Wrivio
Get Wrivio
8 min readBy Wrivio Team

What Changes Under the EU AI Act on 2 August 2026

2 August 2026 was, for years, the date everyone circled. It was when the EU AI Act high-risk obligations were to become binding, and a large amount of consultancy revenue was generated preparing for it.

Then the deadline moved, partially. The simplification package agreed in mid-2026 deferred the high-risk obligations while leaving other parts of the date intact, which produced exactly the confusion you would expect. Here is what actually takes effect and what it means for a business that uses AI to write and review documents.

What Applies From 2 August 2026

Three things.

Transparency obligations under Article 50. These cover disclosure: telling people when they are interacting with an AI system, marking synthetic content, and disclosing certain AI-generated or AI-manipulated material. They are not deferred.

Enforcement powers over general-purpose AI. The obligations on general-purpose model providers came into effect in 2025; from August 2026 the authorities have the enforcement machinery to act on them. This lands primarily on the labs rather than on you, and it improves the documentation available to you as a deployer.

The full penalty regime. Fines become available across the applicable obligations. This is the part that concentrates minds.

What Was Deferred

The Commission published a Digital Omnibus proposal in November 2025, and following the European Parliament’s endorsement in June 2026 and Council approval on 29 June 2026, the high-risk timeline shifted materially:

Stand-alone high-risk systems under Annex III move to 2 December 2027.

AI embedded in regulated products under Annex I move to 2 August 2028.

That is a substantial extension for organizations deploying high-risk systems, and it is genuinely welcome given how much guidance was still unsettled. It is not a general reprieve, and reading it as “the AI Act was delayed” is the mistake to avoid.

Good running summaries of the timeline are maintained at artificialintelligenceact.eu, and the official framework page is the authoritative source.

Is An AI Writing Tool High-Risk?

Almost certainly not, and it is worth understanding why rather than just being relieved.

High-risk classification under Annex III attaches to defined use contexts: biometric identification, critical infrastructure, education and vocational training decisions, employment and worker management, access to essential services, law enforcement, migration, and administration of justice.

Rewriting an email for tone is not on that list. The same tool used to generate automated decisions about candidates in a recruitment process could enter high-risk territory, and the distinction is the use rather than the technology. Which means the correct question for your organization is not “is our AI tool high-risk” but “what are we using it for.”

Two places where ordinary writing use gets close enough to warrant care:

Employment decisions. Using AI to draft performance reviews or restructuring communications is not high-risk on its own. Using it to evaluate or rank people is a different matter. Keep the tool on the drafting side of that line, and note that this is exactly the category where you want processing to stay local anyway.

Essential services. Customer communications about access to credit, insurance, or utilities can sit near regulated territory depending on what the AI actually influences.

What Transparency Actually Requires

Article 50 obligations are narrower than the panic suggests, and they hinge on the type of interaction.

Where a person interacts directly with an AI system, they should be informed unless it is obvious. That covers chatbots, not a tool you use privately to tidy your own email before sending it.

Where content is artificially generated or manipulated in ways that could deceive, marking obligations apply. Rewriting your own message for register is not the target of that provision; synthetic media presented as authentic is.

The practical upshot for a professional using a rewriting tool: the Act does not require you to disclose that you tightened your own email with AI assistance. Whether you should is a separate question about professional norms rather than law, and we wrote about it in should you disclose you used AI to write an email.

Where Local Processing Helps, And Where It Does Not

Being precise about this, because the two regimes get conflated constantly.

Local processing does not exempt you from the AI Act. The Act regulates systems by use and risk, not by where inference happens. If you owe someone a disclosure, running the model on your own laptop does not remove the duty.

Local processing does help substantially with GDPR. Chapter V of the GDPR governs transfers of personal data outside the EEA. A model running on your own workstation involves no transfer, so the hardest part of that analysis does not arise. No standard contractual clauses, no adequacy assessment, no subprocessor review for the inference itself.

Local processing helps with minimization and security. Text that is never transmitted cannot be retained by a third party or exposed in their breach. Article 5 minimization and Article 32 security obligations are easier to satisfy when the data does not leave.

So: two different regimes, and local execution is a strong answer to one of them and neutral on the other. There is more on the data-protection side in Mistral, open models, and European data sovereignty.

What To Actually Do This Month

Five items, and none of them require a consultant.

  1. Inventory the AI tools in actual use, including the ones nobody approved. Shadow usage is the norm rather than the exception.
  2. For each tool, record what it is used for, not just what it is. Use determines risk category.
  3. Note which tools transmit content externally and which do not. This is your GDPR transfer picture.
  4. Check whether any use touches employment, essential services, or the other Annex III contexts. If so, get advice rather than guessing.
  5. Write down your disclosure position for client-facing work, so the answer is consistent when a client asks.

There is a fuller process in how to run an AI tool audit for your team.

Writing The Client-Facing Answer

Clients will ask, and vague answers read as evasion, particularly to another professional.

Before:

We take AI compliance seriously and are fully compliant with all applicable regulations including the EU AI Act.

After:

Our position on AI use is as follows. We use AI assistance for drafting and editing our own written work. Confidential client material is processed with a tool that runs locally on our workstations, so document text is not transmitted to any third-party service. We do not use AI to make or materially influence decisions about individuals. We have reviewed our use against the EU AI Act risk categories and do not operate any high-risk system as defined in Annex III. We are happy to provide our tool inventory on request.

A Wrivio Context for compliance correspondence could say:

Rewrite this as a formal client communication on regulatory compliance. Professional register, complete sentences, no contractions. Keep every legal reference, article number, and factual claim exactly as written. Do not add certifications, guarantees, or commitments that are not in the original, and do not replace specific statements with general assurances.

Press Ctrl+Shift+Space, run it, and read the diff. Specific compliance statements turning into blanket claims is the failure mode, and a blanket claim of full compliance is worse than a specific accurate one. Run this kind of correspondence in Local mode so the draft stays on your machine.

Common Questions

Did the EU AI Act get delayed?

Partially. High-risk obligations moved to December 2027 and August 2028 depending on category. Transparency obligations, general-purpose AI enforcement, and the penalty regime took effect on 2 August 2026 as planned.

Does the Act apply to us if we are not in the EU?

It can. The Act has extraterritorial reach where output is used in the EU or systems are placed on the EU market. Non-EU businesses serving EU customers should assume it may apply and check.

Is a local AI writing tool regulated?

The tool itself is a general-purpose system being deployed. Your obligations as a deployer depend on what you use it for. Ordinary drafting and editing is not high-risk.

Do we need to tell clients we use AI?

Not generally under Article 50 for privately tidying your own writing. Whether professional norms or a specific client agreement require it is a separate question worth settling deliberately rather than case by case.

Download Wrivio for Windows to keep confidential drafting on your own hardware, where the transfer analysis does not arise.