AI Agency Zurich — Enterprise AI for Swiss Corporate Finance & Tech
Nehos deploys production-grade AI for Zurich's corporate banking (UBS, Julius Baer), insurance and reinsurance (Swiss Re, Zurich Insurance Group), tech multinationals (Google Zurich, ETH spinoffs), and Crypto Valley companies (Zug, 20 min). FINMA Circ. 18/3 governance included. Swiss data residency on Exoscale Zurich. 40–50% below local boutique day rates.
Adapté à toute taille de structure
AI agency Zurich — frequently asked questions
#AI Agency in Zurich: Local Market Context
Zurich is the undisputed financial capital of Switzerland, hosting the global or European headquarters of UBS, Julius Baer, Swiss Re, Zurich Insurance Group, and dozens of private banks along the Bahnhofstrasse corridor. ETH Zurich, consistently ranked among the top five technical universities worldwide, produces a steady pipeline of AI-focused spinoffs. Twenty-six minutes south by train, Zug hosts Crypto Valley — the densest cluster of blockchain and DLT companies in Europe, many holding FINMA banking or fintech licences. This concentration of regulated, data-intensive enterprises creates a demand for AI agency services that is both technically sophisticated and compliance-heavy.
What makes Zurich unusual is that the research supply and the enterprise demand sit inside the same tram network. Google runs its largest engineering centre outside the United States here, IBM Research maintains its European laboratory in Rüschlikon, and Microsoft opened a mixed reality and AI lab in the city. The ETH AI Center coordinates machine learning work across dozens of research groups, and the Swiss AI Initiative — a joint ETH Zurich and EPFL programme running on the Alps supercomputer at CSCS — produced Apertus, a fully open large language model whose weights and training recipe were published rather than licensed. For a Swiss institution that cannot send client data through a foreign API, an openly licensed, Swiss-trained model family is not an academic curiosity: it is a procurement option.
That said, the gap between what Zurich can build and what Zurich has deployed remains wide. In our conversations with heads of data and operations across banking, insurance and industrials in the Greater Zurich Area, the recurring pattern is not scepticism about AI value — it is a portfolio of eight to fifteen proofs of concept, none of which has an owner, a runbook, or a line in the operating budget. Innovation teams demonstrate; operations teams inherit nothing. An AI agency in this market earns its fee at exactly that transition point, not at the demo.
The second structural factor is cost of labour. Zurich has some of the highest engineering and compliance salaries in the world, which changes the arithmetic of automation entirely. A process that would not justify an automation project in Lisbon or Warsaw justifies one here after a far smaller volume of transactions. This is why Swiss AI programmes tend to start in back-office and middle-office functions — onboarding, reconciliation, regulatory reporting, claims administration — rather than in customer-facing experimentation.
#The regulatory frame we design against
Switzerland has deliberately not copied the European AI Act. In February 2025 the Federal Council set out a sector-specific approach: ratify the Council of Europe Framework Convention on artificial intelligence, adapt existing sectoral law where needed, and avoid a single horizontal statute. For a Zurich institution this creates a two-speed picture. Domestically, the binding constraints are the ones that already exist — financial market supervision, data protection, professional secrecy. Internationally, any Swiss firm placing an AI-enabled product on the EU market falls inside the EU AI Act's territorial scope regardless of where the model runs. Most Zurich groups therefore end up building to the stricter of the two, not because Bern requires it, but because their EU subsidiaries and clients do.
FINMA's expectations are spread across instruments rather than concentrated in one. Circular 2018/3 governs outsourcing for banks and insurers: an inventory of outsourced functions, a materiality assessment, audit and inspection rights that must extend to subcontractors, and business continuity provisions. Any managed AI service, any external inference endpoint, any vendor-hosted vector database is an outsourcing question before it is a technical one. Circular 2023/1 on operational risks and resilience, in force since January 2024, adds ICT and cyber risk management, critical data identification, and the requirement to define critical business functions with an explicit tolerance for disruption. And FINMA's 2024 guidance on governance and risk management in the use of artificial intelligence sets out what supervisors will look for concretely: a documented inventory of AI applications with risk classification, clear accountability, data quality controls, testing and ongoing monitoring, explainability proportionate to the use case, and independent review.
