Pillar 03 · Residency

The Global Risk Institute just published a 49-page paper by Chris Collins of the Cascade Institute on AI infrastructure risk for Canadian financial institutions. I recommend reading it. I mean that sincerely, which is rare for me and policy PDFs.

The paper does something useful. It puts numbers and institutional letterhead on a problem that usually gets waved away as paranoia from people who sell solutions to it. Hello.

Here is the diagnosis, compressed. Three American hyperscalers control roughly two thirds of global cloud infrastructure. The AI systems Canadian banks run sit almost entirely on that infrastructure. Those providers answer to U.S. law wherever the racks happen to be. Canadian institutions have no practical alternative at the scale advanced AI workloads require. A prolonged outage at one provider takes down multiple major institutions simultaneously. The FIFAI II work that OSFI and GRI convened calls the dependency structure a source of systemic fragility.

So far, so correct. A risk paper written for bank CROs has now told bank CROs, in plain language, that their AI stack is a concentration risk with a foreign legal system attached.

Then comes the remedy. The federal government is planning a Canadian Sovereign Cloud.

Planning. The paper cites the plan, then spends the next paragraph explaining why the plan would inherit the same data fragmentation and oversight problems it is meant to solve. This is the policy equivalent of prescribing a medication that has not been invented and listing its side effects anyway.

The deeper problem is a word the paper never quite says: jurisdiction.

The entire Canadian sovereignty conversation keeps collapsing jurisdiction into residency. Data in a Toronto region feels sovereign. It has a postal code. You could drive to it. None of that matters, because the operator is a U.S. entity and the CLOUD Act reaches the operator, and the operator reaches the data. The subpoena does not care about the postal code. Residency answers the question of where the bytes sleep. Jurisdiction answers the question of who can be compelled to hand them over. Canadian policy keeps solving the first question and declaring victory on the second.

Contracts do not fix this. A hyperscaler can promise you anything its lawyers can survive, and its lawyers report to a legal system that is not yours. Sovereignty delivered by contract is a promise. Sovereignty delivered by architecture is a property. And here is the part that surprises people: the architecture does not require leaving the hyperscalers at all. Encrypt client-side. Hold the keys under a hierarchy no single operator controls. Then shard the ciphertext across the hyperscalers themselves, spread over genuinely independent jurisdictions, so that each provider holds an encrypted fragment below the threshold of reconstruction. The same three companies the paper identifies as the concentration risk become interchangeable storage substrates holding nothing anyone can read. The subpoena still arrives. It still reaches the operator. The operator produces a shard that is cryptographically indistinguishable from noise, and the honest answer under oath is that no coherent whole exists to surrender. Try getting that from a data residency addendum.

The paper actually hands the financial sector the right frame for this and then walks past it. Its best section is a cascade scenario: drought hits a data centre region, curtailment follows, regulators react, valuations reprice, contagion spreads through correlated holdings. That is a correlated loss story, and correlated loss is the one dialect every CRO speaks fluently. Multi-jurisdictional custody is decorrelation. Same discipline the portfolio side applies to holdings, applied to the question of who can seize, subpoena, or switch off your data. One provider, one country, one watershed is a concentrated position. Risk officers would never run a book that way. They run their infrastructure that way every day.

There is also a deadline hiding in the appendix of all this. OSFI Guideline E-23 lands in May 2027. Model risk management stops being aspirational and starts being examinable. When the examiner asks where the training data lives, who holds the keys, and what evidence supports the answer, "our vendor assures us" will be exactly as persuasive as it sounds. Cryptographic custody evidence with independent timestamps is auditable. Assurances are decor.

Credit to the paper for naming the disease in front of the patient. The gap it leaves open is that the only cure on offer is a government build with no ship date, while the architectural cure runs today, on the same hyperscaler infrastructure the banks have already procured, contracted, and security-reviewed. No rip and replace. No waiting for Ottawa to finish a procurement cycle. The concentration risk stays exactly where it is; it just stops mattering, because concentration of unreadable fragments is not concentration of anything. Canadian financial institutions do not need a new cloud to stop being sovereign by press release. They need a new relationship with the one they have.

The diagnosis was the easy part. It always is.

https://globalriskinstitute.org/publication/ai-infrastructure-and-data-centre-risks-for-canadian-financial-institutions/

Bias Declaration: I founded SkyeConnex, which builds jurisdiction-fragmented data custody infrastructure. I am the least neutral person you will read on this topic today, and probably the most specific.