revFADP and the EU AI Act: What Swiss Companies Must Verify Before Deploying an AI Agent
Swiss data protection fines target individuals, not companies. The 12-point compliance checklist to run before an AI agent touches customer data.
Switzerland has not enacted a horizontal AI law. On 12 February 2025 the Federal Council opted for a sector-specific approach and to ratify the Council of Europe AI Convention. An AI agent deployed in Switzerland is therefore governed by existing law — principally the revised Federal Act on Data Protection, in force since 1 September 2023 — plus the EU AI Act where output is used in the EU. The revFADP detail that changes procurement behaviour: fines of up to CHF 250,000 are directed at the responsible natural person, not the company.
Published 28 July 2026 · Last updated 28 July 2026
Legal note. Informational only, not legal advice. Have Swiss counsel review before publication. Do not paraphrase specific articles of the revFADP or the EU AI Act without checking the primary text.
The regulatory picture in one page
Three layers apply at once, and none is a Swiss AI act. The first is general Swiss law, data protection above all. The second is sector regulation, reaching your deployment through your industry's supervisory expectations rather than anything AI-specific. The third is the EU AI Act, which reaches a Swiss company from outside.
The absence of a horizontal statute is a deliberate policy choice, not a gap awaiting a fix. On 12 February 2025 the Federal Council decided to ratify the Council of Europe Convention on AI and to adopt a sector-specific rather than horizontal regulatory approach, according to the Swiss Federal Council media release published on admin.ch in 2025. For a company deploying an agent, the reading is practical: there is no AI regime to certify against, so the obligations you already carry apply unchanged.
An AI agent is a software system that interprets a request in natural language, retrieves data from your systems and executes an action, which is what separates it from a chatbot following a scripted tree. The distinction matters legally: once an agent reads customer records or writes to a CRM, it is processing personal data in the ordinary sense, and every rule that governs other processing governs it.
Why revFADP changes how Swiss executives buy AI
Because the exposure is personal. The revised Federal Act on Data Protection entered into force on 1 September 2023, with fines of up to CHF 250,000 directed at responsible natural persons rather than the company, according to Pestalozzi Attorneys at Law (2023). That design choice explains why procurement conversations here sound different from those in neighbouring markets.
When the sanction attaches to an individual, "where does this data actually go" stops being an IT footnote and becomes a question the person signing wants answered in writing. It also changes who attends the vendor call: the managing director, the data protection officer and often external counsel, where elsewhere the review would sit with a systems administrator. Their interest is narrow — who decides, and what evidence exists afterwards.
Adoption is not hypothetical, at least in one supervised sector. In Swiss finance, around 50% of institutions already use AI or have applications in development, and the top identified risk is data quality, followed by data protection and explainability, according to a FINMA survey of roughly 400 institutions published in 2025. Two caveats before that figure reaches a board paper: it describes supervised financial institutions rather than Swiss companies generally, and the ranking is self-identified. It signals where experienced buyers look first.
Does the EU AI Act apply to your Swiss company?
Possibly, even with no EU entity, staff or servers in the EU. The EU AI Act has extraterritorial effect on Swiss companies whose AI output is used in the EU, according to Lenz & Staehelin (2025). The trigger is the destination of the output, not the location of the company.
Read that criterion narrowly. It is a general principle, and whether it captures a given deployment depends on facts only your own counsel can weigh: what the agent produces, who relies on it, where those people are and in what capacity. No article can perform that assessment; it can only describe the preparation that makes it cheaper.
Before asking for an opinion, write down what the agent does and for whom: purpose, the people affected, the data it reads and writes, the actions it takes without a human, and the countries where the recipients of its output sit. One page is enough. Most Swiss SMEs find that only one or two cases — a German-language sales agent answering enquiries from Germany, an assistant whose summaries go to an EU subsidiary — need a legal view. Two errors are common: assuming that being Swiss puts the EU regime out of scope, and assuming it covers everything you build.
The pre-deployment checklist: 12 things to verify
These twelve points are what a Swiss reviewer will ask about. Each deserves a written answer before the agent sees a customer record: none can be answered retroactively.
Where the model runs and where data is processed
Establish where processing happens: inference, logging and human review. A region named on a marketing page is not one named in the contract.
Whether prompts or outputs are used for training
Consumer plans and enterprise agreements differ here, often decisively. Require the position in the contract, renewals included.
Sub-processor list and contractual chain
A sub-processor is a third party engaged by your supplier to process data on its behalf, which is why the chain matters more than one supplier's assurances. Ask for the list and notice period.
Retention and deletion of conversation logs
Transcripts often hold more personal data than the database beneath them. Fix a retention period per log category, confirm deletion reaches backups, and record why.
Human oversight for consequential decisions
Identify the actions with a real effect on a person — a rejection, a price, a payment — and require a person in the loop.
