Cookies

We use cookies for analytics and advertising. You can accept all, keep only necessary, or customize your preferences. Cookie Policy

Digital Vantage LogoDigital Vantage Logo
  • About us
  • Offer
    • Websites
    • Web Applications
    • Applications
    • Technology consulting for companies
    • Online marketing and branding
  • Resources
    • Blog & News
    • Tools and calculators
    • Templates and checklists
    • Independent industry reports
  • Contact
Let's talk!
Digital Vantage LogoDigital Vantage Logo
  • About us
  • Offer
  • Resources
  • Contact
  • Szukaj w artykułach ⌘K
    • Websites
      Building a professional online presence
    • Web Applications
      Dedicated web applications - automate and grow your business!
    • Applications
      Custom solutions tailored to your business needs
    • Technology consulting for companies
      That support business Technology consulting for companies where technology has stopped keeping up with business
    • Online marketing and branding
      Designing logos, corporate colors and letterheads
    • Blog & News
      News from the digital world.
    • Tools and calculators
      Before you start talking to an agency, check how much your project should cost.
    • Templates and checklists
      Professional checklists for B2B companies
    • Independent industry reports
      Cyclical report programs based on publicly available sources
Let's talk!
Digital Vantage LogoDigital Vantage Logo

Digital Vantage
Tel+48 663 877 600, +48 22 152 51 05
Andriollego 34, 05-400 Warsaw
REGON: 540674000
EU VAT: PL5321813962

Services
  • Websites
  • Company websites
  • Landing page
  • Web applications
  • Mobile apps
  • MVP for startups
  • Software development
  • Technology consulting
  • Online marketing and branding
  • Website pricing
Digital Vantage
  • About us
  • Contact
  • Let's talk about your business
  • Partner programme
  • Resources for business
  • Site map
Articles and guides
  • Websites
  • Online stores
  • Starting a business online
  • Web applications
  • Business applications
  • Google Business Profile
  • SaaS software
  • Glossary
Industry reports
  • Polish web market price analysis
  • Website costs
  • Online store costs
  • Web application costs
  • Mobile app costs
  • SaaS tool costs
Tools and calculators
  • Website cost
  • Online store cost
  • Web application cost
  • Website maintenance cost
  • Online store TCO
  • Website speed test
  • Quiz: website or app
  • Quiz: which e-commerce platform
  • Quiz: WordPress or headless
  • Quiz: ready-made SaaS or custom
Checklists and templates
  • Launching a website
  • Website audit
  • E-commerce UX checklist
  • Store migration
  • Choosing a web agency
  • Website security
Follow Us
FacebookInstagram
© Digital Vantage - Warsaw, Poland
Cookie PolicyPrivacy PolicyConditions
English|Français
© 2026 Digital Vantage. All rights reserved.
Digital Vantage LogoDigital Vantage Logo

Digital Vantage
Tel+48 663 877 600, +48 22 152 51 05
Andriollego 34, 05-400 Warsaw
REGON: 540674000
EU VAT: PL5321813962

★ 5.0
Google reviews
24h
We reply on business days.
20+ yrs
in IT/B2B EMEA
100/100
Desktop PageSpeed
© Digital Vantage - Warsaw, Poland
Cookie PolicyPrivacy PolicyConditions
English|Français
© 2026 Digital Vantage. All rights reserved.

Table of Contents · 13 sections

In this article

  1. 01When the EU AI Act reaches a Swiss company
  2. 02AI rules in Switzerland: the FADP now, an AI bill in preparation
  3. 03The AI Act — what it is and what the July 2026 regulation changed
  4. 04Provider or deployer — who your company is under the AI Act
  5. 05What applies from when — duties by role
  6. 06Prohibited practices — what no company may do
  7. 07Art. 4 and AI literacy — what "supporting skills" means after the change
  8. 08Art. 50 — chat, agent, deepfake and texts: what a company must do
  9. 09High risk: when it concerns a small company and what applies from 2.12.2027
  10. 10Fines — what a company actually risks
  11. 11Who enforces the AI Act — and where a Swiss company can ask
  12. 12The AI Act and the FADP — two lists, not one
  13. 13The AI Act in a small company — a checklist
  1. Home›
  2. Blog & News from the Digital World›
  3. AI in business — where to start, what it costs and what the law says›
  4. EU AI Act for a Swiss business — when it applies, the FADP and fines
AI Act and AI rules·ChatGPT and AI tools·37 min reading time·44,652 characters·7,299 words

EU AI Act for a Swiss business — when it applies, the FADP and fines

QR Code

When the EU AI Act reaches a Swiss company, how the FADP already applies to AI, deadlines to 2028 and fines in euros, with a checklist for small businesses.

RE
Redakcja Digital VantageYour Partner in Business, Digital Vantage Team · Digital Vantage team is a group of experienced professionals combining expertise in web development, software engineering, DevOps, UX/UI design and digital marketing. Together we carry out projects from concept to implementation - websites, e-commerce stores, dedicated applications and digital strategies. Our team combines years of experience from technology corporations with the flexibility and immediacy of working in a smaller, close-knit structure. We work in agile methodologies, focus on transparent communication and treat each project as if it were our own business. The strength of the team is the diversity of perspectives - from systems architecture and infrastructure, frontend and design, to SEO and content marketing strategy. As a result, the client receives a cohesive solution where technology, aesthetics and business goals go hand in hand.
Published7 Oct 2026
Updated8 Oct 2026

Whether the EU AI Act, the European regulation on artificial intelligence, concerns a Swiss company depends on one question: does your AI system, or its output, reach the EU? If it does, the AI Act is, for most small companies, not a compliance project but four concrete tasks: you do not use prohibited practices, you take measures that support the skills of people working with AI (Art. 4), you tell people they are dealing with AI and label deepfakes and some published texts (Art. 50), and if AI evaluates job candidates, employees or customers' creditworthiness you prepare for the duties for high-risk systems that start to apply on 2.12.2027. If it does not, the AI Act does not apply to you, but the Swiss Federal Act on Data Protection (FADP) already applies to AI.

