Everything that is protected by regulation, confidential, or business-critical. That covers three categories.
Regulated data. Under FINMA rules, banks may not hand over customer data, risk analyses, or trading strategies. Law firms are bound by professional secrecy, which demands absolute confidentiality for mandates, contracts, and communication. In medicine, the Swiss DPA, GDPR, and professional secrecy protect patient data, diagnoses, and treatment plans. In all these cases cloud solutions often fail the requirements, and on-premise is frequently the only legally safe option.
Sensitive business data. Trade secrets, proprietary algorithms, M&A documents, strategy papers, and financial forecasts do not belong on someone else’s servers. Whoever puts such data in the cloud loses control over who sees it and where it ends up.
Data under Swiss data sovereignty. Some data simply has to stay in Switzerland. Cloud providers, however, often store and process abroad, with corresponding conflicts with Swiss law.
Why the cloud is a risk here
AI models can only process unencrypted data. During processing, your content therefore lies open at the cloud provider, no matter how well the transmission is encrypted. That makes access possible for the provider itself and for foreign authorities (see the US Cloud Act), and you no longer have full control over what happens to the data.
On-premise as the solution
With on-premise AI, the data never leaves your premises: no sharing with third parties, full control over access, backup, and deletion, compliance with Swiss law. For the highest security levels, even air-gapped systems are possible, environments fully isolated from the internet. That is something a cloud cannot offer by design.
Next steps
Contact us for advice on data protection and compliance
Sources and further information:
- Does on-premise AI make sense for SMEs? (compliance and data protection)