# EU AI Act, The Guide for Swiss Companies

> The EU AI Act for Swiss companies: extraterritorial reach, risk classes, GPAI, obligations of providers and deployers, links to the FADP and GDPR.

- Source: https://www.sidd.swiss/en/insights/eu-ai-act-switzerland-guide/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Dr. Dr. Nino Jibuti
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

**Regulation (EU) 2024/1689**, the EU AI Act, has been in force since 1 August 2024. It is the world's first comprehensive horizontal AI regulation and affects Swiss companies far more often than initially assumed. Extraterritoriality under Art. 2 captures any provider, importer, distributor or deployer of an AI system whose output is used in the Union, regardless of the provider's domicile. In practice this means that every Swiss SaaS company with EU customers must check whether it is in scope as a provider or deployer.

This guide consolidates the most important requirements for Swiss companies. It covers:

- Extraterritoriality and Swiss exposure
- The risk pyramid (prohibited, high-risk, transparency and minimal-risk systems)
- The GPAI tier for general-purpose AI models
- The phased timeline 2025–2027
- Obligations for providers and deployers
- Interaction with DSG, GDPR and sectoral Swiss law

We reference regulation articles as ‘Art. X AI Act’. Where duties overlap with the GDPR, we mark the interface.

## Extraterritoriality and Swiss exposure

Under **Art. 2(1)** the AI Act applies in four constellations:

1. Providers placing an AI system or GPAI model on the Union market or putting it into service, regardless of domicile.
2. Deployers (users) established or located in the Union.
3. Providers and deployers in a third country whose AI output is used in the Union.
4. Importers, distributors, authorised representatives, manufacturers (in product packages) and affected persons located in the Union.

For a Swiss SaaS company with German customers that, for example, offers an AI-supported CV screener, the following applies:

- the full provider obligations (the system is high-risk under Annex III no. 4),
- the duty to appoint an **authorised representative in the Union** under Art. 22, unless an importer assumes the role,
- registration in the EU database under Art. 49 (for high-risk),
- CE marking under Art. 48 and the conformity assessment under Art. 43.

Swiss providers who want to stay fully out of the EU must put in place clean contractual geofencing and exclusion clauses, otherwise Art. 2(1)(c) catches them through the output.

## The risk pyramid

The AI Act allocates each system to one of four risk tiers:

**1. Prohibited practices (Art. 5):** social scoring, manipulative subliminal techniques, real-time biometric identification in public spaces (with narrow exceptions), emotion recognition in the workplace and education, untargeted scraping of facial images from the internet, predictive policing based purely on profiling, classification of natural persons based on sensitive attributes. These prohibitions apply since **2 February 2025**.

**2. High-risk systems (Art. 6 in conjunction with Annex I and III):** AI in regulated products (Annex I: medical devices, machinery, toys etc.) and AI in eight explicit areas (Annex III): biometrics, critical infrastructure, education, employment, essential private and public services (including credit scoring and benefits), law enforcement, migration/asylum/border control, administration of justice and democratic processes.

**3. Transparency duties (Art. 50):** chatbots must identify themselves, AI-generated images/video/audio must be labelled (with exceptions, e.g. artistic works), deepfakes need clear marking, emotion recognition and biometric systems must inform affected persons.

**4. Minimal risk:** everything else, no mandatory duties, but voluntary codes of conduct are foreseen.

## GPAI, general-purpose AI models

Articles 51 ff. AI Act introduce a stand-alone regime for **general-purpose AI models**. This captures foundation models such as GPT-4/5, Claude, Gemini, Mistral Large or Llama, models that can be used for a wide variety of downstream tasks. The duties apply since **2 August 2025**.

Baseline duties for all GPAI providers (Art. 53):

- Technical documentation
- Information for downstream providers
- Copyright policy
- Summary of training data using the AI Office template

Heightened duties apply for **GPAI models with systemic risk** under Art. 51, one indicator is training compute above 10^25 FLOPs. These models additionally undergo model evaluation, adversarial testing, risk tracking, cybersecurity controls and a serious-incident notification duty. For Swiss companies that *use* such models (deployers), GPAI is only indirectly relevant, the obligations sit with the provider. However, anyone building their own models or fine-tuning open-source models and distributing them under their own name can themselves become a GPAI provider.

