Regulation (EU) 2024/1689 · staggered application
With an AI model, liability does not stop at whoever built it.
The AI Act spreads duties across the chain: providers, deployers, importers, distributors. Using a system means knowing what you are using – and being able to evidence it.
The AI Regulation classifies systems by risk and attaches duties accordingly. High-risk systems require conformity assessment, technical documentation, logging and human oversight; general-purpose models carry their own transparency duties towards downstream providers.
For Swiss companies the reach is wider than it first appears: among other triggers, it matters whether a system’s output is used in the EU. And beyond that the chain carries on – supply an AI component and your EU customer will ask for documentation.
Where the chain bites
- Providers placing an AI system on the market under their own name – even when someone else’s model sits inside.
- Deployers using a system professionally, who must maintain oversight and logs.
- Suppliers of models, training data and components through information duties to downstream providers.
- Companies that substantially modify a bought-in system and thereby become providers themselves.
What the chain must supply
- Classification
- Establish whether a deployed system counts as high-risk – unanswerable without provider information.
- Documentation
- Obtain and retain technical documentation and instructions for use.
- Data provenance
- Understand what a model was trained on and what usage rights exist.
- Oversight
- Organise human oversight and keep logs of use.
- Changes
- Record the provider’s model and version changes – they can alter the classification.
How SCRM covers it
Provider per AI component
Model, platform and data source as separate records with an owner.
Documents with validity
Documentation and declarations dated, so the version in use at a given time stays provable.
Changes as events
A silent model switch becomes visible instead of passing unnoticed.
Classification recorded
“Not high-risk” is evidence too, with its reasoning.
Frequently asked
Does the AI Act apply to Swiss companies?
Not as domestic law. It bites where, among other triggers, a system’s output is used in the EU – and in practice through customer contracts. Your own position needs case-by-case legal assessment.
What separates a provider from a deployer?
A provider places on the market, a deployer uses. Substantially modifying a bought-in system or offering it under your own name switches the role – with considerably more duties.
How does this relate to ISO/IEC 42001?
The AI Act is law, the standard a management system. A system run to 42001 eases the evidence but does not replace legal assessment.
As of July 2026. Application is staggered; the deadlines in force govern. Not legal advice.