01 Where we start
Claude, ChatGPT, Copilot and Gemini come from American companies — anyone automating in Europe has to deal with that fact.
02 A European region is not a European company
That the data centre region sits in Frankfurt or Ireland says something about where data is stored, and nothing about where the provider is based.
03 Why the provider's seat counts
A company based in the US is subject to American law, wherever its servers stand.
04 What a data processing agreement settles and what it does not
It settles the purpose, the duration and the instruction-bound nature of the processing; it does not set aside a foreign legal order.
05 The Swiss DSG and the GDPR side by side
Both allow the use but tie it to conditions: data minimisation, purpose limitation, traceability and a basis for transfers abroad. The four questions you have to answer are in Using AI under Swiss data protection law.
05a What the EU AI Act has to do with it
The AI Act does not regulate data residency but the risk of the system — which tier ordinary automation falls into is in The EU AI Act for Swiss companies.
06 The measures that actually help
Send less data to the model, strip personal references before the call, switch retention off at the provider, and log what was read.
07 Measure 1: send only what is needed
A contract does not have to run through a model in full when only three fields are needed.
08 Measure 2: strip personal references first
Names, addresses and contract numbers can be substituted before the model call and restored afterwards.
09 Measure 3: switch retention and training off
On business contracts it can usually be switched off that inputs are stored or used for training — that has to be checked and documented. What applies differs by provider and contract type and has to be checked per provider before use.
10 Measure 4: log it
Being able to show which document was read and which result was produced covers the larger part of the documentation duty.
11 The European route: Mistral
Mistral is a European provider, hosted in France, and so the direct route when data residency carries the decision. Which model we run for which job and where it runs is in AI models and data residency.
12 The own route: self-hosting
An open model on your own infrastructure cuts the whole question off, because no data leaves the building.
13 The open models and where they come from
Kimi, GLM and Qwen are open models originating in China; we name a provider and a seat only where we can evidence them, and we run these models self-hosted only — then their origin has no bearing on the data flow.
14 Llama and Meta
Meta is a US provider, but the models are open and can be self-hosted — the same applies: self-hosted means nothing flows out.
15 What we check before we use a model
The provider's seat, the operating region, the contractual position on retention and training, whether it can be logged — and whether the job needs the model at all.
16 Our rule
If a model does not meet these conditions we do not use it, however well it scores in tests.
17 What you should write down internally
Which tools are approved and who may do what with them belongs in a written rule — what it looks like is in What belongs in an internal AI policy.
Related entries: Using AI under Swiss data protection law · The EU AI Act for Swiss companies · What belongs in an internal AI policy · AI models and data residency