Industries / Public administration · federal, cantonal & municipal
AI protection for the public sector. Protect your staff's AI usage.
Nearly every Swiss public office has an AI directive, "Copilot only with public data" is typical. Hardly any has a technical control layer that enforces it. Citizen data deserves more than a rule on paper.
The Swiss Science Council (the Federal Council's advisory body) has named the gap in its working paper "AI in Higher Education: SSC considerations and recommendations" of 2 June 2026: AI is entering institutions faster than governance can adapt, enforcement is missing, and responsibility is spread across IT, legal and data protection. It names digital sovereignty as one of its eight guiding principles for a national AI infrastructure. NativeAI Guard is exactly that control layer, ready for use today, while the national framework is still years away.
The AI governance framework for the public sector
Five obligations. Here's our part, honestly.
We mark what NativeAI Guard solves for the channels we protect, where it contributes, and what stays with your processes.
Seen in Swiss administrations
A federal authority permits Copilot for public data only. Whether an employee pastes a case file instead is, today, a matter of trust, not of technology.
A four-language administration means DeepL and other translation tools are daily infrastructure, rulings, citizen correspondence, internal reports. Whole documents leave the office, and nobody classifies a translator as an AI risk.
The scenario cantonal CISOs name first: chained AI systems making decisions about citizens with no person in between, and the Air Canada ruling showing that courts hold you to what your chatbot says.
There is an internal rule that employees may only use Copilot with public data. There is no technical control layer enforcing it.
Policies, managed
The rulebook for public institutions is already written. You adapt it instead of inventing it.
A base rulebook is already written and active from day one: the rules from the Swiss DSG, GDPR and the EU AI Act, plus the requirements your industry is specifically subject to. It covers the standard cases without you writing a single line. Security and compliance practitioners review it, and we keep it current as the law changes. On top of it sit the rules that apply only to you: your own data structures, your internal requirements, your exceptions.
During onboarding we tune the pack to your own data structures and internal rules, working from the compliance documents you already have.
Common questions
Frequently asked questions
We have an internal directive saying AI may only be used with public data. Is this not already solved?
A directive is a rule on paper; what is usually missing is the technical control that enforces it. In practice, nobody can currently tell whether a case file was pasted into a chatbot, and the directive is honored on trust. NativeAI Guard turns the written rule into an enforced one, at the moment the prompt is sent, with a record afterwards. This gap was described to us in almost identical words by security leads at a federal agency and a cantonal administration.
Our concern is AI systems talking to other AI systems with no person in between. Does that fall within scope?
Yes, and it is the harder half of the problem. Where an internal agent calls an external model directly, the browser is not involved and no human reviews the exchange. The API proxy inspects that traffic in both directions and enforces human-review checkpoints where your policy demands them, which turns an accountability principle into something you can evidence.
Public procurement is slow, and we cannot set up a large consulting project. How do we start?
With a pilot phase that we fully manage: one month, we run it, no changes to workflows, and the result is a report on data leaks, shadow AI and AI usage that goes to your management. It is deliberately sized to stay under most direct-award thresholds and to produce the evidence a formal procurement needs, rather than requiring that procurement first. The product is standard software with configuration, not a bespoke build.
Protect your staff's AI usage, with a pilot phase that we run for you.
A report for your management on data leaks, shadow AI, AI usage and model costs, which can start before formal procurement begins. Off-the-shelf, Swiss-hosted. Data stays in Switzerland, under Swiss law, on the servers of a Swiss company.