# AI Regulation Switzerland, 2026 Status and Outlook

> AI regulation in Switzerland: the Federal Council's sectoral approach, the Council of Europe AI convention, FDPIC positions and the effect of the AI Act.

- Source: https://www.sidd.swiss/en/insights/ai-regulation-switzerland/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Dr. Dr. Nino Jibuti
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

Switzerland in 2026 has no dedicated "AI Act" but pursues a technology-neutral, sector-specific approach that builds on existing legal frameworks: the Federal Act on Data Protection (DSG), the Code of Obligations, FINMA law, the Medical Devices Ordinance (MepV) and the Therapeutic Products Act (HMG), anti-discrimination law. In February 2025 the Federal Council decided to ratify the Council of Europe Framework Convention on Artificial Intelligence (CETS No. 225) and to prepare targeted amendments in existing law. A standalone horizontal AI regulation modelled on EU Regulation 2024/1689 is not planned.

This article sets out the 2026 status and a realistic outlook:

- The Federal Council decision of February 2025 and the ongoing consultations
- The Council of Europe AI Convention: what it mandates, what it leaves open
- Sector overlays: FINMA, Swissmedic, OFCOM (BAKOM), Federal Office for Cyber Security (BACS / NCSC)
- The position of the Federal Data Protection and Information Commissioner (FDPIC / EDÖB) on AI and automated individual decisions
- De facto relevance of the EU AI Act for Swiss companies (the Brussels effect)
- What Swiss organisations should already be preparing

Important: technology-neutral does not mean unregulated. AI applications that process personal data fall under Art. 5–22 DSG. AI systems affecting consumers fall under the Unfair Competition Act (UWG) and the Consumer Credit Act (KKG). AI in occupational pensions falls under BVG/FZG supervision. The claim that "Switzerland does not regulate AI" is legally wrong.

## Federal Council decision February 2025

On 12 February 2025 the Federal Council took a position on the AI report from FDJP/DETEC and set out three directions. First: ratification of the Council of Europe AI Convention by the end of 2026 with a related consultation on the necessary legislative amendments. Second: targeted sector-specific amendments to existing law rather than a horizontal AI act. Third: legally non-binding measures such as industry self-regulation, best practices and guidelines from the competent federal authorities.

The consultation on implementing the AI Convention is expected to open at the end of 2026, with a Federal Council dispatch to Parliament likely in 2027. Realistic entry into force is 2028 at the earliest. Until then the current legal framework continues to apply, with the addition that FINMA, FDPIC/EDÖB, Swissmedic and other supervisory authorities are continually refining their own supervisory and interpretive documents.

## The Council of Europe AI Convention

The Council of Europe Framework Convention on AI and Human Rights, Democracy and the Rule of Law (CETS No. 225), opened for signature in Vilnius on 5 September 2024, is the first international legally binding instrument on AI regulation. Its substantive requirements are more general than the EU AI Act: protection of human rights, democratic processes and the rule of law; transparency and oversight; accountability and responsibility; equality and non-discrimination; data protection; reliability; safe innovation.

The Convention binds the public sector and leaves it to the contracting parties whether and how it applies to the private sector (Art. 3(1)(b)). Switzerland is likely to apply the Convention to the private sector via existing sectoral laws and the DSG, rather than create a new horizontal obligation. In practice this means AI providers that comply with DSG, MepV, FINMA circulars and, where relevant, the Product Liability Act, will likely also satisfy Convention requirements.

## Sector overlays

FINMA: Supervisory notice 08/2024 of December 2024 sets out expectations for licence holders using AI, governance, bias controls, explainability, outsourcing requirements under circular 18/03 when AI is sourced from third parties. The notice in particular requires, for models that feed into risk decisions (credit scoring, AML triage, insurance pricing), a documented model risk management function.

