📊 Full opportunity report: The Fallacy Of Using 'Not American' To Measure AI Control on ThorstenMeyerAI.com — validation score, market gap, and execution plan.

TL;DR

This article examines why using ‘not American’ as a proxy for AI control is misleading. It explains the legal distinctions between Canada and the US and why nationality alone doesn’t measure data security or sovereignty.

Recent discussions in Europe have shifted toward defining AI sovereignty based on company nationality, particularly emphasizing Canadian-incorporated AI firms as alternatives to US-based ones. This shift is based on the fact that Canada is not subject to the US CLOUD Act, making Canadian companies legally distinct from American ones. However, experts warn that this approach oversimplifies the complex legal and geopolitical landscape, and relying solely on nationality as a measure of control is fundamentally flawed.

Canada’s legal framework and international agreements differ significantly from those of the United States. The U.S. CLOUD Act compels American-incorporated providers and subsidiaries to comply with US law, but Canada has no such bilateral agreement with the US. Canadian courts have also explicitly rejected the US third-party doctrine, which diminishes the legal equivalence often assumed between Canadian and American data protections.

Furthermore, Canada’s status under the UKUSA Agreement as part of the Five Eyes intelligence alliance involves extensive cooperation, but with strict legal and procedural safeguards. Canadian law explicitly prohibits CSE from targeting Canadians’ private information, emphasizing territorial jurisdiction and national protections. These legal distinctions challenge the assumption that ‘not American’ automatically equates to better control or sovereignty.

European policymakers and industry players have, in some cases, adopted the proxy of ‘not American’ to evaluate AI providers, but experts argue this is a category error. The adequacy decision granting EU-to-Canada data transfers was assessed under PIPEDA, focusing on commercial data protections, not on broader sovereignty or control issues. Therefore, using nationality as a proxy ignores the nuanced legal and operational realities.

At a glance
analysisWhen: developing; ongoing debate and recent p…
The developmentThe article critically assesses the common misconception that ‘not American’ AI companies are inherently more controlled or secure, highlighting legal and geopolitical nuances.
The Wrong Test — Reality Check
AI Dispatch · Reality Check · 16 July 2026

The wrong test: “not American” is not a sovereignty standard

In one press conference, European sovereignty changed definition — from “incorporated in the EU” to “not incorporated in the US” — and nobody asked whether the second is a test or merely a proxy. It’s a proxy. Proxies fail at the edges. The edges are where procurement lives.

✓ First, what’s true — the Canadian case is stronger than critics allow

The CLOUD Act genuinely doesn’t reach Canadian incorporation. Canada has no CLOUD Act executive agreement — negotiating since March 2022, nothing finalized. And the Supreme Court of Canada (R. v. Spencer, R. v. Bykovets) explicitly rejected the US third-party doctrine. On several dimensions Canada is more protective than the US. This is not a hit piece.

The Five Eyes fact, stated precisely

UKUSA (1946): NSA · GCHQ · CSE · ASD · GCSB. CSE’s oversight is real — ministerial authorization, an independent Intelligence Commissioner (a retired judge) who can block, NSIRA review. Now read the operative restriction:

“CSE is prohibited by law from targeting the private information of Canadians, or any person in Canada.”

The protection is national and territorial. Europeans are neither.

Not an accusation — architecture. It’s structurally why Safe Harbor fell: protections protect the home nationals.

The adequacy gap nobody mentions

Canada has adequacy since 2001/2002 (Decision 2002/2/EC). But its scope is PIPEDA-only — employee data largely excluded; Alberta/BC/Quebec regimes never got adequacy; Quebec’s was withdrawn in 2014.

It was assessed against PIPEDA’s commercial framework — not against Canada’s intelligence laws or Five Eyes participation.

That’s the same hole the CJEU punched through Safe Harbor. In fairness: the Commission did examine public-authority access and found redress “accessible to non-Canadian nationals.” That clause is the best argument Canada has — and NSIRA is largely classified. Unsettled, not resolved.

⚠ The nexus problem — incorporation is not the test

US courts have been clear for 40 years: Bank of Nova Scotia — American courts enforce subpoenas against entities subject to US jurisdiction even where compliance violates foreign law, and fine for refusal. Jurisdiction attaches to presence and activity, not the incorporation certificate. So corporate pledges to “resist” are sincere and legally insufficient. And Canadian exposure creeps through ordinary commercial expansion:

BCE bought Ziply Fiber (US) Aug ’25 TELUS — 1,600+ US staff Shopify — 57% of txns in US; NY principal executive office None changed nationality. All changed nexus. So: what US nexus does Cohere have? Customers · ops · Microsoft partnership · US investors · a likely US listing. Nobody has asked.
The honest hierarchy — three standards, ranked by what they actually protect
✕ A proxy
“Not American”
Fails on nexus, fails on Five Eyes statutory architecture, fails when the ally’s interests diverge — and fails silently, because nobody’s measuring. This is what Europe just adopted.
◐ A test
“EU-incorporated”
SecNumCloud’s 24%/39% cap — narrow, arithmetic, checkable from a shareholder register. Also undeniably protectionist. Both true. What Europe already had — and just stepped back from.
✓ An architecture
Open weights · your keys · air-gappable
Requires trusting no jurisdiction, no ally, no election result, no executive directive. The only posture that survives every question below.
Europe just moved from the second to the first — and called it progress.
✓ The right test — enforceable, auditable control
1Who can compel you, under what standard, with what judicial review?
2Is there redress for a non-national? (US–UK/AU deals create none)
3What’s your nexus — not your incorporation?
4Who holds the keys, and can they be compelled to produce them?
5Can you leave, and how fast? (12–18 months of exit work)
6Can it be air-gapped?
Notice what happens down the list: the questions stop being about jurisdiction and start being about architecture. That’s not an accident — that’s the finding.
The take

