The Wrong Test: “Not American” Is Not A Sovereignty Standard

📊 Full opportunity report: The Wrong Test: “Not American” Is Not A Sovereignty Standard on ThorstenMeyerAI.com — validation score, market gap, and execution plan.

TL;DR

European authorities have implicitly shifted their sovereignty assessment from ‘incorporated in the EU’ to ‘not American,’ but this proxy is flawed. Canadian law and data protections challenge this simplified view, raising questions about measurement and actual sovereignty.

European authorities have effectively redefined sovereignty by adopting a standard that equates ‘not American’ with sovereignty, a move that has significant implications for international data governance and procurement. This shift, while seemingly straightforward, is based on a proxy that overlooks complex legal distinctions, especially regarding Canadian data laws and jurisdictional protections.

Recent European policy statements and procurement practices suggest a move away from assessing sovereignty solely based on geographic or legal incorporation within the EU. Instead, the focus has shifted to whether a company is American, under the assumption that US jurisdiction, exemplified by laws like the CLOUD Act, compromises data sovereignty. Canada’s legal framework complicates this narrative: Canadian law explicitly protects data of its own citizens and does not fall under the reach of the CLOUD Act, as Canada has not signed a bilateral executive agreement with the US. Canadian courts have also rejected the US third-party doctrine, strengthening data protections for Canadians.

Despite this, European policymakers and buyers often treat ‘not American’ as a proxy for sovereignty, which the analysis suggests is a flawed shortcut. The Canadian case demonstrates that jurisdictional sovereignty involves nuanced legal protections, oversight mechanisms, and international agreements that cannot be reduced to simple nationality markers. The recent European adequacy decisions for Canada, reaffirmed in January 2024, are based on PIPEDA’s commercial data protections, but these do not cover all data types or provincial laws, raising questions about the adequacy’s scope and reliability.

At a glance
reportWhen: developing; recent European policy shif…
The developmentEuropean policymakers have adopted a new standard equating ‘not American’ with sovereignty, but legal and jurisdictional nuances reveal this is a proxy, not an actual measure.
The Wrong Test — Reality Check
AI Dispatch · Reality Check · 16 July 2026

The wrong test: “not American” is not a sovereignty standard

In one press conference, European sovereignty changed definition — from “incorporated in the EU” to “not incorporated in the US” — and nobody asked whether the second is a test or merely a proxy. It’s a proxy. Proxies fail at the edges. The edges are where procurement lives.

✓ First, what’s true — the Canadian case is stronger than critics allow

The CLOUD Act genuinely doesn’t reach Canadian incorporation. Canada has no CLOUD Act executive agreement — negotiating since March 2022, nothing finalized. And the Supreme Court of Canada (R. v. Spencer, R. v. Bykovets) explicitly rejected the US third-party doctrine. On several dimensions Canada is more protective than the US. This is not a hit piece.

The Five Eyes fact, stated precisely

UKUSA (1946): NSA · GCHQ · CSE · ASD · GCSB. CSE’s oversight is real — ministerial authorization, an independent Intelligence Commissioner (a retired judge) who can block, NSIRA review. Now read the operative restriction:

“CSE is prohibited by law from targeting the private information of Canadians, or any person in Canada.”

The protection is national and territorial. Europeans are neither.

Not an accusation — architecture. It’s structurally why Safe Harbor fell: protections protect the home nationals.

The adequacy gap nobody mentions

Canada has adequacy since 2001/2002 (Decision 2002/2/EC). But its scope is PIPEDA-only — employee data largely excluded; Alberta/BC/Quebec regimes never got adequacy; Quebec’s was withdrawn in 2014.

It was assessed against PIPEDA’s commercial framework — not against Canada’s intelligence laws or Five Eyes participation.

That’s the same hole the CJEU punched through Safe Harbor. In fairness: the Commission did examine public-authority access and found redress “accessible to non-Canadian nationals.” That clause is the best argument Canada has — and NSIRA is largely classified. Unsettled, not resolved.

