OPINION: The digital sovereignty debate

Skip to Content News Archives Economy Energy Oil & Gas Renewables Electric Vehicles Mining Commodities Agriculture Real Estate Mortgages Mortgage Rates Finance Banking Insurance Fintech Cryptocurrency Work Wealth Smart Money Wealth Management Investor Personal Finance Family Finance Retirement Taxes High Net Worth FP Comment Executive Women Puzzmo Newsletters Financial Times Business Essentials More Innovation Information Technology FP500 Podcasts Small Business Lives Told Tails Told Shopping Financial Post Store Obituaries Place a Notice Advertising Advertising With Us Advertising Solutions Postmedia Ad Manager Sponsorship Requests Classifieds Place a Classifieds ad Working Profile Settings My Subscriptions Saved Articles My Offers Newsletters Customer Service FAQ News Economy Energy Mining Real Estate Finance Work Wealth Investor FP Comment Executive Women Puzzmo Newsletters Financial Times Business Essentials This advertisement has not loaded yet, but your article continues below.HomeInformation TechnologyOPINION: The digital sovereignty debateRepatriating our digital economy: making the case for data autonomy and a Canadian sovereign cloudLast updated 1 hour ago You can save this article by registering for free here. Or sign-in if you have an account.Digital sovereignty went from an afterthought to a dinner-table topic in about five years. In our rush to keep pace with everyone else’s digital ambitions, we quietly wired the country’s nervous system through infrastructure we don’t own and can’t govern. THIS CONTENT IS RESERVED FOR SUBSCRIBERS ONLYSubscribe now to read the latest news in your city and across Canada.Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman, and others.Daily content from Financial Times, the world's leading global business publication.Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles, including the New York Times Crossword.SUBSCRIBE TO UNLOCK MORE ARTICLESSubscribe now to read the latest news in your city and across Canada.Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman and others.Daily content from Financial Times, the world's leading global business publication.Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles, including the New York Times Crossword.REGISTER / SIGN IN TO UNLOCK MORE ARTICLESCreate an account or sign in to continue with your reading experience.Access articles from across Canada with one account.Share your thoughts and join the conversation in the comments.Enjoy additional articles per month.Get email updates from your favourite authors.THIS ARTICLE IS FREE TO READ REGISTER TO UNLOCK.Create an account or sign in to continue with your reading experience.Access articles from across Canada with one accountShare your thoughts and join the conversation in the commentsEnjoy additional articles per monthGet email updates from your favourite authorsSign In or Create an AccountIt’s an exposure that buys us a level of strategic risk Canada has not faced in the digital era. You can lock your house but still lose everything inside if someone else has your keys. Most of the debate about Canadian digital security is stuck on the technology or compliance fights while ignoring the ground the servers sit on and the laws that govern them. We’re having the wrong argument. Cybersecurity is theatre if the box behind it answers to a foreign court. Petabytes of our domestic traffic still boomerangs through American exchange points across town, open to foreign collection the whole way. Get the latest headlines, breaking news and columns.By signing up you consent to receive the above newsletter from Postmedia Network Inc.A welcome email is on its way. If you don't see it, please check your junk folder.The next issue of Top Stories will soon be in your inbox.We encountered an issue signing you up. Please try againThe AI blind spot is the training data Now bolt AI onto that threat risk, which is what every sector is doing. A model is only as trustworthy as the data it trained on, and almost no Canadian enterprise or government shop can tell you where that data came from, who owns it or whether they had the right to use it. This lack of scrutiny is how you end up with hallucination, copyright landmines and quiet data leakage baked into systems people are about to trust with real decisions. A slick model trained on data nobody can trace is just a black box wearing a maple leaf. Provenance is not compliance theatre. It is the line between an AI system you can defend in a courtroom or a crisis and one you can’t defend anywhere. Federal procurement should demand a training-data bill of materials (TDBOM), full stop. We insist on knowing where and how our food is sourced. We should accept nothing less for the data steering our national interests. The scale of foreign cloud dependency Drop the algorithms and look where you are. Canada runs its digital life on hardware it doesn’t control. By the Balsillie School’s estimate, around 80 per cent of our cloud services lean on foreign infrastructure, and roughly 60 per cent run on American servers under American law. A Global News report in September 2025 revealed that Ottawa spent close to $1.3 billion on U.S. cloud hosting. Just last month, Policy Options called DND’s Defence 365 nothing more than Microsoft 365 with a Canadian wrapper. We would never let a foreign company run our ports or our power grid, yet we handed them the data without a second thought. It is a comfortable excuse to say that a server inside Canadian borders is somehow beyond foreign reach. The U.S. CLOUD Act says otherwise. It lets American courts compel any provider under U.S. jurisdiction to produce records wherever the machines physically live, which means a subpoena to a U.S.