Switzerland - Generative AI Guidelines
Fact sheet on the use of generative AI tools in the Federal Administration
Switzerland
RAI-CH-NA-FSUGAXX-2024A practical guidance note (V1.2, 18 January 2024) issued by the Competence Network for Artificial Intelligence (CNAI) for employees of the Swiss Federal Administration on safe and compliant uses of internet-hosted generative AI tools. It encourages responsible experimentation while prohibiting the input of classified, confidential or personal data and requiring verification, documentation and adherence to existing IT and data protection rules.
Summary
Read full text ↗Plain English
Overview
The "Fact sheet on the use of generative AI tools in the Federal Administration" (V1.2, 18 January 2024) is a concise, operational guidance note published by the Competence Network for Artificial Intelligence (CNAI) to support federal employees considering or using internet-hosted generative AI services. It explains in plain language how these systems work (probabilistic next-token prediction engines trained on large corpora), illustrates common low-risk use cases (summaries of public reports, presentation design, code inspiration) and sets out clear dos and don’ts for day-to-day use. The fact sheet warns that training and storage typically occur outside Switzerland, that model outputs can be incorrect or biased, and that user prompts may be incorporated into further training. The document encourages responsible experimentation while emphasising that existing legal and IT obligations (data protection, information security, secrecy) continue to apply. The primary source and downloadable version are maintained by CNAI; see the published PDF for the authoritative text: Fact sheet V1.2 (18 Jan 2024) - CNAI (EN).
Definitions
The fact sheet sets working definitions for practical application. "Generative AI tools" are defined as internet-accessible systems that produce new content (text, images, audio, code, video or simulations) from prompts, typically via large-scale statistical models ("next-token prediction"). The document references the CNAI terminology repository for uniform definitions across the administration. Key operational terms include "personal data" (any information relating to identified or identifiable natural persons, per the Federal Act on Data Protection), "official or professional secrecy" (e.g. medical or tax secrecy), and "confidential/classified information" (internal, confidential, secret) which must never be shared with public AI tools. The fact sheet underscores the difference between permissible use of publicly available Open Government Data and prohibited sharing of sensitive internal or secret records.
Governance and Institutional Framework
The fact sheet is published under the CNAI (Competence Network for Artificial Intelligence), which operates within the Federal Statistical Office and coordinates AI-related expertise, resources and competence hubs across departments. It sits alongside the Federal Administration's seven AI guidelines and a code of practice for human-centric and trustworthy data science. The Federal Chancellery's Digital Transformation and ICT Steering (DTI) provides strategic direction for AI use in the administration; operational IT and cyber security responsibilities rest with the Federal Office of Information Technology, Systems and Telecommunication (FOITT). Data protection oversight and advice are provided by the Federal Data Protection and Information Commissioner (FDPIC) and the Federal Office of Justice (FOJ) is responsible for legal drafting on AI matters. The CNAI fact sheet explicitly cross-references these institutional actors and directs employees to consult IT security officers, data protection advisors or the CNAI competence hubs (legal, algorithms, data science) when in doubt. For institutional background and the CNAI repository of instruction sheets see CNAI Instruction Sheets and for Federal Chancellery strategy material see the FCh AI pages: Federal Chancellery – Artificial Intelligence.
Key Focus Areas
The fact sheet concentrates on immediate, practical safeguards that operational staff can apply. First, strict data minimisation and classification-aware behaviour: never paste classified, internal, contractually protected, professional-secret or personal data into public AI tools. Second, verification and accountability: employees remain accountable for decisions and must verify AI outputs against authoritative sources; AI outputs must not be used verbatim without validation. Third, transparency: where appropriate, staff should indicate that AI tools were used and document reliance on AI-generated content. Fourth, security and compliance: use of AI tools must respect existing IT, information security and password policies and comply with departmental guidance on blocked or restricted services. Fifth, intellectual property and reuse rights: users should consult service terms to avoid inadvertent copyright breaches when (re-)using generated content. Sixth, triage of use-cases by risk: low-risk uses (summarisation of public reports, layout help, brainstorming) are permitted with precautions; high-risk uses (automated individual decision-making with legal consequences, processing of sensitive personal data) are essentially disallowed unless covered by strict controls, legal basis and internal approvals. This risk-based approach mirrors the administration’s broader AI guidelines and the Federal Council’s direction to harmonise safety, transparency and human oversight across deployments.
