Framework v1 · legal version 2026-08-27
Methodology & regulatory framework
The KarmaScore is a linear weighted model, chosen for its exact explainability: every point of the global score is attributable to a specific indicator, and the sum of the 24 contributions gives the score back. No black box: this is verified by a reproducible selftest at every change to the engine.
Formula (alpha version)
value(indicator) = answer ÷ 4 × 100 · score(dimension) = average of its 6 indicators · global score = Σ sector weight × score(dimension)
Threshold of the “Swiss Ethical AI Inside” label: 70/100. A practice prohibited by Art. 5 of the AI Act blocks the label whatever the score.
Scope: what the framework covers, and what it leaves out
No framework covers the whole of the law, and claiming otherwise would be the first reason to distrust it. What a serious framework does is define its scope and be complete inside it. Here is ours, written so that the absence of a text reads as a choice rather than an oversight.
Inside the scope
- The law that bears on a Swiss SME because it deploys AI systems or digital tools, together with the data processing that use entails.
- The obligations of the deployer, the party using a system under its own authority: that is the situation of almost every SME.
- Swiss law first, European law next, where a connection to the Union market makes it applicable.
- Recognised good practice where no obligation exists, labelled as such: that is currently the case for most of the Environment dimension. Two hard-law exceptions, shown as such: the end of life of equipment (OREA) and the energy efficiency of hardware, including hardware acquired for one's own use (OEEE).
Outside the scope, deliberately
- General business law: tax, company law, leases, commercial contracts. It enters here only where the use of AI changes it.
- The obligations of the provider of a high-risk AI system (AI Act Art. 8 to 25). Almost no Swiss SME holds that role, and including them would dilute the questions that actually concern it.
- Regimes reserved to large companies by a threshold, sustainability reporting among them. An SME of twenty people is not subject to them: flagging them would be a false alarm.
- The technical quality and performance of the models used. The framework assesses your practices, not your tools.
And it is not an audit. A twenty-minute self-declared questionnaire locates a level of maturity, it does not certify compliance. A high score is not a legal guarantee, and a critical signal is not a finding of breach: it is an obligation potentially not covered, to be checked with a lawyer.
What is still missing, and what we are not hiding: the weightings already vary by sector family, but the legal references displayed are the same for everyone. Neither the regulated sector (finance, health, public subcontracting) nor the facts that trigger a particular regime (a link to the EU, the sale of a software product) make them vary yet. Both layers are work in progress; their absence is written here rather than passed over in silence.
Critical signals: what the average never compensates
An additive model can hide a serious failure behind a good global score. The KarmaScore answers this known limit with non-compensable signals: 8 indicators anchored in a legal obligation are, if left at level 0, flagged next to the score, on screen, in the downloaded summary and in the report sent by email. The wording stays legally cautious: we flag an obligation that is potentially not covered, we never assert a breach.
- Informing data subjectsFADP art. 19–21 · AI Act art. 50
- Data subject rightsFADP art. 25 · FADP art. 25 al. 2 let. f · FADP art. 32 · GDPR art. 15–22
- Impact assessments (DPIA)CO art. 328b · FADP art. 22–23 · GDPR art. 35
- AI Act applicability and classificationAI Act art. 2 · AI Act art. 50 · AI Act art. 6, 26 (from 2 December 2027) · CoE Convention Framework Convention on AI
- Basic IT securityFADP art. 8 · FADP art. 24 · DPO art. 15 al. 4 · GDPR art. 32
- Human oversightOLW 3 art. 26 · AI Act art. 14, 26(2) (from 2 December 2027) · FADP art. 21
- Control over AI vendorsCopA art. 2, 10 · FADP art. 9, 16 · AI Act art. 25 (from 2 December 2027)
- Avenues of recourseAI Act art. 86 · AI Act art. 26(11) (from 2 December 2027) · FADP art. 21 al. 2 · Case law CJEU C-634/21 “SCHUFA”
Sector weightings
The four dimensions are weighted according to the sector family: no axis exceeds 40 % (anti-over-representation cap). The v1 weights are set by expert judgement and will be recalibrated on the pilot data.
| Family | T | C | E | S |
|---|---|---|---|---|
| Industry & Energy | 25% | 25% | 30% | 20% |
| Services & Finance | 25% | 35% | 15% | 25% |
| Digital & AI | 35% | 30% | 15% | 20% |
| Other sector | 30% | 30% | 20% | 20% |
Why these weightings, profile by profile
The starting point is a balanced profile (T 30 · C 30 · E 20 · S 20). Each sector family emphasises the axis where its real impact is strongest, never exceeding the cap of 40 %: a score must never be dominated by a single dimension.
