AI-Karma

01Starting well

What applies from the first AI tool

Legal version 2026-10-09

For an SME that has nothing in place yet. The actions below are those of the KarmaScore framework, in the order to do them; each block only adds what your situation triggers. Dated reference points, not legal advice.

02Starting well

From the first tool

Whatever the use, even without any personal data.

  1. 01

    Inventory of AI and digital systems

    From the first tool, whatever the use.

    First step
    Start a first list in 1 hour Gather the team leads for 1 hour and list every tool in use in a spreadsheet: name, what it is for, who uses it, what data it processes. Save the dated file in a shared folder.
    Deliverable
    Inventory of digital and AI tools, dated
    References
    AI Act Art. 26 (from 2 December 2027) · Good practice ISO/IEC 42001
    Keep the register of AI systems
  2. 02

    Staff training

    From the first tool, whatever the use.

    First step
    Write a 2-page AI charter Set down in writing: what is never entered into an AI tool (identifiable customer data, trade secrets), the authorised tools, who to report a doubt to. A simple document beats an unreadable rulebook.
    Deliverable
    AI usage charter signed by everyone
    References
    AI Act Art. 4 · FADP Art. 8
    Write the AI usage policy
  3. 03

    Control over AI vendors

    Because your data will go to a provider whose hosting you do not know yet.

    First step
    Review what you already have Go back to your tool inventory and, for each AI or cloud supplier, look up the country where the data is hosted in its privacy policy or its “security” page. Fill in the corresponding column of the inventory.
    Deliverable
    Supplier evaluation grid (1 page)
    References
    CopA Art. 2, 10 · FADP Art. 9, 16 · AI Act Art. 25 (from 2 December 2027)
    Keep the register of AI systems

03Starting well

If personal data goes into the tool

Clients, prospects, employees or candidates: in Switzerland the FADP applies from the first processing.

  1. 04

    Informing data subjects

    Because personal data will go into the tool.

    First step
    Take stock of your channels List where you already inform your customers and staff: website, forms, contracts, HR documents. Reread your current privacy policy and highlight everything that does not match your actual practice.
    Deliverable
    Dated, versioned privacy policy
    References
    FADP Art. 19–21 · AI Act Art. 50
  2. 05

    Basic IT security

    Because personal data will go into the tool.

    First step
    Switch on two-factor authentication everywhere Enable two-factor authentication (a code on top of the password) on email, administrator accounts and cloud tools, starting with management accounts. Roll out a password manager for the team and keep a screenshot of the settings.
    Deliverable
    One-page security policy, circulated
    References
    FADP Art. 8 · FADP Art. 24 · DPO Art. 15 para. 4 · GDPR Art. 32
  3. 06

    Data subject rights

    Because personal data will go into the tool.

    First step
    Designate a single point of contact Choose an owner and a stand-in, and create a dedicated address (e.g. data@your-company.ch). Publish it in your privacy policy.
    Deliverable
    1-page procedure
    References
    FADP Art. 25 · FADP Art. 25 para. 2 let. f · FADP Art. 32 · GDPR Art. 15–22
  4. 07

    Data governance

    Because data about employees or candidates is involved.

    First step
    Map where your data lives In a 1-hour meeting, list your main data categories (customers, HR, accounting, projects) and where each one is stored: server, cloud, mailboxes, Excel files. Record it all in a simple table.
    Deliverable
    Access matrix (who accesses what)
    References
    CO Art. 328b · FADP Art. 6, 8 · AI Act Art. 26(4) (from 2 December 2027) · FADP Art. 7 para. 3 · FDPIC “Different phases of the employment relationship”

04Starting well

If the tool weighs on decisions about people

Sorting applications, rating clients, sensitive data: a natural person must be able to review, explain and respond.

  1. 08

    Human oversight

    Because the tool will weigh on decisions about people.

    First step
    Spot what goes out unchecked Review your automated tools and flag those whose output applies directly, with no human eye: automatic emails, rejections, scores, published content. Rank them by their impact on people.
    Deliverable
    List of automated decisions with their control point
    References
    OLW 3 Art. 26 · AI Act Art. 14, 26(2) (from 2 December 2027) · FADP Art. 21
  2. 09

    Explainability of automated decisions

    Because the tool will weigh on decisions about people.

