INSIGHT // 61 Comparative

Switzerland's Lean AI Path: Why the Federal Council's Sector-Specific Approach Diverges From the EU AI Act

Abstract: On 12 February 2025 the Federal Council set Switzerland's course on artificial intelligence: no horizontal statute, ratification of the Council of Europe's AI convention, sectoral amendments where implementation requires them, and a consultation draft due by the end of 2026. For US technology companies serving Switzerland and the EU, compliance splits into two architectures moving on different clocks.
Plain Language Summary

Switzerland regulates artificial intelligence without a single horizontal law like the EU AI Act. It plans instead to ratify the Council of Europe's AI convention and to adjust individual sectoral laws, with a consultation draft due by the end of 2026. US technology, digital-health, and MedTech companies active in both Switzerland and the EU therefore work under two frameworks at once. The same AI system faces different obligations in each market.

Table of Contents
  1. The Federal Council's Choice: Sector Law, Not a Horizontal Act
  2. The Council of Europe AI Convention as Switzerland's Anchor
  3. Where the Swiss Path and the EU AI Act Diverge
  4. What This Means for AI in Swiss Digital Health and MedTech
  5. Strategic Considerations

US legal teams tend to treat European AI regulation as a single variable: the EU AI Act, budgeted as one compliance program for one continent. Switzerland does not fit the model. It is not an EU Member State, the AI Act does not apply there, and on 12 February 2025 the Federal Council decided against building a Swiss counterpart to it. What Switzerland is building instead, a treaty-anchored framework assembled sector by sector, behaves differently on almost every axis a compliance calendar cares about. For a company serving both markets, the result is not one European AI program. It is two.

1. The Federal Council's Choice: Sector Law, Not a Horizontal Act

The decision rests on an analytical exercise the Federal Council commissioned in November 2023 and received as the Auslegeordnung, a mapping of possible regulatory approaches led by BAKOM, the federal communications office, and published alongside the decision itself. Three objectives frame the outcome: strengthening Switzerland as a location for innovation, protecting fundamental rights including economic freedom, and building public trust in AI. The conclusion drawn from them is deliberately narrow. Switzerland is to ratify the Council of Europe's AI convention, amend sectoral law where implementation requires it, and confine general, cross-sector rules to fields central to fundamental rights, the example the decision names being data protection. The EJPD, the federal justice and police department, working with the departments responsible for communications and foreign affairs (UVEK and EDA), is to deliver a consultation draft by the end of 2026 addressing transparency, data protection, non-discrimination, and oversight; UVEK is to deliver, on the same deadline, a plan of legally non-binding measures such as self-declaration agreements and industry solutions, weighing compatibility with the regulatory development of Switzerland's major trading partners.1Schweizerischer Bundesrat, 'KI-Regulierung: Bundesrat will Konvention des Europarats ratifizieren' (Medienmitteilung, 12. Februar 2025); BAKOM, 'Auslegeordnung zur Regulierung von künstlicher Intelligenz' (Bericht an den Bundesrat, 12. Februar 2025).

The absence of a Swiss AI Act is not the absence of Swiss AI law: the obligations exist, but they sit in sectoral statutes that must be assembled, not read.

