Robots are leaving the shielded factory cell. They transport goods, assist in hospitals, monitor facilities, serve customers and work right alongside people. Software, sensors and artificial intelligence are making them increasingly autonomous. For companies and investors, robotics is therefore not only a technical or financial bet but also a legal one: liability, data access, intellectual property rights and market authorisation determine commercial success.
This article continues our technology series and is the second instalment, following our Insight on automated vehicles “Who is liable when the car drives itself?”. Switzerland has no single “robot law”. Yet robots do not operate in a legal vacuum. Depending on their function, product liability, contract, product safety, data protection, intellectual property, employment and sector-specific rules may all apply at the same time[1]. Legal structuring should therefore begin before the pilot phase.
Who is liable when a robot causes damage?
Under Swiss law, a robot is neither a person nor a liable party in its own right. The physical robot may qualify as a movable object, a product and a machine; software, data and cloud services must be assessed separately. Liability therefore lies not with “the robot” but (depending on the cause, the contractual chain and the ability to exercise control) with, for example, the manufacturer, the component or software supplier, the importer, the integrator, the seller or the operator[2].
Where a product is defective, the Product Liability Act (PrHG)[3] may give rise to strict (no-fault) liability on the part of the manufacturer. It covers death and personal injury as well as damage to property that is ordinarily intended for private use and has been used mainly privately. Damage to the defective product itself is not covered. In an industrial setting this is decisive: damage to the robot, to commercially used equipment or pure economic loss frequently falls outside the PrHG. Contractual warranty and damages claims, as well as general non-contractual liability under Art. 41 CO, then take centre stage[4].
Pure software is an exposed flank. According to the official analysis by the Federal Office of Justice, it is disputed whether software that is not embedded in a physical product is a “product” within the meaning of Art. 3 PrHG at all. The Federal Supreme Court has not yet ruled on this question. Where software forms part of the physical robot, the robot as a whole may in any event be covered as a product; for separately supplied AI models, control software or cloud services, however, the independent classification of the software remains relevant[5].
If a robot continues to learn after sale, is reprogrammed or is hacked, liability does not disappear. Instead, the source of the defect becomes decisive: Was the learning architecture insufficiently safeguarded? Were updates, access controls or warnings missing? Did the operator use unsuitable training data, deactivate safety functions or neglect maintenance?
A cyberattack may alter the chain of causation, but it does not automatically exonerate other parties if inadequate protective measures contributed to the damage. Autonomy is no free pass from liability. AI applications have no legal personality of their own; they remain technical tools that, in the performance of a contract, are in principle attributed to the risk sphere of the contracting party deploying them[6].
The chain of liability must therefore be mapped out contractually before rollout: through acceptance criteria, responsibilities for integration and training, update and cybersecurity obligations, change-control processes, rules on incidents, recourse and insurance, and tamper-proof logs. With learning systems, the chain of evidence is often as valuable as the source code.
Who owns inventions and data?
A robot cannot be an inventor under either Swiss or European patent law. In the Swiss DABUS proceedings, the Federal Administrative Court held that an AI system cannot be registered as an inventor. At the same time, a natural person may be an inventor on the basis of relevant contributions to an AI-assisted development process. In that case, it was sufficient in particular that the person had been involved in providing the data and in the training and had recognised the final solution as a patentable invention. The European Patent Office likewise requires a natural person to be designated as inventor[7].
Companies should therefore document who defined the technical problem, selected the training data and parameters, evaluated the results and derived the technical solution from them. For employee inventions, Art. 332 CO must also be observed. A seamless transfer of rights remains indispensable.
For data, the answer is different. Swiss law recognises no general property right in non-personal data. The owner of a robot therefore does not automatically “own” all sensor, usage, telemetry or maintenance data. What matters are contractual access and usage rights, actual control, data protection, trade secrets, intellectual property and unfair competition law[8]. If the contract is silent on data access, a key economic asset remains unregulated.
For robotics products and users in the EU, there is also the Data Act, which has applied since 12 September 2025. Under certain conditions, it grants users of connected products, including smart industrial machinery, access to the data generated and enables that data to be shared with third parties. However, it does not create a blanket “data ownership” and continues to protect trade secrets, personal data and the rights of third parties[9].
