
Table of Contents
As of August 2, 2026, up to €15 million or 3% of global revenue: that's the fine a company now risks if it lets a chatbot answer a client without ever disclosing that it's an AI.
For a wealth management firm, this date doesn't mark the full application of the EU's AI regulation. It marks the point where regulators can finally investigate and sanction.
AI's role in the advisory journey now has to become identifiable, controllable, and traceable, not just effective.
In short: as of August 2, 2026, any AI system that interacts directly with a client (chatbot, assistant, conversational agent) must clearly disclose that fact, or risk a fine. The heaviest obligations, reserved for systems classified as high-risk (credit scoring, life and health insurance pricing), are pushed back to December 2027 and August 2028. For a wealth advisor, the immediate priority is transparency, not an overhaul of every tool in use.
What is the AI Act?
The AI Act is EU Regulation (EU) 2024/1689, which governs the development and use of artificial intelligence systems.
Its approach is risk-based: a tool that sorts emails and a system that contributes to an important decision about a person are not held to the same requirements. The regulation distinguishes four categories:
prohibited practices;
high-risk systems;
systems subject to transparency obligations;
low-risk or minimal-risk uses.
The regulation entered into force on August 1, 2024, and applies in stages. Several practices have been banned since February 2025, and obligations on providers of general-purpose AI models have applied since August 2025. The timeline was adjusted in 2026 by a text that few wealth-advisory articles mention: the Digital Omnibus on AI, a regulation published in the EU Official Journal on July 24, 2026, which notably pushed back the heaviest obligations on high-risk systems.
What actually changes on August 2, 2026?
The most immediate change concerns transparency, set out in Article 50 of the regulation.
When an AI system interacts directly with a person, that person must be informed they are dealing with an artificial intelligence system, unless this is already obvious. This information must be communicated clearly, no later than the first interaction.
For a wealth management firm, this obligation can apply to:
a chatbot on the firm's website;
an assistant built into the client portal;
an agent that automatically answers a prospect's questions;
a conversational interface that collects wealth-related information.
The client needs to understand that they're dealing with an automated system, what it can do, and at what point a human advisor takes over. A general mention buried in the terms of use doesn't meet this transparency requirement.
One reassuring detail: systems already on the market before August 2, 2026 get an additional transition period, until December 2, 2026, to come into compliance.
Does this also cover AI-generated content?
Yes. The AI Act also governs artificial or manipulated content.
Providers of generative systems must make certain content technically detectable through marking. Disclosure obligations also cover deepfakes, as well as AI-generated text published to inform the public on a matter of public interest without genuine human editorial oversight.
For a firm, this can involve an artificially generated video, an automatically published study, an article produced entirely by AI, or an economic analysis distributed without real review.
A piece written with AI assistance, then read, corrected, and validated by a qualified person, is clearly distinct from content generated and published without oversight. Human validation has to mean a genuine substantive review, not quickly opening a document before it goes out.
Which uses are classified as high-risk for a wealth advisor?
Only two financial use cases are automatically classified as high-risk under the AI Act: credit scoring and life/health insurance pricing.
Annex III of the regulation lists eight domains where an AI system is automatically classified as high-risk. For the financial sector, these two specific use cases apply:
AI systems intended to assess a natural person's creditworthiness or establish their credit score, except systems used for fraud detection;
AI systems intended for risk assessment and pricing for natural persons in life and health insurance.
A meeting copilot, a document-extraction tool, or a general-purpose wealth assistant doesn't fall into this category by default. What tips a tool into high-risk isn't the fact that it uses AI, it's its precise purpose: assessing a credit score, or setting a life or health insurance price based on a person's profile.
A firm should therefore look at each tool individually, not assume risk based on the presence of AI in general.
What should wealth advisors do today?
The first step is to map out every place where AI is used within the firm: meeting transcription, information extraction from documents, CRM updates, wealth analysis preparation, report generation, drafting recommendations, marketing content creation.
For each use, five simple questions help take stock:
What data is sent to the AI?
What processing is performed?
What output is produced?
Who reviews that output?
Which version is ultimately used or shared with the client?
This mapping exercise doesn't necessarily take several weeks. It mainly calls for rigor: list the tools, then answer these five questions honestly for each one.
How do you build transparency into your tools?
The main change isn't adding a banner that says "AI in use here."
In an advisory process, it becomes necessary to clearly separate: information the client provided directly, data automatically extracted from a conversation or document, a hypothesis suggested by the AI, a calculation produced by an engine, a recommendation put forward, and an element corrected or validated by the advisor.
