AI for All, Security for Whom? Reading the Fault Lines in Canada’s National AI Strategy

Published On: September 2026Categories: 2026 Editorial Series, Canada's New AI Strategy, Editorials

Author(s):

Tae Yeon Eom

EOM, Tae Yeon_Headshot – Tae Yeon Eom
Disclaimer: The French version of this text has been auto-translated and has not been approved by the author.

Canada’s newly released National Artificial Intelligence Strategy, AI for All, speaks the vocabulary of a security document while carrying the architecture of an industrial one. Trust, sovereignty, and protection appear on nearly every page. Six pillars promise to shield Canadians from AI’s risks while multi-billion-dollar commitments flow toward compute, talent, and Canadian champions. The strategy will undoubtedly accelerate adoption and grow the domestic AI sector. A harder question remains. Does the document treat security as a designed capability, or does it borrow the vocabulary of security to justify an economic growth plan?

Read closely, against a technology-security fusion standard, AI for All is an accomplished industrial strategy still assembling its security architecture.

The Fragmentation of Security Architecture

The strategy’s six pillars scatter security functions across nearly every section instead of anchoring them in one coherent structure. Pillar 1 folds consumer privacy, online safety, deepfakes, and algorithmic bias together with a single line noting that AI protections extend to “the digital systems on which government services, critical infrastructure, and national security depend.” That sentence carries enormous weight for the modest institutional apparatus behind it: a $50-million expansion of the Canadian AI Safety Institute, watermarking research, and a certification program aimed chiefly at consumer trust. Pillar 4 handles sovereignty as infrastructure. Pillar 6 handles alliances as trade diplomacy. The document names no single coordinating function responsible for AI-related national security across these domains. The strategy opens by warning of “profound strategic risk” and a shifting balance of economic and political power. Measured against that framing, the absence of a unified security architecture is the document’s most consequential silence.

Sovereignty’s unresolved double meaning

AI for All uses “sovereignty” to mean two different things without distinguishing between them. In its economic register, sovereign compute is a magnet for capital, intellectual property, and talent, and the “build-partner-buy” approach welcomes continued foreign investment from hyperscalers where it benefits Canadians. In its protective register, sovereignty means insulating Canadian data and infrastructure from decisions, rules, and legal regimes beyond Canada’s direct control. The strategy never reconciles these competing objectives. Nor does the document distinguish allied foreign dependency, on the United States, Germany, or other Sovereign Technology Alliance partners, from adversarial foreign dependency. Dependency on a treaty ally and dependency on a strategic competitor are not equivalent risks, yet the strategy’s language of “foreign jurisdiction” and “foreign platforms” treats them as a single undifferentiated exposure.

One sentence carrying Canada’s defence-AI posture

Perhaps the clearest textual signal of an unfinished security architecture is how little the strategy says about military and defence applications of AI. In a document running to six pillars and dozens of listed actions, the connection to defence appears in one sentence, appended almost as an afterthought to the priority-sectors section on manufacturing and robotics: sector investment will also prioritize dual-use applications consistent with protection, sovereignty, and security objectives under the recently released Defence Industrial Strategy. AI-enabled ISR (Intelligence, Surveillance, and Reconnaissance systems), autonomous systems, electronic warfare, and defence decision-support go unmentioned. Allied strategies in Washington, London, Canberra, and Tokyo treat these domains as a core pillar of national AI policy. Canada may keep defence-specific AI planning in classified channels deliberately, but a strategy that invokes the language of geopolitical competition cannot avoid the question of military AI entirely without leaving allies and rivals to guess at Canadian intent.

The Indo-Pacific subtext

A closely related silence involves geography. The strategy’s alliance language leans heavily toward the Indo-Pacific: a trilateral technology partnership forming with Australia and India, cooperation with Australia’s AI Safety Institute, and expanded semiconductor and robotics ties with Japan through a modernized Joint Economic Committee. None of this is accidental. It mirrors the priorities Canada set out in its 2022 Indo-Pacific Strategy: diversifying supply chains and strengthening security ties with regional democracies. The AI strategy never names that document, and it never names China. Read together, the two texts suggest AI for All functions as an implementation layer for a geopolitical posture Canada has already declared elsewhere, a convergence left implicit rather than spelled out.

Alliances built for markets first

The strategy’s most genuinely novel security-adjacent move is the Sovereign Technology Alliance with Germany, alongside a widening web of partnerships with the UK, France, Australia, India, and Japan. Eleven of twenty new economic and defence partnerships reportedly touch AI cooperation, described almost entirely in the vocabulary of market access, shared compute, and common standards, aimed at resilience and choice against dominant hyperscalers. Collective threat assessment and information-sharing on AI-enabled attacks receive no comparable treatment. That may suit a country that prefers quiet coordination to public confrontation, but the choice still leaves the security content of Canada’s AI alliances implicit rather than declared.

The missing piece: crisis governance

Finally, the strategy is rich in prevention: safety evaluations, transparency, watermarking, cyber-defence research partnerships. It is largely silent on response. No named framework addresses what happens when an AI system is implicated in a major incident, whether a poisoned model embedded in critical infrastructure, a coordinated disinformation operation during an election, or an AI-accelerated attack on financial markets. Trust-building and crisis governance are different disciplines, and a mature technology-security strategy needs both.

The democratic paradox

One further tension deserves attention. Pillar 1 grounds itself in protecting democracy through modernized privacy law, deepfake countermeasures, election safeguards, and a certification regime for trustworthy AI products. Each of these measures also requires more monitoring capacity: tracking AI-generated content, evaluating models, watermarking outputs, flagging synthetic media at scale. Security-driven AI governance and expanded state visibility into information flows tend to grow together, a tension the strategy does not confront. A document that protects democracy through new instruments of monitoring and classification needs an explicit answer for how those instruments stay bounded, or the tools built to defend open societies against AI-enabled manipulation risk narrowing the openness they were built to protect.

What the next iteration should do

AI for All succeeds as what it fundamentally is: a well-financed adoption and industrial strategy that borrows the language of trust and sovereignty to justify public investment. That borrowing is politically astute, and defensible, since economic strength is itself a component of national security. The strategy commits to “clear-eyed agility” as circumstances evolve. Five additions would meaningfully close the gap between its security vocabulary and a genuine technology-security fusion: a named cross-pillar security coordination function; an explicit distinction between allied and adversarial foreign dependency in its sovereignty language; a defence-AI component connected openly to the Defence Industrial Strategy; an acknowledged link to the objectives already set out in the Indo-Pacific Strategy; and a national incident-response framework for AI-enabled crises, paired with clear limits on the surveillance capacity its own trust-building measures create. Canada has the research base, the alliances, and now the capital commitments to lead. What remains is to build security as an explicit, coordinated capability, matched to the ambition already given to compute, talent, and capital.

More on the Author(s)

Tae Yeon Eom

Asia Pacific Foundation of Canada

Project Manager and Researcher

The University of Texas at Austin

M.S. Candidate in Artificial Intelligence