Where a robot captures identifiable individuals, the Swiss Federal Act on Data Protection[10] applies and, where there is a relevant EU nexus, the GDPR[11] as well. Cameras, microphones, location data and biometric sensors may also capture employees, visitors or passers-by. Data protection by design, transparent information, data minimisation and retention periods therefore belong in the product design. Where there is a potentially high risk – for example, extensive processing of sensitive personal data or systematic, extensive monitoring of public areas – a data protection impact assessment is required[12].
Contracts must therefore clearly regulate data categories, access rights, purposes of use, model training, disclosure, storage, security and deletion.
How can robots be deployed in operations with legal certainty?
The first step is to classify the system from a regulatory perspective: an industrial robot, a medical robot, an autonomous vehicle and a flying platform are not subject to the same rules. Ordinary machinery is governed in particular by the Product Safety Act and the Machinery Ordinance. The safety requirements must be met before the product is placed on the market or first put into use by the company itself. This typically includes a risk assessment, technical documentation, operating and safety information, a conformity assessment, a declaration of conformity and CE marking[13].
Under general machinery law, there is in principle no separate operating permit triggered solely by the fact that a system is a robot. The regime is based on self-responsibility, proof of conformity and subsequent market surveillance by the authorities. This is without prejudice, however, to any plan approval and operating permit requirements for industrial plants and to requirements under special legislation. Medical robots may be subject to medical device legislation.
Labelling a project a “pilot” does not create a blanket exemption. Non-conforming prototypes may be shown at exhibitions only under narrow conditions: the non-conformity must be clearly indicated and the safety of persons ensured. Making them available for use beyond demonstration is in principle not permitted. Manufacturing or direct import for a company’s own use in its operations is also subject to the PrSG[14].
Interfaces and subsequent modifications deserve particular attention. A safe robot can become part of an unsafe overall system through grippers, conveyor belts, sensors, software or spatial integration. If safety characteristics are substantially modified, a new product may come into being; the party making the modification then itself becomes the party placing the product on the market[15].
Where humans and robots share a workspace, duties of care and occupational health and safety obligations also apply. The employer must organise hazards, protective zones, emergency-stop concepts, maintenance, instruction and access rights.
Sensors must not incidentally become a means of unlawful employee monitoring. Art. 26 ArGV 3 prohibits systems intended to monitor employee behaviour. Data capture that is necessary for safety or operational reasons may be permissible, but must be proportionate, transparent and as unintrusive as possible. Art. 328b CO additionally restricts the processing of employee data[16].
If automation leads to the thresholds for mass redundancies under Art. 335d CO being reached, consultation and notification obligations apply. No general obligation to retrain follows from this; however, offering further training in good time can reduce restructuring and safety risks[17].
The US and China – how different are the rules of the game?
The US does not have a single robot law either. Product liability is governed predominantly at state level and, depending on the jurisdiction, may be based on negligence, strict liability or warranty. OSHA expressly points out that there are no specific OSHA standards for the robotics industry. General occupational safety rules continue to apply, for example on machine guarding and hazardous energy. Technical consensus standards and the voluntary NIST AI Risk Management Framework complement this fragmented system[18].
China combines general product liability with more centralised data, cybersecurity and administrative law. Product damage is covered in particular by the Civil Code and the Product Quality Law. For data-intensive robots, the Personal Information Protection Law and the Data Security Law also apply. Where a system uses facial recognition, additional requirements have applied since 1 June 2025. In particular, the processing must serve a specific purpose, be sufficiently necessary and be accompanied by strict protective measures. Insofar as processing is based on consent, separate consent is in principle required. In addition, a personal information protection impact assessment must be carried out in advance[19].
The comparison shows that the US is more decentralised, more state-driven, more sectoral and more litigation-driven. China combines product law with far-reaching administrative supervision of data and security. Switzerland is technology-neutral and pragmatic, but leaves uncertainties regarding pure software, updates, learning systems and access to evidence.
A global robotics product therefore does not need one-size-fits-all compliance that has merely been translated, but a legal market architecture: functions, data flows, documentation, contracts and responsibilities must be reviewed separately for each target country.
How can Switzerland become the location of choice for robotics?
Switzerland currently has no overarching AI legislation. By the end of 2026, the Federal Office of Justice is preparing a consultation draft to implement the Council of Europe’s AI Convention. In parallel, the Swiss Machinery Ordinance is to be aligned with the EU Machinery Regulation 2023/1230, which expressly addresses new challenges posed by machine learning and robotics[20].
These reforms should aim not for as many rules as possible, but for as much predictable legal certainty as possible.