## Phased timeline 2025–2027

The AI Act's applicability is phased, the overview of key deadlines is the most important roadmap input:

- **2 February 2025:** prohibitions under Art. 5 take effect; general provisions and definitions (Chapter I + II) apply; the AI literacy duty under Art. 4 applies to providers and deployers.
- **2 August 2025:** GPAI duties (Chapter V); notification and governance structures; sanctions regime (Art. 99–101); national competent authorities must be designated.
- **2 August 2026:** main applicability, all high-risk duties under Annex III; transparency duties under Art. 50; full conformity assessment and market surveillance.
- **2 August 2027:** high-risk duties for Annex I systems (AI in regulated products such as medical devices, machinery, toys).

The **AI literacy duty (Art. 4)** is the most underestimated deadline: providers and deployers must give their staff and contracted personnel an adequate AI understanding. For SMEs that means a written training plan, documented attendance and role-based depth. Without that evidence, supervisors will presume fault.

## Provider and deployer obligations

For high-risk systems, the AI Act strictly distinguishes between **provider** (who develops a system or markets it under their own name) and **deployer** (who uses it in the course of their professional activity). Provider duties (Art. 8–15):

- Risk management system across the full lifecycle
- Data governance (training, validation, test data)
- Technical documentation (Annex IV)
- Record-keeping (logging)
- Transparency and information to deployers
- Human oversight (Art. 14)
- Accuracy, robustness, cybersecurity (Art. 15)
- Quality management system (Art. 17)
- Conformity assessment, CE marking, EU declaration of conformity
- Registration in the EU database (Art. 49)
- Post-market monitoring (Art. 72)

Deployer duties (Art. 26 ff.):

- Use the system in accordance with the provider's instructions
- Implement human oversight
- Input data appropriate to the intended purpose
- Retain logs (≥ 6 months)
- Inform affected persons where relevant
- For personal-data processing: DPIA (Art. 26(9) referring to Art. 35 GDPR)
- For employment contexts: inform and where applicable consult worker representatives

Fines up to CHF 35 million or 7% of global group turnover (Art. 99), the highest tier in EU law.

## Interaction with DSG, GDPR and Swiss sectoral law

Swiss companies that use AI with personal-data exposure are subject in parallel to at least three regimes:

**DSG:** Art. 21 DSG governs automated individual decisions and gives data subjects a right to human review. Art. 25 DSG grants a right of access to the underlying logic. A DPIA under Art. 22 DSG is mandatory for high-risk processing (AI typically qualifies). The FDPIC published AI-specific guidance in 2023 and 2024, among other things, this clarifies that the mere existence of an AI system without explainable logic is in many cases unlawful.

**GDPR:** Art. 22 GDPR (parallel to Art. 21 DSG), Art. 35 GDPR (DPIA), Art. 5 (data minimisation, challenging with large training sets), Art. 6 (legal basis for training and inference), Art. 9 (special categories) and third-country transfers under Chapter V when using US model vendors.

**Swiss sectoral law:** FINMA published Supervisory Communication 08/2023 on AI in the financial sector. Healthcare is shaped by HMG and KVG, employment by Art. 328b OR (personality rights). Switzerland itself opened consultation in 2024–2025 on a national AI act referencing the Council of Europe AI Convention; a final text is not expected before 2027.

In practical terms: anyone GDPR-compliant who builds an AI Act compliance stack is almost fully covered on the DSG side.

## How SIDD supports you

SIDD pragmatically guides Swiss companies through the AI Act introduction. We begin with an inventory of your AI use cases, allocate each to the risk pyramid, clarify the provider/deployer role and derive the concrete duty catalogue. Our Swiss data protection consultancy ([Swiss data protection advisor](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland)) covers the DSG interface; for the EU-side GDPR duty we provide a [GDPR DPO](https://www.sidd.swiss/en/services/data-protection-officer-eu) and, where required, an [EU representative under Art. 27 GDPR](https://www.sidd.swiss/en/services/eu-representative).

On the technical security side we embed the required risk management (Art. 9 AI Act) and cybersecurity requirements (Art. 15) into your [ISMS](https://www.sidd.swiss/en/services/iso-27001-isms) and stress model integrity with targeted [penetration tests](https://www.sidd.swiss/en/services/penetration-test). Awareness and AI literacy under Art. 4 come through our [workshops](https://www.sidd.swiss/en/services/it-security-workshop-sme). Arrange a first baseline via the [contact form](https://www.sidd.swiss/en/contact) or request our [offer](https://www.sidd.swiss/en/quote) for a full AI Act implementation package.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
