
The European Union has agreed on a set of rules governing the use of AI. This legal framework aims to strengthen public trust in AI while protecting safety and fundamental rights. On December 8, 2023, the European Commission, the Council of the European Union, and the European Parliament reached a political compromise on the AI Act. The AI Act applies to AI systems introduced or used in the EU and to those that have an impact on individuals in the EU. The AI Act is expected to enter into force in the first quarter of 2024. A two-year implementation period will then follow. Although it will be some time before the regulation becomes relevant for Swiss companies, it is advisable to familiarize oneself with the current draft now. Given its extraterritorial effect, the AI Act could become significant for Swiss companies, particularly if they offer an AI system on the EU market or if the data generated by their AI system is used in the EU.
This briefing provides an overview of the AI Act. It is followed by a discussion of the potential implications of the AI Act for Swiss companies. However, certain changes may still be made in the final version.
New guidelines have been introduced for AI systems to regulate situations in which they are used for a wide range of purposes (general-purpose AI) and later integrated into high-risk systems. The preliminary agreement also takes into account specific cases of general-purpose AI (GPAI) systems. It is crucial to note that so-called “highly effective” foundation models also fall under the category of foundation models. However, there are differences that should be taken into account: Clear regulations have been established for foundation models—that is, large systems[1]. According to the provisional agreement, they must meet certain transparency requirements before they can be brought to market. Stricter regulations have been introduced for “high-impact” foundation models. These models are trained on extensive datasets and are characterized by above-average complexity, capabilities, and performance. They have the potential to propagate systemic risks throughout the entire value chain.
The regulation of AI systems is based on their potential risks to society and fundamental rights. The categorization is divided into the following risk levels: A distinction is made between i) an unacceptable risk, ii) a high risk, iii) a limited risk, and iv) a minimal or no risk:
(i) Unacceptable risk
This risk level covers AI systems that pose a significant threat to society and to the fundamental rights of individuals. AI systems are considered unacceptable if they violate the values of the European Union, such as fundamental rights. The use of these systems is strictly prohibited and must be discontinued within six months of the AI Act taking effect. Examples include:
(ii) High-risk AI systems
AI systems are considered high-risk if they pose a high risk to the health and safety or to the fundamental rights of natural persons. In accordance with the risk-based approach, such high-risk AI systems are permitted on the European market provided they meet certain mandatory requirements and undergo a conformity assessment in advance. Examples of such AI systems include:
iii) Low-risk systems
This category of AI systems includes systems that pose low risks. Low-risk systems are those where there is a risk of manipulation. Such AI systems must meet specific transparency requirements so that users can make informed decisions. Users should be aware that they are interacting with an AI system. Examples include:
The examples mentioned above must be designed in such a way that users perceive them as artificially generated or artificially manipulated.
iv) Systems with minimal or no risk
Systems in the category of those with minimal or no risk may be developed and used in compliance with generally applicable law. No additional legal obligations are to be introduced. Providers of such systems may voluntarily commit to complying with codes of conduct. This category includes, for example, AI-powered video games, spam filters, or AI used to sort documents in offices.
The AI Act will impose heavy fines. Among other things, the following fines are expected[2]:
A fine of up to 35 million euros or 7 percent of global annual revenue is provided for violations of prohibited uses or failure to comply with data and data governance requirements.
In addition, a fine of up to 15 million euros or 3 percent of global annual revenue may be imposed for violations of other requirements or obligations under the Regulation, including violations of the provisions regarding GPAI models.
Finally, companies may be fined up to 7.5 million euros or 1.5 percent of their global annual revenue if they provide false, incomplete, or misleading information in responses to requests for information from notified bodies and competent national authorities.
Swiss companies that develop or use an AI system are urged to closely monitor when the AI Act takes effect and to prepare accordingly.
Next, companies should determine whether the AI Act applies as a first step. The Act applies if they offer their AI system in the EU, if their AI system is deployed, imported, or used in the EU, or if the output of their AI system is used in the EU. If this is the case, the second step is to determine which risk category their AI system falls into.
If a Swiss company uses AI systems that pose unacceptable risks, it must discontinue their use within six months of the AI Act taking effect. If a company uses AI systems with limited risk, it must ensure that it complies with the transparency requirements or other obligations by the time the AI Act takes effect.
When dealing with high-risk AI systems, Swiss companies must, in particular, review or implement the following checklist:
Checklist for High-Risk AI Systems
Is there AI governance in place? Yes/No
Information notices to ensure compliance with transparency requirements. Yes/No
Is there a process in place to ensure data quality and governance when training AI systems? Yes/No
Are risk management systems needed, or do they need to be expanded as needed? Yes/No
Are cybersecurity measures being implemented? If such measures are in place, they should be reviewed and updated as needed. Yes/No
Are there procedures in place for conformity assessment? If so, existing sector-specific conformity assessment procedures should be expanded as needed. Yes/No
Has a procedure been established for conducting a fundamental rights impact assessment? It can build on previous experience with data protection impact assessments. Yes/No
Has a procedure been implemented to ensure human oversight? Yes/No
Is the use of high-risk AI systems documented in technical terms? Yes/No
Has the AI system been registered with the relevant authorities? Yes/No
On November 22, 2023, the Federal Council decided to evaluate AI regulation in Switzerland. The goal was to ensure that the potential of AI can be harnessed while simultaneously mitigating risks such as discrimination or misinformation. Possible approaches to regulating AI in Switzerland are to be identified by the end of 2024. Swiss companies are therefore advised to monitor the current development of the AI Act and make appropriate adjustments as needed. This is particularly important given that Swiss policymakers are increasingly focusing on the regulation of AI and are expected to follow the guidelines set forth in the AI Act.
What’s next? The AI Act still needs to be formally adopted to become law. It is expected to take effect in the first quarter of 2024. The AI Act will become applicable two years after it takes effect. However, it should be noted that the ban on AI systems posing unacceptable risks will take effect six months after the Act takes effect, and the provisions regarding GPAI will take effect twelve months after the Act takes effect.
[1] Large systems are capable of performing a wide range of different tasks, such as generating video, text, and images; conversing in natural language; performing computations; or generating computer code.
[2] For fines, the higher of the two amounts is used. That is, if 7% of annual revenue is greater than EUR 35 million, that amount is used as the fine.
Do you have any questions about this topic, or would you like a personal consultation? Write to us—we’re happy to help.