- Industry & Energy E raised (30 %): the footprint of these SMEs comes first from energy, machinery and hardware, which is where their digital choices weigh most. C lowered to 25 %: their AI uses process, on average, fewer personal data day to day than services do (industrial processes rather than client files); compliance remains essential, but relative exposure is lower.
- Services & Finance C raised (35 %, close to the cap): personal and financial data are the raw material of the business, the sector is the most densely regulated (FADP, GDPR, professional secrecy), and Annex III of the AI Act targets it first (credit to individuals, life and health insurance, HR). S raised (25 %): AI-assisted decisions there directly affect people. E reduced (15 %): an essentially tertiary footprint, without heavy physical processes.
- Digital & AI T raised (35 %): these companies build or integrate the systems; safety, explainability, oversight and incident handling are the core of their responsibility, and Art. 25 of the AI Act can reclassify them as providers. C stays high (30 %) for the same reason. E at 15 %: the cloud footprint is real but, at equal size, lower than that of physical industry.
- Other sector Base profile with no sectoral assumption: T and C in equal parts (technical command and compliance are the two universal foundations), E and S at 20 %. It is the starting point of which the three other profiles are accentuations.
Do you disagree with a weight? That is expected, and welcome: write to contact@ai-karma.ch with your argument. Well-founded disagreements are incorporated into a dated version of the methodology and credited in the changelog. The v1 weights will also be recalibrated on real data from the pilot companies: that is a public commitment, not an intention.
Regulatory timetable
Review of 26 August 2026: addition of the Swiss legal anchors outside the FADP, namely Art. 328b CO (data of employees and applicants), Art. 26 OLW 3 (monitoring at the workplace), Art. 3 GEA and Art. 8 of the Federal Constitution (non-discrimination in hiring), Art. 3 UCA (misleading indication) and the Copyright Act (rights over generative outputs). State of the AI Act unchanged. The timetable was settled after the entry into force of the “Digital Omnibus AI”: Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July 2026, in force since 27 July 2026. The Commission published its final guidelines on Art. 50 on 20 July 2026; the code of practice on the transparency of AI-generated content was found adequate by the Commission and by the AI Board, and had around 190 signatory organisations at the end of July 2026. On 31 July 2026 the Commission confirmed that the transparency obligations start applying on 2 August. Next milestones to watch: end of the machine-marking transition on 2 December 2026, draft Swiss AI legislation expected by the end of 2026, entry into force of the Council of Europe Framework Convention on AI.
- 02/02/2025In forceEU
AI Act — prohibited practices and AI literacy
Art. 5 (manipulation, exploitation of vulnerabilities, social scoring, emotion recognition at work and in education, etc.) and Art. 4 (AI literacy, relaxed by the omnibus into a best-efforts obligation). Penalties up to EUR 35 million or 7 % of worldwide turnover for prohibited practices.
- 02/08/2025In forceEU
AI Act — general-purpose AI models (GPAI) and governance
Obligations of GPAI providers (Chapter V), setting up of the authorities and of the national penalty regime.
- 02/08/2026In forceEU
AI Act — transparency (Art. 50)
Informing people who interact with a chatbot, marking of generated content, labelling of deepfakes, information in case of emotion recognition or biometric categorisation. Applies to providers and deployers, including Swiss ones, as soon as the output is used in the EU. Penalties up to EUR 15 million or 3 % of worldwide turnover (Art. 99(4)). Applicable since 2 August 2026. Nuance: machine-readable marking (Art. 50(2)) of generative systems placed on the market BEFORE 2 August 2026 has a transition until 2 December 2026; the chatbot and deepfake obligations, however, have been due since 2 August. Application landmarks: the Commission's final guidelines on Art. 50 (20 July 2026) and the code of practice on the transparency of AI-generated content, open for signature to providers as well as to deployers subject to Art. 50(2), (4) and (5), wherever they are established (around 190 signatory organisations at the end of July 2026). For an SME, the penalty ceiling must be read together with Art. 99(6): the LOWER of the two amounts applies, and the omnibus extended this regime to small mid-cap companies, opening the way to warnings and non-financial measures.
- 02/12/2026UpcomingEU
AI Act — new prohibitions and end of the marking transition
New prohibitions under Art. 5 (generators of non-consensual intimate images, CSAM); end of the machine-readable marking transition (Art. 50(2)) for generative systems placed on the market before 2 August 2026.
