Skip to content

Switzerland — AI regulation and data protection

Provenance & licence

Source: bk.admin.ch — Regulierung von KI · EDÖB — KI und Datenschutz · Fedlex — DSG SR 235.1 · Last observed: 2026-09-05 · Version: DSG in force since 2023-09-01 (consolidated 2025-07-07); Federal Council decision 2025-02-12; CETS 225 signed 2025-03-27, not in force · Status: planned · Licence: Swiss federal legal texts and official publications — reuse with source attribution (open-attribution); Council of Europe treaty text © CoE, quoted via the EU Official Journal (facts and quotation)

Summary

Switzerland has no AI act and, by the Federal Council's own plan, will not have a consultation draft before the end of 2026. What governs AI today is three layers. First, the technology-neutral Federal Act on Data Protection (DSG, SR 235.1, in force since 1 September 2023), which the Federal Data Protection and Information Commissioner (EDÖB) declared directly applicable to AI-based processing on 9 November 2023 and re-affirmed on 8 May 2025. Second, the Federal Council decision of 12 February 2025: a sectoral approach, cross-sector rules only for central fundamental-rights areas such as data protection, ratification of the Council of Europe Framework Convention on AI (CETS 225), and a consultation draft to be prepared by the Federal Office of Justice (BJ, within the EJPD; with BAKOM and the Directorate of International Law) by the end of 2026, plus a parallel plan of non-binding measures. Third, supervisory practice — dated EDÖB notices, pre-investigations (X/Grok 2025, Meta 2026) and the annual activity report. Switzerland signed CETS 225 on 27 March 2025; the Convention is not yet in force (one ratification, the EU on 15 May 2026, against five required).

In plain language

Our explanation, not the official text

Plain-language summary in our own words — not the normative text. Swiss federal law and official communications are quoted with attribution. This is general information, not legal advice.

If you build or run AI for Swiss users or a Swiss client, don't look for a Swiss "AI Act" — there isn't one, and the first draft is a year away. Look at the data protection law instead: the EDÖB reads the DSG as already covering AI. That means telling people when they talk to a machine and what your system does with their data (Art. 19), letting them contest automated decisions and get a human to look (Art. 21), running a data protection impact assessment when the risk is high (Art. 22), and building privacy in from the start (Art. 7). Above that sits a political commitment — Switzerland will implement the Council of Europe's AI Convention, mostly through sector laws — but that commitment has not become law yet. For an auditor, the DSG plus the EDÖB's published practice is the checklist; the Convention is the direction of travel.

Key terms

  • DSG — Bundesgesetz über den Datenschutz (Federal Act on Data Protection), SR 235.1, revised, in force since 2023-09-01; supplemented by the ordinance DSV (SR 235.11).
  • EDÖB — Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, the federal data-protection authority; supervises private and federal processing, no fining power against companies (penalties target natural persons).
  • Vernehmlassung — the formal consultation procedure that precedes federal legislation; the AI draft is due by the end of 2026.
  • CETS 225 — the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Vilnius, 2024-09-05); the first binding international AI treaty. Full page: Council of Europe AI Convention (CETS 225) — the status statement ("not in force") is maintained there.
  • Sectoral approach — the Federal Council's choice to adapt existing sector laws rather than enact a horizontal AI statute.

In depth: the Federal Council's sectoral approach and the CETS 225 path

Reading guide: boxed “Source text” quotes are the authority's own wording (German original, quoted with attribution). Text marked “In our words” is our explanation.

Source text — EDÖB, 9 November 2023 (updated 8 May 2025)

Der EDÖB weist deshalb darauf hin, dass das seit dem 1. September 2023 geltende Datenschutzgesetz des Bundes auf KI-gestützte Datenbearbeitungen direkt anwendbar ist.

In our words — the regulator's position is that no new law is needed for the DSG to bite: AI processing of personal data is processing, full stop. The notice names the duties that follow — transparency on purpose, functioning and data sources; the right to object to, or have a human review, automated individual decisions; disclosure when someone corresponds with a machine; clear marking of synthetic media that manipulates identifiable people; a DPIA for high-risk processing; privacy by design — and calls real-time facial recognition and social scoring inadmissible.

Source text — Federal Council, media release of 12 February 2025

Die KI-Konvention des Europarats wird ins Schweizer Recht übernommen. […] Wo Gesetzesanpassungen nötig sind, sollen diese möglichst sektorbezogen ausfallen. Eine allgemeine, sektorübergreifende Regulierung beschränkt sich auf zentrale, grundrechtsrelevante Bereiche, wie beispielsweise den Datenschutz.

In our words — the Federal Council chose the middle of three options laid out in BAKOM's Auslegeordnung (stock-taking report): not the status quo of sector-by-sector tinkering, not an EU-AI-Act clone, but ratification of CETS 225 with targeted amendments. The regulation is to serve three goals — Switzerland as an innovation location, protection of fundamental rights including economic freedom, and public trust. The mandate: the Federal Department of Justice and Police (EJPD), with UVEK and EDA, prepares a consultation draft by the end of 2026 covering transparency, data protection, non-discrimination and oversight; UVEK prepares, in parallel, a plan of non-binding measures (industry self-declarations, sector solutions). The Justice Office's legal analysis behind the decision found that Swiss law already applies to AI in full, but that ratification requires additions — chiefly on transparency, fundamental-rights impact assessment and control mechanisms, including a supervisory body covering the Convention's whole scope, which today no single Swiss authority does.