The revised Federal Act on Data Protection, in force since September 2023, adds obligations that bite differently from the GDPR. Article 21 gives individuals a right to be informed of decisions taken solely by automated means that have a legal effect or significantly affect them, and a right to request human review — which sets a hard architectural boundary for any system touching credit, underwriting, or claims outcomes. Cross-border disclosure follows the country adequacy list maintained by the Federal Council. And crucially, the criminal provisions target responsible natural persons rather than the company, which is why Swiss legal departments treat AI vendor selection with a seriousness their EU counterparts sometimes find surprising.
Finally, the constraint that is unique to this city: banking secrecy under Article 47 of the Banking Act is criminal law, and Article 271 of the Criminal Code makes performing acts for a foreign authority on Swiss soil an offence. Client identifying data — names, account numbers, or any combination that permits re-identification — cannot be casually routed abroad on the strength of a data processing agreement. This is not a preference. It is the reason serious Zurich AI architecture starts with a data classification exercise rather than a model comparison.
#Where AI Actually Pays Off in the Zurich Market
We do not sell a catalogue. The engagements that produce durable value in this market cluster into six patterns, and we would rather argue you out of the wrong one than deliver it.
#Regulatory change intelligence and compliance drafting
FINMA circulars, guidance notes and FAQs, SECO sanctions updates, Basel Committee consultations, MROS communications and cantonal supervisory publications arrive continuously and in three languages. Most compliance teams handle this with a shared mailbox and a spreadsheet. A retrieval-grounded system that ingests the source documents, maps each material change to the internal policies, control descriptions and model documentation it affects, and drafts a redline for human review, compresses a multi-week cycle into days. The design point that matters is provenance: every proposed change must cite the paragraph it derives from, or the compliance officer will not trust it twice.
#Underwriting and actuarial knowledge retrieval
Reinsurance and specialty insurance run on decades of accumulated internal research — peril models, event reconstructions, loss studies, treaty precedents — that is effectively unsearchable because it lives in PDFs, network shares and the heads of three senior people. Retrieval-augmented systems built over that corpus, with strict source attribution and access control inherited from the document management system, change the economics of underwriting preparation and shorten the ramp-up of junior staff. These corpora are exactly the kind of intellectual property that must never transit a public API, which is why we deploy them on self-hosted open-weight models inside Swiss infrastructure.
#Claims intake, classification and routing
Swiss personal-lines claims arrive predominantly by mobile: free text plus photographs plus a PDF the customer scanned badly. A multimodal pipeline that classifies the claim type, extracts the structured fields the case management system needs, checks policy coverage against the contract, flags anomaly signals for the fraud team and routes to the right adjuster removes the least valuable hour in the whole process. The governance requirement follows from revFADP Article 21: the system prepares and prioritises, a human decides anything that affects the policyholder's entitlement, and the audit trail shows which was which.
#Advisor productivity in private banking and asset management
The Financial Services Act imposes real documentation duties — suitability and appropriateness assessments, records of advice given, delivery of key information documents. Relationship managers spend a substantial share of their week producing this paperwork. Systems that transcribe and structure client meetings, draft the suitability rationale for advisor review, assemble pre-meeting briefing packs from portfolio and CRM data, and pre-check proposed transactions against mandate constraints give time back to the front office without touching the advice itself. We are explicit with clients about the boundary: the model drafts the record, the advisor owns the recommendation.
#Unlocking data trapped in core banking platforms
Zurich's banking sector runs on Avaloq, Temenos T24 and Finnova, with decades of parametrisation and custom scripting layered on top. The practical obstacle to most AI projects is not the model, it is that nobody currently employed can explain what a given batch job does or which table holds the authoritative version of a field. Large language models are genuinely good at this: reading legacy scripts and stored procedures, producing accurate documentation, mapping data lineage, and generating the test cases for an extraction layer. It is unglamorous work that unblocks everything downstream, and it is where we frequently start.
#Industrialising models built by research teams
ETH spinoffs and corporate R&D groups arrive with excellent models and no path to production: a notebook, a conda environment, and a founder who has become the deployment pipeline. The work here is engineering rather than data science — packaging inference, adding observability and evaluation, versioning models and prompts, defining rollback, and building the infrastructure that lets a Series A company answer a customer's security questionnaire without a two-week fire drill. We provide that layer so the scientific team keeps working on the science.
#How a Nehos Engagement Runs
We work in four movements, and the first one is deliberately cheap to exit.
Framing. A short, intensive phase with your business owners, not just IT. We map candidate use cases against value, data readiness and regulatory exposure, classify each data set (public, internal, confidential, client identifying) because that classification determines the architecture, and produce a prioritised matrix with an honest note on the ones we think you should not do. Deliverables are a scored use case portfolio, a target architecture, and a governance plan aligned to your existing risk framework.
