Artificial Intelligence in the Enterprise, 2026 Compliance Guide

25 min readLast updated 5 Aug 2026By Dr. Dominic Staiger

What does AI compliance mean?

AI compliance denotes the entirety of all legal, regulatory and normative obligations to be observed when developing, deploying, placing on the market and operating systems of Artificial Intelligence within enterprises. It connects AI-specific law, in particular the EU AI Act, with data protection, information security, product liability and sector-specific regulation.

Three frameworks form the core of AI compliance for companies in the DACH region: first, Regulation (EU) 2024/1689 (EU Artificial Intelligence Act, the EU AI Act), which entered into force on 1 August 2024 and applies on a staggered basis. Second, data protection law (GDPR and the Swiss FADP), which governs the processing of personal data by and within AI systems. Third, the management standard ISO/IEC 42001:2023 for AI management systems (AI Management System, AIMS), published in December 2023 as the first certifiable standard for AI governance.

In Switzerland there is, as of May 2026, no AI-specific federal statute. On 5 September 2024 the Federal Council signed the Council of Europe Framework Convention on Artificial Intelligence, and a national implementing act is being prepared. Until then the existing law applies: the FADP for personal data, the Code of Obligations for contractual and non-contractual liability, and sector-specific enactments (FINMA circulars, therapeutic products law, health insurance law).

AI compliance is YMYL-relevant: a faulty automated decision can affect credit approvals, medical diagnoses, personnel decisions or insurance contracts. Infringements of the EU AI Act may be sanctioned with up to EUR 35 million or 7 percent of global annual turnover, higher than the GDPR.

Which companies are affected by the EU AI Act?

The EU AI Act applies under Art. 2 of the EU AI Act to a wide range of actors along the AI value chain and reaches extraterritorially well beyond the borders of the EU. Swiss companies are affected indirectly in many constellations.

Addressees (Art. 2(1) of the EU AI Act). Covered are providers who place AI systems on the market or put them into service in the Union; deployers who use AI systems under their own responsibility; importers and distributors; product manufacturers who place AI systems on the market together with their product under their own name; authorised representatives of providers established outside the EU; as well as affected persons located in the EU.

Territorial scope (Art. 2(1)(a) to (c) of the EU AI Act). The Regulation applies where a provider places an AI system on the EU market, regardless of its place of establishment; where a deployer uses the system within the EU; or where the output of the AI system is used in the EU, even if the provider and the deployer are established outside the EU. This output clause functionally corresponds to the market principle of Art. 3 GDPR and captures Swiss companies extensively.

Swiss SMEs and groups. A Swiss provider that sells an AI solution into the EU market is directly subject to the EU AI Act. A Swiss company whose internal chatbot delivers results to employees of an EU subsidiary may likewise fall within the scope. Swiss cloud providers or API providers whose output is used by EU customers are also affected.

Exemptions (Art. 2(3) to (10) of the EU AI Act). Excluded from the scope are AI systems for exclusively military or defence purposes, exclusively scientific research and development, free and open-source AI outside the prohibitions or high-risk cases, as well as purely personal, non-professional use. The exemptions must be construed narrowly.

The four risk classes of the EU AI Act

The EU AI Act follows a risk-based approach and distinguishes four risk classes, each with different obligations. The correct classification of an AI system is the starting point of every AI compliance assessment.

Unacceptable risk (Art. 5 of the EU AI Act). These AI practices are prohibited. They include social scoring by public authorities, manipulative or exploitative techniques, real-time remote biometric identification in public spaces (with narrowly defined exceptions for law enforcement), emotion recognition in the workplace and in educational institutions, and the untargeted scraping of facial images for facial-recognition databases. The prohibitions have applied since 2 February 2025.

High risk (Art. 6 et seq. of the EU AI Act). High-risk AI systems are subject to the most comprehensive obligations. Two categories are covered: first, AI systems used as a safety component in a product under Annex I (medical devices, machinery, toys, lifts, radio equipment and others); second, stand-alone AI systems in the areas listed in Annex III (biometric identification, critical infrastructure, education, employment and recruitment, access to essential private and public services such as credit and insurance, law enforcement, migration and border control, justice and democratic processes).

