AI consulting services cover several kinds of work, from assessing a business case to building and operating the software. For a company choosing a provider in Switzerland, the first step is to establish which of those services the project needs and what the team should receive.
A production system needs lawful access to data, connections to business systems and agreed quality standards. It also needs maintenance as models, prompts, search indexes and upstream services change. Google Cloud's production guidance covers this lifecycle through discovery, experimentation, evaluation, deployment and monitoring.
This guide explains the deliverables to request, the factors behind consulting costs and timelines, and the data-protection questions Swiss and European organisations need to resolve.
Where AI projects get difficult
A consultancy should establish how well AI performs on the proposed task before recommending a wider rollout. Published research gives a useful reason for that discipline.
A National Bureau of Economic Research working paper on customer-support agents found that a generative AI assistant raised productivity by nearly 14% on average. In a field experiment with 758 consultants, AI users completed 12.2% more tasks and worked 25.1% faster on work within the model's capabilities. On a task outside those capabilities, AI users were 19 percentage points less likely to reach the correct answer.
The findings describe specific tasks and users. A consulting engagement should establish where the proposed system works, where it fails and how those failures affect the business. That requires representative data and agreed acceptance criteria.
Use the unresolved questions to define the engagement:
Specify the decisions the consultancy must help you make and the assets it must hand over: for example, an evaluated use case, an integration or a production system your team can operate.
AI consulting deliverables by phase
Agree on outputs and ownership for each phase. A discovery-only engagement will produce different assets from an implementation contract, but both should have clear acceptance criteria. NIST's AI Risk Management Framework also treats risk management as continuing work through its Govern, Map, Measure and Manage functions.
Scroll the table sideways to see all columns.
| Phase | What the consultancy does | What you should receive |
|---|---|---|
| Strategy and opportunity discovery | Interviews business and technical owners; examines volumes, error costs and measurable outcomes; separates AI problems from ordinary software problems | Prioritised use-case portfolio, value hypotheses, baseline KPIs, feasibility and risk matrix, and an explicit list of rejected use cases with reasons |
| Process analysis | Maps the workflow, decisions, exceptions and hand-offs before anything is automated | Current and target-state process maps, integration map, exception paths, human-oversight design, automation boundaries |
| Data readiness | Establishes what data exists, who owns it, how fresh and reliable it is, and what may lawfully be used | Data inventory, access matrix, quality findings, permission model, gap plan, and a representative evaluation dataset |
| Architecture and model integration | Compares foundation models and classical ML; chooses APIs, orchestration, retrieval, fine-tuning or deterministic components | Architecture diagrams, decision records, model evaluation matrix, security boundaries, cost drivers, vendor lock-in analysis |
| Prototype or MVP | Builds the smallest complete workflow that can prove value under realistic conditions | Working application, source code, deployment configuration, initial integrations, first evaluation results, documented limitations |
| Production engineering | Adds authentication, authorisation, secrets handling, logging, observability, fallbacks, rate limits, auditability and escalation | Production code, CI/CD pipeline, IAM configuration, threat model, test suite, governance documentation, runbooks |
| Evaluation and launch | Tests answer quality, retrieval, safety, adversarial behaviour and business metrics against criteria agreed in advance | Versioned evaluation set, results by use case, pass/fail thresholds, red-team findings, launch decision, unresolved-risk register |
| Operation and optimisation | Monitors behaviour, latency, cost, failures, feedback and regressions as models and data change | Dashboards, alerting, incident process, regression suite, version history, update policy, knowledge transfer |
An implementation proposal should specify which of these assets are included and which your team must supply. Google's production guidance includes evaluation datasets for typical and difficult cases, version control and CI/CD for prompts and retrieval systems, end-to-end logging, and evaluation after launch.
Prompt engineering is only one small part of that work. Whether an application succeeds in everyday use depends just as much on retrieval, application logic, models, APIs, permissions and user experience.