Audit trail and reconstructability
You should be able to reconstruct, months later, what the agent was asked, what it retrieved, what it answered and on which model version.
Transparency: the user knows it is a system
State at the start of the conversation that the counterpart is an automated system, and how a person can be reached instead.
Data minimisation in the conversation design
Design the dialogue to ask for the least it needs. Most over-collection comes from a form field copied into a prompt.
Access control and secret management
The agent holds credentials to your systems and should hold the narrowest set that works. Shared keys and administrator-level integration accounts are the usual findings.
Incident and breach procedure
Write down who is notified, within what time and by whom, when the agent discloses something it should not. Name deputies, and rehearse it once.
Records of processing activities updated
A record of processing activities is an internal register that documents what personal data you process, for what purpose, on what basis and with whom you share it. The agent belongs in it.
Named responsible person
One named individual owns the deployment, with authority to switch it off. Since Swiss sanctions can attach to a natural person, agree that name in writing.
Copy the following into your project documentation, alongside the vendor file:
☐ 1. Processing location documented in the contract, not only in marketing material ☐ 2. Training on prompts and outputs excluded in writing, including at renewal ☐ 3. Current sub-processor list obtained, with notice period for changes ☐ 4. Retention period set per log category, with a stated deletion window ☐ 5. Consequential actions listed and human approval required for each ☐ 6. Audit trail captures prompt, retrieved data, output and model version ☐ 7. Disclosure that the counterpart is an automated system, plus route to a human ☐ 8. Conversation design reviewed for data minimisation before launch ☐ 9. Least-privilege credentials, rotated, with no shared administrator account ☐ 10. Incident procedure written, roles named, rehearsed once ☐ 11. Records of processing activities updated to include the agent ☐ 12. Named owner with authority to switch the system off
Data residency options, ranked by control
Four options are realistically available to a Swiss SME, trading control against capability. The choice follows the sensitivity of the data the agent touches, not the size of the company. Hosting is covered in our article on where your data actually lives.
| Option | Control over processing | Main trade-off | Reasonable when |
|---|---|---|---|
| Swiss-hosted, open-weight model | Highest: you choose the data centre and model version | Lower capability than frontier models; you carry operations | Client identifiers, health, legal or financial detail in scope |
| EU-hosted provider or EU region | High: processing located in a defined jurisdiction | Feature releases lag; the chain still needs checking | Personal data involved, sector not supervised |
| Global provider, enterprise terms, contractual region | Moderate: strong terms, wider supply chain | Depends on the contract and the sub-processors | Data is business data with limited personal content |
| Consumer AI tools on personal accounts | None in any usable sense | No contract, no audit trail, no deletion control | Public information only; never for client data |
Cost separates these options less than buyers expect. Swiss hosting carries an infrastructure premium; for a typical SME deployment the monthly difference against a hosted provider is [RANGE TO BE CONFIRMED], and the larger cost is the engineering time to run it. Decide on sensitivity first, then price it.
What does "human oversight" actually have to look like?
Human oversight is a documented arrangement in which a named person can review, correct or reverse what the system does before its effect on a person becomes final. A policy line saying decisions are "monitored by staff" does not meet that description.
Four components make it real. Sampling: a defined share of conversations is read by a person each week, chosen partly at random, not only after complaints. Escalation triggers: conditions under which the agent must stop and hand over — low confidence, a complaint, an erasure request, a legal or medical topic, an amount above a threshold. Override authority: the reviewer can reverse the outcome without asking whoever commissioned the system. Documentation: samples, escalations and overrides are recorded, because oversight leaving no trace cannot be demonstrated.
Set the sampling rate by consequence rather than volume: an agent that books appointments and one that communicates a decision on an application are not the same object, even on the same model. Start high, reduce once you know where failures cluster, and keep the rate above zero. The reviewer should not report to the person whose targets the agent improves.
Questions to put to your AI vendor in writing
Ten questions, with the answer an experienced supplier will give. Send them by email and keep the reply.
- Where is the model hosted and in which country is inference processed? Expect a named region and provider, not "the cloud".
- Are our prompts or outputs used to train any model? Expect a clear no, written into the contract, including at renewal.
- Who are your sub-processors today? Expect a current list and a notice period before it changes.
- What is logged, where is it stored and for how long? Expect retention per log type and a deletion window covering backups.
- How do we delete a specific person's data on request? Expect a procedure with a timescale, not "contact support".
- Which model version runs in production and how are changes notified? Expect version pinning and advance notice.
- What does the audit trail contain? Expect prompt, retrieved data, output, timestamp, model version and retention.
- What happens when the model is unavailable? Expect a defined fallback to a human queue, not a silent failure.
- Who is liable if the agent gives a customer incorrect information? Expect a direct answer and a contractual position.