Implementation Framework
The fact sheet is deliberately lightweight and pragmatic: it is not a stand-alone regulation but an operational interpretation of higher-level rules tailored to generative AI. Implementation relies on three pillars: (1) local ownership - each administrative unit must enforce existing IT, security and data protection rules and train staff; (2) central support - CNAI, DSCC (Data Science Competence Center) and FOITT provide technical support, competence hubs and internal services (e.g. RoBIT chatbot) to guide safe use; (3) process controls - units should develop local procedures for approvals, recordkeeping and escalation when contemplating higher-risk AI uses. The fact sheet instructs employees to use work email addresses for enrolment where professional sign-up is required, to choose strong passwords and to consult IT/data protection officers before processing sensitive cases. It also advises experimentation within sandboxed settings and reuse of open government data (OGD) where possible.
Monitoring and Evaluation
The fact sheet states it will be regularly reviewed as technology and use-cases evolve. Monitoring responsibilities are shared: CNAI curates experience and updates instruction sheets, FOITT and local IT security teams monitor technical compliance and potential security incidents, and FDPIC provides oversight on data protection matters. The Federal Audit Office (SFAO) and other evaluators may audit deployments and the Federal Chancellery tracks strategic implementation via the Digital Switzerland strategy and the AI sub-strategy for the Federal Administration. Units are expected to record notable AI experiments and lessons learned in CNAI’s project database to enable cross-government learning and to identify recurring risks or compliance issues.
Penalties, Liability, and Appeals
The fact sheet itself does not specify new penalties but reminds staff that existing legal regimes apply. Disclosing secret or classified information via an external AI service may contravene criminal provisions (e.g. Art. 320 Swiss Criminal Code on official secrecy) and give rise to criminal liability, administrative sanctions or disciplinary measures under employment rules. Data protection breaches may trigger FDPIC investigations, remedial orders and, where applicable under Swiss law, sanctions or administrative fines. Liability for harms caused by misuse of AI outputs remains with the responsible public official or office; units must therefore maintain documentation and be able to justify decisions. Appeals against administrative measures would follow ordinary administrative procedure channels; affected persons retain rights under the Federal Act on Data Protection (FADP) when personal data is processed and under administrative law when decisions are taken.
Relationship to Other Instruments
The fact sheet is intentionally aligned with and subordinate to higher-level instruments: the Federal Administration’s seven AI guidelines, the Human-Centric Code of Practice for Data Science and AI, sector-specific legal requirements (e.g. health law, financial supervisory rules), the Federal Act on Data Protection (FADP) and information security rules (ISG/ISV where applicable). It functions as an operational companion to those instruments rather than a replacement. For example, the FADP sets legal conditions for processing personal data while criminal provisions (official secrecy) remain binding regardless of the fact sheet’s permissive tone on experimentation. Readers are directed to consult the FOJ and FDPIC materials for legal interpretation where necessary.
International Alignment
The fact sheet is a domestic operational tool but the approach is consciously compatible with international norms and discussions. Switzerland’s strategy emphasizes alignment with OECD, Council of Europe and EU developments, and the Federal Administration monitors international regulatory trends (including the EU AI Act) to ensure interoperability and legal certainty. The fact sheet’s risk-based, human-centric emphasis mirrors common international principles (transparency, accountability, data protection) and supports eventual harmonised approaches to higher-risk categories where supranational rules may apply. CNAI and the Federal Chancellery coordinate with the FOJ and OFCOM on international law and cross-border data issues.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Fact sheet V1.2 published (CNAI) | 2024-01-18 | Operational guidance for federal employees; downloadable PDF on CNAI site. |
| Regular review and updates | Ongoing | Document flagged for periodic review to reflect technical/legal changes. |
| Federal Chancellery AI sub-strategy & implementation plan | 2024–2025 (implementation phase) | Broader governance measures, coordination and strategy development. |
Compliance Checklist
| Check | Required action |
|---|---|
| Am I entering personal or confidential data? | If yes: do not use the public generative AI tool; consult DPO/IT security. |
| Is the data public (OGD) or non-sensitive? | Permitted: ensure outputs are verified and documented. |
| Will the AI output inform a decision affecting rights? | Do not rely solely on automated processing; ensure human oversight and legal basis. |
| Have I checked service terms for reuse/copyright conditions? | Confirm permitted reuse and attribution; when in doubt consult legal hub. |
| Have I recorded prompts, outputs and validation steps? | Yes: keep evidence for accountability; No: document now before using output in official work. |
Sources and References
This Swiss guideline, effective January 18, 2024, offers practical advice for employees of the Federal Administration on how to use internet-hosted generative artificial intelligence tools safely and compliantly.
The guidance applies to all federal employees considering or using public AI services that generate new content like text, images, or code. It encourages responsible experimentation but sets clear boundaries to protect sensitive information and ensure accountability. The most critical rule is a strict prohibition: employees must never input classified, confidential, professional-secret, or personal data into public generative AI tools. This is because these tools often train on user prompts and store data outside Switzerland, posing significant security and privacy risks.
