AI-Karma · Starting well with AI · legal version 2026-10-09 · ai-karma.ch/en/demarrer
01Starting well
What applies from the first AI tool
Legal version 2026-10-09For an SME that has nothing in place yet. The actions below are those of the KarmaScore framework, in the order to do them; each block only adds what your situation triggers. Dated reference points, not legal advice.
02Starting well
From the first tool
Whatever the use, even without any personal data.
- 01
Inventory of AI and digital systems
From the first tool, whatever the use.
- First step
- Start a first list in 1 hour Gather the team leads for 1 hour and list every tool in use in a spreadsheet: name, what it is for, who uses it, what data it processes. Save the dated file in a shared folder.
- Deliverable
- Inventory of digital and AI tools, dated
- References
- AI Act Art. 26 (from 2 December 2027) · Good practice ISO/IEC 42001
- 02
Staff training
From the first tool, whatever the use.
- First step
- Write a 2-page AI charter Set down in writing: what is never entered into an AI tool (identifiable customer data, trade secrets), the authorised tools, who to report a doubt to. A simple document beats an unreadable rulebook.
- Deliverable
- AI usage charter signed by everyone
- References
- AI Act Art. 4 · FADP Art. 8
- 03
Control over AI vendors
Because your data will go to a provider whose hosting you do not know yet.
- First step
- Review what you already have Go back to your tool inventory and, for each AI or cloud supplier, look up the country where the data is hosted in its privacy policy or its “security” page. Fill in the corresponding column of the inventory.
- Deliverable
- Supplier evaluation grid (1 page)
- References
- CopA Art. 2, 10 · FADP Art. 9, 16 · AI Act Art. 25 (from 2 December 2027)
03Starting well
If personal data goes into the tool
Clients, prospects, employees or candidates: in Switzerland the FADP applies from the first processing.
- 04
Informing data subjects
Because personal data will go into the tool.
- First step
- Take stock of your channels List where you already inform your customers and staff: website, forms, contracts, HR documents. Reread your current privacy policy and highlight everything that does not match your actual practice.
- Deliverable
- Dated, versioned privacy policy
- References
- FADP Art. 19–21 · AI Act Art. 50
- 05
Basic IT security
Because personal data will go into the tool.
- First step
- Switch on two-factor authentication everywhere Enable two-factor authentication (a code on top of the password) on email, administrator accounts and cloud tools, starting with management accounts. Roll out a password manager for the team and keep a screenshot of the settings.
- Deliverable
- One-page security policy, circulated
- References
- FADP Art. 8 · FADP Art. 24 · DPO Art. 15 para. 4 · GDPR Art. 32
- 06
Data subject rights
Because personal data will go into the tool.
- First step
- Designate a single point of contact Choose an owner and a stand-in, and create a dedicated address (e.g. data@your-company.ch). Publish it in your privacy policy.
- Deliverable
- 1-page procedure
- References
- FADP Art. 25 · FADP Art. 25 para. 2 let. f · FADP Art. 32 · GDPR Art. 15–22
- 07
Data governance
Because data about employees or candidates is involved.
- First step
- Map where your data lives In a 1-hour meeting, list your main data categories (customers, HR, accounting, projects) and where each one is stored: server, cloud, mailboxes, Excel files. Record it all in a simple table.
- Deliverable
- Access matrix (who accesses what)
- References
- CO Art. 328b · FADP Art. 6, 8 · AI Act Art. 26(4) (from 2 December 2027) · FADP Art. 7 para. 3 · FDPIC “Different phases of the employment relationship”
04Starting well
If the tool weighs on decisions about people
Sorting applications, rating clients, sensitive data: a natural person must be able to review, explain and respond.
- 08
Human oversight
Because the tool will weigh on decisions about people.
- First step
- Spot what goes out unchecked Review your automated tools and flag those whose output applies directly, with no human eye: automatic emails, rejections, scores, published content. Rank them by their impact on people.
- Deliverable
- List of automated decisions with their control point
- References
- OLW 3 Art. 26 · AI Act Art. 14, 26(2) (from 2 December 2027) · FADP Art. 21
- 09
Explainability of automated decisions
Because the tool will weigh on decisions about people.
