AI Regulation in Switzerland
Switzerland has 32 tracked AI regulatory updates across 3 frameworks. This page provides an overview of the current regulatory landscape, upcoming deadlines, and recent enforcement activity.
Upcoming Deadlines
Planned Swiss AI bill target year-end 2026
Swiss FDPIC guidance on AI and data protection, plus legislative roadmapBAIT continues for some firms during transition period before DORA replacement
BaFin DORA implementation guidance and filing proceduresRemaining FinmadiG transition ends for certain German institutions
BaFin DORA implementation guidance and filing proceduresRecent Regulatory Updates
Swiss FDPIC guidance on AI and data protection, plus legislative roadmap
The FDPIC has made clear that Switzerland’s data protection law already applies to AI-supported processing and that the federal government is targeting an AI bill by the end of 2026, so organizations should harden transparency and automated-decision controls now.
FINMA sets governance and risk-management expectations for AI use in Swiss financial institutions
FINMA’s 2024 guidance states that Swiss financial institutions using AI must identify, limit, control, and monitor AI-related risks within their existing supervisory framework, so firms should immediately test whether their governance and model-risk controls are adequate.
FDPIC guidance and enforcement focus on AI and data protection
The FDPIC states that the Swiss FADP applies directly to AI-supported processing and is actively pursuing investigations, so organizations using AI with personal data must now evidence transparency, proportionality, purpose limitation, and human review readiness.
FDPIC says Swiss data-protection law applies directly to AI-supported processing
On 2025-05-08, the FDPIC reiterated that Switzerland’s data-protection law already applies directly to AI-supported processing, meaning transparency, purpose limitation, and data-subject rights must be built into current AI operations now.
FDPIC confirms Swiss data-protection law applies directly to AI
The FDPIC reiterates that the Swiss Federal Data Protection Act applies directly to AI-supported processing, so organizations cannot wait for a separate AI statute before fixing transparency, automated-decision, and human-review controls.
ISO/IEC 42005:2025 published for AI system impact assessments
ISO published ISO/IEC 42005:2025 in May 2025, adding a formal AI system impact-assessment standard that organizations can now use to evidence structured AI governance alongside ISO/IEC 42001.
FINMA guidance on governance and risk management when using artificial intelligence
FINMA’s 18 December 2024 guidance says supervised institutions must adapt governance and controls to the materiality and probability of AI risks, including operational, model, data, IT/cyber, third-party, legal, and reputational risks.
FDPIC AI and data protection guidance
The FDPIC states that Switzerland’s FADP applies directly to AI-supported processing and expects manufacturers, providers, and users to be transparent about purpose, functionality, and data sources.
FDPIC guidance on AI and data protection
The FDPIC’s AI guidance states that the Swiss FADP applies directly to AI-supported processing and requires transparency about purpose, functionality, and data sources, which elevates compliance expectations for AI deployments in Switzerland.
FINMA guidance on AI governance and risk management
FINMA’s AI guidance highlights operational, model, cyber, data-quality, third-party, legal, and reputational risks, so Swiss financial institutions should formalize AI governance and oversight now.
BSI publishes G7 SBOM for AI guidance
BSI released a G7-developed guideline setting minimum requirements for a Software Bill of Materials for AI, so organizations should tighten AI component inventory and supply-chain traceability practices.
FINMA Guidance on Governance and Risk Management When Using Artificial Intelligence
FINMA published AI governance guidance on December 18, 2024, making governance, model risk, data quality, cyber risk, third-party dependence, and legal/reputational risk explicit supervisory priorities for Swiss financial institutions using AI.
Swiss FDPIC AI and data protection guidance
The FDPIC’s 2025 guidance makes clear that Swiss data protection law applies directly to AI-supported processing, so organizations must treat transparency, DPIAs, and human review rights as immediate design requirements for AI systems using personal data.
FDPIC confirms Swiss data protection law applies directly to AI processing
The FDPIC’s AI and data protection page confirms the nFADP has applied directly to AI-supported data processing since 1 September 2023, so Swiss organizations must treat AI use as already in scope for data protection controls.
FDPIC guidance on AI and data protection
The FDPIC states that Switzerland’s data protection law applies directly to AI-supported processing, so organizations must document purpose, data sources, and automated-decision safeguards now.
Applicable Frameworks
Key Topics
Weekly digest
Leave your email to get each issue in your inbox. Free, no account required.
We use your email only for the digest. Privacy policy