Research notes on AI governance, written for Switzerland
Short analytical pieces on the FADP, GDPR, the EU AI Act, and what actually breaks when enterprises deploy AI systems. Written for people who have to make the decision and live with it, not for people writing about it.
All notes
-
When the Builders Ask for Brakes: What the Amodei–Altman–Musk Alignment Means for Governance
Anthropic, OpenAI, and Elon Musk have publicly converged on the same warning: AI capability is outpacing anyone’s ability to control it. Not everyone reads that alignment as good-faith safety concern.
-
When the tool you trust becomes the competitor
A proof made the headlines. The more durable story is that two sophisticated users spent a year putting unpublished work into a vendor’s tool without a verified answer to whether the vendor could read it.
-
The EU AI Act wasn’t delayed. Read the fine print.
The high-risk deadline moved. Almost nothing else did. The obligations that apply to nearly every organisation using AI have been in force since August, and the same instrument added a new prohibition.
-
“We follow GDPR” is the wrong starting sentence for a Swiss deployer
Most Swiss AI governance documents open by invoking GDPR. That single framing choice misstates which statute has jurisdiction, and everything built on top of it inherits the error.
-
Permissions don’t survive ingestion, and a checklist isn’t readiness
Two failures recur across enterprise AI deployments, independent of vendor, model or industry. Both look fine until the moment they don’t, and neither can be fixed by adding a policy document.