lunedì, 6 luglio 2026
Dr. iur. Servatius von Tatzenberg
FINMA ran its enforcement calendar in two directions at once today, a European DPA proved GDPR can get to AI enforcement before the AI Act does, and the weekly sanctions queue filled up — not a settling-in Monday.
FINMA Ends the Patience Era for Intermediaries — Proceedings, Not Reminders
FINMA (de)
The transitional window FINMA extended to financial intermediaries who were slow to meet supervisory expectations under Art. 33 FINMAG is closed. Servatius von Tatzenberg's piece today traces what this enforcement posture shift means in practice — and "in practice" is the operative phrase, because the announcement is not a warning shot but a change of track. If your Art. 33 remediation plan has been sitting in legal-review status, today is the day to escalate it. The April 2026 annual conference audit mandate pointed in this direction; this is the destination.
Previsione: Watch for a cluster of Art. 33 proceedings in FINMA's enforcement diary before the end of Q3 2026 — the referral pipeline built during the tolerance period will not clear quietly.
FINMA Reaches Past the Firm — Wendelspiess Gets the Art. 33 Ban
FINMA (de)
The individual activity ban under Art. 33 FINMAG, which many compliance teams have been treating as a theoretical backstop, is now a live instrument — and Wendelspiess is the proof. Servatius von Tatzenberg's piece today explains why the mechanism matters more than the individual case: a firm in liquidation is a concluded matter; two named individuals barred from the Swiss financial sector on a long-term basis — the decision is not yet final and may be appealed to the Federal Administrative Court — are a signal that travels. Read this alongside the intermediary-transition piece above as a single enforcement posture, not two separate stories. The firm and the responsible individuals are simultaneously in scope.
GDPR Gets to AI Enforcement Before the AI Act Does
EDPB / National DPA (en)
A European data protection authority has fined an AI company under GDPR, making good on what enforcement watchers have been predicting since the AI Act passed: that national DPAs would not wait for the new framework to mature before moving. Casimir von Firn's piece today maps the legal geometry — GDPR Art. 5, Art. 22, and the automated decision-making rules reach into AI systems further than many compliance teams have assumed. The practical implication: if your AI system processes personal data, the GDPR compliance gap is not a 2027 problem, it is a current one. Our earlier piece on Art. 89 DSGVO and AI training sets maps the adjacent exposure.
Previsione: Expect at least two more significant DPA AI-sector fines before the AI Act's Chapter II prohibited-practice provisions become fully operable in August 2026.
FINMA's Portfolio-Management Guidance Locates the Conflict Upstream
FINMA (de)
FINMA's new guidance on portfolio management identifies the relevant conflict of interest not at the execution stage but in product structure and selection — earlier in the process than most firms' conflict-management frameworks contemplate. Casimir von Firn's piece today works through what this means operationally. By the time a portfolio manager executes a trade, the conflict FINMA is focused on may already have crystallised in the mandate structure. Product governance committees and legal teams reviewing portfolio mandates need to work through this together, not hand it off sequentially. Cross-reference with the disclosure obligation under Art. 717a OR — the requirement to document and disclose is not sector-limited.
KlimaSeniorinnen's Execution Gap Is Doing New Legal Work
ECHR (en)
The ECHR judgment in KlimaSeniorinnen has not executed cleanly at the domestic level, and that gap is being read as an opening by NGOs and courts testing the boundaries of standing in climate and environmental proceedings. Servatius von Tatzenberg's piece today traces where the standing door is widening and who is walking through it. For corporate counsel: the plaintiff universe in environmental-adjacent regulatory challenges is not stable. Standing was granted to the Verein Klimaseniorinnen Schweiz (the applicant association); the four individual pensioners were explicitly denied victim status — the precedent operates at the association level, and that is now part of opposing counsel's toolkit in qualifying group-based environmental challenges. The trend is structural, not case-specific.
Russia Sanctions — Anhang 8 Updated, Screening Check Due
FINMA (de)
WBF has revised Anhang 8 of the March 4, 2022 Russia sanctions ordinance; FINMA's notice is live. This is the maintenance layer — the policy substance of the 20th sanctions package was the news; the annex update is the compliance trigger. If your screening workflow keys off FINMA notices rather than the underlying WBF/SECO publications, verify you are seeing this update and run the check today.
Iran — Appendices 12 and 14 of the December Ordinance Revised
FINMA (de)
WBF has revised Anhänge 12 and 14 of the December 12, 2025 Iran sanctions ordinance — the framework that replaced the JCPOA-era regime, as we covered in our structural overview. Two of four annexes updated; the other two are unchanged. If your Iran sanctions mapping was done on the original December text, it needs refreshing before the next screening cycle.
Sudan and SR 946.231.09 Updated — Three Jurisdictions in One Week
FINMA (de)
FINMA also published notices for SR 946.231.18 (Sudan, Anhang 2) and SR 946.231.09 this week — alongside Russia and Iran. Three jurisdiction updates in a single cycle is not unusual by volume, but the operational load compounds: each triggers its own screening run, its own documentation trail, its own sign-off. If this workflow is still manual and per-notice at your institution, the cadence is now the argument for automation. The Sudan annex framing from May still applies.
Parliament Wants Cobalt in Swiss Responsible Business Rules
SWI swissinfo.ch (en)
Civil society organisations have urged that cobalt be added to the mineral scope of the NUFG before the consultation closes on 9 July 2026. This matters on two tracks running simultaneously: the EU's CSDDD is already binding Swiss exporters contractually before domestic Swiss law catches up — our NUFG/CSDDD piece maps that gap — and cobalt supply chains run through the DRC, through Chinese refiners, and into battery assembly across the EU, making multi-tier due diligence genuinely complex rather than administrative. If your company touches cobalt, the Vernehmlassung text is the document to watch, and supply chain mapping should begin before it arrives.
Mainland China Foreign Law Firm Retrenchment — Read This as a Panel Signal
Law.com International (en)
The contraction of international law firms in mainland China is accelerating — Hunton Andrews Kurth is the latest to shutter its China office entirely, and the broader trend among the largest international firms is continued downsizing. For in-house counsel managing APAC panel relationships, the structure of what was available two years ago is no longer the structure of what exists now: international firms that remain are concentrating on high-margin cross-border regulatory and disputes work, while local and regional firms absorb transactional volume. If your panel was calibrated for the old equilibrium, the mismatch is worth checking this review cycle before it becomes a resourcing problem mid-transaction.
One Signal, Two Regulators — Individual Accountability Is the New Enforcement Lever
FINMA / EU DPAs (en)
Set the Wendelspiess Art. 33 ban next to a DPA fine on a named AI company controller, and the pattern becomes structural rather than coincidental: financial services and data protection regulators are both moving from entity liability to individual accountability as the primary deterrent. The corporate fine gets absorbed and provisioned for; the personal industry ban or the individual data-protection sanction does not. Compliance programmes calibrated to manage corporate exposure are systematically underweight on the individual-risk dimension. The conversation with your FINMA-supervised managers and your GDPR-accountable person about personal liability should be on the agenda before proceedings make it urgent.
Three sanction annexes, two enforcement pieces, and a DPA fine before noon.
Archivio