Limited risk (Art. 50 of the EU AI Act). AI systems that interact with natural persons, generative systems, emotion-recognition systems and deepfakes are subject to specific transparency obligations. The end user must be able to recognise that they are interacting with an AI, or that content has been synthetically generated or manipulated.

Minimal risk. All other AI systems are not subject to any specific EU AI Act obligations. Spam filters, AI-assisted image editing or classic recommendation algorithms typically fall into this category. Data protection obligations nevertheless remain unaffected.

Classification is made on the basis of the specific intended purpose. A language model is not high-risk per se; where it is used for the automated pre-selection of job applications, however, it falls under Annex III No. 4 into the high-risk area.

Prohibited AI practices under Art. 5 of the EU AI Act

The AI practices listed in Art. 5 of the EU AI Act have been prohibited Union-wide since 2 February 2025. Providers and deployers must discontinue the practices; infringements may be sanctioned with up to EUR 35 million or 7 percent of global annual turnover (Art. 99(3) of the EU AI Act).

Manipulative and exploitative techniques (Art. 5(1)(a) and (b) of the EU AI Act). Prohibited are AI systems that deploy subliminal techniques or deliberately manipulative or deceptive methods in order to materially influence a person's behaviour and thereby cause significant harm. Likewise prohibited is the exploitation of the vulnerabilities of certain groups of persons on grounds of age, disability or social and economic situation.

Social scoring (Art. 5(1)(c) of the EU AI Act). AI systems that evaluate and classify natural persons or groups of persons on the basis of their social behaviour or predicted personal characteristics are prohibited where the resulting score leads to detrimental or unfavourable treatment in contexts unrelated to the original collection context, or where it is disproportionate.

Profile-based predictive policing (Art. 5(1)(d) of the EU AI Act). Prohibited is the AI-assisted prediction of the likelihood of a criminal offence by a natural person, in so far as it is based solely on profiling or on the assessment of personality traits.

Untargeted facial-image scraping (Art. 5(1)(e) of the EU AI Act). The untargeted scraping of facial images from the internet or from CCTV footage to expand or build facial-recognition databases is prohibited.

Emotion recognition in the workplace and in education (Art. 5(1)(f) of the EU AI Act). AI systems to detect emotions in the areas of the workplace and educational institutions are prohibited, with narrowly defined exceptions for medical and safety-related purposes.

Biometric categorisation of sensitive characteristics (Art. 5(1)(g) of the EU AI Act). Biometric systems that categorise persons on the basis of sensitive characteristics such as race, political opinion, trade union membership, religious belief, sex life or sexual orientation are prohibited.

Real-time remote identification in public spaces (Art. 5(1)(h) of the EU AI Act). Real-time remote biometric identification in publicly accessible spaces by law-enforcement authorities is prohibited in principle; narrowly defined exceptions subject to judicial authorisation exist for the search for victims of serious crimes, the prevention of terrorist attacks and the localisation of suspects of serious crimes.

For Swiss companies with a market presence in the EU or with EU users, this means: every HR software with an emotion-recognition function (such as stress detection in video interviews), every customer scoring beyond the original collection context, and every biometric filtering system based on sensitive characteristics must be assessed against Art. 5 of the EU AI Act.

High-risk AI systems, obligations under Art. 6 et seq. of the EU AI Act

High-risk AI systems are subject to the most comprehensive catalogue of obligations under the EU AI Act. The obligations are addressed primarily to providers (Art. 16 of the EU AI Act), and in part also to deployers (Art. 26 of the EU AI Act). The applicability of the high-risk obligations begins on 2 August 2026.

Risk management system (Art. 9 of the EU AI Act). A documented risk management process must be established across the entire lifecycle of the system: identification and analysis of foreseeable risks, assessment of the risks under intended use and reasonably foreseeable misuse, adoption of appropriate measures, testing.