Proof on the real constraint. A single use case, built against production data in a controlled environment, with the hard part attacked first. If the hard part is the Avaloq extraction, we do that in week one. If it is convincing your CISO that inference never leaves Swiss territory, we build and document that before we tune a single prompt. A proof that avoids the constraint proves nothing.
Production. Deployment with CI/CD, monitoring, evaluation harnesses that run on every model or prompt change, incident response procedures, and the governance pack — model inventory entry, risk classification, data lineage, testing evidence, human oversight design, and the outsourcing documentation your supervisor will ask for. Typical production timelines run 8 to 12 weeks from framing to live service.
Run and evolve. Ongoing monitoring against a defined service level of 99.5% availability, drift and quality tracking against the golden evaluation set, periodic review as FINMA guidance and your own policies change, and a quarterly business review that reports on the KPIs agreed at framing rather than on activity.
#Five Failure Patterns We Are Regularly Called In to Fix
"It's a Swiss region, therefore it's sovereign." The major hyperscalers all operate Swiss regions, and they are excellent infrastructure. But a US-headquartered provider remains subject to US law regardless of where the disk sits, which is precisely the exposure that Article 47 of the Banking Act and Article 271 of the Criminal Code make uncomfortable for client identifying data. Depending on data class, the answer is a Swiss-operated provider, a hyperscaler with confidential computing and customer-held keys, or pseudonymisation before the data ever reaches the model. What is not an answer is a data processing addendum and a hopeful shrug.
Pilots with no operational owner. The most common artefact we inherit is a successful demo that nobody in the line organisation asked for. We refuse framing workshops that do not include the person whose team will run the process afterwards, because that person's objections are the actual requirements.
Governance documentation written last. Model inventories, risk classifications and testing evidence assembled retroactively are both expensive and unconvincing. Produced as the system is built, they cost a fraction and read as what they are. Supervisors and internal audit can tell the difference immediately.
Fine-tuning as a reflex. Teams reach for fine-tuning when the actual problem is retrieval quality, chunking strategy, or the fact that the source documents contradict each other. Fine-tuning bakes in knowledge that will change next quarter and makes updates expensive. We use it where it earns its place — domain vocabulary, output format discipline, narrow classification — and retrieval everywhere else.
No evaluation harness. If you cannot say whether last week's prompt change made the system better or worse, you do not have a product, you have a demo with good luck. A representative golden set, built with the business experts and maintained as a living asset, is the cheapest insurance in the whole programme.
#What Clients Measure
Across our production deployments the pattern holds: an average return on investment of 340% over twelve months, a 40% reduction in operating cost on the processes actually automated, and a 55% productivity gain on the high-value tasks that people are freed to do instead. Those are averages across a portfolio, not a promise for your specific case — which is why we fix the measurement baseline during framing, before anything is built, and report against it quarterly. The number that matters most in Zurich is usually not headcount saved but cycle time: how long from client instruction to executed onboarding, from claim notification to first payment decision, from regulatory publication to updated internal policy.
#Why Nehos in Zurich
- 47 specialists in AI, data and cloud, and 200+ projects in production since 2014 — an engineering firm, not a strategy practice that subcontracts delivery.
- Sovereign Swiss deployment by default. Data classification drives architecture; production workloads for regulated clients run on Swiss infrastructure with documented residency.
- Supervisory documentation as a deliverable, aligned to FINMA outsourcing, operational resilience and AI governance expectations — and to your existing risk taxonomy, not ours.
- English and German working languages, with technical documentation your internal audit function can actually read.
- The team that scopes is the team that builds. No handover to an offshore delivery centre after signature.
- A free 30-minute audit to qualify a use case and tell you honestly whether it is worth doing.
Related areas we cover: artificial intelligence agency Zurich Switzerland, FINMA compliant AI agency Zurich, AI agency corporate banking Switzerland, InsurTech AI agency Zurich, sovereign AI with Swiss data residency, and AI for ETH Zurich spinoffs.
For the operational side of this work, see our AI agents Zurich — detailed page and the Nehos Zurich hub overview. Our sector work is documented on the Banking, Insurance, Finance vertical page, our regulatory practice on Compliance service (AI Act, FINMA, DORA), and the full service description on the Nehos AI agency main page. For French-speaking Switzerland, see AI agency Geneva.
The FAQ below answers the questions Zurich clients ask most often before starting.