EU AI Act in Switzerland: Why There Is No Swiss Application Date, Only Extraterritorial Reach
Switzerland is neither EU nor EEA, so the EU AI Act never becomes Swiss law. It binds Swiss companies only through Article 2 when they touch the EU market.
Only via the EU market. Switzerland is neither an EU Member State nor an EEA member, so the EU AI Act never becomes Swiss domestic law and there is no Swiss application date to wait for. The trap is to read "we are not in the EU, so the Act does not apply to us" as a clean exemption — correct as to Swiss domestic law, wrong for any company that touches the EU market, because Article 2 reaches Swiss providers and deployers regardless of where they are established. For a Swiss company, Article 2 extraterritorial reach is not an interim bridge but the entire and permanent basis on which the Act can ever apply.
Switzerland, the EU, and why there is no automatic application
Switzerland sits in an unusual position among Europe's non-EU states. It is not in the EU, and unlike Norway, Iceland, and Liechtenstein, it is not in the European Economic Area either.
Not EU, not EEA: a third-country position
For the purposes of the EU AI Act — Regulation (EU) 2024/1689 — Switzerland is a third country, full stop. EU single-market legislation does not extend to it automatically, and the Regulation is never incorporated into Swiss law. There is no transposition step (the Act is a directly applicable Regulation inside the EU, not a Directive) and no EEA incorporation step (Switzerland is outside the EEA). The consequence is blunt: there is no Swiss commencement date for the EU AI Act, and there never will be one.
Why Switzerland is different from Norway
Norway, Iceland, and Liechtenstein are EEA states. EU single-market law reaches them through the EEA Agreement: an act assessed as EEA-relevant is incorporated by the EEA Joint Committee and then taken into domestic law. Switzerland declined EEA membership in a 1992 referendum and has since relied on bilateral agreements with the EU, none of which incorporates the AI Act. So while a Norwegian company may eventually see the Act become domestic law through EEA incorporation, a Swiss company never gets that domestic application event at all.
The mistake: reading no-EEA as no-obligation
The reasoning trap is to treat "no transposition, no incorporation" as "no obligation." It is true that the Act imposes no Swiss domestic duty. It is false that a Swiss company on the EU market is therefore free of it. Article 2 reaches Swiss companies by virtue of their contact with the EU market, not by any Swiss legal step. The evolving Swiss AI-governance debate is a separate matter, treated later as context, not a source of binding EU AI Act obligations.
Article 2: the only route the EU AI Act reaches a Swiss company
For a Swiss company, Article 2 is not one route among several. It is the only route, with no domestic backstop sitting behind it, so understanding its limbs is the whole game.
Placing AI on the EU market (Article 2(1)(a))
Under Article 2(1)(a), a provider placing an AI system on the EU market or putting it into service in the Union is in scope regardless of where that provider is established. A Swiss provider headquartered in Zurich, Geneva, or Zug is caught the moment it sells an AI product to customers in the Union. Non-EEA status changes nothing; selling into the Union moves you inside the Regulation.
Output used in the Union (Article 2(1)(c))
Under Article 2(1)(c), a provider or deployer established in a third country is in scope where the output of the AI system is used in the Union. The effect lands in the EU, not where the company or its servers sit. Article 2(1)(b) separately catches deployers of AI systems located within the Union, relevant to Swiss groups running EU-based operations. Swiss companies already know this logic from data protection: under the FADP and the GDPR, the hook follows the EU-based person or the EU use, not the headquarters.
Why Switzerland has no domestic backstop
This is where Switzerland diverges sharply from Norway. Because there is no EEA incorporation, there is no domestic-law backstop and no later Swiss enforcement forum that ever switches on. For a Norwegian company, Article 2 is an interim bridge until incorporation completes; for a Swiss company, it is the entire and permanent basis of application — nothing behind it, nothing coming after. For the full Article 22 authorised-representative mechanics, see the dedicated extraterritorial guide.