Data governance (Art. 10 of the EU AI Act). Training, validation and testing data must be relevant, representative and, as far as possible, free of errors and complete. Data governance practices encompass data collection, data preparation, assumptions about the data, availability, quantity and suitability of the data sets, as well as the examination for possible bias.

Technical documentation (Art. 11 in conjunction with Annex IV of the EU AI Act). Before placing the system on the market, detailed technical documentation must be drawn up and kept up to date. Minimum content under Annex IV: general description, description of the elements and development processes, information on monitoring, functioning and control, risk management system, described changes, list of the harmonised standards applied, EU declaration of conformity.

Record-keeping / logging (Art. 12 of the EU AI Act). High-risk AI systems must technically enable the automatic recording of events (logs) during their operation.

Transparency and provision of information to deployers (Art. 13 of the EU AI Act). The systems must be designed so that deployers can appropriately interpret and use the outputs. Instructions for use with mandatory content must be provided.

Human oversight (Art. 14 of the EU AI Act). During use, effective oversight by natural persons must be possible, with the ability to review the output, halt operation or override the results.

Accuracy, robustness, cybersecurity (Art. 15 of the EU AI Act). High-risk systems must be designed so that they achieve an appropriate level of accuracy, robustness and cybersecurity and function stably across the entire lifecycle.

Conformity assessment and CE marking (Art. 43, 48 of the EU AI Act). Before placing on the market, a conformity assessment procedure must be carried out and the CE marking affixed. Registration in the EU database for high-risk AI systems under Art. 71 of the EU AI Act.

Deployer obligations (Art. 26 of the EU AI Act). Deployers must take technical and organisational measures to ensure use in accordance with the instructions for use, to guarantee human oversight, to control the input data and to monitor the system. Certain deployers must additionally carry out an AI impact assessment under Art. 27 of the EU AI Act.

General-Purpose AI (GPAI) and foundation models, obligations from 2 August 2025

General-Purpose AI Models (GPAI) are AI models with a general purpose that can competently perform a broad spectrum of distinct tasks and can be integrated into a multitude of downstream systems. The obligations applicable to them have applied since 2 August 2025.

Definition (Art. 3 No. 63 of the EU AI Act). Covered are models such as large language models (the GPT family, Claude, Gemini, LLaMA), large image models and multimodal models, which are typically trained on large volumes of data, use self-supervision techniques and display generality.

Obligations of all GPAI providers (Art. 53 of the EU AI Act). Drawing up and updating technical model documentation, provision of information to downstream providers, implementation of a policy to comply with copyright law, and publication of a sufficiently detailed summary of the content used for training.

Obligations for GPAI with systemic risk (Art. 51 et seq. of the EU AI Act). Models whose cumulative training compute exceeds 10^25 FLOPs are presumed, rebuttably, to pose a systemic risk. Additional obligations: model evaluation with standardised protocols including adversarial testing, assessment and mitigation of systemic risks at EU level, recording and reporting of serious incidents, ensuring an appropriate level of cybersecurity.

Open-source exemption. For free and open-source GPAI models, parts of the obligations are reduced, provided there are no systemic risks and the model is made available with transparent parameters (Art. 53(2) of the EU AI Act).

Significance for deployers. Even those who merely integrate a GPAI model (for example via API into an internal RAG stack) should request the provider information and document it as part of their own risk assessment. Anyone who substantially re-trains or adapts a GPAI model may themselves become a provider within the meaning of the EU AI Act, with all the consequent obligations.

Transparency obligations, when must you inform users? (Art. 50 of the EU AI Act)

Art. 50 of the EU AI Act defines transparency obligations that apply to certain AI systems irrespective of the risk class. They apply among other things to chatbots, generative systems and deepfakes and are a focal point of AI compliance for SMEs that integrate external models.

Chatbot transparency (Art. 50(1) of the EU AI Act). Providers of AI systems that interact with natural persons must ensure that the affected persons are informed that they are interacting with an AI system, unless this is obvious from the circumstances.

Marking of synthetic content (Art. 50(2) of the EU AI Act). Providers of generative AI systems must ensure that the outputs are marked in a machine-readable format and identifiable as artificially generated or manipulated. This concerns text, image, audio and video outputs.

