Swiss AI regulation 2026 does not mean that law firms should wait for a new AI statute. No overarching Swiss AI Act currently applies. Yet data protection law, professional duties and criminal law already cover many legal AI workflows. A consultation draft is only expected by the end of 2026. Legal practice must therefore separate current law from the political timetable.
The short answer: what applies and what is planned?
Switzerland has not adopted a comprehensive AI Act based on the EU model. The Federal Chancellery and the Federal Office of Justice continue to state that Switzerland has no overarching legislation specifically governing AI. That does not put AI into a legal vacuum.
Four existing areas of law are particularly relevant to Swiss law firms and legal teams today:
The Federal Act on Data Protection applies whenever the AI system processes personal data.
Lawyers remain subject to the duty to practise carefully and conscientiously under Art. 12 BGFA.
Professional secrecy under Art. 13 BGFA and Art. 321 of the Criminal Code does not cease to apply when an external provider is involved; the status and contractual safeguards of the persons involved require a separate assessment.
Other rules may apply depending on the use case, including contract, employment, copyright or procedural law.
Switzerland is preparing a consultation draft on AI regulation. The Federal Office of Justice is expected to complete it by the end of 2026. Legislative measures are envisaged in particular for transparency, data protection, non-discrimination and supervision. Non-binding instruments such as industry arrangements and voluntary commitments are also being considered. Neither the mandate to draft legislation nor a future consultation proposal creates new duties for law firms today.
The legal framework for legal work at a glance
Issue | Status on 18 September 2026 | Meaning for law firms and legal teams |
|---|---|---|
Swiss AI Act | No overarching AI-specific statute yet | Apply existing law to the actual workflow instead of waiting for a new act |
Swiss data protection law | Already applies | Review personal data, purpose, transparency, security, processing by third parties, foreign disclosure and potential DPIA triggers |
Lawyers' duty of care | Already applies | Verify sources, current law and the result before using it in a matter |
Professional secrecy | Already applies | Clarify data flows, access, subcontractors and contractual confidentiality before use |
Council of Europe AI Convention | Signed by Switzerland but not ratified | Do not derive an immediately applicable Swiss law-firm duty from the Convention |
Swiss consultation draft | Announced for the end of 2026 | Monitor the actual draft once published; do not invent detailed duties now |
EU AI Act | Separate EU framework | Assess scope separately by reference to role, system and connection with the EU |
This overview is deliberately functional. Whether a rule applies does not depend on the label "AI". It depends on the data processed, the system's task, who makes the decision and where information flows.
Data protection law already applies to AI
The Federal Data Protection and Information Commissioner expressly states that the Swiss Federal Act on Data Protection is technology-neutral and directly applies to AI-supported processing of personal data. This is often the first concrete legal test for legal work. If a contract, pleading, email thread or data room contains information about an identified or identifiable natural person, the use of AI is also a data-processing operation.
That does not mean that every use of AI is treated in the same way. Research in published statutes and judgments has a different risk profile from an analysis of an employment file containing health information. Relevant factors include purpose, nature and volume of data, access rights, retention, model training, subcontractors and possible disclosure abroad.
Art. 6 revFADP contains the general processing principles. Art. 7 revFADP requires privacy by design and privacy-friendly default settings. If a provider processes data on behalf of another organisation, Art. 9 revFADP must be examined. This requires a factual assessment of roles and contracts. A provider does not become a processor in every situation merely because its product uses AI.
Nor does the word "AI" automatically trigger a data protection impact assessment. Under Art. 22 revFADP, a DPIA is required if planned processing is likely to create a high risk to the personality or fundamental rights of affected persons. The FDPIC identifies new technologies as one possible risk factor, while also looking at the nature, scope, circumstances and purpose of processing. A documented trigger assessment is therefore more defensible than a blanket rule that every AI project needs a DPIA.
Automated individual decisions require particular attention. Where a system makes a decision without human intervention that produces legal effects for a person or significantly affects that person, specific information and review rights may apply. The FDPIC's guidance on Art. 21 revFADP explains that the affected person must generally be informed and be able to request human review. An AI system that gives a lawyer a draft clause or research lead is different because a human still decides. That distinction should be reflected in the actual process and in its documentation, not merely asserted in a policy.
