AIThis post was created with the assistance of artificial intelligence (AI).

Yesterday this publication argued that Canada’s AI ecosystem could materially broaden Europe’s technological options, and that von der Leyen’s associate-membership proposal is strategically more interesting than the trade framing suggests.

That argument stands. This piece is the other half of it.

Because “alliance” is a mood until it is a clause. Associate membership does not exist in the EU treaties. Nobody has said who approves it, what it contains, or how long it takes. Canada’s own ambassador says Ottawa is not there yet, and both sides are deliberately settling the substance before the label.

Which means the substance is being drafted right now — and this is the narrow window in which specifying the tests is worth more than praising the alliance.

Here are six. Each one is answerable, each has a wrong answer, and one of them is a live contradiction nobody in Brussels or Ottawa has publicly resolved.

The Associate Member Test — Insights
AI Dispatch · Insights · 17 September 2026

The associate member test: six things Europe should ask Canada for

The alliance is strategically sound. But “alliance” is a mood until it’s a clause — associate membership isn’t in the treaties, nobody’s said who approves it, and Ottawa is “not there yet.” Which means the substance is being drafted right now. This is the narrow window where specifying the tests beats praising the partnership.

⚠ The contradiction nobody is naming — two files, two directorates, no headline
5 March 2026 · Toronto · Šefčovič + Sidhu
The Canada–EU Digital Trade Agreement negotiations formally launch. Intended to prohibit “unjustified data-localization requirements.” Backed by the European Parliament 482–108.
vs
How EU sovereignty is actually enforced
SecNumCloud: EU-only storage + 24%/39% non-EU ownership caps, mandatory for sensitive French public data. CADA: assurance levels turning on data residency. Every one is a data-localization requirement.
So: is SecNumCloud justified localization — or the kind the DTA is designed to prohibit? That single word is where allied AI sovereignty and European AI sovereignty get reconciled — by lawyers, in a text, probably without a headline.
The six tests — each answerable, each with a wrong answer
1
Does the DTA carve out security-certification regimes by name?
Not “public policy exceptions” in general. SecNumCloud, EUCS, CADA assurance levels — named. A vague carve-out gets litigated, and the party with more lawyers wins.
2
Under what assurance level does a Canadian supplier actually qualify?
Cohere’s shareholders hold ~90% of the merged entity against a 24% individual cap — roughly 4× over. Nothing about associate membership changes that arithmetic unless it’s deliberately changed.
3
Does CADA recognize associate states — Article 17 pathway or not?
National labels don’t auto-satisfy CADA; even SecNumCloud providers need separate recognition. If associate membership lands in 2027 and CADA passes without an associate-state provision, the alliance stops at the procurement door.
4
Is adequacy re-examined against intelligence law?
Canada’s adequacy (2002) was assessed on PIPEDA’s commercial framework — not intelligence law or Five Eyes. That’s the gap the CJEU punched through Safe Harbor. In fairness: no CLOUD Act agreement, and the Supreme Court rejected the third-party doctrine. Canada may pass — nobody has tested it.
5
Whose jurisdiction governs shared compute?
Compute has a physical location, and location decides which police force can walk in. Reciprocal access is not reciprocal jurisdiction. The template exists: Canada’s SAFE accession (Feb 2026, first non-European into the €150B instrument) — access with conditions.
6
What is the exit clause?
Alliances are political objects. Canada’s pivot is driven by a hostile Washington — real, current, not permanent. CETA is still unratified by 10 member states after nine years. Build on what survives a reversal: open weights, rehostability, migration terms, air-gap path.
Test 2 in detail — three options, pick one openly
Option A
Leave the cap

Canadian suppliers sell commercially, stay out of SecNumCloud-gated procurement. Honest — and limits the alliance exactly where sovereignty decides deals.

Option B
Associate-member tier

Associate-state entities count as EU-equivalent, conditional on jurisdictional guarantees. The interesting option and the dangerous one — converts bright-line arithmetic into political judgement.

Option C
EU-controlled subsidiary

The S3NS/Bleu pattern — Thales holds control of the Google venture; Capgemini+Orange front Azure. Existing rules already accommodate this. No new category needed.

