AI Architecture & Sovereignty

Why your data is not safe on AWS, Azure or Google Cloud

Post written by the Wiven team April 2026 · 5 min read

«"Why can't you use AWS?" That's the question a prospect asked us last week. His reasoning was simple: AWS is reliable, scalable, and cheaper. Why complicate things?

Here is our answer.

1. The real problem is not technical, it is legal

When a Swiss SME entrusts its invoices, contracts, supplier data, or HR documents to an AI provider, it is entrusting them with sensitive data. Data protected by law. nLPD (new Federal Data Protection Act), which came into force on September 1, 2023.

The problem with AWS, Azure, or Google Cloud: your data passes through servers subject to American CLOUD Act. In practical terms, a US authority can demand access to your data, even if it is stored in Europe. Even if you are a small business in the canton of Vaud with 30 employees.

Key figure

In 2023, Microsoft received over 35,000 government data access requests worldwide. Your Swiss SME is subject to the same legal scrutiny as all others.

2. "But they have data centers in Switzerland now?"«

Yes, AWS, Azure, and Google Cloud have opened regions in Switzerland. But the physical location of the servers doesn't change the legal issue.

The CLOUD Act applies to any company incorporated under US law, regardless of where its servers are located. An Azure data center in Zurich remains subject to US law.

What matters

It's not where your data is located that matters—it's the legal entity that controls it. A server in Switzerland operated by an American company does not protect your data from the CLOUD Act.

3. What the nLPD says — and the sanctions

The new Swiss Data Protection Act (nLPD) imposes strict requirements regarding the transfer of personal data to countries that do not guarantee an adequate level of protection.

The United States is not on the list of countries offering adequate protection according to the Swiss Federal Council.

Sanctions

Violations of the nLPD can result in fines of up to CHF 250,000 — and these fines target the responsible individuals, not just the company.

4. The CLOUD Act, in concrete terms

The Clarifying Lawful Overseas Use of Data Act (CLOUD Act), adopted in 2018, allows US authorities to compel any US-registered company to provide data stored on its servers, wherever they are in the world.

This means that if your AI provider uses AWS, Azure, or Google Cloud infrastructure, your billing data, contracts, and HR documents could theoretically be accessible to US authorities — without your knowledge.

Critical point

Unlike the European GDPR, the CLOUD Act does not require notification to the data subject. Access can be completely opaque.

5. Copilot, ChatGPT, Gemini — same problem

It's not just a matter of cloud infrastructure. The most popular AI tools — Microsoft Copilot, OpenAI ChatGPT, Google Gemini — are all operated by US companies subject to the CLOUD Act.

Every prompt you send, every document you analyze with these tools, passes through servers controlled by entities governed by US law. Even if your instance is "dedicated" or "European".

6. The Swiss alternative exists

Providers such as Exoscale offer a 100% Swiss cloud infrastructure, operated by companies incorporated under Swiss law. This means:

→ Your data is hosted in Switzerland
→ The legal entity is Swiss (no CLOUD Act)
→ Native nLPD compliance
→ No cross-border data transfer

Our approach

At Wiven, all our AI agents are deployed exclusively on Swiss infrastructure. Our models run on Exoscale servers, guaranteeing complete data sovereignty.

7. How to assess your exposure

Ask yourself these simple questions:

→ Is your AI provider a company governed by Swiss or European law?
→ Does the data pass through servers belonging to American companies?
→ Do you have a Data Processing Agreement (DPA) that complies with the nLPD?
→ Do you know where the data you send to your AI tools is stored?

If you cannot answer these questions with certainty, it is likely that your data is exposed under the CLOUD Act.

Data sovereignty is not a luxury—it's a legal obligation for any Swiss company handling personal data. And with the rise of AI in business, this issue is becoming critical.

Don't let ease of use mask a real legal risk. Choose partners who take the protection of your data as seriously as you do.

Also read: our approach to AI agents for Swiss companies, with data that remains in Switzerland.

Do you want to know if your AI tools comply with the nLPD? Let's talk about it.

Request an audit Discover our solutions