Skip to content
Cogio
Sovereignty· 10 min read· by Alexandre Sauvageau

CLOUD Act: why a server in Montreal is not always sovereign

The CLOUD Act lets US authorities demand data from an American provider even when it sits in Canada. How to choose genuinely sovereign AI hosting in Quebec.

A server room lit in blue
Photo: Panumas Nikhomkhai, Pexels

What the CLOUD Act actually says

In March 2018 the US Congress passed the Clarifying Lawful Overseas Use of Data Act, better known as the CLOUD Act. The text settles a question American courts had been wrestling with for years: can a US authority require a service provider to hand over data stored abroad? The legislature’s answer is unambiguous. A provider subject to United States jurisdiction must hand over the data in its possession, custody or control, wherever it physically sits.

In practice, an order aimed at a company headquartered in Seattle or Redmond also covers the servers that company runs in Montreal, Toronto or Frankfurt. The provider can challenge the order in certain cases of conflict with a foreign law, but the principle stands: what counts is the owner’s jurisdiction, not the server’s location.

The CLOUD Act also provides for bilateral agreements governing reciprocal access to data between states. The United States has concluded such agreements with the United Kingdom and Australia. As of this writing, there is no such agreement with Canada.

2018

the year the US Congress passed the CLOUD Act

A server in Montreal, an American jurisdiction

Take an SME in Granby that migrates its quotes, its pricing and its client data to the “Montreal region” of a large American cloud provider. Technically, everything is beyond reproach: the data sits in data centres located in Quebec, encrypted and replicated across several sites. Legally, it remains in the hands of a company incorporated under American law, and therefore exposed to the CLOUD Act.

That is the whole distinction between data residency and data sovereignty. Residency answers the question “where are the servers?” Sovereignty answers a more demanding one: “what law applies to whoever controls them?” The Canadian regions of AWS, Azure and Google Cloud offer the first, not the second.

Does that mean these services are off limits? No. For plenty of low-sensitivity uses they remain a reasonable and documentable choice. But for sensitive personal information, industrial secrets or files covered by professional secrecy, the word “sovereign” in a sales deck deserves to be held up against the provider’s ownership structure.

Section 17 of Law 25 against the CLOUD Act

Law 25 (CQLR c. P-39.1) governs the disclosure of personal information outside Quebec. Before such a disclosure, section 17 requires an assessment that considers, among other things, the legal regime applicable in the destination state. The disclosure can only take place if the assessment shows the information would receive adequate protection, and it must be the subject of a written agreement.

And what if the data stays physically in Quebec but with an American-owned provider? The prudent reading is to treat CLOUD Act exposure as a risk to document: in the privacy impact assessment that section 3.3 requires before any project involving a system that processes personal information, then in the processor contract under section 18.3, which has to cover data residency and incident notification timelines. Ignoring that exposure means building a compliance record that would not survive serious scrutiny.

This is no longer theoretical. The Commission d’accès à l’information can impose administrative monetary penalties directly, reaching $10M or 2% of worldwide revenue, and the penal track, before the courts, runs up to $25M or 4%. The CAI’s first penalties were made public in 2026. Our Law 25 compliance guide sets out all the obligations.

$10M or 2%

ceiling on administrative penalties imposed directly by the CAI

Professional secrecy: the bar rises further

For a law firm, a notary’s office, an accounting practice or a clinic, three legal layers stack up. First professional secrecy, protected by codes of ethics: entrusting client files to a third party remains a governed disclosure, and the professional stays responsible for it. Then Law 25 and its section 17. Finally the CLOUD Act, which can compel an American provider to disclose a file, US law even allowing, in certain cases, an order that forbids telling the client.

Lawyers are among the professionals most exposed when it comes to protecting information. A lawyer who pours their files into an AI tool hosted with an American-owned provider should be able to answer a very simple question from their client: who, in the last resort, can be compelled to hand this file over?

The answer runs through the architecture, but also through how internal use is governed. An AI acceptable use policy that forbids putting personal information or client files into unapproved public tools is now the norm in regulated professions.

The real levels of hosting sovereignty

Not all hosting is equal. Here is the hierarchy we use at Cogio to assess an AI infrastructure, from most sovereign to least.

  • On premises: the server is in your building, under your physical and legal control. Nothing leaves the perimeter. This is the maximum level, the one the most sensitive files call for.
  • A Canadian-owned host in Quebec (VEXXHOST in Montreal, PlanetHoster): the data is in Quebec and the owner is subject to Canadian law end to end. High sovereignty, with no capital outlay.
  • A European host established in Quebec (OVHcloud in Beauharnois): the servers are in Quebec, the owner answers to French and European law. Outside American jurisdiction, but outside Canadian jurisdiction too: one notch below the previous tier.
  • An American cloud giant, Canadian region (AWS and Google Cloud in Montreal, Azure in Quebec City and Toronto): Canadian residency, American jurisdiction. Low sovereignty in CLOUD Act terms.