Which duties apply to your company is decided by its role: provider of an AI system or deployer. It does not matter whether you pay for the tool. In the EU the authorities of the member states enforce the AI Act; there is no Swiss AI authority, and the fines are in euros. The Commission's AI Act Service Desk answers questions, including in your own language.

State of the law on 8.10.2026, after the amendment made by Regulation 2026/1744 of July 2026. This describes the rules and the official explanations of the Commission and the FDPIC, not legal advice: for any borderline case decide with a lawyer.

When the EU AI Act reaches a Swiss company

The AI Act reaches a Swiss company through Art. 2(1), and only where its AI system or the system's output reaches the EU. Art. 2(1) of the consolidated Regulation (EU) 2024/1689 applies to:

  • (a) "providers placing on the market or putting into service AI systems or placing on the market general-purpose AI models in the Union, irrespective of whether those providers are established or located within the Union or in a third country";
  • (b) "deployers of AI systems that have their place of establishment or are located within the Union";
  • (c) "providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union".

In practice: a Swiss company that offers its own AI system, for example a chatbot, to users in the EU is a provider under (a). A Swiss company that merely uses AI in Switzerland is not a deployer under (b), which concerns those established in the Union; it is caught by (c) only where the output of the system is used in the Union. Where exactly that line runs for, say, AI-written texts sent to EU clients is not settled in the texts we read, so describe the case to a lawyer.

An authorised representative only for high-risk systems and general-purpose models. Art. 22(1) says that, prior to making their high-risk AI systems available on the Union market, providers established in third countries shall, by written mandate, appoint an authorised representative established in the Union; Art. 54(1) imposes the same duty on providers of general-purpose AI models. An ordinary chatbot that is not a high-risk system does not need an EU representative under the AI Act. The representative keeps the documentation for ten years and cooperates with the authorities (Art. 22(3)).

Who enforces it and in what currency. The AI Act is enforced against a Swiss company by the market surveillance authorities of the member states (Art. 70); no Swiss authority enforces it. The fines are the euro caps of Art. 99, set out below. All the dates in this article are the EU's and bind a Swiss company only once Art. 2(1) is triggered.

AI rules in Switzerland: the FADP now, an AI bill in preparation

Switzerland has no AI act. The revised Federal Act on Data Protection (FADP) applies to AI now, and a consultation draft on AI regulation is due by the end of 2026. The Federal Chancellery writes on Regulation of AI: "In Switzerland, there is not yet any overarching legislation that deals specifically with AI."

The Federal Council's plan. On 12 February 2025 the Federal Council decided, in the words of the OFCOM press release, that "Switzerland intends to ratify the Council of Europe Convention on Artificial Intelligence (AI) and to make the necessary amendments to Swiss law", and that work on AI regulation in specific sectors such as healthcare and transport will continue. Switzerland signed the convention on 27 March 2025 (OFCOM). The Chancellery adds that a bill on AI regulation is to be submitted for consultation by the end of 2026, implementing the convention in particular on transparency, data protection, non-discrimination and supervision. The latest official status we found is the Federal Council's answer of 20 May 2026 to an interpellation in Parliament (26.3414, published in German, French and Italian only; our translation from the French): the Federal Department of Justice and Police is drawing up the draft that is to be presented to the Federal Council at the end of 2026, it is "still too early" to give concrete indications of the legislative changes, the draft should in principle also provide obligations for private actors where fundamental rights have a direct or indirect horizontal effect, and the aim is a level of protection of fundamental rights equivalent to that of the EU. As of 8 October 2026 we found no consultation opened, so the draft is a plan, not law.

The FADP applies to AI already. The FDPIC states in AI and data protection (24 September 2025) and in its update that the FADP, in force since 1 September 2023, "is directly applicable to AI-supported data processing", that "regardless of future regulations, the data protection provisions already in force must be complied with", and that manufacturers, providers and users of AI systems must make the purpose, functionality and data sources of AI-based processing transparent. It writes that "in the case of intelligent language models that communicate directly, users have a legal right to know whether they are speaking or corresponding with a machine and whether the data they have entered is being processed to improve self-learning programs or for other purposes", and that the law requires a data protection impact assessment in high-risk cases. This is the FDPIC's reading of the FADP's transparency principle, not an express article, so we do not write that Swiss law requires a chatbot label.

What the Act itself says (English version on Fedlex; it has no legal force, the French text is authoritative):

  • Art. 3(1): the Act applies to circumstances that have an effect in Switzerland, even if they were initiated abroad.
  • Art. 21: the controller informs the data subject about any decision based exclusively on automated processing that has a legal consequence for or a considerable adverse effect on the data subject, and the person may request that the decision be reviewed by a natural person. This matters for AI that filters applicants or scores customers.
  • Art. 22 and 23: where processing is likely to result in a high risk to personality or fundamental rights, a data protection impact assessment beforehand, in particular when using new technologies; if a high risk remains, the FDPIC is consulted.
  • Art. 60–64: a fine of up to CHF 250,000 on the responsible private person who acts wilfully (for example by failing to inform under Art. 19 and 21), prosecuted by the cantons; if the fine does not exceed CHF 50,000 and identifying the individuals would be disproportionate, the business can be fined instead (Art. 64(2)).

We found no Swiss statutory counterpart to Art. 4 (AI literacy), to the bans in Art. 5 or to the labelling duty in Art. 50 of the AI Act, so we describe those EU duties as applying only where Art. 2(1) is triggered.

