Trackers
Trackers

AI Regulation in Switzerland: 2026 Update

Switzerland has chosen a measured, risk-proportionate approach to AI regulation rather than a sweeping single statute. Businesses operating in Switzerland face a patchwork of existing laws - covering data protection, product liability, financial services and employment - that already apply to AI systems, alongside active policy work that is shaping dedicated AI governance rules. For international founders, technology companies and in-house counsel, understanding the current landscape and the direction of travel is essential to avoid compliance gaps and reputational risk. This guide covers the existing legal framework, the relationship with the EU AI Act, sector-specific obligations, recent legislative developments, and the practical steps businesses should take now.

The current legal framework for AI regulation in Switzerland

Switzerland does not yet have a single AI-specific statute. Instead, ai regulation switzerland is built on a layered set of existing laws that collectively govern how AI systems may be developed, deployed and marketed.

The Federal Act on Data Protection (revDSG), which entered full force in recent years, is the most directly relevant instrument. It applies to any automated processing of personal data, including AI-driven profiling, recommendation engines and decision-support tools. The revDSG introduces a right to explanation for automated individual decisions with significant legal or comparable effects, mirroring the logic of the EU';s General Data Protection Regulation. Controllers must be able to explain the logic behind such decisions and allow individuals to request human review. Failure to comply can trigger administrative proceedings and reputational consequences.

Product liability law under the Product Liability Act (Produkthaftpflichtgesetz) applies when an AI system is embedded in a physical product or constitutes a product in its own right. If a defective AI component causes personal injury or property damage, the producer bears strict liability. Swiss courts have not yet issued landmark rulings on AI-specific product liability, but the statutory framework is clear and applies today.

The Code of Obligations governs contractual relationships involving AI services. Providers of AI tools must ensure their contractual documentation accurately describes the system';s capabilities and limitations. Misrepresentation of AI performance can give rise to claims for breach of contract or pre-contractual liability.

Switzerland';s relationship with the EU AI Act

Switzerland is not an EU member state and is therefore not directly bound by the EU AI Act. However, the practical relationship between Swiss AI regulation and the EU framework is close and consequential for any business operating across both jurisdictions.

Swiss companies that place AI systems on the EU market, or whose AI systems are used by EU-based individuals, must comply with the EU AI Act regardless of where the developer is incorporated. This means Swiss AI developers targeting European customers face the full weight of EU obligations - including conformity assessments for high-risk systems, CE marking requirements and registration in the EU database for high-risk AI - without Switzerland being party to the regulation.

Switzerland';s Federal Council has explicitly stated that it is monitoring EU AI Act developments and intends to assess the need for alignment. The Swiss approach to regulatory alignment with the EU has historically followed a bilateral, sector-by-sector model. In practice, many Swiss companies are already building internal compliance programmes that satisfy EU AI Act requirements, because their customer base or supply chains require it. This dual-track reality - Swiss law on one side, EU obligations on the other - is the defining feature of the current landscape.

The Swiss-EU institutional relationship also affects mutual recognition of conformity assessments. Under the existing Mutual Recognition Agreement (MRA), certain product conformity assessments conducted in Switzerland are recognised in the EU. The extension of this logic to AI-related product categories is under active discussion, and businesses should monitor developments closely.

Sector-specific AI obligations in Switzerland

Several Swiss regulatory authorities have issued guidance or applied existing rules to AI in ways that create concrete obligations for specific industries.

Financial services. FINMA, the Swiss Financial Market Supervisory Authority, has addressed AI in the context of its existing supervisory framework. FINMA expects supervised institutions - banks, insurance companies, asset managers and fintech firms - to apply the same governance standards to AI-driven processes as to any other material business process. This means documented model risk management, explainability requirements for credit and underwriting decisions, and senior management accountability for AI-related risks. FINMA';s circular on operational risk and its guidance on outsourcing apply when AI functions are delegated to third-party providers.