Source text — Federal Council, media release of 10 February 2026

Der Schwerpunkt lag auf Massnahmen wie Selbstverpflichtungserklärungen einzelner Branchen, Ethikkodizes und Standards.

In our words — a year after the decision, the visible implementation work is on the soft-law track: the Digital Switzerland advisory board discussed self-regulation concepts from the media and energy industries, and the government's own framing is that legislation "usually takes several years", so short-term measures should run in parallel. No consultation draft had been published at the observation date.

From my training — University of Oxford · Managing Enterprise AI Risks (2026)

Cross-jurisdiction work in my Oxford certification taught me to separate what binds today from what is announced. For Switzerland that split is unusually clean: the DSG binds, the EDÖB's dated notices show how it is enforced, and everything about the Convention is direction, not obligation — until a Swiss statute says otherwise. In an audit I anchor Swiss findings to DSG articles with the consolidation date, and I file the Convention under "regulatory horizon" with its ratification status quoted from the treaty chart. Verify certificate ↗

Application timeline (as it stands)

Date What Status
2023-09-01 Revised DSG (SR 235.1) and DSV (SR 235.11) in force in force; consolidated version of 2025-07-07 (further amendments pending, see AS 2025 444)
2023-11-09 EDÖB: DSG directly applicable to AI (updated 2025-05-08) supervisory position — current
2024-09-05 CETS 225 opened for signature (Vilnius) signed by 21 parties as of 2026-09-05
2025-02-12 Federal Council decision: sectoral approach, ratify CETS 225, consultation draft by end of 2026 political mandate — not law
2025-03-27 Switzerland signs CETS 225 in Strasbourg signature only, no ratification
2026-02-10 Digital Switzerland advisory board: self-regulation measures (media, energy) soft-law track under way
2026-05-15 EU deposits its approval of CETS 225 (Council Decision (EU) 2026/1080) first and, at the observation date, only ratification
by end of 2026 Consultation draft (EJPD/BJ) on transparency, data protection, non-discrimination, oversight; UVEK plan of non-binding measures announced, not published
open Entry into force of CETS 225 — needs 5 ratifications incl. 3 CoE member states (Art. 30(3)) not in force — current status on the CETS 225 page

Key Sections

Audit-Relevant Anchors

Auditor Checklist

Evidence-oriented checks for an engagement with a Swiss client, Swiss users or Swiss personal data:

  • Personal data in scope? If yes, the DSG applies to the AI processing regardless of any future AI law (EDÖB 2023/2025).
  • Transparency: users are told when they interact with an AI system and how their inputs (prompts) are used (DSG Art. 19; EDÖB Datenschutztag 2026).
  • Automated individual decisions are identified, disclosed, and a human-review/objection path exists (DSG Art. 21).
  • A DPIA exists for high-risk AI processing — always for biometrics/facial recognition and large-scale profiling (DSG Art. 22; EDÖB Meta pre-investigation 2026).
  • Privacy by design and by default is evidenced in the AI system's design records (DSG Art. 7).
  • Training on user data: a documented, functioning opt-out and, for foreign controllers, a Swiss representative (DSG Art. 14; X/Grok 2025).
  • Cross-border disclosure of personal data to model providers is covered by DSG Art. 16–17 (adequacy or safeguards).
  • Synthetic media that manipulates identifiable persons is clearly marked (EDÖB 2023).
  • The report states the DSG consolidation date used and the CETS 225 status "as of" date — and does not present the Convention as binding Swiss law.
  • Sector rules checked: financial market (FINMA), health, energy, media — the sectoral analysis names the moving files.

Cross-Framework Mapping

Indicative cross-references, not authoritative equivalences — confirm against the source texts before relying on them.

Switzerland (DSG / EDÖB / CETS 225) EU AI Act GDPR NIST AI RMF ISO/IEC 42001
DSG Art. 19 + EDÖB disclosure duty (machine interaction, synthetic media) Art. 50 Art. 13–14 GOVERN 1.x, MAP 1.x Cl. 7.4, Annex A (transparency)
DSG Art. 21 (automated individual decision) Art. 26 (deployer duties, human oversight) Art. 22 MANAGE 2.x Annex A (human oversight)
DSG Art. 22 (DPIA) Art. 27 (FRIA), Art. 9 Art. 35 MAP 5.x, MEASURE Cl. 6.1.4 (AI system impact assessment)
DSG Art. 7 (privacy by design) Art. 10, Art. 15 Art. 25 GOVERN 1.x Cl. 8, Annex A (data)
CETS 225 Art. 16 (risk and impact assessment, incl. moratoria) Art. 9 + Art. 27 MAP / MEASURE Cl. 6.1
CETS 225 Art. 26 (effective oversight mechanisms) Art. 70 (national authorities) Art. 51 ff. GOVERN Cl. 5

Recent Changes (rolling, last 5)

Date Severity What changed
2026-09-05 baseline Initial baseline: DSG applied to AI (EDÖB 2023/2025), Federal Council decision 2025-02-12, CETS 225 signed 2025-03-27 and not in force (1 ratification, EU 2026-05-15), soft-law track (2026-02-10), consultation draft due end of 2026 (prepared by the Federal Office of Justice, BJ, within the EJPD), EDÖB activity report 2025/26 captured. The Convention's content and treaty status are maintained on the dedicated Council of Europe AI Convention page; this page links there instead of restating the ratification count.

Sources