- First step
- Identify the automated decisions Go through your tool inventory and flag those that influence a decision: CV screening, customer scoring, calculated prices, automated replies. For each one, note who is affected by the outcome.
- Deliverable
- One-page explanation sheet per tool
- References
- FADP Art. 25 para. 2 let. f · AI Act Art. 13, 26 (from 2 December 2027) · FADP Art. 21 · Case law CJEU C-634/21 “SCHUFA”
- 10
Avenues of recourse
Because the tool will weigh on decisions about people.
- First step
- List the automated decisions that affect someone In 1 hour, list the cases where a tool decides without a human: customer rejection, CV screening, account blocking, price applied. For each, note the channel through which the person learns of the decision.
- Deliverable
- Published recourse procedure
- References
- AI Act Art. 86 · AI Act Art. 26(11) (from 2 December 2027) · FADP Art. 21 para. 2 · Case law CJEU C-634/21 “SCHUFA”
- 11
Impact assessments (DPIA)
Because the tool will weigh on decisions about people.
- First step
- Put the trigger criteria in writing Write a 1-page sheet listing the situations that require an impact assessment (a written study of the risks to individuals): sensitive data on a large scale, systematic monitoring, profiling (automated evaluation of people) — including via AI. Date the sheet and hand it to the project leads.
- Deliverable
- Sheet of trigger criteria
- References
- CO Art. 328b · FADP Art. 22–23 · GDPR Art. 35 · FADP Art. 7
- 12
Record of processing activities
Because sensitive data is involved.
- First step
- Check whether the obligation applies to you Count your staff (threshold of 250), check whether you process sensitive data on a large scale, carry out profiling (automated evaluation of people) or serve customers in the EU. Record the conclusion in a 1-page note, dated and signed by management — the register remains good practice even without an obligation.
- Deliverable
- Completed register of processing activities (spreadsheet or export)
- References
- FADP Art. 12 para. 5 · DPO Art. 24 · GDPR Art. 30
- 13
Bias prevention
Because people will be sorted or assessed.
- First step
- List the tools that screen people Gather HR, sales and IT for 1 hour to list every tool that filters, scores or ranks people (applications, customers, pricing). Record the result on one page, with the area concerned.
- Deliverable
- Dated bias test notes
- References
- AI Act Art. 10, 26 (from 2 December 2027) · GEA Art. 3 · Const. Art. 8 · CoE Convention non-discrimination
05Starting well
If people talk to a machine or read generated content
Chatbot, images, published texts: say so, in Switzerland as in the Union.
- 14
Transparency about AI use
Because people will talk to a machine or read generated content.
- First step
- Take stock of your AI touchpoints In 1 hour, list where your customers encounter AI: chatbot, generated email replies, published images or text, voicemail. Note who manages each channel.
- Deliverable
- Transparency policy published on the site
- References
- AI Act Art. 50 · UCA Art. 3 para. 1 let. b · FADP Art. 19
06Starting well
If your clients, the people concerned or the outputs affect the European Union
Without a link to the Union market, the AI Act does not apply to a Swiss SME. With one, the prohibited practices and transparency are already in force.
- 15
AI Act applicability and classification
Because the European Union is affected.
- First step
- List all your AI use cases Gather the teams for 1 hour and note every actual use: chatbot, generated content, CV screening, forecasting — including tools used without official approval. This list is your starting point.
- Deliverable
- Table of obligations / owners / deadlines
- References
- AI Act Art. 2 · AI Act Art. 5 · AI Act Art. 50 · AI Act Art. 6, 26 (from 2 December 2027) · CoE Convention Framework Convention on AI
07Starting well
What next
Answer the five questions of the "Getting started" path to get this list tailored to your situation, then write your usage policy. Once the first actions are done, the full assessment on 24 indicators will measure the ground covered.
Reference points for information, not legal advice. They follow legal version 2026-10-09 of the framework; revisions are dated on the Watch page. See the watch