The Problem With Using 'Not American' As An AI Standard

📊 Full opportunity report: The Problem With Using 'Not American' As An AI Standard on ThorstenMeyerAI.com — validation score, market gap, and execution plan.

TL;DR

European authorities have shifted their AI data standards to focus on ‘not American’ companies, but this proxy is flawed. Canada’s legal protections and international agreements complicate this approach, raising questions about the effectiveness of such a standard.

European policymakers are increasingly adopting ‘not American’ as a key criterion for AI procurement and regulation, but this approach relies on a simplified proxy that ignores complex legal and jurisdictional realities. This shift matters because it influences international AI supply chains and regulatory standards, especially for companies outside the US.

Recent European policy statements and procurement practices have emphasized the importance of avoiding US-based AI providers, citing legal protections and sovereignty concerns. However, this reliance on nationality as a measurement is problematic because it oversimplifies the legal landscape. Canada, a key partner in AI development, is legally distinct from the US, as Canadian data protections and international agreements differ significantly. Canada is not subject to the US CLOUD Act, and its courts have rejected the US third-party doctrine, making US data access less straightforward than some European policymakers assume.

Canada’s legal architecture, reinforced by a 2001/2002 adequacy decision from the European Commission, provides protections for data transferred from the EU. Nonetheless, this adequacy is limited in scope, primarily covering commercial data and excluding sensitive or employee data, especially in provinces like Quebec, Alberta, and British Columbia. Moreover, the adequacy assessment was based on Canada’s data protection laws, which differ substantially from European standards.

European authorities’ focus on ‘not American’ as a proxy risks ignoring these nuances, potentially leading to ineffective or legally questionable procurement decisions. The shift reflects a broader move toward sovereignty in digital and AI regulation but may overlook the complex realities of jurisdictional protections and international agreements.

At a glance
analysisWhen: developing; recent European policy shif…
The developmentEuropean policymakers are increasingly relying on ‘not American’ as a criterion for AI vendor selection, but this proxy faces significant legal and practical limitations, especially regarding Canadian companies.
The Wrong Test — Reality Check
AI Dispatch · Reality Check · 16 July 2026

The wrong test: “not American” is not a sovereignty standard

In one press conference, European sovereignty changed definition — from “incorporated in the EU” to “not incorporated in the US” — and nobody asked whether the second is a test or merely a proxy. It’s a proxy. Proxies fail at the edges. The edges are where procurement lives.

✓ First, what’s true — the Canadian case is stronger than critics allow

The CLOUD Act genuinely doesn’t reach Canadian incorporation. Canada has no CLOUD Act executive agreement — negotiating since March 2022, nothing finalized. And the Supreme Court of Canada (R. v. Spencer, R. v. Bykovets) explicitly rejected the US third-party doctrine. On several dimensions Canada is more protective than the US. This is not a hit piece.

The Five Eyes fact, stated precisely

UKUSA (1946): NSA · GCHQ · CSE · ASD · GCSB. CSE’s oversight is real — ministerial authorization, an independent Intelligence Commissioner (a retired judge) who can block, NSIRA review. Now read the operative restriction:

“CSE is prohibited by law from targeting the private information of Canadians, or any person in Canada.”

The protection is national and territorial. Europeans are neither.

Not an accusation — architecture. It’s structurally why Safe Harbor fell: protections protect the home nationals.

The adequacy gap nobody mentions

Canada has adequacy since 2001/2002 (Decision 2002/2/EC). But its scope is PIPEDA-only — employee data largely excluded; Alberta/BC/Quebec regimes never got adequacy; Quebec’s was withdrawn in 2014.

It was assessed against PIPEDA’s commercial framework — not against Canada’s intelligence laws or Five Eyes participation.

That’s the same hole the CJEU punched through Safe Harbor. In fairness: the Commission did examine public-authority access and found redress “accessible to non-Canadian nationals.” That clause is the best argument Canada has — and NSIRA is largely classified. Unsettled, not resolved.

⚠ The nexus problem — incorporation is not the test

US courts have been clear for 40 years: Bank of Nova Scotia — American courts enforce subpoenas against entities subject to US jurisdiction even where compliance violates foreign law, and fine for refusal. Jurisdiction attaches to presence and activity, not the incorporation certificate. So corporate pledges to “resist” are sincere and legally insufficient. And Canadian exposure creeps through ordinary commercial expansion:

BCE bought Ziply Fiber (US) Aug ’25 TELUS — 1,600+ US staff Shopify — 57% of txns in US; NY principal executive office None changed nationality. All changed nexus. So: what US nexus does Cohere have? Customers · ops · Microsoft partnership · US investors · a likely US listing. Nobody has asked.
The honest hierarchy — three standards, ranked by what they actually protect
✕ A proxy
“Not American”
Fails on nexus, fails on Five Eyes statutory architecture, fails when the ally’s interests diverge — and fails silently, because nobody’s measuring. This is what Europe just adopted.
◐ A test
“EU-incorporated”
SecNumCloud’s 24%/39% cap — narrow, arithmetic, checkable from a shareholder register. Also undeniably protectionist. Both true. What Europe already had — and just stepped back from.
✓ An architecture
Open weights · your keys · air-gappable
Requires trusting no jurisdiction, no ally, no election result, no executive directive. The only posture that survives every question below.
Europe just moved from the second to the first — and called it progress.
✓ The right test — enforceable, auditable control
1Who can compel you, under what standard, with what judicial review?
2Is there redress for a non-national? (US–UK/AU deals create none)
3What’s your nexus — not your incorporation?
4Who holds the keys, and can they be compelled to produce them?
5Can you leave, and how fast? (12–18 months of exit work)
6Can it be air-gapped?
Notice what happens down the list: the questions stop being about jurisdiction and start being about architecture. That’s not an accident — that’s the finding.
The take