Healthcare and medical devices. AI systems used as medical devices are regulated under the Medical Devices Ordinance (MepV), which aligns closely with the EU Medical Device Regulation (MDR). Software that qualifies as a medical device - including diagnostic AI tools - must undergo conformity assessment, obtain a CE mark and be registered in the relevant database. Swissmedic, the national competent authority, supervises compliance. The threshold for classification as a medical device is functional: if the software is intended to influence clinical decisions, it is likely to qualify.

Employment and workplace AI. The Code of Obligations and the Labour Act impose obligations on employers who deploy AI for performance monitoring, recruitment screening or workforce management. Employees have rights to information about automated monitoring systems. Works councils and employee representatives must be consulted before significant changes to working conditions, which can include the introduction of AI-driven management tools.

Public procurement and government AI. Federal and cantonal authorities are developing internal guidelines for the use of AI in public administration. The Federal Chancellery has published principles for responsible AI use by government bodies, emphasising transparency, accountability and non-discrimination. These principles do not yet have statutory force but signal the direction of future binding rules.

If your business operates in any of these sectors, contact info@vlolawfirm.com to assess your current compliance position. We can assist with gap analyses and regulatory mapping across Swiss and EU requirements.

Recent legislative developments and the Swiss AI policy agenda

Switzerland';s legislative approach to AI has accelerated in recent periods. The Federal Council and the Federal Department of Justice and Police (EJPD) have been conducting consultations on whether a dedicated AI Act is needed, and if so, what form it should take.

The Swiss approach favours a horizontal, risk-based model rather than a sector-by-sector patchwork. Under this model, AI systems would be classified by risk level - from minimal-risk applications such as spam filters to high-risk systems used in critical infrastructure, law enforcement or employment - with obligations scaled accordingly. This mirrors the EU AI Act';s architecture, though the Swiss version is expected to be lighter in administrative burden, consistent with Switzerland';s tradition of proportionate regulation.

A non-obvious requirement that many foreign businesses miss is that Switzerland';s cantonal structure means implementation of federal AI rules may vary in practice across cantons, particularly in areas such as public services, healthcare administration and education. Businesses operating across multiple cantons should not assume uniform application.

The Swiss Parliament has received several motions and postulates calling for faster legislative action on AI. The Federal Council';s response has been to commission expert reports and engage with the OECD AI Policy Observatory and the Council of Europe';s AI Convention process. Switzerland signed the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law - a binding international treaty - which creates obligations around transparency, accountability and human rights safeguards for AI systems used by public authorities and, in some provisions, private actors.

Recent revisions to the Swiss Criminal Code are also relevant. Automated systems that generate deepfakes, manipulate individuals or facilitate fraud are subject to existing criminal provisions on fraud, forgery and defamation. Prosecutors have begun applying these provisions to AI-generated content, and businesses should ensure their AI tools cannot be used in ways that trigger criminal exposure.

Practical compliance steps for businesses operating in Switzerland

For businesses already active in Switzerland or planning to enter the market, the following framework captures the most important practical actions.

Conduct an AI inventory. Map every AI system your business uses or provides, including third-party tools embedded in your products or services. Classify each system by function, data inputs, outputs and the decisions it influences. This inventory is the foundation of any compliance programme.

Apply the revDSG to all personal data processing. Any AI system that processes personal data about Swiss residents must comply with the revDSG. Key obligations include:

  • Maintaining a record of processing activities
  • Conducting data protection impact assessments for high-risk processing
  • Providing transparency notices to data subjects
  • Implementing the right to explanation for automated decisions

Assess EU AI Act applicability. If your AI systems are used by EU-based customers or deployed in EU contexts, map your obligations under the EU AI Act independently of your Swiss compliance work. High-risk AI systems require conformity assessments, technical documentation and post-market monitoring.

Review contracts with AI vendors. Contracts with AI tool providers must address data processing, liability allocation, explainability obligations and audit rights. Standard vendor terms frequently do not satisfy Swiss or EU requirements. A common mistake is accepting vendor terms without reviewing them against applicable law.

