All insights

AI Innovation Built on Trust: What Software Development Companies Need to Know

Laura Kiviharju

Founder & CEO; AI, Data Protection & Cybersecurity Legal Expert

Swiss software companies have adopted AI faster than almost any other sector in Europe. However, even if the companies might have AI policies and a general understanding of AI-related risks, what many have not built at the same speed with the innovation is the governance layer that turns AI from an experiment into a compliant business capability — and governance, designed well, protects margin instead of consuming it.

81.4% of Swiss software companies used AI in software development in 2025, up from 46.8% in 2024 (Swiss Software Industry Survey 2025, University of Bern for Swico). The study is blunt about what is happening with AI governance: employees retain a lot of freedom in selecting tools, especially AI tools, because most companies remain in an experimental phase without strict usage guidelines. Switzerland leads at individual level too — 37.8% of the working-age population used generative AI in Q1 2026, against 17.8% globally (Microsoft AI Diffusion Report).

The case for moving forward with AI is clear: AI-accelerated innovation could add CHF 15 billion annually to the Swiss economy by 2034 (Computerworld.ch). At the same time Raiffeisen study (August 2026) finds only 9% of Swiss companies use AI systematically while 54% run pilots. This gap is not technological: in EY Switzerland's 2026 survey the top barriers to scaling are data quality and silos (20%), security and data protection (19%) and skills (18%); only 14% scale systematically, and 51% call Swiss or EU data processing business-critical. For a software company these are not IT concerns — they are the conditions for your customers’ purchase decisions.

Visibility instead of sanctioning: Governing AI with flexibility while staying compliant

Shadow IT is not new, but shadow AI poses different kind of challenges, and it is growing for three reasons (CIO, November 2025): democratization — generative AI's low entry barrier turns every employee into a potential developer; organizational pressure — business units clearly incentivised to raise productivity, but not in parallel to improve governance; and cultural reinforcement — engineering cultures value speed over process. The difference matters. Classic shadow IT put company data somewhere it should not be — a containment problem. Shadow AI does that too, but its output also flows back into the work: into code, customer emails and decisions, with no record of where it came from. The risk is no longer only what leaves the company, but what enters it unchecked.

Swiss software firms are structurally exposed: 52.5% let employees choose their own AI tools, against 36.9% for classical IT tools (SSIS 2025). AI governance is looser than the IT governance those same firms already run competently. Organisations with high levels of shadow AI carry USD 670,000 in additional average breach cost, and 63% of breached organisations had no AI governance policy (IBM, 2025). Prohibition is not the answer, and the market has concluded this: outright AI bans fell from 28% to 7% in one year (Cisco, 2026). A ban does not stop the usage, it only hides it. Visibility lowers the risk without slowing down the people creating the value.

Table 1 — Practical controls: what triggers them, what is their return
ControlTriggerReturn
AI mapping: reporting and technical discoveryBefore any policy workRemoves the unknowns that make audits and customer due diligence expensive
Central AI registryAs soon as mapping is completeAnswers customer and auditor questions in hours, not weeks
Risk categorisation by data sensitivityBefore tools are approved for useConcentrates review on the 10% of cases carrying majority of risk
Enterprise licences and compliance assessments for critical toolsWhen a tool becomes business-criticalContractual data protection, no training on your data, audit logs
Sandbox on synthetic dataBefore work on sensitive client dataKeeps experimentation where it is most valuable

The guiding principle is proportionality: the depth of review should match the sensitivity of the data and process involved. Applying the same level of scrutiny across the board is how governance starts eating the efficiency gain it was meant to protect. Where you want to experiment on sensitive client data, sandboxes running on synthetic data can serve as a pragmatic answer.

When AI moves into your product: Governance by design

Most software suppliers already offer AI features or AI solutions, or plan to. In practice this usually means integrating large language models — such as Claude, GPT or Mistral — into the products. That changes what you have to manage. Data no longer flows only through your own systems — it passes through the model, through APIs, and through whatever tools your AI agents call, and every hop is a processing step you are accountable for. The cybersecurity picture shifts with it, and entirely new risk categories appear: hallucinated output, and limited visibility into how the system reached a result at all.

The exposure is measurable. 45% of AI-generated code contains security vulnerabilities where no explicit security guidance is given — a figure that has not improved since 2025, across 150+ models tested (Veracode, Spring 2026). Faster generation without a matching shift in review and testing moves defects downstream, where they cost more.

