In brief
- A Swiss registered office does not rule out application of the EU AI Act.
- The Act distinguishes four system risk levels: unacceptable, high, transparency, and minimal or no risk.
- Classification follows the intended purpose and context; the same model can support systems in different risk levels.
- GPAI model duties are a separate regulatory track and are not a fifth system risk level.
- Swiss privacy, employment, contract and sector rules continue to apply independently.
When an EU connection needs assessment
Article 2 of the EU AI Act contains several territorial connecting factors. For Swiss companies, supply and putting into service in the EU market and use of system output in the EU are particularly relevant. A precise analysis must examine the actual distribution and data flow.
- Is an AI system or GPAI model placed on or supplied to the EU market?
- Does the company act as provider, deployer, importer, distributor or product manufacturer?
- Is output from a system operated outside the EU used in the EU?
- Are EU entities, clients, employees or processes involved in the use?
- Does a statutory exemption or specific transition rule apply?
The company’s role determines who must do what
The AI Act does not simply distinguish buyer from seller. The actual activity matters more than a contractual label: in-house development, substantial modification or marketing under a company’s own name can change the role and therefore the duties.
- A provider develops an AI system or has it developed and places it on the market or puts it into service under its own name or trademark.
- A deployer uses an AI system under its authority; for high-risk systems this can include human oversight, monitoring and information duties.
- For high-risk systems, importers and distributors must perform defined checks before making the system available in the EU.
- For a high-risk system, rebranding, a substantial modification or changing the intended purpose into a high-risk use can transfer provider duties.
- One company can hold several roles along the value chain, so every system and distribution setup needs its own assessment.
The four risk levels in plain language
The AI Act does not assign a company, provider or model to one fixed risk level. The intended purpose, specific use and influence on people are decisive. The same language model can be minimal risk for internal drafting, trigger transparency duties as a customer chatbot and form part of a high-risk system when assessing applicants.
The levels can overlap: a high-risk system may also carry a transparency duty. General-purpose AI models, or GPAI, are not a fifth level; their providers and models with systemic risk are covered by separate model-level rules.
- Unacceptable risk — prohibited
- Particularly harmful practices generally may not be offered or used. Examples include emotion recognition in the workplace from voice or camera data (with exceptions for medical or safety reasons), certain forms of social scoring and untargeted collection of facial images to build recognition databases.
- High risk — permitted under strict rules
- This includes safety components of certain regulated products and listed uses in sensitive areas. Examples are filtering or ranking applicants, assessing exams or admission, evaluating a person’s creditworthiness and safety functions in critical infrastructure. A narrow preparatory tool may be excluded if it does not materially influence the decision; profiling people remains high-risk in Annex III cases.
- Transparency risk — disclosure required
- People must, for example, be informed when they are interacting with a chatbot unless this is already obvious. Synthetic content must be technically identifiable, while deepfakes and certain AI-generated public-interest content require visible disclosure, subject to the statutory exceptions.
- Minimal or no risk — no category-specific duties
- Most AI systems fall here. Official examples include spam filters and AI-enabled video games; internal forecasting or drafting can also fit when it neither affects high-stakes decisions about people nor triggers a transparency case. The cross-cutting AI literacy duty and privacy, employment, copyright and other applicable law still remain relevant.
The timeline is phased and evolving
The AI Act entered into force on 1 August 2024 and applies in stages. Parliament and the Council adopted the 2026 Digital Omnibus, whose adopted text provides for 2 December 2027 for stand-alone high-risk systems under Annex III and 2 August 2028 for high-risk systems embedded in regulated products under Annex I. As at 17 July 2026, publication in the Official Journal and entry into force were still pending, so the formal legal status must be checked separately. Other provisions still have earlier dates; the exact duty—not just the label ‘AI Act’—must therefore be mapped to the relevant system.
| Date | What applies | Practical meaning |
|---|---|---|
| 2 February 2025 | Definitions, AI literacy and the first prohibited practices | Companies need role-appropriate AI competence and must already exclude prohibited uses. |
| 2 August 2025 | Governance and obligations for general-purpose AI models | GPAI providers and affected value-chain actors must map the model-level rules separately from system risk classes. |
| 2 August 2026 | Most remaining rules, enforcement and the main Article 50 transparency duties | Check the amended transition provisions for systems already on the market and do not confuse this date with the postponed high-risk obligations. |
| 2 December 2026 | Additional prohibited practices and a transition deadline for certain providers of systems generating synthetic content | Review affected content-generation products and the technical marking required by Article 50(2). |
| 2 December 2027 | High-risk obligations for stand-alone systems under Annex III | Typical areas include employment, education, essential services and certain biometric or public-sector uses. |
| 2 August 2028 | High-risk obligations for systems embedded in regulated products under Annex I | Product and sector compliance plans must coordinate the AI Act with the applicable safety legislation. |
Practical steps for a Swiss company
As at July 2026, Switzerland has no overarching AI-specific legislation. Existing law, especially data protection law, remains directly applicable. EU scope and Swiss duties can be tracked in one inventory but require separate legal analysis.
- Step 1
Record the system and market link
Document product, purpose, users, output and affected countries.
- Step 2
Qualify the role
Assess provider, deployer, importer or other roles against contracts and distribution.
- Step 3
Assess risk category
Check prohibited practices, high-risk status and transparency duties; assess GPAI obligations separately.
- Step 4
Map duties and dates
Assign evidence, accountable owners and the applicable date.
- Step 5
Monitor change
Track EU guidance, standards and Swiss regulation as formal review triggers.
Example: Swiss recruitment software sold to EU clients
A Swiss provider sells AI-assisted applicant ranking to companies in Germany and France. It reviews not only privacy contracts but also its role as provider, possible high-risk classification in employment, technical documentation and the clients’ deployer duties. The analysis may differ for a purely internal Swiss test environment.
What to remember
Do not begin with a generic compliance checklist. For each system, first establish EU connection, role, risk category and application date, then derive the actual duties.
Sources and further reading
These primary sources provide further detail on definitions, technical foundations or responsible use.
Content reviewed
Reviewed 17 July 2026. General information, not legal advice. The specific legal position and applicable scope must be assessed for each use case.
- EUR-Lex: Regulation (EU) 2024/1689, Articles 2, 5, 6 and 50 and Annexes I and III
- European Commission: AI Act and application timeline
- European Commission AI Act Service Desk: implementation timeline
- Council of the EU: final adoption of the 2026 AI Omnibus
- Council of the EU: adopted legal text of 8 July 2026
- Swiss Federal Chancellery: Regulation of AI
- OFCOM: Artificial intelligence and Switzerland’s regulatory approach