Ask your team: most people already use ChatGPT, Copilot or similar tools – for emails, quotes, translations or Excel formulas. That is a good thing, because it saves time. It becomes a problem when nobody has defined what may be pasted into them. Experts call this “shadow AI”: tools used in the business without the company knowing.
A ban rarely helps. It simply moves usage to private devices. A short, clear AI policy works better.
The risk: company data in someone else’s hands
Whatever you enter into a public AI service leaves your company. Depending on the provider and plan, inputs may be stored, reviewed by humans or used for training. For customer data, contracts or personnel files that is sensitive – also from a data protection perspective. The Swiss Federal Data Protection Commissioner has made clear that the Data Protection Act also applies to AI applications. More in our article on the Swiss Data Protection Act.
The traffic light: which data goes into which AI?
A simple classification is enough for everyday use:
- Green – public information: texts for the website, general questions, wording help without names. Allowed in approved tools.
- Amber – internal information: internal processes, anonymised examples. Only in tools with a business contract that excludes training on your data.
- Red – confidential data: personal data of customers or employees, contracts, financial figures, passwords, source code. Only in an AI running on your premises or in Switzerland – see local AI for SMEs.
What belongs in the policy
An AI policy doesn’t need ten pages. One page with these points is enough:
- Approved tools: which AI services may be used – with a company account, not a private one?
- Data classes: the traffic light above, with examples from your daily work.
- Duty to check: AI can be convincingly wrong. Whoever uses a result checks it and takes responsibility.
- Disclosure: when must it be visible that a text or image was created with AI – for example towards customers?
- Copyright: don’t upload third-party texts, images or logos you have no rights to.
- Contact person: who answers questions and adds new tools to the list?
Choosing the right tools
- Business plans instead of free accounts: business versions from the major providers contractually exclude training on your data and offer central management.
- Manage accounts centrally: staff sign in with their company account, ideally with multi-factor authentication. When someone leaves, access is revoked.
- Local for confidential data: your own AI on your server or in a Swiss data centre solves the problem at the root.
Legal framework in Switzerland
Switzerland does not yet have a dedicated AI law. In 2025 the Federal Council decided to ratify the Council of Europe’s AI convention and to adapt existing laws selectively. Until then, the Data Protection Act and copyright law are the main rules. Companies offering products or services using AI in the EU should also keep the EU AI Act in mind.
Note: this article is not legal advice.
Conclusion
AI at work is a reality. With a short policy, approved tools and a local solution for confidential data, you get the benefits without losing control. We help with selection, setup and, if you wish, running your own AI – more under automation & AI.
Frequently asked questions
Should we simply ban ChatGPT at work?
Usually not. Bans push usage onto private devices and accounts where you have no control at all. Clear rules and approved tools work better.
Are my inputs used to train the AI?
It depends on the provider and plan. With many free accounts it is possible; business plans usually exclude it contractually. Check the terms or use a local AI for confidential data.
How long should an AI policy be?
One to two pages are enough. More important than length are understandable examples from your daily work and a person people can ask.
Does the Data Protection Act apply to AI?
Yes. When personal data is processed with AI, the same principles apply as for any other processing.



