📊 Full opportunity report: Why We Need More Than 'Not American' To Define AI Sovereignty on ThorstenMeyerAI.com — validation score, market gap, and execution plan.

TL;DR

This article examines why relying solely on ‘not American’ status to define AI sovereignty is inadequate. It highlights legal, geopolitical, and measurement issues, emphasizing the need for nuanced criteria.

Recent discussions around AI sovereignty have often reduced the concept to a simple distinction: not American. However, experts warn that this narrow view overlooks critical legal, geopolitical, and measurement issues, which are essential for truly understanding and defining AI sovereignty. The debate has gained prominence as European policymakers and industry leaders seek to establish independent digital and AI frameworks.

Europe recently claimed a new AI champion, with its parent company based in Canada, emphasizing that Canadian jurisdiction is not subject to the US CLOUD Act, unlike US-incorporated companies. This legal difference is real and significant, as Canadian law and courts have explicitly rejected US surveillance doctrines, making Canadian data less vulnerable to US access. However, this legal distinction alone is insufficient for comprehensive sovereignty.

Canada is part of the Five Eyes intelligence alliance, which includes the US, UK, Australia, and New Zealand. Despite this partnership, Canadian law strictly prohibits targeting Canadians and those in Canada, creating a territorial protection that does not extend to Europeans or other jurisdictions. Canada holds a European Commission adequacy decision since 2002, but this covers only certain organizations and is based on PIPEDA, which has limited scope. The adequacy status does not fully address the broader issues of measurement, jurisdiction, or the complex realities of AI governance.

Experts warn that equating nationality with sovereignty is a proxy that can fail at critical edges—particularly in procurement and international data flows—where measurement and legal frameworks matter more than simple jurisdictional labels. The European shift from ‘incorporated in the EU’ to ‘not American’ as a defining criterion risks oversimplifying a complex landscape. For more on this topic, see The Sovereignty Paradox: Mistral’s Impact On European AI.

At a glance
analysisWhen: developing; ongoing debate and recent p…
The developmentThe article analyzes recent developments in AI sovereignty, focusing on legal distinctions and geopolitical implications beyond simple nationality labels.
The Wrong Test — Reality Check
AI Dispatch · Reality Check · 16 July 2026

The wrong test: “not American” is not a sovereignty standard

In one press conference, European sovereignty changed definition — from “incorporated in the EU” to “not incorporated in the US” — and nobody asked whether the second is a test or merely a proxy. It’s a proxy. Proxies fail at the edges. The edges are where procurement lives.

✓ First, what’s true — the Canadian case is stronger than critics allow

The CLOUD Act genuinely doesn’t reach Canadian incorporation. Canada has no CLOUD Act executive agreement — negotiating since March 2022, nothing finalized. And the Supreme Court of Canada (R. v. Spencer, R. v. Bykovets) explicitly rejected the US third-party doctrine. On several dimensions Canada is more protective than the US. This is not a hit piece.

The Five Eyes fact, stated precisely

UKUSA (1946): NSA · GCHQ · CSE · ASD · GCSB. CSE’s oversight is real — ministerial authorization, an independent Intelligence Commissioner (a retired judge) who can block, NSIRA review. Now read the operative restriction:

“CSE is prohibited by law from targeting the private information of Canadians, or any person in Canada.”

The protection is national and territorial. Europeans are neither.

Not an accusation — architecture. It’s structurally why Safe Harbor fell: protections protect the home nationals.

The adequacy gap nobody mentions

Canada has adequacy since 2001/2002 (Decision 2002/2/EC). But its scope is PIPEDA-only — employee data largely excluded; Alberta/BC/Quebec regimes never got adequacy; Quebec’s was withdrawn in 2014.

It was assessed against PIPEDA’s commercial framework — not against Canada’s intelligence laws or Five Eyes participation.

That’s the same hole the CJEU punched through Safe Harbor. In fairness: the Commission did examine public-authority access and found redress “accessible to non-Canadian nationals.” That clause is the best argument Canada has — and NSIRA is largely classified. Unsettled, not resolved.

⚠ The nexus problem — incorporation is not the test

US courts have been clear for 40 years: Bank of Nova Scotia — American courts enforce subpoenas against entities subject to US jurisdiction even where compliance violates foreign law, and fine for refusal. Jurisdiction attaches to presence and activity, not the incorporation certificate. So corporate pledges to “resist” are sincere and legally insufficient. And Canadian exposure creeps through ordinary commercial expansion:

BCE bought Ziply Fiber (US) Aug ’25 TELUS — 1,600+ US staff Shopify — 57% of txns in US; NY principal executive office None changed nationality. All changed nexus. So: what US nexus does Cohere have? Customers · ops · Microsoft partnership · US investors · a likely US listing. Nobody has asked.
The honest hierarchy — three standards, ranked by what they actually protect
✕ A proxy
“Not American”
Fails on nexus, fails on Five Eyes statutory architecture, fails when the ally’s interests diverge — and fails silently, because nobody’s measuring. This is what Europe just adopted.
◐ A test
“EU-incorporated”
SecNumCloud’s 24%/39% cap — narrow, arithmetic, checkable from a shareholder register. Also undeniably protectionist. Both true. What Europe already had — and just stepped back from.
✓ An architecture
Open weights · your keys · air-gappable
Requires trusting no jurisdiction, no ally, no election result, no executive directive. The only posture that survives every question below.
Europe just moved from the second to the first — and called it progress.
✓ The right test — enforceable, auditable control
1Who can compel you, under what standard, with what judicial review?
2Is there redress for a non-national? (US–UK/AU deals create none)
3What’s your nexus — not your incorporation?
4Who holds the keys, and can they be compelled to produce them?
5Can you leave, and how fast? (12–18 months of exit work)
6Can it be air-gapped?
Notice what happens down the list: the questions stop being about jurisdiction and start being about architecture. That’s not an accident — that’s the finding.
The take

