Back to Blog
Artificial IntelligenceIT Strategy

EU AI Act: What Swiss Businesses Need to Know Now

Mert Bacak··7 min read
Lady Justice statue with scales and sword – representing AI regulation and the EU AI Act.

Since 2 August 2024, the EU AI Act — the world's first comprehensive AI regulation — has been in force. What began as a forward-looking piece of EU legislation is now phasing into reality. And Swiss businesses are not exempt.

What is the EU AI Act?

The EU AI Act (Regulation 2024/1689) is a binding regulatory framework covering the use and placement on the market of AI systems. It classifies AI by risk level — from prohibited to minimal — and sets concrete obligations for each tier: documentation, transparency, human oversight, and data governance.

The goal: build trust in AI, protect fundamental rights, and position Europe as a safe hub for AI innovation.

Does the EU AI Act apply to Switzerland?

Yes — using the same extraterritorial principle as the GDPR. The AI Act applies if:

  • You offer or deploy an AI system on the EU market
  • The output of your AI system is used by people in the EU
  • Your customers or end users are based in the EU

A GmbH headquartered in Zurich that sells an AI-powered recruitment platform to German companies, or whose cloud service is used by a client in Paris? Affected.

Switzerland itself is developing its own AI governance framework (led by SECO and the Federal Council) but has not yet passed comparable legislation. Companies that align with the EU AI Act today will be well positioned for Swiss regulation when it arrives.

The four risk tiers

Unacceptable risk (prohibited from February 2025)

Certain AI applications are banned outright:

  • Social scoring: by authorities or companies (classifying people based on social behaviour)
  • Real-time biometric identification in public spaces: (facial recognition by state actors, with narrow exceptions)
  • Subliminal manipulation: — AI that influences behaviour without the person's awareness
  • Emotion recognition: in the workplace or educational settings (with exceptions)
  • Scraping: facial images from the internet to build recognition databases

High-risk AI (strict requirements)

These systems are permitted but carry extensive obligations:

  • HR & Recruiting: CV screening software, hiring decisions, employee performance evaluation
  • Education: automated assessment of exam results, learning monitoring
  • Financial services: credit scoring, insurance classification
  • Healthcare: AI-powered medical devices, diagnostic support
  • Critical infrastructure: energy, water, transport
  • Law enforcement & border control:

Requirements: technical documentation, risk assessment, training data traceability, human oversight, registration in the EU database.

Limited risk AI (transparency obligations)

  • Chatbots and virtual assistants: must disclose that users are interacting with AI
  • Deepfakes: and AI-generated content must be labelled as such

Minimal risk (no obligations)

Spam filters, recommendation algorithms, AI in video games — no regulatory overhead.

Key deadlines

  • 2 February 2025: Prohibited AI practices (unacceptable risk tier)
  • 2 August 2025: Rules for general-purpose AI models (e.g. GPT, Claude)
  • 2 August 2026: High-risk AI under Annex I (safety-critical systems)
  • 2 August 2027: Full application for all high-risk AI (Annex III)

For most businesses, the relevant date is 2 August 2027 — but preparation starts now.

What are the penalties?

The AI Act has teeth:

  • Deploying prohibited AI: up to €35 million or 7% of global annual turnover
  • Other violations: up to €15 million or 3%
  • Misleading authorities: up to €7.5 million or 1.5%

For context: GDPR's maximum penalty is 4% of global turnover. The AI Act exceeds that for the most serious breaches.

What businesses should do right now

1. Build an AI inventory

Which AI systems do you use or develop? In-house builds, purchased tools, AI embedded in SaaS platforms — catalogue everything.

2. Classify each system by risk tier

For each system: which tier does it fall into? Many businesses will find that their HR software or credit-scoring tool now qualifies as high-risk.

3. Identify the gaps

High-risk systems require: technical documentation, risk management, training data traceability, human oversight mechanisms, conformity assessment.

4. Build documentation

No high-risk AI without a paper trail. Who developed it, who tested it, what data was used, what checks were performed.

5. Audit your supply chain

If you use third-party AI (Microsoft Copilot, Salesforce Einstein, etc.): have those vendors classified their systems? Are they providing the necessary documentation?

How Business IT Partners can help

We help Swiss businesses align their AI use with the EU AI Act — without unnecessary complexity:

  • AI inventory: we catalogue all AI systems in use and classify them against the Act's risk model
  • Gap analysis: where is action needed? We prioritise by risk level and effort
  • Documentation: we help build the technical documentation required for high-risk systems
  • Private AI: if you run or develop your own AI systems, we ensure they operate in a controlled Azure cloud environment with full visibility into data flows and model behaviour
  • Ongoing monitoring: AI regulation continues to evolve. We keep you current.

Want to know where your business stands today? Book a free initial consultation.


The EU AI Act is not a compliance burden — it is a competitive advantage for businesses that act early. Companies that deploy AI responsibly today build trust that cannot be bought.

Sources

AI for Your Business

Want to put AI to work in your business?

From AI agents to private AI: we guide you from strategy to implementation — privacy-compliant and tailored to your processes.

Book a Free Consultation

30 min · Free · No obligation

AI consulting for businesses