← All articles

Switzerland Wants Off Microsoft. EMBAG Gives It a Legal Framework.

· ozeye
sovereigntyopen-sourcedata-sovereigntyeu-cloud

Switzerland reducing Microsoft dependency through EMBAG open-source law

Switzerland is moving to replace Microsoft across 54,000 federal workstations. The Federal Chancellery confirmed the plan on 19 April, and the 2024 EMBAG law gives it the legal framework to enforce it.

EMBAG: The Law That Makes Open Source the Default

Switzerland's "Federal Law on the Use of Electronic Means for the Fulfillment of Government Tasks" (EMBAG), enacted in 2024, requires government agencies to use open-source software and to release the source code of any software developed by or for the public sector under an open-source license. The only exceptions are when third-party rights or security concerns prevent disclosure.

EMBAG also mandates that non-personal, non-security-sensitive government data be published as Open Government Data. The law creates a dual "open by default" regime: software and data are both presumed public unless a specific exception applies.

This is the legal infrastructure that makes Switzerland's Microsoft exit plan enforceable. Previous calls for alternatives inside the federal administration were dismissed as "tinkering" by Microsoft incumbents. EMBAG reverses the burden of proof. Agencies no longer need to justify choosing open source. They need to justify staying locked into proprietary vendors.

The Numbers Behind the Decision

An investigation by SRF revealed that the Swiss federal government and cantons poured over CHF 1.1 billion (approximately $1.4 billion) into Microsoft licences over the past ten years. That is public money transferred to a foreign corporation for the privilege of depending on it, with no reduction in lock-in, no improvement in sovereignty, and no control over pricing.

The cost argument alone would be enough. But the political risk has made it urgent. The US CLOUD Act allows American law enforcement to compel US-headquartered companies to hand over data regardless of where it is stored. A foreign government can access Swiss federal data on Microsoft infrastructure without Swiss authorities ever being informed. That is not a hypothetical. The ICC's Chief Prosecutor lost access to his own Microsoft email after US sanctions were imposed on the court.

The Feasibility Study and the German Model

Former army chief Thomas Süssli called for alternative solutions to be examined more quickly. A feasibility study has now concluded that replacement with open-source software is technically possible across the federal administration.

Germany serves as the reference case. The state of Schleswig-Holstein has already migrated 80% of its 30,000 government workstations away from Microsoft, saving EUR 15 million in licensing costs in 2026 alone. Switzerland is reportedly interested in the independent open-source solution being developed in Germany, and Bern has engaged with the project.

Metric Switzerland (Federal) Schleswig-Holstein
Workstations 54,000 30,000
10-year Microsoft spend ~$1.4 billion Not disclosed
Migration status Feasibility confirmed 80% complete
Legal basis EMBAG (2024) State-level directive
Open-source default Mandated by law Mandated by policy

The Sovereignty Logic Extends to AI

Switzerland's move follows a pattern already visible across Europe. France ordered all ministries to eliminate extra-European digital dependencies by autumn 2026. Denmark is moving from Microsoft Office to LibreOffice. The ICC switched from Microsoft to European openDesk after its Chief Prosecutor lost access to his email under US sanctions. Europe's desktop migration away from Microsoft is well underway, and the logic applies equally to the AI layer.

Under GDPR Article 45, transfers of personal data to third countries require an adequacy decision or appropriate safeguards. The Schrems II (C-311/18) ruling found that US surveillance law does not provide equivalent protection. Every prompt sent to an American AI provider is a data transfer that violates this standard. Companies and agencies routing AI inference through US-headquartered providers are repeating the Microsoft dependency at a new layer, with the same legal exposure and the same lack of control.

The EMBAG principle of "open by default" translates directly to AI infrastructure. If the source code of government software must be open and auditable, the inference pipeline that processes government data must be equally transparent. That means knowing which subprocessors handle prompts, where they are incorporated, and under which jurisdiction data access requests are processed.

What Swiss Agencies Should Evaluate

For engineering teams inside the Swiss federal administration - and for any EU organisation watching the EMBAG precedent - the assessment criteria for AI infrastructure now mirror the EMBAG requirements:

  1. Jurisdictional clarity. Every provider in the inference chain must be subject to Swiss or EU law, not US law. The full subprocessor list should be published and auditable.

  2. Zero data retention. If prompts and completions are never stored, the question of foreign data access becomes moot. This is the strongest technical measure against CLOUD Act exposure.

  3. Multi-provider routing. EMBAG's anti-lock-in principle applies to infrastructure too. A single-provider dependency recreates the Microsoft problem at the AI layer. Fallback routing eliminates concentration risk.

  4. Open compatibility. EMBAG mandates open-source software. An OpenAI-compatible API that works with existing SDKs and tooling reduces switching costs and preserves the ability to change providers without rewriting integrations.

Switzerland has the legal framework. The feasibility study confirms it is technically possible. The cost data proves it is financially rational. The CLOUD Act proves it is strategically necessary. The German example proves it can be done fast. The only thing left is execution.

Sources