Four AI architectures compared

In the field, the hosting question gets settled at the same time as the AI architecture. We distinguish four, each with its level of sovereignty and its order of cost.

48 GB

of video memory is enough, in our deployments, to serve a quantized 70-billion-parameter open model to an entire firm

The four AI architectures and their level of sovereignty
ArchitecturePrincipleSovereigntyOrder of cost
On premisesA GPU server in your building, self-hosted open modelMaximumInitial investment of $10,000 to $20,000 for a server suited to an SME in our deployments, plus IT operations
Sovereign cloud hostingOpen model and RAG on a GPU rented from a Canadian or European host in QuebecHigh to maximumMonthly running cost of a few hundred to a little over $1,000 depending on the GPU
Contractually governed APILocal data and vectors, queries out to an external API (Claude, Mistral)Low to conditional: requires zero retention, no training and documented jurisdiction, in writingLow initial investment, billed per token
HybridConfidential work handled locally, anonymized queries out to a frontier modelHigh if the partitioning is rigorousIn between: a local GPU, plus tokens on demand

What local cannot do (yet)

Let us be straight, because that is how we work: for some very fine reasoning, such as complex legal analysis or sharp synthesis across dozens of documents, frontier models keep an edge over the best 70-billion-parameter open models. Claiming otherwise would be selling you a disappointment.

That is exactly the dilemma the hybrid architecture resolves. Confidential documents, personal information and trade secrets never leave the local infrastructure, where an open model handles the large majority of queries. For questions that demand cutting-edge reasoning, a sensitivity router redacts and anonymizes the query before sending it to the external API, under a contract guaranteeing zero retention, no training on your data and a documented jurisdiction.

Properly partitioned, this approach combines the confidentiality of local processing for what has to stay with you and the power of frontier models for what can leave once anonymized.

Where to start, depending on your situation

Three questions are enough to place your organization. Where does your data physically sit, and the data your AI tools process? Who is the ultimate owner of each provider, and what law do they answer to? Do those answers appear in your register and in the assessments Law 25 requires?

If even one answer is missing, the next exercise is an inventory: the list of your tools, each provider’s jurisdiction, the sensitivity of the data involved. That is the starting point of our approach, which always begins with an audit before recommending any architecture at all.

And if you practise a regulated profession, do that inventory this week rather than this quarter: professional secrecy cannot be repaired after the fact. To talk it through with us, write to us.

Frequently asked questions

Are the Canadian regions of AWS, Azure or Google Cloud compliant with Law 25?

Law 25 does not prohibit these services. It requires you to document your processing, carry out the required assessments (including the privacy impact assessment under section 3.3) and govern your processors by contract (section 18.3). CLOUD Act exposure has to appear in that analysis: for low-sensitivity data it can be acceptable and documented; for sensitive files or files covered by professional secrecy, it becomes hard to justify.

Does the CLOUD Act apply even if my contract guarantees the data stays in Canada?

Yes. The CLOUD Act targets providers subject to American jurisdiction and covers data in their possession, custody or control, wherever it sits. A Canadian residency clause determines where the servers are, not what law applies to the provider running them.

Is OVHcloud in Beauharnois beyond the reach of the CLOUD Act?

OVHcloud is a French-owned company: it is not automatically subject to American jurisdiction the way AWS, Azure and Google Cloud are. Its Beauharnois servers therefore offer markedly greater sovereignty than an American cloud giant. A Canadian-owned host in Quebec, such as VEXXHOST or PlanetHoster, remains the first choice when you want Canadian law end to end.

Is a locally hosted AI model as capable as the frontier models?

For most business uses, such as document search, summarization and assisted writing, a well-configured 70-billion-parameter open model does the job very well. For some very fine reasoning, frontier models keep an edge. The hybrid architecture answers that dilemma: confidential work stays local and only anonymized queries go out.

What should a law firm already using American cloud tools do?

Start with an inventory: which tools, which data, which jurisdiction for each provider. Then check the applicable ethical obligations and carry out the assessment Law 25 requires for any disclosure of personal information outside Quebec. Depending on how sensitive the files are, migration to a sovereign host or a hybrid architecture can then be planned in stages, without interrupting the practice.

Sources and references

This article is a plain-language summary, accurate as of the date shown. It is not legal advice: for your own situation, consult a legal adviser or contact the Commission d’accès à l’information.