On 18 June 2026, Bloomberg reported that Lugano-based Prem AI is raising a USD 100 million Series A at a valuation of at least USD 500 million - one of the largest Swiss AI fundraises of the year. The number matters less than what it validates: sovereign inference is now a venture-scale category, not a niche concession to risk-averse buyers.
Prem’s product, Fluso, is an encrypted AI workspace that runs large language models entirely inside the customer’s own infrastructure - private cloud, virtual private cloud, or air-gapped on-premises. The architecture is stateless by design: the provider cannot access user data during inference, even if compelled. Each interaction is secured with post-quantum encryption. Earlier rounds - a USD 14 million seed and a USD 6.1 million bridge - were backed by Breyer Capital, Index Ventures, and Sequoia China co-founder Fan Zhang.
The customers tell the story
The target buyers are explicit: hedge funds and law firms. Both handle data - trading strategies, client records, privileged legal correspondence - where exposure to any third-party provider governed by foreign law is an operational risk, not merely a compliance checkbox. These are organisations that have done the calculation and concluded that the most sensitive data in finance and law should not leave infrastructure they control.
That demand signal is the real headline. When the institutions managing the highest-stakes confidential data are willing to pay a premium to keep AI inference inside their own perimeter, sovereign deployment stops being a defensive posture and becomes a procurement standard. The market is pricing the difference between using a model and owning the conditions under which it runs.
The architecture is the same at any scale
What a USD 500 million valuation funds at venture scale, a single Swiss enterprise can replicate in pattern: models running on dedicated hardware under Swiss law, with no data egress and no foreign-jurisdiction dependency. The components are not exotic. Open-weight models now match proprietary systems on the benchmarks that matter for enterprise work; dedicated Swiss hardware runs them without per-token billing or usage telemetry; and the legal framework - data, model, and audit trail in one jurisdiction - is the same whether the workload is a hedge fund’s research desk or a regional bank’s compliance team.
Prem AI’s raise confirms what the demand side has been signalling for some time. For Swiss enterprises evaluating where their AI workloads should run, the relevant question is no longer whether sovereign inference is viable. The capital markets have answered that. The question is whether to treat data control as a feature bolted on after the fact - or as the foundation the deployment is built on.