Insights · AI Governance

The EU AI Act applies to Swiss companies too: what matters now

It is not your registered office that decides, it is where your systems have effect. For most companies the effort is smaller than feared, provided you start early.

We are a Swiss company, the EU AI Act does not concern us. I hear that sentence often, and it is about as reliable as the same claim was in its day about the GDPR.

The AI Act attaches not to your location but to the effect of your systems. If you operate an AI system whose output is used in the EU, if you serve customers in the EU, or if you deploy a system at a subsidiary there, you fall within scope. For many Swiss companies at least one of these applies.

The good news first

The regulation is risk-based, and the large majority of business applications sit in the lowest tier. An assistant that summarises meeting notes, a tool for drafting text, search support across your own documents: all of these carry light requirements, essentially transparency towards users and adequate competence among the people working with them.

It becomes demanding in two areas: systems that influence decisions about people, and systems that are prohibited. Both can be clarified in a few hours per use case, provided you know which use cases exist in the first place.

The bottleneck is almost never the regulation. The bottleneck is the missing overview of your own systems.

Where companies unexpectedly land in the high-risk class

The high-risk class sounds exotic but covers widespread applications. Most often, companies trip over tools in HR.

  • Pre-selection or scoring of job applications, even where a person makes the final decision.
  • Systems that evaluate performance, prepare promotions or allocate tasks.
  • Creditworthiness and credit scoring of individuals.
  • Applications connected to access to essential services or insurance.

Prohibited practices include emotion recognition in the workplace, biometric categorisation by sensitive characteristics, and social scoring systems. The first of these turns up surprisingly often in product demonstrations of sales and call centre software.

The pragmatic plan

For a mid-sized company, the realistic effort is six to ten weeks spread across a handful of people. It consists of four steps.

  • Build an inventory: every system with an AI component, including purpose, data basis and the person responsible. Include bought-in systems, since a large share now sits inside standard software.
  • Classify: determine the risk class for each system. Most will land at the bottom, and having that documented is valuable.
  • Close the gaps: for the few relevant systems, add documentation, human oversight and transparency notices.
  • Ensure competence: people working with these systems must understand their limits. That is already a requirement today and the most frequently overlooked point.

What I advise leadership teams

Treat the AI Act not as a compliance project but as the occasion to build the overview you need anyway. The inventory from step one is at least as valuable for your strategy work as it is for the regulation: for the first time it shows you completely where AI is already in use across the company.

And expect surprises. Almost every inventory ends up listing systems the executive team knew nothing about: usually bought in, usually harmless, occasionally not.

Invitation

Let us discuss this in your context

Articles stay general. Your situation is not. In sixty minutes we translate the thinking to your starting point.

Book a sparring session

No preparation, no obligation.