EU AI Act: the August 2026 deadline and what Swiss SMEs should do now
The EU AI Act applies to Swiss companies via the marketplace principle. Who it affects, what the risk classes mean, and a five-step roadmap.
The EU AI Act affects Swiss SMEs despite their non-EU location, as soon as their AI outputs are used in the EU. What matters is the marketplace principle: not where the company is based, but where the AI output is put to use.
In short: If your AI serves customers in the EU, the AI Act’s obligations apply. The level of obligation depends on the risk class, not on your company size.
Does the EU AI Act affect Swiss companies?
Yes, if their AI systems or the outputs are used in the EU. As with the GDPR, market access is enough, not the company’s seat. A Swiss SME serving EU customers with AI-based services falls within scope. The timeline is staggered; some obligations apply from 2025, others follow in 2026. The official schedule is documented in the AI Act implementation timeline.
The risk classes explained simply
The AI Act classifies AI systems by risk. Obligations rise with the risk class:
- Prohibited: practices such as social scoring or manipulative systems are banned.
- High risk: for example AI in hiring or credit decisions, with duties on documentation, data quality, and human oversight.
- Limited risk: transparency duties, such as disclosing that you are interacting with an AI.
- Minimal risk: most applications, with light requirements.
On top of this come duties for providers of general-purpose models (GPAI). Those who only use models rather than build them mainly carry transparency and due-diligence duties.
Five-step roadmap for SMEs
- Inventory: record where AI is used across the company, including informal shadow AI.
- Classification: assign each use case to a risk class.
- Transparency: label AI interactions and document purpose and data.
- Traceability: ensure a log that shows what the AI did.
- Governance: define responsibilities, rights, and an internal AI policy.
A platform with a complete audit trail and central rights management makes steps three to five considerably easier. What this looks like for small teams is on our page on AI for SMEs.
Common questions
Does an SME with no EU customers need to do anything?
Often not directly under the AI Act, but Swiss law and the duty of care still apply. An AI inventory and an internal policy are sensible in any case.
What about ChatGPT in the team?
Using third-party models also falls under transparency and data protection duties. An approved, documented platform is easier to control than private use.
Does AIgent help with traceability?
Yes. Every agent step is logged with model, time, and cost, so you can evidence the required traceability.