What sovereign AI actually means for Swiss companies

If you sell discretion, you have a problem the moment a client asks where the data goes. Sovereignty is the answer, and it is not a product but a dial.

Guide · Published 16 Jul 2026 · Updated 24 Aug 2026 · Joel Barmettler

What sovereign AI actually means

Sovereign AI means that you decide who gets to see your most confidential data. It is not a finished product but a degree of control over four questions: which model does the work, where it runs, who sees the data, and whether you can switch providers. How much control you need depends on how confidential your data is.

In brief

  • You do not have to choose between all or nothing. Sovereignty has six axes, and you set each one separately.
  • Two mix-ups cost you room to manoeuvre: “hosted in Switzerland” does not yet mean sovereign, and open weights are not the same as open source.
  • Do not budget for higher costs. Budget for more work: nobody delivers everything from a single source.
  • If you sell discretion, you should be able to prove it in your AI too. Otherwise your own promise stands against your own technology.

A pattern repeats across our mandates. A law firm, a trustee, a medical practice lives on discretion; it is the actual product. Then AI arrives, and suddenly exactly that confidential data flows through a chat service to an American corporation. As long as nobody asks, it goes unnoticed. The moment a client does ask, the promise of discretion stands against the technology behind it.

Sovereign AI is about closing that gap. The decision reaches further than this month’s chatbot: it lays a foundation for years, and nobody swaps a foundation in passing.

This article opens our five-part series on sovereign AI. It sets out the terms; the four further parts work through the decision layers one by one.

Sovereignty is a mixing desk, not a light switch

The most common mistake is treating sovereignty as a yes-or-no question. That ends in one of two dead ends. The first: “everything must run in-house,” expensive and rarely necessary. The other: “we sit in a Swiss data centre, so we are sovereign,” a widespread fallacy.

Sovereignty in fact has several axes, and you set each one on its own. A model with open weights running on an American cloud is not sovereign. A Swiss provider delivering an impenetrable black box is not either. Only together do they form a picture:

less sovereign more sovereign →
Jurisdiction
US
EU
Switzerland
Model
closed
open weights
open + training data
Software
proprietary
open code
true open source
Operation
US cloud
Swiss provider
in-house
Data
provider may train on it
contractually forbidden
technically impossible
Integration
proprietary API
open standards
in-house

Nobody needs every dial turned all the way to the right. The text of a marketing brochure is fine on the left; HR files need several dials moved to the right. The work lies in deciding this separately for every category of data.

Two terms are worth keeping apart, because providers like to blur them. Open weights means you may download the finished model and run it yourself. Open source goes further and also discloses the training code and the training data. Meta, for instance, calls its Llama models “open source,” even though the training data stays locked away and the licence restricts use; the Open Source Initiative explicitly disagrees. The Swiss model Apertus, developed by ETH Zurich, EPFL and the CSCS supercomputing centre, meets the stricter definition: weights, data and code are all open.

Why this matters for Swiss SMEs

The driver is rarely big geopolitics. There are four sober reasons.

Cost. Sovereignty has a reputation for being expensive. For models, the opposite is true: open models cost a fraction, per token, of the large American ones, and that advantage holds wherever you run the model. Whether your own server pays off is then a question of utilisation. Book an interface and you pay only for what you use; your own hardware only pays off under consistently high load. And a Swiss data centre is not automatically cheaper than AWS, but is often competitive on compute and storage.

Key figure

around a fifth
What a leading open model like GLM-5.2 costs per token compared with a comparable US model. The total price also depends on token consumption. Proton runs exactly this model for its assistant Lumo on European servers.

Source: Artificial Analysis and price lists from Z.ai and Anthropic, as of July 2026

Why the cheapest model is nonetheless rarely the least expensive one, we worked through in our article on LLM cost. That capable AI can run entirely on European infrastructure is shown by Proton with Lumo.

Lock-in. How easily could your company get out of Microsoft 365 today? With AI the same question arises again, and the lock-in sits deeper. Open weights and open software hand the freedom back: nobody can take away what you build today or change it overnight. And because the same open model runs at many hosts, you switch operator whenever it suits you.

Consistency. If you sell trust, you have to deliver it in your technology too. If a client learns that their data sits with an American corporation via an AI service, they will draw their own conclusions about the discretion you have promised so often. With sovereign AI, the question never arises in the first place.

Equal footing. One provider sends three hundred pages of terms and conditions and a support queue. The other, say a Swiss data centre such as SteppingStone, sits an hour away, runs the same open model at a similar price, and signs a contract you helped negotiate. With the hyperscaler you are a number in a ticketing system; with the Swiss provider, someone who knows your business sits across the table from you.

