Analyse· 9 min de lecture

AI in Swiss healthcare: what a regulated sector allows

Healthcare is probably Switzerland's most regulated sector, and yet AI is already established there — not in conference-stage promises, but in everyday routine: imaging analysis, administrative management, clinical research. This is the demonstration that matters to any executive operating under regulatory constraint: the rule doesn't block AI, it selects well-built projects. This note lays out the uses that hold up, the framework that structures them, and what an SME — in healthcare or elsewhere — can take from it.

Preliminary note ahead of MCVA Cahier No. 3, dedicated to the healthcare sector, to be published in the first quarter of 2027.

Where is AI already established in Swiss healthcare?

Three areas have moved beyond the experimental stage into the everyday practice of institutions and companies in the sector.

AI-assisted medical imaging analysis is the most mature. In radiology, dermatology, and ophthalmology, diagnostic support systems built on deep learning are being tested, integrated, or deployed in certain hospital settings. Their status deserves precise framing: an automated second opinion that flags elements for the practitioner to examine without replacing their clinical decision. The scientific literature documents high performance on specific detection tasks — performance that holds under study conditions and does not extrapolate mechanically to every practice.

Administrative management is the second area, and the strongest economic argument for adoption. Transcribing consultations into structured reports, assigning diagnostic codes, optimizing schedules and resources: repetitive, high-volume tasks with no direct clinical risk, absorbed by generative systems. The time returned to care staff is the most tangible and most quickly measurable benefit.

Support for clinical research completes the picture, especially in the pharmaceutical industry and university centers: large-scale literature analysis, identifying trial candidates from anonymized records, accelerating molecule screening. These uses operate at a level where an isolated error is caught by downstream scientific validation — a property of design, not chance.

Three layers of rules — and a more predictable terrain than before

Since September 1, 2023, the revised Federal Act on Data Protection (FADP) classifies health data among sensitive personal data, subject to reinforced protection: any processing by an AI model requires explicit consent, documented irreversible anonymization, or a specific legal basis[1]. The law also governs automated individual decisions and imposes information obligations in relevant cases.

Added to this is the European Artificial Intelligence Act, being phased in progressively since 2024, which classifies medical devices incorporating AI among high-risk systems — reinforced technical documentation, conformity assessment, risk management, post-market surveillance[2]. Any Swiss company exporting to or addressing the European Union market must build this framework into its development cycle from the start. Swissmedic, finally, is progressively harmonizing its requirements with international standards: medical devices incorporating AI go through applicable conformity procedures before market entry, and the authority is involved in surveillance[3].

The result of this stacking surprises those who don't work with it: the environment is more demanding than it was five years ago, but also more predictable. Players who build compliance into the initial scoping deliver devices that actually get deployed; those who treat it as an end-of-project obstacle pay for costly catch-up. I see this as the most transferable lesson of the entire sector.

Where does patient data go?

The question of sovereignty arises here with particular sharpness: where is the data stored, and under what law? Systems hosted on American clouds expose data to extraterritorial law that can conflict with Swiss protection requirements.

Three operational answers exist. Hosting with providers established in Switzerland, whose offering has expanded since 2020. Deploying open-weight models on controlled infrastructure, which has become realistic for reasonably sized models with useful performance. Finally, federated learning — training models without centralizing data: each institution keeps its own, only the model's parameters circulate — still marginal but actively explored by several Swiss university hospitals. None of these paths is superior in every situation; each has its costs, its performance limits, and its technical requirements. The choice comes down to a risk qualification by use case — the same sovereignty framework I describe, outside healthcare, in the architecture of a well-built AI project.