Drift is the worst outcome. If nobody can say which of A, B or C is the plan, the AI content of the alliance is aspirational.
✓ The negotiating position, compressed
1Name the security-certification carve-out in the DTA text
2Pick A, B or C on the ownership cap — publicly
3Write an associate-state pathway into CADA Article 17
4Commission a fresh adequacy review covering national-security access — and publish it
5Specify conflict-of-laws rules per workload class, on the SAFE model
6Require open weights, rehostability & migration terms in sensitive procurement
None are hostile to the alliance. Five of six make it more durable — an alliance with specified terms survives a change of government; one built on goodwill does not.
The take

The geopolitics were settled the moment Carney got a standing ovation in Strasbourg. What’s unsettled is the text — and the text is where sovereignty either gets operationalized or gets talked about. The real risk isn’t that Canada is untrustworthy. It’s that Europe spends two years negotiating a partnership that sounds like sovereignty while negotiating a trade agreement that constrains the instruments that enforce it — and nobody notices until a French procurement officer finds the localization clause in his tender is now a trade violation. Answer the six and allied AI sovereignty becomes a real category — arguably the most sensible one on offer for a continent that can’t build the whole stack alone. Leave them unanswered and it becomes what “not American” already became: a proxy standing in for a test, adopted because the test was inconvenient.

Sources: Canada–EU DTA negotiations launched 5 Mar 2026 (Šefčovič/Sidhu, 5th CETA Joint Committee), the data-localization objective and EP resolution 482–108 via Commission & Global Affairs Canada joint statements, Agence Europe, EU Perspectives; Canada–EU AI cooperation agreement (late 2025), Digital Partnership (Dec 2023); SAFE accession Feb 2026; CETA unratified by 10 member states; SecNumCloud caps & Cloud au Centre per ANSSI; CADA (COM(2026) 502) Art. 17; Canada’s adequacy (2002/2/EC, Jan 2024) & its PIPEDA scope per IAPP, CIPS (Leblond & Camilleri), UTFLR. The reading of “unjustified” localization as an unresolved tension is the author’s, not a reported position of either party. Not legal advice.
thorstenmeyerai.com

First, the tension nobody is naming

Start here, because it reframes the other five.

On 5 March 2026, in Toronto, EU Trade Commissioner Maroš Šefčovič and Canadian Trade Minister Maninder Sidhu formally launched negotiations on a Canada–EU Digital Trade Agreement. Per the Commission’s own framing, the DTA is intended to prohibit unjustified data-localization requirements, ban customs duties on electronic transmissions, and establish common rules for e-signatures, e-contracts and consumer protection. The European Parliament backed the direction 482 votes to 108.

Now hold that next to how European AI sovereignty is actually enforced.

SecNumCloud requires EU-only data storage and caps non-EU ownership at 24% individually, 39% collectively. France’s Cloud au Centre doctrine makes it mandatory for sensitive public-sector data. The proposed Cloud and AI Development Act would establish Union assurance levels turning on legal control, jurisdictional risk and data residency. Every one of those instruments is, in trade-agreement vocabulary, a data-localization requirement.

So: is SecNumCloud “justified” localization, or is it the kind the DTA is designed to prohibit?

That single word — unjustified — is where the entire relationship between allied AI sovereignty and European AI sovereignty will be settled. It will be settled by lawyers, in a text, probably without a headline. And if it is settled the wrong way, Europe will have signed a digital trade agreement that constrains the only instrument it has that actually tests sovereignty.

Test 1: Does the DTA’s data-localization clause carve out national and Union security-certification regimes explicitly — by name? Not “public policy exceptions” in general. SecNumCloud, EUCS, and CADA assurance levels, named. If the carve-out is vague, it will be litigated, and the party with more lawyers wins.

Amazon

EU-Canada digital trade agreement guide

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Test 2: Under what assurance level does a Canadian supplier actually qualify?

Associate membership without a procurement answer is a press release.

Today the arithmetic is unforgiving. SecNumCloud’s ownership cap is 24% individual / 39% collective non-EU. Cohere’s shareholders hold roughly 90% of the merged Cohere–Aleph Alpha entity. That is not a marginal miss; it is roughly four times the individual cap. Nothing about associate membership changes that arithmetic unless the arithmetic is deliberately changed.

So Europe has exactly three options, and it should pick one openly rather than drift:

(a) Leave the cap as is. Canadian suppliers sell into the commercial market and stay out of SecNumCloud-gated public procurement. Honest, and limits the alliance’s practical value in exactly the verticals where sovereignty is decisive.

(b) Create an associate-member tier. A defined category — call it what you like — where entities from associate states count as EU-equivalent for ownership purposes, conditional on jurisdictional guarantees. This is the interesting option and the dangerous one, because it converts a bright-line arithmetic test into a political judgement.

(c) Require EU-controlled subsidiaries. The S3NS/Bleu pattern: Thales holds operational control of the Google-based venture; Capgemini and Orange front Azure. A Canadian AI supplier could be delivered into sensitive European procurement through an EU-majority JV. This is the path the existing rules already accommodate — no new category required.

Test 2: Which of (a), (b) or (c) is the plan — and if (b), what conditions attach? If nobody can answer, the AI content of the alliance is aspirational.

Amazon

data localization compliance tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Test 3: Does CADA recognize associate states, and on what basis?