What RAG and AI agent projects require
Retrieval-augmented generation, or RAG, lets a model use private or frequently changing information without putting all that information into its training. The application searches company data and passes relevant material to the model as context. Microsoft's Foundry documentation explains how document preparation and retrieval configuration affect results. Source context does not guarantee a correct answer, and search must enforce access controls.
A RAG engagement should cover ingestion, updates and deletion; document chunking and metadata; permissions; traceable sources; and tests for retrieval. Ask how the provider measures search quality separately from answer quality. Include retrieval calls, embeddings and additional prompt tokens when estimating response time and cost per request.
AI agents can call APIs, change records, send messages or create tickets. Those actions require controls beyond checking the text of a response. OWASP's Top 10 for Agentic Applications 2026 covers risks including goal hijacking, tool misuse, privilege abuse and unexpected code execution. A hostile instruction may arrive through a retrieved document or tool result.
Define permissions for each tool, use identities with only the necessary access, and require approval for consequential actions. Add transaction limits, audit trails and adversarial tests. Specify how to stop a workflow and recover from partial completion; some external actions cannot simply be rolled back.
When you do not need a consultant
Not every AI project needs outside help. An internal team can usually handle a low-risk use case when a packaged product already covers the need and no unusual integration is required. The data should be accessible, the engineering team should understand production operations, security should already have assessed the service, and the business should be able to define success for itself.
Outside support becomes useful when several teams need to solve open questions together. Common examples include multiple source systems, sensitive internal data, unfamiliar architecture, customer-facing output, regulated decisions, complex permissions, agents with write access, or the jump from a prototype to dependable production software.
Seven questions are enough for an initial assessment:
- Can you name a measurable outcome rather than simply “use AI”? If not, start with the process rather than the build.
- Do you understand the current workflow and where it fails? If not, map it before trying to automate it.
- Do you have representative, lawful and sufficiently reliable data? If not, the data foundation is the first project.
- Are there engineers on the team who can integrate and operate the system? If not, you need implementation rather than advice alone.
- Can you create evaluation cases and acceptance criteria? If not, the partner should build that skill with your team.
- Can your security team assess RAG, prompt-injection and agent-specific risks? If not, bring in that expertise.
- Who will own the system after launch? If that is unclear, include managed support or genuine knowledge transfer in the contract.
Sometimes AI is simply the wrong answer. If the required output can be specified exactly, conventional software, search, workflow automation or a few clear rules will often be cheaper and more reliable. A model only adds uncertainty. The project should wait if there is no measurable objective or usable data, if errors would be unacceptable without a workable review, or if the underlying process changes too much to automate responsibly.
Automate
Bounded, high-volume work where a mistake is cheap to catch and cheap to reverse.
- A measurable baseline already exists
- Representative evaluation cases can be assembled
- Errors surface quickly and can be undone
Augment
Judgement-heavy work where a person stays accountable for the output.
- AI drafts, a named human decides
- Review effort is lower than doing it unaided
- Consequential actions keep an approval gate
Use another approach
Work that needs fixed rules, or decisions whose errors cannot be safely managed.
- Deterministic software already produces the answer
- No workable review mechanism exists
- The process is too inconsistent to automate responsibly
Choose a provider for the work you need
A ranking will not tell you which provider fits your project. A Swiss industrial company connecting an assistant to SAP and private engineering documentation needs different expertise from a regulated bank, an e-commerce business or an infrastructure team deploying agents.
