> Quelle: https://souverana.ch/en/insights/ki-governance/
> Sprache: en

# AI governance: one page is enough to start

A policy that takes three months to finish protects no one today. Shadow AI grows for exactly as long as the document keeps maturing.

Template · Published 4 Aug 2026 · Updated 24 Aug 2026 · Joel Barmettler

## What belongs in AI governance?

**AI governance only helps once it is in force, and one page is enough for that. It consists of three parts: a policy stating which tool may be used with which data, a responsible person per tool, and a way to report doubtful cases before use.**

**In brief**

-   Budget an afternoon for the first draft. The weeks after that go into reviewing the provider contracts, not into writing.
-   Purchased software also contains AI features that nobody ever approved. They belong in the table with a line of their own.
-   If nobody wants their name in the table for a tool, the company apparently does not need it. That, too, is a useful outcome.
-   Without a date on the page, you cannot show in a dispute which version applied. Put one on it.

One client had made AI governance a matter for top management: its own focus group, fixed meetings, high priority. Every meeting added a chapter that nobody had missed before. Months later, nothing exists that an employee could read, and the work has long since moved to personal accounts. Shadow AI? grows for as long as the document keeps maturing. An unfinished page that is in force today protects better than a complete one arriving in three months.

This is the fourth part of our Law & Regulation series, and the most practical one: the obligations from the other parts turn into one page that applies in daily operations.

Series · Law & Regulation

1.  1[AI regulation in Switzerland: what already applies](/en/insights/ki-regulierung-schweiz/)
2.  2[revFADP and AI: what the law actually requires](/en/insights/revdsg-ki/)
3.  3[Professional secrecy and AI: what may go to the cloud](/en/insights/berufsgeheimnis-cloud/)
4.  4AI governance: one page is enough to startYou are reading this part
5.  5[EU AI Act Switzerland: role first, then duties](/en/insights/eu-ai-act-schweiz/)

## What belongs on the one page

The core is a table. It answers the question an employee actually has: am I allowed to enter this here?

Before that, you need three data classes, no more. **Public** is anything that could also sit on your website. **Internal** is the normal case: quotes, minutes, source code with no customer link. **Especially sensitive** covers health, HR and client-mandate data, plus anything subject to a duty of confidentiality. Anyone who sets up four or five levels invites boundary questions that nobody answers in daily practice.

| Tool | Approved data | Owner |
| --- | --- | --- |
| Chat tool, business tier | public, internal | Name |
| Translation service, signed in | public, internal | Name |
| Coding assistant | public, internal | Name |
| Line-of-business app with AI feature | per contract | Name |

Add four rules, and daily use needs nothing more. Approved tools only, [company account only↗](/en/insights/souveraene-ki-plattform/), only with the data approved for it. Check results for accuracy, because responsibility for your own work stays with you. Create transparency wherever third parties need to know. And report what goes wrong, even where it could be quietly fixed: whoever quietly fixes a case makes sure the next person makes the same mistake.

Evidence

Souverana did not invent the one-pager. The Zurich law firm VISCHER has published its template policy as a one-pager for free use since 2024, in German and English, explicitly as a minimum set of rules meant to be extended later. In the revised 2025 version, it trimmed the ground rules down to what applies to employees without a special role.

## How to staff the owner role

The column on the far right says who answers when there is a question. This person knows the contract, sets the approved data classes and keeps them updated when the provider changes something.

The owner rarely sits in IT. They sit wherever the benefit accrues: the translation service with marketing, the coding assistant in development, the AI feature in the ERP with whoever already manages the ERP. Whoever gets the benefit has to propose and carry it. The specialist units advise and lay out the risks; sign-off happens wherever the policy itself is issued.

This role also makes clear who the acting person is if things go wrong. Why that matters is explained in our [revFADP guide](/en/insights/revdsg-ki/): the criminal provisions of the data protection act reach the acting person inside the company. The data-protection obligations themselves stay with the company.

## When someone asks

A policy cannot anticipate every future use case. The five questions on which a project can stall, together with the reasoning behind them, are set out in the [regulatory map](/en/insights/ki-regulierung-schweiz/).

For the policy, what matters is what follows a yes. Three details are enough: who the question goes to, by when it gets answered, and where the decision is recorded. Without them, people keep deciding for themselves, just with a worse conscience.

The response time is the part most likely to be forgotten. Anyone waiting weeks for approval reaches for a personal account in the meantime. Set a deadline your point of contact can keep even in a busy week, and name a deputy.