What already exists is easy to underestimate from a US vantage point, where the federal analogue is a voluntary baseline built from the NIST AI Risk Management Framework and executive action, with binding duties arriving state by state rather than as a single federal act. The Swiss baseline is binding at federal level; it is simply not labeled as AI law. The EDÖB, the federal data protection authority, confirmed on 9 November 2023 that the DSG, Switzerland's data protection statute in force since 1 September 2023, applies directly to AI-supported processing of personal data, and Art. 21 DSG attaches duties to automated individual decisions: the person concerned must be informed, may on request state a position, and may demand review by a natural person.2Bundesgesetz über den Datenschutz (Datenschutzgesetz, DSG) vom 25. September 2020 (SR 235.1), Art. 21; EDÖB, 'Geltendes Datenschutzgesetz ist auf KI direkt anwendbar' (9. November 2023). Sector regulators have not waited for the consultation draft either. FINMA's Aufsichtsmitteilung 08/2024 sets out supervisory expectations for governance and risk management where supervised financial institutions deploy AI, and the Verordnung über das automatisierte Fahren (VAF) has, since 1 March 2025, permitted conditionally automated driving on Swiss motorways under rules no horizontal statute frames.3FINMA, 'Governance und Risikomanagement beim Einsatz Künstlicher Intelligenz' (Aufsichtsmitteilung 08/2024, 18. Dezember 2024); Verordnung über das automatisierte Fahren (VAF) vom 13. Dezember 2024 (SR 741.59). A company that scans Swiss law for an AI act, finds none, and concludes that nothing binds it has misread the architecture, not the law. The obligations are real. They are filed under other names, and no single register collects them.

2. The Council of Europe AI Convention as Switzerland's Anchor

The instrument Switzerland chose as its anchor is not a product regulation. The Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, signed for Switzerland on 27 March 2025, is a treaty binding its Parties, States and the European Union alike: it obliges them to adopt or maintain measures for transparency and oversight, for remedies, and for risk and impact management across the AI lifecycle, and it leaves the form of those measures to national law.4Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No 225, opened for signature 5 September 2024; signed by Switzerland 27 March 2025). Nothing in it binds a company directly. Its reach into the private sector runs through a fork built into Art. 3 of the convention: each party applies the convention to activities of public authorities and of private actors acting on their behalf, while for the remaining private-sector activity each party must address risks and impacts in a manner conforming with the convention's object and purpose, and must specify in a declaration how it intends to do so. The declaration may apply the convention's principles and obligations to private actors outright, or rest on other appropriate measures; Norway, for instance, lodged a declaration at signature.

That declaration is where the lean path either holds or hardens. Applying the convention's principles and obligations to private actors wholesale would pull Swiss law considerably closer to a general AI regime than the sectoral rhetoric suggests; resting on other appropriate measures preserves the leanness, and invites the question whether the sectoral patchwork actually delivers what the convention demands. The declaration falls due, if not lodged at signature, when the instrument of ratification is deposited, and ratification waits on the end-2026 draft, consultation, and parliamentary approval. The convention itself, meanwhile, had not entered into force as of publication: its threshold of five ratifications including three Council of Europe member states remained unmet after the European Union deposited its approval on 15 May 2026. A US company modeling Swiss AI exposure is modeling a moving object, and the binding content will crystallize in instruments that do not yet exist.

3. Where the Swiss Path and the EU AI Act Diverge

The EU chose the opposite architecture, and the differences are structural rather than cosmetic. The AI Act is a horizontal product regulation: it prohibits defined practices outright, classifies systems by risk, attaches conformity assessment and CE-marking duties to high-risk systems, regulates general-purpose AI models as a category of their own, and backs all of it with administrative fines reaching 35 million euros or 7% of worldwide annual turnover, whichever is higher, for prohibited practices, and 15 million euros or 3% on the same basis for a closed list of other operator and transparency obligations.5Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (AI Act) [2024] OJ L 2024/1689. Swiss law has none of these elements: no risk taxonomy, no AI conformity assessment, no AI-specific market-surveillance authority, no AI-specific fine. Even the sanctions logic differs: where the AI Act fines undertakings, the DSG's criminal provisions aim at responsible natural persons, with fines of up to 250,000 Swiss francs, a personal-exposure profile that US officers rarely price into a Swiss launch. The comparison a US reader will be tempted to draw, regulated in the EU against unregulated in Switzerland, is the wrong one. The accurate comparison is codified and centralized against distributed and partly unwritten, and distributed regimes are harder to diligence, not easier.

