AI Form Builders — What They Do, and What They Do With Your Data
«AI form builder» covers four very different things: generating a form from a prompt, translating it, talking to respondents, and analysing the answers. Only the last two put respondent data in front of a model — and that is the distinction that decides whether the feature is a convenience or a disclosure. Where prompts go, how to read a training-data commitment, when AI in a form crosses into automated decision-making, and what the EU AI Act actually requires from 2 August 2026.

Every form product now has an AI badge, and the badge means at least four different things. One of them touches nothing but your own words at design time. Another sends every answer your respondents write to a third-party model. They look identical in a feature list, they are priced the same way, and the difference decides whether the feature is a convenience or a disclosure you have not documented.
The short version
Ask one question first: does respondent data ever reach a model? Generating a form from a description and translating its questions are design-time features — they process your text, not your respondents'. Conversational AI forms and answer analysis are run-time features, and they put other people's data in front of an inference provider. Then ask three more: which company runs the model and under which jurisdiction; whether prompts are stored, logged or used for training, and by whom; and whether that provider is named as a sub-processor in your agreement. The regulatory trigger is narrower than the marketing suggests — drafting a form is not automated decision-making, but scoring an applicant with it is, and that is where Art. 21 nFADP, Art. 22 GDPR and the EU AI Act's high-risk rules actually bite.
Four Different Features Wearing One Label
| Feature | What reaches the model | Privacy weight |
|---|---|---|
| Prompt-to-form generation | Your description of the form. Nothing from respondents — the form does not exist yet | Low, but not zero: the description itself can carry commercial or medical context |
| Question translation | The question and label text you wrote | Low. It is your own published copy |
| Field suggestions / autocomplete while building | Your partial form definition | Low, with a quality catch — see the minimisation trap below |
| Conversational AI forms (the model interviews the respondent) | Everything the respondent says, in real time, turn by turn | High. The inference provider is now inside your data flow |
| Answer analysis — summarising, categorising, sentiment, scoring | The submitted answers, in plaintext | High, and highest of all when the output influences a decision about the person |
The first three are the ones most products actually ship, and they are genuinely useful: a blank form builder is intimidating, and a prompt gets you to a first draft in twenty seconds. The last two are the ones that need a paragraph in your record of processing and a named sub-processor in your DPA. Vendors rarely draw the line for you, because the badge sells better undivided.
Where the Prompt Goes — and What Happens to It There
Almost no form vendor runs its own models. Your prompt travels to an inference provider, and the properties that matter are the ones nobody puts on the pricing page:
- Which provider, and where. The form tool may be European while its model provider is not. This is a disclosure abroad in its own right, with its own Art. 16/17 nFADP basis to document — see which form data can legally leave Switzerland.
- Whether the prompt is stored. Many providers retain prompts for a period for abuse monitoring — commonly 30 days — even when they do not train on them. «Not used for training» and «not stored» are different promises; get both.
- Whether it is used for training. Read whose commitment it is: the form vendor's, the gateway's, or the model provider's underneath. A chain is only as good as its weakest written promise.
- Whether a human ever reads it. Abuse review and quality sampling are legitimate processes that put a person in front of your text. Ask.
- Whether the provider is in your DPA. If it is not named as a sub-processor, either the feature is not being used the way you think, or the paperwork is wrong. See do you need a data processing agreement for your form tool.
Prompts are more sensitive than they feel
«Create an intake form for our new oncology second-opinion service, we expect 40 referrals a month from three cantonal hospitals» is a business plan, a clinical context and a partner list in one sentence — typed casually into a box, because it feels like a search query rather than a data transfer. The same is true of «exit interview form for the restructuring in the Lausanne office». Prompts leak strategy, not just personal data.
How to Read a «We Don't Train on Your Data» Claim
The sentence is now standard, which means it has stopped carrying information. Four things separate a commitment from a slogan:
- Is it in the contract or on the website? A marketing page can be edited on a Tuesday. A DPA cannot.
- Does it cover the whole chain? Vendor → gateway → model provider. Each link needs its own written position, and the weakest one governs.
