Key points
- Sovereignty is three different questions: residency (where data sits and is processed), control (who can access it or compel access) and dependency (how reliant you are on specific foreign vendors).
- Options range from hyperscaler Canadian regions to Canadian-controlled providers, private deployments, open models and hybrids. Each answers the three questions differently.
- Decide workload by workload. Many workloads do not need Canadian-hosted infrastructure; some clearly do.
- Federal policy is actively investing in domestic AI compute, which is widening the set of Canadian options.
“Sovereign AI” has become a common phrase in Canadian boardrooms and policy discussions. It is also used loosely. For some it means data stored in Canada. For others it means Canadian-owned infrastructure, or independence from a small number of foreign technology providers. These are different concerns with different solutions, and treating them as one leads to either overspending or under-protecting.
This guide separates the questions, outlines the realistic options, and offers a practical way to decide what each workload actually needs.
Three questions, not one
Residency: where is the data?
Data residency concerns where information is stored and processed. With AI, that includes the documents you index, the prompts people send, the outputs generated, logs, and any data used to customize a model. A service can store your files in Canada and still process requests elsewhere, so it is worth asking about each stage.
Control: who can access it?
Control concerns who can access the data or the system, and who could be compelled to provide access. A provider headquartered outside Canada may be subject to the laws of its home jurisdiction even when the data sits in a Canadian data centre. For most commercial workloads this is an acceptable, well-understood risk. For some public-sector, defence-adjacent, health or highly confidential workloads, it may not be.
Dependency: how easily could you change course?
Dependency concerns reliance on particular foreign vendors or models. If a core workflow only works with one provider’s proprietary model, changes to that provider’s pricing, terms, availability or policies become your problem. Dependency is partly a sovereignty question and partly ordinary vendor risk management.
The options
| Approach | Residency | Control | Dependency |
|---|---|---|---|
| Hyperscaler with Canadian regions | Can be strong if all stages run in Canadian regions | Provider may be subject to foreign jurisdiction | Often high for proprietary services |
| Canadian-hosted | Strong | Depends on who owns and operates the provider | Varies |
| Canadian-controlled | Strong | Strongest for commercial options | Lower foreign dependency; capability may vary |
| Private deployment | Your choice | Held by your organization | Lower, but you carry operating responsibility |
| Canadian AI vendors and models | Often Canadian, confirm per service | Often Canadian, confirm per service | Reduces foreign reliance |
| Open models | Wherever you run them | Wherever you run them | Low; models can be moved or replaced |
| Hybrid | Matched to each workload | Matched to each workload | Managed deliberately |
Open models deserve a note. Their weights can be downloaded and run on infrastructure you choose, which can address residency, control and dependency together. The trade-off is that you or a partner must host, secure, update and evaluate them, and the most capable proprietary models may outperform them on some tasks.
A decision framework by workload
Sovereignty is contextual. The right question is not “should our AI be sovereign?” but “what does this particular workload need?” Work through these factors for each one:
- Data sensitivity. Does the workload involve personal information, health information, privileged material, trade secrets or security-sensitive data? Or is it public or low-sensitivity content?
- Regulatory and contractual obligations. Do privacy laws, sector rules or client contracts impose residency or access requirements? PIPEDA applies to private-sector personal information federally, and Alberta, British Columbia and Quebec have their own private-sector privacy laws. Contracts often add stricter terms. Confirm what applies with counsel.
- Public-sector requirements. Government bodies and organizations serving them often have specific hosting, security and procurement requirements. Federal institutions also work under the Directive on Automated Decision-Making, which uses an Algorithmic Impact Assessment.
- Cost. Stronger residency and control can cost more to run, particularly for private deployments. Weigh that against the actual risk being reduced.
- Capability. Does the workload need the most capable model available, or would a smaller or open model perform well enough? Test rather than assume.
- Latency. Some interactive or high-volume uses benefit from processing close to users and systems.
- Exit risk. How hard would it be to move this workload if a provider changed terms or became unavailable? Designing for portability from the start is usually cheaper than migrating later.
In practice, many organizations land on a hybrid: mainstream cloud AI services for general productivity and low-sensitivity work, and Canadian-hosted, Canadian-controlled or private deployments for the workloads where sensitivity, obligations or exit risk justify it.
Questions to ask any AI provider
Marketing language around sovereignty varies widely, so ask specific questions and get the answers in writing:
- Where are prompts, outputs, indexed documents and logs stored and processed, including backups and support access?
- Is our data used to train or improve the provider’s models, and can that be turned off contractually?
- Who owns and operates the provider, and which jurisdictions’ laws could require access to our data?
- How would we be notified of a request for access, where notification is permitted?
- Can we export our data, configurations and evaluation results in a usable form if we leave?
- Which parts of our workflow depend on features only this provider offers?
The answers rarely settle the decision on their own, but they turn a vague concern into a specific, comparable set of trade-offs.
When it clearly matters, and when it may not
Sovereignty considerations tend to weigh heavily when a workload involves:
- sensitive personal information at scale, such as health, financial or HR records;
- government or public-sector data with explicit hosting requirements;
- client contracts that specify Canadian residency or restrict foreign access;
- core operations where dependency on one foreign provider is an unacceptable business risk.
They tend to matter less for:
- drafting and editing work using public or non-confidential information;
- general research and learning;
- internal productivity tasks where approved enterprise tools already meet your policies.
The point is proportionality. Applying the strictest architecture to every workload is expensive and slows adoption. Applying the loosest to every workload exposes the organization where it matters most.
The Canadian policy context
The federal government is actively investing in domestic AI capacity through the Canadian Sovereign AI Compute Strategy and the AI Sovereign Compute Infrastructure Program. Over time, this is likely to widen the set of Canadian infrastructure options available to organizations.
On regulation, the proposed Artificial Intelligence and Data Act, part of Bill C-27, did not become law, and the federal approach continues to evolve. Privacy law remains the most immediate framework for most organizations, and the Office of the Privacy Commissioner of Canada publishes guidance worth following. For more on the Canadian landscape, see our Canada page.
How Trained helps
Trained helps organizations work out what actually needs Canadian residency or control and what does not, then design architectures that match. We assess workloads, compare Canadian-hosted, Canadian-controlled, private, hyperscaler, open-model and hybrid options, and build for portability. Learn more about our approach to sovereign AI, or start a conversation about your workloads.