Emotion recognition and biometric categorisation (Art. 50(3) of the EU AI Act). Deployers must inform the natural persons exposed to such systems of their operation, subject to the prohibitions under Art. 5 of the EU AI Act.

Deepfakes (Art. 50(4) of the EU AI Act). Deployers of AI systems that generate or manipulate deepfakes must disclose that the content has been artificially generated or manipulated. Exceptions exist for evidently artistic, satirical or fictional works; the disclosure may be made in an appropriate manner that does not impair the enjoyment of the work.

Content in the public interest (Art. 50(4) of the EU AI Act). AI-generated or manipulated text published to inform the public on matters of public interest must be marked as artificially generated.

Form of the information. Clear, conspicuous and at the latest at the time of the first interaction. Hidden notices in the terms and conditions or at the foot of a web page are not sufficient. We recommend a combined solution: a prominent notice in the UI plus detailed information in the privacy or AI notice.

Data protection and AI, GDPR Art. 22 + FADP for automated decisions

In many cases AI systems process personal data and are therefore subject, in addition to the EU AI Act, to data protection law. The overlap is considerable; an isolated assessment is not possible.

Legal basis (Art. 6 GDPR). Every processing of personal data in AI systems requires a legal basis, typically legitimate interest (Art. 6(1)(f) GDPR) with a balancing test, or consent. For training data obtained from the internet (web scraping) the legal basis must be examined with particular care; the European supervisory authorities pursue a restrictive line.

Special categories (Art. 9 GDPR). Where the AI system processes health data, biometric identification data or data on sexual orientation, Art. 9 GDPR applies, with markedly stricter conditions.

Automated individual decisions (Art. 22 GDPR). A decision based solely on automated processing which produces legal effects or similarly significantly affects the data subject is only permissible where it is necessary for the performance of a contract, authorised by law, or covered by explicit consent. In any event the data subject has the right to human intervention, to express their point of view and to contest the decision.

Swiss equivalent (Art. 21 FADP). The FADP requires, in the case of automated individual decisions with legal effect or significant impairment, the information of the data subject and the possibility to express a point of view. The provision is framed more narrowly than Art. 22 GDPR but does not contain a general prohibition.

DPIA (Art. 35 GDPR / Art. 22 FADP). When deploying new technologies, which AI practically always involves, as well as in the case of systematic evaluation or profiling with significant effect, a Data Protection Impact Assessment (DPIA) is mandatory. It must be interlinked in substance with the AI impact assessment under Art. 27 of the EU AI Act (see below), but conducted separately in legal terms.

Data minimisation and purpose limitation. Training on the largest possible volumes of data systematically conflicts with the principle of data minimisation (Art. 5(1)(c) GDPR). Approaches: synthetic data, pseudonymisation, differential privacy, federated learning.

For further detail on the data protection obligations, see our GDPR guide and the FADP guide.

ISO/IEC 42001:2023, the first management standard for AI systems

ISO/IEC 42001:2023, published on 18 December 2023, is the world's first management standard for Artificial Intelligence. It defines requirements for the establishment, operation, monitoring and improvement of an AI Management System (AIMS) and is designed as a certifiable standard following the Annex SL high-level structure.

Structure. ISO/IEC 42001:2023 follows the harmonised high-level structure (HLS) and is thereby interoperable with ISO/IEC 27001 (information security), ISO 9001 (quality) and ISO/IEC 27701 (privacy). The normative chapters 4 to 10 (context, leadership, planning, support, operation, performance evaluation, improvement) formally correspond to the structure of ISO/IEC 27001. Annex A contains reference controls for AI systems.

Core content. The standard addresses AI-specific risks and obligations along the lifecycle: definition of the AI policy, allocation of roles and responsibilities (in particular AI Ethics Officer / AI Governance), risk management for AI systems with a focus on fairness, explainability, robustness and security, AI Impact Assessment (clause 4.3 / 6.1.4), data governance, lifecycle management of AI systems, supplier management for procured AI components.

