Data residency isn't the same as data sovereignty. Five questions that actually determine who controls your workload, and why the answer matters more than where the servers sit.
Canada has committed well over a billion dollars to domestic AI compute. None of it determines where your inference runs next quarter, who holds the keys, or what it costs you to move. Those are architecture decisions, they are being made right now on ordinary procurement timelines, and lots of organizations are making them without recognizing them as placement decisions at all.
A useful illustration of the gap came out of France. In June 2025, Microsoft's legal director for France was asked before a Senate committee whether he could guarantee that data belonging to French citizens under public contracts would never be transmitted to the American government without French consent. He answered "No."
The answer was about jurisdiction rather than about any hyperscaler. Any provider under US law can be compelled to produce data it holds, wherever that data physically sits. A Canadian region label does not change the answer.
What Ottawa has funded
The Canadian Sovereign AI Compute Strategy rests on three pillars: private investment in domestic AI data centres, public compute infrastructure, and broader compute access for Canadian researchers and companies.
The AI Sovereign Compute Infrastructure Program launched in April 2026 with up to $890 million over seven years, and applications closed that June. The federal budget added $925.6 million over five years for large-scale sovereign public AI infrastructure. A parallel initiative targets facilities above 100 megawatts, and Ottawa is reviewing more than 160 data-centre proposals. The AI for All strategy from June 2026 names data sovereignty as a national priority.
This is real industrial policy and it will produce real Canadian capacity. Every line of it concerns megawatts, buildings and hardware. None of it concerns the control plane operating your cluster, the jurisdiction of the entity holding your keys, or the integration work that determines whether you can leave.
Three different things get called sovereign
CBC's Kyle Bakx put the distinction well when covering the federal program: the goal is data centres that are "not just physically located here, but controlled here." That test is correct at the level of a building. It applies equally to a workload, where it is asked far less often.
Data residency is where the bytes sit.
Data sovereignty is whose law governs them.
Operational control is who runs the control plane, holds the keys, and can be compelled to act.
Offerings marketed as sovereign frequently satisfy the first and leave the third untouched. Data resides locally while control planes, identity systems, billing layers and operational dependencies stay integrated with global provider infrastructure. The industry now calls this sovereignty washing, and European providers have warned regulators against letting the term be defined by the vendors least able to deliver it. Legal control beats location.
Five questions that decide where a workload should run
1. Where does the data physically reside? The question every provider answers, and the weakest one on its own.
2. Whose law can compel disclosure? Not where the data sits, but where the provider is incorporated and which statutes reach it. This is the question the French Senate asked.
3. Who operates the control plane? Someone schedules your workloads, holds admin credentials and pushes platform updates. If that team and its tooling sit under another jurisdiction, the data's location is a detail.
4. Who holds the encryption keys, and can they be compelled to use them? Encryption at rest means little if the provider can decrypt. Identify who holds the root of trust.
5. What does it cost to move? Placement you cannot revisit is not a choice you still hold. If migrating would take three years and a rewrite, the decision was made once, permanently, by whoever picked the platform.
Answer all five before deciding. A workload that answers "Canada" to the first question and nothing to the rest is hosted in Canada, which is a different property from the one most people believe they are buying.
The legal asymmetry
The CLOUD Act sounds like a compliance footnote and functions as a structural feature of the market. The 2018 statute lets US authorities compel US-jurisdiction providers to produce data wherever it is stored. The reverse does not hold. Canadian authorities rely on the slower MLAT process, and as of early 2026 there was no timeline for a reciprocal agreement. Legal scholars argue that a CLOUD Act executive agreement could permit access under standards that would be unconstitutional if applied by Canadian authorities inside Canada.
American providers are complying with the laws that govern them, which is what any provider should do. The point is narrower: jurisdiction is an architectural input, and most Canadian organizations have never treated it as one.
What France did next
France acted on its own answer. In January 2026 it mandated replacing Teams and Zoom with the domestic Visio platform for 2.5 million civil servants by 2027. On 8 April 2026 the Interministerial Digital Directorate announced it would migrate its workstations from Windows to Linux and ordered every ministry to produce a plan for eliminating extra-European digital dependencies by autumn 2026.
Those plans must address eight categories: workstations and operating systems, collaborative and communication tools, antivirus and security software, artificial intelligence and algorithms, databases and storage, virtualisation and cloud infrastructure, and network and telecommunications equipment.
In the words of Anne Le Hénanff, Minister Delegate for Artificial Intelligence and Digital Technology, "Digital sovereignty is not an option, it is a strategic necessity."
US providers hold an estimated 85% of the European cloud market. France started at the layer it directly controls and has been explicit that the substrate underneath is harder. Canada is funding the substrate while the workloads running on it stay where they are.
