EU AI Act after 2 August 2026: What It Means for Swiss Companies
Which EU AI Act duties become relevant in August 2026, what the AI Omnibus postponed and why companies and self-employed professionals in Switzerland can still fall within scope.
The EU AI Act enters into force on 2 August 2026. That is how the date is currently described in many articles, newsletters and presentations. Strictly speaking, it is wrong: the regulation already entered into force on 1 August 2024. Its provisions have been becoming applicable in stages ever since.
2 August 2026 nevertheless remains an important date. From then on, large parts of the regulation apply, supervisory authorities can enforce additional obligations and certain infringements can lead to fines. At the same time, the EU changed the timetable shortly before the deadline. The extensive requirements for high-risk systems were postponed by the AI Omnibus to December 2027 and August 2028 respectively.1
That does not necessarily make the situation simpler. Some obligations already apply, others begin on 2 August 2026 and still others much later. There is also the question of when an EU regulation affects a Swiss company or a self-employed developer in Kreuzlingen, Zurich or Basel at all.
The short answer is: more often than the national border might suggest.
This article puts the current deadlines in order, explains the roles and risk categories under the AI Act and translates the regulation into practical consequences for companies and self-employed professionals. The legal status described here is current as of 31 July 2026.
This article is a technical and organisational assessment, not individual legal advice. High-risk systems, sensitive personal data and concrete market entry into the EU should be assessed on their specific facts with qualified legal counsel.
The actual timetable
The AI Act is not a regulation that becomes fully applicable on one date. The EU deliberately introduced several stages. Following the AI Omnibus, the timetable now looks like this:
| Date | What applies from this date? |
|---|---|
| 1 August 2024 | The AI Act formally enters into force. |
| 2 February 2025 | Prohibitions on certain AI practices and the obligation to promote AI literacy become applicable. |
| 2 August 2025 | Rules for General-Purpose AI models, or GPAI models, begin to apply. Models already released before that date receive transitional periods. |
| 2 August 2026 | Further general provisions, transparency obligations, supervision, sanctions and numerous organisational provisions become applicable. The AI Office and national authorities can enforce the relevant duties. |
| 2 December 2026 | The new prohibition covering certain non-consensual sexualised deepfakes and comparable content becomes applicable. A limited transitional period for technical marking of older generative systems also ends. |
| 2 December 2027 | High-risk rules become applicable to the use cases listed in Annex III. These include certain applications in employment, education, creditworthiness assessment and access to essential services. |
| 2 August 2028 | High-risk rules become applicable to AI components in regulated products under Annex I, for example certain machinery, medical devices and safety components. |
2 August 2026 is therefore neither meaningless nor the one big starting signal. It is the next major expansion stage of a regulatory regime that is already running.2
For practical implementation, the important point is not to bundle every topic under the label “AI Act from August”. A publicly accessible chatbot can already trigger a clear transparency obligation from 2 August 2026. An internal candidate-ranking system may in future qualify as high-risk, while the complete high-risk requirements currently apply only from December 2027.
What the AI Act regulates
The AI Act follows a risk-based approach. Not every use of a language model automatically becomes a regulated high-risk project. The decisive factors include:
- the concrete function of the system,
- its intended purpose,
- the context in which it is used,
- the role of the organisation involved,
- the effects on people and their rights,
- and whether the system or its output reaches the EU market.
The familiar pyramid of “minimal”, “limited”, “high” and “unacceptable” risk is useful as an introduction, but it covers only part of the regulation. Separate rules apply in parallel to General-Purpose AI models, meaning foundation models such as large language or multimodal models that can be used for many different tasks.
For a typical company, four layers matter:
- Prohibited practices: Certain uses are fundamentally prohibited.
- Transparency obligations: In defined situations, people have to be able to recognise that they are interacting with an AI system or viewing synthetic content.
- High-risk systems: Certain sensitive purposes later trigger extensive requirements around risk management, data, documentation, monitoring and conformity.
- GPAI rules: Providers of general-purpose models have to meet obligations including technical documentation, information for downstream providers and copyright-related requirements. Models with systemic risk face additional duties.