Table 2 — Product-side risks and examples of design-stage answers
RiskBusiness impactExamples of measures at design stage
Uncontrolled data architectureCompliance gaps, costly rebuildData residency assessment; data-flow mapping; model portability
Vulnerabilities in AI-generated codeBreach liability, emergency patchingSecure AI development practice; developer training; AI-assisted security testing
Wrong or hallucinated output in customer workflowsWarranty claims, SLA credits, churnAccuracy KPIs; fine-tuning data quality; human oversight
Customer data used for training without a basisDSG exposure, lost dealsTraining controls; documented data sources
Opaque recommendationsCustomer cannot meet their own dutiesExplainability requirements in the product
Outdated customer agreementsUnpriced liability, disputes over AI outputAI-specific contract clauses; subprocessor transparency

Regulated industries change the risk profile, not the principles

Many software providers sell into finance, healthcare or the public sector, which means inheriting the sector-specific requirements their clients must meet. Beyond the AI-specific ones, cloud guidance is often the binding constraint on an AI product sold into a regulated industry, because it determines where processing may occur at all. Data sovereignty demands are also becoming a more common concern.

Table 3 — Examples of sector-specific considerations for Swiss software vendors
Customer sectorKey frameWhat it means for you as a vendor
All sectorsDSG, including Art. 21 (automated decisions), 8 (information security), 9 (processor contracts), 16 (data transfers abroad)Transparency and human review; technical and organisational security; transfer safeguards
FinanceBanking secrecy, FINMA Guidance 08/2024: model robustness, explainability, bias, data quality, third-party dependencyClient-identifying data handling (CID); model documentation; performance evidence; audit rights
HealthcareMepV/MedDO;

patient data and Art. 321 StGB secrecy
Device qualification; local or controlled processing
Public sectorFederal and cantonal law on the legal basis for data processing; Art. 320/321 StGB secrecyPermitted processing purposes; data residency; cloud requirements
EU-facing customersEU AI Act including Art. 50 transparency from Aug 2026; high-risk deployer duties as of Dec 2027/Aug 2028AI disclosure to end-users; high-risk use-case classification (e.g. recruitment)

Meeting the legal and regulatory requirements is the baseline. Following the relevant industry guidelines as well is what gets a vendor through procurement in these sectors.

The bottom line

The regulatory case for acting is real, and the economics point the same way. Explainability, traceable data flows and a lawful basis for training data are inexpensive to specify at the outset and expensive to retrofit. Cataloguing twenty AI tools is manageable; cataloguing several hundred is a different project.

Governance that works is light where risk is low and more thorough where risk is real. It runs on visibility rather than prohibition, and is ingrained in engineering processes rather than assembled when a prospective client asks how you govern AI. For a Swiss software company the case is commercial as much as legal: enterprise customers pass their own regulators' questions on to you as procurement requirements, and smaller customers, who rarely audit, still notice a breach. Firms that can respond promptly, and with evidence, shorten a sales cycle that others spend months working through. That is the return on trust by design.

Where this gets difficult is rarely the principle. It is the specific case: whether your architecture qualifies under a client's secrecy obligations, whether a given control satisfies a regulator, whether the sector guidance your customer follows applies to you as their vendor. Those questions are worth answering before a procurement questionnaire forces them.

Building Trust in AI Innovation

Business Swiss connects Swiss business leaders with expertise in AI, data protection, cybersecurity, and governance. Laura’s perspective brings these disciplines together around a practical business question: how can software companies turn AI innovation into a capability their customers can trust?

Laura Kiviharju

About the author

Laura Kiviharju

Founder & CEO; AI, Data Protection & Cybersecurity Legal Expert

Laura Kiviharju helps technology companies turn AI, data protection, and cybersecurity requirements into practical governance and controls. She brings more than 15 years of legal, security, and risk governance experience across regulated industries, advising founders, executives, and boards in Switzerland, the Nordics, and the EU.

More articles

Is Your SAP Transformation Really Ready?

Why successful SAP transformations require more than technology.

Read more

Your Data Is in Switzerland — But Is It Really Yours?

Swiss data residency does not automatically mean Swiss data control. Digital sovereignty requires governance, operational visibility, and a platform architecture designed around ownership.

Read more

Let's create new synergies

Your Contact

  • Stefan Müller
    Founder
    Business Swiss Network
    Ackerstrasse 12
    CH-8005 Zürich
    [email protected]
Mitglied des Swiss Board Forum