The calendars diverge as sharply as the architectures. The AI Act's prohibitions have applied since 2 February 2025 and its obligations for general-purpose AI models since 2 August 2025; on 2 August 2026 the regulation reaches its general application date and the Commission's enforcement powers over model providers switch on. The high-risk timetable is being moved: under the Digital Omnibus on AI, approved by the European Parliament on 16 June 2026 but not formally adopted as of publication, the stand-alone high-risk obligations of Annex III would shift to 2 December 2027 and the Annex I product rules to 2 August 2028.6European Commission, 'Digital Omnibus on AI' COM(2025) 836 final (19 November 2025); provisional agreement 7 May 2026; approved by the European Parliament 16 June 2026; not formally adopted as of publication. Switzerland's calendar holds, so far, a single fixed point: a consultation draft by the end of 2026, to be followed by consultation, parliamentary deliberation, a possible referendum, and only then ratification and whatever sectoral amendments survive the process. One regime's dates are enforcement dates. The other's are drafting milestones.

Two calendars: EU AI Act application dates against Switzerland's implementation track A timeline from 2025 to the end of 2028 with two tracks. The EU AI Act track shows prohibitions applying on 2 February 2025, general-purpose AI obligations on 2 August 2025, general application and enforcement on 2 August 2026, and Annex I product obligations on 2 August 2027, then, as outlined markers pending formal adoption of the amending regulation, Annex III high-risk obligations on 2 December 2027 and a deferral of the Annex I product obligations to 2 August 2028. The Switzerland track shows the Federal Council decision of 12 February 2025, signature of the Council of Europe AI convention on 27 March 2025, and a consultation draft due by the end of 2026, followed by a dashed open-ended segment for consultation, parliamentary deliberation, and ratification without fixed dates. Two calendars: EU application dates, Swiss drafting milestones EU AI Act Switzerland Prohibitions 2 Feb 2025 General-purpose AI obligations 2 Aug 2025 General application + enforcement powers 2 Aug 2026 Annex I products 2 Aug 2027 Annex III high-risk 2 Dec 2027 Annex I, if deferred 2 Aug 2028 Federal Council decision 12 Feb 2025 Convention signed 27 Mar 2025 Consultation draft due end 2026 Consultation, Parliament, ratification no fixed dates 2025 2026 2027 2028
Application dates under the AI Act against Switzerland's implementation track. The 2 December 2027 and 2 August 2028 dates reflect the amendment approved by the European Parliament on 16 June 2026, not formally adopted at publication (outlined markers), and sit against the 2 August 2027 date the AI Act sets for Annex I products; the Swiss track carries no dates beyond the end-2026 consultation draft.

Neither regime stops at its border, which is what makes the divergence a compliance problem rather than a curiosity. Art. 2(1) AI Act reaches providers wherever established once a system is placed on the Union market, and reaches providers and deployers in third countries where the system's output is used in the Union; a deployment run from Switzerland with output flowing to EU users can sit inside the Act while the deploying entity sits outside it. The inverse holds with equal force: full AI Act conformity discharges nothing under the DSG, whose duties attach to any processing that has an effect in Switzerland, wherever it is carried out, regardless of what a CE marking attests. US privacy teams have lived this pattern in the GDPR and DSG pairing, two regimes that resemble each other without substituting for each other; the AI version repeats it with less symmetry, because one side is finished law and the other is a draft not yet published. Which group entity is the AI Act provider for the EU market while a Swiss affiliate carries DSG duties for the same system, whether the intercompany agreements allocate those roles at all, and what happens to the allocation when the Swiss implementing legislation arrives, are questions the two regimes pose without answering.

4. What This Means for AI in Swiss Digital Health and MedTech

Digital health is where the divergence bites hardest, because a second regulatory layer already sits on both sides. For the EU market, an AI-enabled medical device runs through the MDR; where that device is required to undergo third-party conformity assessment, the AI system is also a high-risk AI system under Art. 6(1) and Annex I AI Act and must in time satisfy the AI Act's requirements inside the MDR conformity assessment itself, an interplay the MDCG and the European AI Board began to address in a joint FAQ in June 2025,7AI Act (n 5), Art. 6(1) and Annex I, Section A; Art. 43(3); MDCG and AI Board, 'Interplay between the MDR & IVDR and the AIA' (AIB 2025-1 / MDCG 2025-6, 19 June 2025). and one examined more closely in the regulatory convergence problem for AI-enabled medical devices. For the Swiss market, the MepV mirrors the MDR's substantive requirements, so the device layer is familiar; what Switzerland does not add is an AI Act layer on top of it.8Medizinprodukteverordnung (MepV) vom 1. Juli 2020 (SR 812.213). The same algorithm, in the same clinical workflow, is high-risk AI in one market and simply a medical device in the other.