First, a coordinated point of contact is needed that classifies robotics projects quickly and brings together the competent specialist authorities. Supervised regulatory sandboxes could allow testing under controlled conditions without suspending safety or data protection standards.
Second, product liability and warranty law should expressly clarify how pure software, security updates, cyber risks and changes resulting from machine learning are to be treated. The political window is open: Motion 26.3338 calls for the PrHG to be modernised, and the Federal Council has proposed that it be adopted. The new EU Product Liability Directive 2024/2853, which covers software including AI and also addresses updates, cybersecurity and evidentiary difficulties, provides an important point of reference[21].
Third, Switzerland should secure the equivalence of its machinery law with that of the EU, make consistent use of international standards and allow for digital conformity documentation.
Fourth, a blanket property right in data would be the wrong approach. Balanced access rules, robust model contracts, interoperability and effective trade secret protection are more appropriate.
Fifth, new obligations should be risk-based and workable for SMEs. Those who comply with recognised standards, document risks and operate effective control processes should benefit from clear presumptions of conformity and simplified procedures.
Innovation does not arise from an absence of law, but from predictable responsibility.
Conclusion: Legal certainty is a competitive advantage
Robotics law brings together liability, product safety, cybersecurity, data protection, intellectual property, employment law and international market access. It is at these intersections that it is decided whether a project is scalable, insurable and investable.
The right time for legal advice is not after the first incident, but before contracts are signed, before the pilot phase and before market entry.
LINDEMANNLAW supports developers, manufacturers, software providers, integrators, operators and investors throughout the entire life cycle: with regulatory classification and pilot design, development, supply and maintenance agreements, liability and insurance matrices, IP and data strategies, data protection impact assessments, product safety and conformity issues, employment law aspects of rollouts, and incidents and disputes.
Robotics is one of our core technology topics. Those who allocate responsibilities precisely before market entry not only protect their company but also increase the product’s investability and marketability. Talk to us before a technical advantage turns into a legal risk.
Disclaimer: This publication contains general information only and does not constitute legal advice. Any assessment always depends on the circumstances of the individual case. For advice on your specific situation, please contact us directly. This article reflects the state of knowledge at the time of writing; legal and regulatory frameworks may change.
Sources
[1] Cf. Federal Office of Justice (FOJ), Rechtliche Basisanalyse im Rahmen der Auslegeordnung zu den Regulierungsansätzen im Bereich künstliche Intelligenz [Basic legal analysis in the context of the overview of regulatory approaches to artificial intelligence], 31 August 2024, in particular sections 6.3–6.4; Federal Chancellery, Regulierung künstlicher Intelligenz [Regulation of artificial intelligence]; Suva, Robotik – Das Wichtigste in Kürze [Robotics – the key points in brief], edition of 28 November 2018.
[2] Cf. Art. 3 of the Federal Act on Product Liability, PrHG; Art. 2 of the Federal Act on Product Safety, PrSG; Machinery Ordinance, MaschV; SECO, Maschinen [Machinery]; FOJ, Rechtliche Basisanalyse KI, section 6.4.2.1, according to which AI applications have no legal personality of their own.
[3] SR 221.112.944 – Federal Act of 18 June 1993 on Product Liability (Product Liability Act, PrHG) | Fedlex
[4] Cf. Arts. 1, 3 and 11 PrHG; Arts. 41, 97 and 197 et seq. of the Swiss Code of Obligations, CO; FOJ, Rechtliche Basisanalyse KI, sections 6.3.2.2–6.3.2.3.
[5] FOJ, Rechtliche Basisanalyse KI, p. 148: the classification of “pure” software as a product is disputed in legal scholarship; the Federal Supreme Court has not yet ruled on the matter. The starting point is the definition of a movable object in Art. 3(1) PrHG. See also Motion 26.3338, Zeitgemässe Produktehaftung für die Schweiz [Modern product liability for Switzerland].
[6] Cf. in particular Arts. 41 and 97 CO, Art. 4 PrHG and FOJ, Rechtliche Basisanalyse KI, pp. 150–151. The FOJ describes AI applications as technical tools that are in principle attributable to the risk sphere of the contracting party deploying them. Whether a cyberattack breaks the chain of liability must be assessed on a case-by-case basis, taking into account causation, duties of care, product defects and the contractual allocation of risk.