Timeline: the EU dates are fixed and there is no Swiss date
Use the EU-wide statutory calendar as your only anchor. A Swiss company on the EU market has no Swiss date to fall back on, so the EU dates are the only ones that matter. Do not invent a separate Swiss date.
| Milestone | EU date | What it means for a Swiss company |
|---|---|---|
| Article 5 prohibited practices; Article 4 AI literacy | 2 February 2025 | In force and enforceable on the EU market now; not delayed |
| GPAI obligations (Articles 51–55) | 2 August 2025 | In force now; not delayed |
| General application incl. Article 50 transparency | 2 August 2026 | EU date; no separate Swiss date exists |
| Stand-alone high-risk (Article 6(2), Annex III) | 2 August 2026 (statute) | Deferred to 2 December 2027 — adopted (Digital Omnibus) |
| Product-embedded high-risk (Article 6(1), Annex I) | 2 August 2027 (statute) | Deferred to 2 August 2028 — adopted (Digital Omnibus) |
The fixed EU calendar applies through Article 2
The statutory dates are set by the Regulation itself and are identical across the EU. Article 5 prohibited practices and Article 4 AI literacy have applied since 2 February 2025; GPAI obligations under Articles 51–55 since 2 August 2025. These are live now for any Swiss company on the EU market. Switzerland gets no separate substantive deadline, because nothing incorporates the Act into Swiss law.
The Digital Omnibus high-risk deferral
The high-risk dates have moved, and the deferral is now adopted. Stand-alone Annex III high-risk (Article 6(2)) reads 2 August 2026 in the statute, deferred to 2 December 2027 under the Digital Omnibus. Product-embedded Annex I high-risk (Article 6(1)) reads 2 August 2027, deferred to 2 August 2028. The European Parliament adopted both on 16 June 2026 and the Council on 29 June 2026; the package enters into force on publication in the Official Journal, expected before 2 August 2026. Both deferral dates are now settled.
No Swiss date, ever
Not everything is delayed, and the "stop the clock" proposal to pause the timeline was rejected. The distinction from Norway is sharp: a Norwegian company might see EEA incorporation lag the EU dates, but a Swiss company has no incorporation event whatsoever. The EU dates are the only ones that will ever exist for it.
Swiss AI-governance context (flagged, not overstated)
This is context for legal review, not a source of EU AI Act obligations. Treat it cautiously.
A separate Swiss track, not EU AI Act transposition
Switzerland has been developing its own approach to AI regulation and has signed the Council of Europe Framework Convention on Artificial Intelligence. That is a distinct instrument and does not implement the EU AI Act. Any Swiss domestic AI rules, sectoral law, or the existing data-protection regime under the FADP are separate obligations. We deliberately do not name a Swiss AI act, enforcement authority, or commencement date here, because the landscape is unsettled; treat those specifics as matters for legal review against the live position.
Why Swiss rules do not displace Article 2
Even if Switzerland adopts domestic AI rules, a Swiss company on the EU market still owes the full EU AI Act obligations through Article 2. Domestic and EU obligations stack; they do not substitute. Clearing a future Swiss regime would not discharge a single Article 2 duty owed to the EU market, so Swiss compliance is not a substitute for EU AI Act readiness.
What in-scope Swiss obligations look like
Equivalent obligations, same Regulation text
Once Article 2 applies, Swiss providers and deployers face the identical Regulation text and figures as their EU competitors. There is no lighter Swiss-specific regime and no Swiss-specific fine amounts; the obligations and penalties are the EU ones.
Provider stack vs the Article 2(2) product route
Roles map identically: provider, deployer, importer (Article 23), distributor (Article 24). A deployer, distributor, or importer becomes a provider under Article 25 on putting its own name or trademark on a high-risk system, substantially modifying it, or changing its intended purpose. Stand-alone Annex III high-risk takes the full provider stack directly: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness (Articles 9–15), conformity assessment (Article 43), the EU declaration of conformity (Article 47), registration (Article 49), and provider obligations (Article 16). The product route differs: Annex I product-embedded high-risk routes through the listed sectoral law under Article 2(2) — do not apply Articles 9–15, 16, or 43 directly to Annex I Section B categories.
Article 22 authorised representative for Swiss providers
A non-EU-established provider of a high-risk system — and a Swiss provider is squarely non-EU-established — must appoint an Article 22 authorised representative in the Union before placing the system on the market. GPAI model providers face the equivalent obligation under Article 54. Penalties are the Article 99 tiers, calculated on worldwide turnover: €35 million or 7%, whichever is higher, for Article 5 breaches (Article 99(3)); €15 million or 3% for high-risk provider breaches (Article 99(4)); €7.5 million or 1% for supplying incorrect or misleading information (Article 99(5)). Only for SMEs and start-ups does Article 99(6) flip the calculation to the lower of the fixed amount or the percentage.
