Analysis

Between a rock and a hard place: how Swiss SMEs navigate global AI regulation

Aug 3, 2026

Lady Justice statue holding scales, against a blurred background.

EU AI Act, US deregulation, Chinese content obligations: Three jurisdictions, three philosophies, one product. What this means for Swiss companies selling abroad.

Imagine you are building an AI-powered HR tool. It screens job applications, supports hiring decisions, and runs on Swiss servers. Your customers are based in Frankfurt, Chicago, and Shanghai.

For the EU market, your system may fall under the high-risk rules of the EU AI Act starting December 2, 2027, provided it is used for certain employment and recruitment purposes, such as selecting, evaluating, or ranking candidates. If so, requirements around risk management, logging, human oversight, and cybersecurity will apply, among others.

If the tool is used for candidates in New York City, Local Law 144 may come into play. For certain Automated Employment Decision Tools, the city requires a bias audit conducted within one year prior to use, public availability of a summary, and specific notices to applicants or employees.

Switzerland currently has no overarching AI law. However, the federal data protection act (technology-neutral in scope) applies to private companies. Cantonal and municipal authorities are additionally subject to their respective cantonal data protection regulations. Particularly relevant are transparency obligations, data protection impact assessments, and the rights of individuals affected by qualified automated individual decisions.

And if you plan to expand into China, you will need to examine (depending on your product and operating model) additional requirements around content compliance, cybersecurity, cross-border data transfers, and potentially local data processing.

For a global product, this can give rise to significant conflicts in data flows, model operations, content moderation, and government access. A unified architecture is not categorically ruled out, but in practice, separate data and operational architectures may become necessary.

This is not a purely hypothetical scenario. It is the operational reality for Swiss SMEs that market AI products or AI-powered services internationally.

Three Jurisdictions, Three Regulatory Logics

Three distinctly different regulatory approaches are emerging for Swiss companies, even if none of these jurisdictions is entirely uniform.

The EU takes a preventive, risk-based approach. The AI Act Regulation (EU) 2024/1689 establishes a comprehensive legal framework for artificial intelligence and captures certain providers and users outside the EU as well. What matters is not only where a company is headquartered, but also whether an AI system is placed on the EU market, deployed within the EU, or whether its outputs are used there.

For certain high-risk applications in the employment sector, the core obligations apply (under the current legal framework) from December 2, 2027. For high-risk AI embedded in regulated physical products, the relevant date is generally August 2, 2028. This distinction is critical for manufacturers of machinery, medical devices, and other regulated products.

The underlying logic of the EU approach: risks should be identified, documented, and mitigated before market entry wherever possible. For the most serious violations (particularly of prohibited AI practices) fines of up to €35 million or 7% of global annual turnover may be imposed. Other violations are subject to graduated maximum thresholds.

The United States does not follow a unified approach to AI regulation. The federal government has rolled back key AI policy directives from the previous administration and shifted emphasis toward innovation and competitiveness. This does not mean, however, that AI applications are unregulated at the federal level. Anti-discrimination law, data protection, product liability, and sector-specific rules continue to apply.

For Swiss providers, this primarily creates a fragmented legal landscape made up of federal law, state statutes, and local ordinances. When an HR tool is deployed across multiple states or cities, no single rulebook governs. Instead, the specific deployment locations, affected individuals, data types, and decision-making functions must each be assessed separately.

China ties AI regulation closely to cybersecurity, data control, content requirements, and state oversight. The specific obligations depend on the product, the area of deployment, the data involved, and the operating model.

For Swiss providers, the challenge is less a blanket legal incompatibility with European rules and more the practical organization of data and operational processes. A product that must simultaneously meet European data protection requirements, Chinese data and content mandates, and the expectations of international enterprise customers may require separate data environments, model variants, and governance frameworks.

The Swiss Special Case

Switzerland is not an EU member but it is not a regulatory island either. This in-between position has real consequences.

Switzerland currently has no comprehensive AI law that companies must fully comply with. At the same time, it is not a legal vacuum. The Federal Act on Data Protection (FADP) has been in force since September 1, 2023, and applies directly to AI-driven data processing. The Federal Data Protection and Information Commissioner (FDPIC) has specifically highlighted transparency, purpose limitation, data sources, data protection impact assessments, and individual rights in automated decision-making.

For private companies, federal law is generally the governing framework. Cantonal and municipal authorities are additionally subject to their respective cantonal data protection rules. The canton of Zurich currently has no general cantonal AI law but that does not mean AI deployment is permissible without legal review.

