AI agents — tools that don't just answer questions, but act on their own: reading files, sending emails, running tasks — are arriving fast in small Swiss offices. The benefits are real. So are the risks, and most people don't yet understand them.

Most of the risk doesn't come from the big, well-known assistants. It comes from the small add-ons: the “skills” and “plugins” that give an assistant extra abilities. A recent look at thousands of these add-ons found that about one in four hides something risky — hidden instructions, leaks of your data, or hidden security holes.

Why this matters for your business

An agent that can read your emails, files or invoices is useful precisely because it can act. But that same access is what makes a bad add-on dangerous. Under the revised Swiss Data Protection Act (revDSG), you stay responsible for what happens to client data — even when a tool you installed misbehaves.

The good news: you don't need to be a security expert to cut the risk sharply. A few habits, plus one or two tools, cover most of it.

Check before you install

Before adding any new skill or add-on, ask three questions:

  • Who made it? Prefer tools from a well-known maker with an active community over anonymous one-file add-ons.
  • What does it touch? A skill that only tidies text is very different from one that asks for your inbox or your bank files.
  • Can it be checked? Tools such as NVIDIA's SkillSpector can look at a skill and flag hidden instructions, data leaks and sneaky backdoors before you install it.

Keep agents in a safe box

When an agent needs real access, put a boundary around it. A “sandbox” — a sealed-off area it can work in — lets the agent do its job in a space you can simply delete afterwards. Stronger tools like OpenShell add another layer: they enforce rules deep in the system, so the agent can only read the files, use the logins and reach the websites you explicitly allow.

For most Swiss SMEs, the everyday version is even simpler: keep agents on a separate account, never hand over your main password, and check anything sensitive before it goes out.

A three-step habit

  1. Check any new skill before you install it.
  2. Run agents you're unsure about in a sandbox, not on your main machine.
  3. Keep client data out of tools you haven't checked.

That's it. You don't need to ban AI. You just need the same care you already apply to any tool that handles client data.