top of page
luzern schweiz

COMPLIANCE SWITZERLAND

Enforced at runtime.

Switzerland regulates AI through a fast-moving patchwork: state AI acts, federal enforcement and sector rules. What is compliant in one state may be a violation in another. EVEDY enforces the applicable rules per jurisdiction – at runtime.

CLEAR CONTROL. SECURE REGULATIONS.

The regulatory framework for AI in Switzerland

Not a single "AI law," but rather an interplay of existing and future regulations—with direct obligations for companies starting today. This is an incomplete excerpt from the current declaration of conformity.

Regulation

What it requires

How Evedy enforces it

revDSG

Revised Data Protection Act, in force since 09/2023

Transparency, data security, privacy by design, special obligations for automated individual decisions and profiling.

Automatic PII redaction in prompts and responses, access control via your IAM, labeling of automated decisions, and full logging.

Council of Europe AI Convention

Ratification decided by the Federal Council; sectoral implementation in preparation

Protection of human rights, democracy and the rule of law in the use of AI; transparency, oversight and accountability duties.

Policy enforcement per use case, human-oversight escalation, tamper-evident audit trails per regulation.

FINMA expectations

Including Guidance 08/2024 for financial institutions

Governance and risk management for AI use: clear accountability, inventories, control of robustness and explainability.

A central control plane across all models and agents, testing and evaluation of every version, continuous monitoring of non-deterministic behaviour.

EU AI Act

Relevant when operating in the EU market (extraterritorial effect)

Risk-based duties up to strict requirements for high-risk systems: logging, transparency, human oversight, robustness.

End-to-end logging of every interaction, policies per risk class, evidence documentation for conformity assessments.

ISO/IEC 42001 & internal policies

AI management standard and your own directives

A systematic AI management system: roles, processes, continuous improvement – plus your enterprise AI policies.

Enterprise policies are stored as machine-enforceable rules and applied automatically to every AI interaction – not just documented.

As of August 2026. This overview does not constitute legal advice.

THE DIFFERENCE

From written policy to runtime enforcement

Most enterprises have AI policies. Very few can prove they are followed. EVEDY closes exactly that gap.

1

Capture the rules

Legal requirements and internal policies are modelled as machine-readable policies – synchronised from your GRC platform if you wish.

2

Enforce at runtime

Every request to a model or agent passes through EVEDY. Violations are blocked, corrected or escalated – in real time, not after the fact.

3

Prove compliance

Audit trails per user, per agent and per regulation give internal audit, the board and regulators defensible evidence at any time.

bottom of page