does PDFKami use AI on my files?

No. No model reads, summarises or alters your documents; the processing is deterministic and runs in your browser.

Read next

← All articles