- Does it apply to your tier? Free and consumer tiers have historically had different training terms from paid and enterprise ones. If the AI feature is on the free plan, read the free plan's terms rather than the enterprise page.
- What is the retention figure? «We don't train» plus «we keep prompts for abuse review» plus no stated period is not a privacy posture, it is an unbounded log.
There is also a structural answer that beats all four: use a model whose operator has no commercial interest in your text, running on infrastructure in your own jurisdiction, on open weights rather than a proprietary frontier model. That is a smaller model with slightly less flair on creative tasks — and for turning «staff feedback form with four rating questions and one free text» into a draft, the difference is invisible.
The Regulatory Layer — Narrower and Sharper Than the Marketing
Automated individual decisions
Art. 21 nFADP requires the controller to inform the data subject of a decision taken exclusively by automated processing that has a legal effect or significantly affects them, and to give them the right to state their position and to have the decision reviewed by a natural person. Art. 22 GDPR is the stricter EU sibling. Neither is triggered by an AI that drafts your form. Both are squarely triggered by an AI that ranks scholarship applicants, filters job applications, or scores an insurance questionnaire. If your AI feature touches answers and feeds a decision, this is the provision to read first.
The EU AI Act, as it actually stands
The timeline moved in 2026 and the movement was uneven, which is exactly why generic advice is unreliable right now. Under the Digital Omnibus on AI agreed in May 2026, the Annex III high-risk obligations were deferred from 2 August 2026 to 2 December 2027, and the Annex I product-related ones from 2027 to 2028. Most of the Art. 50 transparency obligations were not deferred and still apply from 2 August 2026.
| Your AI feature | Likely AI Act classification | What that means |
|---|---|---|
| Prompt-to-form generation, translation | Minimal risk | No specific obligations beyond general transparency and honest description |
| A chatbot interviewing respondents | Transparency obligation | People must be told they are interacting with an AI system — the Art. 50 layer that applies from 2 August 2026 |
| AI-generated text presented to respondents | Transparency obligation | Machine-generated content has marking and disclosure duties |
| AI screening job applicants or scoring access to services | Annex III high-risk | The heavy obligations — deferred to 2 December 2027, not removed. Plan for them now |
For a Swiss company: the AI Act binds you when you place a system on the EU market or when its output is used in the EU, so an EU subsidiary or EU respondents can pull you in. Switzerland has no equivalent statute of its own — the nFADP, sector law and the transparency principle carry the weight domestically.
The Trap Nobody Warns About: Minimisation by Autocomplete
This is the practical risk of AI form generation, and it has nothing to do with where the prompt went. Ask a model for a patient intake form and it will helpfully produce date of birth, insurance number, emergency contact, allergies, current medication and a free-text medical history — because that is what the corpus says such forms contain. Every one of those fields is defensible in a clinic and indefensible in the physiotherapy studio that just wanted to schedule appointments.
A generated form is a plausible average of everything similar that has ever been published. Proportionality under Art. 6 nFADP is not an average; it is a judgement about your purpose. The discipline is simple and it takes two minutes: read the generated draft and delete every field you cannot justify out loud. Generation should be a starting point that saves typing, never an authority on what to ask.
And the injection problem
If the model output creates form fields, and part of the input comes from somewhere you do not control — a pasted description, an imported document, a respondent's answer in a conversational form — then that text can try to instruct the model. The containment is architectural: treat all user text as data rather than instructions, give the model no tools or side effects, and validate its output against a fixed list of allowed structures before anything is created. A vendor who has thought about this can describe it in two sentences.
How Schweizerform Does It
Building AI into a zero-knowledge product forces the honest answer, because the architecture removes the option of cheating. We cannot read submissions — so we cannot send them anywhere, whatever a roadmap might want.
- Inference runs in Switzerland. We use Infomaniak's Swiss-hosted AI services with an open-weight model. Infomaniak's published position, as we checked it in July 2026, is that prompts and data stay in Switzerland, requests are not stored or logged, and nothing is used to train third-party models. That is their commitment and you should read it yourself — but it is why they are the provider.