A company merely using a standard service such as ChatGPT, Claude, Gemini, Microsoft Copilot or a translation service is normally not the provider of the underlying model. It may nevertheless be a deployer of a system built on top of that model or become a provider itself through adaptation, white-labelling or a changed intended purpose.
Roles matter more than company size
The AI Act distinguishes several actors along the value chain. The main ones are providers, deployers, importers and distributors.
Provider
Simplified, a provider is a party that develops an AI system or GPAI model, or has one developed, and places it on the market or puts it into service under its own name.
That can be a large model vendor. It can just as easily be a small software company that integrates an existing model into its own product and sells the result under its own brand.
A company that substantially modifies an existing system, rebrands it or changes its intended purpose in a way that creates a high-risk use can also assume provider obligations.3
Deployer
A deployer uses an AI system under its own authority in the course of professional or economic activity.
This does not apply only to corporations. A self-employed consultant, photographer, developer or writer can also be a deployer when using AI for paid work. Purely personal, non-professional use is generally outside that definition.4
Importers and distributors
Importers bring systems from a third country into the EU market. Distributors make them available within the supply chain. These roles are particularly relevant to Swiss software and product manufacturers selling through an EU partner, reseller or subsidiary.
Product manufacturers
Where AI is supplied as part of a regulated product, obligations applying to product manufacturers may also become relevant. Examples include machinery, medical devices, vehicles and other products with safety-related AI components.
The central question is therefore not whether a company is large enough to fall under the AI Act.
It is: Which role does the company have for each concrete system?
What becomes practically relevant on 2 August 2026
People must know when they are interacting with AI
A provider or deployer offering a chatbot, voice bot, avatar or agent that interacts directly with people generally has to inform them that they are interacting with an AI system. The information must be clear and understandable no later than the first interaction unless the AI nature is already obvious.5
A hidden sentence on a secondary privacy page is unlikely to be a useful implementation. A direct notice in the interface is more appropriate, for example:
You are communicating with an AI-assisted system. Answers can be incorrect and are not necessarily reviewed by a human.
The exact wording depends on context. A support chatbot needs a different explanation from a virtual sales adviser or an agent that books appointments independently.
For Swiss companies, the decisive issue is whether the service is offered to users in the EU or its output is used there. The location of the web server or the company’s registered office does not decide the issue on its own.
Generative output needs technical marking
Providers of generative AI systems have to ensure that synthetically generated or manipulated output can be recognised as such in a machine-readable format. This generally covers audio, images, video and text.
This technical marking obligation primarily addresses the provider of the generative system, not automatically every user. The idea is to provide robust markings or metadata that support later detection. The EU is working with standards and a code of practice for this purpose.
There are exceptions, including certain editing functions, machine-to-machine scenarios and closed industrial processes. There is no general B2B exemption. The exception is narrower and depends on the concrete technical use.6
For systems already placed on the market before 2 August 2026, a limited transitional period runs until 2 December 2026. It applies only to this technical marking requirement, not to all transparency obligations.7
Deepfakes require visible disclosure
A deployer publishing image, audio or video content that constitutes a deepfake has to disclose that the content has been artificially generated or manipulated.
A machine-readable marker hidden in the file is not enough for this obligation. The information has to be perceptible to the viewer. For artistic, satirical or fictional works, disclosure may be designed in a way that does not unreasonably impair the work.8
Not every image generated with Midjourney, Flux or a video model is automatically a deepfake. The concept generally involves content resembling real people, objects, places, entities or events in a way that could falsely appear authentic. An obviously stylised science-fiction image is different from a realistic video in which a real CEO appears to make a statement he never made.
This matters for marketing teams and self-employed content producers. Anyone creating a synthetic testimonial, manipulated product demonstration or realistic reconstruction of a person for a German client should not leave the disclosure question until the final video is exported.
AI-generated text on matters of public interest
A special rule covers AI-generated or manipulated text published for the purpose of informing the public about matters of public interest. Such text generally has to be disclosed as AI-generated or AI-manipulated.
The obligation does not apply where the content has undergone human review or editorial control and a natural or legal person takes editorial responsibility for publication.9
This is not a blanket labelling requirement for every text that involved AI. An automatically generated product description, internal email or linguistically edited project report is not automatically covered.
