Transparency on the use of artificial intelligence for eIAM incl. AGOV
Status as of August 2026: Artificial intelligence (AI) is now a widely used tool in software development and content creation. Particularly in the case of a government authentication service, it is important to distinguish whether AI is used as an aid in the creation of software or content or whether it is part of the system in operation, processes personal data or influences login processes. This article provides transparency on how AI is used for eIAM incl. AGOV, where it is currently not used and according to which principles any future use would be assessed.The essentials at a glance
- In the eIAM incl. AGOV core system considered here, AI is currently not used to process personal data.
- AI is currently not used to assess or carry out eIAM incl. AGOV login processes.
- AI may be used as an aid in software development, quality assurance and security testing. Responsibility remains with the people and organisations involved.
- AI may be used extensively in the creation of texts, images, audio and video content relating to eIAM incl. AGOV. The Federal Chancellery is responsible for the content it publishes, regardless of the tools used to create it.
- eIAM incl. AGOV authenticates natural persons, not AI agents. These persons may act towards target systems on their own behalf or in an organisational context. eIAM incl. AGOV does not determine which rights and legal effects are associated with this.
- The distinction between AI as a tool used in the creation process and AI as an operational component of the eIAM incl. AGOV system during runtime is crucial.
Purpose and legal framework
The use of AI takes place within the applicable law and the requirements applicable to the Federal Administration. In this article, the term AI is used in accordance with the AI terminology of the Federal Administration. An AI system is therefore a machine-based system that, based on received inputs, derives how to generate outputs such as predictions, content, recommendations or decisions. Not every form of automation and not every algorithm therefore constitutes an AI system. As of the date of this article, Switzerland has no overarching legislation specifically governing AI. Nevertheless, the use of AI does not take place in a legal vacuum: existing law applies regardless of the technology used. In particular, the Data Protection Act is technologically neutral and directly applicable to AI-supported processing of personal data. Depending on the specific use, additional information, transparency or other legal obligations may apply. For the Federal Administration, the strategy on the use of AI systems in the Federal Administration also provides the overall direction. AI systems are to be used responsibly; in particular, the applicable requirements concerning the law, information security and data protection must be complied with. With this article, the Federal Chancellery provides transparency on the specific situation regarding eIAM incl. AGOV. This general description does not replace any information or other obligations that may arise from a specific use case.What this article covers
To ensure that statements about the use of AI are clear, the scope under consideration is clearly defined.For the purposes of this article, the eIAM incl. AGOV core system includes in particular:
- the eIAM incl. AGOV accounts and the functions associated with them;
- the connections of authorities and their applications to eIAM incl. AGOV;
- the mechanisms for authentication and for carrying out the actual login processes.
This delimitation defines solely the subject matter of this article. It does not alter any legal responsibilities, areas of competence or supervisory obligations.
AI in the processing of personal data in the eIAM incl. AGOV core system
Within the eIAM incl. AGOV core system defined above, AI is currently not used to process personal data. This statement is deliberately precise. eIAM incl. AGOV naturally processes personal data and uses software, algorithms, cryptographic procedures and automated processes. However, automation and algorithmic processing should not be equated with the use of artificial intelligence. If AI were to be used in the future within the eIAM incl. AGOV core system to process personal data, the legal requirements and, in particular, the requirements relating to data protection, information security, transparency and proportionality would have to be assessed before its introduction.AI in eIAM incl. AGOV login processes
AI is currently not used either for the actual authentication or for the assessment of an eIAM incl. AGOV login process. This could change with technological developments. For example, methods could be envisaged that combine different technical signals from a login process to increase security, detect anomalies or assess their plausibility. Such use would have to be assessed fundamentally differently from the use of AI as a development tool. If an AI system were to perform an assessment during a productive login process and that assessment influenced whether a login was permitted, prevented or made subject to additional checks, the AI would be an operational component of the eIAM incl. AGOV system during runtime. Before such an introduction, the legal and data protection requirements, information security, traceability, proportionality, potential discrimination risks and the impact on digital sovereignty would need to be assessed in particular. Depending on the specific design, the data protection provisions on automated individual decisions could also be relevant.AI in the development of eIAM incl. AGOV source code
eIAM incl. AGOV is developed under the responsibility of qualified specialists. AI may be used to provide support, like other development tools.Possible areas of use include, for example:
- generating source code suggestions;
- analysing and reviewing existing source code;
- supporting testing and documentation;
- searching for errors or vulnerabilities;
- other development and quality assurance tasks.
Source code generated or proposed by an AI does not acquire any special status as a result. The same requirements concerning quality, security, verifiability and third-party rights apply to it as to source code created in other ways. Responsibility is not transferred to the AI system used. It remains with the people and organisations responsible for development, delivery, testing and acceptance. AI is also relevant to IT security. AI-supported tools may be used as part of authorised security testing, for example in penetration tests or bug bounty activities. At the same time, attackers may also use such tools. The continued development of security measures must take this technological development into account. Regardless of the tool used, the applicable requirements concerning information security, data protection, confidentiality and third-party rights apply when handling information and source code.