The Five Eyes question isn’t “is Canada spying for America” — that’s the tabloid version, it’s unsupported, and it’s a distraction. The real question is duller and more damaging: why is Europe using nationality as a substitute for measurement? Because a proxy is cheap and a test is expensive. “Not American” lets you approve the deal, satisfy the minister, and skip the register, the nexus, the redress. It produces a press release. It does not produce protection. Every sovereignty claim here is a jurisdictional bet — that a legal system, an alliance and a political mood hold for the life of your data. The Canadian bet is genuinely better than the American one. It’s still a bet. The only positions that don’t require one are where you hold the weights and can pull the plug. If the answer is “well, they’re not American” — you haven’t been given a standard. You’ve been given a mood.

Sources: CSE’s own published material (UKUSA, mandate, Intelligence Commissioner, NSIRA, the targeting prohibition); IAPP, CIGI, Dentons, McMillan (Canada’s adequacy scope, PIPEDA limits, Quebec 2014); Barry Appleton, “Whose Law Governs Canadian Data?” (Balsillie Papers/SSRN 2026) & Citizen Lab Feb 2025 (Spencer/Bykovets, stalled CLOUD Act talks, Bank of Nova Scotia, UK’s 20,000+ requests, remedial no-man’s land, BCE/TELUS/Shopify nexus, US NSS & AI Action Plan). Some Five Eyes/GDPR analysis in circulation originates with vendors selling EU-hosted alternatives — read accordingly. Procurement & policy analysis, not an allegation of misconduct. Not legal advice.
thorstenmeyerai.com

Implications of Proxy-Based AI Standards for International Data Law

This shift toward ‘not American’ as a standard could undermine effective data protection and legal clarity in AI procurement. Relying on nationality as a proxy risks excluding capable providers like Canadian companies, which are legally protected from US surveillance laws. It also raises questions about the legitimacy of using simplified proxies in complex legal environments, potentially leading to gaps in data security, compliance issues, and diplomatic tensions. For European AI regulation, this approach might foster a false sense of security while complicating international cooperation and legal enforcement.

Amazon

European data protection compliance software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Legal and International Frameworks Shaping the ‘Not American’ Proxy

Canada’s legal protections, including its rejection of the US third-party doctrine and its strict foreign-intelligence laws, make it structurally different from the US in terms of data access. Canada has not signed a CLOUD Act executive agreement, and its courts have explicitly protected Canadians from foreign surveillance efforts, unlike the US. Additionally, Canada holds an EU adequacy decision since 2002, which permits data transfers but with limitations: it mainly covers commercial data under PIPEDA, excluding sensitive categories and certain provinces.

European policymakers’ reliance on the ‘not American’ proxy overlooks these distinctions, assuming that Canadian companies are equivalent to US providers in terms of data access and legal risks. This assumption is challenged by Canada’s legal protections and international agreements, which do not align neatly with US-based surveillance laws.

“The shift to ‘not American’ reflects a desire for sovereignty, but it risks oversimplifying complex jurisdictional protections and international agreements.”

— European Data Protection Official

Legal and Practical Risks of the ‘Not American’ Proxy Approach

It remains unclear how European regulators will enforce or verify the ‘not American’ standard in practice, especially given the legal complexities and international agreements involved. The effectiveness of this proxy as a safeguard against US surveillance laws is also uncertain, as it depends on evolving legal interpretations and diplomatic negotiations, such as Canada’s ongoing discussions with the US regarding data access agreements.

Future Regulatory Developments and International Negotiations

European policymakers are expected to refine their criteria and possibly develop more nuanced standards that go beyond simple nationality proxies. Meanwhile, Canada and other jurisdictions may seek to strengthen legal protections or negotiate new agreements to clarify data access rights. The ongoing negotiations between Canada and the US, along with evolving EU regulations, will shape how effectively ‘not American’ can serve as a reliable standard for AI procurement and data security.

Key Questions

Why is relying on ‘not American’ as an AI standard problematic?

Because it oversimplifies complex legal protections and international agreements, potentially excluding capable providers and creating gaps in data security and compliance.

Canada’s courts have rejected the US third-party doctrine, and it lacks a CLOUD Act agreement with the US, making US data access more limited and legally complex.

What are the limitations of Canada’s EU adequacy status?

It mainly covers commercial data under PIPEDA and does not extend to sensitive or employee data, especially in certain provinces, limiting its scope as a comprehensive safeguard.

Could the ‘not American’ standard be effective in European AI regulation?

Its effectiveness is questionable due to legal and jurisdictional complexities; it may serve more as a political signal than a practical safeguard.

Source: ThorstenMeyerAI.com

This content is for general information only and is not financial, tax or legal advice. Consult a qualified professional for decisions about your money.
You May Also Like

7 Best Security Surveillance Deals for Prime Day Savings in 2026

Discover the best security surveillance deals for Prime Day 2026, including wired, wireless, and multi-camera systems for home and business security.

AI’s Role In Modern Software: From Sensor Inputs To Autonomy

AI is increasingly central in transforming sensor data into autonomous decisions, with significant implications for sovereignty and security.

The Eye Over the City: How Wide-Area Motion Imagery Works — and Where It Goes Blind

An in-depth look at WAMI technology, its capabilities, limitations, and future prospects in urban surveillance and security.

AI’s Radar Functionality: A Key Tool For Institutions Navigating Modern Challenges

Artificial intelligence-enhanced SAR technology is transforming surveillance and disaster response, providing persistent, detailed ground imaging regardless of weather or light.