Switzerland - Generative AI Guidelines

Fact sheet on the use of generative AI tools in the Federal Administration

Switzerland

RAI-CH-NA-FSUGAXX-2024
Effective: January 18, 2024
In Force(In Force)
GuidelineRisk ManagementData Protection and PrivacyAccountability and Documentation
Export PDF

A practical guidance note (V1.2, 18 January 2024) issued by the Competence Network for Artificial Intelligence (CNAI) for employees of the Swiss Federal Administration on safe and compliant uses of internet-hosted generative AI tools. It encourages responsible experimentation while prohibiting the input of classified, confidential or personal data and requiring verification, documentation and adherence to existing IT and data protection rules.

Overview

The "Fact sheet on the use of generative AI tools in the Federal Administration" (V1.2, 18 January 2024) is a concise, operational guidance note published by the Competence Network for Artificial Intelligence (CNAI) to support federal employees considering or using internet-hosted generative AI services. It explains in plain language how these systems work (probabilistic next-token prediction engines trained on large corpora), illustrates common low-risk use cases (summaries of public reports, presentation design, code inspiration) and sets out clear dos and don’ts for day-to-day use. The fact sheet warns that training and storage typically occur outside Switzerland, that model outputs can be incorrect or biased, and that user prompts may be incorporated into further training. The document encourages responsible experimentation while emphasising that existing legal and IT obligations (data protection, information security, secrecy) continue to apply. The primary source and downloadable version are maintained by CNAI; see the published PDF for the authoritative text: Fact sheet V1.2 (18 Jan 2024) - CNAI (EN).

Definitions

The fact sheet sets working definitions for practical application. "Generative AI tools" are defined as internet-accessible systems that produce new content (text, images, audio, code, video or simulations) from prompts, typically via large-scale statistical models ("next-token prediction"). The document references the CNAI terminology repository for uniform definitions across the administration. Key operational terms include "personal data" (any information relating to identified or identifiable natural persons, per the Federal Act on Data Protection), "official or professional secrecy" (e.g. medical or tax secrecy), and "confidential/classified information" (internal, confidential, secret) which must never be shared with public AI tools. The fact sheet underscores the difference between permissible use of publicly available Open Government Data and prohibited sharing of sensitive internal or secret records.

Governance and Institutional Framework

The fact sheet is published under the CNAI (Competence Network for Artificial Intelligence), which operates within the Federal Statistical Office and coordinates AI-related expertise, resources and competence hubs across departments. It sits alongside the Federal Administration's seven AI guidelines and a code of practice for human-centric and trustworthy data science. The Federal Chancellery's Digital Transformation and ICT Steering (DTI) provides strategic direction for AI use in the administration; operational IT and cyber security responsibilities rest with the Federal Office of Information Technology, Systems and Telecommunication (FOITT). Data protection oversight and advice are provided by the Federal Data Protection and Information Commissioner (FDPIC) and the Federal Office of Justice (FOJ) is responsible for legal drafting on AI matters. The CNAI fact sheet explicitly cross-references these institutional actors and directs employees to consult IT security officers, data protection advisors or the CNAI competence hubs (legal, algorithms, data science) when in doubt. For institutional background and the CNAI repository of instruction sheets see CNAI Instruction Sheets and for Federal Chancellery strategy material see the FCh AI pages: Federal Chancellery – Artificial Intelligence.

Key Focus Areas

The fact sheet concentrates on immediate, practical safeguards that operational staff can apply. First, strict data minimisation and classification-aware behaviour: never paste classified, internal, contractually protected, professional-secret or personal data into public AI tools. Second, verification and accountability: employees remain accountable for decisions and must verify AI outputs against authoritative sources; AI outputs must not be used verbatim without validation. Third, transparency: where appropriate, staff should indicate that AI tools were used and document reliance on AI-generated content. Fourth, security and compliance: use of AI tools must respect existing IT, information security and password policies and comply with departmental guidance on blocked or restricted services. Fifth, intellectual property and reuse rights: users should consult service terms to avoid inadvertent copyright breaches when (re-)using generated content. Sixth, triage of use-cases by risk: low-risk uses (summarisation of public reports, layout help, brainstorming) are permitted with precautions; high-risk uses (automated individual decision-making with legal consequences, processing of sensitive personal data) are essentially disallowed unless covered by strict controls, legal basis and internal approvals. This risk-based approach mirrors the administration’s broader AI guidelines and the Federal Council’s direction to harmonise safety, transparency and human oversight across deployments.

