
Adobe stock
In the first two weeks of August, Ottawa did two things that matter. On August 6, Defence Minister David McGuinty stood at the University of Calgary and launched Canada's first Quantum Defence Innovation Secure Hub, a $20.3 million project meant to move quantum sensing, communications and navigation out of the lab and into the hands of the Canadian Armed Forces.
A 13-member consortium led by the university's Quantum City initiative will run it over two years, serving both the CAF and the Communications Security Establishment. And on August 14, the Request for Supply Arrangement for the new Defence Drone Initiative closes its first round, the government's bid to build a domestic pipeline for uncrewed systems across six use cases, from tactical ISR to counter-drone.
Both are the right moves. Both are sold under the same word: sovereign. And both sit on top of a layer that is not sovereign at all.
The harder sovereignty
I say this as someone who spent seven years in the Army and now runs an AI company in Vancouver selling into government. Canada has learned to worry about who builds the airframe, the hull and the rifle. We have not yet learned to worry, with the same intensity, about who controls the data those systems generate and the software that turns that data into a decision. That is the harder sovereignty, and it is the one we are quietly renting.
Where the fight is
Start with where the fight actually is. The war in Ukraine has settled an old argument about drones. The airframe is the cheap, disposable part. A November 2025 Hudson Institute report by Tsiporah Fried found that the real innovation, and the real vulnerability, sits in drone software: communication protocols, navigation and flight-control algorithms need updating roughly every four to six weeks just to stay ahead of jamming and other electromagnetic warfare tactics.
The Royal United Services Institute, in its February 2025 assessment of the third year of the war, reported that 60 to 80 percent of Ukrainian first-person-view drones were failing to reach their targets, which is why both sides are racing toward fibre-optic links and machine-vision guidance to beat electronic warfare in the final metres. A drone you cannot reprogram in weeks is a drone that is already obsolete. The Defence Drone Initiative is correct to prioritize Canadian uncrewed systems. But a Canadian airframe running a foreign autonomy stack, updated on someone else's schedule and someone else's priorities, is a leased capability wearing a maple leaf.
The plumbing underneath
Now look at the plumbing underneath all of it. The Defence Team runs its day-to-day collaboration on Defence 365, which DND itself describes as a Microsoft 365 platform adjusted for the Defence Team.
Research from the Balsillie School of International Affairs, citing the federal government's own figures, reports that more than 80 percent of Canadian cloud services rely on foreign infrastructure. Under the U.S. CLOUD Act, a provider under American jurisdiction can be compelled to produce data regardless of where that data physically sits.
Storing it on Canadian soil does not change who can be ordered to hand it over. Data residency answers where the data lives. Sovereignty answers whose law reaches it, and for the most sensitive defence workloads those are not the same question.
A lesson from the F-35
This is an argument about leverage, not an argument against American technology or our closest ally. And August 2026 is a strange moment to be relaxed about leverage. The F-35 review remains open. The government has kept paying for long-lead items while it studies a fighter fleet it has not fully committed to, precisely because it is no longer comfortable with the dependence the original deal implied. If that discomfort is real for jets, it should be real for the data pipes and the model weights, because those are harder to see and far harder to swap out once they are embedded.
The AI strategy's blind spot
The DND and CAF Artificial Intelligence Strategy commits the Defence Team to being AI-enabled by 2030. That is the right ambition. But AI is only as good as the data underneath it. My company, Caseway, builds form automation and data intelligence for large organizations, and the pattern we see every week is the same one DND's outside reviewers have flagged for years: critical information trapped in forms, PDFs and stovepiped systems that were never built to talk to each other. You cannot bolt trustworthy AI onto fragmented, poorly governed data and expect an advantage. The quantum hub, the drone initiative and the AI strategy all assume a clean, controlled, Canadian-governed data foundation that does not yet exist. Build that foundation and everything else compounds. Skip it and we will have spent billions automating a mess we do not own.
The counterargument
Here is the counterargument, and it is a fair one. Full sovereignty is expensive, slow and sometimes pointless. Duplicating a hyperscaler's infrastructure to run a cafeteria menu is waste, not security. True. The answer is precision, not nationalization.
A narrow set of workloads, meaning the intelligence, targeting, autonomy and command data that would actually hurt us if a foreign court or a foreign vendor reached into them, needs real control across four dimensions: where it lives, who operates it, who holds the encryption keys, and whose law can compel disclosure. Everything else can stay commercial. Sovereignty by design, not sovereignty by slogan.
Three asks
So a concrete ask, aimed at the Defence Investment Agency and DND. First, when the Defence Industrial Strategy names its sovereign capabilities, add a test that runs through all of them: for any capability handling sensitive data, require Canadian-held encryption keys and Canadian legal control, not merely Canadian data residency.
Second, write that test into the Defence Drone Initiative supply arrangement now, while it is being stood up, so the autonomy and data layers are scored the way the airframe is. Third, treat the growing DISH network as the place to prove a Canadian-governed defence data stack, not only Canadian-invented sensors. If a technology is validated in a secure hub but its data leaves Canadian legal control the moment it goes operational, we have proven the wrong thing.
We are finally spending like a country that takes its defence seriously. Let us not discover in 2030 that we bought sovereign hardware and rented the intelligence that makes it dangerous.