⚠ The nexus problem — incorporation is not the test

US courts have been clear for 40 years: Bank of Nova Scotia — American courts enforce subpoenas against entities subject to US jurisdiction even where compliance violates foreign law, and fine for refusal. Jurisdiction attaches to presence and activity, not the incorporation certificate. So corporate pledges to “resist” are sincere and legally insufficient. And Canadian exposure creeps through ordinary commercial expansion:

BCE bought Ziply Fiber (US) Aug ’25 TELUS — 1,600+ US staff Shopify — 57% of txns in US; NY principal executive office None changed nationality. All changed nexus. So: what US nexus does Cohere have? Customers · ops · Microsoft partnership · US investors · a likely US listing. Nobody has asked.
The honest hierarchy — three standards, ranked by what they actually protect
✕ A proxy
“Not American”
Fails on nexus, fails on Five Eyes statutory architecture, fails when the ally’s interests diverge — and fails silently, because nobody’s measuring. This is what Europe just adopted.
◐ A test
“EU-incorporated”
SecNumCloud’s 24%/39% cap — narrow, arithmetic, checkable from a shareholder register. Also undeniably protectionist. Both true. What Europe already had — and just stepped back from.
✓ An architecture
Open weights · your keys · air-gappable
Requires trusting no jurisdiction, no ally, no election result, no executive directive. The only posture that survives every question below.
Europe just moved from the second to the first — and called it progress.
✓ The right test — enforceable, auditable control
1Who can compel you, under what standard, with what judicial review?
2Is there redress for a non-national? (US–UK/AU deals create none)
3What’s your nexus — not your incorporation?
4Who holds the keys, and can they be compelled to produce them?
5Can you leave, and how fast? (12–18 months of exit work)
6Can it be air-gapped?
Notice what happens down the list: the questions stop being about jurisdiction and start being about architecture. That’s not an accident — that’s the finding.
The take

The Five Eyes question isn’t “is Canada spying for America” — that’s the tabloid version, it’s unsupported, and it’s a distraction. The real question is duller and more damaging: why is Europe using nationality as a substitute for measurement? Because a proxy is cheap and a test is expensive. “Not American” lets you approve the deal, satisfy the minister, and skip the register, the nexus, the redress. It produces a press release. It does not produce protection. Every sovereignty claim here is a jurisdictional bet — that a legal system, an alliance and a political mood hold for the life of your data. The Canadian bet is genuinely better than the American one. It’s still a bet. The only positions that don’t require one are where you hold the weights and can pull the plug. If the answer is “well, they’re not American” — you haven’t been given a standard. You’ve been given a mood.

Sources: CSE’s own published material (UKUSA, mandate, Intelligence Commissioner, NSIRA, the targeting prohibition); IAPP, CIGI, Dentons, McMillan (Canada’s adequacy scope, PIPEDA limits, Quebec 2014); Barry Appleton, “Whose Law Governs Canadian Data?” (Balsillie Papers/SSRN 2026) & Citizen Lab Feb 2025 (Spencer/Bykovets, stalled CLOUD Act talks, Bank of Nova Scotia, UK’s 20,000+ requests, remedial no-man’s land, BCE/TELUS/Shopify nexus, US NSS & AI Action Plan). Some Five Eyes/GDPR analysis in circulation originates with vendors selling EU-hosted alternatives — read accordingly. Procurement & policy analysis, not an allegation of misconduct. Not legal advice.
thorstenmeyerai.com

Implications of Using ‘Not American’ as a Sovereignty Proxy

This shift impacts how European entities evaluate foreign technology providers and data sovereignty. Relying on the ‘not American’ proxy risks oversimplification, potentially leading to procurement decisions based on incomplete or misleading assumptions about jurisdictional protections. It also raises broader questions about the effectiveness of sovereignty measures when proxies are used instead of direct legal assessments. For Canadian providers, this means their legal protections may be misunderstood or undervalued in European markets, despite being stronger than the simplified proxy suggests.

Non-Deterministic Software Engineering: How to Build Reliable Software with AI Assistants Without Losing Quality, Security, or Control

Non-Deterministic Software Engineering: How to Build Reliable Software with AI Assistants Without Losing Quality, Security, or Control

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Legal and Jurisdictional Foundations of Data Sovereignty

The concept of sovereignty in digital data has traditionally hinged on jurisdictional sovereignty—whether a country’s laws and courts can enforce protections over data within its borders. The CLOUD Act exemplifies how US law extends influence over data held by US-incorporated providers, but Canada’s legal architecture offers stronger protections for its citizens’ data, explicitly prohibiting targeting Canadians and requiring oversight for intelligence disclosures. Canada’s long-standing status under the EU’s adequacy decision, reaffirmed in January 2024, reflects recognition of its legal protections, but these are limited to specific data types and entities.

