Sovereign AI in Canada: what it means for a smaller manufacturer or distributor
Sovereign AI means that a country or a company controls the AI it relies on: the servers it runs on, the model, the data it reads and which country’s law can reach that data. If you run a smaller manufacturer or distributor, sovereign AI in Canada comes down to two decisions for each kind of data you hold: where it is stored, and where the model that reads it runs. Most federal money for sovereign AI builds data centres and supercomputers, and the programs that help a plant adopt AI are separate. This guide covers both, with each program’s status on September 27, 2026.

What sovereign AI means
The Government of Canada described a sovereign AI system in the priorities for its AI Sovereign Compute Infrastructure Program (SCIP), which funds a large-scale sovereign public AI supercomputer for Canadian researchers and innovators. One priority asks for a “Canadian-located, Canadian-governed system that ensures data residency, operational control, and decision-making authority and agency remain in Canada.” A company can use that priority as a test for its own AI, one layer at a time.
Inference is the step where the model reads your request and writes its answer. The table breaks the test into five questions you can ask about any AI tool. The layers are our reading, and the government did not write them.
| Layer | The question | What decides the answer |
|---|---|---|
| Storage | Where do your files and databases sit when nobody is using them? | The data centre where the provider keeps them. |
| Inference | Where does the model run when it reads a request and writes the answer? | The provider’s region and routing settings for that model. |
| Operation | Who runs the servers, and who can switch the service off? | Whoever operates the system, and your contract with them. |
| Law | Which country’s courts and agencies can order the data handed over? | Who owns and controls each company that holds the data. |
| Exit | Can you take your data and move to another provider? | The export format and the contract terms. |
Even the federal government does not expect to control every layer. The Government of Canada’s Digital Sovereignty Framework says “It is impossible for the GC to obtain a state of complete digital sovereignty,” where GC means the Government of Canada. It asks that the risks be managed “in proportion to operational importance and the potential impact on service continuity and security.” A smaller company can use the same rule and set a level of control for each kind of data, as the section on sizing sovereignty shows.
Sovereign AI, data sovereignty and data residency
A 2018 Government of Canada white paper on data sovereignty and public cloud defines the two older terms. Data residency is “the physical or geographical location of an organization’s digital information.” Data sovereignty, in relation to Canada, is “Canada’s right to control access to and disclosure of its digital information subject only to Canadian laws.”
The paper also says “Data residency does not mitigate against the application of foreign laws.” The newer Digital Sovereignty Framework makes the same point about suppliers: “Using a Canadian supplier or storing data in Canada does not guarantee data will be outside the jurisdiction of foreign courts.” Its examples of laws that let authorities request access to information held by organizations include Canada’s Criminal Code and the US Clarifying Lawful Overseas Use of Data Act (CLOUD Act).
Sovereign AI adds the model to the same question. Data sovereignty asks whose law reaches the stored data. Sovereign AI also asks where the model runs when it reads that data, and who operates it. The Canadian legal picture for a business is in AI governance.
What a sovereign cloud is
A sovereign cloud applies the same idea to cloud computing: the servers and services a country can control under its own law. Canada uses the term in its own plans. Budget 2025 says it “helps Canada build necessary AI compute infrastructure, including the development of a Sovereign Canadian Cloud.” The AI for All strategy, which the Prime Minister launched on June 4, 2026, commits to secure digital systems for government operations, “including sovereign cloud, AI, cyber and quantum initiatives.”
The strategy is direct about where Canada starts. It says “Canadian companies store sensitive data in foreign jurisdictions,” and that “Canada’s sovereign compute capacity is nascent, particularly in cloud.” When a vendor offers you a sovereign cloud, ask which of the five layers in the table above it keeps in Canada.
Canada’s sovereign AI programs and where each one stands
Most federal money for sovereign AI in Canada pays for compute, meaning the data centres and processors that AI runs on. The Canadian Sovereign AI Compute Strategy, which the government launched on December 5, 2024, commits $2 billion over five years from Budget 2024. Up to $1 billion of that goes to public supercomputing, including up to $200 million to add to existing public computing capacity for immediate needs. The table shows the programs with their status on September 27, 2026, taken from each program’s own page where one exists.
