Trust, Security & Law
AI Security, Privacy and Regulation: the Overview for Swiss Businesses
The three layers and how they connect
Security, privacy and regulation are often treated separately, yet in AI they overlap. Security asks: is the system technically robust and protected against misuse? Privacy asks: is personal data processed lawfully and transparently? Regulation asks: is the application permitted at all, and under what conditions? Only together do they form a dependable framework.
Swiss companies face an added twist: they are governed by the revised Federal Act on Data Protection (revFADP) but can simultaneously fall under the extraterritorial EU AI Act as soon as their AI outputs are used in the EU. A purely national view is therefore too narrow.
- Security: protects models, data and infrastructure against attacks, manipulation and data leakage (technical and organisational layer).
- Privacy: governs how personal data may be collected, processed and disclosed (revFADP, supervised by the FDPIC).
- Regulation: sets permissibility, risk class and duties per use case (EU AI Act, sector law such as FINMA rules or medical-device law).
AI security: the key risks
AI systems, especially those built on large language models, open attack surfaces that classic software does not have. The OWASP community has summarised the most common ones in its list for LLM applications. They belong in every security review before an AI feature ships to production.
- Prompt injection: attackers smuggle instructions into inputs or documents to make the model take unwanted actions or leak data.
- Data leakage: personal data or trade secrets reach external models via prompts, or surface in responses to the wrong recipients.
- Hallucinations and faulty output: wrong but convincing answers drive bad decisions when no control catches them.
- Supply-chain and model risks: compromised models, plugins or training data introduce vulnerabilities.
- Shadow AI: staff use unapproved AI tools with company data, outside any control or contractual coverage.
Privacy: the revised FADP and handling personal data
Since 1 September 2023 Switzerland applies the fully revised Federal Act on Data Protection (revFADP). It is aligned with the risk-based logic of European law but remains a distinct statute: for Swiss matters you refer to the revFADP, not the GDPR. As soon as AI processes personal data, the usual principles apply: lawfulness, purpose limitation, transparency, proportionality and data security.
- Data protection impact assessment (DPIA): carry out before deployment when a high risk is likely, e.g. large-scale profiling or processing of sensitive data.
- Processing on behalf: AI vendors are usually processors; you need a contract, vetted sub-processors and clarity on the processing location (Switzerland/EU vs third country).
- Transparency and data-subject rights: disclose when AI supports decisions and ensure access, rectification and human review.
- Data minimisation: put only truly necessary personal data into prompts, training sets or vector databases; anonymise or pseudonymise where possible.
Regulation: the EU AI Act and Swiss law
The EU AI Act is the first comprehensive AI regulation and enters into force in stages. It follows a risk-based approach: prohibited practices (such as social scoring), high-risk applications with strict duties (e.g. hiring or credit scoring), limited transparency duties (labelling of chatbots and AI-generated content) and minimal risk. Key for Switzerland: the Act applies extraterritorially as soon as AI outputs are used in the EU.
Switzerland has no dedicated horizontal AI law yet. The Federal Council favours a sector-specific, technology-neutral approach and is examining how international instruments such as the Council of Europe's AI Convention will be implemented. Regulated industries also face existing rules, e.g. FINMA in finance or therapeutic-products law for medical uses. Exporters and firms serving EU customers effectively align with the stricter EU standard.
A practical roadmap for Swiss SMEs
Governance need not be heavy. A pragmatic sequence connects the three layers without blocking innovation and can be aligned with recognised frameworks such as the NIST AI Risk Management Framework or the ISO/IEC 42001 standard.
- Inventory: list every AI use in play or planned, including shadow AI, and prioritise by data type and purpose.
- Risk and legal classification: for each use, determine the security risk, privacy relevance and potential EU AI Act risk class.
- Guardrails: an internal AI policy, a tool-approval process, vetted vendors with a processing agreement and clear rules for customer data.
