Answer the EU compliance question before it stalls the deal.
Your EU customers ask about compliance before they evaluate the product. The answer is knowable today, and Swiss companies are better placed to give it than most. This page sets out what applies, with the source for every claim, and what to have ready before the next procurement review.
Find out which regulations your product must comply with
Fifteen minutes on your product, not on the regulation in general. You will leave knowing which regimes reach you and which do not, whether you are a provider or a deployer under each, what is already in force for you as against what is still ahead, and where your largest gap is. Not a sales call. If we are not the right fit, we will say so before the fifteen minutes are up.
Book a free scoping callWhy Swiss companies are well placed
Switzerland's regulatory position is usually written up as a gap. Treated properly it is an advantage, and there are three reasons for that.
One regime to satisfy, not two.
The Federal Council decided in February 2025 to ratify the Council of Europe AI Convention and to regulate sector by sector rather than through a horizontal Swiss AI law. Consultation is expected at the end of 2026 and entry into force in 2028 at the earliest. So your EU answer is your only answer. EU-established competitors are managing national implementation, national authorities and national timetables on top of the same Regulation. You are not.
The obligations are knowable now, even though the standards are not.
No harmonised standard has yet been cited in the Official Journal under the AI Act or the CRA, which means nobody has a presumption of conformity and everyone is demonstrating conformity by their own technical reasoning. That is not a reason to wait. It is a reason to build the reasoning properly and keep it versioned, because when the first citations land your case gets measured against them and a documented one adjusts. An undocumented one starts again.
In B2B, compliance is a sales asset.
Security and legal review now run ahead of the technical evaluation. Procurement asks the compliance question first, and the supplier who answers it on the call moves to the next stage while the others go away and prepare. Being able to produce evidence is the difference between a deal that progresses and a deal that waits a quarter.
What to have in place, and by when
Five things that are settled enough to act on today, each with the source so you can check it rather than take our word for it. Dates are current after the Digital Omnibus.
Build the conformity case, and version it.
The CEN-CENELEC JTC 21 programme for the AI Act and the CRA horizontal and vertical programmes are in drafting, enquiry and formal vote. First citations are expected over the next fifteen months. Until then Articles 40 AI Act and 27 CRA give you nothing, so your own technical justification is the whole case. Keep it dated, keep every version, and keep it tied to the essential requirement it answers.
The CRA reporting process needs to exist now.
Article 14 obligations applied from 11 September 2026. Actively exploited vulnerabilities and severe incidents go to ENISA and the relevant CSIRT on statutory timelines, which means the process and the contacts have to be in place before anything happens. Annex VII documentation, the declaration of conformity and CE marking follow on 11 December 2027. Article 13(5) also requires documented due diligence on third-party and open-source components.
From 9 December, your technical file is a defence.
The revised Product Liability Directive applies to products placed on the market after that date, and software is within scope. Article 9 lets a court order disclosure of relevant evidence, and Article 10(2)(a) presumes defectiveness where a defendant fails to disclose it. Read the other way round, that is the point: a company that can produce its file meets the claim on the merits. This is the clearest commercial argument for documenting as you go.
The AI Act dates, current after the Digital Omnibus.
Annex III high-risk obligations apply from 2 December 2027, Annex I product-embedded systems from 2 August 2028. The grace period for marking legacy synthetic content under Article 50 was shortened from six months to three and lands 2 December 2026. Prohibited practices under Article 5 and the Article 4 AI literacy obligation have applied since 2 February 2025 and are live now.
Appoint your EU representative before market, not at first customer.
A provider established outside the Union placing a high-risk AI system on the EU market appoints an authorised representative under Article 22 before placing it. Written mandate, entity established in the Union, and it cannot be a consultant, a distributor or a mailbox. Article 27 GDPR requires a separate representative where you process personal data of people in the EU, and Article 13 DSA another again for intermediary services. Adequacy does not remove any of them, because adequacy is about transfers.
Produce the evidence once, not five times.
The CRA, the AI Act, GDPR, NIS2 and DORA reach the same product and draw on the same facts about it. One encryption specification can satisfy CRA Annex I, AI Act Article 15 and GDPR Article 32 at the same time. One risk assessment answers parts of three regimes. The expensive mistake is not missing an obligation, it is three teams producing the same artefact separately and discovering during an audit that the three versions say different things. Map the obligations against one set of product facts and the overlap does the work for you.
