Swiss companies want to finally move artificial intelligence (AI) beyond the pilot phase. Yet, when it comes to scaling up, of all things, data protection, cloud contracts, copyright, employee data and the EU AI Act quickly become stumbling blocks. The good news is that companies do not have to wait for the announced amendments to Swiss legislation. Those who translate the existing rules into a functioning AI governance framework today can combine innovation with legal certainty.
From an AI experiment to a legal issue?
Artificial intelligence has become established in most Swiss companies. What is still lacking in many places, however, is the transition from individual co-pilots, chatbots or analysis tools to systematic, company-wide deployment. This is precisely the picture painted by the Swiss IT Study 2026: companies see considerable potential in AI for efficiency, growth and competitiveness, yet productive applications often remain limited to individual areas of use. Among the obstacles cited are regulatory uncertainty, data quality, governance, system integration and issues of data sovereignty.
From a legal perspective, this reluctance is understandable, but it is partly based on a misunderstanding. Although Switzerland does not currently have any general AI legislation, the use of AI is by no means in a legal vacuum. Data protection law, employment law, copyright law, contract law and sector-specific regulations already apply today. In addition, where relevant to the European Union, the EU AI Act applies.
The real ‘AI dilemma’ therefore lies less in the absence of legislation than in its fragmentation: a company must translate rules from various areas of law into a unified process before AI can be scaled up responsibly.
Swiss AI regulation: deliberately sector-specific – but not static
As is well known, the Federal Council has decided against a comprehensive Swiss version of the EU AI Act. Switzerland is pursuing a sector-specific approach and intends, in particular, to implement the Council of Europe’s AI Convention. Switzerland therefore signed the Convention on 27 March 2025; ratification is still pending. A consultation draft is expected to be available by the end of 2026. Legislative amendments are being examined, particularly in areas such as transparency, data protection, non-discrimination and oversight. At the same time, non-binding measures such as industry-specific solutions and voluntary commitments are being developed.
For businesses, however, this has an important strategic implication: a ‘wait-and-see’ approach is not a compliance strategy. The future Swiss regulations will not be created from scratch, but will supplement existing obligations. Furthermore, the Council of Europe Convention places a clear emphasis on transparency, accountability, data protection, non-discrimination and ongoing risk and impact assessments throughout the lifecycle of an AI system.
Companies that establish such controls today are therefore not merely investing in voluntary ‘AI ethics’, but are creating structures that are likely to remain usable under the future legal framework.
Data protection: the first legal hurdle to scaling
For numerous AI applications, the Swiss Data Protection Act (DSG) is the most important starting point. The FDPIC expressly clarifies that the technology-neutral DSG also applies directly to data processing carried out by AI. Data protection must therefore be taken into account right from the planning, development and deployment stages of an AI system. During the pilot phase, this is still relatively easy to monitor. However, with a company-wide roll-out, the scope and risk change: staff transmit customer data to assistants, marketing teams analyse user profiles, HR departments have job applications pre-sorted, or support systems generate personalised responses.
Before scaling up, it is therefore particularly important to clarify which personal data enters the system, for what purpose it is used, who can access it, and whether the provider reuses the data itself. In addition, there are information obligations, technical and organisational security measures, and, where applicable, a data protection impact assessment. The latter is required if planned processing is likely to result in a high risk to the privacy or fundamental rights of the data subjects; the use of new technologies can be a relevant risk factor in this regard.
Automated individual decisions deserve particular attention. Where decisions are made exclusively by automated means and have legal consequences or significantly affect the data subject, Article 21 of the Data Protection Act (DSG) provides for specific rights to transparency and intervention. Data subjects may, subject to the statutory conditions, set out their point of view and request a review by a human being.
The most legally robust AI strategy therefore does not begin with a list of prohibited tools, but with a classification of specific use cases according to data and decision-making risk.
Data sovereignty is more than just a server in Switzerland
The Swiss IT study also highlights the growing importance of data sovereignty. Legally, however, this term should not be equated with a server location in Switzerland. When using external AI and cloud services, the company using them remains fundamentally responsible for its data processing under data protection law; the cloud provider often acts as a data processor. The company must therefore carry out appropriate checks on providers, data flows and protective measures.
Key factors include sub-contractors, access rights, storage and deletion policies, the use of input data for model training, and data transfers abroad. Where data is transferred to countries without an adequate level of data protection, the legal requirements for international transfers must be observed.
In terms of procurement and contract drafting, this means that ‘hosting in Switzerland’ alone does not resolve the issue of sovereignty. What matters is who can actually access the data, where further processing takes place, what safeguards are in place, and whether data can be reliably exported and deleted at the end of the contract.
