Your business can be based elsewhere. Whether you are still planning the build or already have a working system determines the right starting point.
Who Can Review an AI App or Chatbot for Legal Requirements in Switzerland or the EU?
Legally She Can is a Zurich-based legal consultancy led by Vena Verga-Danemar, a licensed lawyer, legal and business trust engineer, and founder of Legally She Can. For suitable client-facing AI apps and chatbots, the review covers the legal, data-protection, AI transparency, provider, documentation and client-use layer. Legally She Can does not build the software itself.
Within the confirmed scope, the review can address Swiss FADP and GDPR requirements, relevant EU AI Act obligations including Article 50 transparency, client-data use, provider and international-transfer issues, and the legal documentation needed around the AI app or chatbot.
A developer can make the product work. That does not necessarily mean somebody has made the separate legal and data-protection judgment about how the system is intended to be used with clients.
The right starting point depends on where you are in the build: is the AI app or chatbot still being planned or built, or does the actual system already exist?
What kind of AI product is this for?
Client-facing AI apps, chatbots and AI-enabled services designed to interact with clients, users or other people, or to produce something that is used in delivering a service to them.
Still planning or actively building?
Start with the AI Ready Diagnostic: a fixed CHF 395 planning and active-build legal and data-protection review, with your direction and next steps in writing.
Check my Build's Eligibility
Does my business need to be based in Switzerland or the EU?
No. Your business may be based elsewhere. What matters for these services is that the AI app or chatbot is intended for users, clients or other affected people in Switzerland or the EU.
Already built, in testing or live?
Start with AI Ready: a review of the actual built system and the relevant legal, data-protection, transparency, provider, documentation and client-use work.
AI APP AND CHATBOT LEGAL HELP AT A GLANCE
Still Building or Already Built?
Start in the Right Place.
STILL PLANNING OR ACTIVELY BUILDING?
Start with the AI Ready Diagnostic if you are planning the product, preparing to brief a developer, deciding how to have it built, actively developing it, or testing an internal prototype using only fake, dummy or synthetic information.
The Diagnostic is a fixed CHF 395 review that answers one central question: should you keep building this as planned, fix something first, or not continue on the current basis? You receive the decision and your next steps in writing.
Before you pay, you complete a short eligibility check to confirm that the Diagnostic fits the stage and type of project.
ALREADY BUILT, IN EXTERNAL TESTING OR LIVE?
Start with Legally Fluent Founder: AI Ready if the main system has been built and can be demonstrated, external users or clients are testing it, it has been soft-launched or launched, or real client or other external-person information has already been entered into it.
AI Ready works from the actual system rather than the proposed direction. Depending on what is relevant and within scope, the work can include GDPR and Swiss FADP documentation, privacy notices and records, DPIA screening or preparation, AI disclosures and Article 50 transparency wording, provider and international-transfer issues, relevant contractual wording and implementation steps.


What Legal Requirements Can Apply to an AI App or Chatbot?
There is no single legal checklist that applies to every AI app or chatbot. Depending on the system and its intended use, requirements may arise under the EU GDPR, Swiss FADP and EU AI Act, including relevant transparency obligations, as well as other laws that apply to the particular business, use or sector.
The Swiss FADP applies directly to AI-supported processing of personal data, and Swiss data-protection guidance specifically addresses transparency, automated decisions and DPIAs in connection with AI. Switzerland does not currently have one overarching AI-specific law equivalent to the EU AI Act, although further AI legislation is being developed.
For a founder, the question is therefore not only “Does the technology work?” It is also “Does the legal setup fit what I actually intend to do with this system?”

Can Legally She Can Help With EU AI Act Compliance for an AI App or Chatbot?
Yes, for the EU AI Act questions within the confirmed scope of these services. For client-facing AI apps and chatbots, the review can consider whether relevant AI Act obligations apply, including where relevant the business's role as a provider or deployer and whether Article 50 transparency requirements are engaged
The review can also flag when the intended use may point toward a prohibited, high-risk or regulated use that needs a different or additional specialist assessment. Legally She Can does not provide full high-risk AI conformity assessments, CE marking or technical AI-safety testing.
Does My AI Chatbot Have to Tell People That It Is AI?
Sometimes, yes. Article 50 of the EU AI Act requires providers of AI systems intended to interact directly with people, subject to its exceptions, to ensure that people are informed that they are interacting with an AI system unless this is already obvious in the circumstances.
Swiss data-protection guidance also addresses transparency where intelligent language models communicate directly with users. But the legal question is not solved simply by adding “This is AI.” What is required depends on the actual system, how it is used and the legal role of the business.
Can I Use Client Data in an AI App or Chatbot?
