Kaum ein Thema erzeugt bei Geschäftsleitungen derzeit mehr Unsicherheit als die Frage, welche KI-Regeln eigentlich gelten. Die kurze Antwort für die Schweiz: Ein eigenes KI-Gesetz gibt es nicht und ist so auch nicht geplant – aber untätig bleiben ist trotzdem die falsche Strategie.
Der Schweizer Weg: Konvention statt KI-Gesetz
Der Bundesrat hat am 12. Februar 2025 den Grundsatzentscheid gefällt: Die Schweiz ratifiziert die KI-Konvention des Europarats (im März 2025 unterzeichnet) und passt das Recht dort an, wo es nötig ist – möglichst sektoriell statt mit einem grossen Querschnittsgesetz nach EU-Vorbild. Bis Ende 2026 erarbeitet der Bund eine Vernehmlassungsvorlage, namentlich zu Transparenz, Datenschutz, Nichtdiskriminierung und Aufsicht; parallel entsteht ein Plan für unverbindliche Massnahmen wie Leitlinien und Branchenlösungen. Konkrete neue Pflichten für Unternehmen entstehen damit frühestens in einigen Jahren.
Der EU AI Act wirkt trotzdem – ab August 2026 richtig
Die EU-KI-Verordnung ist seit August 2024 in Kraft und wird gestaffelt anwendbar: Verbote inakzeptabler Praktiken gelten seit Februar 2025, Pflichten für Anbieter von Basismodellen seit August 2025 – und ab dem 2. August 2026 greift der Grossteil der übrigen Bestimmungen. Entscheidend für hiesige Firmen: Der AI Act wirkt extraterritorial. Wer KI-Systeme in den EU-Markt bringt oder deren Ergebnisse in der EU verwendet werden, fällt darunter – Schweizer Sitz hin oder her. Exportorientierte KMU sollten ihre KI-Anwendungsfälle deshalb jetzt den Risikoklassen des AI Act zuordnen.
Was heute schon gilt
Wer auf «die Regulierung» wartet, übersieht: Das revDSG gilt jetzt – auch für jede KI-Anwendung, die Personendaten verarbeitet. Transparenz, Zweckbindung, Auskunftsrechte und die Regeln zu automatisierten Einzelentscheidungen sind auf ChatGPT-Nutzung im Betrieb genauso anwendbar wie auf klassische Software. Für Verwaltungen kommt das kantonale Datenschutzrecht dazu.
Drei No-Regret-Massnahmen
1. KI-Richtlinie erlassen: Welche Werkzeuge sind freigegeben, was gehört nie in einen Prompt (Personendaten, Geschäftsgeheimnisse), wie werden Ergebnisse geprüft. Das braucht jede Organisation – unabhängig von jeder künftigen Regulierung.
2. KI-Inventar führen: Wo ist KI im Einsatz, auch versteckt in bestehenden Produkten? Ohne Inventar lässt sich weder revDSG-Konformität noch eine spätere AI-Act-Einstufung beurteilen.
3. EU-Bezug klären: Werden Produkte oder KI-gestützte Dienstleistungen in die EU geliefert? Dann gehört die AI-Act-Zuordnung ins Risikomanagement – vor August 2026.
Fazit
Die Schweiz reguliert zurückhaltend und sektoriell – aber zwischen revDSG heute und AI Act ab 2026 ist der rechtsfreie Raum eine Illusion. Wer Richtlinie, Inventar und EU-Bezug jetzt klärt, ist für beide Welten vorbereitet.
Quellen
Hardly any topic currently creates more uncertainty among executive boards than the question of which AI rules actually apply. The short answer for Switzerland: there is no dedicated AI act and none is planned as such – but doing nothing is still the wrong strategy.
The Swiss way: convention instead of an AI act
On 12 February 2025 the Federal Council took the fundamental decision: Switzerland ratifies the Council of Europe's AI Convention (signed in March 2025) and adapts the law where necessary – as sector-specifically as possible instead of with a large cross-cutting act modelled on the EU. By the end of 2026 the federal government is preparing a consultation draft, notably on transparency, data protection, non-discrimination and supervision; in parallel, a plan for non-binding measures such as guidelines and industry solutions is being developed. Concrete new obligations for companies will therefore arise in a few years at the earliest.
The EU AI Act still has an effect – fully from August 2026
The EU AI Regulation has been in force since August 2024 and becomes applicable in stages: bans on unacceptable practices have applied since February 2025, obligations for providers of foundation models since August 2025 – and from 2 August 2026 most of the remaining provisions kick in. Decisive for companies here: the AI Act has extraterritorial effect. Anyone who places AI systems on the EU market, or whose outputs are used in the EU, falls under it – Swiss headquarters or not. Export-oriented SMEs should therefore map their AI use cases to the AI Act's risk classes now.
What already applies today
Anyone waiting for "the regulation" overlooks this: the revised FADP applies now – including to every AI application that processes personal data. Transparency, purpose limitation, access rights and the rules on automated individual decisions apply to ChatGPT use in the workplace just as they do to classic software. For public administrations, cantonal data protection law applies in addition.
Three no-regret measures
1. Issue an AI policy: which tools are approved, what never belongs in a prompt (personal data, trade secrets), how results are verified. Every organisation needs this – independent of any future regulation.
2. Keep an AI inventory: where is AI in use, including hidden in existing products? Without an inventory, neither revFADP compliance nor a later AI Act classification can be assessed.
3. Clarify the EU connection: are products or AI-supported services delivered into the EU? Then the AI Act mapping belongs in your risk management – before August 2026.
Conclusion
Switzerland regulates cautiously and sector by sector – but between the revFADP today and the AI Act from 2026, the legal vacuum is an illusion. Anyone who clarifies policy, inventory and EU exposure now is prepared for both worlds.