"We're Swiss, the AI Act doesn't apply to us." That is the sentence I would least like to hear across the table at a fund evaluating a startup with customers in the EU. It is half true, and the false half is the expensive one.
Start with what is genuinely true. Switzerland is not an EU member and has not adopted Regulation (EU) 2024/1689. As things stand there is no Swiss AI-specific law — the applicable framework is still the generic one: data protection, product liability, intellectual property, employment law. On 12 February 2025 the Federal Council settled on the direction it wants to take, and it is deliberately light-touch: strengthen Switzerland as an innovation hub, protect fundamental rights and public trust, and prioritise sectoral regulation and non-binding measures (self-declaration, industry-led solutions) over a horizontal, European-style law.
On 27 March 2025, in Strasbourg, Switzerland signed the Council of Europe Framework Convention on Artificial Intelligence, Human Rights, Democracy and the Rule of Law. Signed, not ratified. Ratification requires parliamentary approval and can end up in a referendum if one is called. The current mandate is for the Federal Department of Justice and Police, together with other departments, to prepare a draft bill implementing the Convention before the end of 2026 — focused on transparency, data protection, non-discrimination and oversight — and put it out for public consultation. In other words: at best, Switzerland will have a draft bill by the end of this year. Not a law in force.
Contrast that with how the EU handles the same Convention: it signed up through Council Decision (EU) 2026/1080 of 21 April 2026, and applies it inside the Union exclusively through Regulation 2024/1689 and the rest of the existing acquis. The EU does not need to legislate again — it already has the vehicle. Switzerland does need one, and that vehicle does not exist yet.
The only instrument with teeth in Switzerland today is the data protection act. The revised FADP, in force since 1 September 2023, does not mention AI by name, but its Article 21 is in practice the main legal brake on an automated decision affecting a person: whoever processes the data must disclose any decision taken exclusively by automated processing with legal or significant effects, and the affected person has the right to have a human review that decision. It is a transparency-and-review approach, not a prohibition — closer in spirit to a duty to inform than to the logic of GDPR Article 22, which starts from a prohibition with exceptions.
Why this changes the technical due diligence of a Swiss startup with EU customers
The mistake is not assuming that Switzerland regulates lightly — that is true, and will stay true for a while. The mistake is assuming that "lightly regulated in Switzerland" means "lightly exposed". The AI Act has a broader territorial test than GDPR: Article 2 triggers not only when the provider is in the EU, but when the system's output is used inside the Union, regardless of where the company sits. A Zurich-based startup selling a candidate screening tool to a client with German operations is not outside the Regulation by virtue of holding a Swiss passport. It is inside it — even though in Switzerland that same tool would carry no equivalent obligation.
What this means around an evaluation table
The question to ask is not "is the company in a country that regulates AI?". It is "where is the output of its system used?". If the answer includes the EU, the regulatory exposure of a Swiss startup can be, in practice, identical to that of one headquartered in Frankfurt — with the difference that the Swiss team is more likely not to have anticipated it, precisely because nobody at home has required it of them yet.
Second point: the European timeline has moved too, and it is worth holding in mind when planning any portfolio company's compliance roadmap. Regulation (EU) 2026/1744, in force since 27 July 2026, postponed the full obligations for high-risk systems until 2 December 2027. That buys room — but only for the startups that have already started classifying their systems. The ones that have not will arrive just as late in 2027 as they would have in 2026.
Third: not everything deferred in the EU is deferred in the rest of the analysis. The Article 50 transparency obligations — that a user knows they are talking to an AI, that synthetic content carries a detectable marker — have been in force since 2 August 2026. Any Swiss startup whose product includes a chatbot or generates public-facing content in the EU already has that obligation live, regardless of whether a Swiss equivalent ever arrives.
This is, at bottom, the same kind of question I raise in my own technical due diligence reports: it is not enough to ask what a company says about itself. You have to ask what regulatory risk it is not mentioning, because it assumes it does not apply — and check that against where its end user actually lives, not where its registered office does.
How are you testing a startup's real regulatory exposure when its headquarters and its market sit in different jurisdictions?