Worked example: a Swiss insurtech placing a health-insurance pricing model on the EU market
HelvetiRisk AG is a roughly 140-employee Zug-based insurtech with about CHF 28 million (around EUR 29 million) in annual revenue, selling an AI risk-scoring and pricing model to health insurers in Germany and Austria.
Why HelvetiRisk is in scope now under Article 2(1)(a)
As a provider placing the system on the EU market, HelvetiRisk is in scope under Article 2(1)(a) today. Its Swiss seat and non-EEA status change nothing, and there is no Swiss date to wait for. Contact with the EU market is the trigger; the Zug headquarters is irrelevant.
Annex III point 5(c) classification and the Article 5 gate
AI used for risk assessment and pricing in life and health insurance is high-risk under Annex III point 5(c), triggering the Articles 9–15 provider stack, Article 43 conformity assessment, and Article 49 registration. Before any of that, HelvetiRisk must clear the hard gate at Article 5: no biometric categorisation inferring sensitive attributes under Article 5(1)(g) may feed the pricing model. A prohibited practice is not curable by documentation; it is simply banned.
Authorised representative, documentation, and penalty exposure
Because HelvetiRisk is not established in the EU or EEA, it must appoint an Article 22 authorised representative in the Union before market placement, and build the Article 11 / Annex IV technical documentation and the Article 47 / Annex V EU declaration of conformity. On exposure, a high-risk provider breach sits in the Article 99(4) tier — €15 million or 3% of total worldwide annual turnover, whichever is higher. As an SME (fewer than 250 staff and turnover at or below EUR 50 million), HelvetiRisk benefits from the Article 99(6) cap at the lower of the two, so 3% of roughly EUR 29 million turnover is the operative ceiling — and that lower-of cap applies only because it qualifies as an SME. Build to the adopted 2 December 2027 high-risk deadline under the Digital Omnibus.
What Swiss companies should do now
Act on the EU timeline, not a Swiss one
Do not wait for a Swiss date — there is none. If you place AI on the EU market or your output is used in the Union, Article 2 binds you on the EU timeline today. Treating Switzerland's non-EU position as an exemption is the trap.
A five-step starting checklist
- Map your AI systems against Article 2 to confirm EU-market touchpoints or EU output use.
- Classify each system, clearing the Article 5 hard gate before any Article 6 / Annex III assessment.
- Assign roles — provider, deployer, importer, distributor — and run the Article 25 conversion check on anything you rebrand, modify, or repurpose.
- For high-risk systems where you are a non-EU-established provider, appoint an Article 22 authorised representative before market placement.
- Build the compliance file: risk management, Annex IV documentation, conformity assessment, and the Annex V declaration of conformity.
Two tracks to monitor
Track the Digital Omnibus adoption status that governs the high-risk dates, and separately monitor the Swiss domestic AI-governance track for legal review. Treat the two as stacking, not substituting. And classify accurately rather than over-scoping: ordinary business analytics, ITSM, and defensive cybersecurity tooling are not Annex III use cases.
How Confir helps Swiss companies
Confir derives your provider, deployer, importer, or distributor role and classifies your systems under Articles 5 and 6 with Annex III logic from plain-language intake. The engine is deterministic and rule-based — no model inference, no hallucination — so the same intake yields the same audit-defensible finding with a human-readable explanation of which rule fired.
Confir generates the Article 11 / Annex IV technical documentation pack and the Article 47 / Annex V declaration of conformity, and supports the Article 27 Fundamental Rights Impact Assessment where it applies. The aim is to position Swiss companies to be ready against the EU calendar regardless of Swiss domestic developments. The GPAI workflow (Articles 51–55) is partial and on the roadmap, not complete. Confir is EU-hosted, at confir.eu.
Related guides
- EU AI Act extraterritorial reach for non-EU companies
- EU AI Act in Norway: the EEA incorporation route
- EU AI Act scope explained (Article 2)
- EU AI Act deadlines and application dates
- market surveillance authority (glossary)
Manage your EU AI Act compliance in one place
Confir automates risk classification, technical documentation, and audit trails for any company. No consultants. No 6-month projects. 14-day free trial.
Start free trial →