Why Swiss Organisations Should Care About EU AI Rules

The Brief: Switzerland is not in the EU, yet its companies sell there, process European data and compete for European contracts. This panel brought together a lawyer specialised in ethics, compliance and AI governance, a former head of parliamentary data and an open-technology advisor. They discussed what regulation means in practice, and why compliance can become an advantage rather than a burden.

Moderator: Christian de Neef

Large or Small, Few Are Ready

Christian de Neef opened with data from his AI maturity model. Small companies score well on skills and technology but poorly on strategy and governance. Large ones have more strategy but lag on skills and governance. Both perform poorly on regulatory compliance: less than a third of respondents say their use cases conform to the AI Act, which is already partly in force.

Why the EU Matters Here

Cecilia Garcia Podoley, a lawyer and Teaching Fellow at the Center for AI and Digital Policy, gave four reasons. The EU is Switzerland's main trading partner. The AI Act applies wherever an AI system's effects are felt, not where a company is based. European clients will ask for EU AI Act compliance in vendor due diligence. And Switzerland has a reputation to protect. "We cannot say we're good while ignoring the law." She recalled the GDPR precedent and noted that Switzerland has signed the Council of Europe AI convention which will potentially align Swiss law with its European counterparts. Most importantly, Swiss law already applies to AI through data protection, product liability and sector rules from FINMA or Swissmedic. "It's not a free-for-all."

Software Is Now Regulated

Tobie Langel, who advises technology companies, standards bodies and the European Commission, urged participants to understand the European project as a whole. The aim is to regulate software so it is fair, secure, understandable and transparent. AI is software, so the Cyber Resilience Act, GDPR and DORA may apply as much as the AI Act. "I think software is becoming regulated now, and we all have to accept this."

His advice: get data, development processes and security controls in order, rather than chasing line items. He told the story of a company that rebuilt its product to process data on users' devices. With no data leaving the device, its sales cycles became much shorter. On innovation, he holds both views at once. Regulation is essential to protect people from scams, but "you can't regulate what you don't control." Europe needs massive public and private investment in sovereign AI.

From Data to Workflows

Dr. Jacqueline Kucera, research fellow at IDHEAP and founder of SOTRAI, former Head of the Parliamentary Library and member of the Swiss AI strategy board, listed concrete first steps. Map where AI is used, classify each use by risk category, organise human oversight, and test automated workflows before they go live. Drawing on her experience leading the library's digital transformation, she warned that organising data means redesigning workflows, which in turn requires bringing people along through training and multidisciplinary teams.

Who Is Responsible?

Christian cited a project with a health insurer. Simple invoice processing turned out to reveal patients' conditions, which raised the risk level. The panel agreed that responsibility ultimately rests with people: executives and the board. "Many leaders and boards are not aware yet of their personal responsibilities."

On the voluntary superintelligence accord announced in Washington, Cecilia was blunt. With no penalties, no public audits and no enforcement, "this is a press release, it's not governance."

Strategic Implications

Map everything, including shadow AI. You cannot govern tools you do not know about.

Name an owner. AI governance falls between compliance, IT and legal unless someone is accountable.

Treat AI literacy as a requirement. It is an obligation under the AI Act, not a nice-to-have.

Make compliance an outcome. Build products around the intent of the law, and document what you already do well.

More on the panelists

Cecilia Garcia Podoley, Vice-Chair  Ethics and Compliance Switzerland
Dr. Jacqueline Kucera, IDHEAP
Tobie Langel, UnlockOpen
Christian de Neef, FastTrack Consulting, moderator