AI Sovereignty Starts at the Inference Layer not the Border
Swiss banks understood the risks of foreign infrastructure. AI now shows why data sovereignty must cover inference, not just storage.
For fifteen years, Swiss banks resisted placing sensitive workloads in foreign datacentres. The concern was not simply where data was stored. It was who could access, control and audit the systems processing it.
They were right.
A foreign large language model does not need to retain your data permanently to create a sovereignty problem. It processes your prompts, documents and outputs inside infrastructure controlled by another provider, often under another jurisdiction. Data residency rules that focus on storage do not fully address that exposure.
The issue is becoming harder for governments and regulated organisations to ignore. Following a cyberattack that reportedly exposed data relating to 700,000 French taxpayers, France’s Budget Minister David Amiel said the government would use sovereign AI providers, including Mistral, to test public systems for vulnerabilities.
Mistral already had a defence framework agreement with France’s Ministry of the Armed Forces from January 2026. The infrastructure and supplier relationship existed before the breach made the policy shift more visible.
What is actually new here?
The concern about foreign cloud infrastructure is not new. Swiss financial institutions have long treated jurisdiction, access rights and right to audit as material risks. European organisations have also spent years debating the limits of cloud sovereignty and the consequences of laws such as the US CLOUD Act.
What has changed is the processing model.
A conventional cloud service may store a database, application or backup in a defined region. A foreign AI service may route prompts through several systems, perform inference on remote accelerators, update supporting models and apply provider-level policies outside the customer’s direct control.
That makes the model itself part of the trust boundary.
FINMA Circular 2023/1 allows Swiss banks to outsource activities, including to providers abroad, provided that appropriate safeguards, risk management and audit rights are maintained. Those controls were designed for outsourcing arrangements where the organisation can define the service, location and access conditions.
AI complicates the arrangement. A standard data-processing agreement may restrict storage locations and subcontractors, but it may not answer more important questions:
- Are prompts retained?
- Are they used to train or improve a model?
- Can model weights or safety systems change without customer approval?
- Where is inference performed?
- Can the provider reroute processing during an outage?
- Can the customer independently verify the answers?
A contract can address some of these questions. It cannot automatically provide technical control over a foreign provider’s infrastructure or model lifecycle.
And the biggest concern by far is, if your red team happen to be using a powerful cyber security capable model like Z.AIs GLM 5.3 because they cannot use Anthropic's Fable 5 without setting off guardrails, then your organisations critical vulnerabilities and proprietary codebase might be have already been shared with a Chinese entity.
Which organisations are actually exposed?
Most companies do not need to replace every foreign AI tool immediately. A marketing team generating public copy is not facing the same risk as a defence contractor summarising classified documents.
The exposure depends on the information entering the model and what the model can access. Sensitive use cases include internal investigations, source code, unreleased product designs, regulated customer records, government information and operational details about critical infrastructure.
The practical consequences are straightforward:
- A classified prompt could become part of a foreign provider’s retained data or improvement process if the contract and configuration permit it.
- A government customer could reject a supplier whose military or critical-infrastructure work depends on a non-sovereign API.
- A CISO may be unable to audit inference paths, model changes or provider access because the relevant systems and weights sit beyond the organisation’s jurisdiction.
This is not an argument that every foreign model is unsafe. It is an argument that the risk assessment must cover more than encryption and storage location.
As I argued in Europe Wants Sovereign Cloud, sovereignty is not a label that a provider earns by placing servers inside Europe. Legal control, operational control and technical control all matter.
What can a CISO do this week?
Start with an inventory of AI use, not an inventory of AI subscriptions. Ask business units which models they use, what data they submit and whether those models can access internal systems. Shadow AI often creates a bigger immediate problem than the centrally approved platform.
Then divide use cases into three categories: public information, confidential business information and restricted information. Block restricted information from external models until procurement, legal and security teams have established an approved processing route.
Finally, update AI supplier reviews. The questions should include retention, training exclusion, inference location, routing, model-change notification, administrator access, logging, audit rights and exit arrangements. If the supplier cannot answer them clearly, the service is not suitable for the most sensitive workloads.
That work can begin without purchasing a new platform. It is a governance and visibility exercise before it becomes a technology project. Smaller organisations can use the practical guidance in Your SME doesn’t build AI, but it desperately needs an AI security strategy as a starting point.
Where does Switzerland go next?
European governments are likely to place tighter conditions on AI used in defence, public administration and critical infrastructure. The question for Switzerland is not simply whether it wants a domestic model. It is whether it wants meaningful control over the systems that interpret its most sensitive information.
Apertus may become part of that conversation, just as Mistral has become part of France’s. The important shift is broader than any individual vendor: AI procurement is becoming a sovereignty decision.
The next contract review should therefore ask not only, “Where is our data stored?” It should also ask, “Who controls the layer that processes it?”
Sources
- FINMA, Outsourcing, banks and insurers, FINMA Circular 2018/3, the current FINMA outsourcing framework referenced in the supplied text.
- French Ministry of the Armed Forces, Mistral AI defence framework agreement, reportedly signed in January 2026.