AI Act, FADP and marketing: what Swiss companies need to know
When the European rules reach a Swiss SME, what Article 50 requires of marketing, and what the FADP already says today.
- Date
- August 18, 2026
- Category
- AI & Compliance
- Reading
- 10 min read
- Byline
- Outsmart Studio
The AI Act's transparency obligations have applied since 2 August 2026. A Swiss company can fall under them without being established in the EU: it is enough that the output is used in the Union.

Since 2 August 2026 the transparency obligations of Article 50 of the European AI Act have been in force, the ones covering chatbots, deepfakes and generated content. A Swiss company can fall under them even without an establishment in the EU: it is enough that the system's output is used in the Union. Switzerland has no AI law yet, but the FADP already applies today, as the FDPIC has made clear. This article is orientation, not legal advice.
- Transparency in force
- The obligations of Art. 50 of the AI Act have applied since 2 August 2026.
- High risk postponed
- The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved the obligations on high-risk systems to 2 December 2027 and 2 August 2028.
- It applies without an EU establishment
- A Swiss SME can fall under the AI Act with no establishment in the Union.
- No regulatory vacuum in Switzerland
- There is no AI law, but the FADP, the Unfair Competition Act, personality rights and copyright all apply.
- The GDPR has not changed
- The second Digital Omnibus, the one on data and the GDPR, is not law yet: at the end of June 2026 the compromise text was withdrawn in Council for lack of a majority.
- 2 February 2025
- Prohibitions (Art. 5) and AI literacy (Art. 4). In force.
- 2 August 2025
- GPAI models, governance, penalties. In force.
- 2 August 2026
- Transparency (Art. 50) and general application. In force.
- 2 December 2026
- End of the grace period for marking systems placed on the market before 2 August 2026. Imminent.
- 2 December 2027
- Stand-alone high-risk systems (Annex III). Deferred.
- 2 August 2028
- High risk embedded in products (Annex I). Deferred.
The Digital Omnibus softened Article 4: the literacy requirement moves from an obligation of result to an obligation of means. It remains enforceable: the authority will assess whether you did something, not whether every employee passed a test. For SMEs the package introduces simplified documentation and reduced penalty ceilings, and Art. 99(6) provides that the lower of the two amounts applies.
When the AI Act reaches a Swiss company
Article 2(1)(c) is the way in: the regulation applies to providers and professional deployers established in a third country “where the output produced by the AI system is used in the Union”.
- You sell or license an AI tool to EU clients
- White label included. Careful: here you risk sliding into the provider role, with far heavier obligations, even when the technology is someone else's.
- You produce content for campaigns published in the EU
- Visuals, video, synthetic voices or generated copy: the output is used in the Union.
- You run a chatbot aimed at EU users
- Or any AI service aimed at that audience.
- You supply AI analysis to an EU subsidiary or client
- The output crosses the border.
The practical test is targeting: deliveries to EU customers, targeted advertising, prices in euros. The mere fact that your Swiss site can be reached from Italy is not enough. But the line between “reachable” and “targeted market” has not yet been tested in case law: this is a case-by-case analysis, not a self-acquittal. The distinction of role matters too: a studio using generative tools for a client is typically a deployer, not a provider.
- Direct interaction, a provider obligation
- Anyone interacting with a chatbot has to know they are talking to an AI, unless it is obvious to a reasonably well-informed person.
- Machine-readable marking, provider
- Generated audio, images, video and text must be marked: watermarking, metadata, fingerprinting. The obligation sits with whoever provides the model, but the agency has to check that the tools comply and must not strip the markings. For systems already on the market, compliance by 2 December 2026.
- Deepfakes and public-interest text, deployer
- This is the heart of the matter for marketing. Anyone publishing images, audio or video that constitute a deepfake has to declare it, at the latest on first exposure. The exemption for artistic or satirical works exists, but must be exercised without getting in the way of enjoying the work.
- Emotion recognition and biometrics, deployer
- Inform the people exposed and comply with data protection law.
The European Commission published the final guidelines on Art. 50 on 20 July 2026 and deemed the Code of Practice on transparency of AI-generated content adequate. Anyone not signing up has to demonstrate the adequacy of their own measures individually.
If the broad reading of what counts as a deepfake holds, generated product visuals and synthetic voices in ads will have to be labelled too.
According to specialist analyses of the guidelines, the notion of a deepfake would be read broadly: any realistic content generated or modified by AI, with no need for real people to be depicted and regardless of deceptive intent, and commercial content would not benefit from the artistic exemption. This reading is still debated and its operational impact is enormous: check it against the official text before redesigning your processes. Penalties for breaching the transparency obligations reach 15 million euros or 3% of worldwide turnover.
