A secure local AI server room in a Swiss alpine building. One black server rack stands behind glass beside a window with mountain light.

This article follows I Tried Kimi K3 Inside Claude Code. That test asked whether Kimi K3 could work inside a familiar coding setup. Here, I test a Swiss sovereign AI business case for a provider serving a model of similar scale. This is K3-class inference.

Banks already treat data sovereignty as an operating issue. In How DORA Made Sovereignty a Bank Problem, I argued that banks must plan for concentration, exit, and audit rights. They must also prepare for rule changes by critical foreign providers.

AI gets the same treatment. Recent open-weight releases make local use more realistic because operators can download and run their learned model weights.

Kimi K3 is huge. Alibaba is moving the Qwen family in the same direction. Inkling may matter more. It is a US-trained model with full weights and a focus on customisation. Its one-million-token context window lets it process large amounts of information in one request.

Swiss sovereign AI: the business case

Assume a Swiss provider operates 64 graphics processing units (GPUs) as one connected cluster in Zurich. It sells dedicated or managed K3-class inference to banks, pharmaceutical companies, government bodies, and other customers that need Swiss data residency. Their data remain stored and processed in Switzerland.

This case assumes $7 million in initial costs, monthly costs of $370,000, and average use of 70%. Subscriptions cost CHF 15,000 to CHF 50,000 each month. With these values, one cluster makes about CHF 7.4 million in annual revenue.

The cluster generates about CHF 3 million in earnings before interest, taxes, depreciation, and amortisation (EBITDA). This measure approximates operating profit before financing and non-cash costs. The cluster recovers its initial cost in three years.

Business case for a Swiss sovereign AI provider. It shows equipment, initial cost, monthly costs, customer mix, five-year results, and sensitivity cases.

The product is control

The provider sells control as well as tokens. It offers Swiss residency and a defined security boundary around each customer’s data and systems. It does not train on customer data. Customers receive audit access, service-continuity terms, and an exit route if the provider fails.

Most companies will not put a model in a basement. Some will pay local providers to get the same control.

What can make local AI inference fail

A 2.8-trillion-parameter model costs a lot to serve, and one cluster puts every customer on the same equipment. Hardware also loses value quickly. If customers use it less than expected, the business loses money. A smaller model may work almost as well next year, before the operator recovers the cluster’s cost.

Those risks are real. I still think this market will exist.