26 April 2026
As part of its "Digital Agenda", the EU has introduced several new regulations governing data and digital systems that extend well beyond AI. These regulations have created a complex regulatory landscape, making it challenging for companies to identify the applicable rules for their products and processes. This article, part of our AI blog series, provides an overview of the seven most prominent regulations to consider in addition to the GDPR. For each regulation, we outline its scope and main obligations, assess its relevance for Swiss companies, and detail the corresponding legal situation in Switzerland.
The EU digital regulations discussed below are the AI Act, the Data Act, the Cyber Resilience Act, the NIS2 Directive, the Digital Services Act, the Digital Markets Act, and the Digital Governance Act. We have prepared an overview of these EU regulations, outlining the main obligations for companies subject to them and their relevance for Swiss companies. This overview is part of our "Data & AI Coordinator Handbook":

The AI Act is an EU regulation that governs AI systems that are placed on the market, put into service, or whose output is used within the European Economic Area (EEA). The AI Act adopts a risk-based approach to safeguard health, product safety, and fundamental rights. It classifies AI systems by risk: prohibited practices are banned outright; high-risk systems face extensive compliance requirements; and general-purpose AI (GPAI) models, particularly those with systemic risks, are subject to specific obligations. The AI Act is not a general regulation of AI or its use, but rather a product safety regulation. Most obligations need to be complied with by those who offer an AI product. Additionally, the AI Act imposes several transparency obligations that may also apply to AI systems that are not necessarily risky, such as chatbots.
Artificial Intelligence (AI) refers to computer systems that are trained – not programmed – to recognize patterns and generate outputs like predictions, content, recommendations, or decisions. The key feature of AI is its autonomy, where outputs are generated from learned patterns in training data rather than from fixed, human-written rules. In principle, an AI system can be any tool, online service, or application that incorporates these techniques. For more details, see our dedicated and extensive blog post on the AI Act here (Part 7 of our AI blog series). For tools and materials on AI, see here.
Switzerland is taking a different approach from the EU. Instead of introducing a new "Swiss AI Act", the Federal Council plans to amend existing laws to address the specific challenges of AI, guided by the Council of Europe's AI Convention. This approach aims to be technology-neutral and principle-based. A legislative proposal is expected by the end of 2026, with a bill for the Federal Parliament to discuss by mid-2028. Until then, and even afterwards, existing Swiss laws fully apply to the use of AI. These include the Swiss Data Protection Act when personal data is processed, as well as copyright, liability and non-discrimination laws. Future Swiss legislation will primarily focus on ensuring transparency, protecting fundamental rights, and building trust in AI. Specific changes are expected concerning semi-automated decisions, impact assessments, and the identification of AI-generated content – with a strong focus on the public sector.
The Data Act regulates access to and sharing of data from "connected products" and associated "related services". Users have the right to freely access data generated by their use of connected products and related services and to share it with third parties upon request, subject to safeguards such as the protection of trade secrets and data protection. "Data holders" (e.g., manufacturers and service providers) must design products and services to allow for data access, provide pre-contractual information, and refrain from imposing unfair contractual terms. Furthermore, there are provisions that intend to facilitate switching between data processing services (mainly cloud providers).
A connected product is hardware or software that obtains, generates, or collects data concerning its use or environment and can communicate that data digitally (e.g., smart home devices, cars, fitness trackers, industrial machinery with interfaces for local or remote data access). A related service is a digital service functionally linked to a connected product's operation or features, without which the product cannot perform one or more of its functions (e.g., control apps). Hence, if you rent a car that records your driving locations, you can ask for this information. Similarly, if you buy a machine that can be diagnosed remotely, you can ask the supplier to make the data available to other companies offering competing services.
