Djtal
  • AI
  • EU AI Act
  • Regulation
  • Compliance
  • Swiss companies

The EU AI Act and Swiss companies: two misconceptions that cost money

Many Swiss executives think the EU AI Act is not their concern. Djtal shows why neither reason holds, what applies to Swiss companies and how to prepare.

Laurent Cuénoud
Stylised map of western Europe in blue tones: a thin open frame marks the European Union, and Switzerland, in a deeper blue, straddles the edge of the frame.

“The AI Act is a European matter. We’re in Switzerland, so it doesn’t concern us.” As founder of Djtal, I hear this often, and it is wrong: the EU AI Act reaches a Swiss company whenever the output of its AI system is used in the EU. After 30 years in IT, I recognise the pattern. People said the same about the GDPR before 2018, until many Swiss companies found out they were subject to it.

Two misconceptions about the EU Artificial Intelligence Act (Regulation (EU) 2024/1689, published on 12 July 2024) are doing the rounds, and both can prove costly. They deserve a calm look, without burying your head in the sand.

Misconception 1: “It’s Europe, not us”

The EU AI Act has extraterritorial reach. Article 2 brings providers and deployers established outside the Union within its scope where the output produced by their AI system is used in the Union, even with no physical presence in Europe.

A Swiss company that places an AI system on the EU market, or whose systems produce output used by a customer in the EU, therefore falls within the scope of the regulation. A provider in French-speaking Switzerland whose candidate-screening tool is sold to a single employer in Germany must, in principle, classify its system and maintain its documentation. The border makes no difference.

Misconception 2: “Switzerland has no law, so there is nothing to do”

Switzerland admittedly has no comprehensive ‘AI Act’. On 12 February 2025, the Federal Council opted for a sector-specific approach, with no single cross-sector framework law. On 27 March 2025, it signed the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, the first legally binding international treaty on AI. A consultation draft is expected by the end of 2026.

A Swiss company therefore already operates within a dual framework: Swiss regulation that is taking shape, and the EU regulation, which applies to it as a knock-on effect. Waiting for ‘the Swiss law’ before looking into the subject ignores half the picture.

The timetable keeps moving, so plan around the framework

The EU AI Act applies in stages. Prohibited AI practices, those posing an unacceptable risk, have been banned since 2 February 2025. The rules on general-purpose AI models and on penalties have applied since 2 August 2025. And the transparency obligations have applied since 2 August 2026: telling people when they are interacting with an AI system, and labelling AI-generated content.

The timetable has in fact just moved again. The EU’s ‘Digital Omnibus’ was published in the Official Journal of the European Union on 24 July 2026 (Regulation (EU) 2026/1744) and entered into force on 27 July. It postpones the obligations for high-risk AI systems to 2 December 2027 for stand-alone systems and to 2 August 2028 for AI embedded in regulated products. The transparency obligations stay on the original timetable, with a deadline of 2 December 2026 for marking content generated by systems placed on the market before 2 August 2026.

When the dates move, the framework holds. Build your compliance on that lasting framework, which will outlive any single deadline.

What the framework requires

The EU AI Act sorts AI systems into four risk levels: unacceptable risk (prohibited), high risk (strict obligations: data governance, technical documentation, record-keeping, human oversight), limited risk (transparency) and minimal risk (the vast majority, with no specific obligations).

Look at the list of obligations for high-risk AI systems: tracing your data, documenting your systems, keeping a human in the loop, logging decisions. These are good engineering practice first and constraints second, and they are what sets a serious deployment apart from a makeshift one. Fines exist (up to EUR 35 million or 7% of total worldwide annual turnover for prohibited practices, Article 99). To set the amount, the authorities take into account, among other things, the gravity of the infringement, whether it was intentional or negligent, and the technical and organisational measures the company had in place.

What we do at Djtal

At Djtal, we run our own AI agents with systematic human oversight, a shared state where information is pooled, and a log of decisions. These three disciplines predate the EU AI Act, because an agent nobody reviews ends up costing a lot. When these requirements become the norm, we will already meet them.

The first step is a mapping exercise, and the legal questions come after it. Know where you stand. Which AI systems do you use, which of them reach the EU, which fall into the high-risk category? A clear assessment is worth more than vague anxiety.

Companies whose engineering is already sound meet most of the EU AI Act’s requirements without realising it.

Wondering whether your uses of AI are covered? Get in touch and we’ll talk it through.

A topic worth exploring for your business?

Let's spend 30 minutes on your context and find where AI can help your business.

Speak to one of our experts