The AI Act — what it is and what the July 2026 regulation changed

The AI Act is [Regulation (EU) 2024/1689](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727), which applies directly in every member state of the Union without being transposed into national law. It entered into force on 1.08.2024, but at that point it did not yet require anything. Art. 113 spreads its application over stages from 2.02.2025 to 2.08.2028, and the general date of application is 2.08.2026. Texts that say "the AI Act has applied since 1.08.2024" confuse entry into force with application of the provisions.

On its page on the AI Act (updated 3 August 2026) the European Commission divides AI systems into four risk levels: unacceptable, high, transparency risk and minimal. The Commission puts "the vast majority of AI systems currently used in the EU" in the last group, for example AI-enabled video games and spam filters, and for them the AI Act introduces no rules. That is the Commission's assessment, not a measurement.

An AI system is, under Art. 3(1), a machine-based system that is designed to operate with varying levels of autonomy and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations or decisions. In its non-binding guidelines on this definition (29.07.2025) the Commission notes that it is not possible to determine automatically which systems fall within it. Each tool is assessed separately.

The AI Act was amended in July 2026. Regulation (EU) 2026/1744 of 8.07.2026, named the "Digital Omnibus on AI" (the Commission calls it the AI Omnibus), was published on 24.07.2026 and entered into force on 27.07.2026. For a company that uses AI (for a Swiss company, only where Art. 2(1) is triggered) it changed five things:

  • the obligations for high-risk systems in Annex III apply from 2.12.2027, and for Annex I from 2.08.2028, where before it was 2.08.2026 and 2.08.2027;
  • Art. 4 on AI literacy received a new, milder wording;
  • new prohibitions were added (Art. 5(1)(ba) and (bb)), applying from 2.12.2026;
  • some of the simplifications provided for SMEs were extended to small mid-cap companies (Commission, 27.07.2026);
  • providers of generative systems placed on the market before 2.08.2026 have until 2.12.2026 to technically mark content under Art. 50(2).

Texts from before 27.07.2026 that write about high risk "from August 2026" are therefore out of date. We show all the dates from 2024 to 2028 on one timeline in the guide AI in business; here we arrange them by whom they concern.

Provider or deployer — who your company is under the AI Act

Your duties depend on your role, and for a company that uses AI two matter: provider and deployer. Art. 3(3) defines a provider as a body that develops an AI system or "has an AI system developed" and places it on the market or puts it into service under its own name or trademark, "whether for payment or free of charge". A deployer is, under Art. 3(4), a body "using an AI system under its authority", except where the system is used in the course of a personal non-professional activity.

A company whose employees use ready-made tools, such as ChatGPT, Copilot, Gemini or a ready-made chat on a website, is therefore a deployer. That includes a sole trader: Art. 2(10) excludes only deployers who are natural persons using AI systems "in the course of a purely personal non-professional activity". How a business plan of such a tool differs from a private one is compared in the article ChatGPT Business, Copilot or Gemini for business.

Who is your company under the AI Act: provider or deployer

Who is your company under the AI Act: provider or deployer

Regulation (EU) 2024/1689, Art. 2(1), 3(3)–(4) and 25(1); Commission guidelines on Article 50, C(2026) 5054, points (11)–(14); read 8 October 2026

Chart description

Decision diagram without numbers. First question, only for a Swiss company: does your AI system, or its output, reach the EU (Art. 2(1)(a) and (c))? If not, the AI Act does not apply and the FADP does; if yes, continue. Question one: did you build the AI system yourself, or commission its building, and do you run it under your own name or trademark? Yes: you are a provider. Question two: do you use another company's ready-made tool without changes? Yes: you are a deployer, and the provider is the maker of the tool. Question three: did you modify an existing generative system, for example with new training data, and do you run it under your own name? Yes: you are the provider of the new system. A separate path for high-risk systems: putting your own name or trademark on such a system, making a substantial modification, or changing its intended purpose so that it becomes high-risk makes you a provider. Grey box: intermediate cases, for example a ready-made SaaS chat configured and running under your own brand, are not settled in the guidelines: a lawyer or the AI Act Service Desk.

In its guidelines on Article 50 of 20.07.2026 the Commission gives three examples that settle the most common questions about role. The guidelines are not binding — an authoritative interpretation can ultimately only be given by the Court of Justice of the European Union — but they show how the Commission reads the rules:

  • A ready-made tool used without changes. A company that provides a generative or interactive AI application (a chatbot, an image generator, an AI agent) under its own name or trademark to users who may use it without modification is a provider. You, as its customer, are a deployer, also when you build the tool into your own processes.
  • A chat built in-house. A company that has developed a chat in-house and puts it into service for its own use under its own name is a provider.
  • A modified generative system. A company that takes an existing generative system placed on the market by another provider, modifies it, for example with new training data, and puts it into service under its own name becomes the provider of the new system.

The guidelines also explain that a deployer's authority means taking responsibility for the decision to deploy the system and for the manner of its actual use, and does not necessarily require technical control. Employees acting under the company's instructions are not separate deployers. A company remains a deployer even if it involves third parties, such as contractors or freelancers, to operate the AI on its behalf. A company that merely commissions an advertising agency to produce an advertisement, without taking decisions about whether and how the agency uses AI, is not a deployer.

For high-risk systems the rule is written in the regulation itself. Art. 25(1) treats any distributor, importer, deployer or other third party as a provider if they put their name or trademark on a high-risk system, make a substantial modification to it, or modify its intended purpose so that the system becomes high-risk.

There is a case the guidelines do not settle: a ready-made SaaS chat that you configure yourself. Your own instructions, your own knowledge base from which the chat answers (that is how RAG works), a widget in your brand colours, but no training of the model. That is neither "use without modification" nor "modification with new training data". Settle such a case with a lawyer or ask the Commission's AI Act Service Desk (see the section on authorities below).

What applies from when — duties by role

Some duties apply to every company from 2025, some only to providers, and the duties for high-risk systems start only in December 2027. The matrix below collects the dates from Art. 111 and 113 of the AI Act as amended by Regulation 2026/1744.

