
Clear expectations from FINMA and planned Swiss legislation
Specific AI legislation, such as the EU AI Act already in place in the EU, does not yet exist in Switzerland but is on the horizon: A draft bill on AI regulation is expected to be submitted for consultation by the end of 2026. In particular, it is intended to specify the legal measures for implementing the Council of Europe’s AI Convention, which Switzerland has signed.
However, Swiss financial institutions should not sit back and wait until the Swiss draft is available: FINMA communicated its expectations for supervised entities using AI early on and is continually refining them. In addition, financial institutions providing cross-border services to EU customers could fall within the scope of the EU AI Act. Finally, provisions of sector-specific legislation, such as data protection laws, also apply to the use of AI.
Action is needed even before AI is deployed in core processes
Regardless of future specific legislation, regulated financial institutions are already required today to systematically identify and analyze the risks associated with the use of AI and to implement appropriate measures. The more closely AI is integrated into decision-making processes, the less adequate purely informal oversight becomes. The specific risks depend heavily on the circumstances of each case. Depending on the AI provider, the selected licence, the settings, and—in particular—the scope of application, the following risks (among others; this list is not exhaustive) must be considered when using AI:
- Governance and organizational risks, such as when responsibilities are unclear or control and escalation mechanisms are lacking.
- Data protection risks associated with the transfer of personal data to third parties.
- Confidentiality risks, specifically the risk that employees may breach confidentiality obligations or disclose trade secrets through the improper use of AI tools.
- Outsourcing and third-party risks associated with the use of external AI solutions, such as cloud-based models, which require more robust contractual arrangements and monitoring. Furthermore, dependencies on AI service providers may arise.
- Operational risks, such as the security, reliability, and traceability of results.
- Reputational and liability risks: AI decisions that lack transparency or are perceived as unfair can permanently undermine the trust of customers and the public.
The risks mentioned may also exist even if AI is not used in core processes or in customer interactions, but is used only as a support tool—for example, for research or analysis. In practice, AI tools from external providers are also frequently used. In such cases, the supervised institution is required to ensure compliance with the requirements for outsourcing, including requirements relating to service outages.
Conclusion: “AI Health Check”
Institutions that analyze their use of AI early on and manage it pragmatically not only ensure regulatory compliance but also strengthen the trust of business partners, auditors, supervisory authorities, customers, and employees. In our AI Health Check, we conduct a structured assessment with you in a facilitated workshop format.
We provide you with an overview of the status of your AI governance, identify regulatory and operational areas for action, and highlight which measures are a priority for your institution. The result is a set of concrete recommendations and a clear implementation plan for the legally compliant and controlled use of AI.
Our specialists from the Regulatory & Compliance FS team would be happy to assist you.