Conversely, for political, economic or social reporting, quickly skimming the raw output and clicking “Publish” is unlikely to qualify as meaningful editorial control. The exception requires genuine substantive review and editorial responsibility. According to the Commission’s interpretation, spelling or grammar correction alone is not enough.
For a blog like this one, that means a writer who reviews an AI draft for substance, checks sources, corrects false statements, rewrites passages and assumes editorial responsibility is not automatically subject to the disclosure duty. Fully automated publication of news articles without substantive review sits in a different category.
Emotion recognition and biometric categorisation
Anyone deploying an emotion-recognition or biometric-categorisation system has to inform affected people. Certain uses are additionally prohibited or classified as high-risk.
“Emotion AI” in particular is often marketed as a harmless extra feature for sales, call centres, video interviews or employee analytics. Legally, it belongs to the most sensitive areas. Emotion recognition in workplaces or educational institutions is generally prohibited unless a narrowly defined medical or safety exception applies.
Supervision and sanctions become operational
From 2 August 2026, another stage of regulatory enforcement begins. Depending on the subject, responsibility lies with the European AI Office and national market-surveillance authorities.
This ends the period in which many organisations could treat the AI Act mainly as a future project. Not every duty is fully applicable on that date, but transparency, AI literacy, prohibitions and GPAI rules are no longer merely preparatory topics.
What already applies: prohibitions and AI literacy
Prohibited practices
The AI Act’s prohibitions have applied since 2 February 2025. Simplified and non-exhaustively, they cover:
- certain manipulative or deceptive techniques that cause significant harm,
- exploitation of particular vulnerabilities,
- certain forms of social scoring,
- certain predictions of criminal behaviour based solely on profiling or personality traits,
- untargeted scraping of facial images from the internet or CCTV footage to build databases,
- certain biometric categorisations based on particularly sensitive characteristics,
- emotion recognition in workplaces and educational institutions, subject to narrow exceptions,
- and certain forms of real-time remote biometric identification in public spaces.
The AI Omnibus added another prohibited practice that becomes applicable on 2 December 2026. It concerns certain systems used to generate or manipulate non-consensual sexualised content and child sexual-abuse material.10
For an ordinary software project, the important consequence is not memorising a list. Organisations need an early screening step before an experiment becomes a production system. Some ideas are not “document later” cases; they are impermissible from the beginning.
AI literacy is not optional training
Since February 2025, providers and deployers have also had to take measures to promote the AI literacy of people working with AI systems on their behalf.
The AI Omnibus simplified the wording. It does not prescribe one specific competence level set by authorities. The obligation nevertheless remains. Measures have to be appropriate to the role, prior knowledge, context of use and associated risks.11
That does not mean every employee needs the same one-hour presentation, a certificate, a dedicated “AI Officer” or a particular commercial training product. A tiered approach is more sensible:
- All users understand basic principles, limitations, hallucinations and privacy risks.
- Developers understand model limits, evaluation, prompt injection, data leakage and technical safeguards.
- Business departments understand the risks attached to their specific decisions.
- Procurement and governance staff can assess provider claims, contracts and risk classifications.
- Employees in sensitive areas receive deeper training on discrimination, human oversight and escalation.
Even a small business using ChatGPT for translation, quotations or advertising should at least brief employees on common errors, confidential information and the need to review outputs. The Commission explicitly cites hallucinations as an example.
High-risk systems: postponed, not cancelled
The largest short-term relief from the AI Omnibus concerns the high-risk requirements. They now apply later than originally planned.
For use cases listed in Annex III, full application begins on 2 December 2027. For AI systems that are safety components of regulated products or regulated products themselves, the date is 2 August 2028.
Typical high-risk areas under Annex III include, subject to the detailed conditions:
- selection, assessment and ranking of job applicants,
- decisions on working conditions, promotion or termination,
- assessment of employee performance or behaviour,
- access to education and assessment of examinations,
- creditworthiness assessment of natural persons,
- risk assessment and pricing in certain life and health insurance contexts,
- access to essential private or public services,
- certain biometric systems,
- and certain uses in law enforcement, migration, border control and the administration of justice.