In regulated sectors, existing sector-specific requirements already apply to AI applications today. These include governance, risk, security, and documentation requirements in financial services, as well as product and safety regulations in healthcare. Companies must therefore assess not only the EU AI Act and Swiss data protection law, but also FINMA requirements, medical device regulations, and other sector-specific obligations.

Switzerland does not offer its companies an automatic compliance pass for the EU market. Anyone exporting to the EU must meet the applicable obligations there — regardless of whether the system was developed, operated, or hosted on Swiss servers.

The MRA Problem: A Potential Conflict for Embedded AI

Switzerland has a Mutual Recognition Agreement (MRA) with the EU that enables the mutual recognition of conformity assessments in certain product sectors. It is a key component of Switzerland's export capacity, particularly for regulated products.

However, the existing MRA does not automatically extend to all new requirements under the EU AI Act. For products that incorporate AI as a safety-relevant component, it is therefore important to assess early on which legal acts apply, which conformity assessment procedure must be followed, and whether existing MRA coverage is sufficient.

This applies to products such as:

  • Medical devices with AI-assisted diagnostic support
  • Machinery with AI-based safety functions
  • Industrial robots
  • Intelligent testing and measuring equipment
  • Products in which an AI system performs safety-critical functions

Under the current EU legal framework, August 2, 2028 is generally the key application date for the high-risk rules governing embedded AI in such products. Depending on the product, the conformity assessment route, and MRA coverage, involvement of an EU-notified conformity assessment body may additionally be required. This is not, however, a blanket obligation for every AI-enabled product.

The practical implication remains significant: Swiss manufacturers should not wait until all technical and legal details are fully resolved. An early assessment by a qualified conformity assessment body can help avoid duplicated processes, delays, and unexpected costs.

What Is Already in Force — and What Can Wait

Not all obligations lie in the future.

Since February 2, 2025, certain AI practices have been prohibited in the EU. These include social scoring, certain forms of harmful manipulation, emotion recognition in the workplace and in educational settings, certain biometric categorizations, and certain forms of real-time remote identification.

Since August 2, 2025, the rules for providers of General-Purpose AI Models have applied. This affects in particular providers that place a general-purpose AI model on the EU market themselves. Depending on their role, obligations around documentation, transparency, copyright, and risk management apply. Providers headquartered outside the EU may also be required to appoint an authorized EU representative.

A Swiss provider of a specialized HR application is not automatically a provider of a General-Purpose AI Model. The decisive question is whether the company itself offers a general-purpose AI model or merely integrates a third-party model into a specialized application.

From August 2, 2026, the AI Act's general transparency obligations apply. These include disclosure requirements when users interact with certain chatbots, as well as requirements for the detectability of certain AI-generated content. Additional visible labeling obligations may apply to deepfakes and certain publicly relevant content.

The major high-risk obligations for certain applications in sensitive domains — including employment, education, migration, and critical infrastructure apply from December 2, 2027, following the entry into force of the AI Omnibus on July 27, 2026.

Compliance as a Market Advantage

The cost of full high-risk compliance varies significantly depending on the product, the data situation, existing quality management systems, and the area of deployment. For an SME, building a robust compliance framework can quickly run into six figures.

The return on that investment can be equally substantial. Large EU companies and public sector buyers are beginning to require compliance evidence in their supplier audits and procurement processes. A Swiss provider with clear documentation, reliable testing procedures, and a well-defined accountability structure can turn this into a concrete competitive advantage in sales conversations.

What to Do Now

The first step costs nothing: classify your own AI portfolio. Which AI applications do you develop yourself, and which do you deploy? For which markets? Who are your customers, and in which sectors do they operate? Most Swiss SMEs will find that they carry few obligations as users of standard SaaS and face clear action items as developers of specialized software.

The second step: identify jurisdictional conflicts. EU and the US simultaneously? Technically manageable if you build on EU standards. EU and China? Structurally challenging: separate product architectures will likely be required. Products subject to the MRA? Engage an EU Notified Body early, before deadlines start to bite.

S-GE supports Swiss SMEs throughout this process: from initial classification to connecting with specialized legal and compliance partners, and through on-the-ground market support: in the EU, the US, and beyond.

Angela Di Rosa

Senior Consultant Southeast Asia

Zürich, Switzerland

adirosa@s-ge.com

+41 44 365 54 73

Log in or register

Enter your email to continue.

Exclusive access for companies based in Switzerland or the Principality of Liechtenstein.