This separation lets the professional catch an extraction error, check a hypothesis, or adjust a proposal before it reaches the client. Informing the user, the advisor's validation, and keeping a record of each step need to progressively become features of the product itself, not a layer bolted on afterward.
How does Apana fit into this model?
Apana was built around a clear separation between what AI extracts, what business engines calculate, and what the advisor validates.
Copilot: extract, then get it validated
Apana Copilot turns conversations and documents into structured wealth data. Extracted information is submitted to the advisor for validation before syncing to the CRM: they can review, correct, or complete the identified data before it becomes part of the client's permanent file.
Advisor: calculate rather than guess
Apana Advisor runs on deterministic calculation engines and wealth simulators. The same set of data and assumptions produces a reproducible, checkable, auditable result, unlike a figure generated directly by a language model with no calculation engine behind it. The conversational model helps understand the request and pull in the right tools; the actual number comes from the calculation engine, along with its assumptions and sources.
Officer: track the compliance journey
Apana Officer manages the rest of the journey: updating the file, producing documents, compliance checks, signature, and keeping a record of each step. This architecture connects the extracted data, the analysis produced, and the document ultimately validated by the advisor.
The firm ends up with a readable chain: AI extracts or proposes, business engines calculate, the advisor reviews and validates, the platform keeps a record of the journey. That's exactly the direction the AI Act is pushing toward: making AI's involvement understandable and enabling genuine human oversight.
For more on these three components, our compliance tools comparison for wealth advisors and our AI tools comparison for wealth advisors go into how each one works day to day.
What's changing in 2027 and 2028?
The obligations on high-risk systems will be considerably more demanding.
Under the timeline set by the Digital Omnibus, they will apply starting December 2, 2027 for standalone systems under Annex III (including credit and life/health insurance), and starting August 2, 2028 for AI systems embedded in products already covered by EU product-safety legislation (Annex I).
Providers concerned will notably need to strengthen risk management, data governance and quality, technical documentation, activity log retention, human oversight, and the accuracy, robustness, and cybersecurity of their systems.
These obligations won't apply to every piece of wealth-management software. They do, however, point to the regulation's overall direction: the more an AI influences an important decision for a client, the more its workings will need to be documented, controlled, and auditable. Firms therefore have an interest in choosing tools now that can retain sources, edits, validations, and result versions, rather than waiting for the regulatory deadline to start.
Timeline at a glance
Date | What applies |
|---|---|
August 2, 2025 | Prohibited practices + obligations on general-purpose AI model providers |
August 2, 2026 | Transparency (Article 50): chatbots, deepfakes, generated content |
December 2, 2026 | End of the transition period for systems already on the market before August 2026 |
December 2, 2027 | Standalone high-risk systems (Annex III): credit, life/health insurance |
August 2, 2028 | High-risk systems embedded in already-regulated products (Annex I) |
For a broader look at what's available today, our meeting copilots comparison for wealth advisors stays current on this front.
FAQ
Does August 2, 2026 mean the AI Act applies in full?
No. This date marks the start of the Article 50 transparency obligations (chatbots, generated content). The heaviest obligations, on high-risk systems, are pushed back to 2027 and 2028.
Is a meeting copilot a high-risk system?
Not by default. Only two financial use cases are automatically classified as high-risk: credit scoring (excluding fraud) and life/health insurance pricing. A meeting-capture copilot doesn't fall into that category by default.
What does a firm risk by not meeting the transparency obligation?
An administrative fine of up to €15 million or 3% of global revenue for an Article 50 breach, versus €35 million or 7% for prohibited practices.
Does AI-written blog content need to be disclosed?
Yes, unless it has been read, corrected, and substantively validated by a qualified person. A piece that's simply opened and published without real review still counts as AI-generated content under the regulation.
Should firms wait until 2027 to act?
No. Mapping out AI use across the firm now, and choosing tools that retain sources, versions, and validations, avoids having to rebuild everything in a rush as the high-risk deadline approaches.
Sources
Touteleurope.eu, Intelligence artificielle : ce qui change vraiment le 2 août 2026 avec le règlement européen, August 2, 2026.
Blog du Modérateur, IA Act : ce qui change le 2 août 2026, July 2026.
Droit & Technologies, Intelligence artificielle : à partir du 2 août 2026, la transparence devient obligatoire, July 2026.
Forum des Compétences, AI Act et systèmes d'IA à haut risque dans la finance, July 2026.
Autorité de contrôle prudentiel et de résolution (ACPR), Le règlement européen sur l'intelligence artificielle (« AI Act »), banque-france.fr.
European Commission, Annex III of Regulation (EU) 2024/1689, ai-act-service-desk.ec.europa.eu.
Want to see how Copilot, Advisor, and Officer track every step of a real file?