| Program | Amount | Who it is for | Status on September 27, 2026 |
|---|---|---|---|
| AI Compute Challenge | Up to $700 million | Companies and consortia, including industry-academic partnerships, building AI compute infrastructure | Open. Applications are accepted on an ongoing basis. |
| AI Sovereign Compute Infrastructure Program (SCIP) | About $890 million over seven fiscal years from 2026-27 | Not-for-profits and post-secondary institutions incorporated in Canada, alone or leading a consortium | Closed on June 1, 2026. |
| AI Compute Access Fund | Up to $300 million | Canadian for-profit companies developing AI products or services, with fewer than 500 full-time equivalent employees | Closed on July 31, 2025. The government announced 44 funded projects, worth $66 million, in May 2026. |
| Compute Access Fund expansion | An additional $700 million | Canadian small and medium-sized enterprises (SMEs) | Announced in AI for All. The fund’s page says it is not accepting applications. |
| Large-scale sovereign AI data centres | No amount on the program page | Data centre projects with more than 100 megawatts of planned capacity | Closed. The call ran from January 15 to February 15, 2026. |
| Budget 2025 sovereign public AI infrastructure | $925.6 million over five years from 2025-26 | Compute capacity for public and private research | Proposed in Budget 2025. The SCIP page says SCIP delivers on investments from Budget 2024 and Budget 2025, so the two amounts may overlap. |
The strategy page, last modified on June 4, 2026, still says SCIP applications are open. The SCIP page says they closed on June 1, 2026, and the table follows the program page. In May 2026, the government announced it was advancing work with TELUS on a proposed large-scale AI data centre in British Columbia under the data centre initiative.
The programs a manufacturer or distributor can use
Judged by their published eligibility rules, none of the compute programs above funds a company that only wants to use AI. The $700 million expansion for SMEs has no published eligibility rules yet. The AI Compute Access Fund, the one that pays part of a company’s own compute costs, requires applicants to “Be a Canadian-registered for-profit company developing AI products or services.” A manufacturer that adopts AI tools for its own work does not fit that description. These adoption programs fit a plant better:
- BDC LIFT. The Business Development Bank of Canada (BDC) launched LIFT on April 24, 2026, with $500 million earmarked to help over 1,000 SMEs adopt AI. Loans range from $25,000 to $5 million. The AI path is for Canadian-based businesses with at least $1 million in annual revenue, and it requires a plan from BDC Advisory Services. BDC offers preferential rates when the technology is provided or integrated by Canadian suppliers.
- RAII in Quebec. Canada Economic Development for Quebec Regions (CED) runs the Regional Artificial Intelligence Initiative (RAII). Its page says it is accepting applications, and the initiative runs until March 31, 2031. SMEs that are ready to adopt AI technologies or solutions are eligible, and support for SMEs is “Interest-free repayable financial support up to 50% of authorized costs.”
- RAII in southern Ontario. FedDev Ontario’s RAII page says “The program is currently not accepting applications.” It notes that AI for All includes $500 million to expand the initiative through Canada’s regional development agencies, and that details on the next intake will be shared once available.
Where AI models run for a Canadian company today
A hosted model runs on the provider’s servers, and your software sends each request to it. An open-weight model is published with its weights, the files that make up the trained model, so you can download it and run it on your own server. On a server in Canada, its inference happens in Canada. Running a local LLM covers what that takes.
For hosted frontier models, meaning the newest and most capable ones, the vendors publish where inference runs. Anthropic’s own API is the connection your software uses to send requests to Claude. Its inference_geo setting takes two values: “global”, the default, and “us”, where “Inference runs only in US-based infrastructure.” Stored data follows a separate workspace setting, and the only choice there is the US: Anthropic says “Currently, ‘us’ is the only available workspace geo.”
AWS groups its data centres into Regions, and two of them are in Canada: Canada (Central) and Calgary. On Amazon Bedrock, AWS’s model cards for Claude Opus 5.5 and Claude Sonnet 5 mark in-Region inference as not supported in both. Requests made there must go through an inference profile, a setting that lets AWS send each request to another Region in a group. The US profile “Keeps data within US and Canada regions,” and the Global profile “Routes worldwide with no residency constraints.” The cards list no Canada-only profile.
AWS calls this cross-Region inference: a request made in one Region is processed in another. In a November 2025 post, AWS said inference processing for requests from Canada (Central) may happen in another Region, while stored data, including logs and the document collections a model searches, stays in Canada (Central). AWS’s data retention guide adds one exception. For models that require human review, currently Claude Fable 5 and Claude Fable 5.1, Bedrock keeps prompts and outputs for up to 30 days, and when cross-Region inference is on, “retained inputs and outputs are stored in destination Regions,” meaning the Region that processed the request.
Zero data retention (ZDR) is an agreement under which the provider does not store your request or its answer once the answer is sent back. It covers only the models and features the provider lists. Anthropic’s retention page says that under ZDR it “does not store customer prompts or responses at rest after the API response is returned.” The same page says Claude Fable 5 and 5.1 and Claude Mythos 5 and 5.1 “require 30-day data retention and are not available under ZDR unless expressly authorized by Anthropic.” On Bedrock, an account set to no retention refuses any model that requires retention. AWS’s data retention guide says Bedrock “will block the request and return an error” when a model requires retention.