AI Act: which duty, who it applies to and from when

AI Act: which duty, who it applies to and from when

Regulation (EU) 2024/1689, Art. 111(4) and 113 as amended by Regulation (EU) 2026/1744; FADP (SR 235.1); FDPIC; Federal Council decision of 12 February 2025; read 8 October 2026

Chart description

Matrix: rows are duties, columns are who is affected and the date of application. These rows apply to a Swiss company only where Art. 2(1) of the AI Act is triggered. Prohibited practices (Art. 5): everyone, from 2.02.2025; new prohibitions in Art. 5(1)(ba) and (bb) (intimate material without consent and material depicting child sexual abuse): from 2.12.2026. AI literacy (Art. 4): providers and deployers, from 2.02.2025. Telling people they are dealing with AI (Art. 50(1)): provider, from 2.08.2026. Marking of content in a machine-readable format (Art. 50(2)): provider, from 2.08.2026, and for systems placed on the market before 2.08.2026 from 2.12.2026. Disclosure of deepfakes and of texts on matters of public interest (Art. 50(4)): deployer, from 2.08.2026. High-risk systems in Annex III: provider and deployer, from 2.12.2027. High-risk systems in Annex I: from 2.08.2028. Strip for Switzerland: the FADP has applied to AI since 1.09.2023 (FDPIC); an AI bill: a consultation draft is due by the end of 2026, no obligations yet.

  • Every company: the ban on the practices in Art. 5 and the duty in Art. 4 apply from 2.02.2025. The new prohibitions in letters (ba) and (bb) apply from 2.12.2026.
  • Provider: telling people they are dealing with AI (Art. 50(1)) and marking content (para. 2) from 2.08.2026. Only the marking has an exception: for systems placed on the market before 2.08.2026 the deadline is 2.12.2026. Telling people they are dealing with AI has no such transitional period (Commission questions and answers on Art. 50, updated 24.07.2026).
  • Deployer: disclosing deepfakes and some texts (Art. 50(4)) and informing about emotion recognition and biometric categorisation (para. 3) from 2.08.2026. The Art. 26 duties for high-risk systems from Annex III from 2.12.2027, from Annex I from 2.08.2028.
  • Switzerland: the rows above bind a Swiss company only where Art. 2(1) is triggered; at home the FADP has applied to AI since 1.09.2023, and the AI bill is still a plan with no obligations.

According to the Commission, from 2.08.2026 the AI Office and the authorities of the member states are responsible for implementing, supervising and enforcing the AI Act. The AI Office holds enforcement powers over general-purpose AI models; in the Commission's Q&A on Art. 50, compliance "will mainly be enforced by national competent market surveillance authorities". Who they are is covered in the section on enforcement below.

Prohibited practices — what no company may do

Art. 5 prohibits several uses of AI regardless of role and company size, and the ban has applied since 2.02.2025. In business terms:

  • subliminal and manipulative techniques, and exploiting people's vulnerabilities (age, disability, social or economic situation), that lead to significant harm;
  • social scoring;
  • assessing the risk that a person will commit a crime solely on the basis of profiling;
  • "untargeted scraping of facial images from the internet or CCTV footage";
  • emotion recognition in the workplace and in education;
  • biometric categorisation that infers race, political opinions, trade union membership, beliefs or sexual orientation;
  • real-time remote biometric identification in public spaces for law enforcement, with narrow exceptions.

For an employer the key one is letter (f). It prohibits "the placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons".

From 2.12.2026 two new prohibitions are added: AI systems that generate or manipulate realistic images, video or audio of an identifiable person's intimate parts or sexually explicit activities without that person's "freely-given, specific, informed, unambiguous and explicit consent" (letter ba), and material depicting the sexual abuse of children (letter bb). On its page the Commission counts them together as the ninth prohibited practice; in the regulation they are two new letters of Art. 5.

Breaching Art. 5 attracts the highest tier of fines: up to EUR 35 million or up to 7% of worldwide annual turnover (Art. 99(3)). On 4.02.2025 the Commission published guidelines on prohibited practices with explanations and examples; they are non-binding.

Art. 4 and AI literacy — what "supporting skills" means after the change

Where the AI Act reaches your company, Art. 4 requires a company that uses AI to take measures supporting people's skills, not to guarantee a specific level. After the July 2026 amendment the provision reads: providers and deployers of AI systems "shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf", taking into account their technical knowledge, experience, education and training and the context the systems are used in. It continues: "This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual." The duty has applied since 2.02.2025.

In its questions and answers on AI literacy (updated 27.07.2026) the Commission answers the questions every small company asks:

  • Does Art. 4 apply to a company whose employees use ChatGPT to write advertising copy or to translate? Yes. They should be informed about the specific risks, for example hallucination, that is a language model stating falsehood as fact.
  • Is a certificate needed? No. Organisations can keep an internal record of trainings and other guiding initiatives.
  • Do you have to appoint an "AI officer", like a data protection officer under the GDPR? No, no specific governance structure is mandated by Art. 4.
  • Do you have to measure employees' knowledge? No, Art. 4 does not entail that.

The Commission also describes the minimum: ensure a general understanding of AI in the organisation, consider your role (provider or deployer), consider the risk of the systems you use, and base concrete actions on that analysis. It warns that in many cases simply relying on the systems' instructions for use or asking staff to read them might be ineffective. Supervision of Art. 4 belongs to national market surveillance authorities, not the AI Office. For SMEs the Commission points to the European Digital Innovation Hubs (EDIHs, "more than 200 one-stop shops") and to the AI Skills Academy, which has operated since 1.05.2026.

An internal AI use policy is our recommendation, not a statutory requirement. One page that records which tools the company uses, for what, what data must not be pasted into them and who answers questions can also serve as an internal record of the measures taken.

