For two years, 2 August 2026 was billed as the day the EU's AI regulation would apply in full. Five days before the deadline, Brussels moved the goalposts. Since then you'll have read both that "the AI Act has been postponed" and that "the AI Act is in force". Both are about three-quarters wrong.
Here's where the text actually stands as of 8 September 2026, with sources. Then what it means for two situations you're probably already in: a PDF tool offering to "summarise" or "translate" your document with AI, and a document you had ChatGPT, Claude or an agent write for you.
The real timeline
- 1 August 2024: Regulation (EU) 2024/1689 enters into force.
- 2 February 2025: ban on unacceptable practices (social scoring, manipulation, certain forms of biometric identification), plus the AI literacy obligation for organisations that deploy AI systems.
- 2 August 2025: obligations for providers of general-purpose AI models (the large language models).
- 2 August 2026 — in force: Article 50 transparency obligations, national supervisory authorities up and running, and the power to fine (up to €35 million or 7% of worldwide turnover for prohibited practices; €15 million or 3% for other breaches) (Studeria, AI x Leaders).
- 27 July 2026: Regulation (EU) 2026/1744, the "AI digital omnibus", enters into force, passed by Parliament on 16 June and approved by the Council on 29 June (donneespersonnelles.fr). It doesn't touch the substance or the risk-based approach. It moves dates.
- 2 December 2026: end of the grace period for technical marking of generated content (Article 50(2)) for systems already on the market before August 2026; explicit ban on "nudification" systems (Quantic Avocats).
- 2 December 2027: obligations for Annex III high-risk systems (recruitment, credit, education, essential services and so on), pushed back from 2 August 2026.
- 2 August 2028: high-risk AI built into products that are already regulated (Annex I).
What's postponed: high-risk. What isn't: everything else, and above all transparency, which is the part that concerns you.
Situation 1: an "AI" PDF tool reads your document
The big online converters have bolted on AI features: automatic summaries, translation, conversion to Markdown, Q&A over the document. iLovePDF, for one, lists an AI summary generator and a translation tool in its menu (tool page).
Here's what that means technically. Your document isn't just uploaded, processed and deleted any more. Its content is sent to a language model, often run by a third party (OpenAI, Anthropic, Google, or a hosted model), to be read and reworded. That's a different kind of processing from merging pages.
What the AI Act has added since 2 August:
- Transparency (Article 50). When you interact with an AI system, you have to be told. When content is generated or substantially altered by an AI, it has to be identifiable as such. An AI-produced contract summary passed on to a client falls squarely within this logic; if you circulate it, you're the deployer and the obligation is yours.
- AI literacy (Article 4). Since February 2025, an organisation that hands AI tools to its staff has to make sure they understand the limits. That includes knowing a summary may drop a clause, and that a confidential document sent to an online summariser has left the building.
What the AI Act doesn't change, and this is the point that matters: it does not govern the confidentiality of your file. That's still the GDPR's job (you're the controller for the data inside it; the service is merely a processor) and, if the model or the host is American, the CLOUD Act's. A "Summarise with AI" button on a converter is a third third party in the loop, under a third piece of legislation, for a document that may have had no business leaving your computer.
Situation 2: an AI wrote your document
The flip side of the same regulation: more and more documents — minutes, reports, specifications, letters — are written by an assistant or an agent, often delivered as Markdown and then converted to PDF.
Article 50 separates two actors. The provider of the generative system (OpenAI, Anthropic, Google, Mistral and the rest) must technically mark what it produces; systems already on the market have until 2 December 2026. The deployer — that's you, when you use the tool — has to disclose in one specific case only, and with an exception that changes everything in practice.
The exact rule, and its exception
Article 50(4), in its consolidated version of 27 July 2026, targets a deployer who has an AI generate or manipulate text published to inform the public on matters of public interest. In that case, they must disclose that the text was artificially generated or manipulated.
Then comes the exception. The obligation does not apply where the content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication.
In other words, the regulation doesn't ask you to say how the text was written. It asks you to say whether nobody is answering for it. The test isn't the tool. It's responsibility.
What it means in practice
You have an AI churn out blog posts and publish them as they come, with no review, no fact-checking and no name behind them: the "AI-generated content" disclosure is due the moment the subject counts as informing the public — news, health, law, finance, consumer affairs, safety. A company blog that explains the GDPR or compares tools is in this category.
You have an AI write a first draft, then a human reviews it, checks every claim, corrects it and signs it — or the company explicitly takes editorial responsibility: no disclosure needed. The AI was a writing tool, like a spell-checker or a translator; what gets published is content someone answers for.
Internal minutes, a quote, a letter to a client: out of scope. The text isn't meant to inform the public.
A deepfake, a synthetic image or video: separate regime (paragraph 4, first sentence). Disclosure is mandatory except for artistic or satirical uses, with no equivalent editorial exception.
"Human review" isn't defined word for word, but the spirit is clear: read it and take responsibility for what it says. Clicking "publish" isn't editorial control. A review that checks the facts, fixes the errors and puts someone's signature on the line is. Evidence of that process — who reviewed, when, what was changed — is what an authority will ask you for if it comes knocking.
Two practical consequences
- Separate generation from conversion. Generating the text is the regulated act; turning it into a PDF isn't. When you convert an AI-generated Markdown file to PDF on PDFKami, no model is involved: the page lays out your text locally, without reading it, changing it or sending it anywhere. The document doesn't change nature by passing through the tool, and it passes through no third party that could in turn be one more "deployer".
- If you don't review, say so. If you do, say who. A line reading "written with AI, reviewed and approved by [name], editor in charge" is worth more than an invisible technical marker: it satisfies the spirit of the text either way, and the reader can actually read it. Put it in the body, in the footer, or as a watermark on the PDF.
The takeaway
The AI Act doesn't say where your file goes; it says what you must be told when an AI touches it. The GDPR says who's responsible. The CLOUD Act says who can demand it. The three texts stack, and all three apply to a document the moment it leaves your machine for a server, a cloud or a model.
A document that never leaves has no AI provider, no processor and no host. To merge, compress, split or convert — or to lay out what an AI has written — PDFKami does the job in your browser, with no model reading your file and without it ever leaving your computer. For the operations that genuinely need an AI, you now know which questions to ask before you click.