


AI did not enter most organizations through one big strategic decision. It arrived gradually: through vendor software, procurement choices, and features quietly added to the tools people already use every day. It’s now involved in decisions that directly affect people, such as approving a loan, flagging a transaction, or screening a CV. And when AI starts influencing decisions like these, someone needs to be able to explain how those decisions are made. Increasingly, regulators expect the same.
That is the role of governance. It gives organizations a way to show that AI risks are understood, responsibilities are clear, and decisions follow a defined process. The OECD AI Principles, the NIST AI Risk Management Framework, ISO/IEC 42001, and the EU AI Act all describe what that looks like, each in its own language. This article pulls that into six operational pillars you can actually use, and looks at what it all means for organizations in Switzerland.
Many AI governance frameworks are written for legal, regulatory, or technical audiences. The six pillars below translate those ideas into the decisions organizations need to make when AI systems are used in practice. None of them is just a principle on paper. Each one becomes a real decision somewhere in the organization.
Transparency is about trust. Not every AI system can be fully interpretable, especially complex models such as deep learning systems, so what matters is reaching a level of explainability that fits the risk and the context. You can get there through model documentation, decision logs, feature importance analysis, or post-hoc explanation methods. If you cannot explain the “why” to stakeholders, regulators, or the people affected by a decision, the risk is not under control.
Accountability means knowing who is responsible for a model’s performance, who defines the metrics used to evaluate it, and who has the authority to stop it if it starts producing unreliable results. Every AI tool in production needs an owner, the same way every other business-critical system does. Without clear ownership, the system is not truly managed. It becomes a liability.
Robustness and safety mean your AI system must remain reliable throughout its lifecycle, whether it is handling routine tasks, foreseeable edge cases, or even misuse. Take a fraud detection model as an example. If it receives invoices with incomplete or conflicting data, it should not simply carry on as if nothing is wrong. It should flag the issue, pause the decision, and escalate the case to a human reviewer.
Data is rarely neutral and it often reflects past decisions, including the flaws and biases behind them. A model trained on ten years of hiring decisions may repeat the same patterns, not because anyone asked it to discriminate, but because no one corrected the bias in the data. If you use AI for hiring, you need to check whether it’s quietly filtering out candidates by gender, age, or background.
Many AI systems run on personal data, and that brings obligations beyond cybersecurity. Privacy governance means deciding upfront what data the system can use, for how long, and with what safeguards, before you build it, not after something goes wrong. In Europe and Switzerland, this is reinforced by law: AI that processes personal data has to comply with data protection rules, and that compliance starts at the design stage, not at the audit stage.
AI automation still depends on human judgment. Kaiti Huang, AI Governance instructor at the Swiss Cyber Institute, puts it clearly: “Human oversight does not mean that a person must approve every AI output. It means identifying when human judgment is necessary, giving people enough information to challenge the system, and ensuring that they have the authority to pause or override it before harm occurs.”
In practice, that means oversight isn’t a final checkpoint bolted on at the end. It’s built into the workflow, so the right people have both the information and the authority they need before a decision becomes irreversible.
Governance becomes more difficult once AI moves from policy documents into real workflows. The six pillars should not sit in separate policy documents. In practice, they need to work together when real risks appear.
Imagine that your organization uses an AI system to assess small-business loan applications. An applicant receives a negative recommendation and contacts the organization for an explanation. In a weak governance setup, the employee may see only a “Denied” status and have no meaningful way to review or challenge the result. In a well-governed process, each governance pillar supports the response.
Transparency makes the recommendation understandable. The employee can review the main factors that influenced the AI’s output. In this case, the system relied heavily on a reported decline in cash flow.
During the review, the employee discovers that the underlying ledger file was incomplete. Robustness means that the system should not treat unreliable data as valid input. It should detect the data-quality issue, pause the automated process, and send the application for human review before a final decision is made.
Accountability ensures that a clearly designated person is responsible for reviewing the case and deciding what action should follow. The AI supports the assessment, but the authorized employee remains responsible for the final decision and for documenting how it was reached.
Later, ongoing monitoring shows that the model rejects applicants from one region at a higher rate than others. As part of the organization’s fairness and non-discrimination controls, the compliance and model teams investigate whether the difference is caused by poor-quality data, inappropriate variables, or unjustified bias. Where necessary, they correct the data, adjust the system, and strengthen monitoring.