AI in HR: particularly sensitive
Generative AI creates a further legal risk: content may appear technically convincing, yet its use may not be uncontroversial from a legal perspective.
Under current Swiss law, copyright protection generally requires a human intellectual creation. If AI is used merely as a tool and a human being creatively shapes the result themselves, protection may arise. By contrast, a result generated exclusively by the system does not become a protected work merely because a prompt was entered. At the same time, AI outputs may reproduce existing protected content or come so close to it that their use infringes third-party rights. The Swiss Federal Institute of Intellectual Property (IPI) therefore recommends that outputs be reviewed before they are used commercially.
The copyright lawfulness of certain training processes involving protected works has not yet been conclusively clarified in Switzerland. Politically, the issue is evolving: Parliament has referred Motion 24.4596 on better protection of intellectual property against AI misuse to the Federal Council; a draft bill is currently being prepared.
Companies therefore need to establish input and output governance: what confidential or protected content are employees permitted to input? Is the provider allowed to use this data for its own training purposes? Who is permitted to publish a generated text, image or software code commercially? And what contractual assurances does the provider provide?
The EU AI Act does not stop at the Swiss border
The fact that Switzerland does not have its own AI Act does not automatically protect Swiss companies from European AI law. The EU AI Act may also apply to providers or operators outside the EU. This applies, amongst other things, to providers who place AI systems or general-purpose AI models on the market in the EU, as well as – under certain conditions – to providers or operators in third countries if the output generated by an AI system is used within the European Union. Swiss companies must therefore assess the territorial scope of application separately for each relevant business process.
Since 2 August 2026, a large part of the AI Act has generally been applicable; certain obligations came into force earlier. These include, in particular, bans on certain AI practices and requirements regarding AI competence. Furthermore, additional transparency and enforcement mechanisms have been in force since August 2026. The substantive obligations for certain high-risk AI systems have, in some cases, been postponed to later dates as a result of the latest European amendments, specifically to December 2027 and August 2028 respectively.
It would therefore be risky for Swiss companies with links to the EU to interpret the extended transition periods as an invitation to do nothing. HR systems in particular, certain biometric applications or other potentially high-risk systems require long lead times for documentation, risk management, supplier management and internal controls.
From AI policy to scalable governance
A multi-page internal policy alone does not make AI compliant. The key is to integrate legal requirements into processes in such a way that staff can use AI without having to review every project from scratch.
To achieve this, a risk-based governance approach is recommended, featuring a centralised inventory of the AI systems in use, clear lines of responsibility, permitted and prohibited data categories, a tiered approval process, supplier and contract vetting, human oversight of critical decisions, and guidelines for testing, documentation, information security and incident management. Employees must also understand the limitations of the systems in use and recognise when human review is required.
The financial sector is already demonstrating that such governance requirements are not merely a theoretical issue for the future. FINMA has identified AI as a supervisory issue and cites, amongst other things, governance and accountability, data and model risks, robustness, reliability, as well as transparency and explainability as relevant risk areas for supervised institutions.
Conclusion: Legal certainty is becoming a scaling factor
The Swiss IT Study aptly describes a Swiss AI dilemma – yet it can be resolved legally. Companies do not need to wait for comprehensive Swiss AI legislation. The key guidelines already exist. Anyone wishing to scale AI in the long term should not wait until the end of a project to assess data protection, employee data protection, information security, copyright, supplier contracts and potential obligations under the EU AI Act. These factors must be integrated into architecture, procurement and governance from the very outset. In this way, Switzerland’s comparatively flexible regulatory framework can even become an advantage. However, it is essential not to confuse flexibility with a lack of rules. Companies that establish a robust AI governance system now are likely to be better prepared, and not just from a regulatory perspective. They are also laying the groundwork for actually turning successful pilot projects into scalable business benefits.
Sources
- Computerworld – Switzerland’s AI Dilemma, 24 June 2026
- Federal Chancellery – Regulation of Artificial Intelligence
- Federal Council – AI regulation: Federal Council intends to ratify the Council of Europe Convention
- Council of Europe – Framework Convention on Artificial Intelligence
- FDPIC – AI and data protection
- IGE – Copyright issues relating to the training and use of artificial intelligence
- Swiss Parliament – Motion 24.4596 ‘Better protection of intellectual property against misuse by AI’
- EUR-Lex – Regulation (EU) 2024/1689, consolidated version
- European Commission – AI Omnibus enters into force
- FINMA – Supervisory Circular 08/2024: Governance and risk management in the use of artificial intelligence