Relationship to the EU AI Act. ISO/IEC 42001 is not a substitute for the EU AI Act and is not a harmonised standard within the meaning of Art. 40 of the EU AI Act (as of May 2026). It is, however, a valuable implementation framework: anyone operating an AIMS in accordance with ISO/IEC 42001 methodically covers central EU AI Act obligations, in particular risk management (Art. 9 of the EU AI Act), data governance (Art. 10 of the EU AI Act), technical documentation (Art. 11 of the EU AI Act) and human oversight (Art. 14 of the EU AI Act).

Relationship to ISO/IEC 27001. The two standards complement one another. ISO/IEC 27001 protects information generically by confidentiality, integrity and availability; ISO/IEC 42001 adds AI-specific aspects such as model robustness, bias and explainability. Anyone who already operates an ISMS in accordance with ISO/IEC 27001:2022 can build the AIMS in an integrated manner, the HLS synergies are considerable. For further detail on the ISMS, see our ISO 27001 guide.

Certifiability. An accredited third-party certification under ISO/IEC 42001 is possible. Accredited certification bodies are currently building up their accreditation under ISO/IEC 17021-1; in the DACH region market readiness is increasing.

AI impact assessment (Fundamental Rights Impact Assessment, Art. 27 of the EU AI Act)

The AI impact assessment under Art. 27 of the EU AI Act (Fundamental Rights Impact Assessment, FRIA) is an ex-ante assessment of the effects of a high-risk AI system on the fundamental rights of natural persons. It is to be distinguished from the GDPR DPIA / FADP DPIA but can be interlinked organisationally.

Who is obliged (Art. 27(1) of the EU AI Act). Obliged are deployers of certain high-risk AI systems: bodies governed by public law, private entities providing public services, as well as deployers of high-risk systems in the areas of the creditworthiness and credit scoring of natural persons and of life and health insurance risk assessment and pricing.

Content of the FRIA (Art. 27(1) of the EU AI Act). Description of the processes in which the system is used; the period and frequency of use; the categories of affected natural persons and groups of persons; the specific risks to the fundamental rights of those persons; description of the human oversight; risk-mitigation measures including internal governance and complaint mechanisms.

Relationship to the DPIA. Where aspects are already covered within the DPIA under Art. 35 GDPR, the FRIA may build on it in a complementary manner (Art. 27(4) of the EU AI Act). The FRIA, however, has a broader fundamental-rights focus, encompassing not only data protection but also the prohibition of discrimination, protection of occupational freedom, freedom of assembly and further fundamental rights of the EU Charter of Fundamental Rights.

Documentation and notification. The results must be kept on a documented basis. Where a high-risk system is newly deployed, the national market surveillance authority must be informed (Art. 27(3) of the EU AI Act).

Swiss perspective. Swiss deployers whose high-risk AI system generates output in the EU are likewise obliged to conduct a FRIA in the corresponding constellations. A free-standing Swiss FRIA obligation does not exist as of May 2026; depending on the individual case, however, the AI impact assessment is also to be classified under Swiss law as an appropriate risk-mitigation measure.

Swiss legal position, as of 2026 (CoE AI Convention, no AI statute, Federal Council guidelines)

As of May 2026, Switzerland has no AI-specific federal statute. AI systems are regulated through the existing cross-cutting law. This must not be misunderstood as a regulatory free zone: in many constellations Swiss companies are captured through the extraterritorial effect of the EU AI Act or through sector-specific regulation.

Council of Europe AI Convention. Switzerland signed the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law on 5 September 2024 (together with the EU, the United Kingdom, the United States, Israel and further states). The convention is the first treaty binding under international law on AI. The national implementation into Swiss law is being prepared by the Federal Council; a draft statute has been announced for the legislative period.

Federal Council guidelines. On 22 November 2023 the Federal Council adopted guidelines for the use of AI in the federal administration and on 12 February 2025 published a report on the regulation of AI in Switzerland. The report sketches a sectoral approach focused on existing enactments (FADP, product liability, sector-specific supervisory law) and a restrained horizontal regulation. The definitive direction remains, depending on the individual case, within the political process.

