The European AI Act: What It Means for Businesses Using AI
The EU AI Act is now the world's first comprehensive AI law, with obligations phasing in through 2027. A practical guide to the risk tiers, the timeline, and what companies – including Swiss ones – need to do.

Table of Contents
“Does the EU AI Act even apply to us?” – it is one of the questions we hear most often from companies in the region, and the answer surprises many of them: quite possibly yes, even from Switzerland. The European Union’s Artificial Intelligence Act (the “AI Act”) is the first comprehensive legal framework for AI anywhere in the world. It entered into force on 1 August 2024, and its obligations are switching on in stages through 2027. If your business builds, sells, or simply uses AI systems, it changes what you are responsible for – and, in some cases, it applies to you even without an office in the EU.
The good news: for most companies this is far more manageable than the headlines suggest. In this post we walk through the Act’s structure, the compliance timeline, and the concrete steps worth taking now – with particular attention to Swiss businesses, which sit outside the EU but rarely outside its reach.
A risk-based law, not a technology ban
The Act does not regulate “AI” as a single thing. It sorts systems into four tiers by the risk they pose to health, safety, and fundamental rights, and attaches obligations proportionate to each tier.
| Risk tier | What it covers | What the Act requires |
|---|---|---|
| Unacceptable | Social scoring, manipulative or exploitative systems, most real-time remote biometric identification in public, untargeted facial-image scraping, emotion recognition at work and school | Banned outright |
| High | AI in medical devices, critical infrastructure, hiring and HR, credit scoring, education, law enforcement, and other listed uses | Risk management, data governance, human oversight, logging, technical documentation, conformity assessment |
| Limited | Chatbots, AI that generates or manipulates content (incl. deepfakes) | Transparency: tell people they are interacting with AI, and label synthetic content |
| Minimal | Spam filters, recommendation engines, most everyday AI | No mandatory obligations; voluntary codes encouraged |
Here is the reassuring part: the vast majority of business AI – analytics, productivity tools, recommendation systems – falls into the minimal-risk bucket and carries no new legal obligations at all. The real work concentrates in the high-risk and limited-risk tiers, so the first task for any company is simply an honest inventory of which of its systems land there.
The obligations depend on your role
The Act assigns duties by role, not just by system. The two that matter most for the majority of companies are:
- Providers – you develop an AI system (or a general-purpose AI model) and put it on the market under your own name or brand. Providers carry the heaviest obligations.
- Deployers – you use an AI system under your own authority in a professional context. Most businesses are deployers. Your duties are lighter but real: use high-risk systems according to instructions, ensure human oversight, monitor operation, and keep logs.
A single organisation can be both. Importantly, if you take a third-party high-risk system and put your own name on it, substantially modify it, or repurpose it for a high-risk use, you can inherit the full provider obligations. Fine-tuning or wrapping someone else’s model is not automatically a free pass.
General-purpose AI models get their own rules
Foundation models – the large language and multimodal models that sit underneath tools like chatbots and copilots – are regulated as general-purpose AI (GPAI). Providers of GPAI models must supply technical documentation, publish a summary of the data used for training, and put a policy in place to respect EU copyright law. Models judged to carry systemic risk (very high-capability models above a compute threshold) face additional duties: model evaluations, adversarial testing, incident reporting, and cybersecurity safeguards.
For most companies this matters indirectly: you are a downstream user of these models, and you will rely on your model provider’s documentation to meet your own transparency and risk obligations. Choosing providers who publish this material – and not locking yourself into a single one – is now part of doing compliance well. (We make the broader case for a multi-provider AI strategy in a separate post.)
The timeline: obligations phase in through 2027
The Act does not land all at once. The dates that matter:
| Date | What applies |
|---|---|
| 1 Aug 2024 | The Act enters into force |
| 2 Feb 2025 | Bans on unacceptable-risk systems take effect; AI-literacy duty for staff begins |
| 2 Aug 2025 | Obligations for general-purpose AI models begin; governance bodies and national authorities stand up |
| 2 Aug 2026 | The bulk of the Act applies, including most high-risk system rules and transparency obligations |
