The European Commission has confirmed that a major model provider did not report a security incident to the responsible AI Office, although the AI regulation requires prompt notification of serious events. Shortly afterwards, a proposal from the European Parliament became known to extend product liability to general-purpose models. The current directive covers software but requires a product defect.

Switzerland is not adopting the AI regulation and is planning sector-specific adjustments. For companies building AI into their business processes, the question nevertheless remains practical: if a customer suffers damage, they turn to their supplier.

We therefore recommend systematically recording the models and providers in use, adding incident notification duties to provider contracts, and clarifying internally who approves AI results and who switches off a faulty function.