Applicable cross-cutting law. Personal data in AI systems is subject to the FADP, in particular Art. 8 FADP (data security), Art. 19 FADP (information duty), Art. 21 FADP (objection to automated individual decisions), Art. 22 FADP (DPIA). Contractual and non-contractual liability follow the Code of Obligations, in particular Art. 41 CO (tort) and the Product Liability Act.

Sector-specific regulation. FINMA circulars (in particular 2023/1 Operational Risks and Resilience) apply to regulated financial service providers, including for AI applications. In the healthcare sector, the Therapeutic Products Act and the Medical Devices Ordinance (MedDO) apply to AI-based medical devices, with a de facto link to the EU medical device legal framework (MDR). In the public sector there are cantonal rules on algorithmic decision-making.

SIDD position. We recommend that Swiss SMEs build their AI compliance on two pillars: cross-cutting legal conformity under Swiss law (FADP, CO, sector-specific) and, wherever there is an EU nexus, proactive EU AI Act compliance, since adaptation after market entry is significantly more expensive. See current supervisory authority practice (FDPIC, NCSC, FINMA) for sector-specific concretisations.

Sanctions under the EU AI Act (Art. 99 of the EU AI Act, up to EUR 35m or 7% of annual turnover)

The EU AI Act introduces a sanction system that exceeds the GDPR in its magnitude. Art. 99 of the EU AI Act defines three fine categories, staggered according to the severity of the infringement. Imposition is carried out by the market surveillance authorities of the Member States; for GPAI infringements the Commission's AI Office is competent.

Infringements of Art. 5 of the EU AI Act (prohibited practices). Up to EUR 35 million or 7 percent of the total worldwide annual turnover of the preceding financial year, whichever is higher (Art. 99(3) of the EU AI Act).

Infringements of provider, deployer and other obligations. Up to EUR 15 million or 3 percent of global annual turnover (Art. 99(4) of the EU AI Act). Covered in particular are infringements of the high-risk obligations of Art. 16 et seq., 26 et seq. of the EU AI Act, conformity assessment obligations and registration obligations.

Incorrect, incomplete or misleading information to authorities. Up to EUR 7.5 million or 1 percent of global annual turnover (Art. 99(5) of the EU AI Act).

SMEs and start-ups (Art. 99(6) of the EU AI Act). For small and medium-sized enterprises and start-ups, the lower of the two amounts applies in each case, a relevant privilege compared with the GDPR sanction regime.

Procedure. The Member States designate the competent market surveillance authorities. The assessment factors in Art. 99(7) of the EU AI Act largely correspond to Art. 83(2) GDPR: nature, gravity and duration of the infringement, intent or negligence, measures to mitigate harm, prior history, cooperation with the authority.

Sanctions against GPAI providers (Art. 101 of the EU AI Act). For GPAI providers, Art. 101 of the EU AI Act provides for separate fines of up to EUR 15 million or 3 percent of global annual turnover, imposed by the European Commission.

Swiss companies. Through the extraterritorial effect of Art. 2 of the EU AI Act, Swiss companies can be captured directly by EU sanctions. Enforcement takes place via the Member States or the AI Office; depending on the individual case, market-access prohibitions (a ban on placing on the market under Art. 79 et seq. of the EU AI Act) are also possible, often economically more severe than the fine itself.

AI risks from an InfoSec perspective (prompt injection, model extraction, data poisoning, OWASP LLM Top 10)

AI systems, in particular large language models (LLMs), bring with them InfoSec risk classes that are only partly reflected in classic Annex A catalogues. The OWASP Top 10 for LLM Applications (OWASP Foundation, latest version 2025) is the established reference catalogue and complements the ISO/IEC 27001 controls for AI workloads.

LLM01, prompt injection. Malicious inputs override the model's system instructions and cause unauthorised actions (data exfiltration, tool calls, policy circumvention). Direct prompt injection is carried out by the user, indirect prompt injection through external content (documents, web pages, emails) that the model processes.