AI in texts, images, audio and video relating to eIAM incl. AGOV
AI is an important aid in the creation and processing of communication content relating to eIAM incl. AGOV.This includes, for example:
- drafting, structuring and revising texts;
- translating and linguistically harmonising multilingual content;
- creating and editing illustrations and images;
- generating and editing speech and audio;
- creating and editing videos.
Individual work steps can be extensively supported by AI. Content may also have been created largely or entirely with the help of generative AI. Responsibility for the content and its publication remains with the Federal Chancellery and the responsible persons, regardless of the production process.
The following requirements are particularly important for official eIAM incl. AGOV content:
- lawfulness;
- factual accuracy;
- currency;
- comprehensibility;
- consistency;
- correct and equivalent multilingualism;
- low barriers and accessibility;
- respect for third-party rights;
- suitability for the respective communication purpose.
AI for end users and AI agents
eIAM incl. AGOV authenticates natural persons. These persons may act towards a target system on their own behalf or in an organisational context. An eIAM incl. AGOV account represents the natural person. Whether this person is authorised to act for a particular organisation, which role or authorisation they have and what legal effect an action has is not determined by eIAM incl. AGOV, but results from the relevant legal and professional context and the target system. eIAM incl. AGOV does not provide independent authentication for autonomous AI agents. The authentication means required for an eIAM incl. AGOV login are assigned to the natural person. After a successful eIAM incl. AGOV login, the situation may be different. End users may – insofar as the target system concerned permits this technically and legally – use AI tools or AI agents to process content or use functions of an e-government service. This generally takes place after the eIAM incl. AGOV login and within the respective target system. Whether and under what conditions automated actions, delegations or AI agents are permitted there is the responsibility of the respective target system and the competent authority. In this context, eIAM incl. AGOV authenticates the person. It does not determine what significance a target system assigns to any subsequent use of AI.AI as a tool or as part of the system
A fundamental distinction is particularly important when classifying the use of AI in eIAM incl. AGOV. Today, AI is used for eIAM incl. AGOV primarily as a tool in the creation or review of products and artefacts. This may include source code, tests, texts, images, audio or video. The result of such an activity may subsequently become part of eIAM incl. AGOV without the AI system used for this purpose itself becoming part of the eIAM incl. AGOV system in operation. An example illustrates the difference: if a programme component is created with the support of an AI model, subsequently reviewed and integrated into eIAM incl. AGOV, eIAM incl. AGOV does not need this AI model to operate that programme component. If, on the other hand, an AI system were used during a login process and its assessment influenced the further course of the login, this AI system would be part of the ongoing service provision. As of today, AI is not an operational component of the eIAM incl. AGOV core system during runtime within the system boundary considered here. This distinction is particularly important for data protection, information security, accountability and digital sovereignty.AI and digital sovereignty
Artificial intelligence is neither digitally sovereign nor digitally non-sovereign in itself. What matters is how a specific AI system is used, what dependencies arise as a result and the extent to which control, verifiability, the ability to switch and the ability to act are retained. For a general assessment of the digital sovereignty of eIAM incl. AGOV, see also the article “To what extent is eIAM incl. AGOV digitally sovereign?” at agov.ch/dCreation dependency and operational dependency
When using AI, a distinction must also be made between a dependency in the creation process and a dependency in operation. If an externally offered generative AI model is used, for example, to support the creation of a text, an image or source code, this does not automatically create an operational dependency of the eIAM incl. AGOV core system on that model. In principle, the resulting output can be reviewed, stored, further processed and operated independently of the original tool.Such use may nevertheless create other dependencies and risks, for example:
- dependencies on specific tools or skills in the development process;
- a possible leakage of information to external providers;
- questions concerning confidentiality and data protection;
- questions concerning rights to inputs and outputs;
- requirements concerning traceability of the creation process;
- dependencies on a provider or its legal and contractual framework;
- restrictions on the ability to replace one tool with another.
The use of AI as a creation tool is therefore not automatically sovereign or non-sovereign. The specific design is what matters. An operational dependency would be much more direct if an AI system were required during ongoing operation, for example if login processes depended on a continuously provided AI assessment. Such use would raise questions in particular concerning availability, control, data sovereignty, interchangeability and resilience. The use of an internationally offered AI service as a creation tool does not in itself create an operational dependency of the eIAM incl. AGOV core system. What matters are the information actually processed, the dependencies that arise and the ability to continue providing the services required for eIAM incl. AGOV in a controlled, secure and independent manner without relying on the AI service concerned.
Further development
AI and its possible uses are developing rapidly. At the same time, the legal framework is also evolving. As of August 2026, the Confederation is preparing a consultation draft for the implementation of the Council of Europe’s AI Convention. Legislative measures are planned in particular in the areas of transparency, data protection, non-discrimination and supervision. The role of AI for eIAM incl. AGOV may therefore also change. The fundamental distinction nevertheless remains clear: there is a difference between AI supporting people in development, review and communication and an AI system itself becoming a productive component, processing personal data or influencing a login process.This article describes the status as of August 2026. Significant changes in the use of AI within the eIAM incl. AGOV core system should be made traceable in this description.