European policymakers have historically viewed US jurisdiction as a threat to sovereignty, leading to the adoption of the ‘not American’ proxy. However, the Canadian legal framework demonstrates that sovereignty is more complex, involving oversight, legal protections, and international agreements that are not reducible to simple nationality markers. The recent policy shift suggests a broader redefinition of sovereignty, but the underlying legal realities remain nuanced and contested.

“Canada remains an adequate jurisdiction for data transfers under EU law, reaffirmed in January 2024.”

— European Commission

Makita XMT04ZB 18V LXT® Lithium-Ion Sub-Compact Brushless Cordless StarlockMax® Multi-Tool, Tool Only

Makita XMT04ZB 18V LXT® Lithium-Ion Sub-Compact Brushless Cordless StarlockMax® Multi-Tool, Tool Only

Makita-built brushless motor with variable speed control dial (10,000-20,000 OPM) enables user to match the speed to the…

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Legal and Practical Limits of the ‘Not American’ Proxy

It remains unclear how European policymakers will reconcile the proxy with the legal realities of jurisdictions like Canada, especially as procurement and data transfer practices evolve. The adequacy decision covers certain data types and entities but does not fully address provincial laws or all data categories, raising questions about the proxy’s reliability and future revisions.

Managing Global AI Compliance Risk: 7 High-Stakes Challenges in Data, Privacy, and Regulation

Managing Global AI Compliance Risk: 7 High-Stakes Challenges in Data, Privacy, and Regulation

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Potential Revisions to Sovereignty Assessments and Policies

European authorities may refine their sovereignty assessment criteria, moving beyond proxies to more direct legal and jurisdictional evaluations. Ongoing negotiations and legal challenges could influence future adequacy decisions, and Canadian providers may need to clarify their legal protections to European buyers. Additionally, the debate highlights the need for clearer standards and measurement tools to assess sovereignty in digital data governance.

Minimum Viable Privacy Compliance: Step-by-Step Instructions for Small to Medium Businesses with a Global Reach

Minimum Viable Privacy Compliance: Step-by-Step Instructions for Small to Medium Businesses with a Global Reach

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

Why does Europe rely on ‘not American’ as a sovereignty marker?

Europe has historically viewed US jurisdiction, especially laws like the CLOUD Act, as a threat to sovereignty, leading to the use of nationality proxies to assess legal protections.

Is Canadian law weaker or stronger than US law regarding data protections?

Canadian law is generally stronger in protecting Canadians’ data, explicitly prohibiting targeting Canadians and requiring oversight for intelligence disclosures, and has explicitly rejected the US third-party doctrine.

What are the limitations of the EU’s adequacy decision for Canada?

The adequacy decision primarily covers commercial data under PIPEDA and does not extend to all data types or provincial laws, such as those in Quebec, Alberta, and British Columbia.

Could the ‘not American’ proxy lead to misjudging data sovereignty?

Yes, relying solely on nationality as a proxy ignores complex legal protections and oversight mechanisms, potentially misrepresenting actual sovereignty and data security levels.

Source: ThorstenMeyerAI.com

You May Also Like

Pesticide-residue Compliance Monitor For Food Importers

A new compliance monitoring tool helps food importers track pesticide residues across suppliers, ensuring adherence to evolving MRL standards.

Apple greift nach China-Speicher. Europa hat nicht einmal diese Option.

Apple plant, Speicherchips vom chinesischen Hersteller CXMT zu kaufen, während Europa keine eigenen Alternativen hat. Das zeigt die Abhängigkeit Europas.

Wikipedia Escapes Category 1 Designation Under The UK Online Safety Act For Now

Wikipedia has temporarily avoided being classified as Category 1 under the UK Online Safety Act, pending further review. The development impacts content moderation obligations.

Reevaluating August 2: AI’s Actual Achievements

A detailed analysis of the EU AI Act’s revised timelines, what obligations remain, and what has actually changed since the initial August 2, 2026 deadline.