The Problem: Dependence on Foreign AI Is Now a Board Question
For Swiss and European companies, "where does our data go, and who else can reach it?" has moved from an IT detail to a leadership concern. The concern is partly legal, partly commercial and partly strategic, and it is easy to overstate. Not every workload needs a sovereign setup, and a blanket policy can be expensive and slow. But for some data, the question deserves a deliberate answer.
EY Switzerland's May 2026 survey of 604 companies found that 51% consider Swiss or EU data protection compliance business-critical (respondents rated its importance 8.7 out of 10), that 56% support investment in Swiss AI infrastructure, and that 19% cite security and data protection concerns as a main barrier to scaling AI. NTT DATA, a vendor, reports from its 2026 Global AI Report (nearly 5,000 decision-makers in more than 30 markets; the press release does not give the geographic breakdown) that more than 95% recognize the importance of private and sovereign AI, yet only 29% prioritize it in the near term, and 60% of AI leaders name cross-border data restrictions as a major challenge. Read together, the message is that many leaders say sovereignty matters, but few have decided what to do about it.
A Cloud Security Alliance (CSA) research note on EU tech sovereignty puts the concentration in numbers: US hyperscalers hold about 80% of EU cloud spending, it says, and it describes an unresolved tension between the US CLOUD Act, which can require US companies to disclose data on government demand, and European data protection rules, noting that no contractual arrangement fully resolves it. The same note says the European Commission aims to reduce non-EU technology dependence from 80% to 40% by 2030. We could not independently verify these figures, and the note itself flags that some of its forward-looking numbers warrant checking against primary sources, so treat them as indicative. The legal tension is a matter for your counsel.
The Solution: Sovereignty by Tier, Not by Slogan
Sovereignty is not binary. A workable approach sorts AI workloads by the sensitivity of the data and the consequences of losing control, and applies a sovereign path only where it earns its cost.
The options are widening. Apertus, a Swiss open-source language model developed by EPFL, ETH Zurich and the Swiss National Supercomputing Centre, is released under the Apache 2.0 license with documented training data and source code, launched in September 2025, and has been deployed by organizations including Swisscom and Infomaniak. In September 2026, ETH reported that Proton is integrating Apertus 1.5 into its privacy-focused Lumo assistant. A director quoted in that announcement offers a fair caution: "Having our own AI isn't enough. It needs to be competitive so that people actually use it."
A different route is confidential computing. On 16 September 2026, Cohere announced that its Model Vault now encrypts inference using confidential-computing hardware, so that even the provider cannot see customers' prompts and responses. VentureBeat's report is careful about limits: it is unclear whether attestation is verified once at boot or per request, confidential computing "does not resolve every data protection question on its own", customers must validate the attestation reports independently, and open-sourcing of the serving stack for auditors is a future commitment. That announcement is days old and we have not tested it; we mention it as an example of the direction of travel, not as a recommendation.
At national level, the Swiss Federal Council decided in February 2025 to ratify the Council of Europe AI Convention and to amend Swiss law, alongside continued sector-specific regulation. Requirements are still being shaped, which is a reason to design flexibility in now.
The Approach: Four Steps to a Tiered Sovereignty Decision
1. Tier your data. Tier 1: information whose loss or foreign access would be severe or is legally restricted, such as trade secrets, unpublished research or clinical data, and regulated personal data. Tier 2: sensitive but manageable with strong contracts and a Swiss or EU hosting region. Tier 3: everything else.
2. Map vendors to jurisdictions. For each AI tool, find out who operates it, where it runs, which sub-processors it uses and under which legal system. The CSA note recommends mapping third-party SaaS providers to the cloud infrastructure that hosts them; the same applies to AI providers.
3. Choose the deployment for Tier 1. Compare a privately hosted model in your own or a Swiss or EU environment, an open model such as Apertus, and confidential-computing offerings. Each trades some capability, cost or maturity for control, so test them on your actual tasks.
4. Verify, and keep an exit. Ask for evidence rather than assurances, including attestation reports where relevant, and make sure you can switch providers. The CSA note states that EU Data Act cloud-switching provisions have applied since September 2025, with switching fees to be eliminated by September 2027; confirm the current legal position with your counsel.
The goal is not to move everything onto a sovereign stack. It is to be able to say which data is on which path, and why.
How ANG Associates Can Help
ANG Associates advises on a Sovereign Path for the small share of AI workloads that warrant it. We work with your business, IT, legal and security leads to tier your data, map your AI vendors to their hosting and jurisdictions, and assess deployment options for your Tier 1 use cases against your real requirements for capability, cost and control. You receive a documented decision by workload, a verification checklist to hold providers to their claims, and a pilot plan to test the preferred option before committing.
ANG is an independent advisor: we do not host models, resell infrastructure or take fees from vendors, so the comparison is not tilted toward any provider. Our Life Sciences background is relevant where research and clinical data are involved. As always, legal questions on data transfer, the CLOUD Act or the Swiss and EU regimes stay with your counsel; we make sure the technical facts they need are established first.
This is one of six services in our ANG AI Trust Compass offering.
Sources
- EY Switzerland, AI survey of Swiss companies (604 respondents, May 2026)
- NTT DATA, 2026 Global AI Report press release (14 May 2026; vendor press release; survey dates and regional breakdown not given)
- Cloud Security Alliance, research note on EU tech sovereignty, cloud, AI and enterprise risk (figures not independently verified; the note flags forward-looking numbers for checking against primary sources)
- ETH Zurich, news item on the Apertus and Proton Lumo partnership (September 2026)
- VentureBeat, report on Cohere's Model Vault and encrypted inference (announced 16 September 2026)
- Swiss Federal Council press release on AI regulation (12 February 2025)