- We never store your prompt. Our usage ledger records the model, token counts, latency, whether the call succeeded, and the length of the prompt in characters. Not its text. The audit log likewise records counts, never content.
- Respondent answers cannot reach a model, structurally. Submissions are encrypted in the respondent's browser under your form's key. The server holds ciphertext. There is no server-side path from a submission to an inference request, and adding one would mean abandoning the encryption model — which we would have to announce, not slip in.
- Translation covers the form, not the responses. What is sent is the question and label text you authored, which was already server-side plaintext because the form is public. Answers are never part of it.
- Injection containment is built in. Your description is framed to the model as data that must never be followed as instructions; the model has no tools; and the generated structure is validated against a fixed catalogue of allowed question types before a form is created. An invalid generation gets one repair attempt and then fails visibly rather than producing something odd.
- Finite on every plan, and switchable off. AI form generation is quota-limited monthly on all plans — including Business, which has a number rather than «unlimited» — with per-user rate limiting, a credit charged exactly once per generation, and a kill switch that disables the feature entirely at the platform level.
The honest limitations: a Swiss-hosted open-weight model is not the largest model on the market, and for elaborate creative writing you would notice. For generating a well-structured form from a plain description in German, French, Italian or English, you do not. And every generated draft still needs the two-minute field review described above — our generator averages the corpus exactly like everyone else's.
Seven Questions for Any AI Form Vendor
Does any respondent data ever reach a model?
If yes, under what circumstances, and can it be switched off per form? This single answer sorts every product on the market into two piles.
Which company performs the inference, and in which country?
Name and jurisdiction, not «a leading AI provider». Then check whether that name appears in your DPA's sub-processor list.
Are prompts stored or logged, and for how long?
Ask for the retention period as a number. «Not used for training» does not answer this question.
Is the no-training commitment contractual, and does it cover the sub-provider?
Website statements are not commitments. The chain matters more than the headline.
Does the AI ever influence a decision about a person?
Scoring, ranking, filtering, flagging. If yes, you are in Art. 21 nFADP / Art. 22 GDPR territory and probably Annex III of the AI Act — regardless of the deferred deadline.
How do you contain prompt injection?
You are looking for: user text treated as data, no tool access, output validated against a fixed schema. A vague answer is an answer.
What happens when I turn it off?
Can AI be disabled account-wide, and do already-generated forms keep working? An AI feature you cannot decline is a dependency, not a feature.
The interesting question was never whether a model wrote your form. It is whether a model read your respondents' answers — and nobody puts that on the pricing page.
Bottom Line
AI in a form builder is mostly a drafting convenience, and a good one. It becomes a data protection question at exactly two points: when a model reads what respondents wrote, and when a model's output influences a decision about a person. Everything else — the badge, the sparkle icon, the launch post — is user interface.
So evaluate it in the boring way. Establish whether respondent data ever leaves the encryption boundary. Get the inference provider's name, country and retention period in writing. Check the DPA. And review every generated form for fields you did not actually need, because the fastest way to breach data minimisation in 2026 is to accept an autocomplete without reading it.
Schweizerform generates forms from a plain description and translates them into German, French, Italian and English with Swiss-hosted inference on an open-weight model, never stores your prompt, and cannot send respondent answers to a model because it cannot read them. The architecture is described in zero-knowledge architecture explained and on the security page; the feature list is under features.
Disclaimer: This article is general information and marketing content, not legal advice. References to the nFADP (Art. 6, 16, 17, 21), the GDPR (Art. 22) and Regulation (EU) 2024/1689 (the AI Act), including the deferral of Annex III high-risk obligations to 2 December 2027 and the continued application of most Art. 50 transparency obligations from 2 August 2026, reflect a position checked in July 2026 and are simplified; the AI Act timeline has moved before and may move again. Statements about Infomaniak reflect that provider's own published commitments as checked in July 2026 — verify them at the source before relying on them. Statements about Schweizerform describe the product as of that date and may change.