top of page

Practical AI Governance in Switzerland: What Companies Are Learning from Early Adoption and Pilots

10 hours ago
10 min read

WAI Legal Insights Blog banner for Practical AI Governance in Switzerland, with portraits of Caroline Perriard and Rebecca Hubert Scherler.

By Caroline Perriard and Rebecca Hubertscherler


Artificial Intelligence is reshaping industries globally, but its rapid adoption introduces significant governance challenges, from compliance to ethical dilemmas. In Switzerland, where no single comprehensive AI law exists, organizations rely on existing cross-sectoral legislation and sector-specific regulations, with additional rules anticipated under the implementation of the Council of Europe AI Convention. Swiss companies must also reckon with the extraterritorial reach of the EU AI Act, whose enforcement by the European Commission's AI Office begins on 2 August 2026.


This blog explores how companies across four key Swiss sectors : life sciences, academia, finance, and non-profits, are adopting AI tools, the lessons learned, and the governance protocols emerging from their experiences.


This blog is written by Rebecca Hubertscherler and Caroline Perriard. Rebecca Hubert Scherler is the Legal & Partnership Lead at Women in AI Switzerland and brings 15+ years of international legal and governance leadership across sectors, including international agricultural development. She advises Boards and senior leadership teams on regulatory, commercial and governance matters, with particular experience in strategic partnerships and scaling emerging technologies and new business models across multiple jurisdictions. Caroline Perriard merges 20+ years in strategy, governance, and AI regulation, with board-level experience at Nestlé, SMEs, and startups, to guide organizations in adopting AI responsibly while driving competitive advantage, blending legal rigor with pragmatic business insight. 


Practical AI Governance in Switzerland: What Companies Are Learning from Early Adoption and Pilots

Artificial Intelligence is transforming industries, but its rapid adoption brings complex risks. From compliance headaches to ethical dilemmas, organizations must prioritize governance to harness AI’s potential responsibly.


Switzerland does not yet have a single, comprehensive “AI Act,” and AI governance is therefore grounded in existing cross-cutting legislation and sector-specific regulation, with an additional layer of rules expected under the forthcoming Council of Europe AI Convention. In parallel, the EU AI Act’s extraterritorial reach is becoming concrete, with enforcement of the EU Act’s General Purpose AI provisions beginning on 2 August 2026 (with high-risk system obligations delayed to December 2027); a development directly relevant for Swiss companies with touchpoints to the EU market¹.


Against this backdrop, the authors spoke with key contacts within their network to examine how companies across four key Swiss sectors have been adopting or piloting AI tools to date, the lessons emerging from their early use, and the governance protocols that can be distilled from their approaches and challenges.


Life Science 

The life science sector emerged as one of the most mature adopters of AI, driven in part by the fact that many Swiss‑headquartered companies operate across Europe and have already been preparing to meet the requirements of the EU AI Act. The sector's approach has been characterised by strong executive sponsorship, with AI positioned as a strategic capability to improve productivity, accelerate innovation and strengthen global competitiveness. Early implementation prioritised governance over experimentation. Many organisations initially restricted access to public generative AI tools while developing internal AI codes of practice, policies and manifestos before authorising broader staff use. AI literacy has become a mandatory organisational capability, with multiple rounds of enterprise-wide training supported by investment in workforce upskilling.


The principal challenge has been balancing rapid AI deployment with effective AI governance. Multiple business units were pursuing AI initiatives simultaneously, resulting in duplicated use cases and highlighting the need for centralised registers of AI projects and validated applications. Interviewed stakeholders consistently emphasised the importance of clearly defined roles, responsibilities and accountability, particularly around data ownership, data lineage and the lawful use of enterprise data. Governance became increasingly viewed as an operational capability rather than merely a compliance exercise.


For multinational organisations, regulatory fragmentation presents a significant obstacle. Respondents described an emerging shift from globalisation towards digital protectionism, requiring continuous monitoring of divergent AI and data protection laws across jurisdictions. They favour integrating AI governance into existing privacy, security and risk management frameworks using a risk-based model similar to GDPR, creating a single, auditable source of governance rather than multiple disconnected assessment processes.


The Academic Sector

In academia, AI technologies introduce governance challenges related to content ownership, research transparency, and information accuracy. Students and professors have adopted and tested generative AI tools at the same time. Access to instant in-depth knowledge is a relatively new phenomenon, and a challenge, because professors were traditionally the primary holders of subject-matter expertise.


Interviews showed that AI technology is raising new questions, which institutions must address by developing new practices.


  • Intellectual property ambiguity: Who owns AI-generated content and research? Universities, researchers, or the AI developers? Swiss copyright law lags behind AI advancements, creating potential disputes over authorship.

  • Transparency: When should academic content produced by AI tools (by both teachers and students) be disclosed? For example, is it acceptable to submit an essay written with a generative AI tool?

  • Accuracy and accountability: If AI-driven research leads to harmful outcomes (e.g., flawed medical advice), who, the researcher, the institution, or the AI provider, is liable ?

