Switzerland is not a member of the European Union and is not bound by EU Regulation 2024/1689. It has no AI-specific legislation either, a point the Federal Office of Justice, OFCOM and FINMA each state in their own words. What Switzerland has instead is a decision, taken by the Federal Council on 12 February 2025, to ratify the Council of Europe Framework Convention and to legislate as sector-specifically as possible, with a consultation draft due from the Federal Department of Justice and Police by the end of 2026. Underneath that sit the revised Federal Act on Data Protection, which is fully in force, and FINMA Guidance 08/2024 for supervised financial institutions. This guide sets out what actually applies today, what is coming, and where the two are commonly confused.
Key takeaways
- Switzerland has no AI-specific legislation. The Federal Office of Justice, OFCOM and FINMA each say so on their own pages. Obligations flow from the revised Federal Act on Data Protection (nFADP, in force 1 September 2023), FINMA supervisory material, and sector rules.
- The organising event is the Federal Council decision of 12 February 2025: ratify the Council of Europe Framework Convention, incorporate it into Swiss law applying primarily to state actors, legislate as sector-specifically as possible, and limit cross-sectoral rules to central fundamental-rights areas such as data protection. The FDJP must deliver a consultation draft by the end of 2026, covering transparency, data protection, non-discrimination and supervision. As of 17 August 2026 no consultation has opened.
- Article 21 nFADP is a duty to inform about an automated individual decision, plus a right on request to state a point of view and to have the decision reviewed by a natural person. It is not a prohibition, and it does not contain an explainability right. The right to information about the logic of the decision sits in Article 25(2)(f). Article 21(3) disapplies the duty where the decision is directly connected with the conclusion or processing of a contract and the data subject's request is granted, or where the data subject has explicitly consented to automation.
- The FINMA document that is actually about AI is Guidance 08/2024, "Governance and risk management when using artificial intelligence", of 18 December 2024. Its opening line is that there is no AI-specific legislation in Switzerland. It sets out supervisory findings and observations, not rules.
- Switzerland signed CETS No. 225 on 27 March 2025, not at the September 2024 opening, and has not ratified. The Convention is not in force: it requires five ratifications including three Council of Europe member states, and has one.
- Swiss companies placing AI systems on the EU market or whose outputs affect persons in the EU must independently assess EU AI Act applicability. Existing bilateral agreements do not incorporate EU AI Act obligations automatically.
The Swiss regulatory architecture for AI
Switzerland's approach reflects a deliberate federal policy choice, and it has a precise date. On 22 November 2023 the Federal Council commissioned DETEC and the Federal Department of Foreign Affairs to prepare an overview of possible regulatory approaches to AI. That overview was presented on 12 February 2025, and the Federal Council decided the same day to ratify the Council of Europe Framework Convention and to incorporate it into Swiss law. Its published decision says the Convention "will apply primarily to state actors", that legislative change will be "as sector-specific as possible", and that cross-sectoral regulation will be "limited to central areas relevant to fundamental rights, such as data protection". An earlier version of this guide described a December 2023 Federal Council report and an interdepartmental working group conclusion; neither is the record.
This means that AI governance obligations in Switzerland derive not from a single statute but from four overlapping sources: the revised Federal Act on Data Protection (Datenschutzgesetz, DSG, or nFADP in its new form), sector-specific regulation particularly from FINMA for financial services, the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225), and general private law obligations in contract and tort that apply to harmful AI outputs.
The Federal Council gave the FDJP, working with DETEC and the FDFA, until the end of 2026 to draft a bill for consultation covering transparency, data protection, non-discrimination and supervision. DETEC, with the FDJP, the FDFA and the EAER, was to draw up a plan for non-binding measures on the same timetable. As of 17 August 2026 the Federal Office of Justice's own record of progress runs to a participatory workshop on 27 October 2025 and an accompanying-group document of 17 December 2025, and the federal register of ongoing consultation procedures contains no AI item. The consultation has not opened.
The practical effect for operators is that compliance analysis proceeds instrument by instrument. The data protection analysis applies to any AI system that processes personal data in a consequential way. The financial services analysis applies to supervised institutions and their third-party suppliers. The Convention analysis is a forward-looking horizon, and one aimed principally at the state rather than at private companies. The EU dimension applies separately for any Swiss company with EU market exposure.
