AI risk · framework · training
AI risk: framework, concept and training for your company
What will legally apply to AI is still open in Switzerland. A lot can still be prepared cleanly: a framework that orders risks from the top down, evidence that holds up, and a team that works with it. I provide the concept and templates, train your team and support the build-up. Your company runs the solution itself and makes its own release decisions.
| Counter-example | T01 | T02 | T03 | T04 | T05 | T06 | T07 | T08 |
|---|---|---|---|---|---|---|---|---|
| Candidate | Leakage: passed | Sensitivity: passed | Subgroups: passed | Robustness: passed | Direction: passed | Calibration: passed | Repeatable: passed | Automation: passed |
| Leakage | Leakage: red | Sensitivity: passed | Subgroups: passed | Robustness: passed | Direction: passed | Calibration: passed | Repeatable: passed | Automation: passed |
| Wrong labels | Leakage: passed | Sensitivity: red | Subgroups: red | Robustness: red | Direction: red | Calibration: red | Repeatable: passed | Automation: red |
| Subgroup bias | Leakage: passed | Sensitivity: red | Subgroups: red | Robustness: red | Direction: red | Calibration: red | Repeatable: passed | Automation: red |
| Sign error | Leakage: passed | Sensitivity: red | Subgroups: red | Robustness: passed | Direction: red | Calibration: red | Repeatable: passed | Automation: red |
| Too cautious | Leakage: passed | Sensitivity: passed | Subgroups: passed | Robustness: passed | Direction: passed | Calibration: red | Repeatable: passed | Automation: red |
| No seed | Leakage: passed | Sensitivity: passed | Subgroups: passed | Robustness: red | Direction: red | Calibration: passed | Repeatable: red | Automation: passed |
| Unpruned tree | Leakage: passed | Sensitivity: passed | Subgroups: red | Robustness: red | Direction: red | Calibration: red | Repeatable: passed | Automation: red |
Demo on toy data, no statement about any customer system.
- 8
- Demo: checks as code
- 7 of 7
- Demo: broken models rejected
- 20 of 20
- Demo: seeds with the same result
- 19
- tests green (pytest)
What I offer
-
Framework and concept
Roles, risk classes, release process and evidence: the scaffolding your company uses to place its AI systems.
Read more Framework and concept -
Risk assessment: method and template
From harm to test in seven steps. Your team applies it to its own systems.
Read more Risk assessment: method and template -
Proof as code: an example
An example test rig showing what evidence can look like. Your company builds its own with its own data.
Read more Proof as code: an example -
Preparing for an open legal situation
EU AI Act and Swiss law with date and sources, plus what can already be prepared cleanly.
Read more Preparing for an open legal situation
Proof instead of claims
“The AI is safe” only becomes a statement when numbers stand behind it. That is the idea behind the framework.
- “Safe” applies to one system, one area of use and one version, with numbers. Not as a label.
- Risk first, then the test, then the claim. Never the other way round.
- Tests are code: versioned, repeatable, and a red test stops the release.
- A test rig must be able to fail itself. So it is tested against models broken on purpose.
- What is not measured is not claimed. Too little data means: out of scope.
Who this is for
- Companies introducing or already using AI that want to build their own framework instead of waiting for a ready-made rule. My background is quality management in regulated industries (ISO 9001, ISO 13485 for medtech, ISO 27001, Swiss data protection law).
- Software companies with AI features whose team wants to structure checks beyond accuracy.
- SMEs where AI drafts mails, quotes or reports and a person approves. That approval can be placed in the framework too.
What I do not do
- I do not assess every single AI system and do not formally accept any system. Testing and release stay with your company.
- I do not certify and I do not give legal advice. That belongs to certification bodies and to lawyers.
- I offer an analysis of individual systems only as an addition, on request and without acceptance.
What proof looks like
The “Proof as code” page runs an example test rig: eight checks, one good candidate, seven models broken on purpose. You see the code, the raw output and the limits of the demo, as a template for how your team can build its own.
Answers
How do I prepare for AI rules while the legal situation is open?
What can be prepared is a framework that holds regardless of the future legal situation: an inventory of AI systems, an owner per system, a risk classification from the top down, data rules, a release with evidence and monitoring in operation. That needs neither a law nor a certificate. Which duties apply later is for your lawyer to decide.
What is an AI risk assessment?
An AI risk assessment links possible harm to an AI system, describes how it could arise, and fixes what catches it and how that is tested. The method works top down: harm, hazard, failure mode, control, test, evidence. The likelihood comes from tests, not from a guess.
How do you show that an AI is safe enough?
An AI counts as sufficiently evidenced for an area of use when tests as code show it with numbers and an upper failure bound. The statement always applies to one system, one area of use and one version. What cannot be shown is taken out of scope or caught with controls outside the model.
What is the difference between verification and validation for AI?
Verification checks that an AI system meets the specified requirements, validation checks that it is fit for its intended use. Verification means tests against acceptance criteria, validation means use with real users and monitoring in operation. Both need criteria that are fixed before the first test.
What does the EU AI Act mean for Swiss companies?
The EU AI Act can affect Swiss companies that offer AI systems in the EU or whose results are used in the EU. After the Digital Omnibus, the duties for high-risk systems under Annex III apply from 2 December 2027. Whether and how that applies to your company is for your lawyer to decide.
Does Switzerland have an AI law?
Switzerland does not yet have its own AI law, as of 6 October 2026. The Federal Council wants to adopt the Council of Europe AI Convention, a consultation draft is due by the end of 2026, and the Data Protection Act (DSG) already applies. What that means for your project is for your lawyer to decide.
Do you assess individual AI systems or formally accept them?
No, not as a rule: I provide framework, concept, templates and training, and your company tests and releases its own systems. I offer an analysis of individual systems only as an addition, on request and without formal acceptance. Certification and legal advice are not part of my offer.
What does working together cost?
My day rate is CHF 1200, billed by effort; this is a price indication, not an offer. Scope and price are in a quote that you confirm. What your project needs we clarify in the first call.
Contact
Send me the use case in two sentences. I will get back to you and say whether and how your project can be tested. Whether I can take the job depends on my workload.