Generative artificial intelligence is rapidly making its way into the operations of pharmacies, pharmaceutical companies, and healthcare organizations: information retrieval, training, translations, draft preparation, preliminary analyses, and administrative support. The potential is real, especially in quality management systems (QMS), where many activities depend on structured documentation, continuous updates, and the ability to quickly retrieve information.
For organizations that are establishing or improving their quality management systems, it may also be helpful to start by examining the principles underlying quality management systems in Swiss pharmacies.
But a useful application of AI does not automatically equate to a compliant, reliable, or appropriate one. A language model can produce a response that is very convincing yet inaccurate; it may use outdated information; it may process data sent to a third-party provider; and it may make it difficult to trace how a particular conclusion was reached.
In the healthcare sector, these issues take on particular significance because personal data, health information, professional confidentiality, and professional liability may all be involved in the same process.
That is why the question should not simply be “Can we use artificial intelligence?”, but rather: “For what tasks, with what data, using what tools, and with what safeguards?”
AI in Switzerland: What Will the Regulatory Framework Look Like in 2026?
As of September 12, 2026, Switzerland still lacks comprehensive, cross-sector legislation specifically dedicated to artificial intelligence. The Confederation is working on a draft regulation to be submitted for public consultation by the end of 2026. The approach announced by the Federal Council focuses, as much as possible, on sector-specific adjustments and cross-cutting rules centered on areas such as transparency, data protection, non-discrimination, and oversight.
This means thatthe European Union’s AI Act should not be automatically applied as if it were Swiss law. It may, of course, be relevant to certain cross-border activities, contractual relationships, or organizations that also operate in the European market, but its impact must be assessed on a case-by-case basis. The announced Swiss regulatory approach is distinct and also provides for the implementation of the Council of Europe Convention on Artificial Intelligence.
However, the absence of a “Swiss AI Act” does not amount to a regulatory vacuum. The IFPDT has clarified that the Federal Data Protection Act (FDPA) is technology-neutral and applies directly to AI-based data processing as well.
The LPD also considers health-related data to be personal data deserving of special protection. It establishes principles of lawfulness, proportionality, accuracy, privacy by design and by default, and—in cases that may pose a high risk to an individual’s privacy or fundamental rights—requires a data protection impact assessment. It also regulates automated individual decision-making: under certain circumstances, the data subject must be informed and may request that the decision be reviewed by a natural person.
Professional confidentiality also comes into play for healthcare professions. The FOPH reminds healthcare professionals that they must keep confidential any information received in the course of their work; this includes pharmacists.
A pharmacist should therefore not view a public chatbot as merely an “online notepad” into which to paste information related to a patient.
Where Artificial Intelligence Can Create Value in the QMS
Document Search and Review of SOPs
One of the most promising applications is making internal documentation searchable. An assistant that is linked exclusively to SOPs, instructions, forms, and approved documents can help an employee quickly find the correct procedure or the relevant section.
The benefit is clear: less time spent searching for files and greater access to corporate knowledge. The key control, however, is to ensure that the system responds based on current documentation, displays the source used, and does not present information as fact if it is not found in approved documents.
AI can therefore serve as an interface for the QMS, but it should not replace the controlled document. The official source must remain the approved version in the document management system.
Staff Training and User Support
AI can transform an SOP into quizzes, training scenarios, FAQs, or summaries tailored to an employee’s role. It can also help users learn how to use software or understand a process.
This is particularly useful in multilingual organizations: the same training program can be adapted for use in Italian, French, German, and English.
Here, too, human review is necessary, especially when a translation could alter the technical, clinical, or regulatory meaning of a procedure.
Drafts, documentation, and administrative tasks
Minutes, emails, operating instructions, checklists, presentations, process descriptions, and draft documents can be prepared more quickly with the help of an AI assistant.
For documents subject to the QMS, however, the output should be treated as a draft: review, approval, versioning, and change control remain as defined by the quality system.
AI can be particularly effective for low-risk administrative tasks, such as reformatting text, summarizing non-confidential content, suggesting a table of contents, or improving linguistic clarity.
Complaints, deviations, CAPA, and preliminary data analysis
A model can help classify complaints or deviations, identify recurring themes, group similar descriptions, and suggest categories for trend analysis. It can also support brainstorming during a root cause analysis.
The line that must not be crossed is that of the final decision. The classification proposed by the AI should not automatically determine critical issues, root causes, CAPA, the closure of a deviation, or an impact assessment.
To explore this issue further, it is helpful to link AI governance to the principles for developing effective CAPA and properly analyzing the root cause.
Translation and Multilingual Communication
In Switzerland, translation is a particularly interesting use case. AI can significantly reduce the time and cost of producing multilingual communications, but texts intended for patients, government agencies, regulated documentation, or operational instructions should be reviewed by someone who is proficient in both the language and the subject matter.
AI Risk-Benefit Matrix in the QMS
| Use Case | Potential benefit | Main Risk | Recommended Minimum Inspection |
|---|---|---|---|
| Search in the SOPs | High | Incorrect answer or outdated version | Approved documents, visible source, user verification |
| Training | High | Simplification or Misinterpretation | Process Owner Validation |
| Document Drafts | High | Errors, fabricated content, poor traceability | Review and Approval in Accordance with the QMS |
| Complaints and Divertions | Medium-high | Incorrect classification or bias | AI as a support tool; human decision-making |
| Data Analysis | Medium-high | Misleading correlations or incomplete data | Verification of the dataset, method, and results |
| Translations | High | Alteration of the technical meaning | Linguistic and Technical Review |
| Administrative Support | High | Disclosure of Confidential Information | Data Restrictions and Authorized Tools |
| Clinical/Professional Support | Potentially high | Error Affecting the Patient | Do not delegate professional decisions to the AI |
The risks that a pharmacy or company must manage
The first risk ishallucination: the model may invent references, procedures, numbers, or plausible explanations. An AI response should therefore not automatically be considered a reliable source. When the content matters, you must go back to the original document and verify its version and validity.