## What you can leave out

Statements of principle on responsible AI use are well-intentioned and dispensable at the start. Much of what is in them is binding anyway through the revFADP?, copyright law and your existing contracts. What goes beyond that is a deliberate self-commitment. A dedicated set of values pays off once the policy is in place.

Much the same applies to training. Anyone falling under the EU AI Act has had to do something for their people’s AI literacy since 2 February 2025. The AI Omnibus replaced Article 4 in July 2026 and softened the duty: the measures to take are ones that support the development of AI literacy, with no guaranteed level required for anyone. For a Swiss company with no EU connection, training is therefore a question of work quality.

## How to get started

1.  01
    
    Write down the data classes
    
    The three levels from above, each with one example from your own company. This is the basis for column two.
    
2.  02
    
    List the tools
    
    Whatever is already in use today, including the AI features in purchased software. One owner per line.
    
3.  03
    
    Put the page into force
    
    With a date, the issuing body and a point of contact. Empty rows are allowed: whatever is not in the table is not approved.
    
4.  04
    
    Update it after a year
    
    Contracts, reported incidents, tools added since.
    

Want the policy and the approvals set up properly once, instead of negotiating them for months?

[AI Governance & Training](/en/leistungen/ki-governance/)

The legal grounding behind this one page is set out in the other parts of the series: the [regulatory map](/en/insights/ki-regulierung-schweiz/), the [revFADP guide](/en/insights/revdsg-ki/), and the [article on professional secrecy](/en/insights/berufsgeheimnis-cloud/).

The author

![Portrait of Joel Barmettler](/_astro/joel-barmettler.CGKHGWrV_sJ0IG.webp)

Joel Barmettler

AI Architect · Souverana, Zurich

Joel Barmettler guides Swiss companies from AI strategy to integration: sovereign, confidential and production-ready. He built the Swiss AI Hub as its architect and today co-owns its architecture; he personally leads every Souverana mandate. Mandates from one-person firms to Fortune 500 corporations.

[Book an intro call](https://meet.brevo.com/joel-barmettler/30-minute-meeting) [More about Souverana](/en/) [LinkedIn](https://www.linkedin.com/in/joel-barmettler-b9ab361b7)

## Frequently asked questions

What belongs in an AI policy?

Three things: which tools may be used with which data classes, who in the company is responsible for each tool, and four ground rules for daily use. Add a way for employees to report a doubtful case. One page is enough for that.

How long does it take to set up AI governance?

Budget an afternoon for the first draft, once the data classes and approved tools are settled. What takes real effort afterwards is reviewing the provider contracts. Delay almost always comes from a single cause: the document is meant to cover a little more at every meeting.

Who decides whether an AI tool gets approved?

The person who wants to use it and is accountable for it. Legal, data protection and security advise and lay out the risks. Without a named responsible person, a tool should not go into productive use.

Does my company need AI ethics principles?

Not to start with. Much of it is already binding through the revFADP, copyright law and your existing contracts. What goes beyond that is a deliberate self-commitment. A dedicated set of values pays off once the policy is in place and you have some initial experience.

Do we need to train employees in using AI?

Anyone falling under the EU AI Act has had to do something for their people's AI literacy since 2 February 2025. The AI Omnibus replaced Article 4 in July 2026 and softened the duty: measures that support the development of AI literacy, with no guaranteed level for anyone. For Swiss companies with no EU connection, training is a question of work quality.

LinkedIn

## Share this article

Ready-formatted graphics and a suggested post for your LinkedIn feed: download, copy, post.

![An AI policy as a one-page diagram with four sections: three data classes, a table with tool, approved data and owner, four ground rules, a point of contact with a response time. Callout: shadow AI grows as long as the document stays in draft.](/media/ki-governance-en/infografik.png)

[Download infographic (PNG)](/media/ki-governance-en/infografik.png)

Suggested post

How long has your AI policy been sitting in draft?

We see the same pattern again and again: the document grows by one chapter at every meeting, a chapter nobody had missed before. Meanwhile employees keep typing their work into personal accounts, where the company has neither a contract nor control over the data.

The core of a policy fits on one page: three data classes, a table with tool, approved data and a responsible person, four ground rules, and a point of contact with a response time. An afternoon is enough for the first draft, once data classes and tools are settled. The weeks after that go into reviewing the provider contracts, not into writing.

Our conclusion: an unfinished page that takes effect from Monday protects more than the complete document in month three. Two details decide more here than any extra chapter: a named person per tool, and a date on the page.

The article carries the policy as a fillable template, plus the companion sheet with the five questions to ask before every new use case, and the list of what is deliberately left for later. Link in the comments.

#AIGovernance #Compliance #AI #Switzerland