The detailed article on AI and the Swiss FADP covers data protection, DPIAs, processing by third parties and foreign transfers. This new regulation article does not replace that resource. It places data protection within the broader Swiss legal framework.
Professional duties and secrecy do not wait for an AI statute
Registered lawyers must also consider professional law. Art. 12 BGFA requires careful and conscientious professional practice. Art. 13 BGFA protects professional secrecy, while Art. 321 of the Criminal Code provides criminal-law protection for specified professional secrets. None of these rules includes an exception for generative AI.
The practical result has two parts.
First, professional responsibility remains with the lawyer. An AI output is an aid, not proof that a legal statement is correct. Sources must exist, fit the facts and reflect the current law. Contract clauses require an assessment of the represented party's position, the negotiation context and interactions with other provisions. The greater the legal consequence, the less a simple plausibility check will suffice.
Second, professional secrecy must be examined along the actual data path. The location of the visible application is not enough. The review should cover inference regions, logging, retention periods, possible human access, model training and every subcontractor. The contractual arrangement matters as well. Whether and under what conditions a provider or specific individuals qualify as auxiliary persons is a concrete legal question, not an automatic product attribute.
The Swiss Bar Association guidance on AI is a useful practical source. It is not itself a statute or an independent sanctioning rule. Its value lies in translating existing duties into the context of AI workflows. The dedicated article explains what the guidance means for vendor selection, output review and internal policies.
What Switzerland is only preparing for the end of 2026
The Federal Council instructed the administration to prepare a consultation draft on new rules for the use of AI by the end of 2026. According to the current federal information, the legislative project is to address transparency, data protection, non-discrimination and supervision in particular. The federal authorities are also preparing a plan for non-binding measures such as industry arrangements and voluntary commitments.
It is not possible to go materially further until a draft is published. It would be premature to derive specific duties, risk classes or sanctions for Swiss law firms from legislation that does not yet exist. It is also still open which current laws will be amended, which sector-specific rules will be added and which transition periods a later act might contain.
The timetable is a policy and legislative timetable, not an effective date. A consultation is followed by evaluation, a Federal Council message, parliamentary deliberation and potentially a referendum. Even if a draft is published at the end of 2026, it will not become applicable law overnight.
Legal teams can therefore use a simple monitoring rule. Implement current duties properly now. Once the proposal is published, analyse the actual text. Only then should the organisation perform a gap analysis between its existing governance and the proposed new duties.
The Council of Europe Convention has been signed but not ratified
Switzerland signed the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law on 27 March 2025. The Council of Europe's official treaty chart still records a signature for Switzerland but no ratification. The treaty status shown there also confirms that the threshold for the Convention to enter into force internationally has not yet been reached.
That distinction is central. The Convention is an international legal reference framework. Switzerland's signature alone does not mean that each substantive provision already applies directly as a new duty for Swiss law firms. The Federal Office of Justice describes the planned Swiss legislation as the step that should enable Switzerland to ratify the Convention.
The Convention can therefore guide monitoring of future subjects such as fundamental rights, transparency, non-discrimination and supervision. It does not replace the analysis of rules currently in force and does not support the statement that "the new Swiss AI regulation already applies".
The EU AI Act is a separate scope analysis
The EU AI Act should not be presented as Switzerland's AI statute. It is a separate EU legal framework with its own personal, material and territorial scope. It may matter to a Swiss law firm, but an EU matter or EU client does not automatically produce the same legal classification for every internal AI workflow.
At a minimum, the assessment must cover the organisation's role, the specific AI system, its intended use and the actual connection with the EU. The relevant duties and dates must then be checked for that specific situation. Blanket statements that all systems and roles are subject to the same rules at the same time are too broad.
The detail belongs in the existing article on the EU AI Act and Legal Tech. This Swiss regulation article is deliberately limited to the boundary between the two frameworks: analyse the Swiss workflow under Swiss law first, then assess the EU AI Act as a separate second layer.
A seven-point legal check for every AI workflow
Instead of assigning an abstract "AI risk", legal teams can test each use case with seven concrete questions.
Task: Does the system assist with research, drafting or analysis, or does it make a decision about a person?
Data: Does it process public sources, personal data, sensitive personal data or confidential matter information?
Roles: Who determines the purpose and means of processing? Which providers and subcontractors are involved?
