Rethinking Cloud Sovereignty: Canada Doesn’t Need to Own the Cloud—It Needs to Control It
Introduction
Ottawa is about to write a definition of “sovereign” into a federal cloud computing contract, and as Lawrence Zhang writes for the Macdonald-Laurier Institute, that definition will decide more than the deal itself. Shared Services Canada has closed its request for information and is preparing the request for proposals for government cloud services, so the question of who counts as a sovereign provider will soon be settled by eligibility rules and price rather than argued in policy commentary (CanadaBuys 2025).
Definitions written into federal procurement travel because provinces and hospital networks take their cues from what Ottawa buys, and a definition that treats Canadian “ownership” as evidence of security will be inherited by organizations that never examined the premise in the first place.
Cloud computing, for the purposes of this debate, means renting computing power, storage, and software from a provider’s data centres as opposed to owning and running computers and servers in-house. Three American firms—Amazon Web Services, Microsoft (Microsoft Azure), and Google (Google Cloud)—supply most of it in Canada, as they do almost everywhere, apart from China (Karadeglija 2026). Meanwhile, “sovereign cloud” is the label for a set of restrictions layered on top of that service: data stored only inside the country, systems administered only by cleared nationals, encryption keys held by the customer, and, in the most extreme version, the entire stack needing to be owned and operated by a domestic company.
The idea has European origins as a reaction to the Snowden disclosures and the US CLOUD Act, and European governments have since written sovereignty criteria into public procurement (Wood and Lewis 2023; European Commission). The hyperscalers responded by building dedicated European offerings, most recently AWS’s European Sovereign Cloud, which launched in Germany under a separate legal entity with EU-resident staff (Amazon Web Services 2026b). Canada has since imported the vocabulary largely intact and with it, the assumption that the more sovereign, the better. The 2024 Canadian federal budget committed $2 billion to a Canadian Sovereign AI Compute Strategy, and Shared Services Canada’s request for information asked the market what a sovereign provider would look like. The answers from domestic firms leaned heavily on ownership (Innovation, Science and Economic Development Canada 2026b).
Under a second Trump administration, the United States has imposed tariffs on Canada and mused about making it the 51st state, and Canadians are reasonably asking what it means to run hospitals and government services on infrastructure operated by firms answerable to US law and, in the end, to US politics.
The case for sovereign cloud rests on three concerns. The first is that Washington could coerce Canada via its cloud dependence, up to and including ordering providers to cut Canada off. The second is that US law, through the CLOUD Act, gives American authorities reach into Canadian data wherever it sits. The third is that Canada is dangerously dependent on a handful of foreign suppliers and needs a domestic alternative to escape them.
Much of what sovereign cloud promises is already for sale. Keeping Canadian data in Canada is standard practice and is already federal policy for sensitive workloads. Restricting administration to people with clearance inside the country is a contractual tier the hyperscalers already sell in Paris and Berlin. Customer-held encryption keys are a configuration choice available to any customer willing to manage them, and they leave the provider storing data that it cannot read no matter who asks. Canadian ownership is different. Unlike residency, cleared administration, or customer-held keys, it cannot simply be specified in a contract with an existing provider. Yet its additional security benefit is far less obvious.
Meanwhile, the sovereignty violations Canada is actually experiencing have nothing to do with American providers. Over the past four years, actors linked to the People’s Republic of China have compromised at least twenty Government of Canada networks, and none of those intrusions would have been prevented by a Canadian-owned data centre (Reddick 2024).
There may be perfectly good commercial reasons to build data centres in Canada. Cheap power and available land are two of them, which is why Bell is spending $1.7 billion in Saskatchewan without Ottawa guaranteeing it customers (Germano 2026). What Canada should not do is guarantee demand through procurement, because the infrastructure layer is where returns are thinnest and the productivity gains from AI land downstream of it. The policy problem is ultimately one of control. Ottawa needs to know who can access sensitive systems and under what authority, whether service can be maintained through a disruption, and whether workloads can realistically be moved when a provider becomes unacceptable. Much of that control can be specified through procurement, technical architecture, and contract design using providers Ottawa already buys from.