Scroll the table sideways to see all columns.
| Provider type | Best fit | What to probe |
|---|---|---|
| Strategy consultancy | Portfolio prioritisation, operating model, executive alignment | Who implements the strategy, and has technical feasibility been tested? |
| Software consultancy | Integrating AI features with ERP, CRM, SaaS, APIs and internal platforms | Does the team also have practical data and evaluation experience? |
| Specialised AI consultancy | Complex retrieval, ML, model evaluation, fine-tuning, agents, AI security | Can it engineer and operate the surrounding production application? |
| Systems integrator | Broad transformation across established platforms and legacy estates | Who will work on the project, and how many delivery layers are involved? |
| Freelance specialist | Narrow investigation, architecture review, evaluation work, temporary capacity | What happens when that person is unavailable? Who owns security and support? |
| Major global firm | Multi-country work with significant regulatory and change-management needs | Who will work on the project, and what will be subcontracted or assigned to less experienced staff? |
For an implementation engagement, ask who will own the work from process analysis and architecture through code, integration and production monitoring. An advisory provider may be appropriate if your internal team can carry out those later stages. Make that division explicit in the contract.
What do AI consulting services cost?
There is no meaningful average price for AI consulting because the label covers very different work: a two-week discovery, extra engineering capacity, a complete RAG system, data engineering, security work or a multinational transformation programme.
Public procurement data at least gives real numbers. On the UK government's G-Cloud framework, one cloud data science AI/ML service publishes £240–£940 per day. One specialist rate card lists a privacy analyst at £500 per day, an AI data engineer at £850, a lead AI architect at £1,100 and a principal AI architect at £1,400, excluding VAT and expenses. Another generative-AI offering on the same framework quotes £300–£1,400 per day. These are supplier list prices on a UK public framework, not independent averages, not Swiss market rates, and not an estimate of what any particular engagement should cost.
Compare the scope and team composition as well as the day rates. Separate discovery, data preparation, integration, evaluation and production work in each estimate. Ask which assumptions would change the price and which work your own team is expected to do.
Common commercial structures include time and materials, fixed-price deliverables, retained support and staged milestones. Time and materials suits uncertain scope; fixed price needs well-defined outputs. Milestones let you decide after discovery whether to fund an MVP, and after evaluation whether to fund production. Agree on the evidence needed for each decision.
Include a way to close the engagement if the prototype does not meet the agreed criteria.
The answer to “build or buy?” is usually somewhere in the middle. Custom development rarely makes sense for a standard task that a mature product already handles well. It becomes valuable where your own workflow, data, user experience or controls matter. Many organisations therefore buy the model or platform and build the process, integration and governance layers around it. Training a foundation model is a different proposition: Google notes that it requires substantial data, specialised hardware and deep expertise.
How long the work takes
There is no useful industry average for duration either. Published supplier timelines at least indicate the order of magnitude, provided they are read as offers rather than benchmarks. IBM's G-Cloud service lists one day for an initial strategy step, two to four weeks of discovery workshops and roughly three to four weeks to co-create an MVP. Another supplier allows one to two weeks for setup, four to six weeks for iterative discovery and another four to six weeks to move a prototype towards production.
For initial planning, we allow two to six weeks for discovery and readiness, three to eight weeks for a focused MVP, and another four to twelve weeks or more for production engineering. These are planning ranges, not measured industry averages or a delivery commitment. Data access, identity and access management, integration, testing and governance determine the actual schedule.
Regulated applications, bespoke ML, autonomous agents and self-hosted infrastructure can require more time. Confirm the assumptions after the initial assessment and assign an owner to dependencies such as data access and security review.
- 01Plan: 2–6 weeks
Discovery and readiness
- Prioritised use cases with baseline KPIs
- Process, data and permission mapping
- Regulatory classification agreed
- Explicit list of what not to build
- 02Plan: 3–8 weeks
A focused MVP
- Smallest end-to-end workflow, real integrations
- Evaluation set and acceptance thresholds
- Documented limitations
- Stop-go decision on evidence
- 03Plan: 4–12+ weeks
Production hardening
- Authentication, authorisation, secrets handling
- Observability, fallbacks and rollback
- Security and adversarial testing
- CI/CD and runbooks
- 04Continuous
Operate and optimise
- Quality, latency, cost and failure monitoring
- Regression suite as models change
- Prompt, model and retrieval version history
- Knowledge transfer to your team
Cloud, private or self-hosted
There is no universally right deployment model. The choice depends on the control you need and the operational burden your team can take on.