For the Claude models on these pages, checked on September 27, 2026, none of the pages offers a setting that keeps inference in Canada. On Amazon Bedrock, a Canadian company can keep stored data in Canada (Central), but the model that reads each request may run outside Canada, and requests that Bedrock retains are stored in the Region that processed them. On Anthropic’s own API, stored data sits in the US. Other providers publish their own tables, and the answer can differ by model and region, so ask for the table that covers the model you will use. An open-weight model on a server in Canada keeps inference in Canada as well.
What hosted models cost per request is in Claude API pricing. ChatGPT alternatives for business in Canada compares where the main business plans store data.
How much sovereignty a smaller company needs
If your company has 20 to 99 employees, it is more likely than the average business to name cybersecurity or privacy concerns as a barrier to its use of AI. In Statistics Canada’s survey for the second quarter of 2026, 22.3% of businesses with 20 to 99 employees named cybersecurity or privacy concerns as a barrier that limits their use of AI, against 13.4% of all businesses.
Sort what you hold before you choose a deployment. The table sorts a typical plant’s data by what sets the rules for it, and the last column is our suggestion.
| Kind of data | Examples | What sets the rules | A deployment that fits |
|---|---|---|---|
| Commercial data | Drawings, routings, costing sheets, quotes and customer lists | Your own judgment of the risk, plus any customer contract terms | Stored in Canada. A hosted model under a written zero data retention agreement, or an open-weight model on your own server for the files you guard most. |
| Personal information | Employee records and customer contacts | PIPEDA, the federal privacy law for businesses, and, for personal information held in Quebec, section 17 of Quebec’s private-sector privacy act | Stored in Canada. For information held in Quebec, a privacy impact assessment (a review of the risks of sending it) before it goes to any server or model outside Quebec. |
| Data under customer terms | Drawings and specifications a customer supplied under contract | The customer’s contract | The level the contract names. If it bars processing outside Canada, an open-weight model on your own server. |
The Office of the Privacy Commissioner’s cross-border guidelines say “PIPEDA does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing.” They add: “No contract can override the criminal, national security or any other laws of the country to which the information has been transferred.” In Quebec, section 17 of the private-sector privacy act says: “Before communicating personal information outside Québec, a person carrying on an enterprise must conduct a privacy impact assessment.” The assessment must weigh how sensitive the information is, what it will be used for, how it will be protected and the law that applies where it goes. The information may be sent if the assessment finds it would be adequately protected, and the transfer must be covered by a written agreement. This page is not legal advice.
A customer contract can set a stricter rule than either law, for example a clause that keeps a customer’s drawings in Canada. Read the data clauses in your largest customers’ contracts before you choose a deployment.
What to ask a vendor who says “sovereign”
Each question maps to a layer in the table at the top of this page. Ask for the answers in writing.
- Which data centre stores our data? Ask for the city and the company that operates it.
- Which region runs inference for each model you offer? Ask for the provider’s own table, such as an AWS model card.
- What is the retention mode, and which model tier does it cover? Some models require retention, so the contract has to name the model.
- Which country’s law governs your parent company and each subprocessor? A subprocessor is another company that handles your data for the vendor. As the federal framework says, a Canadian supplier does not by itself put data beyond the reach of foreign courts.
- How do we export our data and leave? Ask for the format, and ask for a test export before you sign.
- Who controls the logins the system uses? If those accounts sit in your own company directory, such as the user list in your Microsoft 365 account, you can cut the system’s access without the vendor.
If the data includes personal information held in Quebec, also ask for what you need to complete the privacy impact assessment that section 17 requires. The account settings and approval controls to check next are in secure AI at work and AI security, and platform choices are covered in enterprise AI platforms.
Check what a vendor keeps in Canada
Send Derik the AI tools your team uses or is considering. He will tell you which layers each one keeps in Canada and which it does not.
Start a conversationHow ThriveAI helps
ThriveAI is an AI engineering company in Ottawa that builds private AI systems for manufacturers and distributors in Ontario and Quebec, on their own data. Derik Lawlis, the founder, leads every project and stays close to the build.
The platform is designed to keep each client’s data on its own server in Canada. You choose the model that reads it: an open-weight model on that server, or a hosted model under a written zero data retention agreement that names the model and its tier. A hosted model may process requests outside Canada. Nothing is sent or saved in your systems until the person responsible approves it, as described in human in the loop.
The ways to set this up, and what each one protects, are compared in private AI for business. What the system does at each desk in a plant is in AI for manufacturing. ThriveAI also runs hands-on AI training on your own documents. For the company and how a project runs, see About ThriveAI.