DECISION TOOLKIT · SWISS AI COMPLIANCE
Use three perimeters to build one defensible file
The legal analysis becomes operational when each perimeter ends in an owner, an evidence set and a decision. The question is not whether a company uses AI; it is whether it can explain each use under pressure.
inventory, data flows, contracts
clauses, controls, assessments
training, intake, quarterly review
A defensible file answers who, what, where, why and under which conditions within one working day.
A Swiss company deploying generative AI in 2026 operates under two legal regimes at once. The first is explicit: the revised Federal Act on Data Protection (nFADP), in force since September 2023, applies to every prompt, every integration and every data flow that contains personal data. The second is quieter: the EU AI Act, which entered into force in August 2024, produces extraterritorial effects that many Swiss organisations discover too late — often in the middle of a tender or a due diligence questionnaire.
The gap we observe in engagements is not a lack of goodwill. It is a lack of framing: legal teams reason in statutes, technical teams in systems, executives in risks — and nobody reasons in evidence. Yet evidence is exactly what will be requested one day, by a client, an auditor or an authority. This article proposes a reading grid built on three perimeters, then a 90-day action plan to move from intention to a defensible file.
Two regimes already in force, one Swiss blind spot
The nFADP is technology-neutral: it does not mention AI, and that is precisely why it already applies. The moment an employee pastes a client email into an assistant, or a connected system indexes HR files, personal data is being processed and the law’s obligations activate: purpose limitation and proportionality, the duty to inform, the framing of processors, the conditions for disclosure abroad. The law also provides for criminal sanctions aimed at natural persons: personal sanctions are possible for executives and designated officers.
The AI Act follows a different logic: it is product regulation, graduated by risk. Its application is staged: in force since August 2024, it has imposed obligations on providers of general-purpose AI models since August 2025, and its obligations for high-risk systems roll out progressively between 2026 and 2027. Its fines are proportional to turnover.
The blind spot fits in one sentence: Switzerland has, to date, no horizontal AI law and favours a sector-based approach. Many organisations infer a regulatory vacuum. That is doubly wrong: the nFADP already covers the raw material of generative AI — data — and the AI Act does not stop at the border. A Swiss company can be in scope without owning a single entity in the EU.
The three perimeters
Rather than stacking statute-by-statute analyses, we frame every situation with three perimeters. Each answers a distinct question, involves different stakeholders and produces its own evidence.
Perimeter 1 — personal data. Which personal data enters our AI uses, and do we comply with the nFADP across the chain: basis for processing, information, processors, disclosure abroad, impact assessment?
Perimeter 2 — the EU market. Are we, through our clients, our subsidiaries or the outputs of our systems, within the scope of the AI Act — and in which role, provider or deployer?
Perimeter 3 — sector and contractual risk. Which obligations sit on top of the statutes: professional secrecy, supervisory expectations, client clauses, audit requirements?
A single use can activate one, two or all three perimeters. An internal assistant for technical documentation often activates only the first, weakly. AI-assisted screening of applications for roles in Geneva and Lyon activates all three. It is this combination — not the tool itself — that determines the justified compliance effort.
Perimeter 1 — personal data (nFADP)
The first perimeter is the most frequently activated and the most poorly documented. Five workstreams structure it.
The basis for processing. Unlike the GDPR, the nFADP does not require a legal basis for every processing operation: it requires compliance with the principles — defined purpose, proportionality, accuracy, security — and a justification whenever processing departs from them. Concretely, the company must be able to state, for each generative AI use, for what purpose the data is processed and why that processing is proportionate. “Improving productivity” is not a sufficient purpose for ingesting the full client history.
Information. The duty to inform applies when personal data is collected: the privacy notice must reflect the reality of AI uses — data categories, recipients including model providers, countries of processing. Automated individual decisions must be disclosed when they produce legal or otherwise significant effects for the person.
Processors. An AI provider that processes personal data on your behalf is a processor: a contract is required, along with security guarantees and the framing of sub-processors. The hard point in practice: the consumer terms of many tools do not meet these requirements — only certain enterprise offerings do.
