DE
Understanding the AI Act: What Is It and How Does It Affect You?

A Closer Look at the AI Act

What the EU AI Act regulates and what requirements Swiss companies may face when using and developing AI.

1. Introduction

The European Union has agreed on a set of rules governing the use of AI. This legal framework aims to strengthen public trust in AI while protecting safety and fundamental rights. On December 8, 2023, the European Commission, the Council of the European Union, and the European Parliament reached a political compromise on the AI Act. The AI Act applies to AI systems introduced or used in the EU and to those that have an impact on individuals in the EU. The AI Act is expected to enter into force in the first quarter of 2024. A two-year implementation period will then follow. Although it will be some time before the regulation becomes relevant for Swiss companies, it is advisable to familiarize oneself with the current draft now. Given its extraterritorial effect, the AI Act could become significant for Swiss companies, particularly if they offer an AI system on the EU market or if the data generated by their AI system is used in the EU.

This briefing provides an overview of the AI Act. It is followed by a discussion of the potential implications of the AI Act for Swiss companies. However, certain changes may still be made in the final version.

2. Classification of AI Systems


  a) AI systems as foundational models

New guidelines have been introduced for AI systems to regulate situations in which they are used for a wide range of purposes (general-purpose AI) and later integrated into high-risk systems. The preliminary agreement also takes into account specific cases of general-purpose AI (GPAI) systems. It is crucial to note that so-called “highly effective” foundation models also fall under the category of foundation models. However, there are differences that should be taken into account: Clear regulations have been established for foundation models—that is, large systems[1]. According to the provisional agreement, they must meet certain transparency requirements before they can be brought to market. Stricter regulations have been introduced for “high-impact” foundation models. These models are trained on extensive datasets and are characterized by above-average complexity, capabilities, and performance. They have the potential to propagate systemic risks throughout the entire value chain.

  b) AI systems under the risk-based approach

The regulation of AI systems is based on their potential risks to society and fundamental rights. The categorization is divided into the following risk levels: A distinction is made between i) an unacceptable risk, ii) a high risk, iii) a limited risk, and iv) a minimal or no risk:

     (i) Unacceptable risk

This risk level covers AI systems that pose a significant threat to society and to the fundamental rights of individuals. AI systems are considered unacceptable if they violate the values of the European Union, such as fundamental rights. The use of these systems is strictly prohibited and must be discontinued within six months of the AI Act taking effect. Examples include:

  • Social scoring systems;
  • proactive policing:
  • Biometric identification systems in public spaces (except for specific law enforcement purposes):
  • the indiscriminate collection of facial images from the Internet or from video surveillance footage for the purpose of creating facial recognition databases;
  • Emotion recognition in the workplace and in educational institutions;
  • Children's toys with voice assistance that could lead to dangerous behavior in children;
  • An AI system that exploits the vulnerability or need for protection of a specific group of people based on their age or physical or mental disability in order to significantly influence the behavior of a person belonging to that group in a way that causes or is likely to cause physical or psychological harm to that person or to another person.

   (ii) High-risk AI systems

AI systems are considered high-risk if they pose a high risk to the health and safety or to the fundamental rights of natural persons. In accordance with the risk-based approach, such high-risk AI systems are permitted on the European market provided they meet certain mandatory requirements and undergo a conformity assessment in advance. Examples of such AI systems include:

  • AI systems for screening applicants during the hiring process;
  • AI in critical infrastructure (e.g., transportation, energy, gas);
  • AI used for creditworthiness checks or to assess individuals' creditworthiness; AI in product safety components (e.g., the use of AI in robot-assisted surgery);
  • biometric identification, categorization, and emotion recognition systems (unless they are completely banned) or AI systems designed to influence elections.

  iii) Low-risk systems

This category of AI systems includes systems that pose low risks. Low-risk systems are those where there is a risk of manipulation. Such AI systems must meet specific transparency requirements so that users can make informed decisions. Users should be aware that they are interacting with an AI system. Examples include:

  • "Chatbots" or "deep fakes";
  • AI-powered video games;
  • AI systems used in virtual assistants;
  • AI systems that use synthetic audio, video, text, or image data.