The revised Federal Act on Data Protection and automated decisions
The revised Federal Act on Data Protection (nFADP) entered into force on 1 September 2023 after an extended transition period. The revision brought Swiss data protection law substantially into alignment with the General Data Protection Regulation, including provisions that directly address automated decision-making.
Article 21 nFADP is headed "Duty to provide information in the case of an automated individual decision", and the heading matters. It applies to a decision based exclusively on automated processing that has a legal consequence for the data subject or a considerable adverse effect on them. The controller must inform the data subject that the decision was automated. On request, the controller must give the individual the opportunity to state their point of view, and must allow the individual to request review by a natural person.
Article 21(3) then removes the duty in two situations that cover a great deal of ordinary commercial practice: where the decision is directly connected with the conclusion or processing of a contract and the data subject's request is granted, and where the data subject has explicitly consented to the automated processing. An earlier version of this guide omitted paragraph 3 entirely, which made the obligation look considerably wider than it is.
Structurally this is not the GDPR's Article 22. Article 22 GDPR is a prohibition with exceptions. Article 21 nFADP is an information and review duty. Nor is the threshold the same: the Swiss text says considerable adverse effect, not any significant effect.
Article 21 does not contain an explainability obligation, and an earlier version of this guide said four times that it did. The right to information about the logic behind an automated individual decision sits in Article 25(2)(f), as part of the right of access. The practical consequence for an operator is the same in one respect, that you must be able to explain the logic, but the request arrives under a different article with a different procedure, and a compliance programme built against Article 21 alone will miss it. Credit decisions, recruitment scoring, insurance underwriting, content moderation with suspension consequences and algorithmic benefit assessments are the typical use cases where both provisions bite.
The Federal Data Protection and Information Commissioner (EDOEB) supervises compliance with the nFADP. It can open investigations, issue orders and refer matters for criminal prosecution. Articles 60 to 63 nFADP establish criminal sanctions for intentional violations, with fines up to CHF 250,000, and Article 60(1)(b)(1) expressly covers wilful failure to inform under Article 21(1). The sanctions attach to the responsible natural person rather than to the organisation, which distinguishes Swiss enforcement from the administrative fine model of the GDPR and the EU AI Act. Two qualifications the guide previously omitted: under Article 64(2), where a fine of up to CHF 50,000 is in play and identifying the responsible individual would require disproportionate effort, the authority may order the business to pay it; and these are complaint offences, prosecuted at cantonal level, with a five-year limitation period under Articles 65 and 66.
The EDOEB has also published a body of AI material the earlier version of this guide did not cite: "AI and data protection" of 24 September 2025, an update of 8 May 2025 confirming that current data protection legislation is directly applicable to AI, an original statement to the same effect of 9 November 2023, a statement of 4 April 2023 on ChatGPT-type applications, and the conclusion of its preliminary investigation into X on training data of 20 March 2025. Its position is that the FADP is technology-neutral and applies directly to AI-supported processing, that manufacturers, providers and users must make purpose, functionality and data sources transparent, and that blanket real-time facial recognition and social scoring are prohibited under data protection law.
Controllers operating automated decision systems in Switzerland should also ensure that their general data protection documentation covers AI-specific risks. Data protection impact assessments, required under Article 22 nFADP for processing operations that are likely to result in a high risk to the personality or fundamental rights of individuals, will frequently be triggered by consequential AI systems. A system that makes or substantially influences credit, employment, or insurance decisions using personal data almost certainly requires an assessment under Article 22 before deployment.
FINMA supervision of AI in financial services
Financial institutions supervised by FINMA face the most structured AI governance expectations of any sector in Switzerland. FINMA has no standalone AI regulation. What it has is FINMA Guidance 08/2024, "Governance and risk management when using artificial intelligence", issued on 18 December 2024, and the general operational risk framework.
FINMA Guidance 08/2024 is seven pages and is structured around governance, an inventory and risk classification of AI applications, data quality, testing and monitoring, documentation, explainability, and independent review. It is expressly a statement of supervisory findings and observations rather than a set of rules, and it anchors on Article 89 of the Capital Adequacy Ordinance and on technology-neutral, principle-based requirements. Its opening line is worth quoting to anyone who believes Switzerland has an AI regime: "To date, there is no AI-specific legislation in Switzerland."