The Five Eyes question isn’t “is Canada spying for America” — that’s the tabloid version, it’s unsupported, and it’s a distraction. The real question is duller and more damaging: why is Europe using nationality as a substitute for measurement? Because a proxy is cheap and a test is expensive. “Not American” lets you approve the deal, satisfy the minister, and skip the register, the nexus, the redress. It produces a press release. It does not produce protection. Every sovereignty claim here is a jurisdictional bet — that a legal system, an alliance and a political mood hold for the life of your data. The Canadian bet is genuinely better than the American one. It’s still a bet. The only positions that don’t require one are where you hold the weights and can pull the plug. If the answer is “well, they’re not American” — you haven’t been given a standard. You’ve been given a mood.

Sources: CSE’s own published material (UKUSA, mandate, Intelligence Commissioner, NSIRA, the targeting prohibition); IAPP, CIGI, Dentons, McMillan (Canada’s adequacy scope, PIPEDA limits, Quebec 2014); Barry Appleton, “Whose Law Governs Canadian Data?” (Balsillie Papers/SSRN 2026) & Citizen Lab Feb 2025 (Spencer/Bykovets, stalled CLOUD Act talks, Bank of Nova Scotia, UK’s 20,000+ requests, remedial no-man’s land, BCE/TELUS/Shopify nexus, US NSS & AI Action Plan). Some Five Eyes/GDPR analysis in circulation originates with vendors selling EU-hosted alternatives — read accordingly. Procurement & policy analysis, not an allegation of misconduct. Not legal advice.
thorstenmeyerai.com

Why Relying on Nationality Is a Flawed Measure of Control

This analysis matters because it exposes the oversimplification in current European discussions about AI sovereignty. Relying on ‘not American’ as a control metric risks ignoring the actual legal protections, oversight, and operational safeguards that determine data security and control. Misjudging these factors could lead to misguided policies, affecting international cooperation, data flows, and the strategic positioning of AI firms.

Understanding the real legal distinctions helps policymakers and industry leaders make informed decisions that go beyond superficial proxies, fostering more accurate assessments of sovereignty and control in the AI landscape.

Amazon

Canadian data sovereignty compliance software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Legal and Geopolitical Foundations of Data Control

The US CLOUD Act, enacted in 2018, compels US-based providers and subsidiaries to comply with US law, but Canada has not signed a similar agreement, and its courts have rejected the US third-party doctrine. Canada’s legal protections for data, especially for Canadians, are stronger and more territorially focused than US protections. Canada’s participation in the Five Eyes alliance involves extensive intelligence cooperation, but with strict legal oversight and safeguards, particularly preventing targeting of Canadians.

European data transfer agreements, like the 2001/2002 adequacy decision, assess protections based on specific frameworks like PIPEDA, but these assessments are limited to commercial data and do not account for broader sovereignty or control issues. Recent debates have conflated these legal distinctions with the idea of control, leading to misconceptions about the significance of nationality.

Legal and Operational Uncertainties in Data Sovereignty

While the legal distinctions are clear, the practical implications of these differences in global AI deployment are still evolving. It remains uncertain how European regulators and industry will interpret and apply these nuanced legal facts in future procurement and policy decisions. Additionally, the extent to which ‘not American’ proxies will influence actual control and sovereignty measures is still being tested in ongoing debates and negotiations.

Future Policy and Legal Clarifications on AI Control Measures

European policymakers are expected to refine their definitions and criteria for AI sovereignty, potentially moving beyond simplistic nationality proxies. Canada and other jurisdictions may seek to clarify their legal frameworks and international agreements to better communicate their protections. Meanwhile, legal experts and industry stakeholders will continue to scrutinize the efficacy of proxies like ‘not American’ in accurately measuring control, with the next few years likely seeing more detailed standards and assessments.

Key Questions

Does Canadian law provide better data protections than US law?

Yes, Canadian courts have explicitly rejected the US third-party doctrine, and Canadian law prohibits targeting Canadians’ private information, offering stronger territorial protections.

Why is using ‘not American’ as a control measure problematic?

Because legal protections, oversight, and operational safeguards are complex and cannot be accurately gauged solely by a company’s nationality.

What role does the Five Eyes alliance play in data control?

It involves extensive intelligence cooperation but with legal safeguards that prevent targeting Canadians’ private data, making it different from US data access laws.

Will European policymakers change their approach to AI sovereignty?

Likely, they will develop more nuanced criteria that go beyond proxies like nationality, focusing on legal protections, oversight, and operational safeguards.

Is the Canadian-AI company Cohere more controlled than US firms?

Legally, Canadian-incorporated firms like Cohere are not subject to the US CLOUD Act, but control also depends on operational and legal safeguards beyond mere incorporation.

Source: ThorstenMeyerAI.com

You May Also Like

Amber the programming language compiled to Bash/Ksh/Zsh

Amber is a new programming language that compiles directly to Bash, Ksh, and Zsh scripts, aiming to simplify scripting for Unix shell environments.

Why is Doordash not working? DoorDash down for many Sunday

Many users experienced outages on DoorDash this Sunday, with the platform reporting widespread disruptions. The cause is currently under investigation.

Blockchain Interoperability Solutions Explained

Connecting diverse blockchains, interoperability solutions unlock seamless asset transfers and smarter decentralized applications—discover how they are shaping the future of blockchain connectivity.

Fan Curves 101: The Quiet Performance Tweak Most People Skip

By customizing your fan curves, you can achieve quieter operation and better…