# EU AI Act, Phases, Obligations, Deadlines for Swiss Companies

> Which EU AI Act obligations apply from when: prohibitions, AI literacy, GPAI models and high-risk systems, and what Swiss companies should do now.

- Source: https://www.sidd.swiss/en/insights/eu-ai-act-phases-deadlines/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Dr. Dr. Nino Jibuti
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

Regulation (EU) 2024/1689, the EU AI Act, entered into force on 1 August 2024, but its obligations apply in five staggered waves between February 2025 and August 2027. Swiss companies with EU exposure therefore do not face a big-bang date but a roadmap that requires distinct preparation for each wave. Anyone unaware of the phasing either overlooks active prohibitions that have been enforceable since February 2025, or misses preparation for conformity assessments that kick in only in August 2026 or August 2027.

This article provides the operational view of the phases:

- Wave 1 (02/2025): Prohibited practices under Art. 5 and the AI literacy duty under Art. 4
- Wave 2 (08/2025): Obligations for General-Purpose AI models (GPAI) under Chapter V
- Wave 3 (08/2026): High-risk systems under Annex III and transparency duties Art. 50
- Wave 4 (08/2027): High-risk systems under Annex I (product safety)
- Sandbox provisions, Codes of Practice and national governance structures
- What Swiss companies need to do now in concrete terms

The Swiss link is not academic: Art. 2(1)(c) AI Act pulls third-country providers and deployers into scope where the output of their AI system is used in the Union. A Swiss SaaS firm supplying an AI-powered HR tool to a German GmbH falls directly under the AI Act, independent of any Federal Council decision on national AI regulation.

## Wave 1, February 2025: prohibitions and AI literacy

Since 2 February 2025 the prohibitions in Art. 5 have been directly applicable and can be sanctioned with fines of up to EUR 35 million or 7 percent of global annual turnover (Art. 99(3)). Prohibited are, among others, subliminal manipulation techniques, exploitation of vulnerabilities of specific groups, social scoring by public bodies, predictive policing based purely on profiling, untargeted scraping of facial images from the internet, emotion recognition in the workplace and in educational institutions, and biometric categorisation on sensitive attributes. The Commission published supplementary guidelines (C(2025) 884 final) on Art. 5 on 4 February 2025, closing several interpretation questions.

In parallel, Art. 4 requires providers and deployers to ensure that every person acting on the organisation's behalf when handling AI systems has a sufficient level of "AI literacy". This duty is low-threshold but enforceable: personnel files and training records must show that relevant staff have been trained. Swiss organisations using ChatGPT, Copilot, Claude or other generative tools need, from Wave 1 onwards, a documented internal training programme with attendance evidence.

## Wave 2, August 2025: GPAI and Codes of Practice

Since 2 August 2025, the obligations for providers of General-Purpose AI models under Chapter V (Art. 51–55) apply. Every GPAI provider, which covers foundation models and similar, must make technical documentation available to downstream providers, provide transparency on training data, comply with copyright, and put in place a policy to respect EU copyright law. For GPAI with "systemic risk" (initial threshold 10²⁵ FLOPs of training compute), additional duties apply on model evaluations, adversarial testing, incident reporting and cybersecurity (Art. 55).

The General-Purpose AI Code of Practice, moderated by the European Commission and the AI Office and finalised in July 2025, operationalises these duties. Providers who sign it benefit from a presumption of conformity. Swiss GPAI providers, when marketing in the EU, should at minimum use the Code as a reference for their compliance architecture, even without formal signature. For downstream Swiss organisations, it is relevant whether their GPAI supplier (OpenAI, Anthropic, Google, Mistral, Meta, xAI) has signed the Code, the related transparency reports substantially ease their own compliance evidence.

## Wave 3, August 2026: high-risk systems under Annex III

On 2 August 2026 the main body of the AI Act becomes applicable, in particular the obligations for high-risk systems under Annex III. Annex III lists eight use-case categories: biometrics (where not prohibited), critical infrastructure, education and vocational training, employment and HR, access to essential services (including credit scoring), law enforcement, migration and border control, and justice and democratic processes. A typical Swiss SME example: an automated candidate screening tool falls under Annex III no. 4(a) and is high-risk, regardless of whether the provider sits in the EU or in Switzerland.