LLM02, sensitive information disclosure. Models reveal training or context data, such as personal data, trade secrets, credentials. The risk is particularly acute in RAG architectures with inadequate source control.

LLM03, supply chain. Pre-trained models, third-party adapters, plugins and data sets carry compromised components. Model hubs without proof of provenance are a growing entry point.

LLM04, data and model poisoning. Manipulation of the training, fine-tuning or embedding data to produce backdoors, bias or model failures.

LLM05, improper output handling. Model outputs are passed on unchecked to downstream systems (SQL, shell, HTML), classic injection vulnerabilities with an AI vector.

LLM06, excessive agency. Agentic LLM systems are granted overly broad tool and permission sets; the consequence: data exfiltration, unintended transactions.

LLM07, system prompt leakage. Disclosure of the system prompt, which often contains policy logic, keys or business-critical instructions.

LLM08, vector and embedding weaknesses. RAG-specific risks: embedding inversion, vector poisoning, inadequate access control over vector stores.

LLM09, misinformation. Hallucinations and excessive trust in model outputs, particularly critical in YMYL applications (medicine, law, finance).

LLM10, unbounded consumption. Resource exfiltration, model extraction and denial of wallet through abusively high request loads or cleverly crafted queries that reconstruct model IP.

Measures. Defence in depth: input and output filters, strict tool permissions, source control in RAG, continuous red-teaming, monitoring and anomaly detection. ISO/IEC 27001 Annex A provides the organisational anchoring, A.5.7 (threat intelligence), A.5.23 (cloud services), A.8.8 (vulnerability management), A.8.16 (monitoring), A.8.28 (secure coding). Penetration tests should explicitly cover AI-specific vectors (prompt injection, jailbreaking, model extraction).

AI compliance checklist for SMEs (10 steps)

The following checklist summarises the steps with which a Swiss SME builds resilient AI compliance, regardless of whether it develops its own AI systems or merely deploys third-party providers (ChatGPT, Microsoft Copilot, an internal RAG). It does not replace individual advice but serves as a structuring aid.

  1. Create an AI inventory. Record all AI systems in use: vendor, model, intended purpose, data flows, user groups, deployment context. Deliberately uncover shadow AI (privately used ChatGPT accounts, unapproved plugins).
  2. Carry out risk classification under the EU AI Act. Per system: unacceptable / high / limited / minimal. In the case of a high-risk classification, conduct a detailed assessment under Annex III of the EU AI Act.
  3. Check the prohibitions under Art. 5 of the EU AI Act. In particular emotion recognition in the workplace, biometric categorisation of sensitive characteristics, untargeted facial-image scraping. Discontinue immediately if suspected.
  4. Conduct a DPIA (Art. 35 GDPR / Art. 22 FADP). For every system involving the processing of personal data. For high-risk systems, additionally assess the need for an AI impact assessment under Art. 27 of the EU AI Act.
  5. Ensure transparency and information (Art. 50 of the EU AI Act). Chatbot and deepfake notices in the UI; an AI clause in the privacy notice; an internal AI usage policy for employees.
  6. Review data processing agreements (DPAs). With every AI provider that processes personal data. Document the data location, use for model training (opt-out), third-country transfer and SCCs. For further detail on international transfers, see the FADP guide and the GDPR guide.
  7. Define AI governance and roles. Anchor responsibility for AI at executive management level (AI Officer, often in personal union with the DPO / CISO). A use-case approval process with defined risk criteria.
  8. Establish awareness and training. AI literacy obligation under Art. 4 of the EU AI Act since 2 February 2025: providers and deployers must ensure a sufficient level of AI competence among their staff. An onboarding module plus role-specific deepening.
  9. Implement technical measures. Input and output filters, access control, monitoring, logging (Art. 12 of the EU AI Act), secret management. The OWASP LLM Top 10 as a reference, ISO/IEC 27001 Annex A as the organisational framework.
  10. Assess an AIMS under ISO/IEC 42001:2023. For regulated sectors, AI manufacturers and companies with a high level of maturity: build the AIMS in an integrated manner with the existing ISMS under ISO 27001, see current supervisory authority practice for sector-specific concretisations.