- 31/12/2026UpcomingSwitzerland
Switzerland — draft AI legislation expected
Implementation of the Council of Europe Framework Convention on AI (signed in March 2025): transparency, data protection, non-discrimination, oversight. Consultation expected by the end of 2026; first legislative amendments in 2027 at the earliest. Sectoral approach, no cross-cutting statute.
- 02/12/2027UpcomingEU
AI Act — “high-risk” obligations under Annex III (POSTPONED by the omnibus)
Standalone systems in the Annex III areas (recruitment and HR, credit, life and health insurance pricing, education, biometrics, essential services, etc.): full obligations of providers and deployers (Art. 26: competent human oversight, control of input data, logs kept for at least 6 months, information of workers and of affected persons, etc.). The initial date of 2 August 2026 has been postponed by 16 months.
- 02/08/2028UpcomingEU
AI Act — high risk under Annex I (AI embedded in regulated products)
Machinery, medical devices, toys and the like that embed AI subject to sectoral product regulations.
Whether the AI Act applies to your company depends on your link with the EU market: check it use case by use case.
The 24 indicators and their legal bases
Each indicator is linked to the texts that motivate it: information landmarks, not legal advice. The E dimension remains essentially voluntary: no law requires a Swiss SME to measure or reduce its digital footprint. Two real obligations are the exception, and the table carries them: the return and disposal of equipment at end of life (OREA) and the minimum energy-efficiency requirements, which also apply to hardware acquired for one's own use (OEEE Art. 4 para. 2).
T · Technology
| Indicator | Legal landmarks | ISO/IEC 42001 |
|---|---|---|
| Inventory of AI and digital systems | AI Act art. 26 (from 2 December 2027) · Good practice ISO/IEC 42001knowing your systems is the precondition of the deployer's duties · inventory of AI systems | A.4 — resources for AI systems |
| Explainability of automated decisions | FADP art. 25 al. 2 let. f · AI Act art. 13, 26 (from 2 December 2027) · FADP art. 21 · Case law CJEU C-634/21 “SCHUFA”right to obtain “the logic on which the decision is based”: the only right to an explanation that applies in Switzerland today, with no EU-link condition · instructions for use and understanding of the system · automated individual decision: information and the person's point of view · where the GDPR applies: a score relied on by a third party is already an automated decision; its logic must be explained intelligibly (C-203/22) | A.8 — information for interested parties |
| Basic IT security | FADP art. 8 · FADP art. 24 · DPO art. 15 al. 4 · GDPR art. 32security proportionate to the risk; breaching the minimum requirements is a criminal offence punishable by up to CHF 250,000 against the responsible natural person (Art. 61) · notification of breaches to the FDPIC “as soon as possible” in case of high risk · document ALL breaches, including those not notified, and keep the documentation for two years · where the GDPR applies | §6 — planning (with ISO/IEC 27001) |
| Data governance | CO art. 328b · FADP art. 6, 8 · AI Act art. 26(4) (from 2 December 2027)data of employees and applicants: only their suitability for the job, or what is necessary to perform the contract · accuracy and security · control of input data (high-risk deployer) | A.7 — data for AI systems |
| Human oversight | OLW 3 art. 26 · AI Act art. 14, 26(2) (from 2 December 2027) · FADP art. 21prohibition of systems INTENDED to monitor employee behaviour at the workplace; monitoring for other reasons remains possible if proportionate · human oversight by competent persons · right to obtain human intervention | A.9 — responsible use |
| Control over AI vendors | CopA art. 2, 10 · FADP art. 9, 16 · AI Act art. 25 (from 2 December 2027)generative uses: check in the provider's terms who holds the rights over the outputs and over what is fed in · processing on behalf of others and disclosure of data abroad · rebranding or substantially modifying an AI system makes you a provider | A.10 — third-party relationships |
C · Compliance
| Indicator | Legal landmarks | ISO/IEC 42001 |
|---|---|---|
| Record of processing activities | FADP art. 12 al. 5 · DPO art. 24 · GDPR art. 30exemption below 250 employees, except for high-risk processing · specifies the exemption: fewer than 250 employees AND limited risk of harm to personality · a far narrower exemption where the GDPR applies | §7.5 — documented information |
| Informing data subjects | FADP art. 19–21 · AI Act art. 50mention of AI interactions — since 2 August 2026 | A.8 — information for interested parties |
| Impact assessments (DPIA) | CO art. 328b · FADP art. 22–23 · GDPR art. 35in an HR context, the lawfulness of the processing is judged here first, before the impact assessment · impact assessment if high risk; consultation of the FDPIC · where the GDPR applies | A.5 — impact assessments |