In Switzerland, there are currently no horizontal rules or laws governing the exchange of non-personal data between private entities. In the area of public law, there is the Federal Act on the Use of Electronic Means for the Fulfilment of Official Tasks (Bundesgesetz über den Einsatz elektronischer Mittel zur Erfüllung von Behördenaufgaben, SR 172.019, EMBAG), which contains provisions on open government data but only applies to the federal administration. Following a parliamentary motion (Motion 22.3890 "Framework Act for the Secondary Use of Data"), the Federal Council was tasked with creating a new framework law to establish the foundations necessary for the rapid development and implementation of infrastructure enabling the secondary use of data in strategic areas. Although the Federal Office of Justice, which is leading this legislative effort, has taken note of the EU Data Act, no decision has yet been made on whether and to what extent, its principles will be integrated into the forthcoming Swiss bill. A new framework act is not expected before 2028.
This EU regulation establishes mandatory cybersecurity requirements for "products with digital elements" made available within the EEA. It sets requirements for their secure design, development, production, and maintenance to reduce cyber risks throughout their lifecycle.
A "product with digital elements" (PDE) is hardware or software that connects directly or indirectly to a network or device and may be exposed to cyber threats. Examples include browsers, routers, smartphones, password managers, fitness trackers, and industrial control systems – encompassing most electronic products, including software. Lifecycle activities include continuous vulnerability management, providing security updates for a defined period, and mandatory incident reporting to authorities to ensure ongoing protection and resilience against cyberattacks.
Switzerland currently has no equivalent to the EU Cyber Resilience Act. In August 2025, the Federal Council tasked the National Cyber Security Centre (NCSC/BACS) with drafting a corresponding bill for new legislation, which is scheduled to be submitted for consultation by autumn 2026. This new legislation will set out cybersecurity requirements for the development and commercialization of products containing digital components, establish rules for market surveillance of these products, and lay the groundwork for banning the import and sale of insecure devices. The goal is to create legislation that is tailored to Switzerland's economic landscape, while ensuring that the administrative burden on companies is kept to a minimum and that Swiss companies operating internationally are not disadvantaged by conflicting requirements, especially from the CRA.
The NIS2 Directive mandates a high common level of cybersecurity resilience for organizations operating in critical sectors across the EEA, classified as "essential" (e.g., energy, transport, finance, healthcare) and "important" (e.g., postal services, manufacturing of key products, digital infrastructure) entities. Not only do they need to maintain cybersecurity practices within their organization, they are also required to report certain incidents.
Switzerland, while not bound by NIS2, has its own similar rules. The revised Information Security Act (Informationssicherheitsgesetz, SR 128, ISG) and the new Cybersecurity Ordinance (Cybersicherheitsverordnung, SR 128.51, CSV), effective March 7, 2025, create a mandatory reporting duty for operators of critical infrastructure. Unlike NIS2, most provisions only apply to the public sector. The one exception is the obligation for many private critical infrastructure organization to notify the National Cyber Security Centre (NCSC/BACS) of cyberattacks within 24 hours of discovery, and update the report as new information becomes available, with the full report completed within 14 days. A report is required if a cyberattack: (i) endangers the functioning of the critical infrastructure; (ii) leads to the manipulation or theft of information; (iii) has not been detected for an extended period of time, particularly if there are indications that it was carried out in preparation for other cyberattacks; or (iv) involves extortion, threats, or coercion.
This EU regulation that establishes a framework for online "intermediary" services, which includes most forms of online service providers – from network and hosting providers to all sorts of online platform and online search companies. The regulation provides uniform rules on the rights and responsibilities of digital services, particularly for dealing with illegal and harmful online content, and content moderation. Obligations are tiered according to service type – with special provisions for very large providers. The DSA also governs the limitation of liability of online providers for third-party content that was previously regulated elsewhere.