[7] Federal Administrative Court, judgment B-2532/2024 of 26 June 2025, Erfindernennung/DABUS [Designation of inventor/DABUS], in particular consid. 4.9 and 6.3; Swiss Federal Institute of Intellectual Property (IPI), Wer hat welche Rechte an der Erfindung? [Who holds which rights in an invention?]; European Patent Office, decision J 8/20 of 21 December 2021, Designation of inventor/DABUS.
[8] Florent Thouvenin/Rolf H. Weber/Alfred Früh, study commissioned by the IPI, Zuordnung von Sachdaten [Allocation of non-personal data], 18 August 2020, in particular p. 61; IPI, Zugang zu Sachdaten in der Privatwirtschaft [Access to non-personal data in the private sector], 1 March 2021. The first study expressly states that Swiss law does not recognise ownership of non-personal data, but that contractual, intellectual property and unfair competition law positions in particular may exist.
[9] Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data – Data Act; European Commission, Data Act and Data Act explained. The Data Act has applied since 12 September 2025 and covers in particular data from connected devices and industrial machinery.
[10] SR 235.1 – Federal Act of 25 September 2020 on Data Protection (Data Protection Act, FADP) | Fedlex
[11] General Data Protection Regulation: final text of the GDPR
[12] Cf. in particular Arts. 7, 19 and 22 of the Federal Act on Data Protection, FADP; Federal Data Protection and Information Commissioner (FDPIC), KI und Datenschutz [AI and data protection], 24 September 2025; FDPIC, Datenschutz-Folgenabschätzung [Data protection impact assessment] and Merkblatt zur DSFA [Information sheet on DPIAs]; for the EU nexus, Arts. 25 and 35 GDPR.
[13] Cf. PrSG, MaschV; SECO, Maschinen; Suva, Robotik – Das Wichtigste in Kürze; Suva, Risiken beurteilen und mindern – Methode Suva [Assessing and reducing risks – the Suva method], edition of 3 August 2026.
[14] SECO, FAQ Produktesicherheit [FAQ on product safety], updated February 2026, in particular the explanations on prototypes, demonstrations and own use; Art. 2(3) and (4) PrSG.
[15] SECO, FAQ Produktesicherheit, in particular on substantial modifications, assemblies of machinery and interfaces; Suva, Robotik – Das Wichtigste in Kürze, in particular on the integration of robots into installations and systems.
[16] FDPIC, Technische Mittel zur Überwachung am Arbeitsplatz [Technical means of monitoring in the workplace]; SECO, Wegleitung zu Art. 26 ArGV 3 [Guidance on Art. 26 ArGV 3]; Arts. 328 and 328b CO. See also BGE 130 II 425 on the permissibility of monitoring that is not primarily aimed at monitoring behaviour, is objectively justified and is proportionate.
[17] Arts. 335d–335g CO; arbeit.swiss, Massenentlassungen [Mass redundancies], updated 2026. The statutory provisions contain consultation and information obligations, but no general individual obligation to retrain.
[18] Cornell Legal Information Institute, Products liability, in particular on the absence of uniform federal product liability law and on negligence, strict liability and warranty; US Department of Justice, Office of Legal Counsel, Congressional Authority to Require State Courts to Use Certain Procedures in Products Liability Cases, 19 December 1989; OSHA, Robotics – Standards; NIST, AI Risk Management Framework, as at 2026.
[19] State Council of the People’s Republic of China, Civil Code of the People’s Republic of China; National People’s Congress, Product Quality Law, Personal Information Protection Law and Data Security Law; Cyberspace Administration of China and Ministry of Public Security, Measures for the Security Management of Facial Recognition Technology Applications, published on 21March 2025, in force since 1 June 2025. The Chinese original text is authoritative for the interpretation of the Chinese provisions.
[20] Federal Chancellery, Regulierung künstlicher Intelligenz, as at 3 September 2026; Federal Council/SECO, Maschinen: Erhalt des erleichterten Zugangs zum EU-Binnenmarkt [Machinery: maintaining facilitated access to the EU internal market], 19 September 2025; Regulation (EU) 2023/1230 on machinery. At the time of review, the total revision of the Swiss MaschV was still in the legislative process.
[21] Motion 26.3338, Zeitgemässe Produktehaftung für die Schweiz – Modernisierung des PrHG [Modern product liability for Switzerland – modernisation of the PrHG], as at 19 June 2026; the Federal Council has proposed that it be adopted. See also Directive (EU) 2024/2853 on liability for defective products, in particular on the extended concept of product, software, AI systems, updates, cybersecurity and evidence; FOJ, Rechtliche Basisanalyse KI, section 6.3.2.3.