← Back to blog

A Swiss hospital keeps the model inside the building


Most arguments for sovereign AI are made in the abstract - a risk register, a clause in a data-processing agreement, a hypothetical about foreign disclosure orders. Lausanne University Hospital has turned the argument into a clinical trial.

CHUV has begun a four-year trial of Meditron, a medical large language model built on Apertus, the Swiss foundation model developed by EPFL, ETH Zurich, and CSCS. The system supports decision-making in the emergency department. More than 300 clinicians evaluated it before the pilot went live in May 2026.

The architecture is the notable part. CHUV fine-tunes the model on its own patient records without sending any of that data to a foreign technology company. A Swiss-origin base model, adapted on Swiss infrastructure, deployed inside the hospital’s own network perimeter. Every inference request begins and ends within the institution.

Why this data could not go anywhere else

Emergency-department records sit at the intersection of nearly every data-protection obligation Swiss law imposes. Federal data-protection law applies. Cantonal health-data rules apply. Professional secrecy applies independently of both, and it binds the clinician rather than the institution’s IT department.

There is no version of this project that routes patient records through a general-purpose foreign API and remains straightforwardly defensible. The choice was not between a convenient option and a sovereign one; sovereignty was the only architecture that made the project possible at all.

The trade-off that did not appear

The interesting result is what CHUV did not have to give up. The prevailing assumption for several years was that keeping data in-jurisdiction meant accepting a materially weaker model - that frontier capability lived with the largest providers, and everyone else worked with what was left over.

A domain-specific model built on an open Swiss foundation, fine-tuned on the institution’s own high-quality clinical data, is a serious counter-example. For a narrow, high-stakes task, adaptation on proprietary in-domain records is often worth more than raw scale in a general-purpose model. The hospital’s own records are an asset no external provider has, and using them is only possible where they are allowed to remain.

Where the template transfers

The pattern generalises past medicine to any institution whose most valuable data is also its most restricted.

A pharmaceutical firm holds clinical-trial results and proprietary formulations. A precision manufacturer holds process recipes and yield data. A materials-science group holds experimental records representing years of funded work. In each case the data that would make an AI system genuinely useful is the data that must not leave the organisation’s control - and the useful system is therefore the one built where the data already sits.

CHUV’s contribution is to show the full path: choose a foundation model with permissive licensing and a known provenance, adapt it on institutional data, run it on infrastructure inside the compliance boundary, and validate it with the professionals who will rely on it before it touches a live workflow.

The precedent matters as much as the pilot

A four-year trial in a university hospital produces something a vendor case study cannot: evidence, gathered under clinical governance, that a sovereign deployment can carry a regulated workload safely.

That evidence is portable. The next Swiss institution weighing the same decision - a hospital group, an insurer, a manufacturer with sensitive process data - now has a reference point in its own jurisdiction, under its own law, rather than a marketing claim from a supplier. For anyone who has had to justify an AI architecture to a compliance function, that is the difference between a proposal and a precedent.