Who Actually Decides? The Sovereignty Test “AI for All” Must Pass
Author(s):
Keyvan Maleki

Disclaimer: The French version of this text has been auto-translated and has not been approved by the author.
Two Canadian policy debates unfolding this summer look unrelated. Underneath, they are the same debate — and together they present the hardest test Canada’s new National AI Strategy wil face.
The first is about water. Bill C-37, the proposed First Nations Clean Water Act, promises to affirm First Nations’ inherent jurisdiction over water on their lands, backed by enforceable standards and a $4.6-billion investment. Yet provinces still issue the licences that decide what actually happens to that water. In northern Alberta, Sturgeon Lake Cree Nation is in court challenging a provincial licence connected to Wonder Valley — one of the largest AI data centres ever proposed in Canada, expected by the company’s own estimate to draw six billion litres of water a year from the Nation’s traditional territory, after Alberta waived the requirement for an environmental impact assessment. Meanwhile, in northern Ontario, Neskantaga First Nation marks its thirty-first year under a boil-water advisory. As Sturgeon Lake Chief Sheldon Sunshine told Windspeaker: “Human beings need water. Data centres should not be taking it from our own mouths.”
The second debate is about data. A recent Community Circle analysis, The Privacy Paradox, traces two decades of European digital sovereignty efforts to a sobering conclusion. Europe built world-class privacy technology — differential privacy, homomorphic encryption, “sovereign cloud” offerings with EU-resident operators — and still handed the real decisions to foreign platforms. The analysis recounts how European cryptographers designed their own privacy-preserving contact-tracing protocol in 2020, only to find a California platform’s specifications deciding what privacy meant for hundreds of millions of Europeans. Even today’s most advanced sovereign cloud remains a wholly owned subsidiary of its American parent, with source code access reserved for undefined “exceptional circumstances.”
Water licensing and cloud jurisdiction are institutionally different problems, and the analogy has its limits. But they share one load-bearing feature: recognition without control is not sovereignty. Technical sophistication without decision-making authority produces only a more sophisticated dependence. The question that matters — for water and for data — is the same: who actually decides, whose interests prevail, and whether communities retain control when control is costly.
Canada is about to answer that question in both arenas at once. In June it released AI for All, a strategy whose six pillars are anchored explicitly in trust, opportunity and sovereignty — and the arenas are literally connected in Wonder Valley’s case, where the physical substrate of
Canada’s AI ambitions is contested on First Nations territory. There is no clearer image of the stakes: sovereign compute built on contested water is not sovereignty; it is the old deployment pattern wearing new language.
The oldest expertise in the newest problem
AI for All opens with an honest admission: the country that helped invent modern AI is losing the adoption race, with roughly 12 per cent of businesses using AI against a target of 60 per cent by 2034. The strategy treats this adoption gap as a new national challenge. It is not new. It is the deployment-frontier problem that rural and Indigenous communities have lived for generations.
“Rural” was never really about geography. It is the condition of being downstream of a rollout you did not design and cannot control — the far side of every “available in select markets.” For most of urban Canada that condition is temporary; the economics eventually close — though in marginalized urban neighbourhoods, thin incomes and thinner institutional trust keep it away even when the fibre runs down the street. For rural and Indigenous Canada the condition is structural — innovation’s cost models reward homogeneity, per-region variation defeats them, and the frontier never arrives on its own. AI has now put the whole country in that seat. Capability is advancing faster than any organization can absorb it, so a Fortune 500 firm, a federal department and a household are suddenly asking the questions remote communities have always asked: Can we trust it? Can we own it? Can we govern it? Does it fit how we actually work and what we value?
Enterprise AI research is independently rediscovering the answers. Pilots stall in “pilot purgatory” unless designed to earn the right to operate indefinitely. Failures live in the seams — ownership, decision rights, accountability — not inside the technology. Trust, built before the work rather than after, is what unlocks scale. Practitioners who spent two decades lifting long-term drinking-water advisories in First Nations communities learned this the hard way and distilled it into a simple test: a solution succeeds only when the community can build it, own it and stand behind it — not when the technology is merely delivered. That standard, and the consent-not-consultation principle First Nations leaders are now demanding of Bill C-37, is exactly the standard AI for All should be held to.

Members of Tl’azt’en Nation remove the boil-water advisory sign at Middle River, B.C., after the community’s long-term advisory was lifted. The sign reads “Issued by: Tl’azt’en Nation” — the community that declared the advisory is the community that ended it. [Photo credit Community Circle]
Applying the sovereignty test to the six pillars
On trust and empowerment (Pillars 1 and 2), literacy programs and safety institutes treat Canadians as recipients of AI. The European lesson: protection without authority is insufficient. The core question is not whether data is private but who decides how it is used, and whether those decisions are auditable and enforceable. The strategy’s commitments to Indigenous AI leadership must mean OCAP-grounded data governance and auditable provenance embedded in technical architectures from the start — not consultation after the licence has already been issued — the very pattern Bill C-37’s critics describe.
On adoption (Pillar 3), the 60 per cent target will be hollow if success is counted in deployments. Europe’s sovereign cloud shows how deployment metrics flatter dependence. Success should be measured by community control and sustained outcomes : systems that are still running, governed and defended by their owners years later.
On sovereignty (Pillars 4 through 6), sovereign compute is the visible half; the invisible half is decision rights over the infrastructure’s full footprint — its land, energy and water. If nation- building projects rely on platforms whose ultimate control sits offshore, or on resources extracted without consent from the territories they occupy, the strategy will have reproduced the deployment frontier under a maple leaf. The constructive alternative: community- controlled, sector-specific data spaces — starting with water, where need is urgent and tied to treaty rights — interconnecting voluntarily, governed locally, with hyperscalers admitted only under legally binding, verifiable frameworks.
None of this is free. Hyperscalers dominate because they offer real advantages — cost, reliability, scarce expertise — and community-controlled alternatives demand investment, capacity and patience. A community in year thirty-one of a boil-water advisory may reasonably prefer infrastructure that works over infrastructure that is sovereign. But for multi-generational infrastructure, Europe’s experience warns, short-term convenience compounds into long-term dependence — and Canada is choosing now.
The playbook already exists
AI for All deserves credit for naming trust as its north star and sovereignty as a pillar. But Neskantaga’s thirty-one years under a boil-water advisory, five prime ministers deep, is a standing reminder of the distance between recognition and reality. The communities on the far side of Canada’s deployment frontier are not the cautionary tale in the AI story, nor a population the strategy must simply remember to include. They hold the country’s hardest-won expertise in the very problem the strategy exists to solve — and they are asking the one question that will determine whether AI for All lives up to its name: who actually decides?
Disclosure: The author is a co-author of The Privacy Paradox, written with Bettina Tratz-Ryan (Gartner) and published by Community Circle.
Acknowledgment: AI tools were used to assist with editing this editorial. All content was reviewed, verified and approved by the author.

