Custodos is live – all leading AI models, securely hosted in the EU or Switzerland.Start free trial
All articles
ComplianceUpdated on 26 July 20267 min readCustodos editorial team

The EU AI Act: what it means for companies in the DACH region

The EU AI Act is Regulation (EU) 2024/1689 and the first comprehensive AI law anywhere. It entered into force on 1 August 2024 and applies in stages – the first obligations have applied since 2 February 2025, and general applicability begins on 2 August 2026.

The AI Act does not regulate technology but applications. What matters is the risk an AI system poses to health, safety and fundamental rights – and the role in which a company deploys it.

Swiss companies are not directly bound by the regulation but can be caught by its scope. This article clarifies when that happens, which deadlines apply and what companies in Germany, Austria and Switzerland should do now.

What the EU AI Act regulates

The AI Act takes a risk-based approach. Rather than regulating AI as a whole, it sorts applications by risk and attaches obligations of differing severity. A chatbot for internal drafting is treated differently from a system deciding on creditworthiness or job applications.

It addresses two roles above all: providers, who develop an AI system and place it on the market under their own name, and deployers, who use a system under their own responsibility. Most companies are deployers – with considerably fewer obligations, but not none.

The timeline

The regulation applies in stages. Two of the dates have already passed.

DateWhat applies from then
1 August 2024The regulation enters into force.
2 February 2025Prohibited practices under Art. 5 and the AI literacy obligation under Art. 4 apply.
2 August 2025Obligations for general-purpose AI models, governance structures and the penalty regime.
2 August 2026General applicability, including high-risk systems under Annex III and the transparency obligations under Art. 50.
2 August 2027High-risk systems embedded as safety components in products that are already regulated.

The four risk classes

Classification determines the entire scope of obligations. It is made per application, not per product: the same model can fall into different classes depending on how it is used.

  • Unacceptable risk: prohibited. This includes social scoring by public authorities, untargeted scraping of facial images from the internet, and emotion recognition in the workplace and in education.
  • High risk: permitted, but with extensive obligations. Covered areas include recruitment, creditworthiness assessment, critical infrastructure, education and law enforcement.
  • Limited risk: transparency obligations under Art. 50. Users must be able to tell they are interacting with an AI system, and AI-generated content has to be labelled.
  • Minimal risk: no specific obligations. This is where most workplace usage sits – drafting, summarising, research.

When Swiss companies are caught

The AI Act does not apply through Swiss law. Its scope is, however, extraterritorial by design: it also captures providers and deployers in third countries where the output of an AI system is used in the EU.

For Swiss companies that produces three typical constellations: they place an AI-supported product on the EU market, they deploy AI and the output feeds into processes with an EU nexus, or they supply a customer who passes the requirements down contractually. In practice the third is by far the most common.

Separately, it is becoming clear that Switzerland will not create a comprehensive AI act on the EU model. The direction of travel points towards ratifying the Council of Europe AI Convention and making sector-specific adjustments within existing law. Data protection law therefore remains the most important framework for AI use in Switzerland.

AI literacy: the obligation that already applies

Art. 4 of the AI Act requires providers and deployers to ensure their staff have a sufficient level of AI literacy. This obligation has applied since 2 February 2025 and is not limited to high-risk systems – it also binds companies that use AI purely for drafting text.

The regulation prescribes no format. What is required is a level of knowledge appropriate to the context: what the deployed system can do, where its limits lie, what risks exist and how output should be checked. Documented training tied to the tools actually in use is the pragmatic route.

For most companies in the DACH region this is the most relevant obligation in the AI Act – because it already applies, because it bites regardless of risk class, and because it can be met with proportionate effort.

Penalties

Art. 99 sets out a tiered penalty regime. It is turnover-based and, at the top end, exceeds the GDPR figures.

BreachMaximum
Prohibited practices under Art. 5Up to 35 million euros or 7 per cent of global annual turnover
Breaches of the remaining obligationsUp to 15 million euros or 3 per cent of global annual turnover
Incorrect or misleading information to authoritiesUp to 7.5 million euros or 1 per cent of global annual turnover

What to do now

The following steps make sense whether or not a company falls directly within scope – and they are the basis for the evidence customers and regulators ask for.

  1. Build an AI inventory: which systems are in use, by whom, for what purpose, with what data? Without an inventory no classification is possible.
  2. Map applications to risk classes and record the reasoning. What counts is the purpose of use, not the product.
  3. Rule out prohibited practices – in particular emotion recognition in the workplace, which ships unnoticed in a number of HR tools.
  4. Ensure AI literacy under Art. 4 and document the training.
  5. Prepare for transparency: labelling of AI-generated content and recognisable interaction with AI systems wherever Art. 50 applies.
  6. Clarify roles: who is provider, who is deployer? Building and distributing your own assistants can move you into the provider role.
  7. Review contracts: customer agreements and tenders often pass the requirements down before the regulation itself bites.

Frequently asked questions

Does the EU AI Act apply to Swiss companies?

Not directly through Swiss law. It can bite where a Swiss company places AI systems on the EU market or where the output of an AI system is used in the EU. More often it works indirectly: through customer contracts, group policies and tenders.

When does the AI Act apply in full?

General applicability begins on 2 August 2026. Before that, the prohibited practices and the AI literacy obligation applied from 2 February 2025, and the obligations for general-purpose AI models from 2 August 2025. For certain high-risk systems embedded in regulated products the deadline runs to 2 August 2027.

Is using an AI chat a high-risk use case?

Usually not. Drafting, summarising and research typically fall under minimal risk. It becomes high risk where output feeds into decisions about individuals – for instance shortlisting job applications or assessing creditworthiness.

What does the AI literacy obligation mean in practice?

Art. 4 requires staff using AI to understand sufficiently how it works, where its limits lie and what risks it carries. The regulation prescribes no format. What works is documented training tied to the tools actually in use and refreshed regularly.

Are we a provider or a deployer?

Most companies are deployers: they use someone else's system under their own responsibility. You can move into the provider role by placing a system on the market under your own name or substantially modifying an existing one. The role determines the scope of obligations and should be documented.

Does the AI Act replace data protection law?

No. The AI Act and the GDPR apply side by side and pursue different aims: the AI Act addresses product safety and fundamental rights, data protection law addresses the processing of personal data. In Switzerland the revFADP remains the central framework, whether or not the AI Act bites.

Sources

Related reading

Bring AI into your company securely.

Try Custodos with your team – and see how quickly secure AI becomes productive.

Start free trial
  • Try it with the whole team
  • Set up in minutes
  • Productive from day one