Cyber Security

Business secrecy and AI: the guide for a Swiss fiduciary firm

By, zero-adm
  • 15 Sep, 2026
  • 4 Views

AI is already inside fiduciary firms. It didn’t arrive through a partner’s decision. It arrived when an associate pasted the text of a client contract into a free assistant to “clean up a draft.” The question is no longer whether to use it, because firms that abstain hand the advantage to their competitors. The question is how to use it without risking the one thing a firm cannot lose: the trust of the clients who entrust it with their affairs.

This guide is the operational part of that answer.

If art. 321 of the Criminal Code doesn't name you, that's not good news

Switzerland’s criminal professional secrecy binds lawyers, notaries and doctors — and, it should be said, auditors bound to secrecy under the Code of Obligations (art. 730b para. 2 CO): if your firm also holds statutory audit mandates, art. 321 names you on those. A fiduciary who does no auditing, as a rule, sits outside that list, and the sector’s most expensive misunderstanding grows from there: the belief that a lighter regime applies.

The opposite holds. A fiduciary answers to the client under contract, not by exclusion from a criminal provision. Art. 398 CO imposes diligence and loyalty in performing the mandate, and loyalty includes keeping confidential everything learned along the way: figures, contracts, banking relationships, pending disputes, plans the client has not yet announced to anyone. On top of that sits the client’s business secrecy, which protects information of economic value, and the Swiss FADP, which covers the personal data inside the files: employees, counterparties, family members.

Three federal layers and a cantonal one: four separate ways for this to end badly. The client enforces the first through a liability claim. The client enforces the second too, but in criminal court: art. 162 of the Criminal Code punishes with a custodial sentence of up to three years or a monetary penalty anyone who reveals a trade secret they were contractually bound to keep; it is prosecuted only on complaint by the injured party. The Federal Data Protection and Information Commissioner (FDPIC) enforces the third. And in Ticino there is a fourth, cantonal layer nobody mentions: art. 16 of the cantonal Fiduciaries Act (LFid) lets the supervisory authority fine a fiduciary up to CHF 50,000 for revealing a secret learned in that role — even after they stop practising, and without anyone having to sue. Duties to inform the authorities or to testify are reserved.

And when the firm works as an auxiliary to a lawyer on a case, the chain of criminal secrecy reaches the person keeping the books.

How this differs from an ordinary human mistake

An associate who talks too much over lunch exposes one file. A badly chosen AI assistant exposes the content of every file the firm runs through it, unnoticed, for as long as it stays in use. The difference isn’t the severity of a single episode. It’s that the second case leaves the firm no trace of its own: the only traces sit with the vendor, and the firm doesn’t decide what happens to them.

As we documented in the opening article, “local” often describes only how the file is read off the disk. The content gets processed somewhere else, and the distinction is real enough that the big vendors put it on their price lists, as the first check shows.

The six checks, in the order to run them

1. Ask where the content is processed, not where the file sits. Two different servers, and the difference is on the price list: the big vendors sell storage location and processing location separately, and the second doesn’t come with the entry-level plan. Even when it does, it covers GPU execution, not authentication, routing and logging. Get the list in writing: processing servers, storage servers, subcontractors and subprocessors.

2. Read the terms and the privacy policy looking for two words: “third parties” and “improvement.” If your data can be shared with third parties or used to improve the service, your clients’ balance sheets take part in the vendor’s commercial life. That’s one of the clauses that, on 10 February 2026, before federal judge Rakoff in New York (United States v. Heppner, S.D.N.Y.), helped deny attorney-client privilege to 31 documents produced with a consumer-tier AI assistant: for the court, a privacy policy under which the provider collects prompts and outputs, uses them to train the model and reserves the right to disclose them to third parties, government authorities included, rules out any reasonable expectation of confidentiality. It was not the only ground — the first was that an AI is not a lawyer — and the privilege was never lost: it was never established in the first place. In Switzerland the mechanism is different and worse: you don’t lose secrecy, you breach it.

Look for them in the terms and privacy policy of the plan you actually use. In free and personal plans, “third parties” and “improvement” are almost always there; in the big vendors’ business plans the opposite commitment is written into the plan’s contractual terms — but subcontractors and subprocessors are still third parties, and some features (thumbs-up/thumbs-down feedback, for instance) can reopen the door. That’s why checks 3, 4 and 6 are the ones that really tell vendors apart.

3. Check the vendor’s jurisdiction, not the geography of its servers. The CLOUD Act lets US authorities obtain from an American provider the data in its possession, custody or control, wherever it is stored, under a US warrant, court order or subpoena. A Zurich data centre is not enough: if effective control stays with an American company, that is where the request lands. Note: under the Swiss FADP, since 15 September 2024 the United States has been listed among countries with adequate protection, for certified companies. The problem here isn’t data protection: it’s that the CLOUD Act and professional secrecy answer to two different authorities. The decisive question: who holds control, who is accountable, and before which court?

4. Demand a signed contract, not a web page. Data processing terms, place of jurisdiction, list of subcontractors and subprocessors, what happens to the data on termination. If the vendor signs nothing with your firm, your firm holds nothing but a web page on the day a client calls it to account. The FADP points the same way: under art. 9 FADP, processing is assigned to a processor by contract or by law, and only if no statutory or contractual duty of confidentiality prohibits it; para. 3 requires your prior authorisation before the vendor assigns the processing to a third party. The signature, though, is your own demand: the law prescribes no form.

5. Require every answer to be verifiable. An AI that asserts without showing its source forces the fiduciary to trust it, and trusting isn’t the job. Every answer must cite the document and the passage it came from. When the answer isn’t in the documents, it has to say so instead of inventing one.

6. Ask for the access log. Who asked what, when, on which mandate. The day a client asks how AI was used on their documents, the answer must be an export, not a reconstruction from memory.

The checklist to keep in the office

□ I know where file content is processed, not just stored
□ I have read the terms and privacy policy of the plan I actually use, not the marketing page
□ I know the vendor’s jurisdiction and that of its subcontractors and subprocessors
□ I hold a signed contract, with a place of jurisdiction and what happens to the data on termination
□ Every answer cites its source; what is missing is declared missing
□ An access log exists and I can read it

Six yeses and you know what you are actually choosing; if no answer stopped you, the vendor choice holds. The rest of compliance stays yours: the controller answers for it, even when it delegates. That’s why two more boxes concern the firm alone:

□ My client mandate allows me to hand their data to a processor
□ There is a written rule for staff on what never gets pasted into an assistant

The fastest way to check

You can debate checklists for months. Or you bring a real file — only if the client has authorised it, and with an NDA and a data processor agreement signed first, as in check 4 — or an anonymised one. Forty-five minutes, no commercial commitment. Ask the questions you’d ask a first-year associate and watch how many answers cite the document they came from. Then ask for something the documents don’t contain, and watch what happens.

Bring a file. Watch where it goes.

Request the demonstration (page in Italian) · reply within 24 hours · sales@zeroedge.ch

Demos in this phase are reserved for fiduciary and accounting firms. The module for law firms is in development: lawyers who write to us join the waiting list and we call them back when it ships.

ZeroEdge AI · Sovereign AI, made in Switzerland. Processing and storage in Switzerland, a data processor agreement, an access log: the building blocks for FADP-compliant processing.

Cover image generated with AI.