The outcome is not an automatic loan approval. It is a fair reassessment based on reliable information, meaningful human oversight, and clear responsibility. The organization also uses what it learned to improve the system and reduce the risk of similar problems in the future.
Good governance does more than prevent mistakes. It helps the organization learn from them. But internal discipline only goes so far. When a client or regulator asks how you manage AI risk, “we have good habits” is not enough.
In practice, auditors, clients, and business partners are likely to look at four main frameworks. The OECD AI Principles set the shared language and strategic thinking for trustworthy AI. The NIST AI Risk Management Framework turns that vocabulary into an operational process. The EU AI Act turns it into binding law. ISO/IEC 42001 gives you a management system to certify it. Together, they’re the baseline for AI governance today.
The OECD AI Principles came out in 2019 and got an update in 2024 to keep up with generative AI and the rules built around it. They were the first intergovernmental standard for trustworthy AI, and today 47 jurisdictions have signed on, including the EU. They’re non-binding, so each government adapts them to its own legal system, but their fingerprints are all over hard law: the EU AI Act, U.S. executive frameworks on AI, and national strategies across many countries have drawn from the same foundational vocabulary.
These principles are best understood as a strategic compass. They give governments and organizations a shared language for discussing trustworthy AI, including transparency, accountability, robustness, fairness, and respect for human rights. They do not prescribe detailed controls or tell organizations exactly how to implement AI governance. Instead, they help leaders align AI strategies, policies, and investment decisions with internationally recognized expectations. This shared language also makes it easier to communicate with regulators, business partners, and other stakeholders, and to connect high-level commitments with more operational frameworks such as the NIST AI RMF and ISO/IEC 42001.
If the OECD principles act as your North Star, the NIST AI Risk Management Framework is your map. Developed by the U.S. National Institute of Standards and Technology, it is widely adopted across both public and private sectors globally. It provides the operational process you need to work responsibly with AI.
The framework organizes governance work into four functions: Govern, Map, Measure, and Manage. All these functions are concurrent disciplines that together create a continuous risk management cycle.
Govern means building the culture, policies, and accountability structures that make safe AI possible. It means defining who has the authority to sign off on a new model, and who owns it once it’s live. Map means identifying the context in which a specific system operates: its intended use, the people it affects, and where potential risks concentrate. Measure means ongoing evaluation: testing for bias, security vulnerabilities, and performance degradation over time. Manage closes the loop; acting on what measurement surfaces, patching what you find, and preparing your team to respond when something goes wrong.
The value of the NIST AI RMF is that it doesn’t tell you exactly what to do. It teaches you the questions to keep asking. For teams starting their governance journey, that structure is worth more than any checklist.
The EU AI Act (Regulation 2024/1689) is the world’s first comprehensive, legally binding AI framework. It’s complex, but its goal is simple: to ensure AI systems are safe and transparent. It entered into force in August 2024 and is rolling out in phases.
The Act’s prohibition rules became applicable on 2 February 2025. The ban on unacceptable-risk systems already applies, since 2 February 2025. On 16 June 2026, the European Parliament approved further amendments extending those prohibitions to AI systems that generate child sexual abuse material or create images, videos, and audio without consent, applying to both providers and users, with a compliance deadline of December 2026.
The next major deadline is 2 August 2026, when Article 50 kicks in: providers of chatbots and generative AI systems will need to disclose that someone’s talking to AI and mark synthetic content as such. Generative AI systems already on the market before that date get a three-month grace period on the machine-readable watermarking requirement, pushing their deadline to 2 December 2026.
Further out, the timeline gets less settled. Under the provisional political agreement on the Digital Omnibus on AI reached on 7 May 2026, stand-alone high-risk systems under Annex III (things like recruitment, credit scoring, law enforcement, and critical infrastructure) would need to comply by 2 December 2027. High-risk AI embedded in regulated products under Annex I would follow by 2 August 2028. Both dates still need formal adoption and publication in the Official Journal, so treat them as likely, not locked in.
The Act’s jurisdictional scope is defined by where systems are deployed and who they affect. This reach is further amplified by the ‘Brussels Effect’ — the tendency of EU regulation to become a de facto global standard as international companies align to a single compliance baseline — which ensures the Act matters well beyond EU borders . The Act can also apply to organizations outside the EU, including where they place an AI system on the EU market, put it into service in the EU, or where the output produced by the system is used in the EU.
