Swiss FADP vs GDPR for AI: How Switzerland Regulates AI Without an AI Act - and When the EU AI Act Still Catches You
Swiss FADP vs GDPR for AI: How Switzerland Regulates AI Without an AI Act
Last updated: 28 September 2026. General information, not legal advice. Swiss and EU counsel should confirm how these rules apply to your specific systems.
Switzerland sits in the middle of Europe's AI rulebook but has deliberately chosen not to adopt an EU-style AI Act. For Swiss companies, and for multinationals with Swiss operations, that creates a practical question: which rules apply to our AI today, and how does the Swiss Federal Data Protection Act (FADP) compare with the GDPR when AI processes personal data?
This guide answers three things: how Switzerland regulates AI now, how the Swiss FADP differs from the GDPR for AI use cases, and when the EU AI Act reaches Swiss companies regardless.
Switzerland's approach: the Convention, not a copy of the EU AI Act
On 12 February 2025, the Federal Council decided that Switzerland will ratify the Council of Europe Framework Convention on Artificial Intelligence and amend Swiss law where needed, while continuing sector-specific AI regulation in areas such as healthcare and transport. Switzerland signed the Convention on 27 March 2025.
The key elements of the plan, as summarized by the Federal Chancellery and practitioners such as CMS:
- No horizontal AI law. Switzerland will not create a cross-sector risk-tier regime like the EU AI Act.
- Targeted amendments. The Federal Department of Justice and Police is preparing a consultation draft, due by the end of 2026, covering transparency, data protection, non-discrimination and supervision.
- Three goals. Strengthen Switzerland as an innovation location, protect fundamental rights, and increase public trust in AI.
- Timeline. Consultation is expected to open around the end of 2026, followed by a dispatch to Parliament. Most observers estimate entry into force in 2028 at the earliest. Treat that date as an estimate, not a commitment.
Until then, the most important Swiss rulebook for AI is the one already in force: the revised FADP.
The FDPIC's position: the FADP already applies to AI
On 8 May 2025 the Federal Data Protection and Information Commissioner (FDPIC) reaffirmed that the revised FADP, in force since 1 September 2023, is directly applicable to AI systems that process personal data. The FDPIC's AI and data protection page sets out its expectations, which in practice mean:
- Transparency about the purpose, functionality and data sources of AI-based processing.
- Disclosure of machine interaction. People should know when they are talking to a machine rather than a human.
- Recognizable deepfakes. Synthetic content depicting identifiable people should be recognizable as such.
- Rights around automated decisions, including the right to express a view and ask for human review.
That is notably close to the EU AI Act's Article 50 transparency duties, even though Switzerland reaches it through data protection law.
Swiss FADP vs GDPR for AI: the side-by-side
The FADP was revised to stay aligned with the GDPR, and the EU has confirmed Switzerland's adequacy. But the two laws differ in ways that matter for AI projects.
| Topic | Swiss FADP | EU GDPR |
|---|---|---|
| Legal basis for processing | Private companies do not need a legal basis for every processing operation. Processing must follow the principles; a justification (such as consent or overriding interest) is needed only where processing unlawfully infringes personality rights | Every processing operation needs one of the Article 6 legal bases (and Article 9 conditions for special categories) |
| Automated individual decisions | Article 21: duty to inform the person of a decision based exclusively on automated processing with legal or significant effects, and on request let them state their view and have a human review it | Article 22: a general right not to be subject to such decisions, with narrow exceptions and safeguards |
| Profiling | Distinguishes "high-risk profiling", which triggers stricter consent requirements where consent is relied on | Profiling covered generally; no separate high-risk tier |
| Impact assessment | Article 22 data protection impact assessment where processing is likely to create a high risk | Article 35 DPIA, with DPA-published lists of mandatory cases |
| Breach notification | To the FDPIC "as soon as possible" where the breach is likely to result in a high risk | To the supervisory authority within 72 hours unless unlikely to result in a risk |
| Sanctions | Criminal fines of up to CHF 250,000, imposed on the responsible individuals for intentional breaches of specific duties | Administrative fines on the company of up to EUR 20 million or 4% of worldwide turnover |
| Cross-border transfers | Federal Council list of adequate countries; Swiss-US Data Privacy Framework available | Commission adequacy decisions; EU-US Data Privacy Framework |
What this means for AI teams
- Training data. The FADP's principle-based model gives Swiss companies somewhat more flexibility than the GDPR's legal-basis requirement, but the principles of purpose limitation, proportionality and transparency still bite on large-scale scraping and reuse of customer data for model training. If the same data set also involves EU residents, the GDPR applies to that processing and sets the stricter bar.
