Europe has a new sovereign AI champion, and its parent is Canadian.
The defence is straightforward and — this matters — substantially correct: Canada is not the United States, so the CLOUD Act does not reach a Canadian-incorporated company the way it reaches Amazon or Microsoft. That’s real. It’s a genuine legal difference, and anyone who waves it away is being sloppy.
But it answers a narrower question than the market thinks it does. Because in the space of one press conference, European sovereignty quietly changed definition — from “incorporated in the EU” to “not incorporated in the US” — and nobody asked whether the second thing is a test or merely a proxy.
It’s a proxy. Proxies fail at the edges. And the edges are exactly where procurement lives.
This isn’t an argument that Canada is secretly America, or that Cohere is compromised. It’s an argument that nationality is a substitute for measurement, and that Europe has adopted the substitute at the precise moment it needed the measurement. Here’s the honest analysis — including the parts that favour the Canadian position, which are stronger than the critics allow.
The wrong test: “not American” is not a sovereignty standard
In one press conference, European sovereignty changed definition — from “incorporated in the EU” to “not incorporated in the US” — and nobody asked whether the second is a test or merely a proxy. It’s a proxy. Proxies fail at the edges. The edges are where procurement lives.
The CLOUD Act genuinely doesn’t reach Canadian incorporation. Canada has no CLOUD Act executive agreement — negotiating since March 2022, nothing finalized. And the Supreme Court of Canada (R. v. Spencer, R. v. Bykovets) explicitly rejected the US third-party doctrine. On several dimensions Canada is more protective than the US. This is not a hit piece.
UKUSA (1946): NSA · GCHQ · CSE · ASD · GCSB. CSE’s oversight is real — ministerial authorization, an independent Intelligence Commissioner (a retired judge) who can block, NSIRA review. Now read the operative restriction:
The protection is national and territorial. Europeans are neither.
Not an accusation — architecture. It’s structurally why Safe Harbor fell: protections protect the home nationals.
Canada has adequacy since 2001/2002 (Decision 2002/2/EC). But its scope is PIPEDA-only — employee data largely excluded; Alberta/BC/Quebec regimes never got adequacy; Quebec’s was withdrawn in 2014.
It was assessed against PIPEDA’s commercial framework — not against Canada’s intelligence laws or Five Eyes participation.
That’s the same hole the CJEU punched through Safe Harbor. In fairness: the Commission did examine public-authority access and found redress “accessible to non-Canadian nationals.” That clause is the best argument Canada has — and NSIRA is largely classified. Unsettled, not resolved.
US courts have been clear for 40 years: Bank of Nova Scotia — American courts enforce subpoenas against entities subject to US jurisdiction even where compliance violates foreign law, and fine for refusal. Jurisdiction attaches to presence and activity, not the incorporation certificate. So corporate pledges to “resist” are sincere and legally insufficient. And Canadian exposure creeps through ordinary commercial expansion:
The Five Eyes question isn’t “is Canada spying for America” — that’s the tabloid version, it’s unsupported, and it’s a distraction. The real question is duller and more damaging: why is Europe using nationality as a substitute for measurement? Because a proxy is cheap and a test is expensive. “Not American” lets you approve the deal, satisfy the minister, and skip the register, the nexus, the redress. It produces a press release. It does not produce protection. Every sovereignty claim here is a jurisdictional bet — that a legal system, an alliance and a political mood hold for the life of your data. The Canadian bet is genuinely better than the American one. It’s still a bet. The only positions that don’t require one are where you hold the weights and can pull the plug. If the answer is “well, they’re not American” — you haven’t been given a standard. You’ve been given a mood.
Start with what’s true
Give the Canadian case its full weight first, because it’s better than the sceptics admit.
The CLOUD Act genuinely doesn’t reach Canadian incorporation. The statute compels US-incorporated providers and their subsidiaries. A Canadian parent isn’t one. That’s not a technicality; it’s the whole architecture.
Canada has not signed a CLOUD Act executive agreement. It has been negotiating one with the United States since March 2022 — and more than three years later, nothing has been finalized. Unlike the UK and Australia, Canada has no bilateral instrument accelerating US access to data held by its providers.
