The Data Brew Podcast
Data & AI: What About Sovereignty?
John Galbraith and Brock Rowlands, co-founders of Evermore AI, join Telmo Silva for a grounded conversation about what data sovereignty really means in the age of AI. From the legal implications of the US Cloud Act to the practical steps businesses can take today, this episode cuts through the noise and brings the conversation back to what actually matters: knowing your data, owning it, and building a strategy around it. Recorded as geopolitical tensions reshape the relationship between businesses and big tech, this is a timely discussion for any organization in Canada or Europe navigating AI adoption.
Questions We Asked
- Is data stored in Canada or Europe truly sovereign, or does it depend on who owns the infrastructure?
- Do Canadian and European businesses have a realistic path to AI independence from US hyperscalers?
- What should companies actually prioritize today: AI strategy, data strategy, or infrastructure?
What We Learned
- Data residency is not data sovereignty. The 2018 US Cloud Act means that if a US company controls your infrastructure, your data is accessible regardless of where it physically lives.
- AI is 20% AI and 80% data. Any AI project that skips data unification is building on sand.
- SaaS is a cost. Building your own data strategy is an investment that shows up on your balance sheet and compounds over time.
- Perfect is the enemy of good. Every company should be experimenting with AI now, because if you hadn’t started, you wouldn’t know anything.
Data Residency vs. Data Sovereignty: A Distinction That Now Has Legal Consequences
For a long time, data residency and data sovereignty were treated as the same thing. John Galbraith explains why that is no longer the case. The 2018 US Cloud Act established that if a US-owned corporation controls your data center, it does not matter where the servers are physically located. The White House can request the data, and companies like Microsoft have confirmed on record that they would comply, whether the data sits in an Azure center in France or anywhere else.
This distinction has real consequences for businesses in Canada and Europe that assumed local storage was enough. The real question is not where the data lives, but who controls the company that holds it.
The Infrastructure Gap: Can Canada and Europe Compete?
Telmo raises a question that does not have a comfortable answer: can a region be sovereign if it does not control the chips, the undersea cables, or the hyperscale infrastructure that AI runs on? Neither Canada nor Europe currently manufactures competitive AI chips or owns the dominant cloud platforms. Research hubs exist in Montreal, Toronto, and across Europe, but that knowledge is rarely productized locally. It either migrates to the US or gets acquired.
Brock notes that Canada’s response so far has been to wait and see, aligning with whatever framework the EU develops rather than leading with its own. The regulatory gap is real, and for most businesses, the status quo feels safe enough until something goes wrong.
Small Language Models and the Case for Local AI
John argues that running every query through 120 billion parameters is wildly inefficient, and that the future points toward small, specialized language models that can run locally on existing hardware. The shift mirrors something from the early internet era: distributed computing power, leveraging the infrastructure businesses have already invested in, rather than routing everything through a distant data center.
This has practical implications. A company does not need a 30 billion parameter model to answer its operational questions. A smaller, purpose-built model running on a local server may be sufficient, more private, and far less expensive to run.
Open Source vs. SaaS: Investment vs. Spending
The choice between open source and SaaS is not just a technical one, it is a financial and strategic one. Brock breaks it down clearly: with SaaS, you are paying per user, per month, forever, often across multiple overlapping licenses. With open source, you pay infrastructure costs, but you are building something that belongs to you.
A trained workforce and a proprietary data strategy appear on your balance sheet. A SaaS subscription does not. The advice is not to rip out the entire stack overnight, but to start making deliberate choices: own your data, control your pipelines, and use the business value you unlock to fund the next step.
Your relationships are data driven, your processes are data driven, your results are data driven. And it all comes down to how you take that information as a competitive advantage and turn it into revenue.
Brock Rowlands, Co-founder, Evermore AI
Regulation: Europe Leads, Canada Watches
GDPR has become the de facto global standard for data privacy, even in countries that have not formally adopted it. Canadian companies operating internationally have largely absorbed GDPR as a fact of life. On the AI regulation side, Canada is taking a wait-and-see approach, likely to adopt whatever framework the EU establishes rather than pioneering its own.
In the meantime, industry-level frameworks like NIST in the US are crossing into Canada through defense supply chains. One example from the episode: a Canadian manufacturer asked their legal team whether they could process controlled goods data through GPT endpoints. The answer came back the same day: no.
Data Unification Before AI: The Only Strategy That Holds
John’s closing thought reframes the entire AI conversation. Every AI project he has run has been 80% data and 20% AI. The goal is not to point an AI model at 16 different SaaS tools. It is to unify all of those sources into a single, coherent view of the business, and then attach the AI to that.
Data sovereignty, in this light, is not about compliance. It is about controlling your own roadmap. If a vendor shuts down tomorrow, you are fine. You are not beholden to someone else’s product decisions. You own your digital destiny.
AI is really a Trojan horse so that we can talk about your data. Any AI project we’ve conducted has been 20% AI and 80% data.
John Galbraith, Co-founder, Evermore AI
Telmo draws a direct line to what ClicData was built to do: unify data in one place. The layer on top, whether it is BI dashboards or AI, matters less than the foundation. Data visualization is the easy part. PowerPoint can do it. Excel has been doing it for 30 years. The hard part, and where 60 to 70% of the time actually goes, is getting the data to talk to each other, cleaning it, and making it trustworthy enough to act on.
