All articles
Compliance

The US CLOUD Act explained: what Swiss companies need to know in 2026

The US CLOUD Act lets US authorities access data held by US companies, regardless of server location. What that means for Swiss firms and how to protect yourself.

The US CLOUD Act compels US companies to hand over stored data on the order of US authorities, regardless of where the servers physically stand. For Swiss companies this means: a data center in Zurich does not protect you if the operator is a US corporation.

In short: What matters is the provider’s jurisdiction, not the location of the hard drive. Sovereignty only arises when no US parent company can be compelled to disclose.

What is the US CLOUD Act?

The Clarifying Lawful Overseas Use of Data Act of 2018 makes clear that US companies must disclose data they own, hold, or control, even when that data is stored outside the US. The obligation follows the company, not the location of the data. A US corporation can therefore be compelled to hand over data on Swiss or EU servers.

Why doesn’t a Swiss or EU data center protect you?

Many providers advertise a region in Switzerland or the EU. But that answers the wrong question. What matters is not where the server stands, but which law the operator answers to. If a US corporation runs the data center, it stays subject to US law. Even an Azure region in Switzerland is subject to the CLOUD Act, because Microsoft is a US company.

For Swiss firms this creates a conflict between two legal orders: revFADP and GDPR require an adequate level of protection for transfers abroad, while the CLOUD Act can compel exactly that disclosure.

The Microsoft case before the French Senate

That a contractual assurance does not neutralise this reach was conceded by Microsoft before the French Senate in 2025: the company could not guarantee that data stored in the EU is shielded from access by US authorities. A promise on paper does not change the underlying jurisdiction.

What does this mean for Swiss companies?

Anyone processing personal or business-critical data in an AI system should judge the provider not by server location, but by its jurisdiction and operator structure. Real independence arises when the operator is not subject to US jurisdiction, or when the data never leaves your own data center.

Checklist: five questions for your AI provider

  1. Where is the operator legally incorporated, and which law does it answer to?
  2. Can the provider be compelled by a foreign authority to disclose data?
  3. Is my data used for model training?
  4. Can I control the processing location per task?
  5. Is every processing step traceable in the audit trail?

How AIgent answers these questions is on our page on GDPR-compliant AI.

Common questions

Does the US CLOUD Act also apply to subsidiaries in Switzerland?

Yes. What matters is control by the US parent. A Swiss subsidiary of a US company can be reached through the group structure.

Does encryption help against access?

Only if the provider does not control the keys. If the US operator also manages the keys, access remains possible. Separate key management or on-premise operation rules that out.

How does AIgent avoid the problem?

AIgent runs in Swiss data centers or fully on-premise, independent of US hyperscalers. There is no US parent company that could be compelled to disclose.