The gap in the estate
As of Q2 2026, 19.2% of Canadian businesses reported using AI to produce goods or deliver services, up from 6.1% in 2024. Adoption concentrates in information and cultural industries (42.3%), finance and insurance (40.4%) and professional services (32.4%). Construction, wholesale and agriculture sit below 10%.
Most of that runs on infrastructure that answers question one and no others.
A large share of the Canadian estate is about to be rebuilt regardless, which matters because re-platforming is the cheapest moment to revisit placement. The virtualization market has been in upheaval since Broadcom's acquisition of VMware. AT&T disclosed in a court filing that it was quoted an increase of roughly 1,050%. Licensing minimums were restructured in ways that hit smaller estates hardest. Survey data through 2026 has consistently shown a large majority of organizations working to reduce their VMware footprint, and migrations involving thousands of VMs are commonly estimated at 18 to 48 months.
An organization that leaves one vendor's licensing terms for another foreign-jurisdiction managed platform has solved a cost problem and fixed its placement for the next decade. The migration is the cheap moment to decide. Afterwards, changing jurisdiction means doing the work again.
When the public cloud is the right answer
Plenty of workloads should stay on a public API or a hyperscaler endpoint, and saying otherwise would be dishonest.
If the provider's data-handling terms, regional coverage, pricing and model roadmap satisfy your production requirements, the public path is faster to start, cheaper at low volume, and removes an operational burden you would otherwise carry. Speed of experimentation is a real advantage. Most pilots belong there.
The requirements that change the answer are specific and worth naming: contractual data-handling obligations you cannot satisfy on shared infrastructure, residency conditions tied to a regulator or a customer contract, latency bound to a physical location, predictable utilization that makes on-demand pricing poor value, or a dependency you need the ability to exit. Production tends to surface these after the pilot has already succeeded.
DIY on Kubernetes and OpenStack is the other honest alternative, and for teams with the expertise and the appetite for day-2 responsibility it is a legitimate choice. The cost is not the software. It is the serving path, the upgrade cycle, the storage and network design, and the on-call rotation.
Designing for placement
Once the five questions have answers, a few things follow.
Open infrastructure preserves room to change. The lesson of the past two years is not that licensing costs rose. A single vendor rewrote the commercial terms of infrastructure that thousands of organizations had built on. Platforms built on OpenStack, Kubernetes and Ceph reduce that exposure because the operating layer is not one company's property. Portability still has to be designed and demonstrated rather than assumed.
The control plane is the boundary worth pressing on. Residency-aware deployment means the people and systems operating the platform sit where your requirements say they should. Ask any provider this question directly and specifically.
AI workloads move the question past storage. Where model weights live, where inference runs, what telemetry leaves the environment, and whether sensitive input reaches a managed model endpoint in another jurisdiction as a routine part of the application. An organization can hold its data in Canada and export the most sensitive derived signal it has, one API call at a time.
Nobody is fully sovereign. Canadian AI infrastructure runs on foreign-designed silicon, across networks that do not always respect national borders, inside global supply chains. Residency, jurisdiction and control are configuration properties, established per deployment and per contract, not a state a vendor can confer on you. Any provider claiming otherwise is selling the word rather than the property.
The strongest objection
The Information Technology and Innovation Foundation published a critique of Canadian cloud policy in April 2026 warning that sovereignty requirements shade into protectionism, raising costs and cutting domestic organizations off from the best available technology.
Against a certain kind of procurement rule, that critique lands, and anyone writing those rules should read it.
It lands less well against the argument here, which is narrower. Nothing above says Canadian organizations should avoid global providers or that domestic infrastructure is automatically better. Placement should be an explicit architectural decision with understood trade-offs rather than a property assumed from a data centre's postal code. Deciding that a workload does not need residency controls is a perfectly good outcome, provided somebody decided it.
Capacity is not control
Canada's sovereignty conversation is a capacity conversation. Megawatts, buildings, supercomputers. That work matters and the country is right to fund it.
Capacity does not answer the five questions. Compute inside Canada, operated from elsewhere, with keys held elsewhere and no practical exit, satisfies one requirement out of five. The national buildout will take years. The placement decisions determining where Canadian workloads run for the next decade are being made this quarter, by architecture and procurement teams, usually without anyone framing them that way.
VEXXHOST operates open infrastructure built on OpenStack, Kubernetes and Ceph, with regions in Montreal, Santa Clara and Amsterdam and a customer-premises deployment path. We design residency-aware deployment options for production AI workloads, hosted or on your own hardware, and operate them after launch.
We're at ALL IN 2026, September 16–17, Palais des congrès de Montréal, booth M30. Bring a workload and we'll walk the five questions against it in about twenty minutes. Book a slot, or come find us.