And Canadian courts have gone further than American ones. In R. v. Spencer and R. v. Bykovets, the Supreme Court of Canada explicitly rejected the US third-party doctrine — the principle that data handed to a service provider loses its constitutional protection. That rejection is why a CLOUD Act agreement would let US authorities obtain Canadian data using standards Canadian courts have declared unconstitutional, and why the negotiation has stalled. The Citizen Lab’s assessment is worth sitting with: one would be hard pressed to find two democracies more incompatible when it comes to aligning digital surveillance law.
On several dimensions, Canada is more protective of data than the United States. That is the honest starting point. Anyone arguing otherwise hasn’t read the case law.
So the question isn’t whether Canada is bad. It’s whether “Canadian” is a measurement of anything a European buyer actually needs to know.

AI Compliance Guide: Canada 2026: AI Regulation, Governance & Risk Management for Canadian Businesses
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
The Five Eyes fact, stated precisely
Canada is one of five signals-intelligence partners under the UKUSA Agreement, formalized in 1946 and extended since: the NSA (US), GCHQ (UK), CSE (Canada), ASD (Australia), and GCSB (New Zealand).
CSE’s own public position deserves quoting fairly, because it’s more disciplined than the conspiracy version: it states plainly that it does not ask international partners to do anything on its behalf that would be illegal for it to do. Disclosure to partners requires the Minister of National Defence to have designated the recipient, and the disclosure must be essential for international affairs, defence, security, or cyber security. Foreign-intelligence and cyber-security authorizations require ministerial approval and sign-off from an independent Intelligence Commissioner — a retired superior court judge who can block them. NSIRA reviews the whole apparatus. That is a real oversight architecture, and it is better than several EU member states manage domestically.
Now read the operative restriction closely, because everything turns on it:
CSE is prohibited by law from targeting the private information of Canadians, or any person in Canada.
Read it again. The protection is national and territorial. It protects Canadians. It protects people in Canada.
Europeans are neither.
From the statutory perspective of Canada’s foreign-intelligence mandate, an EU company and its employees are, definitionally, foreign — which is what a foreign-intelligence mandate is for. Bill C-59, the National Security Act 2019, expanded CSE’s powers to conduct active cyber operations and collect foreign intelligence.
This is not an accusation of wrongdoing. It’s the architecture, and it is structurally identical to the reason Safe Harbor and Privacy Shield fell: a country’s privacy protections protect its own nationals, and a European data subject is on the wrong side of that line. The CJEU didn’t strike down US frameworks because America was uniquely villainous. It struck them down because the safeguards didn’t extend to Europeans and the redress wasn’t reachable.
That reasoning is structural, not American-specific. Which is exactly why using “not American” as your test is a category error.

AI Engineering: Building Applications with Foundation Models
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
The adequacy gap nobody mentions
Canada holds a European Commission adequacy decision — granted in 2001/2002 under Decision 2002/2/EC, reaffirmed most recently in January 2024 alongside ten other jurisdictions. That makes EU→Canada transfers legally valid. Fine.
Three things about it, in ascending order of importance.
First, its scope is narrower than people assume. It covers organizations subject to PIPEDA: federally regulated entities (banks, airlines, telecoms), federal works and undertakings, and commercial activities in provinces that haven’t passed substantially similar law. Employee data largely falls outside it. And Alberta, British Columbia, and Quebec — whose laws are “substantially similar” — have never received adequacy status in their own right. Adequacy has been withdrawn before: Quebec lost it in 2014.
Second, and this is the load-bearing point: the adequacy decision was assessed against PIPEDA’s commercial data-protection framework. It was not assessed against Canada’s intelligence laws or its Five Eyes participation.
That is precisely — structurally, not rhetorically — the hole the CJEU punched through Safe Harbor in Schrems I. The framework was evaluated on commercial protections while the national-security apparatus sat outside the assessment.
Third — and in fairness, this is the strongest counter — the Commission did not entirely ignore the question. In its review it found that Canadian public authorities are subject to appropriate limitations and safeguards under the Charter, case law, and public-sector data-protection rules, and that Canada’s legal system provides effective oversight and redress mechanisms accessible to non-Canadian nationals or residents. That last clause is doing real work, and it’s the best argument the Canadian position has. It’s also the exact clause the CJEU spent two decisions interrogating in the American context — and NSIRA’s operations remain largely classified and, in practice, hard for an EU data subject to reach.