Not every system used by an HR department is automatically high-risk. An AI tool rewriting job adverts is different from a system that scores or rejects applicants. Intended purpose remains decisive.
For providers of high-risk systems, the later requirements include:
- continuous risk management,
- data and data-governance requirements,
- technical documentation,
- automatic logging,
- clear information and instructions for use,
- human oversight,
- requirements for accuracy, robustness and cybersecurity,
- a quality-management system,
- conformity assessment and registration,
- post-market monitoring,
- and incident-reporting and corrective-action processes.
Deployers have to use systems according to instructions, ensure human oversight, control input data, monitor operation and respond to identified risks. Certain cases add information duties towards employees and a fundamental-rights impact assessment.12
The postponement should not be read as permission to ignore the subject until the end of 2027. Anyone developing a high-risk product already needs appropriate data, logs, tests, responsibilities and contractual arrangements. These cannot be bolted onto a mature system a few weeks before the deadline.
General-Purpose AI: relevant to model providers and downstream developers
GPAI rules have generally applied since 2 August 2025. They mainly address providers of general-purpose models.
Their obligations include:
- technical documentation of the model,
- information for providers integrating the model into downstream systems,
- a policy to comply with EU copyright law,
- and a sufficiently detailed summary of content used for training.
Models with systemic risk face additional duties including model evaluations, adversarial testing, assessment and mitigation of systemic risks, reporting of serious incidents and cybersecurity.
A Swiss company does not become a GPAI provider merely by using the API of a large model. The situation can be different if it publishes its own general-purpose model, distributes another model under its own name or makes a modification that legally amounts to a new placing on the market.
Anyone fine-tuning an open-source model should therefore ask more than whether it is technically still “the same model”. Scope, purpose, distribution, branding, documentation and the organisation’s role in the value chain also matter.
What does this mean for an ordinary company?
The AI Act has sometimes been presented as though every prompt will have to be documented and every AI output will need a warning label. That is wrong. For most everyday uses, the immediate work is about clear responsibility, transparency, competence and control of sensitive use cases.
Internal use of ChatGPT, Copilot or Claude
A company uses an established AI service for emails, summaries, research, translation or source code.
This is generally not a high-risk use. The company is typically a deployer rather than the provider of the foundation model. Relevant issues nevertheless include:
- AI literacy of users,
- protection of confidential information,
- data protection and processing arrangements,
- review of output,
- copyright and licensing questions,
- rules for approved tools and accounts,
- and clear boundaries for sensitive decisions.
Not every internally edited email needs a “created with AI” notice. The AI Act contains no general labelling requirement for every instance of AI assistance.
Website chatbot
A company integrates an AI chatbot into its website or customer portal.
From 2 August 2026, users have to be able to recognise that they are interacting with an AI system unless that is obvious. Data protection, logging, protection against prompt injection, escalation to a human and answer quality also matter.
If the bot accepts orders, gives binding information or controls processes, a small notice is not enough. Responsibility for incorrect outputs, unauthorised actions and complaints also has to be defined.
Generated advertising and social media
A marketing team produces images, video or audio with generative AI.
Not every asset is a deepfake. Realistic manipulation of people or events can, however, require visible disclosure. The provider of the generator additionally has to support technical detectability.
Personality rights, unfair-competition law, copyright and trademark law remain relevant independently of the AI Act. A transparently labelled asset can still be unlawful.
Candidate selection and employee assessment
An HR department uses AI to score CVs, rank candidates or assess employee performance.
A high-risk classification is plausible here. The complete high-risk duties have been postponed to December 2027, but the project should be classified now. Data protection, employment law and anti-discrimination rules already apply today.
Anyone waiting until 2027 may find it difficult to reconstruct training data, decision logic, logs, tests and human-control steps retrospectively.
Own AI product built on somebody else’s model
A software company builds an assistant on top of an external model and sells it under its own brand.
The role allocation needs careful assessment. The company may be the provider of the finished AI system even though another vendor supplies the foundation model. It then depends on information and contractual assurances from upstream providers.
A label such as “Powered by Model X” does not automatically transfer responsibility to the model vendor.
Self-employed professionals are not exempt
The AI Act has no general de minimis exemption for sole proprietors. A self-employed developer or consultant can be a provider or deployer just as a corporation can.