A separate and future duty concerns high-risk systems: from 2.12.2027 oversight of them must be assigned to people who have "the necessary competence, training and authority, as well as the necessary support" (Art. 26(2)).

Art. 50 — chat, agent, deepfake and texts: what a company must do

Art. 50 splits the duties: the provider is responsible for telling people they are dealing with AI and for technical marking of content, and the company that uses AI for disclosing deepfakes and certain texts. For a Swiss company these duties matter where the AI Act reaches it; the FDPIC's reading of the FADP on chatbots is in the Swiss section above. The duties apply from 2.08.2026.

Chat and agent: the information at the latest at the first interaction

Art. 50(1) obliges the provider to design the system so that the persons concerned are informed that they are interacting with an AI system, "unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect". Para. 5 adds that the information must be given "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure" and must conform to the applicable accessibility requirements; who is bound by digital accessibility, and how, we cover in the article on WCAG.

According to the Commission's guidelines it is enough for a chat to start the conversation by mentioning that it is based on AI technology, or for an email generated by an AI agent to carry an AI label at the top. It is not enough to disclose it only in terms and conditions, URLs or documentation, to use unclear signals such as a generic reference to "assistant", a general statement like "Services on this website use AI", or a statement solely referring to the underlying technology such as "this system uses LLMs". The "obvious" exception should be interpreted restrictively, according to the Commission.

Three cases from the guidelines matter for customer service:

  • simple automated responses that are not based on AI, such as a traditional out-of-office email, are outside the provision;
  • a customer service representative who uses an AI assistance tool in the background to communicate is not covered by para. 1;
  • if AI-generated responses are blended with human ones, you label the generated ones, unless they have been properly reviewed and sent by a person as the main interlocutor.

On agents the guidelines are explicit: AI agents are covered by Art. 50(1) if they are capable of interacting with the persons instructing them or with other natural persons in the execution of their tasks, such as making bookings, managing correspondence, negotiating or concluding contracts or executing purchases. They must disclose both their artificial nature and the person on whose behalf they are acting. More about agents is in the article AI agent in business, and about a chat in an online shop and who is responsible for this duty with a ready-made bot, in the text on ecommerce customer service.

Marking content — a duty of the tool provider

Art. 50(2) requires providers of generative systems to ensure that outputs "are marked in a machine-readable format and detectable as artificially generated or manipulated". That is the work of the generator's maker, not of the company that uses it. The exception covers systems that perform an assistive function for standard editing.

Deepfakes and texts — a duty of your company

The rules contain no duty to label every piece of content created with the help of AI. Art. 50(4) concerns the deployer, that is you, and covers two things. If you publish images, audio or video that are a deepfake, you disclose that they have been artificially generated or manipulated. A deepfake is, under Art. 3(60), content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.

That is why the guidelines give an example from selling. An AI-generated image of a product in an advertisement or on packaging that can affect the audience's perception and mislead as to the actual product appearance, characteristics or use, for example by making it appear more appealing or of better quality than in real life, is a deepfake. A real product, such as a car, shown against an AI-generated background is not, as long as the advertisement is not likely to mislead about the product itself. Colour correction, background extension or re-scaling of product images is likely to have only a minor impact, according to the Commission. Where to legally get photographs for a website is covered in the text on images for a company website.

You disclose a text only if you publish it to inform the public on matters of public interest. The Commission excludes advertising and product descriptions, unless they contain claims about, for example, health, consumer safety or sustainability, and also private correspondence and internal texts. As an example of a text in scope it gives a corporate report published on a listed company's website containing investor information.

A text on matters of public interest does not need labelling if two conditions are met at once. First, a person with relevant knowledge has reviewed its substance; fact-checking is the minimum according to the Commission, and spell-checking or grammar correction is not enough. Substantial changes made by AI after sign-off void that review. Second, a person, a company or a function (for example the editor-in-chief) bears editorial responsibility, and their identity and contact details are publicly available in an easily findable place.

Content generated before 2.08.2026 does not have to be labelled retroactively, unless you publish it on or after that date. The Commission and the AI Board have confirmed the code of practice on transparency of AI-generated content as an adequate voluntary tool to demonstrate compliance; according to the Commission's press release of 31.07.2026 more than 180 organisations signed it. To label content you may voluntarily use the icons created by the EU. Copyright in AI-generated content is a separate topic, outside the AI Act; we touch on it in the article on logo design.

High risk: when it concerns a small company and what applies from 2.12.2027

Where the AI Act reaches your company, a system becomes high-risk through its use, and for a typical small company the first such use is recruitment. High risk is associated with face recognition, but in a small company it is usually the HR function that meets it. Annex III point 4(a) covers "AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates". On its page on the AI Act the Commission gives CV-sorting software for recruitment as an example: a tool that screens applications itself and ranks candidates.

Letter (b) of the same point covers systems for decisions on terms of employment, promotion and termination, for allocating tasks based on behaviour or personal traits, and for monitoring and evaluating the performance of workers. The other areas of Annex III that can concern SMEs are:

  • evaluating the creditworthiness of natural persons or establishing their credit score, except for detecting financial fraud (point 5(b));
  • risk assessment and pricing in life and health insurance (point 5(c));
  • education and vocational training: access, evaluating learning outcomes, monitoring during tests (point 3);
  • biometrics, including emotion recognition (point 1).

The exception in Art. 6(3): an Annex III system is not high-risk if it does not materially influence the outcome of decision-making, because it performs a narrow procedural task, improves the result of a previously completed human activity, detects patterns without replacing human assessment, or performs a preparatory task. The exception does not work when the system profiles people: such a system "shall always be considered to be high-risk". Check a tool that evaluates candidates on their characteristics from exactly that angle. We know the Commission's guidelines on classification only from the draft consulted until 23.07.2026.

