Sovereign AI · Compliance

GDPR- and FADP-compliant AI.
Swiss-hosted, outside the US Cloud Act.

GDPR- and revFADP-compliant AI means your data is processed in Swiss data centers, outside the reach of the US CLOUD Act and with no training on your content. AIgent is built sovereign from the ground up.

Fundamentals

What does GDPR- and FADP-compliant AI mean?

GDPR- and FADP-compliant AI is an AI system whose data processing meets the requirements of the EU General Data Protection Regulation and the revised Swiss Federal Act on Data Protection: a lawful basis, purpose limitation, data minimisation, data subject rights, and a verifiable record of processing. Compliance comes not from a label, but from the data location, the operator's jurisdiction, and the traceability of every processing step.

With AIgent that means, concretely: processing in Swiss data centers under Swiss law, no handover of your content to model training, a data processing agreement provided as a template, and a complete audit trail with model, tokens, cost, and time. Data export and account deletion are built in, so data subject rights are met without special processes.

Legal landscape

revFADP or GDPR: which applies to your company?

Swiss companies are governed first by the revised Federal Act on Data Protection (revFADP), in force since 1 September 2023, which regulates the processing of personal data in Switzerland. The GDPR applies in addition, as soon as you offer goods or services to people in the EU or monitor their behaviour. The two frameworks are closely related and both require a legal basis, transparency, and a data processing agreement.

The decisive point for AI: both laws tie the admissibility of a transfer abroad to an adequate level of data protection. This is exactly where many cloud AI offerings fail, because the data is in practice exposed to the reach of a foreign jurisdiction. The statutory text (Fedlex) and the Federal Data Protection Commissioner (FDPIC) document the requirements in detail.

US CLOUD Act

Why EU or Swiss hosting with US providers does not protect you.

The US CLOUD Act of 2018 compels US companies to hand over stored data on the order of US authorities, regardless of where the servers physically stand. A data center in Zurich or Frankfurt changes nothing, as long as the operator is a US corporation or its subsidiary. What matters is the provider's jurisdiction, not the location of the hard drive.

That a contractual assurance does not neutralise this reach was conceded by Microsoft before the French Senate in 2025: the company could not guarantee that data stored in the EU is shielded from access by US authorities. AIgent removes the problem at the root: there is no US parent company that could be compelled to disclose. About the US CLOUD Act.

A glass vault with a Swiss cross, symbolising data control
Data control

Your data stays in your jurisdiction.

Sovereignty means your data stays where Swiss law applies, and that no foreign provider can be compelled to hand it over. The key rests with you, not with a US corporation.

Whether in Swiss data centers or fully on-premise: you decide the processing location, and the complete audit trail evidences every processing step.

Comparison

AIgent versus typical US-hyperscaler hosting.

The same AI models, a fundamentally different legal frame. The difference is not the model, but who can legally reach the data.

Comparison of the data protection properties of AIgent and US-hyperscaler hosting
US hyperscaler (Azure/AWS/GCP)AIgent (Swiss DC / on-premise)
Server location selectable in Switzerland Yes Yes
Operator governed by Swiss law No Yes
Outside the US CLOUD Act No Yes
No training on your data No Yes
On-premise up to air-gapped No Yes
Model choice per data class No Yes
Complete audit trail No Yes

Comparison based on publicly available information, as of July 2026. "US hyperscaler" means hosting by a US company, including in a Swiss or EU region.

Checklist · Information gain

Five questions for any AI provider.

These five questions separate sovereign AI from a security label. Ask them of every provider before you process personal data.

Question 1

Where is the operator legally incorporated?

Not where the servers stand, but which law the provider answers to. A US corporation stays subject to US law, even with a data center in Zurich.

Question 2

Is my data used to train models?

Require a written assurance that inputs and documents never flow into model training. With AIgent that is the default.

Question 3

Is there a data processing agreement (DPA)?

Every processing of personal data needs a DPA under revFADP and GDPR. Without one, the use is not compliant.

Question 4

Can I control the processing location per task?

Sovereignty means control over each individual processing step, not a blanket region label.

Question 5

Is every AI processing step traceable?

Without an audit trail recording model, time, and cost, no data protection officer can evidence the processing.

Last updated: 8 July 2026

Questions & answers

Common questions about GDPR-compliant AI.

Does AIgent require a data processing agreement (DPA)?
Yes. As soon as an AI system processes personal data on your behalf, revFADP and GDPR require a data processing agreement. For AIgent we provide a DPA template covering the purpose, data categories, technical and organisational measures, and the sub-processors. Because processing happens in Swiss data centers by default, the usual basis for a third-country transfer to the US does not arise. In on-premise operation you process exclusively on your own infrastructure, so commissioned processing in the narrow sense no longer applies.
Where exactly are the servers?
By default, in data centers in Switzerland, operated under Swiss law and independent of US hyperscalers. That places neither the location nor the operator under the US CLOUD Act. For full control, you run AIgent on-premise on your own Kubernetes cluster, up to air-gapped with no internet connection. In both cases your data never leaves the chosen environment, unless you deliberately connect an international model for non-critical tasks.
Does AIgent train on our data?
No. Your inputs, documents, and chat histories do not flow into model training. Models run as inference over a protected interface; your content stays your content. This applies to the Swiss-hosted models as well as to connected international models, whose providers we contractually bind to the same principle.
What does the EU AI Act change for Swiss companies?
The EU AI Act applies to Swiss companies via the marketplace principle, as soon as their AI outputs are used in the EU. Depending on the risk class it requires transparency, documentation, and human oversight. AIgent supports this with a complete audit trail, transparent agent reasoning instead of a black box, and central management of rights and models, so you can evidence the required traceability.
Who can see our data?
Only you and the people you authorise. You manage access, roles, and rights centrally, and in on-premise operation through your own directory with single sign-on. AIgent does not access your content to train models or produce analytics for third parties. Every access is traceable in the audit trail.

Sovereign AI. For every discerning company.

On your use-case, in your environment, within a clearly defined scope. See measurable results within a few weeks.

Secure early access. No per-seat fees. No lock-in.