-parented hyperscaler sails clean past any Canadian judge. Ireland found this out the hard way in 2018 (United States v. Microsoft Corp.) when a U.S. warrant for emails stored in Dublin pushed Congress to pass the CLOUD Act, settling the question in favour of reach. This advertisement has not loaded yet.This advertisement has not loaded yet, but your article continues below.A new warrant was issued, and Microsoft did hand over those emails. “Stored in Canada” is a marketing line, not a legal shield. Comparative cloud jurisdiction risk Many Canadian IT leaders will tell you that critics say ownership is a weak proxy for security, and that a walled-off domestic cloud risks being pricier and a step behind the state of the art. They are right that owning a thing is not the same as controlling it, and that standing up a Canadian copy with no legal teeth accomplishes nothing. But the fight was never about protectionism. It is about compellability; about who has the legal power to reach in and seize Canadian records. This is not about painting a data centre red and white. It is about enforceable Canadian control over access, key management and exposure to foreign law. Our current government does inspire hope. The federal Digital Sovereignty Framework from November 2025 and Shared Services Canada’s March 2026 sovereign cloud RFI, the one that invoked the national security exception to step around our trade obligations, are real movements. Budget 2025 put $925.6 million over five years toward public AI compute, and Bell and Telus are pouring concrete for sovereign data centres, according to Business in Vancouver. It is a good but small start. Bank of America projects China’s total AI capital spending will reach as much as US$98 billion in 2025, roughly US$56 billion of it government-led, according to South China Morning Post. European governments are marching civil servants off American platforms, as seen with France’s recent decision to shift civil servants off U.S. collaboration tools. It is fair to say that Canada still has a way to go. The way forward Government sets the security bar and pools public demand, so there is a market worth building for. Industry builds the platform. Canadian venture capital (VC) funds it, so the ownership, the board seats and the IP stay here instead of getting bought out and shipped south the moment it works. If Canadian VCs won’t back Canadian sovereignty, I would genuinely like to know why they are here. We need real partnership, not a working group. The reason organizations stay captured in today’s cloud providers isn’t loyalty; it is pain. Egress fees, rewrites, database lock-in engineered to make the exit hard to find. This initiative must then also fund the boring, unglamorous transition tooling that automates moving workloads out. Nobody stays on a foreign cloud because they love it. They stay because leaving feels like digital quicksand. Sovereignty isn’t a posture we can scramble to assemble mid-crisis. It is a capability we must build long before the crisis shows up. Canada has a narrow window now, and that window is a political choice, not a technical wall. To be taken seriously, our sovereign cloud must be backed by an Act of the House of Commons. It must assure our ownership while carrying the political weight and money of a national critical infrastructure project. A permanent statutory mandate is what tells the market this is real. What leaders should do now For business and government leaders, the first moves cost nothing but attention. Find out where your data actually lives and whose law governs it, then ask your provider, in writing, who can compel access to it and to your encryption keys. Hold your own keys where you can, rather than letting the provider hold them for you. Demand a training-data bill of materials from any AI vendor before you trust its model with a real decision. Write portability and exit terms into your next cloud contract now, while you still hold the upper hand, so that leaving is an option and not a threat. And classify the handful of workloads that are too sensitive to ever sit under a foreign court, because those are the ones to move first. For the government, the mandate is bigger. Turn the Shared Services RFI into binding procurement that scores sovereignty, not only price. Make a training-data bill of materials a condition of federal AI purchases. Back the sovereign cloud with the statutory footing this piece calls for, so it survives the next election. We can own our digital sovereignty, or we can keep renting it. There is no third option. Canadians should watch for three things over the next two quarters: Whether the Shared Services RFI turns into real contracts. Whether the coming national AI strategy treats data provenance as a requirement or an afterthought. And whether the Budget 2025 money converts into Canadian-controlled capacity or quietly flows back to the same foreign providers. George Al-Koura is a security and technology senior executive and you connect with him here. This section is powered by Revenue Dynamix. Revenue Dynamix provides innovative marketing solutions designed to help IT professionals and businesses thrive in the Canadian market, offering insights and strategies that drive growth and success across the enterprise IT spectrum. Notice for the Postmedia NetworkThis website uses cookies to personalize your content (including ads), and allows us to analyze our traffic. Read more about cookies here. By continuing to use our site, you agree to our Terms of Use and Privacy Policy.

Original Source

Read the full article at Financialpost →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.