EU AI Act: What Swiss Businesses Need to Know Now

Since 2 August 2024, the EU AI Act — the world's first comprehensive AI regulation — has been in force. What began as a forward-looking piece of EU legislation is now phasing into reality. And Swiss businesses are not exempt.
What is the EU AI Act?
The EU AI Act (Regulation 2024/1689) is a binding regulatory framework covering the use and placement on the market of AI systems. It classifies AI by risk level — from prohibited to minimal — and sets concrete obligations for each tier: documentation, transparency, human oversight, and data governance.
The goal: build trust in AI, protect fundamental rights, and position Europe as a safe hub for AI innovation.
Does the EU AI Act apply to Switzerland?
Yes — using the same extraterritorial principle as the GDPR. The AI Act applies if:
- You offer or deploy an AI system on the EU market
- The output of your AI system is used by people in the EU
- Your customers or end users are based in the EU
A GmbH headquartered in Zurich that sells an AI-powered recruitment platform to German companies, or whose cloud service is used by a client in Paris? Affected.
Switzerland itself is developing its own AI governance framework (led by SECO and the Federal Council) but has not yet passed comparable legislation. Companies that align with the EU AI Act today will be well positioned for Swiss regulation when it arrives.
The four risk tiers
Unacceptable risk (prohibited from February 2025)
Certain AI applications are banned outright:
- Social scoring: by authorities or companies (classifying people based on social behaviour)
- Real-time biometric identification in public spaces: (facial recognition by state actors, with narrow exceptions)
- Subliminal manipulation: — AI that influences behaviour without the person's awareness
- Emotion recognition: in the workplace or educational settings (with exceptions)
- Scraping: facial images from the internet to build recognition databases
High-risk AI (strict requirements)
These systems are permitted but carry extensive obligations:
- HR & Recruiting: CV screening software, hiring decisions, employee performance evaluation
- Education: automated assessment of exam results, learning monitoring
- Financial services: credit scoring, insurance classification
- Healthcare: AI-powered medical devices, diagnostic support
- Critical infrastructure: energy, water, transport
- Law enforcement & border control:
Requirements: technical documentation, risk assessment, training data traceability, human oversight, registration in the EU database.
Limited risk AI (transparency obligations)
- Chatbots and virtual assistants: must disclose that users are interacting with AI
- Deepfakes: and AI-generated content must be labelled as such
Minimal risk (no obligations)
Spam filters, recommendation algorithms, AI in video games — no regulatory overhead.
Update, August 2026: the Digital Omnibus moved the deadlines
On 27 July 2026, Regulation (EU) 2026/1744 — the Digital Omnibus on AI — entered into force and amended more than 40 articles of the AI Act. Three points matter for businesses:
- High-risk deadlines pushed back: Standalone high-risk systems under Annex III now have until 2 December 2027 instead of 2 August 2026. For safety components in regulated products (Annex I), the deadline moves from 2 August 2027 to 2 August 2028.
- The transparency obligations apply regardless: Article 50 has been applicable since 2 August 2026. If you run a chatbot, you must disclose that users are talking to a machine. AI-generated content needs machine-readable marking. Generative systems already on the market before 2 August 2026 have a transition period until 2 December 2026.
- AI literacy weakened: The duty to ensure sufficient AI competence became a duty to promote it. Nobody has to guarantee a specific level of competence any more.
In short: the part that affects your website and your customer conversations already applies. The part demanding technical documentation and conformity assessment has been given more room.
Key deadlines
- 2 February 2025: Prohibited AI practices (unacceptable risk tier)
- 2 August 2025: Rules for general-purpose AI models (e.g. GPT, Claude)
- 2 August 2026: Article 50 transparency obligations — chatbots, deepfakes, AI-generated content
- 2 December 2027: High-risk AI under Annex III — standalone systems, such as HR, credit scoring, or education
- 2 August 2028: High-risk AI under Annex I — safety components in regulated products
For most businesses, 2 August 2026 is already in effect. 2 December 2027 is the date to plan towards.
What are the penalties?
The AI Act has teeth:
- Deploying prohibited AI: up to €35 million or 7% of global annual turnover
- Other violations: up to €15 million or 3%
- Misleading authorities: up to €7.5 million or 1.5%
For context: GDPR's maximum penalty is 4% of global turnover. The AI Act exceeds that for the most serious breaches.
What businesses should do right now
1. Build an AI inventory
Which AI systems do you use or develop? In-house builds, purchased tools, AI embedded in SaaS platforms — catalogue everything.
2. Classify each system by risk tier
For each system: which tier does it fall into? Many businesses will find that their HR software or credit-scoring tool now qualifies as high-risk.
3. Identify the gaps
High-risk systems require: technical documentation, risk management, training data traceability, human oversight mechanisms, conformity assessment.
4. Build documentation
No high-risk AI without a paper trail. Who developed it, who tested it, what data was used, what checks were performed.
5. Audit your supply chain
If you use third-party AI (Microsoft Copilot, Salesforce Einstein, etc.): have those vendors classified their systems? Are they providing the necessary documentation?
How Business IT Partners can help
We help Swiss businesses align their AI use with the EU AI Act — without unnecessary complexity:
- AI inventory: we catalogue all AI systems in use and classify them against the Act's risk model
- Gap analysis: where is action needed? We prioritise by risk level and effort
- Documentation: we help build the technical documentation required for high-risk systems
- Private AI: if you run or develop your own AI systems, we ensure they operate in a controlled Azure cloud environment with full visibility into data flows and model behaviour
- Ongoing monitoring: AI regulation continues to evolve. We keep you current.
Want to know where your business stands today? Book a free initial consultation.
The EU AI Act is not a compliance burden — it is a competitive advantage for businesses that act early. Companies that deploy AI responsibly today build trust that cannot be bought.
Sources
AI for Your Business
Want to put AI to work in your business?
From AI agents to private AI: we guide you from strategy to implementation — privacy-compliant and tailored to your processes.
Book a Free Consultation30 min · Free · No obligation
Not ready for a call? Take the AI Check — 8 minutes
More Articles
Seven Questions for Your IT Partner – Ask Them Before You Sign
Daniel Da Cruz · 24 August 2026
AI Cracks an 87-Year-Old Math Problem in One Evening – and the Recipe Works for Your Business Too
Mert Bacak · July 20, 2026
Claude Fable 5 Is Here: Anthropic's Most Powerful AI Model Is Now Available to Everyone
Mert Bacak · July 2, 2026