- Technical controls: access management, logging, input/output filters against prompt injection and human oversight for significant decisions.
- People and iteration: train staff, assign accountability and revisit the assessment regularly, since models and law change fast.
Sovereignty and the Swiss path
For sensitive data, digital sovereignty moves to the fore: where is data processed, who has access, and how dependent are you on single vendors? Switzerland is building its own capability here. The open language model Apertus, developed at ETH Zurich and EPFL with the Swiss National Supercomputing Centre, shows that transparent, Swiss-hosted AI is feasible. Innosuisse funds related innovation projects.
In this topic area
AI and data privacy for businesses: which data flows where, and how do you stay compliant?
When you use AI, personal data usually leaves the company through prompts, uploads and connected systems, landing with a provider …
How do SMEs set up practical AI governance?
AI governance for SMEs is the lightweight set of policy, roles, human oversight and documentation that keeps AI use safe, lawful a…
AI in Switzerland: research, models and regulation at a glance
Switzerland is among Europe's leading AI hubs: ETH Zurich and EPFL run world-class research, the national supercomputing centre CS…
AI Risks and Limitations: What You Need to Know and How to Mitigate Them
AI systems such as large language models have systematic limitations: they invent plausible-sounding facts (hallucination), reprod…
AI Transparency and Disclosure: When Must You Tell People They Are Interacting With AI?
AI transparency means disclosing to people that they are interacting with artificial intelligence or viewing AI-generated content.…
What is the EU AI Act – and what does it mean for Swiss businesses?
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive law on artificial intelligence. It classifies AI syst…
What is responsible AI and how do you put it into practice?
Responsible AI means developing and deploying AI systems along five core principles: fairness, transparency, accountability, safet…
The Revised FADP and AI: What Must Swiss Businesses Consider?
The revised Federal Act on Data Protection (revFADP, in force since 1 September 2023) applies to any AI application that processes…
What is AI security?
AI security covers the technical and organisational measures that protect AI systems from misuse, manipulation and data leakage wh…
Frequently asked questions
What is the difference between the revFADP and the GDPR?
The revFADP is Switzerland's data protection law, the GDPR the EU's. Both follow a similar risk-based logic but are separate legal regimes differing in fines, notification duties and terminology. Swiss matters fall under the revFADP; the GDPR may additionally apply when you process data of people in the EU.
Does the EU AI Act apply to Swiss companies?
Yes, it can apply extraterritorially. As soon as a Swiss company places AI systems on the EU market or the AI-generated output is used in the EU, the Act may apply. Independently, aligning with its risk-based approach is worthwhile because it is becoming the international benchmark.
What is prompt injection and why is it dangerous?
In a prompt injection, attackers hide instructions in text, documents or web pages that the AI system processes. The model may then bypass rules, leak data or trigger unwanted actions. It is dangerous because it needs no classic code exploit and is especially potent against AI agents with access to tools and data.
Do I need a data protection impact assessment for an AI application?
If the processing is likely to entail a high risk to personality or fundamental rights, the revFADP requires a DPIA before deployment. With AI this is often the case, e.g. large-scale profiling or sensitive data. The assessment documents risks and measures; when in doubt, consult the FDPIC or expert advice.
May I use public AI tools with customer data?
Only with care. Without a suitable contractual basis, a clarified processing location and assurance that inputs are not used for training, you risk privacy breaches and loss of secrecy. Business offerings with a processing agreement, EU/Swiss hosting or locally run models are preferable. Minimise or pseudonymise personal data by default.
Where should I start with AI governance?
Start with an inventory of all AI tools in use, including unofficial ones. Classify them by security risk, privacy relevance and potential EU AI Act risk class, then define a lean internal policy and an approval process. The NIST AI Risk Management Framework and ISO/IEC 42001 offer orientation. Crucially, repeat the process regularly.
Key terms in the glossary
Practical AI for your business
From idea to implementation – we show you what is concretely possible in your case.
Request a demo