- Can we export everything and leave? Expect an export format, a timescale and confirmation of deletion.
Two answers should end the conversation: an inability to name where processing occurs, and a refusal to put the training position in writing.
Common mistakes in Swiss AI deployments today
The recurring failures are organisational rather than technical.
Staff pasting client data into consumer chat tools. This happens in companies that have deployed nothing, which is the uncomfortable part. Without a sanctioned tool, capable employees find their own.
No record of the agent as a processing activity. The register covers the CRM and the payroll system, and the agent that reads both is missing. Inexpensive to fix before launch, awkward to explain afterwards.
No named owner. Built by a supplier, commissioned by one department and connected by another, the system belongs to nobody. When something goes wrong, the first hour goes on establishing who decides.
Transcripts kept indefinitely. Storage is cheap and nobody chose a period, so years of conversations sit in a logging platform never reviewed.
Oversight declared but not performed. The policy describes weekly review; it happened twice, during the pilot. Only documented sampling turns the claim into evidence.
When should you not deploy an AI agent yet?
In five situations the honest answer is "not yet", and proceeding creates exposure without benefit.
Nobody will accept the named-owner role. If no individual will put their name to the deployment, that hesitation is information. Resolve governance first.
The underlying process is undocumented. If it lives only in the heads of two colleagues, the agent will encode a version nobody agreed. Write it down first, and consider whether deterministic process automation for Swiss SMEs solves the same problem with far less regulatory surface.
The data the agent would read is not classified. If you cannot say which fields are personal, special-category or confidential, you cannot design minimisation or answer the vendor questions above.
The use case is a decision with a real effect on a person. Approvals, refusals, pricing towards individuals, employment or health consequences are not first projects. Begin where an error is inconvenient rather than injurious.
Counsel has not reviewed a borderline case. Where output reaches the EU, where the sector is supervised, or where sensitive data is in scope, the review is cheaper than the alternative.
Frequently asked questions
Is there an AI law in Switzerland?
There is no horizontal Swiss AI act. On 12 February 2025 the Federal Council decided to ratify the Council of Europe Convention on AI and to adopt a sector-specific rather than horizontal regulatory approach, according to the Swiss Federal Council media release published on admin.ch in 2025. An AI agent is therefore governed by the law that already applies to your company: data protection above all, plus what your sector's supervisor expects. There is no separate regime to register with, and no AI certificate to obtain.
Can we use ChatGPT or Claude with client data?
It depends on the plan and the contract. Consumer plans and enterprise or API agreements differ on the points that matter to a Swiss buyer: whether inputs are used for training, where processing takes place, what is logged and for how long, and who the sub-processors are. A personal account creates no contractual relationship with your company. Obtain written answers on those four points before client data reaches any tool, and have Swiss counsel confirm the arrangement.
Does our data have to stay in Switzerland?
Not automatically. Swiss law does not impose blanket localisation on ordinary commercial processing, and transfers abroad are possible under recognised conditions. Sector rules, professional secrecy obligations and client contracts can nonetheless make Swiss or European processing the practical requirement, and many Swiss firms impose it contractually even where the law does not, because it shortens the review. Whether your case falls into that group is a question for counsel who knows your sector.
Who is liable if the AI agent makes a mistake?
Responsibility sits with the controller — your company — and is not transferred by a supplier's terms. Under the revised Federal Act on Data Protection, in force since 1 September 2023, fines of up to CHF 250,000 are directed at responsible natural persons rather than the company, according to Pestalozzi Attorneys at Law (2023). A named individual therefore carries the exposure, which is why the named owner and the audit trail are worth what they cost.
Do we need a DPIA for an AI agent?
A data protection impact assessment is a structured written analysis that describes a planned processing operation, identifies the risks to the people affected and records the measures chosen to reduce them. It is generally expected where processing is likely to present a high risk to those people, which an agent can reach through the volume of data it touches, its sensitivity or the consequence of its decisions. Write the one-page description of purpose, data and actions first: that is the input to it.
How long can we keep AI conversation transcripts?
For as long as the purpose you collected them for requires, and no longer. Applying that principle means naming a purpose per log category: a support transcript kept for quality review needs weeks, a record evidencing a contractual instruction may need years, a debugging log rarely needs more than days. Set a period per category, make deletion automatic, and confirm that it reaches backups. An undefined retention period is the finding reviewers report most often.
DINOLABS is a Colombian company that builds websites, process automation and AI agents for businesses in Colombia, Mexico, the United States and Switzerland.
To have the twelve points above assessed against a deployment you are considering, Request a Confidential Assessment — NDA available.
Legal note. Informational only, not legal advice. Have Swiss counsel review before publication. Do not paraphrase specific articles of the revFADP or the EU AI Act without checking the primary text.