The examples mentioned above must be designed in such a way that users perceive them as artificially generated or artificially manipulated.

  iv) Systems with minimal or no risk

Systems in the category of those with minimal or no risk may be developed and used in compliance with generally applicable law. No additional legal obligations are to be introduced. Providers of such systems may voluntarily commit to complying with codes of conduct. This category includes, for example, AI-powered video games, spam filters, or AI used to sort documents in offices.

3. Sanctions

The AI Act will impose heavy fines. Among other things, the following fines are expected[2]:

A fine of up to 35 million euros or 7 percent of global annual revenue is provided for violations of prohibited uses or failure to comply with data and data governance requirements.

In addition, a fine of up to 15 million euros or 3 percent of global annual revenue may be imposed for violations of other requirements or obligations under the Regulation, including violations of the provisions regarding GPAI models.

Finally, companies may be fined up to 7.5 million euros or 1.5 percent of their global annual revenue if they provide false, incomplete, or misleading information in responses to requests for information from notified bodies and competent national authorities.

4. What must Swiss companies do?

Swiss companies that develop or use an AI system are urged to closely monitor when the AI Act takes effect and to prepare accordingly.

Next, companies should determine whether the AI Act applies as a first step. The Act applies if they offer their AI system in the EU, if their AI system is deployed, imported, or used in the EU, or if the output of their AI system is used in the EU. If this is the case, the second step is to determine which risk category their AI system falls into.

If a Swiss company uses AI systems that pose unacceptable risks, it must discontinue their use within six months of the AI Act taking effect. If a company uses AI systems with limited risk, it must ensure that it complies with the transparency requirements or other obligations by the time the AI Act takes effect.

When dealing with high-risk AI systems, Swiss companies must, in particular, review or implement the following checklist:

Checklist for High-Risk AI Systems

Is there AI governance in place? Yes/No

Information notices to ensure compliance with transparency requirements. Yes/No

Is there a process in place to ensure data quality and governance when training AI systems? Yes/No

Are risk management systems needed, or do they need to be expanded as needed? Yes/No

Are cybersecurity measures being implemented? If such measures are in place, they should be reviewed and updated as needed. Yes/No

Are there procedures in place for conformity assessment? If so, existing sector-specific conformity assessment procedures should be expanded as needed. Yes/No

Has a procedure been established for conducting a fundamental rights impact assessment? It can build on previous experience with data protection impact assessments. Yes/No

Has a procedure been implemented to ensure human oversight? Yes/No

Is the use of high-risk AI systems documented in technical terms? Yes/No

Has the AI system been registered with the relevant authorities? Yes/No

5. The Development of Switzerland

On November 22, 2023, the Federal Council decided to evaluate AI regulation in Switzerland. The goal was to ensure that the potential of AI can be harnessed while simultaneously mitigating risks such as discrimination or misinformation. Possible approaches to regulating AI in Switzerland are to be identified by the end of 2024. Swiss companies are therefore advised to monitor the current development of the AI Act and make appropriate adjustments as needed. This is particularly important given that Swiss policymakers are increasingly focusing on the regulation of AI and are expected to follow the guidelines set forth in the AI Act.

6. Conclusion

What’s next? The AI Act still needs to be formally adopted to become law. It is expected to take effect in the first quarter of 2024. The AI Act will become applicable two years after it takes effect. However, it should be noted that the ban on AI systems posing unacceptable risks will take effect six months after the Act takes effect, and the provisions regarding GPAI will take effect twelve months after the Act takes effect.

[1] Large systems are capable of performing a wide range of different tasks, such as generating video, text, and images; conversing in natural language; performing computations; or generating computer code.

[2] For fines, the higher of the two amounts is used. That is, if 7% of annual revenue is greater than EUR 35 million, that amount is used as the fine.

More Information

Would you like to learn more?

Do you have any questions about this topic, or would you like a personal consultation? Write to us—we’re happy to help.