Scroll the table sideways to see all columns.
| Approach | What you gain | What you take on |
|---|---|---|
| Managed cloud or API | Fast access to strong models, little serving infrastructure, quick access to new capabilities | Provider dependency, contractual and data-processing review, variable usage cost, model and API changes outside your control |
| Managed private or hybrid | Tighter network and data boundaries while keeping managed components | More architecture and platform work, and vendor dependencies do not disappear |
| Self-hosted open-weight | Maximum control over runtime, infrastructure and certain data flows | GPU capacity planning, scaling, patching, model lifecycle, observability, security and on-call operations become yours |
Self-hosting gives the team control over the runtime and infrastructure, while leaving it responsible for the controls around them. Data-protection requirements concern how personal data is processed as well as where it runs. A retrieval system still needs correct permissions, retention rules and audit records in a private data centre.
Operating costs need to be understood before the architecture is approved. Depending on the design, they include inference or API usage, embeddings, search or vector infrastructure, storage, ingestion, GPUs, application hosting, monitoring, security tooling, evaluation runs, maintenance and support.
How to test a consultancy before signing
Ask each shortlisted firm to walk through a comparable project, including its data flows, permission model, evaluation results and handover. If a confidentiality agreement prevents sharing code or customer data, the team should still be able to explain its methods and the limits of the example.
Scroll the table sideways to see all columns.
| Area | The question | What a strong answer contains |
|---|---|---|
| Business case | How will you decide this use case should not use AI? | Baseline KPIs, alternatives considered, explicit stop criteria |
| Data | What do you need before development starts? | Source inventory, access and quality analysis, lawful-use assessment |
| Model choice | How will you compare models? | Task-specific evaluation, not leaderboard scores |
| Retrieval | How do you test retrieval independently of generation? | Retrieval metrics, representative question set, citations, access-aware search |
| Agents | What can the agent do without human approval? | Least privilege, scoped tools, approval gates, auditability |
| Engineering | Who owns integration into our real applications? | API experience, tests, CI/CD, infrastructure as code, code ownership |
| Evaluation | What must be true before production? | Versioned test set, acceptance thresholds, human review, adversarial cases |
| Security | How do you handle prompt injection and data leakage? | Threat model, red-team testing, output controls, retrieval permissions |
| Regulation | Who classifies FADP, GDPR and AI Act obligations? | Documented data flows, controller and processor roles, an impact-assessment process |
| Operations | What do you monitor after launch? | Quality, latency, failures, usage, cost and security telemetry |
| Resilience | What happens when the model or retrieval layer is down? | Timeouts, fallbacks, graceful degradation, rollback |
| Ownership | What will you hand over at the end? | Source, infrastructure definitions, prompts, evaluation sets, documentation |
Follow up on accuracy claims without a defined metric, missing evaluation datasets, promises that RAG prevents all hallucinations, or unrestricted agent permissions. Clarify code and configuration ownership, support arrangements and the reasons behind a product recommendation before signing.
Test demonstrations against realistic cases. Include stale content, different user permissions, concurrent requests, incomplete sources and unavailable integrations. These conditions help show how much work remains before production.
Switzerland and the EU in 2026
For Swiss organisations, the legal starting point is clearer than the debate about a future AI law might suggest: existing data-protection law already applies. The revised Federal Act on Data Protection has been in force since 1 September 2023. According to the Federal Data Protection and Information Commissioner, it also covers AI-supported processing of personal data. Processing limited to factual information with no link to identifiable people generally falls outside it.
As of September 2026, Switzerland does not have a general AI act. The Federal Council plans to implement the Council of Europe Framework Convention on AI, with a focus on transparency, data protection, non-discrimination and supervision. A consultation draft is expected by the end of 2026. Existing sector-specific rules continue to apply.