Where Switzerland stands
On 12 February 2025 the Federal Council decided to ratify the Council of Europe Framework Convention on AI, signing it in Strasbourg on 27 March 2025. The underlying choice is a sector-based approach: no horizontal AI Act-style law, but regulation sector by sector, with cross-cutting adjustments limited to data protection and non-discrimination.
The Federal Office of Justice must draft a bill for consultation by the end of 2026; DETEC a plan of non-binding measures. As of August 2026 the draft has not yet been published: it is the Swiss regulatory event to watch in the final quarter. Ratification will follow the adoption of domestic legislation, realistically not before 2027-2028.
Meanwhile the FADP already applies
The FDPIC was blunt in a communication of 8 May 2025: the current data protection act applies directly to AI. The FADP is drafted in technology-neutral terms, so no new law is needed for you to be bound already.
- Transparency, Art. 19
- On purpose, operation and data sources. If you use foreign providers, the privacy notice has to state the destination country and the safeguards applied: this is the part almost everyone forgets.
- The right to know
- Whether you are talking to a machine, and whether your data, prompts included, will be used to train the models.
- Automated decisions, Art. 21
- If a decision rests solely on automated processing and has significant effects, the person concerned must be informed and can ask for human review.
- Impact assessment, Art. 22
- For high-risk processing. Predictive profiling, AI lead scoring or cross-channel personalisation are typically the moment it becomes necessary.
- Record of processing, Art. 12
- Companies under 250 employees are exempt, but the exemption falls away with high-risk profiling. A lot of data-driven marketing falls into the second case.
- Transfers abroad, Art. 16-17
- The United States has been deemed adequate since 15 September 2024, but only towards recipients certified under the Swiss-U.S. DPF. A breach exposes you to fines of up to 250,000 francs, payable by the responsible individual, not the company: that is the substantial difference from the GDPR.
One last note that doubles as a commercial argument: on 15 January 2024 the European Commission confirmed Switzerland's adequacy. EU data can keep flowing to you without additional safeguards, a concrete advantage for anyone serving Italian or German clients.
The figure that makes all this urgent
Set beside the other figure, that over 80% of the Swiss population trust a digital service more if it is Made in Switzerland, the picture says one thing: in Switzerland compliance is not a compliance cost, it is a brand asset. And right now it is an asset two SMEs out of three are leaving on the table.
- Map where you use AI
- Content, chatbots, lead scoring, customer service, analysis.
- Establish your role
- For each use: deployer or provider, and whether the output reaches the EU.
- Check your tool contracts
- Whether prompts are used for training; switch on and document the no-training options in business plans.
- Update your privacy notice
- AI purposes, recipients, destination country, safeguard applied.
- Set up an editorial approval log
- Who reviewed, when, what was changed. It is the evidence that makes the human-review exemption on text defensible.
- Set an internal labelling rule
- Before a client or an authority imposes one on you.
- Does the AI Act apply to Swiss companies?
- It can apply even without an EU establishment, when the system's output is used in the Union. The practical test is whether you target the EU market, not whether your site can simply be reached.
- Do I have to label AI-generated images?
- If they are realistic and published in the EU, very probably yes: Art. 50(4) requires deepfakes to be declared, and the artistic exemption does not clearly cover commercial content. Assess your own case with a lawyer.
- Does Switzerland have an artificial intelligence law?
- Not yet. The Federal Council chose a sector-based approach and instructed the Federal Office of Justice to prepare a bill for consultation by the end of 2026.
- If there is no AI law, am I free to do as I like?
- No. The FADP, the Unfair Competition Act, personality rights and copyright already apply. The FDPIC has explicitly stated that the FADP applies directly to AI.
- Can I use ChatGPT with my clients' data?
- It depends on the plan and the contract: check whether prompts feed training, switch on the options that exclude it, verify that the provider is Swiss-U.S. DPF certified or covered by standard contractual clauses, and update your privacy notice.
Sources: Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744, OJEU 24 July 2026 · European Commission, Guidelines on Art. 50, 20 July 2026 · Code of Practice on transparency, 10 June 2026 · Federal Council, 12 February and 27 March 2025 · Federal Office of Justice · FDPIC, 8 May 2025 and X/Grok investigation · FADP SR 235.1 and DPO SR 235.11 · Swiss-U.S. Data Privacy Framework, 15 September 2024 · European Commission, adequacy decision on Switzerland, 15 January 2024 · AXA, SME Study, 5 November 2025 · Risiko-Dialog Foundation, Digital Barometer 2026.


