Regulation · EU AI Act

What is the EU AI Act – and what does it mean for Swiss businesses?

What is the EU AI Act?

The EU AI Act is the first horizontal, cross-sector regulation for artificial intelligence. As Regulation (EU) 2024/1689 it entered into force on 1 August 2024 and applies directly in every EU member state, with no national transposition needed. Its goal is a single market for trustworthy AI: enabling innovation while protecting fundamental rights, health and safety.

The approach is risk-based, not technology-specific. What is regulated is not the technology itself but the intended purpose of an AI system and the risk it entails. The higher the risk to people and society, the stricter the requirements – ranging from an outright ban to no additional obligations at all.

The four risk tiers at a glance

Cutting across these tiers are the rules for general-purpose AI models (GPAI), such as large language models. Their providers must supply technical documentation, a copyright policy and a summary of training data; models powerful enough to pose systemic risk face additional obligations.

  • Unacceptable risk (prohibited, Art. 5): practices such as social scoring by authorities, manipulative or exploitative techniques, untargeted scraping of facial images to build databases, and – with narrow exceptions – emotion recognition in the workplace and in education.
  • High risk: AI in sensitive areas (Annex III) such as recruitment, creditworthiness, critical infrastructure, education, law enforcement or migration, as well as AI acting as a safety component of regulated products. Duties: risk management, data quality, technical documentation, human oversight and conformity assessment.
  • Limited risk (transparency, Art. 50): systems that interact with people or generate content. The main duty is disclosure – users must know they are dealing with AI or that content is artificially generated.
  • Minimal risk: the vast majority of today's applications – e.g. spam filters, recommendation systems or AI in video games. Here the EU AI Act imposes no additional legal obligations; voluntary codes of conduct are encouraged.

Extraterritorial reach: why Switzerland is affected

Switzerland is not an EU member, yet the EU AI Act can apply directly to Swiss companies. What matters is the link to the EU market, not where the company is based. It captures providers that place AI systems on the EU market, and providers and deployers outside the EU where the output of their AI system is used within the EU.

In practice this means: a Swiss SME that sells an AI tool to customers in Germany, or whose AI-generated screening of a job application concerns a person in the EU, can fall within scope. As with the EU's data protection regulation, the reach is deliberately cross-border.

Transparency duties under Article 50

Article 50 covers a very broad set of applications and is, for many companies, the most practically relevant duty. It requires disclosure so that people are not misled about the involvement of AI.

  • Chatbots and assistants: people must be able to tell they are interacting with an AI system and not a human – unless this is obvious.
  • Generated content: synthetic audio, image, video or text content must be marked in a machine-readable way as artificially generated.
  • Deepfakes: anyone generating or manipulating image, audio or video content that appears authentic must disclose that it was artificially created.
  • Emotion recognition and biometric categorisation: affected individuals must be informed that such systems are in use.

The timeline: when each obligation applies

  • 1 August 2024: the regulation enters into force.
  • 2 February 2025: the prohibitions (Art. 5) and the AI-literacy duty (Art. 4) apply.
  • 2 August 2025: obligations for general-purpose AI models, governance structures and penalty provisions take effect.
  • 2 August 2026: the majority of provisions apply, including the high-risk requirements under Annex III and the Article 50 transparency duties.
  • 2 August 2027: the high-risk rules for AI as a safety component of regulated products (Annex I) apply.

What this means for Switzerland – EU AI Act, revFADP and the Swiss path

Switzerland currently has no horizontal AI law of its own. In 2025 the Federal Council decided to ratify the Council of Europe's Convention on AI and to regulate AI primarily in a sector-specific way and by adapting existing law, rather than creating one comprehensive statute. A corresponding bill is to be drafted by the end of 2026.

Independently of this, the revised Data Protection Act (revFADP/nFADP), overseen by the FDPIC, already governs the handling of personal data in AI systems. Anyone deploying AI in Switzerland must therefore already address data-protection, transparency and fairness questions today – the EU AI Act adds to this where there is an EU-market link, but does not replace the revFADP.

First steps: how to prepare

  • Build an inventory: catalogue all AI systems in use and planned, with their intended purpose and whether there is an EU link.
  • Clarify your role: are you a provider, deployer, importer or distributor? Obligations differ significantly by role.
  • Classify the risk: for each system, check whether it is prohibited, high-risk, subject to transparency duties or minimal.
  • Build AI literacy: train staff in the responsible use of AI (Art. 4 requires a sufficient level of AI literacy).
  • Implement transparency: label chatbots and AI-generated content, and document your measures in a traceable way.

Frequently asked questions

Does the EU AI Act apply to Swiss companies?

It can apply directly. What matters is the link to the EU market: if you place AI systems on the EU market, or their output is used in the EU, you fall within scope regardless of a Swiss registered office – similar to the extraterritorial logic of EU data protection law.

When does the EU AI Act start to apply?

It entered into force on 1 August 2024 and applies in stages: prohibitions since 2 February 2025, GPAI duties since 2 August 2025, most obligations including high-risk (Annex III) and transparency (Art. 50) from 2 August 2026, and product-embedded high-risk rules (Annex I) from 2 August 2027.

What is a high-risk AI system?

A system used in sensitive areas listed in Annex III – such as recruitment, creditworthiness, critical infrastructure, education or law enforcement – or one acting as a safety component of a regulated product. Such systems face duties like risk management, data quality, documentation, human oversight and conformity assessment.

What penalties apply for non-compliance?

Fines are tiered: up to 35 million euros or 7% of worldwide annual turnover for prohibited practices, and up to 15 million euros or 3% for breaches of other obligations (whichever is higher). For SMEs and start-ups the lower of the two amounts applies.

Do I have to label AI-generated content and chatbots?

Yes, where Article 50 applies. Chatbots must disclose that an AI is interacting with the person (unless obvious), and synthetic content and deepfakes must be identifiable or machine-readable as artificially generated. These duties apply from 2 August 2026.

Does the EU AI Act replace the Swiss Data Protection Act (revFADP)?

No. The EU AI Act governs AI systems, while the revFADP/nFADP governs the handling of personal data. Both can apply in parallel: in Switzerland the FDPIC oversees data protection, while the EU AI Act applies additionally where there is an EU-market link. Switzerland is also pursuing its own sector-specific path to AI regulation.

Key terms in the glossary

← Back to overview

Practical AI for your business

From idea to implementation – we show you what is concretely possible in your case.

Request a demo