Frequently asked questions on AI compliance (FAQ)

When does the EU AI Act apply in Switzerland? The EU AI Act has been in force since 1 August 2024 and applies on a staggered basis (prohibitions from 2 February 2025, GPAI from 2 August 2025, high-risk from 2 August 2026). Switzerland is not a member of the EU, yet Swiss companies are captured extraterritorially through Art. 2 of the EU AI Act, in particular where they place AI systems on the EU market or where the output of their system is used in the EU.

Do I need an AI impact assessment if I only use ChatGPT? It depends on the individual case. A FRIA under Art. 27 of the EU AI Act is only mandatory for certain high-risk deployers. A DPIA under Art. 35 GDPR or Art. 22 FADP, however, is practically always indicated as soon as personal data is processed, including when using cloud language models. In addition, the AI literacy obligation under Art. 4 of the EU AI Act must be observed.

What happens if I infringe Art. 5 of the EU AI Act? The prohibitions under Art. 5 of the EU AI Act have applied since 2 February 2025. Infringements may be sanctioned under Art. 99(3) of the EU AI Act with up to EUR 35 million or 7 percent of global annual turnover, whichever is higher. For SMEs the lower amount applies in each case.

Does ISO/IEC 42001 replace EU AI Act compliance? No. ISO/IEC 42001:2023 is a management standard and provides a methodical framework for AI governance. It is not, as of May 2026, a harmonised standard within the meaning of Art. 40 of the EU AI Act and does not trigger the presumption of conformity. Anyone operating an AIMS in accordance with ISO/IEC 42001 nevertheless methodically covers central obligations and considerably reduces the effort of EU AI Act implementation.

Who in the company is responsible for AI compliance? Overall responsibility lies with executive management. In practice, in many SMEs the role is assigned to the data protection officer or the CISO, frequently in personal union as AI Officer. For high-risk systems we recommend a dedicated committee comprising legal, IT security, data protection and the business function. ISO/IEC 42001 requires an explicit allocation of roles.

What distinguishes Art. 22 GDPR from Art. 21 FADP? Art. 22 GDPR prohibits, in principle, decisions based solely on automated processing which produce legal effects, with narrowly defined exceptions. Art. 21 FADP contains no prohibition but requires the information of the data subject and the possibility to express a point of view. Anyone subject to both regimes must align with the stricter GDPR.

How do I protect myself against prompt injection? Defence in depth: input filters (classification for malicious inputs), output filters (sensitive-information detection), strict tool permissions (least privilege for agentic systems), source control in RAG (trust tiers for external content), continuous red-teaming and monitoring. Penetration tests should explicitly cover prompt-injection vectors. Reference: OWASP Top 10 for LLM Applications.

Does the EU AI Act also apply to open-source models? Partly. For free and open-source AI models the obligations are reduced, provided there are no systemic risks and the model is made available with transparent parameters (Art. 2(12) and Art. 53(2) of the EU AI Act). The prohibitions under Art. 5 of the EU AI Act and the obligations for GPAI with systemic risk nevertheless also apply to open-source models.

How SIDD supports you on AI compliance

SIDD is the data protection and InfoSec brand of Priverion GmbH (Baar/ZG), founded in 2017. We support Swiss SMEs and internationally active groups on AI compliance across all relevant regimes: EU AI Act risk classification, AI impact assessment under Art. 27 of the EU AI Act, DPIA for AI workloads, AI usage policies and awareness, as well as the establishment of an AI Management System in accordance with ISO/IEC 42001:2023 integrated with your existing ISMS under ISO/IEC 27001. For personal data in AI systems we coordinate your mandate as Swiss Data Protection Adviser and EU Data Protection Officer. For further detail we refer to our guides on the DSG / FADP, on the GDPR and on ISO/IEC 27001. We keep advice and audit strictly separate.

Need help putting this into practice? SIDD operates the matching service.
See service →