National Councillors Warn AI Reverse Engineering Could Expose E-ID and Patient Records
Four members of the National Council are warning that AI tools able to reverse-engineer software within weeks pose a new risk to federal IT projects such as the electronic identity (E-ID) and the electronic patient record, 20 Minuten reported. Franz Grüter (SVP), Gerhard Andrey (Greens), Marcel Dobler (FDP) and Dominik Blunschy (Centre) all want security testing to keep pace with the technology, though none of them calls for a general halt to state digitalisation projects.
Reverse engineering means taking a finished program apart until something close to its source code is recovered. For years the sheer effort involved protected many systems, because hidden flaws stayed hidden. New AI models can now do much of that work in weeks or months. In gaming the results are playful, such as viral videos of Super Mario dropped into the world of Elden Ring, but the same capability aimed at e-banking, business software or state systems is far less harmless. “Artificial intelligence drastically lowers the barrier to attacks,” Grüter said.
The Federal Office for Cyber Security (BACS) agrees the threat is real. A spokesperson said the latest models are a very powerful instrument for cyberattacks, cutting the time and expertise needed to find and exploit vulnerabilities, so authorities and companies must close gaps much faster. The office also sees an upside: used consistently to check code, AI could improve cybersecurity in the medium to long term, and BACS already works with ethical hackers. “Security must therefore never rely on code staying secret,” the spokesperson said, adding that the state should store as little data as necessary.
What it means in practice
The four MPs differ on remedies. Grüter wants the Confederation to attack its own systems with AI on an ongoing basis and to require independent audits. Dobler says AI-based attacks must be built into security tests and that, for critical systems, “security comes before the schedule”, even if a launch has to be postponed. Andrey argues state software should be open source, since a system is only secure if it stays secure when everyone knows how it is built. Blunschy cautions that “a copied interface is not yet a hacked system” and wants end-to-end encryption for the patient record, because stolen diagnoses could be used for blackmail.
Blunschy also leads the new parliamentary AI group in Bern, and the debate comes as the Federal Council sets priority areas for AI in the federal administration. Swiss research shows AI can help defenders as well, for example through ETH work on LLM honeypots that keep attackers busy for longer.
What to watch: whether the four turn their warnings into parliamentary motions, whether BACS sets testing requirements for AI-assisted attacks, and whether the E-ID timetable shifts if audits find critical gaps.