Sécurité des données et IA en Suisse : des données protégées à l'intérieur d'un périmètre sécurisé, devant un paysage alpin, symbolisant la souveraineté des données.

AI and data security in Switzerland: where does your data go, and how do you stay in control?

  • Using AI without exposing your data is entirely possible, but it does not happen by itself. Swiss law (the nFADP) applies fully to AI, and liability can fall personally on the company’s director.
  • The same tool does not offer the same guarantees depending on the version used: a consumer version and contractual professional access handle your data very differently.
  • Several deployment levels exist, from a proprietary model governed by contract to fully local (100%) hosting. The right choice depends on the sensitivity of your data, not on a single solution.

As soon as an SME takes an interest in AI, a legitimate concern resurfaces. If my teams use these tools, where does our data go, and who can access it? The question is all the more sensitive in Switzerland, where confidentiality is a strong value and where the law imposes precise obligations. The good news is that security is not a matter of luck, but of architectural choices. You just need to know the options. This article takes stock, without jargon, of what the law says, of the common pitfalls, and of the levels of control available.

Is your data really secure when you use AI?

It can be, provided you make the right choices. In Switzerland, the Federal Act on Data Protection (nFADP) applies fully to processing carried out by AI. Security therefore depends less on the tool than on how it is governed, namely which data, which provider, which hosting, and which internal rules.

The Federal Data Protection and Information Commissioner (FDPIC) is clear. The revised law, in force since 1 September 2023, is drafted in a technology-neutral way and therefore applies directly as soon as an AI processes personal data (FDPIC). In practice, an SME must be able to explain which data is processed, for what purpose, and by what means. When processing presents a high risk to individuals, an impact assessment is even required.

This framework has a consequence that many directors overlook. In the event of an intentional breach, the fine, which can reach CHF 250,000, targets the responsible natural person (the director, a business manager), and not the company, which moreover cannot assume it on their behalf (Graduate Institute Geneva). An exception exists for small fines (up to CHF 50,000). If identifying the responsible person would require disproportionate effort, the company can then be sentenced in their place (FDPIC, criminal provisions). These sanctions concern intentional violations and are generally prosecuted upon complaint, so it is not a matter of dramatizing, but of understanding that liability is real and often personal. That is one more reason to govern the use of AI rather than let it take hold at random.

Yet this governance is often missing. According to the AXA / Sotomo 2025 study, only one Swiss SME in three has defined clear rules on the data its employees may enter into an AI tool, and that proportion falls below a quarter in companies of fewer than ten people (AXA / Sotomo). The most common risk is not a sophisticated cyberattack, but an employee who pastes sensitive information into a consumer tool, with no bad intent.

Why aren’t all uses of ChatGPT or Claude equal?

Because the same tool comes in several versions with very different rules. On consumer versions, your exchanges can be used to train the model unless you change the setting. On professional access, governed by a contract, data is not used for training by default. Knowing which version you are using changes everything.

This is the most misunderstood point, and the one with the heaviest consequences. On their professional offerings (API, enterprise plans), the major providers commit contractually not to use your data to train their models. OpenAI states this clearly, since by default, data sent via the API or professional plans is not used for training (OpenAI). Anthropic applies the same rule to its commercial products (Anthropic). These offerings come with recognized certifications (SOC 2, ISO 27001) and encryption of data in transit and at rest.

On consumer versions, however (free accounts, and in some cases certain individual paid plans), the logic is reversed: since 2025, several providers use conversations by default to improve their models, unless the user disables this option themselves. The same brand, the same model, but two different worlds when it comes to confidentiality. An employee who uses a free personal account to process an internal document does not offer the same guarantees as governed professional access.

The practical consequence is simple. It is not “AI” in general that is safe or not, but the precise version and the contract that comes with it. This is also why ungoverned use (“Shadow AI”, where everyone installs their own tools) is a risk, because the company loses visibility over what is shared and through which channel.

Where does your data really go? The question of sovereignty

Where your data is physically stored (residency) and the law that governs it (sovereignty) are two different things. A US provider, even with servers in Europe, remains subject to US law. For highly sensitive data, this point can justify choosing a Swiss or European operator.

The CLOUD Act, a US federal law adopted in 2018, allows US authorities to require a US-law provider to hand over data in its possession, regardless of where it is stored, including on servers located in Europe. A 2026 analysis by the firm CMS confirms that this framework remains fully relevant and that the location of servers is not enough to escape its reach (the mechanism dates back to a dispute involving Microsoft, as a 2018 analysis from Columbia Law School noted as early as then). Hence an essential distinction. Hosting your data in Frankfurt or Dublin with a US provider ensures data residency in Europe, but not sovereignty. It is the operator, and its legal nationality, that determine which law applies, not merely the server’s location.

We need to be honest about the scope of this risk. In practice, actual access by US authorities to European corporate data remains rare. But for compliance, what matters is not the case-by-case probability, it is the structural legal risk. The “sovereign cloud” or “EU data boundary” offerings from the major US players limit certain access, but do not change their underlying legal obligation. For particularly sensitive data (health, finance, trade secrets), this nuance can justify turning to a Swiss or European operator. The debate remains lively: in 2025, the European Union adopted a declaration on digital sovereignty, a sign that the question of extraterritorial access to data is more topical than ever for European companies.

Which deployment levels help you stay in control?

There is a range of solutions, from the simplest to the most sovereign: a proprietary model governed by contract, an open-source model on a shared then dedicated Swiss cloud, and finally fully local (100%) deployment. Each level shifts the cursor between simplicity, cost, and control of the data. The right choice depends on the sensitivity of your data.

