With the AI Act, the EU regulates the use of AI
comprehensively for the first time — risk-based, from prohibited
practices via high-risk systems to transparency duties. The
regulation reaches beyond the EU: it applies even when a system
is operated outside the EU but its output is used within it.
Swiss companies are in scope faster than many realise.
The law is only half the equation. Introducing AI creates new
attack and leakage surfaces: uncontrolled AI use by employees,
trade secrets in third-party models, systems open to manipulation.
And wherever personal data is involved, the revDSG and GDPR apply
in full — technology neutrality is no shield from supervision.
-
Approach
Risk-based — duties scale with the risk classHigh-risk systems require risk management, data quality, human oversight, and documentation.
-
Timeline
Prohibitions since 02 / 2025 · transparency from 08 / 2026 · high-risk from 12 / 2027The high-risk deadlines were deferred in 2026 via the "Digital Omnibus" to December 2027 and August 2028.
-
Sanctions
Up to €35 m or 7% of worldwide annual turnoverFor prohibited practices; other violations up to €15 m or 3%.
-
Data protection
Personal data in AI systems falls under revDSG and GDPRThe revised Swiss Data Protection Act is technology-neutral — it covers AI use in full.
Introducing AI takes both: a legal framework that holds up before
the supervisor, and a security framework that prevents data leakage
and misuse — before the first system goes live, not after.