From 2.12.2027 a company that uses a high-risk system from Annex III must, under Art. 26:

  • use it in accordance with the provider's instructions for use;
  • assign human oversight to people who have the necessary competence, training and authority, as well as the necessary support (para. 2);
  • ensure that input data is relevant, to the extent it controls it;
  • monitor the operation of the system and, where it considers that the system poses a risk, without undue delay inform the provider or distributor and the relevant market surveillance authority, and suspend use of the system (para. 5);
  • keep the logs for at least six months;
  • before using the system at the workplace, inform workers' representatives and the affected workers (para. 7); the information follows "the rules and procedures laid down in Union and national law and practice on information of workers and their representatives", so the details depend on the member state;
  • inform natural persons who are subject to decisions the system helps to take that it is used on them (para. 11);
  • use the information from the provider in the data protection impact assessment under the GDPR (para. 9).

There is an exception for systems placed on the market or put into service before that date: the regulation applies to them only if they are subject to significant changes in their designs later (Art. 111(2); systems intended for public authorities have a separate deadline, 2.08.2030). Whether an update of a tool you buy by subscription is such a change, settle with a lawyer.

A fundamental rights impact assessment (Art. 27) does not concern a typical SME: it covers public bodies, private entities providing public services, and private companies that use systems for credit scoring or for life and health insurance. The duties of providers of high-risk systems, that is conformity assessment, documentation and registration, are a separate and heavier package, which the July 2026 amendment partly simplified for SMEs and small mid-cap companies.

A chat on a website and an AI agent are not high-risk systems by their nature: as with recruitment, the task you use them for decides.

Fines — what a company actually risks

The AI Act has three tiers of fines, and for SMEs the lower of the two amounts counts: the amount in euros or the percentage of turnover. For a Swiss company the AI Act fines can only come from a member state authority, after Art. 2(1) is triggered. Art. 99 provides for:

  • up to EUR 35 million or up to 7% of total worldwide annual turnover for the preceding financial year for prohibited practices (para. 3);
  • up to EUR 15 million or up to 3% for breaches of, among others, deployers' obligations under Art. 26 and transparency obligations under Art. 50 (para. 4);
  • up to EUR 7.5 million or up to 1% for supplying incorrect, incomplete or misleading information to authorities (para. 5).

For large companies the higher amount applies. For SMEs, including start-ups, each fine "shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower" (para. 6). After the July 2026 amendment the same rule applies to small mid-cap companies, but only for the thresholds in paragraphs 4 and 5 (para. 6a).

Upper limits of AI Act fines in euros, with a Swiss SME example and the FADP fine

Upper limits of AI Act fines in euros, with a Swiss SME example and the FADP fine

Regulation (EU) 2024/1689, Art. 99(3)–(6); FADP, Art. 60–63; our calculation, assumed turnover CHF 5 million; read 8 October 2026

Chart description

Horizontal bars for the EUR caps, and text rows for a Swiss example, our calculation. Prohibited practices, Art. 99(3): up to EUR 35 million or 7% of worldwide annual turnover. Breach of, among others, Art. 26 and Art. 50, Art. 99(4): up to EUR 15 million or 3%. Incorrect or misleading information to authorities, Art. 99(5): up to EUR 7.5 million or 1%. Example for a company with an assumed turnover of CHF 5 million, in a different currency from the caps: 7% is CHF 350,000, 3% is CHF 150,000 and 1% is CHF 50,000; for SMEs the lower of the two amounts applies, and the results are far below the caps at any plausible rate. Separate box, a different legal nature: FADP Art. 60–63, up to CHF 250,000, a fine on the responsible individual, intentional breaches only, prosecuted by the cantons. These are upper limits, not expected fines.

The calculation (our arithmetic): for a company with an assumed annual turnover of CHF 5 million the percentages give CHF 350,000 (7%), CHF 150,000 (3%) and CHF 50,000 (1%). We show them in francs because the percentage applies to the company's own turnover. The caps are in euros and the example is in francs: the EUR caps are in the law, we do not convert them to francs because there is no legal rate, and the "lower of the two" result holds at any plausible exchange rate, since CHF 350,000 is far below EUR 35 million. How an authority of a member state converts a turnover that is not in euros is set by national rules, not by the AI Act. These are upper limits in an example with an assumed turnover, not expected fines.

The actual size of a fine is set by the authority. Art. 99(7) lists the circumstances it takes into account, including the size, annual turnover and market share of the company and its degree of cooperation, and para. 1 requires member states to take into account the interests and economic viability of SMEs. Who inspects, the procedure, the appeal routes and any reductions are set by each member state; the AI Act fixes the ceilings and the factors. Depending on the legal system, fines may be imposed by national courts or other bodies, with effective judicial remedies and due process (Art. 99(9) and (10)).

Art. 4 is not on the list of breaches in Art. 99(4).

The Swiss fine is of a different kind. Under Art. 60–63 FADP a fine of up to CHF 250,000 can be imposed on the responsible private person who wilfully breaches, for example, the information duties of Art. 19 and 21 (automated individual decisions). The FDPIC's page on criminal law says: "They are intentional offences only." "They primarily sanction individuals." and that the cantonal prosecution authorities prosecute them. Under Art. 64(2) the business can be fined instead if the fine does not exceed CHF 50,000 and identifying the responsible individuals would be disproportionate. This is not a company turnover fine and does not belong on the euro scale above.

Who enforces the AI Act — and where a Swiss company can ask

The EU AI Act is enforced by the authorities of the member states, not by a Swiss one, and a Swiss company has two practical places to ask: a lawyer and the Commission's AI Act Service Desk. Under Art. 70(1) each member state establishes or designates as national competent authorities at least one notifying authority and at least one market surveillance authority; where there are several, one is designated as the single point of contact, and the Commission makes the list of those points publicly available (Art. 70(2)). The Commission's page on market surveillance authorities under the AI Act (last updated 7 September 2026) says that the list is updated continuously and that, for the contact points marked with an asterisk, the national designation decision is still pending final adoption. As of that list several member states had not yet finally designated their contact point; if a member state fails to designate an authority, the Commission may launch a formal infringement procedure.