| 2 Aug 2027 | Rules for high-risk AI embedded in regulated products (e.g. medical devices, machinery) apply |
As of mid-2026 the prohibitions, the AI-literacy obligation, and the GPAI rules are already live. The large wave of high-risk obligations arrives on 2 August 2026 – which for most companies is the deadline to plan around.
Penalties are on the GDPR scale – or higher
Enforcement has teeth. Fines are tiered:
- Up to €35 million or 7% of worldwide annual turnover (whichever is higher) for deploying prohibited systems.
- Up to €15 million or 3% for breaching most other obligations.
- Up to €7.5 million or 1% for supplying incorrect information to authorities.
For a mid-sized company, the turnover-percentage basis means exposure can dwarf any nominal cap. The point of listing these numbers is not to alarm – it is that, as with the GDPR, the reputational cost of an enforcement action often exceeds the fine itself, and both are entirely avoidable with a bit of groundwork.
Why this matters to Swiss businesses
Switzerland is not an EU member and is not bound by the AI Act directly. But the Act, like the GDPR before it, has extraterritorial reach. It applies to providers and deployers established outside the EU whenever:
- an AI system is placed on the EU market, or
- the output of the system is used within the EU.
A Swiss company that offers an AI-powered product to EU customers, or whose AI processes data on EU individuals, is squarely in scope. Beyond the legal text, EU-based clients and partners will increasingly demand AI Act conformity as a condition of doing business – the same “Brussels effect” that made GDPR compliance a de facto global standard.
Switzerland is also developing its own approach: the Federal Council has signalled it will align with international standards, including the Council of Europe’s AI Convention, and adapt Swiss law rather than copy the EU Act wholesale. Swiss businesses are therefore best served by building AI governance that satisfies the stricter EU requirements now, rather than waiting for a lighter domestic regime and retrofitting later.
What to do now
The Act rewards companies that treat compliance as ongoing governance rather than a one-off audit. A pragmatic starting sequence:
- Inventory your AI. List every AI system you build or use, including embedded features in SaaS tools and models accessed via API. You cannot classify what you cannot see.
- Classify by risk. Map each system to a tier. Flag anything touching hiring, credit, biometrics, critical infrastructure, or the other high-risk uses for closer review.
- Identify your role. For each system, are you a provider, a deployer, or both? This determines your obligations.
- Close the transparency gaps. For customer-facing chatbots and generative features, make sure users are told they are dealing with AI and that synthetic content is labelled – these obligations are among the first to bite.
- Raise AI literacy. The Act already requires that staff who operate AI systems have sufficient understanding of them. Training is a live obligation, not a future one.
- Document and govern. Establish who owns AI risk, keep records of decisions and data sources, and build the technical documentation you would need to demonstrate conformity.
None of this means holding back on AI. The Act is explicitly designed to enable trustworthy AI, not to prohibit it – and in our experience the companies that move fastest are precisely the ones that get their governance house in order early. Once the groundwork is done, new use cases can be assessed and shipped with confidence instead of stalling on legal uncertainty. Good governance is not the brake; it is what lets you keep your foot on the accelerator.
At Datia we help companies in the Lenzburg region, across Aargau, and beyond adopt AI responsibly – from mapping where AI already lives in your stack to building the multi-provider, well-governed architecture that makes compliance a byproduct of good engineering rather than a burden bolted on afterwards. If the AI Act has moved from headline to to-do list for your business, get in touch.
This article is a general overview and does not constitute legal advice. For obligations specific to your systems and jurisdiction, consult qualified counsel.
Not sure where to start?
Tell us what you need across Web, Cloud, Data or AI. The first call is free and without obligation. You'll talk directly to the engineer who'd do the work.
Related Articles

Cloud Migration for SMEs in Aargau: A Practical Guide
What a cloud migration costs for an SME in Aargau, how it works step by step, and what Swiss data protection requires – a practical guide from Datia in Lenzburg.

AI for SMEs: Five Use Cases That Are Proving Themselves Today
Five AI use cases proven in small and medium-sized businesses – from document processing to customer assistants. Explained in practical terms by Datia.

Claude Code vs Codex vs OpenCode: Choosing an AI Coding Agent
A practical engineering comparison of Claude Code, OpenAI Codex and OpenCode: workflow, model flexibility, security, pricing and how to choose.