Engage sector-specific regulators proactively. FINMA, Swissmedic and other authorities welcome early engagement on novel AI deployments. Proactive dialogue reduces the risk of enforcement action and can provide informal guidance on compliance expectations.

Build governance structures. Assign clear internal accountability for AI systems. Document decision-making processes, model validation procedures and incident response plans. Senior management accountability is expected by regulators across all sectors.

In practice, founders should consider that the cost of retrofitting compliance into an AI system after deployment is significantly higher than building it in from the start. Many underestimate the documentation burden associated with high-risk AI systems, particularly the requirement to maintain technical documentation throughout the system';s lifecycle.

A practical scenario: a Swiss fintech company deploys an AI-driven credit scoring tool for retail customers. Under the revDSG, it must provide an explanation of the scoring logic to any customer who requests it and allow human review of adverse decisions. Under FINMA';s model risk guidance, it must document the model';s development, validation and ongoing monitoring. If the tool is also used by EU customers, the EU AI Act classifies credit scoring as a high-risk application, triggering conformity assessment obligations. The company faces three overlapping compliance regimes simultaneously.

A second scenario: a healthcare software startup develops an AI diagnostic tool for use in Swiss hospitals. If the tool influences clinical decisions, it is likely classified as a medical device under the MepV. The startup must engage Swissmedic, conduct a conformity assessment and obtain CE marking before the tool can be used in clinical settings. Skipping this step - a common mistake among software companies unfamiliar with medical device law - results in the product being unlawful to deploy, regardless of its technical quality.

FAQ

What AI-specific laws currently apply to businesses in Switzerland?

Switzerland does not yet have a single AI statute. Businesses are governed by the Federal Act on Data Protection (revDSG), the Product Liability Act, the Code of Obligations, sector-specific regulations from FINMA and Swissmedic, and the Council of Europe AI Convention to the extent it applies to their activities. The Federal Council is actively developing a dedicated AI governance framework, but it has not yet been enacted. In the meantime, compliance requires mapping existing laws to each AI system';s specific function and risk profile. Foreign businesses often underestimate how many existing Swiss laws already apply to their AI tools.

How long does it take to achieve AI compliance in Switzerland, and what does it cost?

The timeline and cost depend heavily on the complexity of the AI system and the sectors involved. A straightforward SaaS tool processing personal data may require a few weeks of legal review and documentation work, with professional fees in the low to mid thousands of CHF. A medical device AI or a high-risk financial services application requires conformity assessments, technical documentation and regulatory engagement that can take several months and cost significantly more. Businesses that also need to comply with the EU AI Act face additional parallel workstreams. Building compliance into the development process from the outset is consistently less expensive than remediation after deployment.

Should a Swiss AI company structure its compliance around Swiss law or the EU AI Act?

The answer depends on where the company';s customers and operations are located. A company serving only Swiss customers and operating entirely within Switzerland can focus on Swiss law for now, while monitoring the Federal Council';s legislative agenda. A company with EU customers or EU-based operations must comply with the EU AI Act regardless of its Swiss incorporation. Most Swiss AI companies with any European market exposure are building compliance programmes that satisfy both frameworks simultaneously, because the cost of maintaining two separate programmes is higher than designing a unified approach from the start. Legal counsel familiar with both Swiss and EU requirements is essential for this work.

Conclusion

Switzerland';s approach to AI regulation is pragmatic and evolving. Existing laws already create real obligations for AI developers and deployers, and the legislative agenda points toward a dedicated, risk-based framework that will add further requirements. Businesses that act now - by inventorying their AI systems, applying existing law rigorously and monitoring EU AI Act obligations - will be better positioned than those waiting for a single definitive statute.

VLO Law Firms advises international clients on AI regulation in Switzerland. We can assist with compliance assessments, regulatory mapping across Swiss and EU frameworks, contract review, and engagement with Swiss supervisory authorities. To request a consultation, contact: info@vlolawfirm.com