| AI Act applicability and classification | AI Act art. 2 · AI Act art. 50 · AI Act art. 6, 26 (from 2 December 2027) · CoE Convention Framework Convention on AIterritorial scope: with no connection to the Union market, the regulation does not apply · transparency: chatbots, generated content, deepfakes · classification as high risk and deployer duties · future basis of Swiss law (draft expected end of 2026) | §4 — context · A.2 — AI policy |
| Data subject rights | FADP art. 25 · FADP art. 25 al. 2 let. f · FADP art. 32 · GDPR art. 15–22right of access; usual 30-day deadline · the reply must state the existence of an automated individual decision and the logic on which it is based · rectification, erasure and other claims · where the GDPR applies | A.8 — information for interested parties |
| Staff training | AI Act art. 4 · FADP art. 8AI literacy — a best-efforts obligation since Feb. 2025 · organisational measures | §7.2 — competence |
E · Environment
| Indicator | Legal landmarks | ISO/IEC 42001 |
|---|---|---|
| Low-footprint hosting | Good practice digital frugality | — |
| Measuring the digital footprint | Good practice digital carbon footprintno direct obligation for an SME; increasingly requested by large clients subject to climate reporting | — |
| Hardware life cycle | OREA art. 5 · OREA art. 9 al. 3 · OREA art. 8 · Good practice IT circular economyduty to return any appliance one disposes of to a retailer, a manufacturer or a disposal firm; taking back is free of charge (Art. 6) · what cannot be handed back must be disposed of at the holder's expense, per the requirements of Art. 10 · data carriers handed over remain subject to the FADP: the end of life of hardware is also a data protection question | — |
| Digital sobriety | Good practice digital frugality | — |
| Responsible IT procurement | OEEE art. 4 al. 2 · Good practice responsible purchasingthe minimum efficiency requirements also apply to appliances “acquired for one's own use in a professional setting”: the SME importing its own equipment does not escape them | — |
| Reduction targets | Good practice tracked climate targetsnational framework: net zero by 2050 (Climate and Innovation Act); no obligation for an SME to set a quantified target | — |
S · Society
| Indicator | Legal landmarks | ISO/IEC 42001 |
|---|---|---|
| Digital accessibility | Good practice WCAG 2.1 AAmandatory in certain EU sectors (European Accessibility Act) | A.9 — responsible use |
| Bias prevention | AI Act art. 10, 26 (from 2 December 2027) · GEA art. 3 · Const. art. 8 · CoE Convention non-discriminationdata governance and oversight (high risk) · prohibition of discrimination in hiring, in particular on grounds of sex — applies to automated screening of applications · equality and prohibition of discrimination | A.5 / A.7 — impact and data (bias) |
| Transparency about AI use | AI Act art. 50 · UCA art. 3 al. 1 let. b · FADP art. 19chatbots, generated content, deepfakes — since 2 August 2026 · Swiss law: letting someone believe they are talking to a human, or advertising an AI inaccurately, is a misleading indication · transparency of processing | A.8 — information for interested parties |
| Impact on jobs and skills | CO art. 328b · OLW 3 art. 26 · AI Act art. 26(7) (from 2 December 2027) · AI Act art. 4limits on processing data of employees and applicants · systems monitoring behaviour at the workplace · prior information of workers and their representatives (high risk) · AI literacy of staff | §7.2 — competence · A.3 — roles |
| Inclusion and diversity | CoE Convention equality and non-discrimination | A.5 — impact assessments |
| Avenues of recourse | AI Act art. 86 · AI Act art. 26(11) (from 2 December 2027) · FADP art. 21 al. 2 · Case law CJEU C-634/21 “SCHUFA”right to an explanation of an individual decision based on an Annex III system · information of the people subject to a decision assisted by the system · right to state one's point of view and to demand human review · where the GDPR applies: the scoring itself may constitute the decision | A.8 / A.9 — information and responsible use |
Acknowledged limits of the alpha version
- Synthetic benchmark the panel of 30 SMEs is fictional, with fixed and documented values; it will be replaced by real pilot data.
- Self-declaration the score reflects the answers given. The “Audited” level of the label (third-party sincerity audit) is described in the label governance.
- v1 weights set by expert judgement not yet calibrated on data: the linear structure makes that future calibration transparent and auditable.
- Indicative legal landmarks legal version 2026-08-27, updated at every milestone (end of the machine-marking transition on 2 December 2026, Swiss draft at the end of 2026, entry into force of the Council of Europe Convention).
The full detail (scientific justification, selftest invariants, governance of the weights and of the label) is recorded in documents versioned with the code (METHODOLOGY.md, LABEL_GOVERNANCE.md), not public to date: this page conveys the essentials.