  • Data sharing vs. privacy: Research often involves sensitive data (e.g., medical records) or confidential enhancements. Balancing open science with data protection frameworks is challenging, especially given the risk of unauthorized disclosure of sensitive content.


University leaders want to encourage innovation. At the same time, they are concerned about the consequences of AI-related errors, such as inaccuracies or hallucinations (where AI generates false or misleading information). They recognise that AI governance is essential for the responsible adoption of AI. They want clear policies on the use of AI in research and education, given how rapidly the AI landscape is changing. New methods for evaluating students are being tested and implemented, often involving more personal interaction. The availability of AI tools leads to a need for deeper insights into how results are achieved, the reasoning behind answers, and the application of specific methodology.

In our interviews, Swiss academics noted that students tend to trust AI tools more than professors do. This means that students often believe they themselves know as much, or more, than the professors. Professors need to challenge their students, not only on the content, but on the methodology or analytics used to produce it.


In terms of AI governance, experts have highlighted three key actions:


1) Institutions have not yet fully addressed ethics and governance issues. Guidelines exist in academic institutions, but training for all levels of knowledge and use is essential. There is a risk that training will remain too basic or become overly specialized, catering only to a niche group of experts. Governance programmes should include a progressive learning curve accessible to all users. For example, a Swiss group of universities has created a series of flash learning videos, allowing users to learn about AI step by step.


2) Data usage needs clarification. Ethical AI policies can help clarify clear institutional rules in AI use in research, teaching, and administration (e.g., disclosure of AI assistance in publications). In addition, data governance committees can oversee privacy, security, and sharing in AI projects.


3) Ownership rights for AI-generated output must be defined to protect proprietary innovation. Promoting transparency in AI-driven research (with, for example, open methodologies or reproducible code) will mitigate the black box effect and increase trust in the output and its subsequent use.


The Financial Sector

Financial institutions operate in a highly regulated environment, and financial experts are accustomed to dealing with risks and mitigation measures. While AI introduces opportunities, compliance officers must also address new threats. Based on our interviews, we highlight two key challenges, among others: regulatory uncertainty and cybersecurity risks.


First, compliance officers struggle to interpret evolving AI regulations (e.g., EU AI Act, Swiss FINMA guidelines, GDPR, and FADP) and anticipate future legislative developments. For example, the scope of liability for AI-driven decisions (e.g., credit scoring, fraud detection) is still subject to review by courts, which creates legal exposure. In addition, many countries are working on sector-specific or general AI-related legislation. Now it is time to anticipate the impact of these new technologies on business models. Financial associations, such as the Swiss Bankers Association, are making valuable contributions to responsible policies.


Second, AI systems are frequent targets for adversarial attacks (e.g., data poisoning, model inversion). A breach could expose sensitive customer data or disrupt financial markets. How can these risks be mitigated, given the (limited) available resources of these institutions? Is it possible to set a maximum investment budget for cybersecurity, especially when AI tools achieve unexpected results that demand a pause for reflection?


Other risks, such as bias, fairness, or model explainability will also face scrutiny in future audits. Regulators and customers demand transparency, but explaining complex models remains technically difficult.


Today, compliance officers recognize the need for cross-functional collaboration (e.g., with data scientists and legal teams) but lack the technical fluency to assess AI risks effectively. How can they review an audit report on bias if they do not know how to interpret outputs and potential errors?


Managers see AI as a competitive advantage but worry about accountability. Most want standardized frameworks to evaluate AI systems’ compliance and ethics. Board members and executives must ensure compliance with general principles of care, especially when dealing with high-risk or opaque AI systems. In particular the Swiss FINMA Guidance note 08/2024 emphasizes that financial institutions must proactively identify, assess, manage, and monitor AI-related risks as part of their governance and risk management obligations. Proper governance is consequently needed. Finally, data analysts tend to prioritize model performance over governance. They require training on ethical AI design and regulatory requirements.


Experts in the financial sector identified three areas for improvement in AI governance and risk mitigation. 


  1. New certification programs, industry workshops, and peer networks can help share knowledge, use cases, and best practices. 

  2. Currently many professionals publicly claim to use AI tools. However, few demonstrate a deep understanding of their governance implications. Managers also see the need to adopt a culture shift toward accountability. Ultimately, with sufficient training and skills, teams should proactively identify and mitigate AI risks rather than merely reacting to incidents. 

  3. AI adoption is often resource-intensive. Compliance officers must, for example, integrate AI governance into existing compliance frameworks (e.g., AML, KYC).


Non-Profit Organisations

Switzerland’s non‑profit sector comprises charitable foundations, associations and international organisations. Interviews with senior leaders in non‑profit organisations that have proactively adopted AI‑enabled tools reveal a strong leadership commitment to AI. AI is viewed primarily as an enabler of mission delivery rather than simply an efficiency tool. Leaders have championed organisation‑wide adoption, with AI already being piloted in core investment and social‑impact assessment processes. Early testing highlighted that effective AI performance requires extensive domain‑specific prompting and deep contextual understanding, reinforcing that human expertise remains essential even when AI supports analytical tasks.