    First step
    Identify the automated decisions Go through your tool inventory and flag those that influence a decision: CV screening, customer scoring, calculated prices, automated replies. For each one, note who is affected by the outcome.
    Deliverable
    One-page explanation sheet per tool
    References
    FADP Art. 25 para. 2 let. f · AI Act Art. 13, 26 (from 2 December 2027) · FADP Art. 21 · Case law CJEU C-634/21 “SCHUFA”
  3. 10

    Avenues of recourse

    Because the tool will weigh on decisions about people.

    First step
    List the automated decisions that affect someone In 1 hour, list the cases where a tool decides without a human: customer rejection, CV screening, account blocking, price applied. For each, note the channel through which the person learns of the decision.
    Deliverable
    Published recourse procedure
    References
    AI Act Art. 86 · AI Act Art. 26(11) (from 2 December 2027) · FADP Art. 21 para. 2 · Case law CJEU C-634/21 “SCHUFA”
  4. 11

    Impact assessments (DPIA)

    Because the tool will weigh on decisions about people.

    First step
    Put the trigger criteria in writing Write a 1-page sheet listing the situations that require an impact assessment (a written study of the risks to individuals): sensitive data on a large scale, systematic monitoring, profiling (automated evaluation of people) — including via AI. Date the sheet and hand it to the project leads.
    Deliverable
    Sheet of trigger criteria
    References
    CO Art. 328b · FADP Art. 22–23 · GDPR Art. 35 · FADP Art. 7
    Check whether an impact assessment is required
  5. 12

    Record of processing activities

    Because sensitive data is involved.

    First step
    Check whether the obligation applies to you Count your staff (threshold of 250), check whether you process sensitive data on a large scale, carry out profiling (automated evaluation of people) or serve customers in the EU. Record the conclusion in a 1-page note, dated and signed by management — the register remains good practice even without an obligation.
    Deliverable
    Completed register of processing activities (spreadsheet or export)
    References
    FADP Art. 12 para. 5 · DPO Art. 24 · GDPR Art. 30
  6. 13

    Bias prevention

    Because people will be sorted or assessed.

    First step
    List the tools that screen people Gather HR, sales and IT for 1 hour to list every tool that filters, scores or ranks people (applications, customers, pricing). Record the result on one page, with the area concerned.
    Deliverable
    Dated bias test notes
    References
    AI Act Art. 10, 26 (from 2 December 2027) · GEA Art. 3 · Const. Art. 8 · CoE Convention non-discrimination

05Starting well

If people talk to a machine or read generated content

Chatbot, images, published texts: say so, in Switzerland as in the Union.

  1. 14

    Transparency about AI use

    Because people will talk to a machine or read generated content.

    First step
    Take stock of your AI touchpoints In 1 hour, list where your customers encounter AI: chatbot, generated email replies, published images or text, voicemail. Note who manages each channel.
    Deliverable
    Transparency policy published on the site
    References
    AI Act Art. 50 · UCA Art. 3 para. 1 let. b · FADP Art. 19
    Prepare the transparency notices

06Starting well

If your clients, the people concerned or the outputs affect the European Union

Without a link to the Union market, the AI Act does not apply to a Swiss SME. With one, the prohibited practices and transparency are already in force.

  1. 15

    AI Act applicability and classification

    Because the European Union is affected.

    First step
    List all your AI use cases Gather the teams for 1 hour and note every actual use: chatbot, generated content, CV screening, forecasting — including tools used without official approval. This list is your starting point.
    Deliverable
    Table of obligations / owners / deadlines
    References
    AI Act Art. 2 · AI Act Art. 5 · AI Act Art. 50 · AI Act Art. 6, 26 (from 2 December 2027) · CoE Convention Framework Convention on AI
    Test whether the AI Act applies

07Starting well

What next

Answer the five questions of the "Getting started" path to get this list tailored to your situation, then write your usage policy. Once the first actions are done, the full assessment on 24 indicators will measure the ground covered.

Reference points for information, not legal advice. They follow legal version 2026-10-09 of the framework; revisions are dated on the Watch page. See the watch