Swiss AI for SMEs: Apertus, Infomaniak and data protection

Anyone in a Swiss business who wants to process documents, enquiries or reminders with a language model runs into three questions: which model, with which provider, and am I even allowed to send the data there? Since September 2025 there has been Apertus, an open model from Switzerland, and with Infomaniak a provider that runs it in its own data centre. This guide explains what that means for an SME, and where the line to American providers runs. As of 8 October 2026.

Path of a document through AI processing: the document comes from the mailbox, a model in Switzerland reads it, a proposal with an audit log is created, and a person approves it in bexio or myfactoryMailbox or scannerDocument,enquiry or listof open itemsModel inSwitzerlandRead, recognisefields, writethe logProposalDraft with therecognisedvaluesbexio or myfactoryA personreviews andapprovesPath of a document through AI processing: the document comes from the mailbox, a model in Switzerland reads it, a proposal with an audit log is created, and a person approves it in bexio or myfactoryMailbox or scannerDocument, enquiry or list of open itemsModel in SwitzerlandRead, recognise fields, write the logProposalDraft with the recognised valuesbexio or myfactoryA person reviews and approves

What Apertus is

Apertus is the language model of the Swiss AI Initiative, developed by ETH Zurich, EPFL and the national computing centre CSCS in Lugano, trained on the Alps supercomputer. According to the ETH press release, the first version came out on 2 September 2025 in two sizes with 8 and 70 billion parameters, trained on 15 trillion tokens in more than 1,000 languages, including Swiss German and Romansh. What sets it apart is not its size but its openness: weights, training data, training code and intermediate checkpoints are published, under a licence that also permits commercial use. The training data comes only from public sources and respects opt-out requests from websites, even retroactively.

On 24 July 2026, according to CSCS, Apertus 1.5 followed: the models now understand images and audio, have an optional thinking mode, a context window four times longer, and follow instructions and tool calls better. For an SME this means a scanned document can be handed to the model as an image, without text recognition beforehand.

What Apertus is not: a rival to the largest American models. The developers say so themselves. For reading documents, mapping line items and writing texts in the national languages it is enough; for complex programming or long chains of reasoning the large models are further ahead.

Where Apertus runs

An open model is a file, not a service. Whoever wants to use it needs someone to run it:

  • Infomaniak offers Apertus 1.5 70B through its AI Tools, alongside models from Mistral, Qwen and Google, via an interface compatible with OpenAI.
  • Swisscom provides Apertus to business customers through its Swiss AI Platform, according to the ETH release.
  • Public AI runs a chat interface that lets you try the model without installing anything.
  • Run it yourself: the 8B version runs on a powerful workstation, the 70B version needs a graphics card with a lot of memory or a server. Then not a byte leaves the building, but you carry operation and updates yourself.
  • Universities get access through a CSCS service.

The Canton of Ticino translates government documents with its own Apertus service, according to CSCS, and the Basel newsroom Bajour runs the model locally in its editorial office. These are the cases the model is made for: sensitive texts that should not leave the country.

What Infomaniak AI Tools offers

Infomaniak is a Geneva hosting company that runs its AI services in its own data centres in Switzerland. For an SME, four properties matter, all according to the product page:

  • No retention: requests and responses are neither stored nor used to train the models or improve the services.
  • Choice of models: alongside Apertus there are Mistral Small, Qwen, Gemma and other open models, some with image input and context windows of 100,000 to 256,000 tokens. You pick the right model per task without switching provider.
  • Pay as you go: you pay per million tokens processed, separately for input and output, with no base fee; there is a starting credit. A page of a document thus costs less than a centime; the current price list is with the provider.
  • Further services: speech recognition with Whisper, embeddings for semantic search, image generation, function calling and MCP to connect a model to your own application.

For the workflows in this guide (reading a document, turning an enquiry into a quote, writing a reminder text) this is the first choice: Swiss law, Swiss data centre, no retention, open models.

Mistral as the route via the EU

If an open model is not enough, Mistral from Paris is the next step. Processing takes place in the EU according to its privacy policy; inputs and outputs are kept for another 30 days after the response for abuse monitoring, unless the "Zero Data Retention" option is activated, in which case they are not. Data goes to providers outside the EU only in exceptional cases, and then with the standard contractual clauses of the European Commission. The EU is on the Federal Council's list of countries with adequate data protection; a transfer there needs no additional safeguards.

Mistral also has its own model for text recognition from PDFs and images, which is faster and cheaper than a large language model for stacks of documents.

When a US provider is permissible

The models from Anthropic, OpenAI and Google are the strongest on the market, and they process data in the United States. The Swiss Data Protection Act permits a transfer abroad without additional safeguards only to countries with adequate protection. According to its press release of 14 August 2024, the Federal Council put the United States on that list, but only for companies certified under the Swiss-U.S. Data Privacy Framework. The participant list at dataprivacyframework.gov shows whether a provider is certified. Anthropic relies on standard contractual clauses in its privacy policy (as of October 2026) and does not mention the framework; anyone using a US provider therefore checks the list themselves before relying on certification.

Without certification, the route is standard contractual clauses (Art. 16 para. 2 FADP) plus a data processing agreement (Art. 9 FADP) in which the provider guarantees not to use the data for training. The business offerings of the large US providers include such contracts. Added to that is the duty to inform the people concerned that their data goes to the United States, for example in the business's privacy notice.

In short, and without being legal advice:

DataInfomaniak (CH)Mistral (EU)US provider
Supplier invoices, articles, pricesyesyesyes, with contract
Customer addresses, enquiries, remindersyesyesyes, with contract, standard clauses and notice
Sensitive data (health, finances, religion)yes, with consent or legal basisyes, with consent or legal basisonly after case-by-case review
Data under professional secrecy (Art. 321 SCC)only with a contract as auxiliaryto be avoidedto be avoided

Professional secrecy as the limit

Doctors, lawyers, auditors and their auxiliaries are subject to Art. 321 of the Swiss Criminal Code. The Federal Data Protection and Information Commissioner writes on its page on the disclosure of patient data (in German) that IT service providers count as auxiliaries, that for cloud services the patients' consent should be obtained as a precaution, and that cloud services abroad are to be avoided in any case, because foreign law does not always offer protection equivalent to Art. 321. For these professions a model in Switzerland is therefore not a matter of taste but the only option, and even there the provider must be bound by contract as an auxiliary.

For most SMEs this does not apply. A joinery, a trading company or an agency processes ordinary personal data: names, addresses, orders. The Data Protection Act with a data processing agreement and data minimisation is enough, and the choice of provider is a matter of trust, price and performance.

Decision aid

  1. Which data? Ordinary business data, sensitive data or professional secrecy. The higher the level, the closer the processing stays.
  2. Which task? Reading documents, writing texts, mapping line items: an open model in Switzerland is enough. Long analyses, programming, multi-step reasoning: EU or United States.
  3. Which contract? Always a data processing agreement; with US providers also standard contractual clauses or certification, and a note in your own privacy notice.
  4. Only the fields needed: a model that is to read an invoice needs the invoice, not the customer file.
  5. A person approves: what the model produces is a proposal. Posting happens after review, with a log.

If you want to connect the model to bexio, the guide Connect the bexio API to WordPress explains how the interface works. If you would rather not build the workflows yourself: on the page Connect AI to bexio and myfactory I describe three workflows with approval and audit log, processed in Switzerland.

All guides