The Five Eyes question isn’t “is Canada spying for America” — that’s the tabloid version, it’s unsupported, and it’s a distraction. The real question is duller and more damaging: why is Europe using nationality as a substitute for measurement? Because a proxy is cheap and a test is expensive. “Not American” lets you approve the deal, satisfy the minister, and skip the register, the nexus, the redress. It produces a press release. It does not produce protection. Every sovereignty claim here is a jurisdictional bet — that a legal system, an alliance and a political mood hold for the life of your data. The Canadian bet is genuinely better than the American one. It’s still a bet. The only positions that don’t require one are where you hold the weights and can pull the plug. If the answer is “well, they’re not American” — you haven’t been given a standard. You’ve been given a mood.

Sources: CSE’s own published material (UKUSA, mandate, Intelligence Commissioner, NSIRA, the targeting prohibition); IAPP, CIGI, Dentons, McMillan (Canada’s adequacy scope, PIPEDA limits, Quebec 2014); Barry Appleton, “Whose Law Governs Canadian Data?” (Balsillie Papers/SSRN 2026) & Citizen Lab Feb 2025 (Spencer/Bykovets, stalled CLOUD Act talks, Bank of Nova Scotia, UK’s 20,000+ requests, remedial no-man’s land, BCE/TELUS/Shopify nexus, US NSS & AI Action Plan). Some Five Eyes/GDPR analysis in circulation originates with vendors selling EU-hosted alternatives — read accordingly. Procurement & policy analysis, not an allegation of misconduct. Not legal advice.
thorstenmeyerai.com

Implications of Simplistic Sovereignty Definitions

Understanding AI sovereignty requires more than just legal jurisdiction or nationality labels. Relying on ‘not American’ as a proxy can lead to flawed assessments, especially in procurement, data security, and international cooperation. This approach risks overlooking the nuanced legal protections, oversight mechanisms, and measurement criteria that truly define sovereignty. For European policymakers, this debate highlights the importance of developing precise, measurable standards rather than relying on proxy indicators.

Amazon

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Legal and Geopolitical Factors Shaping AI Sovereignty

The legal landscape distinguishes Canadian law from US law, notably through the CLOUD Act and Canadian courts’ rejection of US surveillance doctrines. Canada’s status within the Five Eyes alliance offers some protection, but it is limited to Canadians and does not extend to European data subjects. The European Union’s adequacy decision for Canada is narrow, based on PIPEDA, and does not cover all data types or jurisdictions within Canada. This context underscores the complexity of defining sovereignty based solely on jurisdictional labels.

Historically, sovereignty debates have focused on physical borders and legal jurisdictions. However, in the digital age, the boundaries are blurred, and the legal frameworks—such as data protection laws, oversight mechanisms, and international agreements—are more relevant. Recent shifts in European policy reflect a move toward recognizing measurement and legal standards over simple nationality proxies.

Amazon

international data governance software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Unresolved Questions About Practical Sovereignty

It remains unclear how European policymakers will operationalize measurement and legal standards beyond jurisdictional labels. The effectiveness of current frameworks in ensuring true sovereignty, especially in procurement and international data flows, is still under debate. Additionally, the evolving nature of international agreements and legal standards could alter the landscape, but specifics are yet to be determined.

The Developer's Playbook for Large Language Model Security: Building Secure AI Applications

The Developer's Playbook for Large Language Model Security: Building Secure AI Applications

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Next Steps in Defining and Implementing AI Sovereignty Standards

European policymakers are expected to refine their criteria for AI sovereignty, moving beyond jurisdictional proxies toward measurable legal and technical standards. Ongoing negotiations around data adequacy, legal oversight, and international cooperation will shape future frameworks. Monitoring these developments will be crucial for understanding how sovereignty is practically enforced in the AI and data landscape.

Amazon

AI jurisdiction management tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

Why is relying on ‘not American’ insufficient to define AI sovereignty?

Because sovereignty involves legal protections, oversight mechanisms, and measurement criteria that go beyond simple jurisdictional labels. Relying solely on ‘not American’ ignores these complexities and can lead to flawed assessments, especially in procurement and data security.

Canadian law, including the Supreme Court’s rulings, explicitly rejects US surveillance doctrines like the third-party doctrine. Canada’s legal protections are territorial, protecting Canadians and data in Canada from US access, unlike US law which compels US-incorporated providers.

What are the limitations of Canada’s European adequacy status?

Canada’s adequacy decision covers only certain organizations under PIPEDA and is limited in scope. It does not fully address all data types or jurisdictions within Canada, and it was assessed based on a narrower legal framework than what is needed for comprehensive sovereignty.

What are the risks of oversimplifying AI sovereignty?

Oversimplification can lead to gaps in legal protections, procurement vulnerabilities, and misunderstandings about jurisdictional influence. It risks creating a false sense of security based on nationality rather than measurable legal and technical standards.

Source: ThorstenMeyerAI.com

You May Also Like

The Local-First Agentic Operator

A single operator using agentic AI now builds and manages multiple complex products across domains, traditionally requiring organizations, highlighting a shift in software development.

Grok Build is open source

Grok Build has announced its source code is now publicly available, enabling community collaboration and development.

The SSD Squeeze: Why Storage Joined the Party

Enterprise and consumer SSD prices soar as NAND supply tightens due to AI-driven demand and wafer competition, impacting the entire storage market.

Pentagon AI Goes Explicit: The Frontier Labs Move Inside the Classified Stack

The Pentagon announces agreements with major AI firms to embed advanced models into classified military networks, signaling a shift to AI-first warfare.