Methods and protocols
Legal orientation — Switzerland and the European Union
Snapshot verified on 20 August 2026. This page helps frame the questions to ask; it is not legal advice. Verify the current text, sector, jurisdiction, and the organization’s exact role before making a decision.
Switzerland
Switzerland does not yet have a general law dedicated exclusively to AI. The technology-neutral Federal Act on Data Protection (FADP) nevertheless applies directly to AI-assisted processing of personal data.
Control points:
- purpose, proportionality, transparency, and individual control;
- sensitive data, profiling, and automated individual decisions;
- data protection by design and by default;
- security, processors, processing locations, and international transfers;
- information about interaction with a machine and data reuse where required;
- a data protection impact assessment when processing is likely to result in a high risk.
The controller remains accountable when processing is entrusted to a provider. In particular, it must govern instructions, confidentiality, security, subprocessors, and transfers.
Operational routing by use pattern:
- for direct language-model interaction, record how people learn that they are corresponding with a machine and whether their inputs are reused;
- for an automated individual decision with legal or similarly significant effects, verify Article 21 FADP notice, the opportunity to state a point of view, review by a natural person, and the exact exceptions;
- for synthetic faces, images, or voices of identifiable people, record clear identification, consent or other authority, privacy controls, and applicable personality, criminal, and intellectual-property rules;
- for processing likely to create a high risk, complete and retain the data-protection impact assessment before the pilot.
As of 20 August 2026, draft legislation intended in particular to implement the Council of Europe Convention was still due to enter consultation by the end of 2026. Do not describe this future proposal as law already in force.
European Union
The AI Act follows a risk-based approach. The role — provider, deployer, importer, or distributor — and the use case determine the obligations.
Status verified on 20 August 2026:
- Article 50 transparency obligations have applied since 2 August 2026;
- the AI Omnibus, which entered into force in July 2026, sets 2 December 2027 as the application date for Annex III high-risk rules;
- high-risk rules for systems embedded in Annex I products apply from 2 August 2028;
- Article 4 retains a duty to support AI literacy appropriate to the role, people, context, and risks, without prescribing a specific individual level;
- national supervision of Article 4 has applied since August 2026.
Prohibitions, rules for general-purpose AI models, transparency, data protection, employment law, consumer protection, intellectual property, and sector-specific rules must be assessed separately.
Operational routing for Article 50:
- direct interaction: determine whether the provider must design the system to inform people that they are interacting with AI;
- synthetic content: determine whether the provider must add detectable machine-readable marking;
- deepfakes and certain public-interest text: determine the deployer’s visible-disclosure duty and the applicable exceptions;
- emotion recognition and biometric categorisation: determine the deployer’s information duty;
- retain the role analysis, interface evidence, marking evidence, exceptions, and verification date.
These EU duties do not replace FADP analysis when Switzerland is also in scope, and Swiss transparency does not by itself prove Article 50 compliance.
Questions to document for every use case
- What is the exact purpose, and what legal basis authorizes the data processing?
- Which people are affected, informed, and able to challenge the outcome?
- Does a decision produce legal or similarly significant effects?
- Does the system or its use fall into a prohibited or high-risk category?
- Where is the data processed, and by which subprocessors?
- Is the data used to improve or train a provider’s systems?
- What retention, access, correction, export, and deletion capabilities apply?
- Is a data-protection or fundamental-rights impact assessment required?
- Which transparency, documentation, logging, oversight, and training duties apply?
- Which audit, human-recourse, and continuity mechanisms are required?
Use the source register and date the legal qualification in every case file.
To print or save as PDF: Ctrl+P (⌘P on Mac).
Source and history · GitHub