Swissmedic: medical devices with AI components fall under the MepV in conjunction with the EU MDR 2017/745; EUDAMED registration and conformity assessment are harmonised. OFCOM (BAKOM): a consultation on platform transparency is running for AI-assisted content moderation on Swiss platforms. BACS / NCSC: AI-specific cybersecurity recommendations for critical-infrastructure operators address adversarial attacks, model poisoning and prompt injection. Anyone operating in a regulated sector must run sector-specific and horizontal requirements together.

## FDPIC / EDÖB positions on AI

Since 2023 the FDPIC has published several positions on AI. The core message: the DSG is technology-neutral and therefore directly applicable to AI. Providers and deployers of AI systems must comply with the principles in Art. 6 DSG (lawfulness, good faith, proportionality, purpose limitation, data minimisation, accuracy, data security). For profile-based processing, the enhanced transparency duties in Art. 19(2)(d) apply and, for "profiling with high risk", the explicit consent requirement under Art. 6(7)(b).

Particularly relevant: Art. 21 DSG on automated individual decisions. If a decision is taken exclusively by automated means and produces legal effects or significantly affects the data subject, the person must be informed and may demand human review. The FDPIC actively examines this duty in audits at insurers, banks and HR platforms. A data protection impact assessment (DPIA) under Art. 22 DSG is generally mandatory for high-risk AI; the FDPIC issued a DPIA guidance with an AI focus in 2024.

## Brussels effect: AI Act reaches Switzerland

Even without a national AI act, Swiss companies are affected by the EU AI Act when they offer in the EU market or when their AI outputs are used in the EU (Art. 2(1)(a) and (c) AI Act). In practice, almost every larger Swiss firm falls into Wave 3 or Wave 4: B2B SaaS with EU customers, medical device manufacturers selling into the EU, cross-border recruiters, financial services with EU branches.

In addition, a de facto Brussels effect emerges: EU corporate customers pull their Swiss suppliers into the AI Act compliance orbit, often contractually before Wave 3 applies. Anyone negotiating contracts with German or French large customers in 2026 regularly sees AI Act conformity clauses, audit rights and indemnities. The rational answer for Swiss providers is not to "wait for Swiss regulation" but to treat AI Act conformity as a market-access condition right away.

## What Swiss organisations should prepare now

First: set up AI governance. An internal AI policy with roles (AI officer, model risk manager), permitted use cases, prohibited use cases (even though the AI Act prohibitions are "only" EU law, the ethical reasoning applies in Switzerland too), a release process for new models and an AI register. Second: DSG compliance for every AI application handling personal data, register entry, transparency in the privacy notice, DPIA for high risk, mechanism for Art. 21 rights.

Third: review contracts. Processor agreements with AI suppliers must clarify whether input data is used for model training, whether output is usable under copyright, where processing takes place, how incident reporting works. Fourth: AI literacy under Art. 4 AI Act for staff with EU exposure, and de facto for all, because it also satisfies DSG due-diligence expectations. Fifth: review sector specifics, FINMA supervisory notice 08/2024, Swissmedic guidance, BACS / NCSC recommendations.

## How SIDD supports you

Switzerland does not regulate AI with a single statute but with layers of DSG, sector law, international commitments and de facto EU alignment. SIDD helps integrate those layers into a coherent AI governance: AI inventory, classification, policy, DPIA process, supplier management, AI literacy training. We tie the DSG track to the AI Act duties so that EU-exposed companies build compliance once and reuse it many times. Further reading: [EU AI Act guide for Switzerland](https://www.sidd.swiss/einblicke/eu-ai-act-schweiz-leitfaden) and [AI Act × DSG × GDPR](https://www.sidd.swiss/einblicke/ai-act-ndsg-dsgvo-schnittstelle). For DPO support on AI topics under the DSG, see [Swiss data protection adviser](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland). To request a concrete status assessment, use the [quote form](https://www.sidd.swiss/en/quote); for confidential initial conversations, reach us via the [contact form](https://www.sidd.swiss/en/contact).

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