The asymmetry cuts in both directions. A Swiss digital-health company selling into the EU carries the heavier EU stack regardless of Swiss leanness at home, and carries it as a third-country manufacturer, as it has since the medical-devices chapter of the Swiss-EU mutual recognition agreement stopped delivering mutual recognition in May 2021. A US company entering through Switzerland cannot read AI Act readiness out of a Swiss market entry: nothing in the MepV route tests the AI-specific requirements the same product will face in the EU, where the Annex I product obligations were scheduled for 2 August 2027 and stand to move to 2 August 2028 under the amendment pending as of publication. Nor is the Swiss side static. Health data are besonders schützenswerte Personendaten under Art. 5 lit. c DSG, Art. 21 DSG reaches automated individual decisions in clinical and reimbursement settings, and healthcare is among the sectors the Federal Council named for continued sector-specific work. Whether the end-2026 draft leaves medical AI to the MepV's device logic or layers transparency and oversight duties of its own over it is precisely the kind of question the sectoral approach makes unanswerable in advance.

5. Strategic Considerations

The divergence will not resolve into convergence on any timeline a product roadmap can use; the strategic question is which side of it a company has quietly bet on without documenting the bet. A group that built its European AI governance around the AI Act's categories has imported assumptions Swiss law does not make, and whether those assumptions overshoot, undershoot, or mislabel the Swiss duties depends on data flows, sector, and counterparties no framework mapping settles in the abstract. A group that deferred Swiss analysis because Switzerland has no AI act holds the opposite exposure, and the EDÖB's position on the DSG's direct applicability has made that a present-tense problem since November 2023, not a matter for 2027. Between the two sits timing. The AI Act's calendar stands to move for the first time; the Swiss calendar consists, so far, of a single drafting deadline; and the contracts being signed in 2026, data-processing agreements, distribution terms, intercompany AI-service arrangements, will still be running when the Swiss implementing legislation arrives with content no counterparty can yet read. Whether those contracts allocate the risk of a regime that does not exist yet, who bears the cost of retrofitting governance built for one architecture onto the other, and at what point deferring the Swiss analysis stops being defensible to a board, an auditor, or an insurer, are questions that turn on facts each company alone possesses. These questions require analysis tailored to specific products, data flows, and market sequence.

