2 August 2026 marks the most important milestone of the EU AI Act: since that date, the bulk of its obligations applies. After the bans on certain practices (in force since February 2025) and the rules for general-purpose AI models (since August 2025), the requirements for high-risk systems under Annex III and the transparency duties for certain AI applications now apply. For high-risk systems embedded in regulated products under Annex I, the transition runs until August 2027.
The decisive point for Swiss companies: the regulation does not only reach actors established in the EU. It covers anyone placing AI systems on the EU market or putting them into service there, and equally anyone operating a system whose output is intended to be used in the EU. A Zurich software vendor with customers in Germany is covered, as is an industrial company delivering AI-supported analyses to an EU subsidiary.
The duties differ sharply by role. Providers carry the main load: risk management, data quality, technical documentation, record keeping, human oversight, robustness and conformity assessment. Deployers must, among other things, use systems as intended, control input data, retain logs and in certain cases inform affected persons. A Swiss company that brings systems into the EU under its own name quickly slides into the provider role, even if the technology is bought in.
The sanctions are substantial: fines can reach 35 million euros or seven percent of worldwide turnover depending on the breach. More important in practice: EU customers increasingly demand conformity evidence in tenders and contracts. Without documentation you lose deals long before any authority acts.
For the coming weeks that means: first, a complete inventory of all AI systems used and offered, including features embedded in standard software. Second, per system, determine the risk class and your own role. Third, run a gap analysis against the applicable duties, with owners and deadlines. Fourth, review contracts with AI vendors and EU customers for warranties, cooperation duties and liability.
Swiss law remains applicable in parallel: the FADP governs every processing of personal data by AI, and the Federal Council has chosen a sectoral regulatory approach aligned with the Council of Europe AI Convention. Whoever implements the EU duties cleanly has most of the Swiss requirements under control.
Our AI check delivers a first structured assessment in minutes. For the deeper analysis of individual systems and the contracts around them, we are happy to assist personally.