The rulebook is being rewritten underneath all of this. The proposed Cloud and AI Development Act would establish four Union assurance levels for cloud sovereignty in public procurement, with Level 1 as the floor for general public-sector work and higher levels for activities tied to preserving public order. Its own recitals concede that cybersecurity certification “is not suited for addressing sovereignty concerns” — which is why sovereignty is migrating out of certification and into procurement law.

Critically, national labels would not automatically satisfy CADA. Even a SecNumCloud-qualified provider would need separate recognition under Article 17.

Which makes the question for the alliance obvious and unasked: does an associate member’s suppliers get a recognition pathway under CADA, or not? If associate membership is negotiated in 2027 and CADA is adopted without an associate-state provision, Europe will have built a technology alliance and a procurement regime that don’t speak to each other. That is not a hypothetical failure mode; it is the default outcome of two files moving on separate tracks.

Test 3: Is there an Article 17 pathway for associate-state providers, with defined conditions?

Amazon

EU security certification software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Test 4: Is the adequacy decision re-examined against intelligence law?

Canada holds EU adequacy under Decision 2002/2/EC, granted in 2001–02 and reaffirmed in January 2024. It is also, on the assessment of Canadian and European scholars alike, fragile — Canada’s privacy law has not kept pace with the EU’s evolving framework, and Canada’s AI legislation has been criticized for not engaging fundamental rights in the way adequacy analysis increasingly demands.

But the structural problem is narrower and more important than “outdated.” The adequacy decision was assessed against PIPEDA’s commercial data-protection framework. It was not assessed against Canada’s intelligence laws or its Five Eyes participation. That is precisely the gap the CJEU punched through Safe Harbor in Schrems I and Privacy Shield in Schrems II: a framework evaluated on commercial protections while the national-security apparatus sits outside the assessment.

Be fair about the counter, because it is real: the Commission did examine public-authority access and found Canadian oversight and redress mechanisms accessible to non-Canadian nationals — a clause that does genuine work, and one the US frameworks could never satisfy. Canada has also not signed a CLOUD Act executive agreement despite negotiating since March 2022, and its Supreme Court has explicitly rejected the US third-party doctrine. The Canadian position is stronger than lazy criticism allows.

The point is not that Canada fails. It is that nobody has tested it against the right question, and an alliance that deepens data flows on the strength of a twenty-four-year-old commercial-framework assessment is building on an untested foundation.

Test 4: Does associate membership trigger a fresh adequacy review covering intelligence-sharing and national-security access — with the result published? If the answer comes back clean, the alliance gets a genuine credential nobody can attack. If it doesn’t, better to know before the compute is co-located.

Amazon

cloud assurance level testing

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Test 5: Whose jurisdiction governs shared compute?

This is the one the strategy documents skip entirely.

Canada launched its AI Sovereign Compute Infrastructure Program in April 2026, and its AI for All strategy calls for a world-leading public AI supercomputer. Europe is building AI gigafactories. The obvious alliance move is shared or reciprocal access.

But compute has a physical location, and location determines which police force can walk in. A European defence contractor training on a model hosted in Quebec is subject to Canadian law regarding that data, regardless of what the partnership agreement says about cooperation. A Canadian firm using EU gigafactory capacity is subject to EU law and the AI Act. Reciprocal access is not reciprocal jurisdiction, and conflating them is how sovereignty claims quietly evaporate.

There is precedent for getting this right. Canada became, in February 2026, the first and only non-European country granted access to SAFE, the EU’s €150 billion defence financing instrument — a real, structured, conditioned integration into a sensitive European programme. That is the template: access with defined conditions, not access as a gesture.

Test 5: For each class of workload — commercial, regulated, classified — which jurisdiction governs, where is it written down, and what happens on conflict? “Trusted partner” is not an answer to a conflict-of-laws question.

Test 6: What is the exit clause?

Every sovereignty argument this publication has made for a year reduces to the same question, and it applies to alliances as much as vendors: can you leave?

Alliances are political objects. Governments change. Canada’s pivot toward Europe is driven substantially by a hostile turn in Washington — a condition that is real, current, and not permanent. CETA itself is instructive: nine years into provisional application, it remains unratified by ten member states. European integration instruments do not always land where they were aimed.

So the design question is whether the AI dependencies created by this alliance are reversible if the politics reverse. If European defence procurement runs on Canadian models trained on Canadian compute, and the relationship cools in 2032, what is the exit cost? Gartner puts full cloud exit at 12–18 months of project work in ordinary commercial circumstances; sovereign AI stacks are worse.

The answer is not to avoid the dependency. It is to build it on things that survive a political reversal: open weights you hold, models you can rehost, contracts with defined migration terms, and architecture that can be air-gapped. That is the same answer this publication reached about vendors, and it applies identically to allies — especially to allies, because the alliance framing is precisely what makes people skip the question.

