Articles in this section
-
AI governance in Switzerland
AI governance guidance for companies operating in Switzerland, written for English-speaking group finance, compliance and engineering teams. -
AI-agent traceability in Switzerland: the obligation nobody wrote down, and the fields it still leaves you with
No Swiss statute expressly requires AI-agent logging. The duty is derived from the art. 21 revFADP right to human review, which presupposes reconstruction. -
Automated individual decisions under Art. 21 of the revised Swiss FADP: which entities are caught and what has to be provable
Art. 21 of the revised Swiss FADP does not ban automated decisions: it requires notice, the data subject's view on request, and review by a person. -
Swiss cyber-incident reporting: the 24-hour clock, who it binds, and why it is not a data-protection deadline
Switzerland's 24-hour cyber report is an ISA duty owed to the NCSC by critical-infrastructure operators. Swiss law contains no 72-hour breach deadline. -
FINMA Guidance 08/2024 on artificial intelligence: what it is, which instruments actually bind, and what a supervised institution has to implement
FINMA Guidance 08/2024 of 18 December 2024 sets seven expectation areas for AI. It is a supervisory communication, not a circular; 2023/1 and 2018/3 bind. -
The data protection impact assessment under Art. 22 of the revised Swiss FADP: when AI triggers it, who owes it, and what belongs in it
Art. 22 of the revised Swiss FADP names the use of new technologies as a high-risk factor, so every substantial AI deployment needs a documented triage.
In practice
Permission before the action. Evidence after it.
The duties on this page attach to the moment an automated system acts: who permitted it, on which data, under which policy version, and what a person saw before approving. Barzel enforces that decision before execution and writes the record an auditor, a regulator or a data subject can be shown.
In force24-hour reporting duty to the NCSC in force since 1 April 2025; fines since 1 October 2025
BarzelVault
The AI action firewall: decide what an agent may do before it does it.
- Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
- Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
- Credential isolation, spend and action limits, and an emergency kill switch.
Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize
Barzel Central Gateway
The AI governance control plane: one inventory and one policy layer across every MCP server and agent.
- Registers and synchronises every tool; enforces identity, policy, region, cost and health per tool.
- Identity mapping through OIDC, Entra ID, Okta, SAML and SPIFFE, with credential brokerage.
- Trace and SIEM export (W3C trace context, OTLP) for the security team and the regulator.
Free tier: 1,000 calls a monthPaid plans from $10 a monthLive on MCPize
Enterprise: written quote by email within two business days. No sales call.
Markets in English
In local languages
- Polska
- Deutschland
- France
- Schweiz / Suisse
- United Kingdom
- United States
- Danmark
- Belgique / België
- Norge
- Slovensko
- Eesti
- Kenya