AI Act, FADP and marketing: what Swiss companies need to know

When the European rules reach a Swiss SME, what Article 50 requires of marketing, and what the FADP already says today.

Date
August 18, 2026
Category
AI & Compliance
Reading
10 min read
Byline
Outsmart Studio

The AI Act's transparency obligations have applied since 2 August 2026. A Swiss company can fall under them without being established in the EU: it is enough that the output is used in the Union.

AI Act, FADP and marketing: what Swiss companies need to know, Journal article · AI & Compliance

Since 2 August 2026 the transparency obligations of Article 50 of the European AI Act have been in force, the ones covering chatbots, deepfakes and generated content. A Swiss company can fall under them even without an establishment in the EU: it is enough that the system's output is used in the Union. Switzerland has no AI law yet, but the FADP already applies today, as the FDPIC has made clear. This article is orientation, not legal advice.

Five facts to be clear on
Transparency in force
The obligations of Art. 50 of the AI Act have applied since 2 August 2026.
High risk postponed
The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved the obligations on high-risk systems to 2 December 2027 and 2 August 2028.
It applies without an EU establishment
A Swiss SME can fall under the AI Act with no establishment in the Union.
No regulatory vacuum in Switzerland
There is no AI law, but the FADP, the Unfair Competition Act, personality rights and copyright all apply.
The GDPR has not changed
The second Digital Omnibus, the one on data and the GDPR, is not law yet: at the end of June 2026 the compromise text was withdrawn in Council for lack of a majority.
What kicks in, and when
2 February 2025
Prohibitions (Art. 5) and AI literacy (Art. 4). In force.
2 August 2025
GPAI models, governance, penalties. In force.
2 August 2026
Transparency (Art. 50) and general application. In force.
2 December 2026
End of the grace period for marking systems placed on the market before 2 August 2026. Imminent.
2 December 2027
Stand-alone high-risk systems (Annex III). Deferred.
2 August 2028
High risk embedded in products (Annex I). Deferred.

The Digital Omnibus softened Article 4: the literacy requirement moves from an obligation of result to an obligation of means. It remains enforceable: the authority will assess whether you did something, not whether every employee passed a test. For SMEs the package introduces simplified documentation and reduced penalty ceilings, and Art. 99(6) provides that the lower of the two amounts applies.

02

When the AI Act reaches a Swiss company

Article 2(1)(c) is the way in: the regulation applies to providers and professional deployers established in a third country “where the output produced by the AI system is used in the Union”.

Situations where a Ticino firm is inside the scope
You sell or license an AI tool to EU clients
White label included. Careful: here you risk sliding into the provider role, with far heavier obligations, even when the technology is someone else's.
You produce content for campaigns published in the EU
Visuals, video, synthetic voices or generated copy: the output is used in the Union.
You run a chatbot aimed at EU users
Or any AI service aimed at that audience.
You supply AI analysis to an EU subsidiary or client
The output crosses the border.

The practical test is targeting: deliveries to EU customers, targeted advertising, prices in euros. The mere fact that your Swiss site can be reached from Italy is not enough. But the line between “reachable” and “targeted market” has not yet been tested in case law: this is a case-by-case analysis, not a self-acquittal. The distinction of role matters too: a studio using generative tools for a client is typically a deployer, not a provider.

Four obligations, different addressees
Direct interaction, a provider obligation
Anyone interacting with a chatbot has to know they are talking to an AI, unless it is obvious to a reasonably well-informed person.
Machine-readable marking, provider
Generated audio, images, video and text must be marked: watermarking, metadata, fingerprinting. The obligation sits with whoever provides the model, but the agency has to check that the tools comply and must not strip the markings. For systems already on the market, compliance by 2 December 2026.
Deepfakes and public-interest text, deployer
This is the heart of the matter for marketing. Anyone publishing images, audio or video that constitute a deepfake has to declare it, at the latest on first exposure. The exemption for artistic or satirical works exists, but must be exercised without getting in the way of enjoying the work.
Emotion recognition and biometrics, deployer
Inform the people exposed and comply with data protection law.

The European Commission published the final guidelines on Art. 50 on 20 July 2026 and deemed the Code of Practice on transparency of AI-generated content adequate. Anyone not signing up has to demonstrate the adequacy of their own measures individually.

If the broad reading of what counts as a deepfake holds, generated product visuals and synthetic voices in ads will have to be labelled too.

According to specialist analyses of the guidelines, the notion of a deepfake would be read broadly: any realistic content generated or modified by AI, with no need for real people to be depicted and regardless of deceptive intent, and commercial content would not benefit from the artistic exemption. This reading is still debated and its operational impact is enormous: check it against the official text before redesigning your processes. Penalties for breaching the transparency obligations reach 15 million euros or 3% of worldwide turnover.