Organisations inside the EU AI Act's scope face a more detailed timetable. The Act became generally applicable on 2 August 2026. Prohibited-practice and AI-literacy obligations began applying in February 2025, and governance and general-purpose AI obligations in August 2025. Following the AI Omnibus, which entered into force on 27 July 2026, Annex III high-risk use cases now have until 2 December 2027, and high-risk AI embedded in regulated Annex I products until 2 August 2028.
Where GDPR applies, it adds another layer. Article 22 limits decisions based solely on automated processing when they have legal or similarly significant effects. Article 35 requires a data protection impact assessment when processing is likely to pose a high risk to people's rights. The European Data Protection Board addresses AI models directly in Opinion 28/2024. Whether a model trained on personal data can be treated as anonymous, and whether legitimate interests provide a lawful basis, must be assessed case by case.
In procurement terms, data flows and purposes need to be documented alongside model providers, processors and subprocessors, retention periods, international transfers, access rights, automated decisions and human intervention. A good consultancy produces that documentation rather than mentioning the topics in a workshop. Legal conclusions remain the responsibility of qualified legal and privacy professionals.
How to read published customer results
When reading published success stories, separate company-reported outcomes from independent research.
UBS reports that a generative-AI system drafts performance-management summaries while managers remain accountable for the final assessment, saving more than 32,000 management hours a year. The bank also says its Front Door sourcing system reduced manual-entry fields by almost 40% and accelerated sourcing initiatives by up to 60%. Siemens reports that early Industrial Copilot pilots reduced reactive-maintenance time by an average of 25%. These are company figures, not controlled studies, so they should not be treated as forecasts for another project. The shared pattern is more useful: AI handles a defined part of a workflow while a person remains accountable.
The research cited earlier also applies to the tasks and populations tested. Use published findings to form a hypothesis for your own workflow. Measure the baseline, test representative cases and include the cost of review before deciding to expand.
Where to start
Bring the provider a description of the current workflow, sample inputs and a measurable target. Use discovery to assess data access, integration, regulatory requirements and alternatives to AI. If a pilot is justified, test a small complete workflow against agreed cases before approving production.
The proposal should make the next decision clear: what the first phase costs, what it produces and what result would justify further investment.
Alpine Edge provides AI consulting and implementation, from discovery and architecture through integration and production operation. A focused technical assessment can establish whether the use case is worth pursuing and define the first build.
Where these numbers come from
- European Commission, regulatory framework for AI. AI Act application dates, including the 2026 Omnibus changes.
- European Commission, AI Omnibus entry into force. Confirms 27 July 2026.
- Swiss Federal Chancellery, regulation of AI. Current status and the planned consultation.
- Swiss FDPIC, AI and data protection. FADP applicability to AI.
- Swiss FDPIC, AI in everyday life. Personal data in AI processing.
- EUR-Lex, GDPR. Official text, including Articles 22 and 35.
- European Data Protection Board, Opinion 28/2024. AI models and GDPR principles.
- NIST, AI Risk Management Framework.
- NIST, AI RMF Playbook. Govern, Map, Measure and Manage.
- Microsoft, retrieval-augmented generation and indexes. Azure AI Foundry: RAG design, security, limitations and cost.
- Google Cloud, deploy and operate generative AI applications. Evaluation, CI/CD, monitoring and the production lifecycle.
- OWASP, Top 10 for LLM Applications 2026.
- OWASP, Top 10 for Agentic Applications 2026.
- National Bureau of Economic Research, Generative AI at Work. Field evidence on customer-support productivity.
- Harvard Business School, Navigating the Jagged Technological Frontier. The 758-consultant field experiment.
- UBS, innovation and AI. Company-reported outcomes.
- Siemens, Industrial Copilot maintenance announcement. Vendor-reported pilot result.
- UK Digital Marketplace, IBM generative AI service. Published discovery and MVP structure.
- UK Digital Marketplace, generative AI service. Published timeline and pricing.
- UK Digital Marketplace, cloud data science AI/ML. Published price range.
- UK Digital Marketplace, Saracen AI services rate card. Role-based day rates.