Jurisdiction
Switzerland
- Source
- Editorial review of primary sources — not yet re-anchored
- Verified
- Evidence not verified
- Confidence
- Low
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
01Framework
Switzerland has no AI statute — the federal communications office states officially that there is currently no specific legislation on AI. AI deployment is governed by the revised Federal Act on Data Protection for automated decisions, impact assessments and cross-border disclosure, by FINMA expectations in the financial sector, and above all by criminal professional-secrecy law. Banking secrecy and Criminal Code article 321 are the real blockers for cloud AI in Swiss banking, legal and healthcare work, and the liability they carry falls on an individual rather than on the company. A bill implementing the Council of Europe AI Convention is in preparation, with a consultation draft due by the end of 2026.
- Region
- Europe
- ISO code
- CH
- Privacy framework
- The revised Federal Act on Data Protection (nFADP/revDSG), SR 235.1, in force since 1 September 2023, with the Data Protection Ordinance and the Ordinance on Data Protection Certification. The AI-relevant provisions are article 21 on automated individual decisions — a duty to inform, a right to state a point of view and a right to review by a natural person on request — article 22 on impact assessments, article 23 on prior consultation of the Commissioner where residual risk stays high, articles 16 and 17 on cross-border disclosure, article 24 on breach notification, article 9 on processors and article 7 on data protection by design. Sanctions are criminal fines of up to CHF 250,000 imposed on responsible private individuals, not administrative fines on companies, which changes who in an organisation has to have read the assessment.
- AI-specific rules
- No horizontal AI regulation is in force. In February 2025 the Federal Council decided to ratify the Council of Europe Framework Convention on Artificial Intelligence and to legislate sector-specifically as far as possible, limiting cross-sector rules to fundamental-rights areas such as data protection, and instructed the justice department to prepare a consultation bill by the end of 2026. As at the review date no consultation draft had been opened. Switzerland signed the Convention in March 2025 but has not ratified it, and the Convention is not yet in force anywhere. The Federal Data Protection and Information Commissioner’s standing position is that the FADP, being technology-neutral, applies directly to AI-supported data processing — so the absence of an AI statute is not an absence of duties. In financial services, FINMA Guidance 08/2024 sets AI governance expectations alongside the operational-risk and outsourcing circulars, and FINMA has no AI regulation project pending.
- Last reviewed
- 20 Aug 2026
- Status
- published
Cross-border transfer
The FADP permits disclosure abroad to States, territories, sectors or international bodies the Federal Council has listed as adequate, and that list is Annex 1 to the Data Protection Ordinance. Its United States entry is limited to organisations certified under the Principles of the Swiss-US Privacy Framework, resting on Executive Order 14086, the Data Protection Review Court rule and Intelligence Community Directive 126. That limitation is the trap: a vendor certified under the EU-US Data Privacy Framework but not the Swiss programme is not covered, and the fallback is contractual clauses notified to or approved by the Commissioner, binding corporate rules, or one of the narrow derogations. Unlawful disclosure abroad is a criminal offence carrying a fine of up to CHF 250,000 imposed on the responsible individual — which is why this is usually the first question a Swiss legal team asks about a model vendor.
Regulators
Primary sources
- LegislationFederal Act on Data Protection (FADP), SR 235.1
- LegislationData Protection Ordinance (DPO), SR 235.11, including Annex 1
- LegislationOrdinance on Data Protection Certification (DPCO), SR 235.13
- LegislationBankengesetz (BankG), SR 952.0 — banking secrecy
- LegislationSwiss Criminal Code (StGB), SR 311.0 — Article 321 professional confidentiality
- Regulator pageOFCOM — artificial intelligence
- Regulator guidanceFDPIC — AI and data protection
- Regulator guidanceFINMA Guidance 08/2024 — governance and risk management when using AI
- Regulator guidanceFINMA Circular 2023/1 — Operationelle Risiken und Resilienz, Banken
- Regulator guidanceFINMA Circular 2018/3 — Outsourcing
- Regulator pageFederal Department of Justice and Police — künstliche Intelligenz
02Regulations and guidance
| Instrument | Status |
|---|---|
| Banking Act art. 47Swiss banking secrecy. Disclosing a secret entrusted to a person in their capacity as an officer, employee, agent or liquidator of a bank is a criminal offence carrying a custodial sentence of up to three years. This is the constraint that decides whether a Swiss bank may put client data through a cloud model. | In force |
| Swiss AI billThe Federal Council decided to ratify the Council of Europe AI Convention and to legislate sector-specifically as far as possible, with cross-sector rules limited to fundamental-rights areas such as data protection. As at the review date no consultation draft has been opened. | Proposed |
| DPO / VDSGImplements the FADP: minimum data security requirements, processor obligations, and the criteria for assessing adequacy. Its Annex 1 is the operative Swiss adequacy list, and its United States entry is limited to organisations certified under the Principles of the Swiss-US Privacy Framework. | In force |
| FDPIC AI statementThe Commissioner’s position that the FADP, being technology-neutral, applies directly to AI-supported data processing — so the absence of an AI statute is not an absence of duties. It also expects transparency about purpose, functionality and data sources, and that people know when they are dealing with a machine. | In force |
| nFADP / revDSGSwitzerland’s general data protection statute. It governs automated individual decisions, impact assessments, prior consultation of the Commissioner, cross-border disclosure and processors — and, unusually, breaches attract criminal fines imposed on the responsible individual rather than administrative fines on the company. | In force |
| FINMA Circ. 2018/3Governs outsourcing by banks, insurers and selected financial institutions: materiality assessment, provider due diligence, contractual requirements, and audit and supervisory access. Buying an AI service is an outsourcing decision under it, not a software purchase. | In force |
| FINMA Circ. 2023/1Governs operational, information and communications technology, cyber and critical-data risk management, and operational resilience, for banks and securities firms. An AI system inside a critical process is inside this circular whether or not anyone calls it a model. | In force |
| FINMA Guidance 08/2024FINMA’s expectations for supervised institutions using AI: identify, assess, manage and monitor model risk, data risk, IT and cyber risk, third-party dependency, and legal and reputational risk. FINMA observed that most institutions’ governance structures for this were still being built. | In force |
| DPCOGoverns the accreditation of certification bodies and the certification of data protection management systems, products and services under the FADP. It is the route by which a Swiss deployment can hold a recognised certification rather than argue its posture from first principles. | In force |
| StGB art. 321Criminalises breach of professional confidentiality by clergy, lawyers, notaries, auditors, doctors, dentists, pharmacists, psychologists, nurses and their assistants. An assistant includes, in practice, whatever handles the material — which is why routing privileged content through a third-party model is a criminal-law question in Switzerland. | In force |
03Common enterprise issues
Professional secrecy
Professional secrecy, not data protection, is the binding constraint on cloud AI
The FADP bars assigning processing to a processor where a statutory or contractual duty of confidentiality prohibits it. Banking secrecy and Criminal Code article 321 — clergy, lawyers, notaries, auditors, doctors, psychologists, nurses and their assistants — therefore gate any cloud model touching client or patient material, and the route out is consent or an authorisation, not a contract clause.
Cross-border transfers
EU-US Data Privacy Framework certification does not carry over
The Swiss adequacy list covers the United States only for organisations certified under the Swiss-US Privacy Framework specifically. Checking a vendor’s European certification and concluding the transfer is adequate is a common and consequential error, because getting it wrong is a criminal offence with personal liability.
Automated decision-making
Article 21 does grant human review — but only on request, and with exemptions
The controller must flag a decision based exclusively on automated processing with a legal consequence or considerable adverse effect, allow the person to state a view, and grant review by a natural person on request. Decisions directly connected with contract performance where the request is granted, and decisions consented to, are carved out.
High-risk AI
A high-risk assessment can force a two-month standstill before launch
An impact assessment is mandatory where processing is likely to result in a high risk, in particular large-scale processing of sensitive data or systematic large-scale monitoring. Where residual risk stays high, the Commissioner must be consulted first and has two months to object, extendable for complex processing. That is a schedule risk, not a document.
Sector rules
FINMA expects documented AI governance, and no AI circular is coming
FINMA Guidance 08/2024 tells supervised institutions to identify, assess, manage and monitor model, data, cyber, third-party and reputational risk from AI, and observed that most governance structures were still being built. It sits alongside the operational-risk and outsourcing circulars, and FINMA has no AI regulation project pending.
04Vendor restrictions
Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.
No vendor restriction has been recorded for this jurisdiction.
05Stacks with notes for this jurisdiction
No published stack carries a compliance note for this jurisdiction yet.
06Evidence
Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.
No sources were recorded for this answer. Nothing on this page should be treated as verified.
Improve this page
Sign in to contribute
From the field
0 deployments · 0 questions
Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.