Pillar 02 · Legal

Bias declaration: I founded SkyeConnex, a data sovereignty company. I have commercial skin in this argument. Every word below is self-interested. It also happens to be correct, which is a nice bonus.

Jaxson Khan published a smart piece in Policy Options last week ("Canada shouldn't try to build everything it needs for the AI era"). His argument: Ottawa borrowed the Build-Partner-Buy framework from the Defence Industrial Strategy and applied it to all of AI, when it only fits the middle of the stack. For models and applications, flip it. Buy first, because the frontier moves faster than any procurement cycle. Partner second. Build only where Canada can hold a defensible position.

On the model layer, he is right. A federally procured Canadian frontier model would be obsolete before the fairness monitor finished the conflict-of-interest forms. I have watched a government procurement cycle and a model release cycle run side by side. One of them produced four generations of frontier AI. The other produced a revised statement of work.

Khan also lands on the correct definition of sovereignty, quoting his own Munk School report: freedom from coercion, not technological self-sufficiency. Options if the tools get turned off. Right frame. Rarer than it should be. Most of the sovereignty discourse in this country is people discovering that "the server is in Toronto" and declaring victory.

Here is where I want to push.

Procurement is not a coercion control

The entire build-versus-buy debate, Khan's improved version included, treats sovereignty as a procurement question. Where was it made. Who owns the vendor. What flag flies over the data centre.

Coercion has never once checked the flag.

The CLOUD Act reaches any provider subject to US jurisdiction, wherever the data physically sits. A hyperscaler region in Montreal is a US legal endpoint with better poutine. Khan cites the number himself: three American firms hold an estimated 85 per cent of Canada's public cloud market. Every byte in that 85 per cent is producible under foreign legal process today. The data is resident. The data is also, in every sense that matters, on a work visa.

So "build more data centres in Canada" delivers jobs, latency, and grid load. Genuinely good things. What it does not deliver is freedom from coercion, because the operator remains compellable. Everyone is compellable. People are compellable. Corporations are compellable. Contracts get amended by whoever has the bigger legal department. The only party that has never lost a motion to compel is mathematics.

If no single operator holds the keys, and no single operator holds enough of the data to reconstruct it, there is nothing to produce. The disclosure order arrives and the response is a genuinely sincere "we cannot comply, and neither can anyone else on Earth." Lawyers hate this one trick. Everything short of it is sovereignty theatre with a maple leaf sticker on the rack.

This is not aspirational, which is the part everyone misses

The reflex at this point in the conversation is to file "compelled-disclosure-proof architecture" next to fusion power and a third national airline. Something for the 2030s. Something requiring a sovereign cloud built from bedrock up.

No. The custody layer is a today problem with a today answer. Client-side encryption, keys the operator never sees, data sharded across independent jurisdictions so that no single provider possesses a reconstructable copy. This runs now, in production, on top of the exact hyperscaler infrastructure Canada already rents. You do not evict the hyperscalers. You demote them. They keep doing what they are legitimately excellent at, which is running racks at scale, and they lose the one job they should never have had, which is being a single legal chokepoint for Canadian data.

That reframes Khan's stack nicely. Buy the models. Keep the clouds. Harden the custody. The hyperscalers become plumbing. Plumbing is honourable work. Nobody subpoenas the pipes.

The classification idea is the real lever

The strongest section of Khan's piece is the least glamorous one. Modernize the federal data-classification framework so sovereignty requirements scale with sensitivity. A chatbot drafting blog posts gets one treatment. CRA taxpayer records get another. With Bill C-36 tabled and the Privacy Act review underway, the timing writes itself.

Correct lever. Wrong test, if we sleepwalk into it.

The threshold question at each tier must not be "is the vendor Canadian." Vendor nationality is a proxy, and a leaky one. Canadian firms get acquired. I have personal experience with this. Canadian firms sign with foreign processors. Canadian firms running on foreign-controlled infrastructure inherit that infrastructure's legal exposure the way you inherit your landlord's foundation problems.

The threshold question is: can any single party, anywhere, be compelled to produce this data in cleartext? If yes, the tier is not sovereign, whatever the flag on the invoice. That test is architectural, auditable, and pleasingly binary. Who holds keys. Whether any one operator can reconstruct plaintext. Whether refusal is a legal argument or a mathematical fact. Put that test in the framework and cloud procurement sorts itself out while the policy people are still scheduling the working group.

Khan proposes publishing the reasoning behind major sovereign-capability decisions. Good. Publish the compellability analysis too. I will bring popcorn.

One addition on quantum

Khan closes by naming quantum as Canada's build-first bet. Agreed, and it connects to his coercion frame more tightly than the piece lets on.

Harvest-now-decrypt-later is not a hypothetical. Adversaries are archiving encrypted traffic today against the day it becomes readable, with the patience of people who have already read your ten-year retention policy. Any "sovereign" system procured in 2026 on classical cryptography is a depreciating asset with a known write-off date. FIPS 203 and 204 are published standards. Mandating them now costs a paragraph in a requirements document. Not mandating them costs a decade of archived Canadian data, delivered to someone else's quantum computer with our compliments.

The unglamorous version of the unglamorous path

Khan calls his approach the unglamorous path to AI leadership. I would make it one notch less glamorous still, which for a man who writes about erasure coding recreationally is saying something.

Buy the models. Partner for compute. Build the custody layer, because custody is the one layer where a middle power's leverage is absolute rather than negotiated, and because it is the only layer on this list that already ships. A model can be swapped. A lease can be renegotiated. Compelled disclosure of your citizens' data cannot be walked back with a press release.

Sovereignty by architecture, not by promise. The rest is procurement policy.

https://policyoptions.irpp.org/2026/08/canada-ai-strategy-build-buy