Switzerland does not currently have a general law on artificial intelligence comparable to the European Union’s AI Act. However, it would be wrong to conclude that the use of AI takes place in a regulatory vacuum.
The Swiss model that is progressively emerging is instead a model of layered regulation, built on existing legislation, interventions by sector-specific authorities, self-regulatory instruments and, going forward, the adjustments required to implement the Council of Europe Framework Convention on Artificial Intelligence.
The first layer consists of general legislation already in force, starting with the Federal Act on Data Protection (FADP); the second consists of the rules and expectations developed across the various regulated sectors.
FINMA, for example, has already defined specific supervisory expectations regarding the governance and management of AI-related risks in the banking and insurance sectors; Swissmedic has identified framework conditions for the use of artificial intelligence in the development of medicinal products and in regulatory processes, while also drawing on internationally developed standards.
These instruments are complemented by forms of self-regulation and professional standards, such as the AI principles developed by the Swiss Insurance Association and the FMH recommendations on the use of generative language models in the medical sector.
The future implementation of the Council of Europe Convention on AI will therefore not start from scratch. Rather, it will be incorporated into a legal and regulatory ecosystem that, particularly in certain sectors, already displays a significant degree of maturity.
The main difference from the European approach is methodological. The European Union has chosen to adopt a horizontal regulatory framework, directly applicable across different sectors and primarily based on the classification of AI systems according to their level of risk.
Switzerland, by contrast, has chosen to start from existing law and introduce new rules where concrete gaps emerge, favouring, wherever possible, sector-specific and technology-neutral solutions. The Federal Council formally confirmed this approach on 12 February 2025.
The Council of Europe Convention on AI as a reference point for future regulatory developments
A decisive step in the evolution of the Swiss framework is the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, the first legally binding international treaty specifically dedicated to AI. The Convention adopts a technology-neutral approach and seeks to ensure that activities carried out throughout the lifecycle of AI systems are compatible with fundamental rights, democracy and the rule of law, without hindering technological progress and innovation.
Switzerland signed the Convention on 27 March 2025 and, as of 18 August 2026, the domestic ratification process has not yet been completed.
The Federal Council instructed the FDJP – Federal Department of Justice and Police, together with the other competent departments, to prepare a draft for consultation by the end of 2026. The draft will need to identify the legislative adjustments required, particularly in the areas of transparency, data protection, non-discrimination and oversight. In parallel, a plan will have to be developed for non-legislative measures, such as sector-specific solutions and voluntary declarations of commitment.
It is therefore more accurate to speak not of a future “Swiss AI law” modelled on the AI Act, but rather of a legislative process aimed at implementing the Council of Europe Convention, accompanied by amendments to existing law, sector-specific measures and soft-law instruments.
A system already regulated sector by sector
The Swiss framework can be better understood by looking at several concrete examples.

The case of FINMA, the independent federal authority responsible for financial market supervision, is particularly significant.
In Guidance 08/2024, the Authority expressly notes that, even in the absence of specific Swiss AI legislation, existing technology-neutral requirements relating to governance and financial risk management also cover the risks arising from the use of artificial intelligence.
As part of its supervisory activities, FINMA therefore assesses whether there is a centralised inventory of AI applications, whether they are classified according to risk, whether responsibilities are allocated, and whether testing requirements, documentation, training and controls over external service providers are met.
The Authority also draws attention to data quality, the possibility that historical data may reproduce biases in future predictions, the robustness and stability of models, and the need for continuous testing and monitoring.
Swissmedic, the Swiss authority responsible for the authorisation and supervision of therapeutic products, follows a similar approach. The Authority highlights issues relating to data quality, model transparency, quality control and bias. When assessing materials produced using AI, it takes into account guidance developed by international organisations and authorities such as the WHO, ICH, IMDRF, EMA and FDA.
The central role of the Federal Act on Data Protection
Among the horizontal rules already applicable, a particularly important role is played by the FADP, which entered into force on 1 September 2023.
The Federal Data Protection and Information Commissioner (FDPIC) has expressly clarified that the FADP is drafted in technology-neutral terms and therefore applies directly to the processing of personal data carried out through artificial intelligence systems.
This principle has significant operational consequences. According to the FDPIC, producers, providers and users of AI systems must ensure transparency regarding the purpose of the processing, the functioning of the application and the sources of the data used.
When a language model interacts directly with an individual, the user must also be able to understand that they are communicating with a machine and must be informed when the data they provide are used to improve self-learning systems or for other purposes.
The FDPIC also addresses the issue of synthetic content, stating that the use of programs that make it possible to falsify faces, images or voice messages attributable to identifiable individuals must be clearly disclosed.
Unlike the AI Act, the rule does not require the use of a specific marking technology. Tools such as watermarks, metadata or other identification techniques may constitute possible operational solutions, but what matters from a legal perspective is transparency towards the data subject.
Where processing is likely to result in a high risk to the personality or fundamental rights of data subjects, the data protection impact assessment (DPIA) required under the FADP also becomes relevant. The FDPIC emphasises that high-risk processing supported by AI may still be lawful, provided that it is accompanied by appropriate safeguards and by the prior impact assessment required by law.