Rather than a single solution, you need to think in levels. Here are the four main options, from the most accessible to the most sovereign:

LevelPrincipleBest when…
1. Governed proprietary modelAccess to a state-of-the-art model (OpenAI, Anthropic) via API or enterprise contract, with non-training guarantees, SOC 2 / ISO 27001, and encryptionYou want the best quality quickly and your data is not highly sensitive
2. Open source, shared Swiss cloudOpen-source model (Llama, Mistral) hosted in Switzerland, infrastructure shared between clients but data kept separateYou want to reduce dependence on US players without the cost of dedicated infrastructure
3. Open source, dedicated Swiss cloudSame principle, but infrastructure reserved for your company alone, in SwitzerlandYour data is sensitive and you want stronger isolation
4. Local deployment (on-premise)The model runs on your own machines, and no data leaves your environmentYou handle highly sensitive data or data subject to strict requirements
Four levels of AI deployment, from the simplest to the most sovereign. The cursor moves between simplicity and cost on one side, control of the data on the other.

Levels 2 and 3 are credible in Switzerland thanks to local sovereign hosting providers. Players such as Infomaniak (which offers open-source models hosted and run exclusively in Switzerland) or Exoscale (data centers in Geneva and Zurich, ISO 27001 certified and outside the CLOUD Act) show that you can run high-performing AI without depending on the US giants. Moreover, the quality gap between open-source and proprietary models has narrowed sharply, which makes these options all the more relevant.

No level is “better” in absolute terms. Level 1 offers the best quality with the least effort, level 4 maximum control at the price of greater complexity and cost. The key is to match the level to the real sensitivity of the data processed, which first requires classifying it.

Beyond hosting, what are the best practices?

The choice of infrastructure is not everything. Encrypting data in transit, defining clear rules on what may or may not be entrusted to AI, and designing flows so that the most sensitive information is never sent to the model are measures that sharply reduce risk, whatever the level chosen.

A few principles apply to every deployment level:

01

Encrypt data in transit.

Exchanges between your users and the model must be encrypted (TLS protocols), a standard practice among serious providers but one that should be verified.

02

Define clear usage rules.

Spell out in black and white which categories of data may be entered into which tools, and which must never be. This is the step most SMEs neglect.

03

Keep sensitive data out of the model.

Flows can be designed so that the most sensitive information (client data, internal references) is never sent to the model and stays in a controlled environment.

04

Set the framework before deploying.

Classifying your data by sensitivity and choosing the right level must precede deployment, not follow it. It is this initial framing that prevents most incidents.

These measures are not a matter of advanced technical skill, but of method. A well-governed AI can be safer than uncontrolled office-software use, whereas an AI deployed without rules can, on the contrary, become an exit door for your most valuable information.

Frequently asked questions

The questions SME directors most often ask us about data security and AI: nFADP compliance, model training, Swiss hosting, and the reach of the CLOUD Act.

It depends on the version and the use. Professional access governed by a contract, with a non-training commitment and security guarantees, can be part of a compliant approach. Unrestricted use via personal accounts, with no rules or contract, on the other hand exposes you to uncontrolled processing. Compliance comes down to governance, not to the tool itself.

On the professional offerings (API, enterprise plans) of OpenAI or Anthropic, no, not by default, because it is a contractual commitment. On consumer versions, however, conversations may be used to improve the models unless the option is disabled. Checking the channel used by your teams is therefore essential.

No, it is not a general obligation. For many everyday uses, a contract-governed proprietary model is enough. Swiss sovereign hosting becomes relevant when the data is particularly sensitive or when sovereignty is a requirement of your clients or your sector.

The risk is mainly legal and structural, because a US provider remains subject to US law, even with servers in Europe. In practice, actual access remains rare, but for a compliance analysis, this point must be documented as a risk, especially for sensitive data.

In this common case, your SME is also subject to the GDPR, in addition to Swiss law. The protection principles are close, but the GDPR’s penalties are far heavier, since they reach 20 million euros or 4% of annual worldwide turnover. Processing the data of people located in the EU therefore demands heightened vigilance over the choice of tools and the governance of flows.

Not necessarily. Local deployment offers maximum control, but a dedicated Swiss cloud or an architecture that keeps sensitive data out of the model can be enough depending on the case. The right level is determined by the real sensitivity of the data and the applicable requirements.

With an inventory. Which tools are already used, by whom, with what data? Then with simple usage rules and the choice of a governed channel. Classifying your data by sensitivity and defining the appropriate deployment level forms the basis of a use that is both useful and controlled.

Sources

  1. Federal Data Protection and Information Commissioner (FDPIC), “AI and data protection”.
  2. Graduate Institute Geneva, “The criminal provisions of the nFADP” (LibGuides Data protection).
  3. Federal Data Protection and Information Commissioner (FDPIC), “Criminal provisions”.
  4. AXA Switzerland / Sotomo institute, “SME labour market study 2025: artificial intelligence”, October 2025.
  5. OpenAI, “Enterprise privacy”.
  6. Anthropic, “Is my data used for model training?” (Privacy Center).
  7. CMS, “Demystifying the debate on the US CLOUD Act vs European/UK Data Sovereignty” (white paper), 2026.
  8. Columbia Law School (Blue Sky Blog), “Debevoise Discusses the U.S. CLOUD Act and Europe’s Response”, 2018.
  9. Infomaniak, “AI Tools” (open-source models hosted in Switzerland).
  10. Exoscale, “Data centers in Switzerland”.
Arvanit GraincaCTO & Founder, Qubitech

Share

Copy link


All publications

Do you want to use AI effectively and with control?

Classifying your data, choosing the right deployment level, and designing a secure architecture from the ground up: this is the core of our support. Let's talk about your context.

Other publications