Concrete obligations for high-risk AI providers: risk management system (Art. 9), data governance (Art. 10), technical documentation (Art. 11, Annex IV), logging (Art. 12), transparency and user instructions (Art. 13), human oversight (Art. 14), accuracy/robustness/cybersecurity (Art. 15), quality management system (Art. 17), conformity assessment and CE marking (Art. 43, 48), registration in the EU database (Art. 49), post-market monitoring (Art. 72) and incident reporting (Art. 73). Deployers have separate duties under Art. 26, including a fundamental rights impact assessment for certain deployers under Art. 27.

## Wave 4, August 2027: Annex I high-risk

On 2 August 2027, the obligations for high-risk AI embedded as a safety component in regulated products (Annex I) become applicable. Annex I lists twenty EU harmonisation acts, including the Machinery Regulation 2023/1230, the Medical Devices Regulation 2017/745, the In-Vitro Diagnostics Regulation 2017/746, the Toys Directive 2009/48/EC, and sector-specific rules for aviation, maritime, road vehicles and rail. A Swiss medical device manufacturer exporting an MDR Class IIa device with an AI component to the EU must demonstrate the MDR conformity assessment and the AI Act requirements in an integrated fashion.

The longer transition for Annex I recognises that existing conformity assessment regimes have to be adapted first. Swiss organisations should not treat this deadline as a pause but as a window to integrate AI requirements into the MDR, MR or UNECE processes that are already running. Anyone keeping two separate conformity files in 2027 has lost.

## Sandboxes, national governance and enforcement

Art. 57 obliges every Member State to establish at least one regulatory AI sandbox by 2 August 2026. The sandbox allows AI providers to test their systems under supervision of the competent authority without immediate regulatory consequences. SMEs and start-ups receive priority and free access (Art. 62). Of relevance for Swiss providers: under Art. 57(11), third-country providers may participate if they have an EU authorised representative.

At EU level, the AI Office established within the Commission in February 2024 coordinates application, in particular for GPAI. At national level, Member States designate market surveillance authorities and notifying bodies. Germany designated the Bundesnetzagentur, Austria KommAustria, France CNIL and ANSSI jointly. Cooperation with national data protection authorities (in Switzerland: FDPIC/EDÖB) is provided for under Art. 74(8) where high-risk AI processes personal data.

## What Swiss companies should do now

First: maintain an AI inventory. Which AI systems does the organisation use, as provider, deployer, importer, distributor? Each role triggers different obligations. Second: classify each AI, prohibited, high-risk (Annex I or III), subject to Art. 50 transparency duties (chatbots, deepfakes, emotion recognition), GPAI, or unproblematic. Third: assess whether the organisation falls under Art. 2(1)(c) because output is used in the EU, this is the rule, not the exception, for B2B SaaS, data analytics, ML-models-as-a-service.

Fourth: set up AI literacy training with training register and effectiveness evidence. Fifth: ask GPAI suppliers whether they have signed the Code of Practice and collect the transparency documentation. Sixth: for high-risk systems, prepare the ten core artefacts by Q2 2026 (risk management file, data governance plan, technical documentation per Annex IV, logging concept, user instructions, human oversight design, robustness tests, QMS documentation, conformity assessment plan, EU database registration draft). Anyone starting in July 2026 will not finish in time.

## How SIDD supports you

The AI Act is not a single compliance project but a series of staggered obligations that take effect over the next 18 months. SIDD structures preparation along the four waves: AI inventory and role classification, AI literacy curriculum, GPAI supplier analysis, high-risk conformity dossier. We tie the requirements into existing data protection and information security frameworks (GDPR, DSG, ISO 27001), so that you do not build parallel silos. For a Swiss deep dive, see [the EU AI Act guide for Switzerland](https://www.sidd.swiss/einblicke/eu-ai-act-schweiz-leitfaden) and [AI Act × DSG × GDPR](https://www.sidd.swiss/einblicke/ai-act-ndsg-dsgvo-schnittstelle). For a status assessment, reach us via the [contact form](https://www.sidd.swiss/en/contact); to request a concrete proposal for AI Act programme support, use our [quote form](https://www.sidd.swiss/en/quote). Our [GDPR DPO mandate offering](https://www.sidd.swiss/en/services/data-protection-officer-eu) complements an initial gap analysis.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