Implementation Framework

The fact sheet is deliberately lightweight and pragmatic: it is not a stand-alone regulation but an operational interpretation of higher-level rules tailored to generative AI. Implementation relies on three pillars: (1) local ownership - each administrative unit must enforce existing IT, security and data protection rules and train staff; (2) central support - CNAI, DSCC (Data Science Competence Center) and FOITT provide technical support, competence hubs and internal services (e.g. RoBIT chatbot) to guide safe use; (3) process controls - units should develop local procedures for approvals, recordkeeping and escalation when contemplating higher-risk AI uses. The fact sheet instructs employees to use work email addresses for enrolment where professional sign-up is required, to choose strong passwords and to consult IT/data protection officers before processing sensitive cases. It also advises experimentation within sandboxed settings and reuse of open government data (OGD) where possible.

Monitoring and Evaluation

The fact sheet states it will be regularly reviewed as technology and use-cases evolve. Monitoring responsibilities are shared: CNAI curates experience and updates instruction sheets, FOITT and local IT security teams monitor technical compliance and potential security incidents, and FDPIC provides oversight on data protection matters. The Federal Audit Office (SFAO) and other evaluators may audit deployments and the Federal Chancellery tracks strategic implementation via the Digital Switzerland strategy and the AI sub-strategy for the Federal Administration. Units are expected to record notable AI experiments and lessons learned in CNAI’s project database to enable cross-government learning and to identify recurring risks or compliance issues.

Penalties, Liability, and Appeals

The fact sheet itself does not specify new penalties but reminds staff that existing legal regimes apply. Disclosing secret or classified information via an external AI service may contravene criminal provisions (e.g. Art. 320 Swiss Criminal Code on official secrecy) and give rise to criminal liability, administrative sanctions or disciplinary measures under employment rules. Data protection breaches may trigger FDPIC investigations, remedial orders and, where applicable under Swiss law, sanctions or administrative fines. Liability for harms caused by misuse of AI outputs remains with the responsible public official or office; units must therefore maintain documentation and be able to justify decisions. Appeals against administrative measures would follow ordinary administrative procedure channels; affected persons retain rights under the Federal Act on Data Protection (FADP) when personal data is processed and under administrative law when decisions are taken.

Relationship to Other Instruments

The fact sheet is intentionally aligned with and subordinate to higher-level instruments: the Federal Administration’s seven AI guidelines, the Human-Centric Code of Practice for Data Science and AI, sector-specific legal requirements (e.g. health law, financial supervisory rules), the Federal Act on Data Protection (FADP) and information security rules (ISG/ISV where applicable). It functions as an operational companion to those instruments rather than a replacement. For example, the FADP sets legal conditions for processing personal data while criminal provisions (official secrecy) remain binding regardless of the fact sheet’s permissive tone on experimentation. Readers are directed to consult the FOJ and FDPIC materials for legal interpretation where necessary.

International Alignment

The fact sheet is a domestic operational tool but the approach is consciously compatible with international norms and discussions. Switzerland’s strategy emphasizes alignment with OECD, Council of Europe and EU developments, and the Federal Administration monitors international regulatory trends (including the EU AI Act) to ensure interoperability and legal certainty. The fact sheet’s risk-based, human-centric emphasis mirrors common international principles (transparency, accountability, data protection) and supports eventual harmonised approaches to higher-risk categories where supranational rules may apply. CNAI and the Federal Chancellery coordinate with the FOJ and OFCOM on international law and cross-border data issues.

Implementation Timeline

MilestoneDateNotes
Fact sheet V1.2 published (CNAI)2024-01-18Operational guidance for federal employees; downloadable PDF on CNAI site.
Regular review and updatesOngoingDocument flagged for periodic review to reflect technical/legal changes.
Federal Chancellery AI sub-strategy & implementation plan2024–2025 (implementation phase)Broader governance measures, coordination and strategy development.

Compliance Checklist

CheckRequired action
Am I entering personal or confidential data?If yes: do not use the public generative AI tool; consult DPO/IT security.
Is the data public (OGD) or non-sensitive?Permitted: ensure outputs are verified and documented.
Will the AI output inform a decision affecting rights?Do not rely solely on automated processing; ensure human oversight and legal basis.
Have I checked service terms for reuse/copyright conditions?Confirm permitted reuse and attribution; when in doubt consult legal hub.
Have I recorded prompts, outputs and validation steps?Yes: keep evidence for accountability; No: document now before using output in official work.

Sources and References

SourceType
Fact sheet on the use of generative AI tools in the Federal Administration, V1.2 (18 Jan 2024) - CNAI (EN)Primary Source
Instruction sheets for the use of AI within the Federal Administration - CNAIPrimary Source
Federal Chancellery - Artificial Intelligence in the Federal AdministrationPrimary Source
Plain English

This Swiss guideline, effective January 18, 2024, offers practical advice for employees of the Federal Administration on how to use internet-hosted generative artificial intelligence tools safely and compliantly.