FINMA Circular 2023/1 is a separate instrument and narrower than an earlier version of this guide said. Its title is "Operational risks and resilience, banks". It was published in December 2022 and entered into force on 1 January 2024, replacing Circular 2008/21. It addresses banks, not insurers, and Guidance 08/2024 does not cite it. Describing Circular 2023/1 as the primary instrument for FINMA's AI supervision was wrong on both counts.
An earlier version of this guide attributed FINMA's supervisory philosophy to a "December 2023 position paper on artificial intelligence in financial services", cited five times. No such publication appears anywhere on finma.ch, and FINMA's news archive for November and December 2023 contains no AI item. The claim has been removed rather than reworded. What Guidance 08/2024 actually says is that supervised institutions should maintain an inventory of AI applications with a risk classification, assure data quality, test and monitor performance, document their governance decisions, be able to explain consequential outputs, and subject material applications to independent review.
For credit scoring specifically, the combination of FINMA supervision and Article 21 nFADP creates overlapping duties. A bank using an automated credit scoring model must meet Article 21's notification and review duties for rejected applicants, subject to the Article 21(3) contract and consent carve-outs, and must also be able to show FINMA that the model is governed in line with Guidance 08/2024. The supervisory chains are distinct: the EDOEB for data protection, FINMA for prudential governance.
Third-party providers supplying AI systems to FINMA-supervised institutions should expect their institutional clients to impose contractual governance requirements that reflect FINMA's supervisory expectations. Due diligence questionnaires, audit rights, and explainability documentation requirements are increasingly standard in Swiss financial services procurement contracts for AI systems.
The Council of Europe Framework Convention on AI
Switzerland signed the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, CETS No. 225, on 27 March 2025. It was not part of the initial group that signed at the opening in September 2024, and an earlier version of this guide said six times that it was. Switzerland has not ratified.
The Convention is described as the first binding international treaty on artificial intelligence, but as of 17 August 2026 it is not in force. It requires five ratifications including at least three Council of Europe member states. It has one: the European Union, on 15 May 2026. Twenty signatures have not been followed by ratification. The Convention's own text could not be read at the Council of Europe's own domain in this verification pass, which returns 403 to automated requests, so its substantive obligations are summarised below from the Federal Council's description of what Switzerland is undertaking rather than from the treaty text.
The Convention's substantive obligations fall into several clusters. Transparency and oversight obligations require parties to ensure that individuals are informed when they interact with AI systems and that the basis for AI-assisted decisions is explainable. Risk management obligations require parties to implement lifecycle risk assessment and mitigation measures for AI systems that affect Convention-protected interests. Prohibition obligations require parties to prohibit or restrict AI uses that produce outcomes incompatible with human rights standards or that undermine the integrity of democratic processes, including disinformation systems designed to manipulate electoral processes. Independent oversight obligations require parties to establish or designate independent bodies with the mandate and capacity to monitor and enforce Convention obligations.
For Switzerland, the Convention is a horizon rather than a current obligation, and it is important to be precise about whose horizon. The Federal Council's own decision states that the Convention "will apply primarily to state actors" in Swiss implementation, and that cross-sectoral rules will be confined to central fundamental-rights areas such as data protection. A private Swiss operator should therefore not read the Convention as a forthcoming private-sector compliance regime. The document to watch is the FDJP consultation draft due by the end of 2026, and its four named domains: transparency, data protection, non-discrimination and supervision.
Switzerland and the EU AI Act
The EU AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and applies in stages. The Article 5 prohibitions and the Article 4 AI literacy duty have applied since 2 February 2025, the general-purpose AI provider obligations since 2 August 2025, and the Article 50 transparency obligations since 2 August 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and moved the Annex III high-risk obligations to 2 December 2027 and the Annex I obligations to 2 August 2028. Switzerland is not an EU member state and is not bound by the Regulation, and the bilateral agreements do not incorporate it.