From these interviews, AI showed greatest value as a counterbalance to cognitive bias and groupthink, for example by acting as a "sparring partner" during investment committee deliberations. However, those interviewed acknowledge the significant challenge of translating many years of implicit organisational knowledge and seasoned reasoning of senior leaders into an AI agent since doing so requires making explicit information that have not necessarily been formally articulated, i.e. in effect, “downloading everything that’s in their board members or executive team’s heads”.


Governance across the sector is pragmatic and proportionate to risk. Rather than expecting perfect accuracy, organisations assess whether AI‑related errors can be safely managed and whether the technology performs at least as well as human decision‑makers while delivering additional insights. Human teams retain accountability for final decisions, with governance frameworks evolving as organisational confidence in AI grows. Respondents also underscored that high‑quality data and robust infrastructure remain essential foundations for responsible adoption.


AI literacy at board level was identified as a significant governance gap, highlighting the need for organisations to also equip board members with a sufficiently deep understanding of AI’s capabilities and limitations, as well as the risks and governance responsibilities associated with its deployment.


At the organisational level, strengthening AI readiness requires a similarly deliberate investment in people. AI academies, hackathons, speaker programmes and structured training can help build knowledge and technical skills while also changing how employees understand, engage with and incorporate AI into their work. These initiatives can help build confidence, reduce resistance and support the transition towards new ways of working, particularly where employees may otherwise feel overwhelmed or concerned about the impact of AI on their roles. However, the pace at which AI capabilities continue to evolve remains a challenge, with organisations needing to ensure that learning and adoption keep pace with technological change and that AI uptake does not become uneven across teams.


Conclusion

The sector snapshots demonstrate that, despite the absence of a comprehensive Swiss AI Act, Swiss organisations are not postponing AI governance efforts while awaiting legislative certainty. Instead, they are building governance frameworks around existing legal obligations - including the Federal Act on Data Protection (FADP), FINMA, contractual obligations, intellectual property law, cybersecurity requirements and sector-specific regulation - while simultaneously preparing for the extraterritorial impact of the EU AI Act.


Across all four sectors, AI governance is becoming an enterprise governance issue, rather than solely a legal, compliance or technology issue. Effective governance increasingly involves appointing a Chief Data Officer or Head of AI to coordinate collaboration across legal, compliance, information security, procurement, HR, data governance and operational teams. In addition, AI literacy is emerging as a core governance capability, enabling boards, executives and operational teams to exercise meaningful oversight. Organisations are also adopting a risk-based approach, drawing on governance models already familiar under privacy and financial regulation. Rather than striving for perfect AI outputs, they are assessing whether risks are identifiable, proportionate and capable of being managed through documented accountability, human oversight, validation and continuous monitoring throughout the AI lifecycle.


Given that AI governance would be part of the board-level fiduciary duties, defining clear accountability and processes is essential in every industry. Responsible AI governance is also becoming a key part of successful digital transformation for SMEs. As AI becomes part of everyday business processes, governance can no longer be considered the sole responsibility of large corporations, universities or technical teams.


A 2026 study of EY² showed that in Switzerland,

“40% of interviewed companies support dedicated programs to help SMEs adopt AI. A similar share sees alignment with the EU AI Act as important for ensuring legal certainty in international business. At the same time, 28% support maintaining an independent Swiss regulatory approach.”

The forthcoming bill regulating AI implementation in Switzerland³ will be welcomed by many organisations. It is expected to provide greater clarity on the legal measures needed to implement the Council of Europe’s AI Convention, including in relation to transparency, data protection, non-discrimination and supervision, while also setting out an implementation plan for non-binding measures relating to industry solutions and voluntary commitment declarations. A distinctly Swiss approach will likely incorporate several of the practical insights outlined in this article. We therefore look forward to reviewing the Swiss Government’s consultation draft, expected by the end of 2026, and sharing further reflections on how the proposed framework can support practical, adaptive and risk-based AI governance.


¹ From 2 August 2026, the European Commission’s AI Office, together with national authorities, will begin enforcing the EU Artificial Intelligence (AI) Act. This will affect Swiss companies operating in Europe that place AI systems directly onto the EU market, deploy or operate AI tools through an EU‑based subsidiary, act as exporters or importers of AI infrastructure into the EU, or whose AI models hosted in Switzerland generate data outputs used within the EU.


 ² EY AI Survey 2026 – Artificial Intelligence in Swiss Companies - https://www.ey.com/en_ch/functional/forms/download/ey-ai-survey-2026





_____________________________________________________________

Collaborate with us!

As always, we appreciate you taking the time to read our blog post.


If you have news relevant to our global WAI community or expertise in AI and law, we invite you to contribute to the WAI Legal Insights Blog in 2016! To explore this opportunity, please contact WAI editors Silvia A. Carretta - WAI Chief Legal Officer (via LinkedIn or silvia@womeninai.co) or Dina Blikshteyn  (dina@womeninai.co).


Silvia A. Carretta and Dina Blikshteyn

- Editors



Comments


bottom of page