Data Residency Is Not Data Sovereignty
A Canadian data centre addresses one part of the issue, but it does not necessarily make the data sovereign.
Residency tells us where data is physically stored. Sovereignty asks who ultimately has legal authority over it.
Ottawa has recognized this distinction for years. The Treasury Board's 2018 white paper on data sovereignty and public cloud noted that when a cloud provider operating in Canada is also subject to another country's laws, storing the data in Canada does not necessarily give Canada complete sovereignty over it.
The U.S. CLOUD Act is the example most often cited. Through lawful procedures, U.S. authorities can seek data in the possession, custody or control of a company subject to U.S. jurisdiction, even when that data is stored outside the United States.
That does not mean U.S. authorities have open access to Canadian corporate or government data. Legal processes and safeguards remain in place, and providers can challenge requests.
But it does mean that asking a vendor only, "Is our data stored in Canada?" no longer gives you the complete answer.
Canada and the United States are taking different approaches
Canada is incorporating digital and AI sovereignty into its national strategy and investing in sovereign computing and domestic infrastructure.
The United States is moving differently. In February 2026, Reuters reported on a State Department cable instructing American diplomats to oppose foreign data sovereignty and localization requirements that the administration considered unnecessarily burdensome.
Both sides have understandable interests. Canada wants greater control and resilience over infrastructure that has become critical to its economy and public services. The United States wants its technology companies to compete globally without navigating an expanding patchwork of national restrictions.
For organizations operating across borders, however, this will not remain a policy debate. It will increasingly show up in contracts, procurement decisions and architecture.
Europe offers another useful perspective.
The European Commission's proposed approach to cloud and AI sovereignty uses different assurance levels rather than treating sovereignty as a simple yes-or-no designation. Higher levels consider factors beyond storage, including third-country dependencies, software supply chains and provider ownership and control.
I think that approach is useful.
Not every workload requires the same level of sovereignty.
Japan is taking a somewhat different route, testing domestic foundation models for government use alongside other models. The objective is not necessarily to exclude international technology, but to ensure that domestic options exist when the sensitivity of a workload requires greater control.
That may be a more practical way to think about sovereignty: not isolation, but choice.
Where this becomes very real: the contact centre
Consider what an AI agent operating in a contact centre may be able to see: customer profiles, interaction histories, transcripts, payment information, CRM records and authentication data.
Increasingly, some AI agents may also be given authority to act. They may issue refunds, change accounts, initiate workflows or eventually negotiate with a customer's own AI assistant.
At that point, asking "Where is the call recording stored?" addresses only a small part of the risk.
Organizations also need to know where transcription occurs, where the model performs inference, whether customer information leaves Canada during an interaction, which third parties can access it, who controls the encryption keys, where prompts, logs and embeddings are stored, and which jurisdiction applies at each stage.
In a modern CX architecture, those answers may be different for every component.
Your CCaaS tenant might reside in a Canadian region while the speech engine, agent-assist model, analytics service or another AI component operates somewhere else.
That is why vendors need to be questioned about individual AI capabilities, not simply the location of the core platform.
For me, this is where data sovereignty stops being merely a compliance checkbox and becomes an architectural issue.
Banking introduces another question: who gave the AI authority to act?
Financial services show how quickly this discussion is evolving.
Canadian banks are already using AI behind the scenes, even if customers do not always see it. As these systems move from analyzing information and making recommendations toward taking actions, sovereignty becomes inseparable from governance and accountability.
Where was the decision made? Which models and systems were involved? What authority was the AI given? What data did it use? And if an AI agent makes a financial decision or transaction that causes harm, who is ultimately accountable?
Many existing financial regulations and consumer-protection frameworks were developed before AI systems began moving from analysis toward autonomous action.
This raises another idea that I think will become increasingly important:
Decision Sovereignty.
It is one thing for an AI model to summarize a conversation or recommend the next best action. It is quite another to give that system the authority to authenticate a customer, approve a transaction, move money, change an account, or make decisions that materially affect someone's life.
At that point, sovereignty is no longer only about where the data resides.
It is also about who gave the AI authority to act, under whose rules, using whose infrastructure and who remains accountable for the outcome.
Healthcare raises the stakes even further.
Health information is among the most sensitive data an organization can hold, while healthcare is also an area where AI could provide significant benefits.
Canada's AI for All strategy reflects that balance through initiatives such as VITAL, a pan-Canadian health data platform designed so provinces and territories maintain ownership and oversight of their hospital data.
But privacy compliance alone will not answer every question created by generative and agentic AI.
Healthcare organizations still need to understand where information is processed, where prompts and responses go, whether information is retained for model improvement, who controls the underlying infrastructure and what happens when another model or third party is introduced.
Those are no longer just security questions. They are procurement and architecture questions.
Government faces much the same challenge. Public-sector systems contain tax records, benefits information, identity data and other sensitive information relating to millions of citizens.
Digital sovereignty does not mean governments must build everything themselves or reject foreign technology. It means understanding the dependencies, understanding the risks they create and consciously deciding which risks are acceptable.
Sovereignty should not mean isolation.
Canada cannot realistically build every cloud service, foundation model, chip and software platform it needs.
Nor should sovereignty automatically mean excluding American or other international providers. Our technology ecosystems are far too interconnected for that to be practical.
The better approach may be to determine the appropriate level of sovereignty for each workload.
Public information may require relatively little control. Customer information may require considerably more. Health records, financial information, government systems and critical infrastructure may require much stronger guarantees.
That is the discipline Canadian organizations can begin applying now, whether regulation requires it or not.
For technology, procurement, security and CX leaders, it means expanding the questions we ask vendors.
The Questions Are Getting Bigger.
Understanding what the AI can do still matters. But we should also be asking: Where does our data go? Who controls the infrastructure? Which laws apply? Who can gain access? Where are AI decisions being made? What authority have we given those systems? What happens if regulations or geopolitical relationships change? And if we need to move to another provider, how difficult will that be?
In the AI era, sovereignty is becoming less about the physical location of a data centre and more about who controls the technology, the data and the decisions, and which legal jurisdiction ultimately applies.