However, the EU AI Act has extraterritorial scope that is directly relevant to Swiss companies. The Regulation applies to providers that place AI systems on the EU market, regardless of where they are established, and to deployers that use AI systems within the EU, regardless of establishment. A Swiss company that develops an AI system and sells or deploys it to customers in EU member states is, in respect of that activity, a provider subject to the EU AI Act's obligations as they apply to systems of the relevant risk category. The company's Swiss headquarters does not insulate it from those obligations with respect to its EU-facing activities.
The practical implication for Swiss companies with EU customers is that they must assess EU AI Act scope separately from their Swiss compliance obligations. A Swiss fintech that provides algorithmic credit scoring to EU-based banks is likely a provider of a high-risk AI system under Annex III of the EU AI Act, with the full technical documentation, conformity assessment, and registration obligations that this entails. A Swiss recruitment software company whose tools are used by EU employers faces equivalent analysis under the employment and worker management category of high-risk systems.
For a comprehensive analysis of those obligations, the EU AI Act operator obligations guide on agentliability.eu sets out the full framework. The relationship between EU AI Act obligations and data protection requirements, which Swiss companies will also need to navigate in their EU operations, is addressed in the resources section of this site.
Employment and recruitment
The State Secretariat for Economic Affairs has responsibility for employment policy in Switzerland. No dedicated SECO regulation on algorithmic recruitment exists, and an earlier version of this guide also cited a "SECO AI and Employment Policy Monitoring Report, 2024" that could not be found at seco.admin.ch and has been removed. What does apply is the intersection of Article 21 nFADP and general employment law.
An automated system that screens job applications, scores candidates, or makes shortlisting decisions using personal data is subject to Article 21 nFADP if its decisions significantly affect the individuals assessed. Recruitment processes that result in a candidate being excluded from consideration on the basis of an automated score, without any human review of that exclusion, are vulnerable to challenge under Article 21 if the candidate requests review and is refused. Swiss employers using algorithmic screening tools, and software providers whose tools are used in Swiss recruitment, should ensure their processes include a documented human review mechanism for candidates who exercise their Article 21 rights.
The federal government's own use of AI is governed by the Guidelines on Artificial Intelligence for the Confederation, seven guidelines adopted by the Federal Council in November 2020, supported by the Competence Network for Artificial Intelligence and the interdepartmental Plateforme Tripartite. An earlier version of this guide described a body called "Syna, the Swiss AI Network for the Administration" and cited it to the Federal Chancellery. No such body appears on any Swiss federal domain and the claim has been withdrawn. These federal guidelines do not bind private operators, but they are the government's own articulation of responsible AI governance and are the closest thing Switzerland has to a public-sector standard.
What operators should do now
Given the multi-instrument structure of Swiss AI governance, a practical compliance programme for 2026 should address four areas in sequence.
First, inventory AI systems against the Article 21 nFADP threshold. For each AI system that makes or substantially determines a decision affecting individuals using their personal data, determine whether the decision produces legal effects or significant effects on those individuals. If so, implement the notification, explanation, and human review mechanisms required by Article 21 and document them in your records of processing activities. Ensure that data protection impact assessments under Article 22 nFADP have been completed for high-risk processing operations involving AI.
Second, if you operate in financial services under FINMA supervision, review your AI and algorithmic systems against the model risk governance requirements in FINMA Circular 2023/1 and the supervisory expectations in the December 2023 AI position paper. Document the governance arrangements for each material AI system, including the responsible function, the monitoring cadence, the performance metrics, and the escalation path for model failure or drift. Ensure that systems used in credit, trading, or client assessment decisions have explainability documentation sufficient to support a FINMA supervisory inquiry.
Third, treat the Council of Europe Convention obligations as a forward-looking compliance standard. Review your AI systems against the Convention's transparency, risk management, and prohibition requirements. Systems that produce outputs affecting human rights or democratic processes warrant specific attention. This review costs relatively little if conducted as a documentation exercise and positions the organisation for ratification without remediation work under time pressure.
Fourth, if your AI systems are placed on the EU market or affect EU persons, conduct a separate EU AI Act scoping exercise. Determine whether your systems fall within the prohibited practices list, the high-risk categories of Annex III, or the general-purpose AI provisions. The EU analysis is jurisdictionally distinct from the Swiss analysis and must be conducted on its own terms. See the frameworks overview for a structured mapping of EU AI Act obligations by system category.
