CTIPilot
← Back to Daily brief 2026-09-02
NOTABLEupdatedNATOB2policy

Swiss federal offices planned to outsource part of the E-ID trust infrastructure to Amazon Web Services; a ministerial veto stopped it in February 2026 on CLOUD Act and digital-sovereignty grounds

Bern almost handed a hyperscaler the register that verifies whether a Swiss digital identity is genuine

Analysis

Republik's investigation, published 2026-09-01, reveals that Switzerland's Federal Office of Justice (Bundesamt für Justiz) and Federal Office of Informatics and Telecommunications (BIT) planned in spring 2026 to award Amazon Web Services a contract covering core components of the Swiss E-ID's "Vertrauensinfrastruktur"; the trust infrastructure that confirms whether a digital identity is genuine and whether a requesting organization is authorized to verify it (Republik, 2026-09-01). The scope covered the Basisregister, which anonymously tracks whether a given E-ID is still valid, and the publicly queryable Vertrauensregister listing every authorized issuer and verifier, from federal, cantonal and communal authorities to private organizations such as banks. AWS was favored chiefly for its around-the-clock data-centre availability, which officials wanted as a fallback given delays in the Confederation's own planned government cloud; the Federal Office of Justice confirmed to Republik that "im Rahmen der Projektarbeiten wurden aus technischer Sicht sämtliche Optionen geprüft" (all options were reviewed from a technical standpoint as part of the project work, translated from German) (Republik, 2026-09-01).

Federal Councillor Beat Jans, the SP minister responsible for approving major federal IT procurements, vetoed the award in mid-February 2026: "an award to Amazon was out of the question," per Republik's sources close to the Federal Council, because handing the task to the American company would directly contradict the Federal Council's own objectives for greater Swiss digital sovereignty (Republik, 2026-09-01). The specific legal exposure behind that reasoning, per Inside IT's own relay of the same insider sourcing, is that Amazon as a US company is subject to the US CLOUD Act (Inside IT Switzerland, 2026-09-01); Republik's and heise's own reporting present the CLOUD Act point as their own explanatory framing rather than folding it into the insider-confirmed statement, so the sourcing on whether Jans's own confirmed rationale explicitly named the CLOUD Act, or only digital sovereignty in general, is not fully consistent across the three outlets. Republik's review of the Confederation's existing 2021 AWS framework contract (obtained after the outlet won a Federal Administrative Court case for disclosure) found a standardized commercial template rather than terms negotiated for state use: Amazon reserves the unilateral right to change the technical basis of the service, liability for outages is minimal, and on contract termination the administration has only 90 days to migrate all its data before Amazon irrevocably deletes it (Republik, 2026-09-01). An expert in decentralized trust architectures quoted by Republik frames the underlying risk independent of the vendor's home jurisdiction: "it becomes questionable when the state makes itself dependent, for critical infrastructure, on a single commercial provider that can discontinue operations, change terms, or impair availability" (translated from German) (Republik, 2026-09-01).

The E-ID's public launch is already delayed from end-2026 to the first half of 2027 for unrelated reasons, open questions on AHV-number lookups, AI-driven deepfake risk to online enrollment, and incompatibility with the EU's own eID system in its first version (Republik, 2026-09-01).

Cited evidence

An award to Amazon was out of the question. (translated from German)

Republik 2026-09-01

It becomes questionable when the state makes itself dependent, for critical infrastructure, on a single commercial provider that can discontinue operations, change terms, or impair availability. (translated from German)

Republik, quoting Martina Kolpondinos (decentralized-trust-architecture expert)

If the cloud contract is terminated, the federal administration has only 90 days to withdraw its data before Amazon irrevocably deletes everything. (translated from German)

Republik 2026-09-01

In light of the latest developments in the field of artificial intelligence, security in the online issuance process for the E-ID is currently being further strengthened. In particular, through the use of additional technical safeguards, it should become harder to introduce malware onto end devices, and the detection of deepfakes should be strengthened.

Worth mentioning in particular are transparency through open source, the conducting of penetration tests, and bug bounty programmes.

Federal Office of Justice / eid.admin.ch (official) 2026-09-03

Updates1

Update

At the 3 September 2026 meeting of the Advisory Council Digital Switzerland, chaired by Justice Minister Beat Jans with Federal Chancellor Viktor Rossi participating, the Federal Department of Justice and Police stated that security in the E-ID's online issuance process is currently being further strengthened in light of recent AI developments: "in particular, through the use of additional technical safeguards, it should become harder to introduce malware onto end devices, and the detection of deepfakes should be strengthened" (eid.admin.ch, 2026-09-03). The release, attributing the emphasis on learning from mistakes to Jans, names the programme's standing security controls as the mechanism for finding such gaps: "transparency through open source, the conducting of penetration tests, and bug bounty programmes" (eid.admin.ch, 2026-09-03). No technical specification of the "additional technical safeguards" (an attestation mechanism, device-integrity check or liveness-detection method) has been published; this is a policy-level commitment, not yet an implementation detail defenders can act on.

Sources4

Revision history

  1. Published 2026-09-02T0411Z-intel
  2. Update 2026-09-05T0409Z-intel

    At the 3 September 2026 Advisory Council Digital Switzerland meeting, the Federal Department of Justice and Police announced it is further strengthening security in the E-ID's online issuance process specifically against AI-enabled threats: additional technical safeguards against malware injection onto end devices during issuance, and reinforced deepfake detection in the identity-verification step. The release reaffirmed open-source transparency, penetration testing and bug bounties as the programme's standing controls.

    Changed: updated_at sources evidence body

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.