The guidance applies to all federal employees considering or using public AI services that generate new content like text, images, or code. It encourages responsible experimentation but sets clear boundaries to protect sensitive information and ensure accountability. The most critical rule is a strict prohibition: employees must never input classified, confidential, professional-secret, or personal data into public generative AI tools. This is because these tools often train on user prompts and store data outside Switzerland, posing significant security and privacy risks.

Employees are also reminded that they remain fully accountable for any decisions or work based on AI outputs. This means all AI-generated content must be thoroughly verified against authoritative sources and not used verbatim without validation. Where appropriate, staff should also be transparent about their use of AI and document how they relied on it. Furthermore, all existing IT security, information security, and data protection rules continue to apply when using these tools.

While the guideline itself doesn't introduce new penalties, it warns that existing laws are in force. Misusing AI to disclose secret information could lead to criminal charges under the Swiss Criminal Code, administrative sanctions, or disciplinary action. Breaches of data protection laws could trigger investigations and fines from the Federal Data Protection and Information Commissioner. A key practical pitfall is that AI outputs can be incorrect or biased, and user prompts might be incorporated into the AI's future training, making careful data handling and verification essential. The guideline will be regularly reviewed to adapt to evolving technology and use cases.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 13 marked complete

Plain-English obligations under Switzerland - Generative AI Guidelines. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalKey Focus AreasBefore using public generative AI tools

    Applies to: Employees of the Swiss Federal Administration using public generative AI tools.

    never paste classified, internal, contractually protected, professional-secret or personal data into public AI tools.
  2. #2CriticalKey Focus AreasBefore using AI outputs in official work

    Applies to: Employees of the Swiss Federal Administration using generative AI tools.

    employees remain accountable for decisions and must verify AI outputs against authoritative sources; AI outputs must not be used verbatim without validation.
  3. #3CriticalKey Focus AreasAlways

    Applies to: Employees of the Swiss Federal Administration using generative AI tools.

    employees remain accountable for decisions and must verify AI outputs against authoritative sources
  4. #4CriticalOverviewAlways

    Applies to: Employees of the Swiss Federal Administration using generative AI tools.

    existing legal and IT obligations (data protection, information security, secrecy) continue to apply.
  5. #5ImportantGovernance and Institutional FrameworkBefore processing sensitive cases or when in doubt

    Applies to: Employees of the Swiss Federal Administration using generative AI tools.

    directs employees to consult IT security officers, data protection advisors or the CNAI competence hubs (legal, algorithms, data science) when in doubt.
  6. #6ImportantKey Focus AreasBefore using AI outputs in official work

    Applies to: Employees of the Swiss Federal Administration using generative AI tools.

    where appropriate, staff should indicate that AI tools were used and document reliance on AI-generated content.
  7. #7ImportantKey Focus AreasBefore publishing or sharing AI-generated content

    Applies to: Employees of the Swiss Federal Administration using generative AI tools.

    where appropriate, staff should indicate that AI tools were used and document reliance on AI-generated content.
  8. #8ImportantKey Focus AreasBefore reusing AI-generated content

    Applies to: Employees of the Swiss Federal Administration using generative AI tools.

    users should consult service terms to avoid inadvertent copyright breaches when (re-)using generated content.
  9. #9ImportantKey Focus AreasBefore using AI tools for a specific purpose

    Applies to: Employees of the Swiss Federal Administration contemplating using generative AI tools.

    high-risk uses (...) are essentially disallowed unless covered by strict controls, legal basis and internal approvals.
  10. #10RecommendedImplementation FrameworkWhen signing up for AI services

    Applies to: Employees of the Swiss Federal Administration using generative AI tools.

    The fact sheet instructs employees to use work email addresses for enrolment where professional sign-up is required
  11. #11RecommendedImplementation FrameworkWhen creating or updating passwords

    Applies to: Employees of the Swiss Federal Administration using generative AI tools.

    to choose strong passwords and to consult IT/data protection officers before processing sensitive cases.
  12. #12RecommendedImplementation FrameworkWhen experimenting with AI tools

    Applies to: Employees of the Swiss Federal Administration experimenting with generative AI tools.

    It also advises experimentation within sandboxed settings and reuse of open government data (OGD) where possible.
  13. #13RecommendedMonitoring and EvaluationOngoing

    Applies to: Administrative units of the Swiss Federal Administration.

    Units are expected to record notable AI experiments and lessons learned in CNAI’s project database to enable cross-government learning

© Regulations.AI — created on 13-Jun-2026