Requirements must be applied proportionately, and sanction ceilings are partly more favourable for smaller businesses. The basic obligations do not disappear.
Example: self-employed writer
A Swiss writer uses a language model to produce articles for a customer in Germany.
The output is intended to be used in the EU. The territorial scope of the AI Act can therefore be triggered even though the writer works exclusively in Switzerland. The Swiss Federal Office of Communications explicitly uses the example of a Swiss company delivering AI-generated text to customers in the EU in its legal analysis.13
Whether disclosure is required depends on the content and publication process. For text on matters of public interest, substantive human review and editorial responsibility become particularly important.
Example: self-employed software developer
A developer builds a support agent for an Austrian customer.
The contract should clarify:
- Who is the provider and who is the deployer?
- Under whose name is the system made available?
- Who determines the intended purpose?
- Who supplies the transparency notices?
- Who monitors the system after launch?
- Who handles incidents and complaints?
- Which information has to come from the model or platform provider?
Without that allocation, it is easy to create a situation where every participant assumes somebody else is responsible.
Example: photographer or video producer
A self-employed producer creates a realistically manipulated video featuring a known person for a French campaign.
Alongside consent and personality rights, the deepfake disclosure may apply. Producing the video in Switzerland is not a reliable way around the obligation when the content is intended for the EU market.
Example: local trade business
A Swiss trade business uses an AI assistant exclusively internally for quotations and translation. It has no EU customers and places no AI system on the EU market.
The AI Act may not apply at all. Swiss data-protection law, contractual confidentiality and the obligation to review quotations for correctness still do.
That distinction matters: the AI Act is extraterritorial, but not unlimited.
Why Swiss companies can fall within scope
Switzerland is not a member of the European Union. The AI Act therefore does not automatically apply to every AI use in a Swiss business. The regulation nevertheless has broad territorial reach.
Simplified, three situations are particularly relevant:
- A Swiss provider places an AI system or GPAI model on the EU market.
- A Swiss organisation deploys a system through an establishment or structure in the EU.
- A Swiss provider or deployer produces output intended for use in the EU.
The third point is broader than many expect. The Swiss Federal Office of Communications notes in its legal analysis that Swiss actors can be covered where output produced by their system is used in the EU. Its example is AI-generated text supplied by a Swiss company to EU customers.13
Output used in the EU is a critical connecting factor
A Swiss SaaS provider can be affected when German or French customers use its system. A Swiss consulting company can be affected when it produces AI-generated assessments for an EU company. A developer can be affected when his agent operates inside an EU customer portal.
Mere accidental accessibility of a website from the EU is unlikely to decide the question by itself. Target market, contracts, marketing, user population, intended use and actual use all matter. Where EU customers exist, however, the issue should not be ignored.
Authorised representative in the EU
Providers from third countries have to appoint an authorised representative in the EU in certain situations. This is particularly relevant to providers of high-risk systems and GPAI models unless an exception applies.14
The representative is not merely a mailbox. He has statutory tasks, keeps defined documentation available and acts as a contact point for authorities.
For a Swiss start-up selling a possible high-risk system throughout the EU, this is therefore an operational and contractual topic that has to be included in market-entry planning.
Swiss blocking statutes and regulatory requests
Cross-border supervision creates another issue that is often overlooked. Article 271 of the Swiss Criminal Code can restrict actions carried out in Switzerland on behalf of a foreign authority without authorisation. Depending on the concrete circumstances, directly handing documents or evidence to an EU authority can therefore create a Swiss-law issue.13
This does not mean every transmission to an EU authority is prohibited. It means Swiss companies should not invent their document-production and authority-response process only after receiving a request. Sensitive cases need coordinated legal analysis and, where necessary, authorisation.
Conformity assessment and technical barriers to trade
For high-risk systems requiring conformity assessment, third-country status can create additional cost. The existing agreement on mutual recognition of conformity assessments between Switzerland and the EU does not automatically cover the AI Act.
