Vidimas is live – all leading AI models, securely hosted in the EU or Switzerland.Start free trial
Vidimas
All articles
ComplianceUpdated on 26 July 20263 min readVidimas editorial team

The EU AI Act: what it means for companies in the DACH region

The EU AI Act is the world's first comprehensive AI regulation. It entered into force on 1 August 2024 and becomes applicable in stages: prohibitions on certain practices first, obligations for providers of large models next, and the rules for high-risk systems in further stages through to 2027.

In Germany and Austria the regulation applies directly. For Swiss companies what counts is the marketplace principle: the AI Act also covers providers and deployers outside the EU where their AI system or its output is used in the EU.

The risk-based approach

The AI Act divides AI systems into risk classes: prohibited practices (social scoring, for instance), high-risk systems (for example in recruitment, lending or critical infrastructure) with extensive obligations, systems subject to transparency obligations (chatbots that must identify themselves as such, for instance) and minimal risks with no particular requirements. Separate rules also apply to providers of general-purpose AI models (GPAI).

Who is affected – in Germany, Austria and Switzerland

In Germany and Austria, companies are covered directly as providers or deployers as soon as they place AI systems on the market or operate them. For Swiss companies, what matters is whether AI systems are placed on the market or operated in the EU – or whether their output is used there. A Swiss company producing AI-assisted reports for EU clients, or offering an AI application to EU users as well, quickly falls within scope. Purely domestic use with no EU connection is untouched by the AI Act – there the revFADP and sector-specific rules apply.

Switzerland itself has so far taken a sectoral approach and keeps reviewing where adjustments are needed. Anyone orienting themselves towards the AI Act is well positioned for both worlds.

What typical applications mean

The good news: most office use cases – drafting text, summarising documents, searching internal knowledge – are not high-risk applications. Areas such as recruitment and CV screening, which the AI Act classifies as high risk, do require attention. Here the principle is: AI may assist, but processes must ensure human oversight, documentation and fairness.

What companies should do now

Four steps create a solid starting position:

  • Build an AI inventory: which systems are in use, for what, with which data?
  • Clarify the EU connection: are systems or their outputs used in the EU?
  • Assign risk classes and identify high-risk use cases
  • Build governance: AI policy, human oversight, documentation and training

Frequently asked questions

Does the EU AI Act apply in Austria and Switzerland too?

In Austria it applies directly as an EU regulation, as it does in Germany. In Switzerland it is not domestic law – but through the marketplace principle it covers Swiss companies whose AI systems or AI output are used in the EU, much like the GDPR.

Does the AI Act prohibit using ChatGPT and similar tools?

No. Using generative AI for office work is not a prohibited practice and is generally not a high-risk use case. Transparency and due diligence obligations may nonetheless apply – for AI-generated content aimed at the public, for example.

What penalties apply for breaches?

The AI Act provides for substantial fines that, depending on the breach, can reach up to 35 million euros or 7 per cent of global annual turnover – with prohibited practices at the top of the scale.

Related reading

Bring AI into your company securely.

Try Vidimas with your team – and see how quickly secure AI becomes productive.

Start free trial
  • Try it with the whole team
  • Set up in minutes
  • Productive from day one