OPINION: The digital sovereignty debate Canada faces a strategic risk from running its digital infrastructure on foreign-owned servers subject to U.S. law, with an estimated 80% of cloud services relying on foreign infrastructure and 60% on American servers, according to the Balsillie School. A Global News report in September 2025 revealed Ottawa spent nearly $1.3 billion on U.S. cloud hosting. The author argues that the U.S. CLOUD Act allows American courts to compel data from U.S.-parented providers regardless of physical server location, and that AI systems trained on untraceable data pose additional risks, calling for a training-data bill of materials in federal procurement. Digital sovereignty went from an afterthought to a dinner-table topic in about five years. In our rush to keep pace with everyone else's digital ambitions, we quietly wired the country's nervous system through infrastructure we don't own and can't govern. It's an exposure that buys us a level of strategic risk Canada has not faced in the digital era. You can lock your house but still lose everything inside if someone else has your keys. Most of the debate about Canadian digital security is stuck on the technology or compliance fights while ignoring the ground the servers sit on and the laws that govern them. We're having the wrong argument. Cybersecurity is theatre if the box behind it answers to a foreign court. Petabytes of our domestic traffic still boomerangs through American exchange points across town, open to foreign collection the whole way. The AI blind spot is the training data Now bolt AI onto that threat risk, which is what every sector is doing. A model is only as trustworthy as the data it trained on, and almost no Canadian enterprise or government shop can tell you where that data came from, who owns it or whether they had the right to use it. This lack of scrutiny is how you end up with hallucination, copyright landmines and quiet data leakage baked into systems people are about to trust with real decisions. A slick model trained on data nobody can trace is just a black box wearing a maple leaf. Provenance is not compliance theatre. It is the line between an AI system you can defend in a courtroom or a crisis and one you can't defend anywhere. Federal procurement should demand a training-data bill of materials TDBOM , full stop. We insist on knowing where and how our food is sourced. We should accept nothing less for the data steering our national interests. The scale of foreign cloud dependency Drop the algorithms and look where you are. Canada runs its digital life on hardware it doesn't control. By the Balsillie School's estimate, around 80 per cent of our cloud services lean on foreign infrastructure, and roughly 60 per cent run on American servers under American law. A Global News report in September 2025 revealed that Ottawa spent close to $1.3 billion on U.S. cloud hosting. Just last month, Policy Options called DND's Defence 365 nothing more than Microsoft 365 with a Canadian wrapper. We would never let a foreign company run our ports or our power grid, yet we handed them the data without a second thought. It is a comfortable excuse to say that a server inside Canadian borders is somehow beyond foreign reach. The U.S. CLOUD Act says otherwise. It lets American courts compel any provider under U.S. jurisdiction to produce records wherever the machines physically live, which means a subpoena to a U.S.-parented hyperscaler sails clean past any Canadian judge. Ireland found this out the hard way in 2018 United States v. Microsoft Corp. when a U.S. warrant for emails stored in Dublin pushed Congress to pass the CLOUD Act, settling the question in favour of reach. A new warrant was issued, and Microsoft did hand over those emails. "Stored in Canada" is a marketing line, not a legal shield. Comparative cloud jurisdiction risk Many Canadian IT leaders will tell you that critics say ownership is a weak proxy for security, and that a walled-off domestic cloud risks being pricier and a step behind the state of the art. They are right that owning a thing is not the same as controlling it, and that standing up a Canadian copy with no legal teeth accomplishes nothing. But the fight was never about protectionism. It is about compellability; about who has the legal power to reach in and seize Canadian records. This is not about painting a data centre red and white. It is about enforceable Canadian control over access, key management and exposure to foreign law. Our current government does inspire hope. The federal Digital Sovereignty Framework from November 2025 and Shared Services Canada's March 2026 sovereign cloud RFI, the one that invoked the national security exception to step around our trade obligations, are real movements. Budget 2025 put $925.6 million over five years toward public AI compute, and Bell and Telus are pouring concrete for sovereign data centres, according to Business in Vancouver. It is a good but small start. Bank of America projects China's total AI capital spending will reach as much as US$98 billion in 2025, roughly US$56 billion of it government-led, according to South China Morning Post. European governments are marching civil servants off American platforms, as seen with France's recent decision to shift civil servants off U.S. collaboration tools. It is fair to say that Canada still has a way to go. The way forward Government sets the security bar and pools public demand, so there is a market worth building for. Industry builds the platform. Canadian venture capital VC funds it, so the ownership, the board seats and the IP stay here instead of getting bought out and shipped south the moment it works. If Canadian VCs won't back Canadian sovereignty, I would genuinely like to know why they are here. We need real partnership, not a working group. The reason organizations stay captured in today's cloud providers isn't loyalty; it is pain. Egress fees, rewrites, database lock-in engineered to make the exit hard to find. This initiative must then also fund the boring, unglamorous transition tooling that automates moving workloads out. Nobody stays on a foreign cloud because they love it. They stay because leaving feels like digital quicksand. Sovereignty isn't a posture we can scramble to assemble mid-crisis. It is a capability we must build long before the crisis shows up. Canada has a narrow window now, and that window is a political choice, not a technical wall. To be taken seriously, our sovereign cloud must be backed by an Act of the House of Commons. It must assure our ownership while carrying the political weight and money of a national critical infrastructure project. A permanent statutory mandate is what tells the market this is real. What leaders should do now For business and government leaders, the first moves cost nothing but attention. Find out where your data actually lives and whose law governs it, then ask your provider, in writing, who can compel access to it and to your encryption keys. Hold your own keys where you can, rather than letting the provider hold them for you. Demand a training-data bill of materials from any AI vendor before you trust its model with a real decision. Write portability and exit terms into your next cloud contract now, while you still hold the upper hand, so that leaving is an option and not a threat. And classify the handful of workloads that are too sensitive to ever sit under a foreign court, because those are the ones to move first. For the government, the mandate is bigger. Turn the Shared Services RFI into binding procurement that scores sovereignty, not only price. Make a training-data bill of materials a condition of federal AI purchases. Back the sovereign cloud with the statutory footing this piece calls for, so it survives the next election. We can own our digital sovereignty, or we can keep renting it. There is no third option. Canadians should watch for three things over the next two quarters: Whether the Shared Services RFI turns into real contracts. Whether the coming national AI strategy treats data provenance as a requirement or an afterthought. And whether the Budget 2025 money converts into Canadian-controlled capacity or quietly flows back to the same foreign providers. George Al-Koura is a security and technology senior executive and you connect with him here. This section is powered by Revenue Dynamix. Revenue Dynamix provides innovative marketing solutions designed to help IT professionals and businesses thrive in the Canadian market, offering insights and strategies that drive growth and success across the enterprise IT spectrum.