04

Where Switzerland stands

On 12 February 2025 the Federal Council decided to ratify the Council of Europe Framework Convention on AI, signing it in Strasbourg on 27 March 2025. The underlying choice is a sector-based approach: no horizontal AI Act-style law, but regulation sector by sector, with cross-cutting adjustments limited to data protection and non-discrimination.

The Federal Office of Justice must draft a bill for consultation by the end of 2026; DETEC a plan of non-binding measures. As of August 2026 the draft has not yet been published: it is the Swiss regulatory event to watch in the final quarter. Ratification will follow the adoption of domestic legislation, realistically not before 2027-2028.

05

Meanwhile the FADP already applies

The FDPIC was blunt in a communication of 8 May 2025: the current data protection act applies directly to AI. The FADP is drafted in technology-neutral terms, so no new law is needed for you to be bound already.

What follows, in practice
Transparency, Art. 19
On purpose, operation and data sources. If you use foreign providers, the privacy notice has to state the destination country and the safeguards applied: this is the part almost everyone forgets.
The right to know
Whether you are talking to a machine, and whether your data, prompts included, will be used to train the models.
Automated decisions, Art. 21
If a decision rests solely on automated processing and has significant effects, the person concerned must be informed and can ask for human review.
Impact assessment, Art. 22
For high-risk processing. Predictive profiling, AI lead scoring or cross-channel personalisation are typically the moment it becomes necessary.
Record of processing, Art. 12
Companies under 250 employees are exempt, but the exemption falls away with high-risk profiling. A lot of data-driven marketing falls into the second case.
Transfers abroad, Art. 16-17
The United States has been deemed adequate since 15 September 2024, but only towards recipients certified under the Swiss-U.S. DPF. A breach exposes you to fines of up to 250,000 francs, payable by the responsible individual, not the company: that is the substantial difference from the GDPR.

One last note that doubles as a commercial argument: on 15 January 2024 the European Commission confirmed Switzerland's adequacy. EU data can keep flowing to you without additional safeguards, a concrete advantage for anyone serving Italian or German clients.

34%
of Swiss SMEs have integrated AI, but only 34% of them have clear data protection rules. Among micro-businesses it drops to 23%
06

The figure that makes all this urgent

Set beside the other figure, that over 80% of the Swiss population trust a digital service more if it is Made in Switzerland, the picture says one thing: in Switzerland compliance is not a compliance cost, it is a brand asset. And right now it is an asset two SMEs out of three are leaving on the table.

Six things to do this month
Map where you use AI
Content, chatbots, lead scoring, customer service, analysis.
Establish your role
For each use: deployer or provider, and whether the output reaches the EU.
Check your tool contracts
Whether prompts are used for training; switch on and document the no-training options in business plans.
Update your privacy notice
AI purposes, recipients, destination country, safeguard applied.
Set up an editorial approval log
Who reviewed, when, what was changed. It is the evidence that makes the human-review exemption on text defensible.
Set an internal labelling rule
Before a client or an authority imposes one on you.
Frequently asked questions
Does the AI Act apply to Swiss companies?
It can apply even without an EU establishment, when the system's output is used in the Union. The practical test is whether you target the EU market, not whether your site can simply be reached.
Do I have to label AI-generated images?
If they are realistic and published in the EU, very probably yes: Art. 50(4) requires deepfakes to be declared, and the artistic exemption does not clearly cover commercial content. Assess your own case with a lawyer.
Does Switzerland have an artificial intelligence law?
Not yet. The Federal Council chose a sector-based approach and instructed the Federal Office of Justice to prepare a bill for consultation by the end of 2026.
If there is no AI law, am I free to do as I like?
No. The FADP, the Unfair Competition Act, personality rights and copyright already apply. The FDPIC has explicitly stated that the FADP applies directly to AI.
Can I use ChatGPT with my clients' data?
It depends on the plan and the contract: check whether prompts feed training, switch on the options that exclude it, verify that the provider is Swiss-U.S. DPF certified or covered by standard contractual clauses, and update your privacy notice.

Sources: Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744, OJEU 24 July 2026 · European Commission, Guidelines on Art. 50, 20 July 2026 · Code of Practice on transparency, 10 June 2026 · Federal Council, 12 February and 27 March 2025 · Federal Office of Justice · FDPIC, 8 May 2025 and X/Grok investigation · FADP SR 235.1 and DPO SR 235.11 · Swiss-U.S. Data Privacy Framework, 15 September 2024 · European Commission, adequacy decision on Switzerland, 15 January 2024 · AXA, SME Study, 5 November 2025 · Risiko-Dialog Foundation, Digital Barometer 2026.

All articles

All articles