Test 6: Are the AI dependencies created here reversible, and at what documented cost?

What Europe should actually ask for

Compressed to a negotiating position:

  1. Name the security-certification carve-out in the DTA text. Not a general public-policy exception.
  2. Pick (a), (b) or (c) on the ownership cap — publicly. Drift is the worst outcome.
  3. Write an associate-state recognition pathway into CADA Article 17, or accept that the alliance stops at the procurement door.
  4. Commission a fresh adequacy review covering national-security access, and publish it.
  5. Specify conflict-of-laws rules per workload class for shared compute, on the SAFE model: conditioned access, not gestural access.
  6. Require open weights, rehostability and documented migration terms in any AI supply arrangement entering sensitive procurement.

None of these are hostile to the alliance. Five of the six make it more durable, because an alliance with specified terms survives a change of government and an alliance built on goodwill does not.

The take

The instinct to treat this as a geopolitical story is understandable and wrong. The geopolitics were settled the moment Carney got a standing ovation in Strasbourg. What is unsettled is the text — and the text is where sovereignty either gets operationalized or gets talked about.

There is a real risk here, and it is not that Canada is untrustworthy. It is that Europe spends the next two years negotiating a partnership that sounds like sovereignty while simultaneously negotiating a digital trade agreement that constrains the instruments that enforce sovereignty — and nobody notices until a French procurement officer discovers that the localization requirement in his tender is now a trade violation.

Two files, two directorates, one contradiction, no headline.

So the useful thing to say, while the drafting is live, is not that Canada would be a good partner. It probably would. The useful thing is: specify the test. Who can compel a supplier, under what standard, with what redress for a non-national. Which assurance level a Canadian firm reaches, and by what route. Which jurisdiction governs which workload. And what it costs to walk away.

Answer those six and allied AI sovereignty becomes a real category — arguably the most sensible one on offer for a continent that cannot build the whole stack alone.

Leave them unanswered and it becomes what “not American” already became: a proxy standing in for a test, adopted because the test was inconvenient.

The window for the first outcome is open now, and it closes when the drafts are done.


Sources: the Canada–EU Digital Trade Agreement negotiations formally launched 5 March 2026 in Toronto by Commissioner Maroš Šefčovič and Minister Maninder Sidhu at the fifth CETA Joint Committee, its intended prohibition of unjustified data-localization requirements, and the European Parliament resolution (482–108) via the European Commission’s and Global Affairs Canada’s joint statements, Agence Europe and EU Perspectives; the Canada–EU AI cooperation agreement (late 2025) and the Digital Partnership (December 2023) per the same; Canada’s accession to SAFE in February 2026 as the first and only non-European participant in the €150 billion instrument, and the June 2025 Security and Defence Partnership, via published accounts of the evolving Canada–EU partnership; CETA’s continued non-ratification by ten member states per European Parliament reporting; SecNumCloud’s EU-only storage requirement and 24%/39% non-EU ownership caps, the Cloud au Centre doctrine, and the S3NS/Bleu joint-venture pattern per ANSSI documentation and analyses cited in this publication’s earlier certification guide; CADA (COM(2026) 502) Union assurance levels and Article 17 recognition per the proposal; Canada’s EU adequacy (Decision 2002/2/EC, January 2024 reaffirmation), its PIPEDA-scoped basis, and academic assessments of its fragility and of AIDA’s fundamental-rights gap via IAPP, CIPS (Leblond & Camilleri), DigitalTrade4.EU and the University of Toronto Faculty of Law Review; the absence of a Canada–US CLOUD Act executive agreement and the Supreme Court of Canada’s rejection of the third-party doctrine as discussed in this publication’s earlier sovereignty analysis; Gartner’s 12–18-month cloud-exit estimate. Associate membership remains a proposal with no agreed legal form, and the DTA is in negotiation — the interpretation of “unjustified” data localization is the author’s identification of an unresolved tension, not a reported position of either party. Not legal advice; procurement and treaty questions require qualified counsel. Analysis and framing are the author’s.

You May Also Like

Unionizing the AI Sector: Could AI Engineers Become the New Labor Movement?

Keen AI engineers may hold the key to transforming workplace rights, but can collective action bridge industry gaps and redefine the future of work?

The Compute-for-Equity Era: Why OpenAI’s AMD Partnership Redefines How Intelligence Gets Financed

AIThis post was created with the assistance of artificial intelligence (AI).When AMD…

Did OpenAI just leak GPT-5? Horizon crushes code & design tasks

AIThis post was created with the assistance of artificial intelligence (AI).Something huge…

Blackwell’s Bottleneck: Inside Nvidia’s 2026 AI Supply Chain (and Why It Matters)

AIThis post was created with the assistance of artificial intelligence (AI).TL;DR —…