Possibly. Using client information in an AI system is not automatically prohibited, but it should not be treated as automatically acceptable either. Where personal information is involved, GDPR or the Swiss FADP may apply depending on the circumstances, and using an outside developer, platform or AI provider does not remove the business's own data-protection responsibilities. That is why the legal and data-protection position needs to be considered in the context of the particular system and intended use, rather than assumed from the provider or platform alone.
If you are still planning or building and no real external-person information has been used, start with the AI Ready Diagnostic. If the actual system already exists, external users are testing it, or real external-person data has already been used, start with AI Ready.
Is Swiss Hosting or EU Hosting Enough to Make an AI App Compliant?
Not by itself. Terms such as “Swiss hosted,” “EU hosted,” “GDPR compliant” or “sovereign” may describe an important part of a system or provider setup, but they do not by themselves answer whether the particular AI product is legally aligned with the way your business intends to use it.
You do not need to become the person who knows how to assess all of that. You need the right review for the stage your system is actually in.
When Should I Get Legal Help While Building an AI App?
Ideally, before decisions become embedded in the finished product. If the system is still being planned or actively built, the AI Ready Diagnostic checks the direction while changes are still easier to make. Once the main system exists and can be demonstrated, the work moves to the actual system through AI Ready. You do not need to wait until it is live.
When Legally She Can Is a Relevant AI Legal Option
This route is particularly suited where:
-
you are working on one main client-facing AI app, chatbot or AI-enabled service;
-
you or a small founder-led team are directly making the decisions around it;
-
you are working directly with a developer, platform or small build team rather than through an enterprise procurement or AI-governance programme;
-
the product is intended for users, clients or other affected people in Switzerland or the EU; and
-
you need help with the legal, data-protection or AI-transparency side rather than the technical build itself.
This can include founders, consultants, coaches, advisors and other independent experts building AI into their existing products or client services. You do not need to know which legal questions you should already be asking before you come in.
What Legally She Can Reviews, and What It Does Not
Legally She Can works on the legal, data-protection, AI transparency, provider, documentation and client-use layer around the AI product. It does not build or technically test the software.
This is not the right service for:
-
cybersecurity audits or penetration testing;
-
security architecture;
-
code review or software QA;
-
model accuracy, hallucination, bias or robustness testing;
-
technical explainability testing;
-
full high-risk AI conformity assessments;
-
CE marking;
-
enterprise-wide AI governance; or
-
specialist regulated-sector AI compliance outside the confirmed scope.
Projects involving medical diagnosis or treatment, employment or hiring decisions, credit, insurance, biometric identification, emotion recognition or other particularly consequential uses may need specialist review. The aim is to identify that before you purchase the wrong service.
Frequently Asked Questions
I am not based in Switzerland or the EU. Can I still work with Legally She Can?
Yes, potentially. Your business does not need to be established in Switzerland or the EU. These services are designed for client-facing AI apps and chatbots intended for users, clients or other affected people in Switzerland or the EU. The exact legal framework still depends on the facts.
My developer says the AI is GDPR compliant. Do I still need a legal review?
Possibly. A developer or technology provider can explain its own system, features, hosting, security or contractual setup, but that does not automatically determine whether the way your business intends to use the AI app or chatbot with clients has the appropriate legal and data-protection setup.
I have only built a prototype. Which route applies?
If it is still an internal prototype using only fake, dummy or synthetic information, start with the AI Ready Diagnostic eligibility check. If real client or other external-person information has already been entered, or external users are already testing it, start with AI Ready.
My AI app is built, but I have not launched it. Do I use the Diagnostic?
No. Once the main system exists and can be demonstrated, AI Ready is the better route because the actual setup can now be reviewed. You do not need to wait until it is live.
Does Switzerland Have an AI Act?
Not currently in the form of one overarching AI-specific statute equivalent to the EU AI Act. Switzerland is developing its regulatory approach, while existing Swiss law, including the FADP where personal-data processing is involved, already applies to AI-related activity.
Does the EU AI Act Apply Only to Businesses Based in the EU?
No simple location-only rule answers that question. The EU AI Act has its own territorial scope rules, so company location alone does not answer the question. Applicability depends on the facts, including the system, your role and the relevant EU connection. Separately, Legally She Can can work with a business based elsewhere where the AI app or chatbot is intended for users, clients or other affected people in Switzerland or the EU.
About the Legal Work Behind AI Ready
Legally She Can is a Zurich-based legal consultancy led by Vena Verga-Danemar, a licensed lawyer, legal and business trust engineer, and founder of Legally She Can. Vena holds postgraduate legal qualifications in International and European Law from Tilburg University and the University of Geneva and has delivered professional data-compliance training for the European Medical Writers Association.
Legally She Can GmbH is the legal consultancy behind the AI Ready Diagnostic and Legally Fluent Founder: AI Ready, which are delivered through Legally Fluent Academy. Legally She Can's AI work focuses on the legal and data-protection questions that arise when founders and experts build AI into products and client services.

