The EU AI Act: what it means for companies in the DACH region
The EU AI Act is Regulation (EU) 2024/1689 and the first comprehensive AI law anywhere. It entered into force on 1 August 2024 and applies in stages – the first obligations have applied since 2 February 2025, and general applicability begins on 2 August 2026.
The AI Act does not regulate technology but applications. What matters is the risk an AI system poses to health, safety and fundamental rights – and the role in which a company deploys it.
Swiss companies are not directly bound by the regulation but can be caught by its scope. This article clarifies when that happens, which deadlines apply and what companies in Germany, Austria and Switzerland should do now.
What the EU AI Act regulates
The AI Act takes a risk-based approach. Rather than regulating AI as a whole, it sorts applications by risk and attaches obligations of differing severity. A chatbot for internal drafting is treated differently from a system deciding on creditworthiness or job applications.
It addresses two roles above all: providers, who develop an AI system and place it on the market under their own name, and deployers, who use a system under their own responsibility. Most companies are deployers – with considerably fewer obligations, but not none.
The timeline
The regulation applies in stages. Two of the dates have already passed.
| Date | What applies from then |
|---|---|
| 1 August 2024 | The regulation enters into force. |
| 2 February 2025 | Prohibited practices under Art. 5 and the AI literacy obligation under Art. 4 apply. |
| 2 August 2025 | Obligations for general-purpose AI models, governance structures and the penalty regime. |
| 2 August 2026 | General applicability, including high-risk systems under Annex III and the transparency obligations under Art. 50. |
| 2 August 2027 | High-risk systems embedded as safety components in products that are already regulated. |
The four risk classes
Classification determines the entire scope of obligations. It is made per application, not per product: the same model can fall into different classes depending on how it is used.
- Unacceptable risk: prohibited. This includes social scoring by public authorities, untargeted scraping of facial images from the internet, and emotion recognition in the workplace and in education.
- High risk: permitted, but with extensive obligations. Covered areas include recruitment, creditworthiness assessment, critical infrastructure, education and law enforcement.
- Limited risk: transparency obligations under Art. 50. Users must be able to tell they are interacting with an AI system, and AI-generated content has to be labelled.
- Minimal risk: no specific obligations. This is where most workplace usage sits – drafting, summarising, research.
When Swiss companies are caught
The AI Act does not apply through Swiss law. Its scope is, however, extraterritorial by design: it also captures providers and deployers in third countries where the output of an AI system is used in the EU.
For Swiss companies that produces three typical constellations: they place an AI-supported product on the EU market, they deploy AI and the output feeds into processes with an EU nexus, or they supply a customer who passes the requirements down contractually. In practice the third is by far the most common.
Separately, it is becoming clear that Switzerland will not create a comprehensive AI act on the EU model. The direction of travel points towards ratifying the Council of Europe AI Convention and making sector-specific adjustments within existing law. Data protection law therefore remains the most important framework for AI use in Switzerland.
AI literacy: the obligation that already applies
Art. 4 of the AI Act requires providers and deployers to ensure their staff have a sufficient level of AI literacy. This obligation has applied since 2 February 2025 and is not limited to high-risk systems – it also binds companies that use AI purely for drafting text.
The regulation prescribes no format. What is required is a level of knowledge appropriate to the context: what the deployed system can do, where its limits lie, what risks exist and how output should be checked. Documented training tied to the tools actually in use is the pragmatic route.
For most companies in the DACH region this is the most relevant obligation in the AI Act – because it already applies, because it bites regardless of risk class, and because it can be met with proportionate effort.
Penalties
Art. 99 sets out a tiered penalty regime. It is turnover-based and, at the top end, exceeds the GDPR figures.
| Breach | Maximum |
|---|---|
| Prohibited practices under Art. 5 | Up to 35 million euros or 7 per cent of global annual turnover |
| Breaches of the remaining obligations | Up to 15 million euros or 3 per cent of global annual turnover |
| Incorrect or misleading information to authorities | Up to 7.5 million euros or 1 per cent of global annual turnover |
What to do now
The following steps make sense whether or not a company falls directly within scope – and they are the basis for the evidence customers and regulators ask for.
- Build an AI inventory: which systems are in use, by whom, for what purpose, with what data? Without an inventory no classification is possible.
- Map applications to risk classes and record the reasoning. What counts is the purpose of use, not the product.
- Rule out prohibited practices – in particular emotion recognition in the workplace, which ships unnoticed in a number of HR tools.
- Ensure AI literacy under Art. 4 and document the training.
- Prepare for transparency: labelling of AI-generated content and recognisable interaction with AI systems wherever Art. 50 applies.
- Clarify roles: who is provider, who is deployer? Building and distributing your own assistants can move you into the provider role.
- Review contracts: customer agreements and tenders often pass the requirements down before the regulation itself bites.
Frequently asked questions
Does the EU AI Act apply to Swiss companies?
Not directly through Swiss law. It can bite where a Swiss company places AI systems on the EU market or where the output of an AI system is used in the EU. More often it works indirectly: through customer contracts, group policies and tenders.
When does the AI Act apply in full?
General applicability begins on 2 August 2026. Before that, the prohibited practices and the AI literacy obligation applied from 2 February 2025, and the obligations for general-purpose AI models from 2 August 2025. For certain high-risk systems embedded in regulated products the deadline runs to 2 August 2027.
Is using an AI chat a high-risk use case?
Usually not. Drafting, summarising and research typically fall under minimal risk. It becomes high risk where output feeds into decisions about individuals – for instance shortlisting job applications or assessing creditworthiness.
What does the AI literacy obligation mean in practice?
Art. 4 requires staff using AI to understand sufficiently how it works, where its limits lie and what risks it carries. The regulation prescribes no format. What works is documented training tied to the tools actually in use and refreshed regularly.
Are we a provider or a deployer?
Most companies are deployers: they use someone else's system under their own responsibility. You can move into the provider role by placing a system on the market under your own name or substantially modifying an existing one. The role determines the scope of obligations and should be documented.
Does the AI Act replace data protection law?
No. The AI Act and the GDPR apply side by side and pursue different aims: the AI Act addresses product safety and fundamental rights, data protection law addresses the processing of personal data. In Switzerland the revFADP remains the central framework, whether or not the AI Act bites.
Sources
- Regulation (EU) 2024/1689 (EU AI Act) · EUR-Lex
- Swiss Federal Act on Data Protection (FADP, SR 235.1) · Fedlex – Swiss Federal Chancellery
Related reading
Bring AI into your company securely.
Try Custodos with your team – and see how quickly secure AI becomes productive.
- Try it with the whole team
- Set up in minutes
- Productive from day one