What technology doesn't solve

Three points of vigilance run through the practice, and none is settled by a simple model improvement:

  1. Algorithmic bias — models trained on historical data that underrepresent certain populations reproduce these blind spots; correction requires diversifying data, validating by subpopulation, and being transparent about the scope of validity.
  2. Medical liability — the majority position in Swiss law keeps the physician as the final decision-maker, bearing clinical responsibility; comfortable for the experienced practitioner, demanding for one who lacks the time or distance to weigh an algorithmic recommendation.
  3. Patient trust — it is built on informing the patient when AI intervenes in their care pathway, and on the quality of the caregiver-patient relationship, which no algorithm replaces.

What can an SME outside healthcare take from this?

I am not a specialist in the medical sector; I read this terrain as an AI practitioner, drawing on published frameworks and documented practice — and Cahier No. 3 will draw on a co-author from the sector. But if I summarize what Swiss healthcare demonstrates to any executive in a regulated environment, three transfers stand out.

First, start where the risk is low and the volume is high: healthcare embedded AI in administrative work — transcription, coding, scheduling — long before touching the clinical core. Every regulated SME has its equivalent: the back office before the sensitive core business. That is exactly the order of priority I apply in my tailor-made automation solutions.

Next, treat compliance as an input to scoping, never as a final step. The devices that get deployed are the ones that built in the FADP, sector requirements, and data localization before the first line of code — a reflex I systematize in every project I build, regulated or not.

Finally, keep the human decision-maker in the loop on anything that engages the company's liability. The "automated second opinion" model — AI flags, human decides — is the configuration that moves through regulatory frameworks without friction, and it's almost always the right first step. To place these choices within a complete approach, see What should a Swiss SME do about AI in 2026?.

Key takeaways

— AI is already routine in Swiss healthcare — imaging as a second opinion, administration, research — proof that a strict framework selects projects without blocking them. — Since September 2023, the FADP classifies health data as sensitive: explicit consent, documented anonymization, or a legal basis — and the AI Act adds its own requirements for anyone targeting the EU. — The transfer for any regulated SME: back office first, compliance built into scoping, a human decision-maker on anything that engages liability.

FAQ

Can AI make a medical diagnosis in Switzerland? No. Deployed systems function as diagnostic support: they flag elements for review, and the physician remains the final decision-maker, bearing clinical responsibility. This "automated second opinion" configuration is the one Swiss law and hospital practice recognize today.

Can a practice or clinic use a consumer AI tool with patient data? Not by default. Health data is sensitive personal data under the FADP: its processing requires explicit consent, irreversible anonymization, or a specific legal basis — conditions a consumer tool hosted abroad generally does not meet. Alternatives exist: Swiss hosting, or open models on controlled infrastructure.

Does the European AI Act apply to Swiss companies? Yes, as soon as they export to or address the European Union market. Medical devices incorporating AI are classified there as high-risk, requiring technical documentation, conformity assessment, and post-market surveillance. Building it into the development cycle costs far less than catching up later.

Where should you start in a regulated sector, healthcare or otherwise? With low-risk, high-volume administrative uses — transcription, filing, scheduling — with compliance built in from the scoping stage and a human decision-maker at the end of the chain. This first step produces measurable gains and builds the maturity needed for more sensitive uses.

Do you operate in a sector under regulatory constraint? The AI Usage Diagnostic: sixty minutes to map your actual workflows, identify what deserves a tailor-made approach, what stays in SaaS, and what doesn't need AI at all. Book a diagnostic

Sources

[1] Federal Act on Data Protection (FADP), revision of September 25, 2020, in force since September 1, 2023. www.fedlex.admin.ch/eli/cc/2022/491/fr []

[2] European Parliament, EU AI Act: first regulation on artificial intelligence. www.europarl.europa.eu/topics/en/article/20230601STO93804/eu-ai-act-first-regulation-on-artificial-intelligen []

[3] Swissmedic, Aperçu des dispositifs médicaux. www.swissmedic.ch/swissmedic/en/home/medical-devices/overview-medical-devices.html []


Jérôme Deshaie is CEO and founder of MCVA Consulting SA, an augmented agency based in Valais. Fifteen years serving major international brands, now working directly for Swiss SMEs. Background.

Related articles