Invoices, contracts or official certificates form the basis of many business processes. But today, these can be faked convincingly using AI. Qualified electronic signatures and electronic seals create a technically verifiable basis of trust. This post explains what threats are relevant today and where and how signatures and seals can provide effective protection.
In early 2026, an entrepreneur from the Canton of Schwyz transferred several million francs to Asia on the instructions of a supposed business partner. The voice on the phone sounded familiar, but was AI-generated.
Such incidents show that trust is increasingly becoming a challenge in the digital sphere. Today, generative AI can imitate voices, fake identities and falsify documents. This potentially affects all organizations that conclude contracts, send invoices or issue official documents. So the key question is no longer: does a document look real? But rather: how can you prove the authenticity of a document?
People assess trustworthiness intuitively. We pay attention to voice, appearance, logos, layouts and writing style. These are precisely the characteristics that can now be manipulated with AI.
Qualified electronic signatures and electronic seals are not based on formal features, but provide cryptographic evidence. This enables technical verification of who sent a document and whether it has been modified since it was created.
Both instruments create trust, but perform different tasks:
The qualified electronic signature confirms the identity of a natural person. Before anyone can use such a signature, they must go through a formal proof of identity process with a certified Trust Service Provider, for example, by means of video identification using an official ID document or, in future, Swiss e-ID. The signature is then recognized in accordance with the Federal Act on Electronic Signatures (ZertES) and the Regulation on electronic Identification, Authentication and trust Services (eIDAS) and is legally equivalent to a handwritten signature.
The regulated electronic seal confirms the origin of a document from an organization. The organization is verified beforehand by a Trust Service Provider on the basis of official registers.
The seal proves:
Signatures represent people, seals represent organizations. Both make any subsequent changes to a document immediately recognizable. This means that documents cannot be technically manipulated unnoticed.
Attackers use deepfake calls or hacked e-mail accounts to identify themselves as suppliers or partners and redirect payments. A qualified electronic signature ties every contract amendment to a certificate-based, verifiable identity. It’s important to remember that signatures protect the contract process, but not against a transfer initiated by someone on the phone outside of this process. Organizational controls such as the dual-checking principle remain indispensable.
Attackers gain access to an entrepreneur’s e-mail inbox, exchange the IBAN in the PDF and forward the invoice. This means that a real invoice is transferred to an incorrect account. A regulated seal on the invoice makes any subsequent IBAN change immediately visible. The recipient checks whether the seal is intact before making the payment.
In 2025, the Hamburg District Court warned against a nationwide wave of falsified invoices for court costs, deceptively real-looking with the state coat of arms and official layout. A seal on residence certificates, extracts from the commercial register or similar documents protects the issuing authority against fraudsters abusing its reputation.
In the case of a sealed or signed document, any changes can be recognized, as the mathematical properties change – even if only a single digit or a single letter is manipulated. A complete audit trail documents who has signed or sealed what and when, and the long-term validation process ensures that signatures and seals can be verified over decades. A document that is cryptographically intact can be used as proof in court.
Signatures and seals protect against three specific attacks that are becoming increasingly common with AI tools:
They do not prevent someone from being persuaded over the phone to make a transfer. Protection lies in the document and in adherence to the digital process.
Trust is the basis for successful business relationships. In the digital sphere, new measures are needed to ensure trust in business processes and to prevent fraudulent attacks.
Trust services form the basis of digital business processes. This means that the question of who provides the infrastructure is important. Public authorities, financial institutions and healthcare organizations in particular process sensitive data. Factors such as data location, regulatory requirements and integration into Swiss jurisdiction play an important role for them.
With AI, voices, identities and documents can be faked convincingly. This makes the ability to verify the authenticity of digital information reliably all the more important. Qualified electronic signatures and electronic seals create precisely this basis of trust. They make the origin and integrity of documents verifiable, which is why they are becoming a key component of trustworthy and secure digital business processes.