REFERENCES

01
Schweizerischer Bundesrat, 'KI-Regulierung: Bundesrat will Konvention des Europarats ratifizieren' (Medienmitteilung, 12. Februar 2025); Bundesamt für Kommunikation (BAKOM), 'Auslegeordnung zur Regulierung von künstlicher Intelligenz' (Bericht an den Bundesrat, 12. Februar 2025). The consultation draft on transparency, data protection, non-discrimination, and oversight and the plan of legally non-binding measures are both due by the end of 2026.
02
Bundesgesetz über den Datenschutz (Datenschutzgesetz, DSG) vom 25. September 2020 (SR 235.1), in force 1 September 2023, Art. 3(1) (the Act applies to circumstances that have an effect in Switzerland, even if they were initiated abroad), Art. 21 (information duty where a decision rests exclusively on automated processing and either carries a legal consequence for the person concerned or significantly affects that person; that person may on request state a position, and may request review by a natural person, Art. 21(2); Art. 21(1) and (2) do not apply where the decision is directly connected with the conclusion or performance of a contract between the controller and the person concerned and that person's request is granted, or where that person has expressly consented to the decision being taken automatically, Art. 21(3)), Art. 60-63 (criminal fines of up to CHF 250,000 for intentional violations, addressed to responsible natural persons); EDÖB, 'Geltendes Datenschutzgesetz ist auf KI direkt anwendbar' (Mitteilung, 9. November 2023).
03
FINMA, 'Governance und Risikomanagement beim Einsatz Künstlicher Intelligenz' (Aufsichtsmitteilung 08/2024, 18. Dezember 2024); Verordnung über das automatisierte Fahren (VAF) vom 13. Dezember 2024 (SR 741.59), in force 1 March 2025 (conditionally automated driving on motorways, automated parking in approved facilities, and driverless vehicles on routes approved by the cantons, under operator supervision).
04
Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (adopted 17 May 2024, opened for signature 5 September 2024) CETS No 225, signed by Switzerland on 27 March 2025; Art. 3(1)(a)-(b) (scope: activities of public authorities and of private actors acting on their behalf; for other private actors, each party addresses risks and impacts and specifies in a declaration whether it applies the convention's principles and obligations or takes other appropriate measures), Art. 8 (transparency and oversight), Art. 14 (remedies), Art. 16 (risk and impact management framework), Art. 30(3) (entry into force on the first day of the month following three months after five ratifications, including three Council of Europe member states). Norway lodged a declaration at signature. The European Union deposited its instrument of approval on 15 May 2026; the convention had not entered into force as of publication.
05
Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (AI Act) [2024] OJ L 2024/1689, Art. 2(1)(a) and (c) (application to providers irrespective of establishment and to providers and deployers in third countries where the output produced by the AI system is used in the Union), Art. 5 (prohibited practices), Art. 6 with Annexes I and III (high-risk classification), Art. 43 (conformity assessment), Art. 99(3)-(4) (administrative fines of up to EUR 35 million or, if the offender is an undertaking, up to 7% of its total worldwide annual turnover for the preceding financial year, whichever is higher, for the prohibited practices, and up to EUR 15 million or, on the same basis, 3%, whichever is higher, for non-compliance with the operator and transparency obligations listed in Art. 99(4)), Art. 99(6) (for SMEs, including start-ups, whichever of the percentage or the amount is lower), Art. 113 (application from 2 August 2026, with the prohibitions applying from 2 February 2025 and the general-purpose AI obligations from 2 August 2025).
06
European Commission, 'Proposal for a Regulation amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)' COM(2025) 836 final (19 November 2025); provisional inter-institutional agreement of 7 May 2026; approved by the European Parliament on 16 June 2026, deferring the application of the Annex III stand-alone high-risk obligations to 2 December 2027 and of the Annex I product obligations to 2 August 2028 while leaving the timetable for general-purpose AI models unchanged. The amending regulation had not been formally adopted or published in the Official Journal as of publication.
07
AI Act (n 5), Art. 6(1) (an AI system is high-risk where it is a product, or a safety component of a product, covered by the Union harmonisation legislation listed in Annex I and the product is required to undergo third-party conformity assessment under that legislation) and Annex I, Section A (listing Regulation (EU) 2017/745 and Regulation (EU) 2017/746), Art. 43(3) (for products covered by Annex I, Section A, the conformity assessment follows the procedure of that sectoral legislation, with the AI Act's requirements assessed within it), Art. 113(c) (Art. 6(1) and the corresponding obligations apply from 2 August 2027); Medical Device Coordination Group and European Artificial Intelligence Board, 'Interplay between the Medical Devices Regulation (MDR) & In vitro Diagnostic Medical Devices Regulation (IVDR) and the Artificial Intelligence Act (AIA)' (AIB 2025-1 / MDCG 2025-6, 19 June 2025).
08
Medizinprodukteverordnung (MepV) vom 1. Juli 2020 (SR 812.213), mirroring for the Swiss market the substantive requirements of the MDR.

How the Swiss and EU AI regimes combine for a particular company depends on its products, its data flows, and the order in which its markets were entered; none of that is visible from either statute book alone.

Get in Touch