It does happen that a US provider actually locks someone out, though for most SMEs it is not an everyday risk. When the American government sanctioned the Chief Prosecutor of the International Criminal Court in 2025, his Microsoft account was suspended shortly afterwards. Microsoft soon after admitted before a French court that it could not prevent access under the US CLOUD Act, even for data held on European servers. It shows where control actually sits when it matters.

The honest price of sovereignty

Sovereignty has a price. It just sits somewhere other than most people assume.

Microsoft delivers model, platform, hosting and advice on one invoice, with a single contact you can hold accountable when something goes wrong. Whoever goes sovereign gives up that convenience. In the end, you might run an open model such as Apertus or Gemma at a Swiss host, through an interface such as Open WebUI, on a server from Infomaniak, looked after by a partner such as VSHN. Four building blocks, four contracts, where Microsoft provides a single one.

The price, then, is not the licence but the work of joining these parts into a whole and maintaining that over years. Sovereign AI therefore calls for a role the Microsoft model does not even have: someone independent, who masters the building blocks and negotiates with you and with the Swiss providers as an equal. Without that role, what is left in the end is an unfinished tinkering project.

The four layers

Sovereign AI is built on four layers, each with its own question and its own article in this series.

  • Strategy. Where does sovereignty begin for you, and which data needs how much of it? This is where you set the dials, before anything is procured.
  • Infrastructure. Which model does the work, and where does it run? Open weights and Swiss operation decide whether the intelligence belongs to you.
  • Platform. What does your team work with daily, and could you ever get out of it again? Open tools keep your data and your freedom to switch in your own hands.
  • Integration. How does AI connect to your specialist applications? Open standards ensure your most confidential documents never leave the building.

The following articles take up the layers in order, from strategy through to integration.

What this means for your company

Sovereign AI is a foundation that belongs to you: free of lasting lock-in, in keeping with what you promise your clients. The first step is a sober stocktaking, not yet a technology question: what data do you hold, how sensitive is it, and where does the dial need to sit for each category? Out of that basic question come a series of concrete, affordable decisions.

What these dials look like in practice is what the further parts of the series show: strategy, infrastructure, platform and integration, each its own decision layer.

Frequently asked questions

What does sovereign AI mean?
Sovereign AI means you decide, at every layer of an AI solution, which model does the work, where it runs, who sees the data and whether you can switch providers. Sovereign AI is not a single product. The term describes a degree of control that you choose yourself, depending on how confidential your data is.
Is sovereign AI more expensive than ChatGPT or Microsoft Copilot?
Not necessarily. Open models often cost a fraction, per token, of the large US models, and a Swiss data centre such as Infomaniak is often competitive with AWS or Azure on compute. Whether running it yourself pays off depends on utilisation, though. What makes sovereign AI demanding is above all that you assemble the building blocks yourself, since nobody delivers everything from a single source.
Which AI comes from Switzerland?
The best-known Swiss model is Apertus, developed by ETH Zurich, EPFL and the CSCS supercomputing centre. It is fully open: weights, training data and code are all disclosed. Alongside it, Swiss hosts such as Infomaniak run open models on their own infrastructure.
What is the difference between open weights and open source?
Open weights means you may download the finished model and run it yourself. Open source goes further and also discloses the training code and details of the training data, under a free licence. Many models marketed as "open source" are, strictly speaking, only open weight. The Swiss Apertus meets the stricter definition.
Does an SME even need sovereign AI?
Not for everything, but for the right data. For publicly accessible tasks, a standard service is often enough. As soon as client, patient, case or HR data is involved, sovereignty decides whether you can defend that use to clients and regulators. The skill lies in setting the dial correctly for each category of data, not demanding the maximum everywhere.

LinkedIn

Share this article

Ready-formatted graphics and a suggested post for your LinkedIn feed: download, copy, post.

Six axes of AI sovereignty with three levels each: jurisdiction, model, software, operation, data and integration, from the convenient to the sovereign level. The decision is made per data class.

Suggested post

Do you sell your clients discretion? Then it is worth asking whether your technology keeps that promise.

In law firms, trust offices and medical practices, confidentiality is the actual product. With AI, exactly that data flows through a chat service to a US corporation. How real this is showed in 2025, in the case of the Chief Prosecutor of the International Criminal Court: after US sanctions, his Microsoft account was suspended, and Microsoft later admitted before a French court that it could not prevent access under the US CLOUD Act, even for data held on European servers.

Sovereignty is therefore not a switch with two positions. It has six axes with three levels each: jurisdiction, model, software, operation, data and integration. Our conclusion from advisory practice: nobody needs every dial turned all the way to the right. The decision is made per data class, and the price of the right-hand column is effort, not a licence fee.

The article explains all six axes individually, the mixing desk as a table to work through your own data classes, and seven questions for your next provider choice. Link in the comments.

#AI #DataSovereignty #Switzerland #SME