According to the Swiss legal analysis, a manufacturer may therefore have to obtain an assessment inside the EU and appoint an authorised representative in addition. Even substantively similar Swiss regulation would not automatically create mutual recognition; the bilateral agreements might need to be amended.15
For purely internal software this is usually not an immediate problem. For manufacturers of machinery, medical technology or other regulated products containing AI components, it can become a concrete market-access issue.
The AI Act does not replace Swiss law
Even where the EU AI Act does not apply, AI use in Switzerland does not take place in a legal vacuum.
The revised Swiss Data Protection Act already applies to processing personal data with AI. The Federal Data Protection and Information Commissioner explicitly notes that existing principles apply to AI in a technology-neutral way.16
These include:
- lawfulness, proportionality and transparency of processing,
- purpose limitation,
- data security,
- privacy by design and privacy-friendly defaults,
- information obligations,
- rules on automated individual decisions,
- and, depending on risk, a data-protection impact assessment.
Employment law, anti-discrimination law, contract law, copyright, personality rights, competition law, professional secrecy and product liability may also apply.
The AI Act is therefore not a complete body of AI law. It complements other rules. A system can comply with AI Act labelling rules and still violate privacy or personality rights. Conversely, a use that is lawful under data-protection law can trigger additional AI Act duties.
Switzerland is not currently planning a horizontal copy of the AI Act
The Federal Council is pursuing a sectoral approach. Rather than copying the EU AI Act in full, Switzerland plans to implement the Council of Europe’s AI Convention and supplement existing law selectively. A consultation draft has been announced for the end of 2026. Based on current plans, transparency, data protection, non-discrimination and supervision are among the main topics.17
Swiss companies therefore have to maintain two perspectives for the time being:
- Activities with an EU connection may fall directly under the AI Act.
- Purely Swiss activities remain subject to existing Swiss law and possible future sector-specific additions.
International businesses will rarely want to operate completely separate processes. In many cases it is more economical to establish one robust baseline for all systems and add stricter EU-specific steps only where they are actually required.
Fines: being small does not remove the obligations
Depending on the infringement, the AI Act provides maximum fines of:
- up to EUR 35 million or 7 percent of global annual turnover for certain breaches involving prohibited practices and data requirements,
- up to EUR 15 million or 3 percent for other breaches of the regulation,
- up to EUR 7.5 million or 1 percent for incorrect, incomplete or misleading information supplied to authorities,
- and, for GPAI providers, up to EUR 15 million or 3 percent of global annual turnover.18
For companies, fixed amounts and turnover percentages are applied differently depending on size. Smaller businesses benefit from certain lower ceilings and the principle of proportionality. That is not an exemption.
For a self-employed professional, the probability of an immediate multimillion-euro fine is not the most useful way to think about risk. More realistic first-order consequences include:
- lost contracts,
- breaches of contract,
- claims from an EU customer,
- complaints,
- regulatory orders,
- removal or suspension of a system,
- reputational damage,
- and the cost of rushed remediation after the fact.
A practical decision matrix for Swiss providers
| Scenario | Likely role | EU connection | Most urgent action |
|---|---|---|---|
| Internal use of a standard chatbot without EU connection | Deployer | probably no | Ensure Swiss data protection, AI literacy and internal rules |
| Website chatbot for customers in Germany and France | Deployer, potentially provider of the complete system | yes | Add AI notice from the first interaction; clarify roles and responsibility |
| Own SaaS product with integrated LLM for EU customers | usually provider of the AI system | yes | Classify the system, document the supply chain, review transparency and contracts |
| AI-generated text for EU customers | Deployer, depending on product possibly provider | often yes | Review use and publication process; document editorial control |
| Candidate ranking for a Swiss company | Deployer | AI Act only with EU connection, but Swiss law applies | Prepare high-risk classification; assess privacy and discrimination risks |
| Candidate-ranking product for EU customers | Provider of a possible high-risk system | yes | Build high-risk roadmap for December 2027; plan technical documentation and EU representation |
| AI component in machinery for the EU market | Product manufacturer and potentially provider | yes | Assess product regulation, conformity assessment and August 2028 deadline |
| Own general-purpose language model for the EU market | GPAI provider | yes | Assess GPAI duties, documentation, copyright policy and EU authorised representative |
The table is an orientation aid, not an automatic legal classification. Small changes to the intended purpose can change both role and risk category.
