EU AI Act August 2026: The Deployer Compliance Checklist for Swiss Companies

In short
From 2 August 2026, EU AI Act high-risk obligations apply to all deployers — including Swiss companies whose AI outputs are used in the EU. This article provides the complete obligation catalogue, an operational checklist, and concrete action steps for C-suite executives.
Deadline: 2 August 2026
From this date, all deployers of high-risk AI systems are fully subject to EU AI Act Art. 26 obligations — regardless of whether the company is headquartered in the EU or Switzerland, as long as outputs are used in the EU.
What Swiss Companies Need to Know Right Now
The EU AI Act is not an EU-only matter. Its extraterritorial scope (Art. 2(1)(c)) covers Swiss companies whose AI systems produce outputs used in the EU. Any organisation running AI-supported processes for EU customers, EU subsidiaries or EU employees is subject to deployer obligations — regardless of its registered headquarters.
The Swiss Data & AI Observatory 2026 (Colombus Consulting / Oracle / HEG, June 2026) reveals: 69% of Swiss companies are still in the exploration or experimentation phase for agentic AI, and 36% do not yet measure the tangible value of their AI projects at all. The 2 August 2026 deadline transforms a strategic question into a legal obligation.
The Deployer Obligation Catalogue under Art. 26 EU AI Act
Art. 26 EU AI Act defines seven core obligations for deployers of high-risk AI systems. These apply cumulatively — no single obligation substitutes for another.
- Follow the instructions for use: The system may only be used in accordance with the technical documentation provided by the provider.
- Ensure human oversight: Deployers must implement physical or organisational measures enabling genuine human supervision of the system — a confirmation click does not suffice.
- Control input data: The quality and relevance of input data is the deployer's responsibility. Poor data quality equals compliance risk.
- Maintain an audit log: All decisions influenced by a high-risk system must be logged. The minimum retention period is 6 months.
- Inform affected persons: Natural persons subject to decisions made by a high-risk system must be informed in clear, understandable language.
- Conduct a Fundamental Rights Impact Assessment (FRIA): Before deployment, a FRIA must be carried out and documented — especially in HR, credit and public services.
- Report serious incidents: Severe incidents or malfunctions must be reported immediately to the competent market surveillance authority.
Operational Checklist: What Must Be Done Before 2 August 2026
- AI system inventory completed
- Comprehensive list of all AI systems in use, classified by risk level (high-risk / limited / minimal)
- High-risk systems identified
- Cross-checked against Annex III EU AI Act: HR, credit, education, critical infrastructure, law enforcement
- Human-in-the-loop implemented
- Documented intervention capability before each material AI-driven decision — not a formality
- Audit log activated
- Automatic logging of all decisions with timestamp, system version, input hash and output — minimum 6 months retention
- FRIA conducted
- Fundamental Rights Impact Assessment documented and archived for each high-risk use case
- Information obligation addressed
- Process defined for informing affected persons about AI-driven decisions
- Provider contracts reviewed
- Confirmed that AI providers supply the required technical documentation (Art. 11)
- Incident management in place
- Clear ownership and escalation path for reporting serious AI incidents
AI Agents: The Critical Special Case
Autonomous AI agents that independently make or prepare decisions in HR, finance or customer service are almost always high-risk systems under Annex III. This means: any company today deploying AI agents in these domains is in all likelihood already subject to deployer obligations.
According to the 2026 Gartner Hype Cycle for Agentic AI (April 2026), AI agents sit at the Peak of Inflated Expectations — and this is precisely when compliance risk is greatest: companies deploy before governance structures are in place. Gartner warns that over 40% of all agentic AI projects will be cancelled by end 2027, often due to inadequate risk controls.