- Automated decisions. Under the FADP, fully automated credit, hiring or account decisions are allowed if you inform people and offer human review. Under the GDPR they are restricted unless an exception applies. A single group-wide process should be designed to the GDPR standard.
- Personal liability. Because FADP fines target individuals, Swiss managers responsible for AI deployments have a direct personal incentive to get information duties right. That changes how you document decisions and allocate responsibility.
Sector rules: financial services
Supervised financial institutions face an additional layer. FINMA's Guidance 08/2024 sets out expectations for governance and risk management when using AI, including clear responsibilities, an inventory of AI applications, data quality, testing and ongoing monitoring, explainability and independent review. For banks and insurers, this is effectively Switzerland's closest analogue to the EU AI Act's high-risk requirements today.
When the EU AI Act catches Swiss companies anyway
The EU AI Act applies based on market and output, not headquarters. Under Article 2, a Swiss company is in scope if it:
- places an AI system or GPAI model on the EU market or puts it into service in the EU, as a provider;
- is a provider or deployer whose AI system's output is used in the EU (Article 2(1)(c)); or
- acts as an importer, distributor or product manufacturer bringing AI into the EU.
Providers of high-risk AI systems established outside the EU must also appoint an EU authorized representative under Article 22 before placing the system on the EU market.
The current EU timeline (after the Digital Omnibus)
Some older articles aimed at Swiss companies still say the Annex III high-risk obligations apply from August 2026. That is out of date. After the Digital Omnibus (Regulation (EU) 2026/1744):
- GPAI model obligations: applying since 2 August 2025.
- Article 50 transparency: applying since 2 August 2026; legacy generative systems must add machine-readable marking by 2 December 2026.
- Annex III high-risk systems: 2 December 2027.
- Annex I product-embedded high-risk systems: 2 August 2028.
One programme, two regimes: a practical checklist
- Map your AI inventory against both laws. For each system, record whether it processes Swiss personal data, EU personal data, and whether its outputs are used in the EU.
- Classify under the EU AI Act where in scope: prohibited, high-risk, Article 50 transparency, or minimal risk.
- Standardize transparency notices to meet both the FDPIC's expectations and Article 50: disclose AI interaction, label synthetic content, and explain purpose and data sources.
- Design automated decisions to the GDPR Article 22 standard and add the FADP Article 21 information and review steps.
- Run one impact assessment template that covers the FADP Article 22 DPIA, the GDPR Article 35 DPIA and, where relevant, the AI Act fundamental rights impact assessment.
- Assign named owners for FADP information duties, given personal criminal liability.
- Appoint an EU authorized representative early if you provide high-risk AI into the EU.
- Watch the Swiss consultation expected at the end of 2026 and budget for gap analysis in 2027.
Bottom line
Switzerland is not regulating AI with a new AI Act, but that does not mean Swiss AI is unregulated. The revised FADP already applies to AI, the FDPIC expects transparency that looks a lot like EU Article 50, and a Convention-based bill is on the way. For any Swiss company whose AI touches EU users or EU markets, the pragmatic answer to "Swiss FADP vs GDPR for AI" is to build to the stricter EU standard once, then layer the Swiss-specific duties, particularly personal liability and the FADP's information requirements, on top.
Related reading

The AI Governance Operating Model: Who Owns What, Who Signs, and How to Build the Machine
Most AI governance frameworks fail not because the policy is wrong but because nobody owns anything. Here's how to build the operating model that actually works - roles, RACI, forums, inventory, and a first-90-days plan.
The Cyber Resilience Act and the EU AI Act: Reporting Went Live on 11 September 2026 - What AI Product Makers Must Do Now
Since 11 September 2026, makers of software and connected products, including most AI products, must report actively exploited vulnerabilities within 24 hours under the Cyber Resilience Act. Here is how CRA reporting works, how CRA Article 12 links to AI Act Article 15, and how to build one incident playbook for both.
EU AI Act News: What the First 60 Days of Enforcement Actually Produced (August-September 2026)
2 August 2026 was supposed to be the day the EU AI Act got teeth. Sixty days later, here is what actually happened: the AI Office's first information requests to GPAI providers, a transparency Code of Practice with 200+ signatories, a new complaints tool, and a string of GDPR decisions that show where AI enforcement is really coming from.