What companies should do now
The best starting point is not a hundred-page policy. It is a reliable inventory.
1. Record all AI systems and relevant functions
Do not count only obvious chatbots. AI is already embedded in:
- office and collaboration tools,
- CRM and marketing platforms,
- applicant management,
- fraud detection,
- translation,
- document analysis,
- software development,
- customer service,
- image and video editing,
- security products,
- and industry-specific business applications.
For each system, record purpose, users, data, provider, geographic connections and affected people.
2. Determine role and EU connection
At minimum, answer these questions for each system:
- Are we a provider, deployer, importer, distributor or product manufacturer?
- Is the system offered under our name?
- Did we define or change the intended purpose?
- Are there customers, users, employees or outputs in the EU?
- Is the system used by an EU establishment?
- Do we need an authorised representative?
A single company-wide status is not enough. The same company can be a deployer for one system and a provider for another.
3. Screen out prohibited and sensitive use cases
Before detailed analysis, establish whether a use is prohibited or clearly sensitive. This includes biometric analysis, emotion recognition, manipulative systems, social scoring, employment decisions, creditworthiness and decisions affecting essential services.
4. Implement transparency by 2 August 2026
For chatbots, agents, deepfakes, public-interest AI text and emotion recognition, assess whether a notice is required.
The notice should:
- appear at the right time,
- be clear and understandable,
- describe the actual use,
- not be hidden inside general terms,
- and be consistent across all relevant channels.
5. Be able to demonstrate AI literacy
A certificate programme is not required. It should nevertheless be possible to show which employees received which information and why the measure was appropriate to their risk.
A pragmatic record can consist of training material, attendance, internal guidelines, role-specific modules and recurring updates.
6. Review contracts with providers and customers
Important points include:
- allocated role under the AI Act,
- technical documentation,
- marking functionality,
- use of customer data and training,
- subprocessors,
- security incidents,
- audit and information rights,
- model changes,
- availability of logs,
- liability and indemnification,
- and support for authority requests.
A standard data-processing agreement does not cover all of this.
7. Describe human control concretely
“Human in the loop” is useful only when the implementation states:
- who performs the control,
- what information he receives,
- which decision he can change,
- when escalation occurs,
- how time pressure and automation bias are addressed,
- and how the review is logged.
A formal approval by somebody who does not understand the system and in practice always accepts its recommendation is not effective oversight.
8. Do not leave high-risk projects untouched until 2027
For possible high-risk systems, organisations should start gap analysis, data-provenance work, test strategy, logging, quality management and responsibility mapping now. The delay creates time for proper implementation, not a reason for inactivity.
A pragmatic 90-day plan
First 30 days
- Create the AI inventory.
- Assign one business owner and one technical owner per system.
- Determine the EU connection and likely roles at a high level.
- Exclude prohibited practices.
- Review publicly accessible chatbots and generative content for transparency obligations.
- Define internal rules for confidential data and approved tools.
By day 60
- Carry out role-based AI-literacy measures.
- Review contracts and provider documentation.
- Assess privacy impact and automated decisions.
- Integrate required disclosures into frontends, content processes and metadata.
- Define incident and escalation processes.
- Mark possible high-risk systems separately.
By day 90
- Complete documented classification for material systems.
- Clean up supply-chain and role agreements with customers and partners.
- Establish technical evaluations, logs and approval mechanisms.
- Create a roadmap to December 2027 or August 2028 for high-risk products.
- Assess whether third-country providers need an EU authorised representative.
- Prepare authority-response and document-production processes with Swiss law in mind.
For a self-employed professional, this can fit into one well-structured table and a few clear templates. The quantity of documentation matters less than whether the important decisions can be reconstructed.
Five common misconceptions
“We are in Switzerland, so the AI Act does not apply”
Wrong. Being established outside the EU can put an activity outside scope, but it does not automatically do so. EU customers, distribution in the EU or intended use of output in the EU can be enough.
“Anyone using ChatGPT operates a high-risk system”
Wrong. Risk classification depends on the concrete intended purpose. Translation is different from automated candidate selection.