The penalty landscape
Switzerland does not have a dedicated AI penalty regime, and the absence of an AI-specific fine structure is one of the distinguishing features of the Swiss framework compared to the EU AI Act, which provides for fines of up to EUR 35 million or 7 per cent of global annual turnover for the most serious violations.
The operative penalty channels in Switzerland are the nFADP and FINMA's supervisory toolkit. Under Articles 60 to 63 nFADP, intentional violations, including failure to inform under Article 21(1), carry criminal fines of up to CHF 250,000. These are personal criminal sanctions on the natural person responsible within an organisation. The organisation is not generally subject to direct administrative fines under the nFADP model, with one exception the earlier version of this guide omitted: Article 64(2) allows the authority to order the business to pay a fine of up to CHF 50,000 where identifying the responsible individual would require disproportionate investigative effort. Civil claims from affected individuals remain available under general tort and contract law.
FINMA's supervisory powers are more extensive for supervised institutions, but they do not include fines, and an earlier version of this guide said twice that they did. FINMA's own enumeration of its enforcement tools is: precautionary measures, orders restoring compliance with the law, declaratory rulings, industry bans, prohibitions on carrying out an activity, publication of supervisory rulings, disgorgement of profits, and withdrawal of authorisation, liquidation and bankruptcy. Publication of a ruling is, in the Swiss financial market, a serious reputational sanction in its own right. For AI systems deployed without adequate governance, FINMA's likely response is an order to restore compliance combined with individual accountability measures.
For AI liability in European markets more broadly, including the insurance and contractual indemnity dimensions that Swiss companies with EU operations must address, the agentliability.eu EU regulatory desk provides analysis of how the EU AI Act's liability provisions interact with national product liability law and the proposed AI Liability Directive.
Frequently asked questions
Does the EU AI Act apply to Swiss companies?
Switzerland is not bound by Regulation (EU) 2024/1689 as a matter of Swiss law. However the EU AI Act has extraterritorial scope: it applies to providers placing AI systems on the EU market and to deployers using AI systems whose outputs affect persons in the EU, regardless of where the company is established. Swiss companies that export AI products or services to EU customers, or whose AI system outputs affect EU persons, must assess EU AI Act applicability independently. Existing Swiss and EU bilateral agreements do not incorporate EU AI Act obligations automatically.
Does Switzerland have an AI law?
No. The Federal Office of Justice, OFCOM and FINMA each state on their own pages that there is currently no AI-specific legislation in Switzerland. On 12 February 2025 the Federal Council decided to ratify the Council of Europe Framework Convention on Artificial Intelligence and to incorporate it into Swiss law, applying primarily to state actors, with legislative change to be as sector-specific as possible and cross-sectoral rules limited to central fundamental-rights areas such as data protection. It instructed the Federal Department of Justice and Police, working with DETEC and the Federal Department of Foreign Affairs, to draft a bill for consultation by the end of 2026, covering transparency, data protection, non-discrimination and supervision. As of 17 August 2026 no consultation had opened.
What does FADP Article 21 require for automated decisions?
Article 21 of the revised Federal Act on Data Protection, in force from 1 September 2023, is headed 'Duty to provide information in the case of an automated individual decision'. Where a decision is based exclusively on automated processing and has a legal consequence for the data subject or a considerable adverse effect on them, the controller must inform the data subject that the decision was automated. On request, the controller must give the individual the opportunity to state a point of view and must allow the individual to request review by a natural person. Article 21(3) disapplies these duties where the decision is directly connected with the conclusion or processing of a contract and the data subject's request is granted, or where the data subject has explicitly consented to the automated processing. Article 21 does not contain an explainability obligation; the right to information about the logic behind the decision sits in Article 25(2)(f).
What does FINMA require of AI systems in financial services?