The Act classifies AI systems into four risk tiers:
| Risk tier | Examples | Key obligation |
| Unacceptable | Social scoring, biometric ID in public spaces, systems exploiting psychological vulnerabilities | Banned outright unless falls into exceptions |
| High | Recruitment screening, credit scoring, medical devices, critical infrastructure | Risk management, data governance, technical documentation, human oversight, accuracy and robustness, and registration |
| Limited | Chatbots, AI-generated content, deepfakes | Disclose AI interaction to users; mark AI-generated content in machine-readable format |
| Minimal | Spam filters, recommendation engines, AI writing tools | AI literacy and transparency |
Mapping your AI inventory to these tiers is a practical first step. It tells you where your obligations are concentrated and where your governance effort should be focused. But the tiers are only part of the picture. As Kaiti Huang, AI Governance instructor at the Swiss Cyber Institute, puts it: “Companies should not approach the AI Act only through the lens of fines. The more serious risk is using a system that no one can explain, challenge, or stop when it affects people. Good governance supports legal compliance, responsible decision-making, and trust at the same time.”
ISO/IEC 42001, published in December 2023, is the first international management system standard specifically designed for AI.
It is often described in the industry as the “ISO 27001 for AI”; a useful shorthand, since the structure will be familiar to anyone who has worked with information security management systems.
Unlike the EU AI Act, this one’s voluntary, and it’s about proof. It gives you a formal structure, an AI Management System, for documenting, managing, and improving how you handle AI over time. You can get third-party certified against it, which leaves you with an audited, repeatable record of how AI is governed inside your organization.
That certification matters more than it used to in B2B contexts. Procurement teams and enterprise clients are asking sharper questions about AI governance these days, and “trust us” doesn’t cut it anymore. ISO/IEC 42001 doesn’t replace regulatory compliance, but it backs it up by showing that your governance is a structured process, not just good intentions.
Switzerland isn’t an EU member state and doesn’t have a standalone AI law. However, that doesn’t mean Swiss organizations operate in a governance vacuum.
For organizations supervised by FINMA, Guidance 08/2024 describes supervisory observations and good practices concerning AI governance and risk management. It highlights areas such as clear responsibilities, model and data quality, explainability, independent review, monitoring, and the management of third-party risks.
On the international treaty front, Switzerland signed the Council of Europe’s Framework Convention on Artificial Intelligence on 27 March 2025. This is the first legally binding international treaty on AI, focused on human rights, democracy, and the rule of law. Signing is the first step; full ratification requires parliamentary approval and legislative amendments, with a consultation draft expected by the end of 2026.
The EU AI Act adds a further layer. Swiss companies placing AI systems on the EU market, or whose systems make decisions affecting people in the EU, fall within its scope. That includes many Swiss firms in finance, healthcare, and technology.
Understanding these frameworks is just the beginning. The organizations that handle AI governance well are the ones that treat it as an ongoing discipline, not as a project to complete before a deadline or a policy to file and forget.
A 2026 report from the UNESCO–Thomson Reuters Foundation AI Company Data Initiative, based on 2025 data from nearly 3,000 companies, found that 44% reported having an AI strategy. However, only 10% publicly committed to following a named AI governance framework, only 13% had a formal policy for human oversight, and 76% showed no evidence of policies for assessing the quality of AI training data.
The gap the report identifies is no longer one of awareness. Most organizations have heard of the EU AI Act, the NIST AI RMF, or the OECD AI Principles. The problem is the distance between knowing a framework exists and being able to use it — mapping AI systems, classifying risks, assigning ownership, documenting decisions, testing for bias, building escalation paths, and explaining outcomes to regulators, clients, and affected individuals.
That distance is where governance becomes a capability, not just a policy.
At the Swiss Cyber Institute, we close the gap between knowing a framework and being able to use one.
Governance is the capability that defines the next generation of industry leaders. We’re here to help you build it.
Disclaimer: This article is intended for general informational purposes and does not constitute legal advice. Regulatory timelines and requirements are subject to change; we recommend verifying current obligations with qualified legal or compliance counsel.
We share the most important news from the industry, technology, and the institute. Stay informed and stay ahead.