AI Risk

Law and standards

AI Act, Swiss law and AI standards: state and preparation

What will legally apply to AI is still open in Switzerland. I show what has to be checked in practice and what can already be prepared cleanly. Whether something applies to your company is for your lawyer to decide. The information is general, dated, and given without warranty of completeness or currency.

As of: 6 October 2026

What can already be prepared cleanly

Whether and when which duties apply is open. Much of what is likely to be required later is already sensible today and costs nothing that is lost later:

  • An inventory of AI systems with data and use.
  • An owner per system and a risk classification from the top down.
  • Data rules: what may go into AI tools, what may not, and where do the inputs land?
  • Acceptance criteria fixed before the first test, and evidence that can be kept.
  • A release process with a stop switch and monitoring in operation.

Which duties arise from this later is for your lawyer to decide.

Selected deadlines

As of 6 October 2026, without warranty. The EU AI Act details come from law-firm reports on Regulation (EU) 2026/1744 (Digital Omnibus); I have not read the Official Journal text myself. The table is a selection, not a complete list.

DateWhat appliesSource
1 September 2023The revised Swiss Data Protection Act (DSG) applies.Fedlex
12 February 2025The Federal Council decides to adopt the Council of Europe AI Convention, with sector-specific changes.BAKOM
2 August 2026The transparency duties under Article 50 of the EU AI Act apply.Regulation (EU) 2024/1689 (AI Act), Article 113
2 December 2026Deadline for labelling AI-generated content (Article 50(2)) for systems already on the market before 2 August 2026.Regulation (EU) 2026/1744
End of 2026A consultation draft on Swiss AI regulation is due.BAKOM
2 December 2027Duties for high-risk systems under Annex III apply.Regulation (EU) 2026/1744
2 August 2028Duties for high-risk AI in regulated products (Annex I) apply.Regulation (EU) 2026/1744

EU AI Act

The “Digital Omnibus” was passed in July 2026. High-risk systems under Annex III apply from 2 December 2027, those in regulated products (Annex I) from 2 August 2028. The transparency duties under Article 50 have applied since 2 August 2026; for labelling AI-generated content (Article 50(2)), systems already on the market before then have until 2 December 2026. The AI Act can also reach Swiss companies that offer AI in the EU or whose results are used in the EU. The details come from law-firm reports; I have not read the Official Journal text myself.

Gibson Dunn · Formalize

Switzerland

The Federal Council wants to adopt the Council of Europe AI Convention (decision of 12 February 2025), sector by sector, with a focus on transparency, data protection, non-discrimination and oversight. A consultation draft is due by the end of 2026. The revised Data Protection Act (DSG) already applies. The linked pages are in German.

BAKOM: Artificial intelligence · DSG on Fedlex

Standards and frameworks

ISO/IEC 42001:2023 is a certifiable management system for AI. ISO/IEC 23894 gives guidance on AI risk management. The NIST AI RMF 1.0 (Govern, Map, Measure, Manage) is voluntary; NIST AI 600-1 extends it to generative AI. ISO 14971 is the source of the harm-to-control thinking in medical devices.

ISO/IEC 42001 · ISO/IEC 23894 · NIST AI RMF · NIST AI 600-1 · ISO 14971

Answers

Do I need ISO/IEC 42001?

ISO/IEC 42001 is a voluntary, certifiable standard for an AI management system; it is not mandatory. A certificate confirms the management system, not that a specific model is safe in your use. Whether it is worth it depends on the requirements of your customers and your industry.

Does Swiss data protection law apply to AI applications?

The revised Swiss Data Protection Act (DSG) has applied since 1 September 2023 to the processing of personal data, including when AI is used. What that means for your project, for example for inputs into chat tools, is for your lawyer to decide. I show what has to be checked in practice.

What I cover and what not

What is the NIST AI Risk Management Framework?

The NIST AI Risk Management Framework (AI RMF 1.0, January 2023) is a voluntary framework with the four functions Govern, Map, Measure and Manage. It has no certification. NIST AI 600-1 extends it to generative AI.

Contact

Send me the use case in two sentences. I will get back to you and say whether and how your project can be tested. Whether I can take the job depends on my workload.

admin@all-answer.com
+41 76 511 52 25