Trust, Security & Regulation
What is responsible AI and how do you put it into practice?
What does responsible AI mean?
Responsible AI is an approach that combines technical performance with ethical, legal and societal requirements. The question is not whether a model works, but whether it is deployed in a way that is fair, explainable, safe and accountable – across the entire lifecycle, from data sourcing to decommissioning.
Most recognised frameworks – the OECD AI Principles, the NIST AI Risk Management Framework, the ISO/IEC 42001 standard and the principles of the EU AI Act – converge on five recurring principles. Responsible AI is therefore not a single tool but a governance posture that translates these principles into processes, roles and documentation.
The five principles of responsible AI
- Fairness: AI systems should not systematically disadvantage people based on gender, origin, age or other protected attributes. Bias often arises unintentionally from unbalanced training data.
- Transparency: those affected and oversight bodies should understand that AI is involved and how a result is reached. This includes disclosure, explainable models (Explainable AI) and documented limitations.
- Accountability: every system has identifiable owners answerable for decisions, failures and remediation. Responsibility cannot be delegated to the algorithm.
- Safety and robustness: systems should be reliable, protected against misuse and stable even with unusual inputs. This covers data security, protection against manipulation and testing under real-world conditions.
- Human oversight: for consequential decisions, humans stay in control – able to intervene, correct or shut the system down. «Human in the loop» is central for high-risk applications.
From principle to practice: concrete measures
Principles only work when they become verifiable actions. The measures below map practical steps to each principle, workable for SMEs and large organisations alike.
- Test fairness: analyse training data for representativeness, break down outcomes by relevant groups (bias testing) and define thresholds for acceptable disparity.
- Create transparency: disclose AI use to those affected, maintain model cards and decision logs, and choose explainable methods for critical cases.
- Anchor accountability: assign a business owner and a technical owner per system, maintain an AI inventory and document decisions.
- Harden safety: limit access rights, validate inputs, protect against prompt injection and data leakage, and test models before go-live and regularly in operation.
- Secure oversight: require human sign-off for consequential decisions, define escalation paths and plan a «kill switch» that lets you shut the system down.
Legal framework in Switzerland and the EU
Switzerland so far has no dedicated comprehensive AI law. What applies is the revised Data Protection Act (revDSG, in force since September 2023) together with existing law – on discrimination, product liability and sector regulation. The revDSG requires, among other things, transparency for automated individual decisions and, in certain cases, a data protection impact assessment. The supervisory authority is the EDÖB.
The EU AI Act applies extraterritorially: Swiss companies are affected as soon as their AI systems are placed on the EU market or their outputs are used in the EU. It classifies applications by risk (prohibited practices, high-risk, limited risk, minimal risk) and ties obligations to high-risk systems – risk management, data quality, transparency and human oversight – the same principles in statutory form.
Governance: roles, processes and documentation
Principles need an organisational home. Lean AI governance makes responsibility visible and auditable without stalling innovation. A few consistently practised elements are enough to start.
- AI inventory: a current list of all deployed and planned AI systems with purpose, data sources, owners and risk classification.
- Risk classification: assign each application a risk level and scale controls accordingly – no overhead for harmless cases, clear requirements for high-risk ones.
- Internal policy: a short AI usage policy governs permitted tools, handling of confidential data and approval paths.
- Training and culture: staff know the opportunities, limits and reporting channels – responsible AI is also a matter of AI literacy.
Common mistakes and how to avoid them
- Ethics on paper: principles are stated but never translated into processes («ethics washing»). Fix: back every principle with a concrete, verifiable measure.
- Blind trust in models: generative AI outputs are accepted unchecked. Fix: mandate human review for consequential outputs and source verification.
- Privacy too late: confidential or personal data flows carelessly into external services. Fix: consider privacy early, minimise data and choose vetted providers.
- Checked once, never again: systems are tested before go-live but not monitored afterwards. Fix: continuous monitoring for drift, errors and changing data.
Frequently asked questions
What are the five principles of responsible AI?
Fairness, transparency, accountability, safety (including robustness) and human oversight. These five recur in nearly every recognised framework – the OECD AI Principles, the NIST AI RMF and the principles of the EU AI Act – and form the basis for concrete measures.
Does the EU AI Act apply to Swiss companies?
Yes, indirectly and extraterritorially. As soon as a Swiss company places AI systems on the EU market or their outputs are used in the EU, the EU AI Act's obligations apply. The revDSG applies additionally in Switzerland. An early risk classification helps determine the right scope of obligations.
What is the difference between responsible AI and AI ethics?
AI ethics describes the values and principles that are desirable. Responsible AI is their practical implementation: it translates values into processes, roles, tests and documentation. Ethics provides the «why», responsible AI the everyday «how».
How do you detect and reduce bias in AI systems?
You detect bias by breaking down outcomes across relevant groups (e.g. gender or region) and comparing them against defined fairness criteria. You reduce it through more representative training data, adjusted thresholds, human review of edge cases and regular re-testing in production.
Does an SME need AI governance?
Yes, but at the right scale. For an SME an AI inventory, a short usage policy, a simple risk classification and named owners are often enough. What matters is not document volume but clear responsibility, protected data and human control over critical decisions.
What does «human oversight» mean in practice?
Human oversight means people can understand, review, correct or overturn consequential AI decisions and, if needed, shut the system down. Depending on risk, this ranges from spot checks to mandatory human sign-off before every execution («human in the loop»).
Key terms in the glossary
Practical AI for your business
From idea to implementation – we show you what is concretely possible in your case.
Request a demo