The question comes up in almost every conversation with owners of French-speaking Swiss SMEs. One employee saves two hours a week having an artificial intelligence proofread their quotes. Another has it summarise meeting notes. Someone eventually asks: are we even allowed to do this?
The honest answer is neither yes nor no. It depends on what you paste in, and above all on the type of account used. This distinction is poorly understood, and it is where everything that matters plays out.
What really happens to the text you paste in?
When you type into a generative AI tool, your text leaves your computer. It travels to the provider’s servers, where it is processed, then generally kept for a certain time. Three separate things can then happen, and they need to be told apart.
Retention. The provider keeps a record of your exchanges, to show you your history and to detect abusive use. Retention periods vary widely from one plan to another.
Human access. Some services state that a portion of conversations may be reviewed by people, employees of the provider or contractors, to assess the quality of the responses. Google, for instance, states for its consumer app that a subset of conversations is examined by human reviewers, and explicitly advises against entering confidential information there.
Training. Your content may be used to improve future models. This is the point that worries people most, often for the wrong reason: the risk is not that a model will spit your contract back out word for word in front of a competitor, that would be highly unlikely. It is simpler than that. You have handed information to a third party, outside your control, that you had no right or no intention to disclose.
Personal account or professional plan: where is the difference?
This is the decisive distinction, and it is almost always overlooked.
The major providers apply different rules depending on whether it is a consumer account or a plan intended for businesses. We checked the policies published in July 2026, bearing in mind that they change regularly.
Anthropic states that, by default, inputs and outputs from its commercial products are not used to train its models, unless the customer explicitly requests it. OpenAI, for its part, documents that data sent to its programming interface is not used to train its models unless opted in, with default retention limited to abuse-detection logs and options for regional data residency. Microsoft states that the prompts, responses and data accessed by the assistant built into its office suite are not used to train its foundation models, and that traffic from users in the European Union stays within the European data boundary. By contrast, consumer plans frequently use data by default, with a setting you must switch off yourself.
| Free personal account | Professional plan | |
|---|---|---|
| Training on your content | Often on by default, must be switched off yourself | Generally excluded by default with the major providers |
| Contract with your company | None, only the employee’s own terms of use | Contract in the company’s name, written commitments |
| Control over accounts | None, the account belongs to the individual | Accounts created and removed by you |
| Visibility over usage | None | Centralised administration |
| Data location | Not chosen | Often configurable depending on the plan |
An employee who uses their personal account for work transfers your data under a contract your company is not party to. When they leave the company, the history leaves with them, on an account you can neither view nor close. It is not artificial intelligence that creates the risk here, it is the absence of a framework.
These policies change fast. Do not rely on what you read a year ago, or on this article in two years’ time: open the provider’s page before deciding.
What Swiss data protection law requires
As soon as you transmit personal data, meaning any information relating to an identified or identifiable person, the Federal Act on Data Protection applies. A client’s name in an e-mail is one such example. Three requirements deserve your attention.
The provider becomes your processor. Entrusting processing to a third party is allowed under the law, provided that third party only processes the data as you yourself would be entitled to, and that this framework is contractual. A box ticked in terms and conditions accepted by an employee on their private account does not meet this condition.
Data often goes abroad. Communicating personal data outside Switzerland requires that the destination country ensure adequate protection, according to the list maintained by the Federal Council, or failing that, that appropriate safeguards be put in place, for example recognised standard contractual clauses. This list changes: check it when choosing your tool, rather than relying on a general claim.
Sensitive data demands more. Health data, data on criminal proceedings, religious or trade-union opinions, biometric data: the law protects these more strictly. A medical file, a sick-leave certificate or a detailed job application generally has no place in a consumer AI service.
These principles are detailed in our article on an SME’s FADP obligations. For a specific case, in particular if you handle data on patients or vulnerable people, have your situation validated by a specialist.
Which uses are genuinely risky?
Not all uses are equal. Here is how to sort them without turning the question into a philosophical debate.
No particular risk. Rephrasing a text you would publish anyway, drafting an ad, explaining a concept, writing a letter template with no names in it.
Needs a framework. Summarising internal meeting notes, having a commercial offer proofread, producing a table from activity figures. This content is confidential without necessarily being personal. It justifies a professional plan rather than a private account.
Avoid, unless a verified contractual framework is in place. Pasting in a complete client contract, a personnel file, a list of patients or beneficiaries, a payroll file, a dispute file, or source code containing your trade secrets or, worse, credentials and access keys.
An HR manager has to summarise twelve annual performance reviews. She pastes the full notes, including names, assessments and two mentions of sick leave, into a free service opened with her private address. The summary is excellent and saves her half a day. She has, however, just transmitted sensitive data on twelve colleagues to a third party, with no contract, no information to the people concerned, and no awareness on the part of her management. No one acted in bad faith: the rule simply did not exist.
Should AI be banned in the company?
An outright ban is tempting. It is also the least effective response, for a reason observed everywhere: it does not remove the use, it makes it invisible.
An employee who saves two hours a week thanks to a tool is not going to give it up because a memo asks them to. They will use it from their personal phone, on their private account, without mentioning it. You will then have combined the two worst conditions: the weakest level of protection, and no visibility at all.
Complete laissez-faire is no better. It amounts to hoping everyone will guess alone where the line lies between an innocuous text and a personnel file.
The workable path lies in the middle: a designated tool, on a professional plan, and a few written rules everyone understands.
A usage policy that fits on one page
Here is a template you can take and adapt. It aims for clarity, not legal exhaustiveness.
- One approved tool, subscribed to by the company. Choose one, on a professional plan, with accounts created and removed by you. Personal accounts for professional use are excluded.
- A list of what never goes into it. Health data, personnel files, complete client contracts, payroll files, credentials and passwords, sensitive source code. Six lines are enough, write them down.
- The principle of anonymisation. Remove names, addresses and numbers before pasting. An anonymised text almost always gives just as good a result.
- Mandatory human review. Nothing the tool produces goes to a client, an insurer or an authority without a person having read and approved it. These systems make mistakes with confidence.
- The screen rule. If you would not display this content on a screen in the waiting room, do not paste it in. It is the quickest test, and your teams remember it.
- A point of contact and the right to ask questions. Someone people can ask “am I allowed to put this in?” without fear of being punished.
Do not open a new binder for six rules. Add them to your IT policy, which your employees have already signed, and circulate it again. A rule attached to a known document is followed far better than an isolated note. While you are at it, review the section on personal accounts and cloud storage, which raises exactly the same problem.
What an SME cannot settle on its own
The six rules above put you ahead of the vast majority of Swiss companies your size, and they rule out the most costly mistakes. They are not, however, enough to answer every question.
Three areas call for an outside perspective. First, analysing your actual data flows: what data circulates within your company, which of it is sensitive, which belongs to your clients rather than to you. This mapping depends on your line of business and appears on no generic list. Then, contractual verification: reading what you have signed, and confirming that any transfer abroad rests on a valid basis. Finally, the assistants built into your existing tools, which expose to each employee everything their access rights already let them reach. If your permissions have never been reviewed, the topic leads directly to access management.
These measures form a solid foundation, they do not replace an examination of your particular situation.
To gauge your general level, the cyber check-up covers the areas that matter in a few minutes. And if your concern is data leaving the company, our article on data theft covers the other channels, often more mundane than artificial intelligence. The baseline measures are grouped in the Good practices pillar.