Data path: Where do inference, storage and support access occur? Are inputs logged or used for training?
Risk trigger: Is the processing likely to create a high data-protection risk? Does it involve automated individual decisions or systematic assessments?
Human control: Who checks sources, current law, clauses and conclusions before the result is used for legal work?
Evidence: Are approval, vendor review, permitted uses and review steps documented so that the real process can be reconstructed?
These questions lead to different outcomes. Research in public judgments may use no matter data, but it still requires reliable source verification. A bulk analysis of personnel files may involve large quantities of sensitive personal data and trigger a DPIA assessment. Drafting a contract from identifiable matter information may engage both data protection and professional secrecy even if the system does not make an automated individual decision.
An example illustrates the required separation. If a lawyer uses AI to search published Federal Supreme Court judgments, the main issues are source quality, currency and professional review. If the lawyer then uploads the client's unpublished draft contract, data paths and professional secrecy become relevant as well. If a company finally uses the same technology to score job applications without human intervention, sensitive data, high risk and an automated individual decision may come into play. The underlying language model could be the same in all three cases, but the legal processing operations are different.
Approval should therefore never attach to a product name alone. It should attach to a defined use case with permitted data, an approved configuration and accountable human review. If the purpose, volume of data or degree of automation changes, the assessment should be reopened. This use-case-based governance also prevents the false assumption that reviewing a provider once makes every later use automatically permissible.
Human review remains necessary with CASUS as well: CASUS AI produces drafts and suggestions that may be incomplete or incorrect and must be reviewed by a legal professional before use.
What law firms should do now
The most useful next step is not to predict the final text of a Swiss AI statute. It is to create a limited inventory of the systems currently in use. For each tool, record the use cases, data categories, roles, data paths and human controls. Existing duties can then be assigned to the workflow.
Three gaps deserve particular attention: unapproved consumer tools, unclear data and access chains, and missing rules for professional review of outputs. A short, binding use policy can state which data may enter which systems, when additional approval is needed and who must review the result.
Future regulation should be a separate monitoring item within governance. A named owner should analyse the proposal once it is published. Until then, placing the words "AI Act ready" on a procurement checklist is not enough. What matters is demonstrable compliance with the law that actually applies to the specific workflow.
If you want to test a legal-AI workflow that produces drafts and suggestions requiring review, you can try CASUS free of charge. The responsible organisation and its legal advisers remain accountable for the legal assessment of the specific use.
FAQ
Does Switzerland have an AI Act in 2026?
No. As of 18 September 2026, the Federal Chancellery and Federal Office of Justice state that Switzerland has no overarching legislation specifically governing AI. A consultation draft is expected by the end of 2026. Existing laws, including data protection and professional law, already apply independently of that project.
Does Swiss data protection law apply to AI?
Yes, where personal data is processed. The revFADP is technology-neutral and, according to the FDPIC, directly applies to AI-supported processing. The specific duties depend on the purpose, data, roles, risk and data path of the individual use case.
Does every law firm need a data protection impact assessment for AI?
No. Under Art. 22 revFADP, a DPIA is required when planned processing is likely to result in a high risk. New technology is one risk factor, not the only one. The nature, scope, circumstances and purpose of processing must be assessed in the specific case.
May lawyers use generative AI?
There is no general prohibition. The use must remain compatible with professional care, professional secrecy, data protection and the duties of the specific matter. Output verification and a defensible review of data flows, access, retention and subcontractors are particularly important.
Does the Council of Europe AI Convention already apply in Switzerland?
Switzerland signed the Convention on 27 March 2025 but, according to the current treaty status, has not ratified it. Signature alone is not equivalent to a new, implemented duty for Swiss law firms. The planned legislation is intended to create the conditions for ratification.
Does the EU AI Act automatically apply to Swiss law firms?
No. Its scope must be assessed separately by reference to role, system, intended use and connection with the EU. It is not Switzerland's AI statute, nor does it apply in full merely because a law firm occasionally works on an EU matter.
What is the most important step before approving an AI tool?
Describe the actual workflow first: task, data, providers, storage and access chain, potential risk triggers and human review. Only then can the organisation reliably identify the current duties and evidence it needs.
*Current as of 18 September 2026. This article provides general information and is not legal advice for a specific matter.*