A further safeguard concerns automated individual decision-making. In such cases, the FADP grants data subjects specific protections where a decision producing legal effects or similarly significant consequences is taken exclusively through automated processing. In the cases provided for by law, individuals have the right to express their point of view and to request that the decision be reviewed by a natural person.
An example: AI-based credit scoring in a Swiss bank
Imagine that a Swiss bank introduces an AI system designed to calculate a customer’s credit score and to support the decision-making process or even automatically make a decision on whether to grant financing.
The bank could not simply state: “The AI Act does not apply in Switzerland, so we will wait for future legislation.”
Compliance requirements already exist today. The FADP governs the processing of personal data, transparency, profiling, automated decision-making where applicable and, where the level of risk is high, the requirement to conduct a DPIA. At the same time, FINMA Guidance 08/2024 requires the issue to be addressed from the perspective of governance, model risk, data quality, bias, testing, explainability and third-party provider oversight.
This example clearly illustrates the logic of the Swiss system: AI regulation may arise from the interaction of several different laws and authorities, without necessarily being concentrated in a single piece of legislation specifically dedicated to artificial intelligence.
Geneva AI Summit 2027: innovation and trust
Switzerland’s political positioning is also reflected in preparations for the Geneva AI Summit 2027, which will take place in Geneva on 21 and 22 June 2027.
On 12 August 2026, the Federal Council defined the strategic approach and organisational structure of the Summit, appointing Fabiola Gianotti, former Director-General of CERN, as the Federal Council’s delegate for the Summit.
The chosen slogan, “Bridging Innovation and Trust”, effectively summarises the Swiss approach. The two key priorities identified by the Federal Council are, on the one hand, the use of AI as a driver of innovation, prosperity and social progress and, on the other, the creation of the conditions necessary for the trustworthy and responsible development and use of artificial intelligence.
The Summit does not, of course, introduce new legal obligations. However, it represents a significant political signal: Switzerland intends to position itself as a place where technological innovation and trust are not regarded as conflicting objectives, but rather as elements that must be developed together.
Swiss companies and the European AI Act: when it is necessary to look beyond Switzerland
For Swiss companies, it is useful to distinguish between two situations.
Company operating exclusively in Switzerland
The relevant legal framework consists first and foremost of the FADP and other applicable Swiss legislation: sector-specific regulation, employment law, anti-discrimination rules, consumer protection legislation and any other provisions relevant to the specific circumstances. In the future, these rules will be complemented by the adjustments required to implement the Council of Europe Convention.
There is therefore no need to voluntarily apply all provisions of the European AI Act as though they were Swiss law. Instead, organisations must identify precisely which obligations already arise under national law and under the rules applicable to the sector in which they operate.
Swiss company also operating in the European Union
The situation changes when there is a relevant connection with the European market.
In such cases, it is necessary to carry out an AI Act scope assessment, because the European Regulation expressly provides for certain situations in which it applies to entities established in third countries.
This may occur, for example, where a provider places an AI system on the market or puts it into service in the European Union or, under certain circumstances, where providers or deployers established in a third country use systems whose output is used within the EU.
Being a Swiss company therefore does not automatically mean being excluded from the scope of the AI Act.
This is conceptually similar to the issue already encountered in relation to the territorial scope of the GDPR: the company’s registered office is only one of the factors that must be considered; it is necessary to assess the activities actually carried out, the market concerned, the role assumed in relation to the AI system and the place where the system or its output is used.
How to build AI Governance for a Swiss Company today
From an operational perspective, it would be inefficient to build a “Swiss AI compliance” framework that is completely separate from the European one. For organisations operating internationally, it is preferable to adopt a modular AI Governance Framework capable of adapting to different legal systems.
A first layer may be defined as the Swiss Baseline and includes the FADP, transparency, privacy by design, automated decision-making, security, DPIAs where required and applicable sector-specific regulation.
A second layer may consist of the EU Overlay: where there is a relevant connection with the European Union, the framework is supplemented by the classification requirements and obligations arising under the AI Act, the GDPR and any applicable EU sector-specific legislation.
The third layer may be defined as Future Proofing and already incorporates the principles that are expected to become increasingly important in the implementation of the Council of Europe Convention: protection of fundamental rights, transparency, accountability, non-discrimination, oversight, risk and impact assessments. The Convention is deliberately drafted in technology-neutral terms precisely so that it can continue to accommodate the future evolution of AI systems.
Conclusions
The Swiss case demonstrates that regulating artificial intelligence does not necessarily mean adopting a single general law specifically dedicated to AI.
Switzerland is following a different path from that of the European Union: technology-neutral law, a strong role for sector-specific authorities, self-regulation and targeted legislative measures, alongside the future implementation of the Council of Europe Convention.
For companies, the practical consequence is that they should neither automatically apply the European AI Act to all activities carried out in Switzerland nor to passively wait for a future Swiss “AI Law”.
AI compliance is therefore already an operational reality. Organisations must start from the FADP and the applicable sector-specific regulation, assess the potential extraterritorial scope of the AI Act and build governance systems capable of progressively adapting to the evolving regulatory framework.
The distinctive feature of the Swiss model can perhaps be summarised as follows: not a single regulatory framework for artificial intelligence, but an AI governance model progressively built through existing law, sector-specific supervision, organisational accountability and trust.