Employees are also reminded that they remain fully accountable for any decisions or work based on AI outputs. This means all AI-generated content must be thoroughly verified against authoritative sources and not used verbatim without validation. Where appropriate, staff should also be transparent about their use of AI and document how they relied on it. Furthermore, all existing IT security, information security, and data protection rules continue to apply when using these tools.
While the guideline itself doesn't introduce new penalties, it warns that existing laws are in force. Misusing AI to disclose secret information could lead to criminal charges under the Swiss Criminal Code, administrative sanctions, or disciplinary action. Breaches of data protection laws could trigger investigations and fines from the Federal Data Protection and Information Commissioner. A key practical pitfall is that AI outputs can be incorrect or biased, and user prompts might be incorporated into the AI's future training, making careful data handling and verification essential. The guideline will be regularly reviewed to adapt to evolving technology and use cases.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 13 marked completePlain-English obligations under Switzerland - Generative AI Guidelines. Not legal advice — verify against the official text before relying on it.
- #1CriticalKey Focus Areas⏰ Before using public generative AI tools
Applies to: Employees of the Swiss Federal Administration using public generative AI tools.
“never paste classified, internal, contractually protected, professional-secret or personal data into public AI tools.”
- #2CriticalKey Focus Areas⏰ Before using AI outputs in official work
Applies to: Employees of the Swiss Federal Administration using generative AI tools.
“employees remain accountable for decisions and must verify AI outputs against authoritative sources; AI outputs must not be used verbatim without validation.”
- #3CriticalKey Focus Areas⏰ Always
Applies to: Employees of the Swiss Federal Administration using generative AI tools.
“employees remain accountable for decisions and must verify AI outputs against authoritative sources”
- #4CriticalOverview⏰ Always
Applies to: Employees of the Swiss Federal Administration using generative AI tools.
“existing legal and IT obligations (data protection, information security, secrecy) continue to apply.”
- #5ImportantGovernance and Institutional Framework⏰ Before processing sensitive cases or when in doubt
Applies to: Employees of the Swiss Federal Administration using generative AI tools.
“directs employees to consult IT security officers, data protection advisors or the CNAI competence hubs (legal, algorithms, data science) when in doubt.”
- #6ImportantKey Focus Areas⏰ Before using AI outputs in official work
Applies to: Employees of the Swiss Federal Administration using generative AI tools.
“where appropriate, staff should indicate that AI tools were used and document reliance on AI-generated content.”
- #7ImportantKey Focus Areas⏰ Before publishing or sharing AI-generated content
Applies to: Employees of the Swiss Federal Administration using generative AI tools.
“where appropriate, staff should indicate that AI tools were used and document reliance on AI-generated content.”
- #8ImportantKey Focus Areas⏰ Before reusing AI-generated content
Applies to: Employees of the Swiss Federal Administration using generative AI tools.
“users should consult service terms to avoid inadvertent copyright breaches when (re-)using generated content.”
- #9ImportantKey Focus Areas⏰ Before using AI tools for a specific purpose
Applies to: Employees of the Swiss Federal Administration contemplating using generative AI tools.
“high-risk uses (...) are essentially disallowed unless covered by strict controls, legal basis and internal approvals.”
- #10RecommendedImplementation Framework⏰ When signing up for AI services
Applies to: Employees of the Swiss Federal Administration using generative AI tools.
“The fact sheet instructs employees to use work email addresses for enrolment where professional sign-up is required”
- #11RecommendedImplementation Framework⏰ When creating or updating passwords
Applies to: Employees of the Swiss Federal Administration using generative AI tools.
“to choose strong passwords and to consult IT/data protection officers before processing sensitive cases.”
- #12RecommendedImplementation Framework⏰ When experimenting with AI tools
Applies to: Employees of the Swiss Federal Administration experimenting with generative AI tools.
“It also advises experimentation within sandboxed settings and reuse of open government data (OGD) where possible.”
- #13RecommendedMonitoring and Evaluation⏰ Ongoing
Applies to: Administrative units of the Swiss Federal Administration.
“Units are expected to record notable AI experiments and lessons learned in CNAI’s project database to enable cross-government learning”
Related Regulations
Guidelines on Artificial Intelligence for the Federal Administration
Switzerland93% similar
Strategy: Use of AI systems in the Federal Administration
Switzerland93% similar
Guidance to civil servants on use of generative AI
United Kingdom92% similar
Federal Council decision to ratify the Council of Europe Convention on Artificial Intelligence
Switzerland91% similar
Overview of potential regulatory approaches for artificial intelligence (OFCOM report)
Switzerland91% similar
© Regulations.AI — created on 13-Jun-2026