Switzerland does not yet have an enacted equivalent to the EU Digital Services Act. The Swiss Federal Council initiated a public consultation on a preliminary draft of the Federal Act on Communication Platforms and Search Engines (Bundesgesetz über Kommunikationsplattformen und Suchmaschinen, KomPG) in late 2025, which concluded on February 16, 2026 (see details here). The proposed Swiss regulation is inspired by the DSA but is not identical, differing in scope and regulatory density. The Swiss draft is narrower, applying only to very large communication platforms and search engines, defined as those reaching at least 10% of the Swiss population monthly. In contrast, the DSA applies more broadly to all intermediary services, including smaller platforms, conduit, and caching services. The Swiss draft focuses specifically on strengthening user rights and increasing transparency to mitigate negative effects without stifling the platforms' positive aspects. The proposed obligations are primarily transparency and conduct-related duties, not a general proactive monitoring requirement. Key duties include establishing notice-and-action mechanisms for specific types of presumably illegal content like hate speech, providing internal complaint systems, participating in out-of-court dispute resolution, and ensuring transparency for advertising and recommendation systems, including maintaining a public ad archive. The platforms would also be required to conduct and report on annual risk assessments concerning systemic risks to Swiss society, though the draft does not explicitly mandate risk mitigation measures. Following the consultation period, the Federal Council is reviewing the submissions and preparing a formal bill to submit to Parliament for debate and adoption.
The Digital Markets Act governs very large online platforms designated as "gatekeepers" (e.g., Google Search, Apple's App Store, Amazon Marketplace, Meta Messenger) to ensure fair and contestable digital markets. It imposes a series of direct obligations on gatekeepers, which in turn grants new rights to business users.
The DMA's objectives are partially addressed in Switzerland through existing legislation. Effective competition in digital markets is primarily ensured by the current competition law framework, which can be applied specifically to platforms. For instance, precautionary measures can be ordered against irreversible market foreclosures. The Cartel Act's rules on abuse of dominance (Article 7; see Motion 23.3069 "Digital Markets Act for Switzerland") were expanded to include the concept of relative market power, an instrument expected to be applied in digital cases. Additionally, specific ex ante regulations for digital platforms have recently come into force, such as the ban on parity clauses for online booking platforms (Art. 8a Unfair Competition Act) and the ban on private geoblocking (Art. 3a Unfair Competition Act). The Federal Council sees no immediate need to adopt a DMA style law. It is expected that large online platforms will apply the new EU rules in Switzerland, partly because they often group Switzerland with EU markets. Furthermore, the Swiss Competition Commission (COMCO) regularly ensures that behavioral changes made by companies following EU competition proceedings are also implemented in Switzerland. In digital cases with a specific Swiss connection, the COMCO can intervene directly using competition law to protect effective competition.
The Data Governance Act seeks to facilitate voluntary data sharing across the EEA through data intermediaries, public sector data reuse, and data altruism organizations. It primarily creates opportunities, while imposing limited or role-specific obligations on businesses. A key goal of the DGA is to make digital data gathered by the public sector institutions available to the private sector.
There is currently no Swiss equivalent to the DGA. Following a parliamentary motion (Motion 22.3890 "Framework Act for the Secondary Use of Data"), the Federal Council was tasked with creating a new framework law to establish the foundations necessary for the rapid development and implementation of infrastructure enabling the secondary use of data in strategic areas. Although the FOJ, which was given the lead on this legislative work, has taken note of the EU's Data Governance Act, no decision has yet been made on whether and to what extent, its principles will be integrated into the forthcoming Swiss bill. A new framework act is not expected before 2028.
For companies serving customers beyond Switzerland, the key challenge lies in navigating this dense web of new regulations and identifying which overlapping rules apply to specific products, applications, or processes. These regulations often intersect, and sometimes even conflict. An AI system could be subject to the AI Act and the Data Act, as well as the Cyber Resilience Act. For example, a smart industrial robot that uses AI for predictive maintenance would be considered a "high-risk AI system" under the AI Act, a "connected product" under the Data Act, and a "product with a digital element" under the Cyber Resilience Act. The Data Act may require data holders to perform actions that are not permitted by the GDPR. In such cases, the GDPR usually "wins", but it is the responsibility of the relevant market player to be aware of this and take it into account.
We also have a series of five-minute videos on each of the above regulations, as well as on the GDPR. See more information here.
This article is part of a series on the responsible use of AI in companies:
We support you with all legal and ethical issues relating to the use of artificial intelligence. We don't just talk about AI, we also use it ourselves. You can find more of our resources and publications on this topic here.
Downloads: