AI Policy Template for Swiss SMEs
Introduction
In May 2026, an AI policy is no longer a luxury for Swiss SMEs but a compliance foundation, for three reasons. First: Art. 4 EU AI Act has, since February 2025, required sufficient "AI literacy" of every person handling AI systems on behalf of a provider or deployer, with an evidence obligation. Second: the DSG requires under Art. 7 and 8 organisational and technical measures to ensure lawful processing, without an AI policy, the evidence is missing. Third: without a policy, shadow-AI risks (data breaches, IP loss, breach of secrecy, hallucinations in customer outputs) arise that are individually costly and cumulatively existential.
This article sets out the structure of an adaptable policy:
- Scope, definitions, roles
- Permitted tools and data classification matrix
- Prohibited and conditionally permitted use cases
- Human-in-the-loop and output responsibility
- Supplier management and processing agreement duties
- Incident response and reporting channels
- Training, sanctions, version management
The structure presented here corresponds to the AI policy SIDD uses as a starting point in mandates and adapts to sector (FINMA, hospital, lawyer, trustee, classical industrial SME), size and risk exposure.
Scope, definitions, roles
§ 1 Scope: The policy applies to all employees, apprentices, interns, temporary staff, external advisers and contractors who access AI systems on behalf of or under the supervision of the company or use the output thereof. It forms part of the staff regulations or the respective assignment or consulting contracts.
§ 2 Definitions: AI system per Art. 3 No. 1 EU AI Act (machine-based system operating at varying levels of autonomy that may be adaptable after deployment); generative AI (subset that produces text, images, audio, video or code); input (prompt plus any context data); output (whatever the system produces). § 3 Roles: AI owner (typically CIO, CISO or DPO), model owner (business owner for each approved use case), user (any authorised person), data protection officer (DSB per Art. 10 DSG), compliance officer.
Permitted tools and data classification
§ 4 Tool whitelist: Only explicitly listed tools may be used for work purposes. Example list: (i) Microsoft 365 Copilot within the company tenant; (ii) ChatGPT Team or Enterprise with company single sign-on; (iii) Claude for Business; (iv) DeepL Pro with enterprise contract. Other tools, including free web versions with private accounts, are not permitted. Pilots require approval by the AI owner with a documented use case and DPIA preliminary review.
§ 5 Data classification matrix: Four classes, Public, Internal, Confidential, Restricted, and per class three permission levels per tool: allowed, allowed with condition, prohibited. Example: in ChatGPT Enterprise, Public and Internal data are allowed; Confidential allowed with documented case review; Restricted (third-party personal data, sensitive personal data, professional-secrecy content, business secrets with IP value) prohibited. In Microsoft 365 Copilot within the Swiss tenant with MIP sensitivity labels: Public, Internal, Confidential allowed; Restricted only where the sensitivity label is configured accordingly. Worded concretely so every user can decide per input.
Prohibited use cases
§ 6 Generally prohibited: all practices under Art. 5 EU AI Act (subliminal manipulation, exploitation of vulnerability, social scoring, predictive policing purely on profiling, untargeted face scraping, workplace/education emotion recognition, biometric categorisation by sensitive attributes, real-time RBI for law enforcement). These prohibitions apply company-wide, also outside EU exposure, for ethical and reputational reasons.
§ 7 Allowed only with conditions: (a) drafting customer communication texts, output must be reviewed by a human, edited before sending, cleared on copyright; (b) contract drafts, only as input; the final version is reviewed by a legal or specialist person; (c) code generation, security and licence check by a second person; (d) candidate screening, AI may only support pre-selection; final hire/no-hire decision by a human; no emotion or personality analysis from video/audio. For Annex III-relevant use cases (HR scoring, credit scoring, insurance risk assessment), the conformity path under the AI Act is to be clarified additionally.
Human-in-the-loop
§ 8 Output responsibility: The using person remains responsible for every generated output, legally and factually. Hallucinations are not an "AI error" but a usage error. Every output that leaves the company (customer e-mail, contract, offer, study, external presentation) requires documented human review before sending. For outputs with legal weight (contract clauses, opinions, financial calculations), a specialist review by a knowledgeable person is mandatory.
§ 9 Automated individual decisions: Within the meaning of Art. 21 DSG / Art. 22 GDPR, decisions based solely on automated processing that have legal effects or significantly affect a person are only permitted where they rest on an explicit statutory or contractual basis, are communicated transparently and the right to human review is ensured. In SME everyday terms: no AI system makes final decisions about customers, applicants, staff or suppliers without human validation.
Supplier management and processing agreement
§ 10 Before procuring a new AI tool, four review steps are mandatory: (a) obtain and review the provider's processing agreement per Art. 9 DSG / Art. 28 GDPR (in particular data location, sub-processors, model-training clauses, deletion and retention rules); (b) for third-country transfer, a transfer impact assessment and where necessary standard contractual clauses + Swiss annex; (c) DPIA preliminary review; (d) security assessment (authentication, encryption, audit logs, certifications).
§ 11 Existing suppliers: annual review of the AI-relevant contract parts. For providers offering GPAI, check whether they have signed the EU GPAI Code of Practice and provide corresponding transparency documentation. § 12 In-house developments with AI components: before go-live, classification under the AI Act (Annex I/III/Art. 5/Art. 50/uncritical); for a high-risk classification, conformity assessment plan and build-out of the risk management file.
Incident response, training, version management
§ 13 Incident notification: the following events are to be reported within 24 hours to the AI or DPO owner: unintended input of Restricted data into an AI system; hallucination forwarded externally; security-relevant anomaly (prompt injection, tool data leak); supervisory or customer query on AI use. The owner assesses within 48 hours whether a data-breach notification under Art. 24 DSG / Art. 33 GDPR to the supervisory authority is required and whether data subjects must be informed.
§ 14 Training: onboarding training for new staff; annual refresher; event-based special trainings on policy changes or incidents. Documentation with attendance lists and understanding confirmation (Art. 4 AI Act). § 15 Version management: the policy is reviewed at least annually, sooner for every AI Act wave and for the introduction of a new central tool. Version status on each document; change history centrally managed. § 16 Sanctions: violations are addressed under labour law, warning on first violation, up to termination on repeat; criminal offences (breach of secrecy) are reported separately.
How SIDD supports you
SIDD develops AI policies tailored to Swiss SMEs, including sector adaptation, technical implementation planning and staff training. We deliver not a PDF but a lived system: policy document, implementation roadmap, communication package, training curriculum, version maintenance process. For clients in FINMA-regulated sectors we integrate the FINMA SN 08/2024 requirements; for EU-oriented firms the AI Act requirements directly.
More on our services at Swiss data protection adviser and on AI literacy training at data protection workshops. Further reading: ChatGPT at work, Copilot data protection, AI Act phases. To request a concrete policy mandate, use our quote form or reach us via the contact form.
