Sovereign AI: Why Your Data Location Really Matters
Beyond marketing catchphrases, data sovereignty has concrete legal and strategic implications. Explanations through the Swiss case.
The term "digital sovereignty" has become ubiquitous, sometimes losing its meaning. Yet behind the concept lies a very concrete question: who can legally access your data, and under which law? The answer depends primarily on where the data is stored and the jurisdiction of your provider.
The most discussed case is the US CLOUD Act of 2018. This law allows US authorities to demand data from providers subject to US law, even when stored on servers located in Europe. In other words, choosing the European datacenter of an American tech giant is not enough to keep your data out of reach of US law.
Hosting your data in Switzerland with a provider subject to Swiss law fundamentally changes the situation. Requests for access from foreign authorities must go through international mutual legal assistance mechanisms, with supervision by Swiss authorities. For fiduciaries, law firms, or medical practices, this difference is not theoretical: it determines compliance with professional secrecy.
Sovereignty also includes business continuity. A foreign provider can modify its conditions, restrict access to certain markets, or face government injunctions. A local provider, subject to Swiss law and billing in Swiss Francs, offers valuable contractual and monetary predictability for an SMB integrating AI into the core of its processes.
For generative AI, the stakes are amplified by the nature of the data exchanged: your employees' prompts tell the story of your business, your clients, your projects, and your challenges. This is strategic raw material. The question is therefore not just "where are my conversations stored?", but also "who can read, analyse, or use them to train other models?".
A reasonable sovereign approach for a Swiss SMB stands on three principles: data stored exclusively in Switzerland, a provider under Swiss law as the sole contractual partner, and a contractual guarantee that conversations will never be used to train third-party models. This is the architecture we chose for Walterdesk, with hosting in secure, redundant datacenters in Switzerland.