Every enterprise tech vendor has a sovereignty story now. It usually involves a slide with a map of Canada, some flags, and the phrase "your data never leaves the country" — delivered with the energy of someone who has just solved cybersecurity.

They have not solved cybersecurity. They have solved the zip code of the server. This is a real problem worth solving. The CLOUD Act is not fictional, and US-headquartered hyperscalers are not, legally speaking, your allies when a foreign government comes asking questions you'll never be told about.

But nobody mentions what comes after the flag slide. Data can sit on genuinely Canadian soil and still be completely ungoverned. Accessible to anyone with the right credentials, or the wrong ones. Unaudited. Unclassified. Retained indefinitely because nobody wrote a policy. Forwarded freely across an email chain now living in fourteen inboxes you don't control.

Sovereignty without governance is just hiding your mess in a Canadian storage unit instead of an American one. The mess is still there. It just has better weather.


And then there's Copilot.

Microsoft Copilot — and every other AI tool that indexes your environment — has a very simple rule: it sees what the user sees. Which is fine, in theory. In practice, it means that the AI has indexed everything your staff have ever had access to, including the things they probably shouldn't have had access to and the things they definitely shouldn't still have access to after they left.

Your offboarding process runs on tickets and good intentions. Copilot ran on everything the moment it was switched on.

The uncomfortable truth is that AI assistants have a longer memory than most organisations' access reviews. If governance wasn't tight before you deployed Copilot, Copilot is now a very enthusiastic and extremely thorough record of exactly how loose it was. It will helpfully summarise that information for whoever asks.

"Former employee" and "former access" need to be the same moment. In most organisations, they are not. That was always a governance gap. AI just made it load-bearing.


Governance is the part regulators actually care about. Not the map — the audit trail. Who accessed what, from which device, at what time, from where, and what they did with it. The retention policy that exists somewhere other than a SharePoint folder last opened in 2019. The access controls that don't rely on someone remembering to file a ticket.

PIPEDA doesn't ask you to point at a data centre. It asks you to demonstrate control. These are different things, and confusing them is a common and occasionally career-defining mistake.


Sovereignty and governance aren't competing priorities. They're the floor and the walls of the same room. You need both. The floor without walls is a very cold, very auditable slab of concrete — and Copilot is standing on it, taking notes.


Next time someone leads with the Canadian flag slide, ask the second question: who touched the data, when, can you prove it to a privacy commissioner, and what has your AI already told people about it?

If the answer involves the phrase "we'd need to loop in the team" — the flag is decorative.


Originally published by Ross Norrie, founder of SkyeConnex, on LinkedIn.

Published March 18, 2026 · More from the SkyeConnex blog