Unsettled, then. Not settled in Canada’s favour, and not settled against it. Which is the problem: Europe just made a €20-billion sovereignty bet on an unsettled question, and called it resolved.
European AI sovereignty compliance solutions
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
The nexus problem — the part that actually matters
Here’s the analytical core, and it’s where “not American” stops being merely imprecise and starts being actively misleading.
Incorporation is not the test. Nexus is.
US courts have been clear for forty years. The Bank of Nova Scotia line of cases established that American courts will enforce subpoenas against entities subject to US jurisdiction even where compliance violates foreign law — and will impose substantial fines for refusal. Jurisdiction attaches to presence and activity, not to the address on the incorporation certificate.
Which means corporate promises don’t survive contact with it. When Microsoft announced C$19 billion of Canadian AI investment in December 2025 with pledges to challenge US legal orders and resist disclosure of Canadian data, those pledges were sincere and legally insufficient. A company cannot contract out of a court’s jurisdiction.
And Canadian corporate exposure is creeping, quietly, through ordinary commercial expansion:
- BCE acquired Ziply Fiber, a US telecom, in August 2025 — which analysts argue makes Canada’s largest telecom almost certainly subject to CLOUD Act compulsion.
- TELUS operates in the US with 1,600+ employees through TELUS Digital.
- Shopify processes 57% of its transactions in the United States and now lists New York as a principal executive office.
None of those companies changed nationality. All of them changed nexus.
So the question a European buyer should be asking about Europe’s new sovereign champion is not “is Cohere Canadian?” — it is:
“What US nexus does Cohere have?” US enterprise customers. US operations. A strategic partnership with Microsoft. US investors including Nvidia, Salesforce Ventures, and Cisco. And — the one that would settle it — a plausible future US listing, which Gomez’s own promise that “Cohere will become a Canadian-German company” gets much harder to keep after.
I don’t know the answer. It’s a factual question about corporate structure and activity that requires disclosure and counsel. But “the parent is Canadian” doesn’t answer it, and as far as I can tell nobody has asked — which is remarkable for a company two G7 governments just anointed as Europe’s alternative to American dependence.

The 2027-2032 World Outlook for Mobile Data Protection Software
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
The geopolitics that reframes the whole thing
Now the context that makes this more than a legal curiosity.
The November 2025 US National Security Strategy reportedly declares that agreements with dependent allies must be sole-source contracts for American companies, and instructs Washington to push out foreign companies that build infrastructure in the region. The July 2025 White House AI Action Plan frames technological dominance — explicitly including “cloud dominance” — as a national security imperative.
Set that beside a Five Eyes partner selling Europe independence from America, and the picture gets complicated. Not because Canada is a stalking horse — there’s no evidence for that and I’m not arguing it. But because “friendly ally” is doing enormous load-bearing work as a security assumption in a period when the United States is explicitly describing allies’ cloud markets as sole-source territory for its own firms, and when this year alone demonstrated that model access can be switched off by executive directive.
Sovereignty frameworks are supposed to survive the friendship ending. That’s the entire point of them. A standard that works only while relations are good isn’t a standard; it’s a mood.
So what is the right test?
Not passports. Enforceable, auditable control. Six questions, in rough order of how much they’ll matter when something goes wrong:
- Who can compel you, under what legal standard, and is there judicial review? Not “where are you incorporated” — who holds the power.
- Is there redress for a non-national? The existing US–UK and US–Australia CLOUD Act agreements establish no rights or remedies for individuals whose data is seized — what researchers call a remedial no-man’s land. If your people can’t sue, the safeguard is decorative.
- What is your nexus — not your incorporation? US subsidiary? US listing? US revenue share? US executive office? This is the question that actually predicts compulsion.
- Who holds the encryption keys, and can they be legally compelled to produce them? Microsoft answered this one accidentally: encryption made access “technically impossible” in May 2025 and couldn’t guarantee immunity from US authorities thirty days later.
