← Back to all articles
Insights

Swiss FADP vs GDPR for AI: How Switzerland Regulates AI Without an AI Act - and When the EU AI Act Still Catches You

Swiss FADP vs GDPR for AI: How Switzerland Regulates AI Without an AI Act

Last updated: 28 September 2026. General information, not legal advice. Swiss and EU counsel should confirm how these rules apply to your specific systems.

Switzerland sits in the middle of Europe's AI rulebook but has deliberately chosen not to adopt an EU-style AI Act. For Swiss companies, and for multinationals with Swiss operations, that creates a practical question: which rules apply to our AI today, and how does the Swiss Federal Data Protection Act (FADP) compare with the GDPR when AI processes personal data?

This guide answers three things: how Switzerland regulates AI now, how the Swiss FADP differs from the GDPR for AI use cases, and when the EU AI Act reaches Swiss companies regardless.

Switzerland's approach: the Convention, not a copy of the EU AI Act

On 12 February 2025, the Federal Council decided that Switzerland will ratify the Council of Europe Framework Convention on Artificial Intelligence and amend Swiss law where needed, while continuing sector-specific AI regulation in areas such as healthcare and transport. Switzerland signed the Convention on 27 March 2025.

The key elements of the plan, as summarized by the Federal Chancellery and practitioners such as CMS:

  • No horizontal AI law. Switzerland will not create a cross-sector risk-tier regime like the EU AI Act.
  • Targeted amendments. The Federal Department of Justice and Police is preparing a consultation draft, due by the end of 2026, covering transparency, data protection, non-discrimination and supervision.
  • Three goals. Strengthen Switzerland as an innovation location, protect fundamental rights, and increase public trust in AI.
  • Timeline. Consultation is expected to open around the end of 2026, followed by a dispatch to Parliament. Most observers estimate entry into force in 2028 at the earliest. Treat that date as an estimate, not a commitment.

Until then, the most important Swiss rulebook for AI is the one already in force: the revised FADP.

The FDPIC's position: the FADP already applies to AI

On 8 May 2025 the Federal Data Protection and Information Commissioner (FDPIC) reaffirmed that the revised FADP, in force since 1 September 2023, is directly applicable to AI systems that process personal data. The FDPIC's AI and data protection page sets out its expectations, which in practice mean:

  • Transparency about the purpose, functionality and data sources of AI-based processing.
  • Disclosure of machine interaction. People should know when they are talking to a machine rather than a human.
  • Recognizable deepfakes. Synthetic content depicting identifiable people should be recognizable as such.
  • Rights around automated decisions, including the right to express a view and ask for human review.

That is notably close to the EU AI Act's Article 50 transparency duties, even though Switzerland reaches it through data protection law.

Swiss FADP vs GDPR for AI: the side-by-side

The FADP was revised to stay aligned with the GDPR, and the EU has confirmed Switzerland's adequacy. But the two laws differ in ways that matter for AI projects.

Topic Swiss FADP EU GDPR
Legal basis for processing Private companies do not need a legal basis for every processing operation. Processing must follow the principles; a justification (such as consent or overriding interest) is needed only where processing unlawfully infringes personality rights Every processing operation needs one of the Article 6 legal bases (and Article 9 conditions for special categories)
Automated individual decisions Article 21: duty to inform the person of a decision based exclusively on automated processing with legal or significant effects, and on request let them state their view and have a human review it Article 22: a general right not to be subject to such decisions, with narrow exceptions and safeguards
Profiling Distinguishes "high-risk profiling", which triggers stricter consent requirements where consent is relied on Profiling covered generally; no separate high-risk tier
Impact assessment Article 22 data protection impact assessment where processing is likely to create a high risk Article 35 DPIA, with DPA-published lists of mandatory cases
Breach notification To the FDPIC "as soon as possible" where the breach is likely to result in a high risk To the supervisory authority within 72 hours unless unlikely to result in a risk
Sanctions Criminal fines of up to CHF 250,000, imposed on the responsible individuals for intentional breaches of specific duties Administrative fines on the company of up to EUR 20 million or 4% of worldwide turnover
Cross-border transfers Federal Council list of adequate countries; Swiss-US Data Privacy Framework available Commission adequacy decisions; EU-US Data Privacy Framework