FINMA has no AI regulation. Its AI document is Guidance 08/2024, 'Governance and risk management when using artificial intelligence', of 18 December 2024, which is expressly a statement of supervisory findings and observations rather than rules. It is structured around governance, an inventory and risk classification of AI applications, data quality, testing and monitoring, documentation, explainability, and independent review, and it anchors on Article 89 of the Capital Adequacy Ordinance. FINMA Circular 2023/1 is a separate instrument, titled 'Operational risks and resilience, banks', in force from 1 January 2024; it addresses banks rather than insurers, and Guidance 08/2024 does not cite it.
Has Switzerland signed or ratified the Council of Europe AI Convention?
Switzerland signed CETS No. 225 on 27 March 2025, not at the September 2024 opening, and has not ratified it. The Convention is not yet in force anywhere: it requires five ratifications including at least three Council of Europe member states, and as of 17 August 2026 it has one, the European Union, deposited on 15 May 2026. The Federal Council's decision of 12 February 2025 states that in Swiss implementation the Convention will apply primarily to state actors, so private operators should not read it as a forthcoming private-sector compliance regime.
Is there a penalty regime specific to AI in Switzerland?
No. Data protection violations under the revised FADP carry criminal sanctions under Articles 60 to 63, with fines up to CHF 250,000 for intentional violations, and Article 60(1)(b)(1) expressly covers wilful failure to inform under Article 21(1). These attach to the responsible natural person, though Article 64(2) allows the authority to order the business to pay a fine of up to CHF 50,000 where identifying the individual would require disproportionate effort. They are complaint offences, prosecuted at cantonal level, with a five-year limitation period. FINMA cannot impose fines: its enforcement tools are precautionary measures, orders restoring compliance, declaratory rulings, industry bans, activity prohibitions, publication of rulings, disgorgement of profits, and withdrawal of authorisation.
References
- Federal Act on Data Protection (nFADP), SR 235.1, in force 1 September 2023, consolidated text at fedlex.admin.ch. Article 21 (duty to provide information in the case of an automated individual decision, including the paragraph 3 exceptions), Article 22 (data protection impact assessment), Article 25(2)(f) (information about the logic of an automated individual decision), Articles 60 to 66 (criminal provisions, corporate liability under Article 64(2), complaint offences and limitation).
- Swiss Federal Council, "AI regulation: Federal Council to ratify Council of Europe Convention", Bern, 12 February 2025, admin.ch. Mandate to the FDJP, with DETEC and the FDFA, to draft a consultation bill by the end of 2026.
- Federal Office of Justice, artificial intelligence pages, bj.admin.ch, and Federal Office of Communications, artificial intelligence pages, bakom.admin.ch. Both state that there is currently no AI-specific legislation in Switzerland.
- Federal register of ongoing consultation procedures, fedlex.admin.ch, checked 17 August 2026. No AI item listed.
- FINMA Guidance 08/2024, "Governance and risk management when using artificial intelligence", 18 December 2024, finma.ch.
- FINMA Circular 2023/1, "Operational risks and resilience, banks", published December 2022, in force 1 January 2024, replacing Circular 2008/21.
- FINMA, enforcement tools, finma.ch. Fines are not among them.
- Federal Data Protection and Information Commissioner, "AI and data protection", 24 September 2025; "Update, current data protection legislation is directly applicable to AI", 8 May 2025; statement of 9 November 2023; statement on ChatGPT-type applications, 4 April 2023; conclusion of the preliminary investigation into X on training data, 20 March 2025. edoeb.admin.ch.
- Council of Europe Treaty Office, chart of signatures and ratifications of CETS No. 225, status as at 17 August 2026. Switzerland signed 27 March 2025 and has not ratified; the Convention has one ratification, the European Union, 15 May 2026, and is not in force. The Convention text itself could not be read at coe.int, which returns 403 to automated requests.
- Guidelines on Artificial Intelligence for the Confederation, seven guidelines adopted by the Federal Council in November 2020, and the Competence Network for Artificial Intelligence. bakom.admin.ch.
- Federal Act on Product Liability (PrHG), SR 221.112.944, of 18 June 1993. Article 3 defines a product as any movable thing plus electricity; Article 5(1)(e) provides the development-risk defence. fedlex.admin.ch.
- Regulation (EU) 2024/1689 (EU AI Act) and Regulation (EU) 2026/1744 (Digital Omnibus on AI, in force 27 July 2026), for comparison.