FINMA Context: Additional Requirements for Regulated Swiss Institutions
For banks, insurers and other FINMA-regulated entities, a dual obligation framework applies. In addition to EU AI Act deployer obligations, FINMA Circular 2023/1 on operational risks and the principle of explainability for model-based decisions must be observed. AI systems in credit origination or risk management must be explainable, auditable and interruptible at any time. Outsourcing to external AI providers additionally requires a FINMA-compliant outsourcing arrangement.
Sanctions and Enforcement
EU AI Act sanctions are substantial: violations of high-risk obligations can be fined up to EUR 15 million or 3% of global annual turnover — whichever is higher. For GPAI violations (in force since August 2025), the maximum sanction is EUR 35 million or 7% of global turnover.
Three Immediate Actions for Executive Leadership
- Commission an AI inventory: Task your IT department and Data Protection Officer this week with a complete audit of all AI systems — including employee-used tools accessing company data.
- Conduct a high-risk assessment: Review every use case against Annex III EU AI Act. When in doubt, classify as high-risk and fulfil the obligations proactively.
- Engage specialist counsel: The combination of EU AI Act, revDSG and FINMA requirements is complex. A Swiss law firm specialising in AI regulation can deliver an initial risk assessment in 2–4 hours.
Strategic Recommendation
Treat EU AI Act compliance not as a one-off project but as an ongoing governance process — analogous to data protection or ISO certification. AI agents within your organisation will only multiply.
Frequently asked questions
- Does the EU AI Act apply directly to Swiss companies?
- Not directly — Switzerland has not adopted the EU AI Act into national law. However, Art. 2(1)(c) has extraterritorial reach: any company worldwide whose AI system produces outputs used in the EU is subject to the Act. Swiss firms with EU customers, EU subsidiaries or EU employees are therefore highly likely to be captured.
- What does the EU AI Act mean by 'deployer'?
- A deployer is any natural or legal person that uses an AI system in a professional context — not the party that developed it (that is the provider). In practice, any company using AI tools from third-party vendors (e.g. Microsoft Copilot, Salesforce Einstein, Workday AI) is a deployer subject to Art. 26 EU AI Act.
- What are the specific obligations for a deployer of a high-risk AI system?
- The seven core obligations under Art. 26 EU AI Act are: (1) follow instructions for use, (2) ensure human oversight, (3) control input data, (4) maintain an audit log (minimum 6 months), (5) inform affected persons, (6) conduct a Fundamental Rights Impact Assessment (FRIA), and (7) report serious incidents. These obligations apply cumulatively.
- Are AI agents automatically classified as high-risk systems?
- Not automatically, but frequently. AI agents operating in HR, credit, education, critical infrastructure or law enforcement fall under Annex III EU AI Act and are classified as high-risk. Autonomous agents that prepare or independently make decisions in these domains are almost always affected.
- What are the sanctions for non-compliance with deployer obligations?
- Violations of high-risk deployer obligations can be fined up to EUR 15 million or 3% of global annual turnover — whichever is higher. Violations of GPAI provisions carry a maximum sanction of EUR 35 million or 7% of global turnover.
- Do FINMA-regulated institutions face additional requirements?
- Yes. Swiss banks and insurers are subject to both the EU AI Act and FINMA Circular 2023/1 on operational risks, including the principle of explainability for model-based decisions. AI systems in credit or risk management must be explainable, auditable and interruptible. Outsourcing to AI providers requires a FINMA-compliant outsourcing arrangement.
Sources
- EU AI Act Art. 26 – Obligations of Deployers
- Gartner: 40% of Enterprise Apps Will Feature Task-Specific AI Agents by 2026
- Gartner: Over 40% of Agentic AI Projects Will Be Canceled by End of 2027
- Gartner Hype Cycle for Agentic AI 2026
- Schweizer Daten- und KI-Observatorium 2026 (Colombus Consulting / Oracle / HEG)
- Lenz & Staehelin: EU AI Act Update für Schweizer Unternehmen
- FINMA Rundschreiben 2023/1 – Operationelle Risiken und Resilienz
Would you like to explore this topic for your company?
Check Availability