AI-Karma

Guides · 10/07/2026 · updated on 02/08/2026 · 6 min

Does the AI Act apply to my Swiss SME?

Territorial criteria (art. 2), the art. 25 trap, four risk levels and the post-Digital Omnibus calendar: what a Swiss SME must check, and what remains due even outside the scope.

Why the question arises

The AI Act is the European regulation on artificial intelligence (Regulation (EU) 2024/1689). It has applied in stages since February 2025. Switzerland is not a member of the European Union (EU) and has not adopted this text. Yet many Swiss small and medium-sized enterprises (SMEs) are directly concerned.

The reason lies in the regulation's extraterritorial reach. Like the General Data Protection Regulation (GDPR) before it, the AI Act does not stop at the EU's borders. It also targets actors established in third countries, as soon as their artificial intelligence (AI) systems touch the European market (art. 2).

The decisive test: the link with the European market (art. 2)

Three situations bring a Swiss SME within the scope of the regulation. A single one is enough.

First case: you sell products or services incorporating an AI system to customers located in the EU. This is placing on the market or putting into service in the Union (art. 2(1)(a)).

Second case: the outputs produced by your system — scores, decisions, content, reports — are used in the EU (art. 2(1)(c)). This is the classic trap for Swiss deployers. Example: a Lausanne accounting firm has an AI analyse the files of a French subsidiary. The system runs in Switzerland, but its outputs are used in France. The regulation applies.

Third case: your system processes or evaluates people located in the EU, for example cross-border applicants, European customers or users.

Conversely, an SME whose AI systems serve only Swiss customers, with outputs used solely in Switzerland, stays outside the scope of the AI Act for those uses.

The article 25 trap: the user who becomes a provider

The regulation distinguishes two main roles. The deployer uses, under its own authority, an AI system it has bought or rented: this is the most frequent case in an SME, for example a SaaS tool (software accessible online) or the AI module of a business application. The provider, on the other hand, develops a system and places it on the market under its own name. Its obligations are markedly heavier.

Article 25 contains a requalification that is often overlooked. If you put your brand on an existing AI system, substantially modify it, or divert it from its intended purpose, you legally become a provider. All the provider's obligations then fall on you.

A concrete example: a web agency that dresses a retail chatbot in its own brand and resells it to its clients is no longer a mere user, but a provider within the meaning of the regulation.

The four risk levels

The AI Act classifies uses, not technologies. The same tool can be innocuous in one context and tightly regulated in another.

Level 1: prohibited practices (art. 5). Manipulation, exploitation of vulnerabilities, social scoring, emotion recognition at work and in education, among others. These prohibitions have applied since 2 February 2025. Penalties reach 35 million euros or 7 % of worldwide turnover (art. 99(3)).

Level 2: high risk (art. 6 and Annex III). It covers in particular CV screening and candidate evaluation, credit scoring, pricing in life or health insurance, education and biometrics. The employment and human resources category is the most frequent in SMEs.

Level 3: transparency obligations (art. 50). Chatbots, AI-generated content, deepfakes and emotion recognition in lawful cases must be flagged as such to the people concerned.

Level 4: minimal risk. This is the vast majority of uses, such as internal writing assistance or translation. No specific obligation beyond voluntary good practice (art. 95) — and Swiss data protection law.

What is due, and when: the calendar after the Digital Omnibus

The “Digital Omnibus AI” regulation — Regulation (EU) 2026/1744 of 8 July 2026, in force since 27 July 2026 — reshaped the initial calendar. Here are the deadlines to remember.

Since 2 February 2025: prohibited practices (art. 5) and the obligation of AI literacy for staff (art. 4), softened by the omnibus into a best-efforts obligation.

2 August 2026: the transparency obligations of article 50 — chatbots, generated content, deepfakes. Applicable since that date, the omnibus not having moved the deadline.

2 December 2026: new prohibitions (generation of non-consensual intimate images, child sexual abuse material) and the end of the machine-readable marking reprieve for generative systems placed on the market before 2 August 2026.

2 December 2027: full obligations for Annex III high risk, postponed by sixteen months by the omnibus. The original date was 2 August 2026 — this is the main change for SMEs.

2 August 2028: Annex I high risk, that is AI embedded in already regulated products such as machinery, toys or medical devices.

Not concerned? Your Swiss obligations remain

Being outside the scope of the AI Act does not mean being free of every obligation. The Federal Act on Data Protection (FADP), in force since September 2023, applies to any processing of personal data, AI included: that is the position of the Federal Data Protection and Information Commissioner (FDPIC). Transparency (art. 19 FADP), security (art. 8 FADP), the rights of data subjects and the framing of automated individual decisions (art. 21 FADP) apply to all Swiss companies.

Swiss AI law is being built alongside. Switzerland signed the Council of Europe Framework Convention on AI in March 2025. A preliminary draft is expected to go to consultation by the end of 2026, with a sectoral approach rather than a cross-cutting law. The practices prohibited by the AI Act are the best predictor of the future Swiss red lines.

Where to start

Three concrete moves. First, inventory your AI uses, including the AI functions embedded in your business software. Then, for each use, ask the question of the EU link: customers, outputs, people concerned. Finally, classify the uses concerned across the four risk levels and note the applicable deadline.

AI-Karma's free tool, designed for Swiss SMEs, allows this assessment in about fifteen minutes. Its AI Act classification module (/aiact) reproduces the reasoning described here, question by question, and returns the obligations and deadlines specific to each use case.

This is not legal advice. For complex situations — provider role, high risk, regulated sector — have your analysis validated by specialised counsel.

Frequently asked questions

Is a Swiss SME with no European customers subject to the AI Act?

No, as long as none of the three links of art. 2 exists: no customers in the EU, no outputs of the system used in the EU, no people located in the EU processed or evaluated. The Swiss FADP, however, remains fully applicable.

What is a deployer under the AI Act?

An organisation that uses an AI system under its own authority without having developed it — for example through a SaaS tool. It is the most frequent role for an SME, with lighter obligations than the provider's.

When do the “high risk” obligations apply?

For the Annex III areas (recruitment, credit, life/health insurance, education, biometrics…), on 2 December 2027: the Digital Omnibus AI — Regulation (EU) 2026/1744, in force since 27 July 2026 — postponed the original date of 2 August 2026 by sixteen months. For AI embedded in regulated products (Annex I), on 2 August 2028.

Does using ChatGPT internally bring my SME within the AI Act?

A purely internal use, in Switzerland, with outputs used in Switzerland, remains in principle outside the territorial scope. But if you publish generated content visible to European customers or process people located in the EU, art. 50 has applied since 2 August 2026. And the FADP applies in every case.

Will the AI Act be adopted as such in Swiss law?

No. Switzerland is preparing its own implementation of the Council of Europe Framework Convention on AI, signed in March 2025: a preliminary draft is expected to go to consultation by the end of 2026, with a sectoral approach. The first legislative amendments are expected in 2027 at the earliest.

And your company, where does it stand?

A score across 24 indicators, AI Act classification, an action plan — 15 minutes, free, no account.

Assess my company