5 min read

Repatriating Our Digital Economy: Making the case for data autonomy and a Canadian sovereign cloud

Repatriating Our Digital Economy: Making the case for data autonomy and a Canadian sovereign cloud

Originally published in the

Ottawa is finally spending on sovereign infrastructure. Data centres on Canadian soil don’t answer the only question that matters: Who can compel us to hand over our data?

The Digital Sovereignty Debate

Digital sovereignty went from an afterthought to a dinner-table topic in about five years. In our rush to keep pace with everyone else's digital ambitions, we quietly wired the country's nervous system through infrastructure we don't own and can't govern. It’s an exposure that buys us a level of strategic risk Canada has not faced in the digital era.

You can lock your house but still lose everything inside if someone else has your keys.

Most of the debate about Canadian digital security is stuck on the technology or compliance fights while ignoring the ground the servers sit on and the laws that govern them. We're having the wrong argument. Cybersecurity is theatre if the box behind it answers to a foreign court. Petabytes of our domestic traffic still boomerangs through American exchange points across town, open to foreign collection the whole way.

The AI Blind Spot is the Training Data

Now bolt AI onto that threat risk, which is what every sector is doing. A model is only as trustworthy as the data it trained on, and almost no Canadian enterprise or government shop can tell you where that data came from, who owns it, or whether they had the right to use it. This lack of scrutiny is how you end up with hallucination, copyright landmines, and quiet data leakage baked into systems people are about to trust with real decisions. A slick model trained on data nobody can trace is just a black box wearing a maple leaf.

Provenance is not compliance theatre. It is the line between an AI system you can defend in a courtroom or a crisis and one you can't defend anywhere. Federal procurement should demand a training-data bill of materials (TDBOM), full stop. We insist on knowing where and how our food is sourced. We should accept nothing less for the data steering our national interests.

 
The Scale of Foreign Cloud Dependency

Drop the algorithms and look where you are. Canada runs its digital life on hardware it doesn't control. By the Balsillie School’s estimate, around 80 percent of our cloud services lean on foreign infrastructure, and roughly 60 percent run on American servers under American law. A Global News report in September 2025 revealed that Ottawa spent close to $1.3B on US cloud hosting. Just last month, Policy Options called DND’s Defence 365 nothing more than Microsoft 365 with a Canadian wrapper. We would never let a foreign company run our ports or our power grid, yet we handed them the data without a second thought.

It is a comfortable excuse to say that a server inside Canadian borders is somehow beyond foreign reach. The US CLOUD Act says otherwise. It lets American courts compel any provider under US jurisdiction to produce records wherever the machines physically live, which means a subpoena to a US-parented hyperscaler sails clean past any Canadian judge. Ireland found this out the hard way in 2018 (United States v. Microsoft Corp.) when a US warrant for emails stored in Dublin pushed Congress to pass the CLOUD Act, settling the question in favour of reach. A new warrant was issued, and Microsoft did hand over those emails. “Stored in Canada” is a marketing line, not a legal shield.

Comparative Cloud Jurisdiction Risk

Critical Question

Foreign-Owned Cloud

Canadian Sovereign Cloud

Where does your data physically sit?

In Canada.

Located in Canada

Whose laws actually apply to it?

U.S. law can reach it. A U.S. court can order it handed over, even when it's stored on Canadian soil.

Canadian law, and only Canadian law.

Who runs it day-to-day?

A foreign parent company.

A Canadian company.

Who holds the keys to unlock and read it?

The provider does, and its home government can force their use.

You do, and only you.

How exposed does that leave you?

High (~80% foreign infrastructure)

Low. It stays under Canadian control.

Many Canadian IT leaders will tell you that critics say ownership is a weak proxy for security, and that a walled-off domestic cloud risks being pricier and a step behind the state of the art. They are right that owning a thing is not the same as controlling it, and that standing up a Canadian copy with no legal teeth accomplishes nothing. But the fight was never about protectionism. It is about compellability, about who has the legal power to reach in and seize Canadian records. This is not about painting a data centre red and white. It is about enforceable Canadian control over access, key management, and exposure to foreign law.

Our current government does inspire hope. The federal Digital Sovereignty Framework from November 2025 and Shared Services Canada's March 2026 sovereign cloud RFI, the one that invoked the national security exception to step around our trade obligations, are real movements. Budget 2025 put $925.6 million over five years toward public AI compute, and Bell and Telus are pouring concrete for sovereign data centres (Business in Vancouver, May 2025). It is a good but small start. Bank of America projects China’s total AI capital spending will reach as much as US$98 billion in 2025, roughly US$56 billion of it government-led (SCMP, June 2025). European governments are marching civil servants off American platforms, as seen with France’s recent decision to shift civil servants off US collaboration tools. It is fair to say that Canada still has a ways to go.

The Way Forward

Government sets the security bar and pools public demand so there is a market worth building for. Industry builds the platform. Canadian venture capital (VC) funds it, so the ownership, the board seats, and the IP stay here instead of getting bought out and shipped south the moment it works. If Canadian VCs won't back Canadian sovereignty, I would genuinely like to know why they are here. We need real partnership, not a working group.

The reason organizations stay captured in today’s cloud providers isn't loyalty, it is pain. Egress fees, rewrites, database lock-in engineered to make the exit hard to find. This initiative must then also fund the boring, unglamorous transition tooling that automates moving workloads out. Nobody stays on a foreign cloud because they love it. They stay because leaving feels like digital quicksand.

Sovereignty isn't a posture we can scramble to assemble mid-crisis. It is a capability we must build long before the crisis shows up. Canada has a narrow window now, and that window is a political choice, not a technical wall. To be taken seriously, our sovereign cloud must be backed by an Act of the House of Commons. It must assure our ownership while carrying the political weight and money of a national critical infrastructure project. A permanent statutory mandate is what tells the market this is real.

What Leaders Should Do Now

For business and government leaders, the first moves cost nothing but attention. Find out where your data actually lives and whose law governs it, then ask your provider, in writing, who can compel access to it and to your encryption keys. Hold your own keys where you can, rather than letting the provider hold them for you. Demand a training-data bill of materials from any AI vendor before you trust its model with a real decision. Write portability and exit terms into your next cloud contract now, while you still hold the upper hand, so that leaving is an option and not a threat. And classify the handful of workloads that are too sensitive to ever sit under a foreign court, because those are the ones to move first.

For the government, the mandate is bigger. Turn the Shared Services RFI into binding procurement that scores sovereignty, not only price. Make a training-data bill of materials a condition of federal AI purchases. Back the sovereign cloud with the statutory footing this piece calls for, so it survives the next election.

We can own our digital sovereignty, or we can keep renting it. There is no third option.

Canadians should watch for three things over the next two quarters. Whether the Shared Services RFI turns into real contracts. Whether the coming National AI Strategy treats data provenance as a requirement or an afterthought. And whether the Budget 2025 money converts into Canadian-controlled capacity or quietly flows back to the same foreign providers.

George Al-Koura is a Security & Technology Senior Executive and you connect with him here.

Why the Future of Digital Transformation Depends on Trust, Not Technology

8 min read

Why the Future of Digital Transformation Depends on Trust, Not Technology

Originally published in the The Next Phase of Digital Transformation Trust Is Becoming Canada's Next Critical Infrastructure For more than two...

Read More
Cybersecurity job market analysis 2024: key findings and insights

1 min read

Cybersecurity job market analysis 2024: key findings and insights

This analysis is based on current year data (9 months) from Canadian Cybersecurity Jobs , owned by the Canadian Cybersecurity Network (CCN). As...

Read More