What this means for AI teams

  • Training data. The FADP's principle-based model gives Swiss companies somewhat more flexibility than the GDPR's legal-basis requirement, but the principles of purpose limitation, proportionality and transparency still bite on large-scale scraping and reuse of customer data for model training. If the same data set also involves EU residents, the GDPR applies to that processing and sets the stricter bar.
  • Automated decisions. Under the FADP, fully automated credit, hiring or account decisions are allowed if you inform people and offer human review. Under the GDPR they are restricted unless an exception applies. A single group-wide process should be designed to the GDPR standard.
  • Personal liability. Because FADP fines target individuals, Swiss managers responsible for AI deployments have a direct personal incentive to get information duties right. That changes how you document decisions and allocate responsibility.

Sector rules: financial services

Supervised financial institutions face an additional layer. FINMA's Guidance 08/2024 sets out expectations for governance and risk management when using AI, including clear responsibilities, an inventory of AI applications, data quality, testing and ongoing monitoring, explainability and independent review. For banks and insurers, this is effectively Switzerland's closest analogue to the EU AI Act's high-risk requirements today.

When the EU AI Act catches Swiss companies anyway

The EU AI Act applies based on market and output, not headquarters. Under Article 2, a Swiss company is in scope if it:

  • places an AI system or GPAI model on the EU market or puts it into service in the EU, as a provider;
  • is a provider or deployer whose AI system's output is used in the EU (Article 2(1)(c)); or
  • acts as an importer, distributor or product manufacturer bringing AI into the EU.

Providers of high-risk AI systems established outside the EU must also appoint an EU authorized representative under Article 22 before placing the system on the EU market.

The current EU timeline (after the Digital Omnibus)

Some older articles aimed at Swiss companies still say the Annex III high-risk obligations apply from August 2026. That is out of date. After the Digital Omnibus (Regulation (EU) 2026/1744):

  • GPAI model obligations: applying since 2 August 2025.
  • Article 50 transparency: applying since 2 August 2026; legacy generative systems must add machine-readable marking by 2 December 2026.
  • Annex III high-risk systems: 2 December 2027.
  • Annex I product-embedded high-risk systems: 2 August 2028.

One programme, two regimes: a practical checklist

  1. Map your AI inventory against both laws. For each system, record whether it processes Swiss personal data, EU personal data, and whether its outputs are used in the EU.
  2. Classify under the EU AI Act where in scope: prohibited, high-risk, Article 50 transparency, or minimal risk.
  3. Standardize transparency notices to meet both the FDPIC's expectations and Article 50: disclose AI interaction, label synthetic content, and explain purpose and data sources.
  4. Design automated decisions to the GDPR Article 22 standard and add the FADP Article 21 information and review steps.
  5. Run one impact assessment template that covers the FADP Article 22 DPIA, the GDPR Article 35 DPIA and, where relevant, the AI Act fundamental rights impact assessment.
  6. Assign named owners for FADP information duties, given personal criminal liability.
  7. Appoint an EU authorized representative early if you provide high-risk AI into the EU.
  8. Watch the Swiss consultation expected at the end of 2026 and budget for gap analysis in 2027.

Bottom line

Switzerland is not regulating AI with a new AI Act, but that does not mean Swiss AI is unregulated. The revised FADP already applies to AI, the FDPIC expects transparency that looks a lot like EU Article 50, and a Convention-based bill is on the way. For any Swiss company whose AI touches EU users or EU markets, the pragmatic answer to "Swiss FADP vs GDPR for AI" is to build to the stricter EU standard once, then layer the Swiss-specific duties, particularly personal liability and the FADP's information requirements, on top.