Disclosure abroad. Inference happens somewhere. If the country of processing does not offer a level of protection recognised as adequate, safeguards are needed — typically standard contractual clauses — plus a check that they are effective. The contractual location of processing becomes a vendor selection criterion, not a technical detail.
The impact assessment. When processing is likely to result in a high risk to personality or fundamental rights — profiling, sensitive data, novel technologies at scale — an impact assessment is required before deployment. Generative AI applied to HR, medical or financial data often ticks these boxes. If the residual risk remains high, the FDPIC is the counterpart foreseen by the law.
Perimeter 2 — the EU market (AI Act)
“We are Swiss, the AI Act does not concern us” is one of the most expensive sentences of 2026. The regulation also applies to actors established outside the EU, and a Swiss company typically enters its scope through three doors.
First door: the market. Whoever places a product or service embedding an AI system on the European market is concerned, regardless of where they are established. That includes the Swiss software vendor whose AI feature is sold to European clients.
Second door: the outputs. The regulation also covers cases where the outputs of a system operated in a third country are used in the EU. A Geneva firm that screens applications for its Lyon branch, or delivers to a German client analyses produced by its AI system, can fall in scope without “selling AI” to anyone.
Third door: the group. A European subsidiary deploying the group’s AI tools is a deployer within the meaning of the regulation, with its own obligations — and mechanically pushes the requirements up to the parent company.
The role matters as much as the scope. Most Swiss companies are deployers: their obligations concern compliant use, human oversight, logs and monitoring of operation. But you become a provider — with a markedly heavier set of obligations — by marketing under your own brand a system built on a third-party model, or by substantially modifying an existing system. Swiss products “with AI inside” cross that line without ever having decided to.
On the calendar: obligations for providers of general-purpose AI models have applied since August 2025, and those for high-risk systems — recruitment, creditworthiness, access to essential services, among others — roll out progressively between 2026 and 2027. Waiting for the last deadline is a losing strategy: it is European clients who, already today, contractually demand proof of compliance, well before the authorities do.
Perimeter 3 — sector and contractual risk
The third perimeter is the most frequently forgotten, yet it sanctions fastest. No authority acts more quickly than a client who terminates.
Professional secrecy. Banks, lawyers, physicians, fiduciaries: transmitting data covered by secrecy to an external AI service without an appropriate framework is a risk of its own, independent of the nFADP. The right question is not “is this vendor serious?” but “is this transmission channel compatible with my duty of secrecy?”.
Sector supervision. Financial institutions must integrate their AI uses into operational risk management and outsourcing rules; healthcare and the public sector have their own requirements. The supervisory authority will not wait for an AI law before asking questions about a critical process delegated to a model.
Client clauses. Non-disclosure agreements, data processing agreements, clauses prohibiting unapproved sub-delegation, localisation requirements: a generative AI use can breach a contract before it breaches a law. The service provider that routes a client’s documents through an undeclared AI tool is exposed contractually, whatever its legal compliance.
Audit requirements. ISO 27001, SOC 2, client audits and due diligence now cover AI. An ungoverned use becomes an audit non-conformity — with a direct commercial effect on sales cycles.
The evidence grid
These three perimeters are only worth something if they produce evidence. Here is the grid we use to objectify an organisation’s state.
| Perimeter | Questions to ask | Expected evidence |
|---|---|---|
| Personal data (nFADP) | Which personal data enters which uses? For what purpose, with which processors, towards which countries? | Records of processing covering AI, processor contracts, analysis of disclosures abroad, impact assessments for high-risk uses |
| EU market (AI Act) | Are our outputs used in the EU? Are we provider or deployer? Which uses will qualify as high-risk? | Map of EU exposure, role qualification per system, compliance file and tracking of the 2026–2027 calendar |
| Sector & contractual | Which secrecy duties, client clauses and supervisory expectations apply? | Review of key contracts, register of commitments made, usage rules per data and client category |
“The regulator will not ask whether you use generative AI. It will ask where, with which data, under which clauses — and who decided.”
