Search

What are you looking for?

Search our services, use cases and practical insights.

Enter at least 2 characters

Popular starting points

Data & governance

What does the EU AI Act mean for Swiss companies?

The EU AI Act does not automatically apply to every Swiss company. It can become relevant when a company offers or uses AI systems or their outputs in the EU market and the statutory connecting factors are met.

The short answer

A Swiss company should assess the EU AI Act particularly where it places an AI system or general-purpose AI model on the EU market, acts as a covered provider or deployer, or where output from a system operated outside the EU is used in the EU. Applicable duties depend on role, system, purpose, market connection and application date.

In brief

  • A Swiss registered office does not rule out application of the EU AI Act.
  • The Act distinguishes four system risk levels: unacceptable, high, transparency, and minimal or no risk.
  • Classification follows the intended purpose and context; the same model can support systems in different risk levels.
  • GPAI model duties are a separate regulatory track and are not a fifth system risk level.
  • Swiss privacy, employment, contract and sector rules continue to apply independently.

When an EU connection needs assessment

Article 2 of the EU AI Act contains several territorial connecting factors. For Swiss companies, supply and putting into service in the EU market and use of system output in the EU are particularly relevant. A precise analysis must examine the actual distribution and data flow.

  • Is an AI system or GPAI model placed on or supplied to the EU market?
  • Does the company act as provider, deployer, importer, distributor or product manufacturer?
  • Is output from a system operated outside the EU used in the EU?
  • Are EU entities, clients, employees or processes involved in the use?
  • Does a statutory exemption or specific transition rule apply?

The company’s role determines who must do what

The AI Act does not simply distinguish buyer from seller. The actual activity matters more than a contractual label: in-house development, substantial modification or marketing under a company’s own name can change the role and therefore the duties.

  • A provider develops an AI system or has it developed and places it on the market or puts it into service under its own name or trademark.
  • A deployer uses an AI system under its authority; for high-risk systems this can include human oversight, monitoring and information duties.
  • For high-risk systems, importers and distributors must perform defined checks before making the system available in the EU.
  • For a high-risk system, rebranding, a substantial modification or changing the intended purpose into a high-risk use can transfer provider duties.
  • One company can hold several roles along the value chain, so every system and distribution setup needs its own assessment.

The four risk levels in plain language

The AI Act does not assign a company, provider or model to one fixed risk level. The intended purpose, specific use and influence on people are decisive. The same language model can be minimal risk for internal drafting, trigger transparency duties as a customer chatbot and form part of a high-risk system when assessing applicants.

The levels can overlap: a high-risk system may also carry a transparency duty. General-purpose AI models, or GPAI, are not a fifth level; their providers and models with systemic risk are covered by separate model-level rules.

Unacceptable risk — prohibited
Particularly harmful practices generally may not be offered or used. Examples include emotion recognition in the workplace from voice or camera data (with exceptions for medical or safety reasons), certain forms of social scoring and untargeted collection of facial images to build recognition databases.
High risk — permitted under strict rules
This includes safety components of certain regulated products and listed uses in sensitive areas. Examples are filtering or ranking applicants, assessing exams or admission, evaluating a person’s creditworthiness and safety functions in critical infrastructure. A narrow preparatory tool may be excluded if it does not materially influence the decision; profiling people remains high-risk in Annex III cases.
Transparency risk — disclosure required
People must, for example, be informed when they are interacting with a chatbot unless this is already obvious. Synthetic content must be technically identifiable, while deepfakes and certain AI-generated public-interest content require visible disclosure, subject to the statutory exceptions.
Minimal or no risk — no category-specific duties
Most AI systems fall here. Official examples include spam filters and AI-enabled video games; internal forecasting or drafting can also fit when it neither affects high-stakes decisions about people nor triggers a transparency case. The cross-cutting AI literacy duty and privacy, employment, copyright and other applicable law still remain relevant.

The timeline is phased and evolving

The AI Act entered into force on 1 August 2024 and applies in stages. Parliament and the Council adopted the 2026 Digital Omnibus, whose adopted text provides for 2 December 2027 for stand-alone high-risk systems under Annex III and 2 August 2028 for high-risk systems embedded in regulated products under Annex I. As at 17 July 2026, publication in the Official Journal and entry into force were still pending, so the formal legal status must be checked separately. Other provisions still have earlier dates; the exact duty—not just the label ‘AI Act’—must therefore be mapped to the relevant system.

The timeline is phased and evolving
DateWhat appliesPractical meaning
2 February 2025Definitions, AI literacy and the first prohibited practicesCompanies need role-appropriate AI competence and must already exclude prohibited uses.
2 August 2025Governance and obligations for general-purpose AI modelsGPAI providers and affected value-chain actors must map the model-level rules separately from system risk classes.
2 August 2026Most remaining rules, enforcement and the main Article 50 transparency dutiesCheck the amended transition provisions for systems already on the market and do not confuse this date with the postponed high-risk obligations.
2 December 2026Additional prohibited practices and a transition deadline for certain providers of systems generating synthetic contentReview affected content-generation products and the technical marking required by Article 50(2).
2 December 2027High-risk obligations for stand-alone systems under Annex IIITypical areas include employment, education, essential services and certain biometric or public-sector uses.
2 August 2028High-risk obligations for systems embedded in regulated products under Annex IProduct and sector compliance plans must coordinate the AI Act with the applicable safety legislation.

Practical steps for a Swiss company

As at July 2026, Switzerland has no overarching AI-specific legislation. Existing law, especially data protection law, remains directly applicable. EU scope and Swiss duties can be tracked in one inventory but require separate legal analysis.

  1. Step 1

    Record the system and market link

    Document product, purpose, users, output and affected countries.

  2. Step 2

    Qualify the role

    Assess provider, deployer, importer or other roles against contracts and distribution.

  3. Step 3

    Assess risk category

    Check prohibited practices, high-risk status and transparency duties; assess GPAI obligations separately.

  4. Step 4

    Map duties and dates

    Assign evidence, accountable owners and the applicable date.

  5. Step 5

    Monitor change

    Track EU guidance, standards and Swiss regulation as formal review triggers.

Example from day-to-day business

Example: Swiss recruitment software sold to EU clients

A Swiss provider sells AI-assisted applicant ranking to companies in Germany and France. It reviews not only privacy contracts but also its role as provider, possible high-risk classification in employment, technical documentation and the clients’ deployer duties. The analysis may differ for a purely internal Swiss test environment.

What to remember

Do not begin with a generic compliance checklist. For each system, first establish EU connection, role, risk category and application date, then derive the actual duties.

Sources and further reading

These primary sources provide further detail on definitions, technical foundations or responsible use.

Content reviewed

Reviewed 17 July 2026. General information, not legal advice. The specific legal position and applicable scope must be assessed for each use case.

Would you like to apply this to your situation?

Together, we clarify what makes sense for your process, data and systems – in plain language and without unnecessary complexity.

Discuss Your Project