A model associated with Switzerland, a service hosted in Switzerland and a legal research product are different things. Each can have a place in a legal workflow, and each needs its own evidence for confidentiality, accuracy and regulatory status.
Apertus, released on 2 September 2025 by EPFL, ETH Zurich and the Swiss National Supercomputing Centre (CSCS), is the clearest Swiss example. Its developers publish the model weights in 8 and 70 billion parameter sizes, together with training code and data documentation, under a permissive open-source licence. They state that it was developed with due consideration to Swiss data protection and copyright law and to EU AI Act transparency obligations, and that its training data respects machine-readable opt-outs. Those are statements about the model. Your deployment still needs its own assessment: which version, who hosts it, under which terms, and how it performs on your tasks.
The Swiss-Judgment-Prediction benchmark published by Niklaus and colleagues in 2021 covers German, French and Italian Federal Supreme Court decisions and examines differences across factors such as legal area and publication year. It tests a defined prediction task, not general legal advice or a current sovereign model. Swiss data and multilingual coverage still require task-specific evaluation.
Assess the complete service
Identify the model provider, the hosting operator, the contracting entity and any subprocessors. Check where prompts, documents, logs and backups are processed, who can access them, and whether the supplier can use them for training. Review current contractual terms and the actual deployment. A geographical brand or server location is only part of that assessment.
Hosting
Evidence to obtain: Data locations, access controls and subprocessor terms
What it does not establish: A national label does not establish confidentiality
Language and law
Evidence to obtain: Coverage, sources, currency and tested retrieval results
What it does not establish: Fluent output does not establish legal accuracy
Deployment
Evidence to obtain: Intended purpose, market, roles and system documentation
What it does not establish: A local installation does not establish regulatory exemption
Map privacy and professional requirements separately
Identify controller and processor roles, the purpose, relevant data and any international disclosure. Swiss data protection requirements and professional secrecy need their own assessment. Where the GDPR applies, consider lawful basis, sensitive data, processor terms, transfers and whether a data protection impact assessment is required. Keeping data in Switzerland answers only the location question.
Use the FDPIC’s guidance and the GDPR as starting sources. For an incident, the roles, risk thresholds and notification clocks differ; see the breach guidance.
Follow the Swiss regulatory path
Switzerland has no AI-specific statute yet, as the Federal Office of Justice (in German) notes. On 12 February 2025 the Federal Council decided that Switzerland should ratify the Council of Europe Convention on AI and amend Swiss law where needed: as sector-specific as possible, with cross-sector rules only in key areas relevant to fundamental rights such as data protection, and with non-binding measures alongside. Under that decision, the Convention is to apply primarily to state actors. Switzerland signed the Convention on 27 March 2025. The Federal Department of Justice and Police is to prepare a consultation draft by the end of 2026 covering in particular transparency, data protection, non-discrimination and supervision. In a statement of 20 May 2026 to Parliament (in German), the Federal Council said the draft was still being prepared; no consultation had opened when we checked on 26 September 2026. In the same statement it said that the draft should in principle also impose duties on private actors where fundamental rights have a direct or indirect horizontal effect, and that participants in a workshop with around 60 experts largely agreed that certain rules, in particular on transparency, should apply in both the public and the private sector.
In the meantime, the FDPIC points out that the Federal Act on Data Protection is technology-neutral and directly applicable to AI-supported processing, including transparency about purpose, functioning and data sources, and a data protection impact assessment in high-risk cases. Recheck this section when the consultation draft is published.
Check the AI Act’s territorial scope and intended purpose
A Swiss organisation becomes subject to AI Act duties through the connections in Article 2, not merely because it has an EU client. Examine placement on the EU market, putting into service in the Union and relevant use of output there, and establish provider, deployer, importer or distributor roles for the specific use.
Ordinary private legal research or contract assistance is not automatically Annex III high-risk. Annex III point 8 concerns the specified administration-of-justice and democratic-process uses. Other listed purposes, such as recruitment, may be relevant. Apply Article 6 and the actual intended purpose rather than classifying the whole firm or model as high-risk.
Apply provision-specific dates
The original Article 5 prohibitions and Article 4 on AI literacy apply from 2 February 2025; since 27 July 2026, Article 4 has had an amended wording that requires measures to support the development of AI literacy, without requiring providers or deployers to guarantee any specific level of AI literacy of any individual. Regulation (EU) 2026/1744, the Digital Omnibus on AI, added two prohibitions that apply from 2 December 2026: AI systems generating or manipulating realistic intimate material of an identifiable person without explicit consent, and child sexual abuse material (Article 5(1)(ba) and (bb), qualified by Article 5(1a) and (1b)). No transparency label makes such a practice lawful.
The rules for general-purpose AI models apply from 2 August 2025, subject to transition provisions. Article 50 transparency duties generally apply from 2 August 2026, with a transition until 2 December 2026 for Article 50(2) for generative systems placed on the market before 2 August 2026. The high-risk timetable, as amended by the same regulation, uses 2 December 2027 for the relevant Annex III duties and 2 August 2028 for the product-related duties. Existing-system transitions and role-specific exceptions still need to be checked for your use.
See the consolidated Act, particularly Articles 2, 4, 5, 6, 50, 111 and 113 and the Commission timetable.
Make a bounded deployment decision
Use approved test material, verify original legal sources, record material errors and assign a qualified reviewer. Keep the supplier assessment, data decision, intended purpose, permitted tasks and escalation path together. Review the service and workflow you will actually use; a model benchmark is one input to that review.
Key Takeaway
Evaluate the service, data flow and intended use. Swiss development or hosting is relevant evidence but does not by itself establish compliance or reliability. The Swiss rules are still being drafted, so record today’s basis and recheck it when the consultation opens.