National authorities "may provide guidance and advice on the implementation of this Regulation, in particular to SMEs, including start-ups" (Art. 70(8)). The word is "may": there is no EU-wide right to a binding opinion, and any binding-ruling procedure is national. The Commission's AI Act Service Desk offers a compliance checker, a tool that assists in evaluating whether AI systems and general-purpose AI models meet the requirements, and a team of experts to whom you can submit questions, "including in your own language". We found no statement on whether its answers are binding, so we do not call them binding.

The AI Act and the FADP — two lists, not one

The AI Act does not replace data protection law: if an AI tool processes personal data, the FADP applies in any case, and the AI Act too where it reaches you. The FDPIC writes that, regardless of future regulations, the data protection provisions already in force must be complied with, and that manufacturers, providers and users of AI systems must make the purpose, functionality and data sources of AI-based processing transparent (FDPIC).

Before a tool is used on customer or employee data, you need (our reading of the FADP) a processor contract with the provider (Art. 9 FADP), information for the people whose data goes into the tool, a data protection impact assessment where processing is likely to result in a high risk (Art. 22), and knowledge of where the data is stored. If a tool is meant to take decisions about people on its own, remember Art. 21 FADP (information about automated individual decisions and the right to have them reviewed by a person). If you also serve people in the EU, the GDPR may apply alongside the FADP; we do not assess when. How to find out where company data lives is covered in the piece on company data security, and what the privacy notice on a website must contain in Privacy policy — what the Swiss FADP requires.

The AI Act in a small company — a checklist

Ten points organise what we described above; it is our list, not an official one, and it does not replace a legal assessment.

First, the Swiss question: does your AI system, or its output, reach the EU (Art. 2(1))? If not, the AI Act does not apply and the FADP does: of the list below, the inventory (1), the contracts (8) and the FADP check (9) still matter. If you offer a high-risk system on the EU market, you also need an authorised representative in the Union (Art. 22; for general-purpose AI models Art. 54); an ordinary chatbot does not.

  1. List the AI tools and uses in the company: what you use, who and for what, on what data.
  2. Determine the role for each tool: provider or deployer (the section on roles and the diagram).
  3. Check that no use is prohibited, especially emotion recognition of employees (Art. 5).
  4. Take the Art. 4 measures matched to roles and risk and record them internally; no certificate is needed.
  5. Chat and agent: if you are the provider, tell people it is an AI in the first message, also in emails sent by an agent, together with the person on whose behalf it acts (Art. 50(1) and (5)); if you use a ready-made tool, check that the provider does it.
  6. Deepfakes and public texts: labelling or, for texts, substantive human review and openly assigned editorial responsibility (Art. 50(4)).
  7. Recruitment, appraisal of employees, scoring: a plan to adapt by 2.12.2027 (Art. 26).
  8. Contracts with providers: a data-processing contract, and if you yourself are the provider of a high-risk system, also the written agreement with the supplier of tools or models mentioned in Art. 25(4).
  9. FADP check for every use on personal data: processor contract (Art. 9), information, impact assessment where the risk is high (Art. 22), automated decisions (Art. 21); keep the completed check.
  10. In doubt: a lawyer, the Commission's AI Act Service Desk with its Compliance Checker and contact in your own language, and for data protection the FDPIC.
FAQ

Frequently asked questions about the AI Act

Only where Art. 2(1) is triggered: if you offer an AI system to users in the EU (provider, Art. 2(1)(a)), or if the output of your system is used in the EU (Art. 2(1)(c)). A Swiss company that only uses AI in Switzerland is not a deployer under Art. 2(1)(b), which covers deployers established in the Union. Where the line runs for AI-written deliverables sent to EU clients is not settled in the texts we read, so ask a lawyer. In Switzerland itself, the FADP has applied to AI since 1 September 2023.

Not as a deployer in the EU sense, unless the output is used in the Union. The FADP applies in any case where personal data is processed: the FDPIC says users have a right to know whether the data they entered is processed to improve self-learning programs or for other purposes. Where the AI Act does reach you, a company whose employees use ChatGPT at work is a deployer: Art. 4 has applied since 2 February 2025 and the European Commission explains that no certificate is needed and that employees' knowledge need not be measured.

Not for an ordinary chatbot. Art. 22 of the AI Act requires providers established in third countries to appoint an authorised representative in the Union only for high-risk AI systems, and Art. 54 only for general-purpose AI models. The Art. 50 duty to tell users they are talking to an AI still applies, and has since 2 August 2026; it needs no representative.

Only where the AI Act reaches you, and not all of them. According to the Commission's guidelines of 20 July 2026, advertisements and product descriptions generated by AI are not subject to the text-labelling duty unless they contain claims about, for example, health, consumer safety or sustainability. You label a deepfake, and a generated product photo that shows the product better than it is can be one. Texts on matters of public interest are labelled unless a person has reviewed them substantively and editorial responsibility is public. The guidelines are not binding.

Art. 99 provides for up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3% for breaches of, among others, Art. 26 and Art. 50, and up to EUR 7.5 million or 1% for misleading information to authorities. For SMEs the lower of the two amounts counts. In our example of a company with an assumed turnover of CHF 5 million the upper limits are CHF 350,000, CHF 150,000 and CHF 50,000; that is a maximum, not an expected fine. The caps are in euros because the law states them in euros. The separate Swiss FADP fine, up to CHF 250,000, falls on the responsible individual for intentional breaches.

There is no Swiss AI authority that rules on it. You can use the Commission's AI Act Service Desk, which offers a compliance checker and, according to the Commission, contact also in your own language; we found no statement that its answers are binding. For data protection questions the FDPIC is the Swiss supervisory authority, and a lawyer decides borderline cases.