“Every AI-generated text has to be labelled”
Wrong. The special disclosure rule concerns published text about matters of public interest. Substantive human review and editorial responsibility also provide an exception.
“The high-risk rules were postponed, so we can wait until 2027”
Dangerous. Data provenance, logging, testing, risk management and supplier contracts require lead time. Privacy and other areas of law already apply today.
“The model provider is responsible for everything”
Wrong. A company integrating a model into its own product, defining the purpose or placing the system on the market under its own brand can acquire provider duties of its own. Deployers also retain responsibility for their concrete use.
Conclusion
2 August 2026 is not the date on which the EU AI Act first enters into force. It is the date when another large group of rules becomes practically relevant and enforceable.
For most companies, the immediate task is not to build a complete conformity programme around every AI tool. It is first to know which systems are actually in use, which role the company has, where an EU connection exists and which applications require transparency, are sensitive or may become high-risk.
For Swiss companies and self-employed professionals, the national border is not a reliable firewall. Anyone offering AI systems in the EU, developing them for EU customers or supplying output intended for use in the EU can fall directly within scope. Swiss data-protection law and other national rules continue to apply independently.
The most important short-term steps are manageable:
- inventory systems,
- clarify roles and EU connections,
- exclude prohibited practices,
- implement transparency obligations,
- build AI literacy,
- clean up contracts and responsibilities,
- and prepare possible high-risk systems early for the 2027 and 2028 deadlines.
The AI Act does not require every AI idea to be buried in bureaucracy. It does require organisations to stop pretending that a production AI system is just another software feature with no distinct risks or responsibilities.
Sources and legal references
Footnotes
-
Regulation (EU) 2026/1744, amending the AI Act, published in the Official Journal on 24 July 2026 and in force since 27 July 2026. It postpones application of the high-risk requirements and makes further amendments. ↩
-
European Commission: AI Act and implementation timeline, status 31 July 2026; European Commission: Start of enforcement and new transparency requirements on 2 August 2026. ↩
-
Regulation (EU) 2024/1689, particularly the provisions assigning provider obligations after a change of name, substantial modification or change of intended purpose of a high-risk system. ↩
-
European Commission: questions and answers on Article 50 of the AI Act, definition of deployer and distinction from personal, non-professional use. ↩
-
Regulation (EU) 2024/1689, Article 50; European Commission: Guidelines on transparency obligations and supplementary questions and answers. ↩
-
European Commission: questions and answers on Article 50, technical marking of generative output and exceptions. ↩
-
Regulation (EU) 2026/1744; transitional rule for systems placed on the market before 2 August 2026. ↩
-
Regulation (EU) 2024/1689, Article 50; European Commission: guidelines on disclosure of deepfakes. ↩
-
Regulation (EU) 2024/1689, Article 50; European Commission: interpretation of disclosure obligations for AI-generated text on matters of public interest. ↩
-
Regulation (EU) 2026/1744, new prohibited practice applicable from 2 December 2026. ↩
-
European Commission: Questions and answers on AI literacy under Article 4 as amended by the AI Omnibus. ↩
-
Regulation (EU) 2024/1689, chapter on high-risk systems; European Commission: overview of duties for providers and deployers. ↩
-
Swiss Federal Office of Communications and Federal Office of Justice: Legal analysis and overview of the regulatory basis for artificial intelligence, 2024/2025, particularly the sections on the extraterritorial scope of the EU AI Act and Article 271 of the Swiss Criminal Code. ↩ ↩2 ↩3
-
Regulation (EU) 2024/1689, provisions on authorised representatives for third-country providers of high-risk systems and GPAI models. ↩
-
Swiss Federal Office of Communications: Auslegeordnung zur rechtlichen Basis für künstliche Intelligenz in der Schweiz, section on conformity assessment, market access and the agreement on mutual recognition of conformity assessments. ↩
-
Federal Data Protection and Information Commissioner: AI and data protection, guidance on direct application of Swiss data-protection law to AI-assisted processing. ↩
-
Swiss Federal Council: AI regulation and implementation of the Council of Europe AI Convention; consultation announced for the end of 2026. ↩
-
Regulation (EU) 2024/1689, provisions on penalties; European Commission: overview of supervision and fines. ↩