The second risk concerns confidentiality and data protection. Entering names, medical histories, prescriptions, contact information, identifiers, or descriptions that could identify a patient into an unauthorized service may result in the processing or disclosure of data that the organization has not adequately assessed.
The same caution applies to employee data, trade secrets, regulatory documents, and confidential information.
Cloud-based AI systems also require verification of the provider’s role, any sub-processors, security measures, the location of data processing, and any potential transfers of data abroad. The IFPDT emphasizes that the data controller remains responsible for compliance even when it outsources processing to an external cloud service.
These issues are directly linked to broader cybersecurity management in the pharmaceutical and healthcare sectors.
A third risk is a failure to validate the system for its intended use. A tool that excels at correcting a sentence is not necessarily suitable for classifying deviations, analyzing trends, or supporting a critical process. The more AI influences an important decision, the greater the need for verification, documentation, control, and monitoring.
There are also less obvious risks: sudden changes to the model by the provider, service unavailability, variations in results, changes in subcontractors, the use of outdated information, and technological dependence.
Governance should therefore also encompass the service lifecycle and, for the most critical uses, an exit strategy.
In the context of drug development and regulatory processes, Swissmedic highlights data quality, model traceability, quality control, and the management of potential biases as critical aspects of AI. These principles are also useful as a governance framework, though they should not be treated as a general rule applicable indiscriminately to every use of AI in pharmacy practice.
A Basic AI Policy: A Practical Example
An effective policy doesn’t have to be long. However, it must clearly state what is allowed, what is not allowed, and who is responsible.
1. Authorized Tools
The organization maintains a list of approved AI tools, specifying the internal owner, authorized purpose, permitted data types, key contractual terms, and the date of the last revision.
The use of different devices for business purposes should be prohibited unless prior authorization is granted.
2. Data That Should Not Be Entered
The following should not be inserted into devices not specifically approved for such treatment:
- health data and personal data requiring special protection;
- data that can be used to identify patients;
- information protected by attorney-client privilege;
- username and password;
- confidential information about customers and partners;
- internal documentation classified as confidential;
- Employee data not required for the specific purpose.
It is also important to remember that pseudonymization does not necessarily mean anonymization. Simply replacing a name with initials or a number may not be sufficient if the person can still be identified based on the remaining information.
3. Permitted Activities
Relatively low-risk uses may include brainstorming, content structuring, linguistic rewriting, preliminary translation, quiz creation, summarizing non-confidential documents, and drafting.
For uses related to the QMS, the output remains subject to standard document controls.
4. Prohibited Activities
AI should not be permitted to make clinical, dispensing, or other decisions that require professional responsibility on its own.
Similarly, they should not independently close deviations or CAPAs, approve documents, assign responsibilities to individuals, or make significant decisions based on personal data without a proper assessment of the process.
5. Liability
Each use case should have a designated process owner. The user who employs the AI remains responsible for verifying the output within the scope of their expertise.
For the most sensitive cases, a reviewer and escalation criteria should also be designated.
6. Human supervision
Supervision should not be merely a formality. Those conducting the review must have the necessary skills and information to identify an error.
A “click of approval” on a result that no one is really able to verify does not constitute an effective control.
7. Verification of Sources
Any relevant regulatory, clinical, or technical statement should be verified against the primary source.
For an in-house records management assistant, the response should ideally indicate the document, version, and section from which it is derived.
8. Training
The minimum training should cover hallucinations, data protection, professional confidentiality, system limitations, source verification, cybersecurity, authorized use cases, and incident reporting procedures.
9. Incident Management
The organization must establish a process for quickly reporting the accidental entry of data into an unauthorized tool, an AI response that contributed to an incorrect decision, or a security issue.
The incident must therefore be assessed in accordance with internal procedures. The LPD also sets forth specific obligations regarding data security breaches when the conditions established in Article 24 are met.
From Experimentation to Governance
One of the most common pitfalls is to start with the tool: purchasing a license, creating a chatbot, and only then figuring out how to integrate it into your processes.
In the QMS, it’s better to do the opposite.
First, the process is identified; then, the data, risks, responsibilities, official sources, and acceptance criteria are established. Only then is the technology selected.
This approach also makes it possible to determine which use cases require sophisticated controls and which can remain simple. Correcting the style of an anonymous internal communication does not pose the same level of risk as a system that analyzes thousands of complaints or recommends a decision regarding a patient.
Conclusion
Artificial intelligence can make a QMS more accessible, reduce repetitive work, and improve document search, training, analysis, and communication.
However, the greatest value does not come from simply “adding a chatbot” to existing processes, but from integrating AI into a governed system.
For Swiss pharmacies and healthcare organizations, the starting point is already clear: the Data Protection Act (LPD), information security, professional confidentiality, liability, and industry-specific regulations continue to apply even when part of the work is performed using artificial intelligence tools.
Good governance should not stifle innovation. It should distinguish between low-risk and critical uses, select appropriate tools, limit the scope of data, maintain human oversight, and ensure that the path from information to decision is verifiable.
This is the difference between experimenting with AI and truly integrating it into the quality system.
The considerations set forth in this article are general and informative in nature: the applicability of individual provisions must be assessed based on the organization, the processing activities, the tool used, and the specific context.