- Can you leave, and how fast? Gartner puts full cloud-exit at 12–18 months of project work. Lock-in is a sovereignty exposure.
- Can it be air-gapped? The only test that survives every answer above.
Notice what happens as you go down that list: the questions stop being about jurisdiction and start being about architecture. That’s not an accident. It’s the finding.
The honest hierarchy
Three standards, ranked by how much they actually protect you:
“Not American” — a proxy. Better than nothing. Fails on nexus, fails on Five Eyes statutory architecture, fails when the ally’s interests diverge, and fails silently because nobody’s measuring. This is what Europe just adopted.
“EU-incorporated” — a test. The 24%/39% ownership cap in SecNumCloud is narrow, arithmetic, and checkable from a shareholder register. It’s also, undeniably, protectionist industrial policy. Both true at once. This is what Europe already had, and what it just quietly stepped back from — because the champion it wanted couldn’t pass it.
“Open weights, your hardware, your keys, air-gappable” — an architecture. It doesn’t require trusting any jurisdiction, any ally, any election result, or any executive directive. It’s the only posture that survives all six questions, and it’s the reason the open-weight labs and the air-gap vendors have a real product rather than a slogan.
Europe just moved from the second to the first and called it progress.
The take
The Five Eyes question isn’t “is Canada spying for America?” That’s the tabloid version, it’s unsupported, and it’s a distraction. CSE’s oversight architecture is genuine, the Supreme Court of Canada has been more protective than its American counterpart, and there is no CLOUD Act agreement.
The real question is duller and much more damaging: why is Europe using nationality as a substitute for measurement?
Because a proxy is cheap and a test is expensive. “Not American” lets you approve the deal, satisfy the minister, and skip the shareholder register, the nexus analysis, the redress question, and the adequacy-scope problem. It produces a press release. It does not produce protection.
Every sovereignty claim in this market is, underneath, a jurisdictional bet — a wager that a particular legal system, a particular alliance, and a particular political mood will hold for the life of your data. Some of those bets are better than others, and the Canadian bet is genuinely better than the American one. But it’s still a bet.
The only positions that don’t require a bet are the ones where you hold the weights and can pull the plug. Everything else is trust, priced as if it were a guarantee.
Ask for the shareholder register. Ask for the nexus. Ask who can be compelled and whether your people can sue. And if the answer to all of it is “well, they’re not American” — you haven’t been given a standard. You’ve been given a mood.
Sources: Five Eyes/UKUSA structure and CSE’s mandate, oversight (ministerial authorization, the independent Intelligence Commissioner, NSIRA) and the prohibition on targeting Canadians or persons in Canada, via the Communications Security Establishment’s own published material; Bill C-59 (National Security Act 2019) scope via the same; Canada’s GDPR adequacy (Commission Decision 2002/2/EC, 2001/2002; January 2024 reaffirmation), its PIPEDA-limited scope, the exclusion of employee data, the non-adequacy of Alberta/BC/Quebec regimes and the 2014 Quebec withdrawal via IAPP, CIGI, Dentons and McMillan analyses; R. v. Spencer and R. v. Bykovets, the stalled Canada–US CLOUD Act executive-agreement negotiations (since March 2022), the Bank of Nova Scotia precedent, the UK’s 20,000+ requests figure, the “remedial no-man’s land” in existing US–UK/US–Australia agreements, and the BCE/Ziply, TELUS and Shopify nexus examples via Barry Appleton’s “Whose Law Governs Canadian Data?” (Balsillie Papers / SSRN, 2026) and the Citizen Lab’s February 2025 analysis; the November 2025 US National Security Strategy and July 2025 White House AI Action Plan characterizations as reported in that paper; Microsoft’s May–June 2025 encryption sequence and its December 2025 Canadian pledges as reported. Note that some Five Eyes/GDPR analysis in circulation originates with vendors selling EU-hosted alternatives and should be read with that interest in mind; the primary legal sources above do not depend on it. This is procurement and policy analysis, not an allegation of misconduct by any company or agency, and it is not legal advice — jurisdictional questions require qualified counsel. Analysis and framing are the author’s.