Find out which EU regulations reach your product
The CRA, the AI Act, GDPR, NIS2, DORA and the Product Liability Directive all reach the same digital product and all draw on the same architecture, data flows and controls. Answered separately they produce the same evidence several times over, and the versions disagree. Grecta resolves obligations across regimes from a single product profile and binds each one to the artefact that satisfies it, deterministically, so every statement traces to the provision it comes from. The 15 minutes tells you whether that applies to you. If your position turns out to be simple, we will tell you that and you will have saved yourself a project.
Book the callFAQ
Not if that stays true. The AI Act, the CRA and the rest reach you when you place a product on the EU market, or when output produced by your system is used in the Union. If neither applies, your obligations are Swiss, and Switzerland is legislating sector by sector rather than through a horizontal AI law. Where it gets less clear is EU-based users signing up without you targeting them, or a Swiss customer deploying your product across its EU subsidiaries. That is worth fifteen minutes to settle rather than assuming either way.
Because the question arrives with a contract attached rather than with a deadline. Security and legal review run ahead of technical evaluation in most enterprise procurement, so the compliance question is the first one asked and the one most likely to hold up a signature. Companies that start when the questionnaire lands spend a quarter answering it. Companies that started earlier answer it on the call. The regulatory deadlines are in 2027, the commercial deadline is whenever your best prospect runs its vendor review.
Those are two different things and it is a common confusion. The adequacy decision means personal data flows from the EU to Switzerland without additional transfer safeguards. That is a question about Chapter V of the GDPR. It has no effect on Article 27, which requires a controller or processor established outside the Union but caught by the GDPR to designate a representative in the Union, and no effect at all on the AI Act or the DSA. Switzerland has the mirror of this in its own law: Article 14 of the revised FADP requires controllers domiciled abroad to designate a representative in Switzerland in defined circumstances. The mechanic is one Swiss companies already recognise, running the other way.
Different work. A firm advises you on what the law says, usually when asked and usually by the hour. What is missing in most companies is not advice, it is the operational layer: the obligation list kept current, the evidence bound to each obligation, the audit trail, and the file in the shape an authority or a buyer asks for. We also hold the authorised representative mandate itself, which an adviser cannot do, because Article 22 requires an entity established in the Union acting under written mandate rather than a firm advising you. Many of our clients keep their law firm and use us for the part the firm does not do.
Some of it will. The Digital Omnibus moved the AI Act high-risk dates to December 2027 and August 2028, and shortened the Article 50 marking grace from six months to three. More adjustment is plausible. What has not moved is what is already in force: prohibited practices and the Article 4 literacy obligation since February 2025, CRA Article 14 reporting since 11 September 2026, and the Product Liability Directive from 9 December 2026. The practical answer is to build the record rather than the compliance programme. A documented position adjusts when dates move. An undocumented one starts again.
There are concessions, not exemptions. The AI Act provides simplified technical documentation for SMEs, and fines for SMEs are capped at the lower of the percentage or the fixed amount rather than the higher. The prohibited practices, the literacy obligation and the substance of the high-risk requirements apply the same way to a fifteen-person company as to a fifteen-thousand-person company. That is the real difficulty with this regime and we would rather say so than pretend otherwise. What does scale is the effort: the work for a small company with one product in scope is a fraction of what a portfolio needs.
The requirement is that the authorised representative is an entity established in the Union under written mandate. Ours is EuroGRC OÜ, registered in Estonia, and that is what holds the mandate and appears in your documentation. Where the people are is not the test, and a Union-established representative is exactly what a Swiss or UK provider cannot supply from its own group. We are also in the same position you are, which is to say a third-country provider selling into the EU, so this is a problem we solved for ourselves before we sold it to anyone.
One product, several regimes, one set of facts.
Most companies discover their obligations through a customer's security review, with a contract already on the table. Fifteen minutes now is the cheaper version. On the call we work through what your product actually does and resolve four things: which of the CRA, AI Act, GDPR, NIS2, DORA and the Product Liability Directive reach it, what your role is under each, whether you need an EU authorised representative and by when, and which single gap is worth closing first. You leave with a short written note of what we covered, so you have something to take to your board or your engineering lead rather than your own memory of a call.
Book the free scoping callNo sales sequence, no follow-up campaign. One email to confirm the time and one after with the note.