What this requires of generative AI
Brought down to operations, the compliance file rests on six building blocks.
The usage inventory. Not just the purchased tools: the actual uses, including unsanctioned ones. For each use: data processed, users, vendor, channel — consumer interface, enterprise offering, API — and outputs produced.
Classification. Each use receives a tier based on data sensitivity and output impact. Classification decides everything else: what is allowed with which tool, what requires an impact assessment, what passes through human validation.
Vendor clauses. Three clauses condition everything: retention (how long are prompts and outputs kept, and can this be aligned with your own policy?), training (is your data excluded from model training, by default and by contract?) and localisation (in which region is data processed and stored?). Add the list of sub-processors and reversibility at the end of the contract.
Technical controls. Single sign-on and role-based permissions first; then limiting the data reachable by connected systems, separating environments and addressing LLM-specific risks — prompt injection, data exfiltration, context poisoning — documented notably by the OWASP Top 10 for LLM Applications.
Logging. Who used which system, when, for what: without logs, neither oversight nor incident response can be demonstrated. Logging must remain proportionate — an employee surveillance apparatus would create a new nFADP problem instead of solving one.
Training. A short usage directive, concrete examples per function, and differentiated training: a baseline for everyone, a reinforced module for exposed functions — HR, legal, finance, client support.
The mistakes we see in engagements
Six patterns recur with remarkable regularity.
The phantom inventory. Management believes in three uses; the survey shows twenty-five, several on personal accounts. Any compliance declared before the inventory is a fiction.
The default contract. The tool was adopted under consumer terms: data reusable for training, uncontrolled retention, unknown sub-processors. Nobody read, nobody negotiated.
The decorative impact assessment. Performed after deployment, for the file, never updated when the use changes. An assessment that does not precede the decision protects no one.
The “we are Swiss” reflex. AI Act exposure is discovered in a European client’s questionnaire, at the worst moment: at the end of a sales cycle.
The policy without controls. A PDF directive forbids what the infrastructure allows. Without single sign-on, without permissions, without an approved alternative, prohibition produces shadow AI, not compliance.
The decision without a trace. Reasonable trade-offs were made — but by no one in particular, on no precise date, in no document. The day evidence is requested, everything must be reconstructed.
The 90-day action plan
Ninety days are enough to move from an endured situation to a defensible file, provided you sequence.
Days 1–30 — establish the facts. Inventory of actual uses, sanctioned or not; data mapping per use; identification of uses whose outputs reach the EU; collection of the vendor contracts in force. Deliverable: a list of authorised, tolerated-under-conditions and prohibited uses, decided by management.
Days 31–60 — close the gaps. Migration of critical uses to enterprise offerings with negotiated clauses — retention, training, localisation; update of the privacy notice; impact assessments on the two or three most sensitive uses; activation of baseline controls: single sign-on, permissions, logging. Deliverable: contracts and controls aligned with the classification.
Days 61–90 — anchor the regime. Usage directive published and taught; an intake desk for any new use, with short response times; a decision log — who authorised what, when, under which conditions; a planned quarterly review, including tracking of the AI Act 2026–2027 calendar. Deliverable: a process that outlives the project.
The success criterion is not documentary volume. It is the ability to answer, within a day, a client, an auditor or an authority asking: which uses, which data, which clauses, which decisions.
The starting checklist
- Inventory all generative AI uses, including unsanctioned ones, with data, users and vendors.
- Classify each use by data sensitivity and output impact.
- Flag the uses whose outputs are used in the EU or serve European clients, and qualify your role.
- Verify for each vendor: retention, training, localisation, sub-processors, reversibility.
- Update the privacy notice and the information on automated decisions.
- Run an impact assessment before deployment for uses likely to present a high risk.
- Review professional secrecy and client clauses before authorising any new use.
- Activate single sign-on, role-based permissions and proportionate logging on approved tools.
- Record every authorisation decision with its owner, date and conditions.
- Schedule the quarterly review and the tracking of AI Act 2026–2027 deadlines.
This article is an operational analysis intended for executive teams; it does not constitute legal advice on your specific situation.