Are you deploying a chat or an AI agent? Let us design it with an AI label, limits and a person in the loop from day one

We leave the legal qualification to a lawyer — we build the system so that the Art. 50 duties can be met.

Let's talk about your business!

Related Posts

    • AI in business — where to start, what it costs and what the law says

      AI in business without the hype: where Swiss firms stand, when an assistant is enough and when you need an agent, what it costs, the FADP and the EU AI Act.

      • 1.
        ChatGPT Business, Copilot or Gemini for business — plans, prices and data

        ChatGPT Business, Copilot or Gemini in Switzerland: what a business plan changes, price per user in CHF, FADP processor rules and what your suite has.

      • 2.
        AI agent in business — what it is and when it makes sense

        An AI agent is a system where a language model chooses its own steps and tools. When an agent makes sense in a business, what it costs, the FADP and the AI Act.

About the Team

Digital Vantage Team

Your Partner in Business, Digital Vantage Team

Digital Vantage team is a group of experienced professionals combining expertise in web development, software engineering, DevOps, UX/UI design and digital marketing. Together we carry out projects from concept to implementation - websites, e-commerce stores, dedicated applications and digital strategies. Our team combines years of experience from technology corporations with the flexibility and immediacy of working in a smaller, close-knit structure. We work in agile methodologies, focus on transparent communication and treat each project as if it were our own business. The strength of the team is the diversity of perspectives - from systems architecture and infrastructure, frontend and design, to SEO and content marketing strategy. As a result, the client receives a cohesive solution where technology, aesthetics and business goals go hand in hand.

Share:

FacebookTwitterLinkedInWhatsAppMessengerDiscord

Table of Contents · 13 sections · 37 minutes read

In this article

  1. 01When the EU AI Act reaches a Swiss company
  2. 02AI rules in Switzerland: the FADP now, an AI bill in preparation
  3. 03The AI Act — what it is and what the July 2026 regulation changed
  4. 04Provider or deployer — who your company is under the AI Act
  5. 05What applies from when — duties by role
  6. 06Prohibited practices — what no company may do
  7. 07Art. 4 and AI literacy — what "supporting skills" means after the change
  8. 08Art. 50 — chat, agent, deepfake and texts: what a company must do
  9. 09High risk: when it concerns a small company and what applies from 2.12.2027
  10. 10Fines — what a company actually risks
  11. 11Who enforces the AI Act — and where a Swiss company can ask
  12. 12The AI Act and the FADP — two lists, not one
  13. 13The AI Act in a small company — a checklist

Comments

Rate this article

No comments yet. Be the first to share your thoughts!

Related Articles

Back to the guide: AI in business — where to start, what it costs and what the law says

⇲
Image on the Digital Vantage website

ChatGPT Business, Copilot or Gemini for business — plans, prices and data

ChatGPT Business, Copilot or Gemini in Switzerland: what a business plan changes, price per user in CHF, FADP processor rules and what your suite has.

Data publikacji: 08/10/2026
Characters: 30663•Words: 4881•Reading time: 25 min
⇲
Image on the Digital Vantage website

AI agent in business — what it is and when it makes sense

An AI agent is a system where a language model chooses its own steps and tools. When an agent makes sense in a business, what it costs, the FADP and the AI Act.

Data publikacji: 05/10/2026
Characters: 29418•Words: 4923•Reading time: 25 min
⇲
Image on the Digital Vantage website

AI in business — where to start, what it costs and what the law says

AI in business without the hype: where Swiss firms stand, when an assistant is enough and when you need an agent, what it costs, the FADP and the EU AI Act.

Data publikacji: 04/10/2026
Characters: 23008•Words: 3821•Reading time: 20 min
⇲
Website Builders.

Web page builders - The complete guide

Practical step-by-step guide: preparing materials, SEO setup, avoiding mobile and reload errors. When to order a migration.

Data publikacji: 14/02/2026
Characters: 16174•Words: 2543•Reading time: 13 min
⇲
SEO copywriting for websites

SEO copywriting — four rules Google contradicts in its own words

No 60-character title limit and no keyword density appear in Google's documentation. Four quotations, and the data on what AI Overviews do to clicks.

Data publikacji: 23/01/2026
Characters: 19487•Words: 3004•Reading time: 16 min
⇲
How to create content for businesses that attracts customers and converts

Content marketing — what actually happens to content after you publish it

Google shows 14% of our articles. What Google documents about content written for search, what scaled content abuse is, and where to start instead.

Data publikacji: 13/01/2026
Characters: 23758•Words: 3647•Reading time: 19 min
⇲
Professional Website Images and Graphics - Entrepreneur's Guide 2026

Images for a company website — where to get them legally and when you need your own

Stock photos are under copyright; only the licence is free. What Unsplash and Pexels forbid, where stock is fine, where it is not, and what WebP saves.

Data publikacji: 03/01/2026
Characters: 16407•Words: 2441•Reading time: 13 min
⇲
Obsługa klienta w e-commerce: jak ograniczyć „gdzie jest paczka?” i zostawić czas na sprzedaż

Ecommerce Customer Service: Fewer "Where Is My Order?" Tickets

Ecommerce customer service in Switzerland: fewer WISMO tickets, complaint handling under Swiss law, chatbot disclosure and two support metrics that matter.

Data publikacji: 02/11/2025
Characters: 14809•Words: 2208•Reading time: 12 min
⇲
Tresci Produktowe SEO

Product Description SEO: Writing Product Content That Meets Google and Merchant Center Requirements

Product description SEO: what Google expects, Merchant Center title/description limits, the 500×500 px image rule, GTIN and the duplicate content myth.

Data publikacji: 29/10/2025
Characters: 14936•Words: 2172•Reading time: 11 min