Sunday, July 26, 2026
spot_img

AI Sovereignty Moves at the Speed of Models, Not at the Speed of Canada

Last updated on July 25th, 2026 at 05:07 pm


Canadian AI Sovereignty Series · Paper 28


It’s fascinating to watch political winds blow across Canada. We are still small enough that only a few things can occupy our collective consciousness at a time. for the past couple of weeks, the discourse has been dominated by forest fires and bridges and implicitly our relationship with the US. what few of us have been talking about our matters that will eventually have a much greater impact on us and that is the daily evolution few weeks, more remarkable than this one in the evolution of artificial intelligence
On Monday, unless the Trump administration makes good on threats to ban Chinese models, the game changes forever.

Five things happened in the American AI stack in the week before the Kimi K3 weights land, on Monday. They describe a market that has stopped trying to separate itself from its rival and started hedging every dependency it cannot exit. Canada appears in none of the five, and yet … will inherit all of them.


On July 20, Microsoft committed to deploying AMD’s Helios racks across Azure, joining Meta, OpenAI and Oracle. On July 21, Microsoft signed a multi-billion-dollar agreement to rent computing capacity from Mistral’s data centres in France and Sweden, and added Mistral’s Medium 3.5 and OCR 4 models to Foundry and Copilot Studio. On July 22, AMD signed a deal with Anthropic for up to two gigawatts of Instinct MI450 accelerators beginning in the first half of 2027, together with an equity investment of up to five billion dollars. On July 24, twenty-five American technology companies published a letter telling Washington that open-weight models are essential to American AI leadership, and Anthropic shipped Opus 5, closed and API-only. On July 27, the K3 weights become downloadable and the claim underneath the letter becomes checkable for the first time. Every one of those transactions is a complication for movement toward sovereignty while simultaneously, in sone ways, enabling it. They are hedges against a dependency we as the buyer cannot exit. None of them is a step toward independence.


The Containment Architecture Produced Entanglement

The clearest case is the one being sold as European sovereignty. Microsoft’s arrangement with Mistral gives Azure customers a European-hosted alternative to US-controlled infrastructure, aimed at regulated sectors (finance, healthcare, manufacturing) that need to deploy under data residency law. Brad Smith and Arthur Mensch described the partnership as delivering sovereignty while preserving access to American software and security features. Reuters was direct about the trigger: the American decision last month to pause foreign access to two advanced Anthropic models made technology independence urgent in Europe.


Mistral is building that capacity with thousands of Nvidia Vera Rubin GPUs. Nvidia, like Microsoft, is a Mistral investor. So the European hedge against American jurisdictional risk runs on American-designed silicon, is funded by an American hyperscaler, and carries American equity at two points in the stack. Mistral targets 200 megawatts by 2027 and a gigawatt by 2030, roughly one French reactor’s output, against the hundreds of billions and multiple gigawatts American firms are building. The sovereignty is real at the jurisdictional layer and nowhere else.


The same pattern appears in the chip deals. Microsoft hedges Nvidia with AMD while remaining Nvidia’s largest class of customer. AMD takes an equity position in Anthropic, which means the accelerator vendor is now capitalizing the model company that buys its accelerators, the two ends of the barbell financing each other across the commoditizing middle. Anthropic hedges its silicon supplier while refusing to hedge its closed-model position at all.


This is what the containment architecture actually produced. American export controls created the scarcity that produced KTransformers, the Tsinghua-developed framework that runs enormous mixture-of-experts models on hybrid CPU and GPU hardware by offloading expert layers into ordinary system memory, and in doing so collapsed the hardware floor for frontier-class inference from hyperscaler scale to server-closet scale. The instrument of containment hasmanufactured its own bypass. In June, export controls and country of origin limitations blocked distribution and use of Anthropic’s most capable models following a reported jailbreak of their cybersecurity guardrails, and the world saw it as bullying, as a flex, but acted on it as a cautionary tale, as a reason for France to buy French compute from an American vendor. The administration is now weighing restrictions on US access to Chinese open models, alleging that Moonshot distilled an Anthropic model on export-controlled Nvidia servers.


Nothing in that sequence separates the two blocs. Each control action tightened the web. The American position in July 2026 is not decoupling but mutual entanglement with an adversary whose release cadence it does not control, mediated by hedges every major player is buying simultaneously. What is grabbing the headlines is a different matter altogether.


The Position America Vacated


The open weights letter published on Friday (and signed after release by OpenAI, but not yet by Anthropic) argues that the United States will hold its AI lead only by building an open ecosystem rather than guarding a single best system. Jensen Huang, in the first post he has ever made on X, wrote that open models strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty.


Meta abandoned open weights in April.


Meta signed it. Muse Spark, the first model from Meta Superintelligence Labs, shipped on April 8 as an explicit ground-up overhaul of Meta’s AI effort: natively multimodal, closed, available at meta.ai and through a private API preview, with no downloadable weights and no self-hosting. Llama 4 remained available and unadvanced. By mid-May, Meta had shipped no new open-weight Llama, Behemoth was still in training, and a near-term Llama 5 had become a low-probability scenario rather than the central case. Eleven of the fourteen researchers on the original Llama paper have since left the company.

Muse Spark scored 52 on Artificial Analysis’s Intelligence Index against Llama 4 Maverick’s 18, Meta demonstrating with its own numbers that the closed path produced the better model.


Llama had been downloaded 1.2 billion times. It was the American open-weights position, and the company holding it walked away in April, leaving Llama 4 users with no migration path and three practical options: stay on a model that will fall further behind, move to Mistral or DeepSeek or Qwen, or migrate to a proprietary API.


That vacancy was filled by Chinese labs. DeepSeek ran an architectural reset in April. Qwen shipped through February and April and teased again in July. Moonshot released K3 on July 16 and reset expectations for how capable a downloadable model can be, taking nearly nine percent off the semiconductor ETF SMH in a single week. GLM opened weights under MIT licence in June and previewed a trillion-parameter successor for August.


So the letter is not America failing to see open weights coming. America held the open-weights frontier, vacated it deliberately for better closed economics, watched Chinese labs occupy the ground within a quarter, and then asked Washington to protect a field its largest signatory no longer competes in. The letter’s defence of distillation as legitimate model improvement, and its request that policymakers pursue intellectual property theft directly rather than restricting open weights as a category, is a response to a live blacklist threat against the lab that took the position Meta left.


Reading the Letter by What Each Signatory Sells


Meta, Microsoft, Nvidia, IBM, Dell, CrowdStrike, Palantir, ServiceNow, Hugging Face, Perplexity, Mistral, Andreessen Horowitz, Y Combinator, the Linux Foundation, Mozilla. OpenAI and Anthropic did not sign.


Nvidia sells the silicon every downloaded weight file runs on. Microsoft and Dell sell the infrastructure underneath it. Palantir and ServiceNow sell the integrations and workflows above it. Andreessen Horowitz and Y Combinator fund the application layer that consumes it. Mistral now sells compute. Not one of them depends on frontier model access as its primary revenue. The two firms that do declined to sign, and one of them shipped a closed flagship the same day.


This is not a coalition for openness. It is the two ends of the stack arguing that the middle should be free, and it is close to unanimous because a free middle is the best available outcome for anyone selling at either end.


The letter frames open weights as protection against gains concentrating among a handful of firms, and as insurance for enterprise customers against vendor lock-in. Both claims are defensible in the abstract. They are also the anti-concentration argument advanced by the most concentrated firms in the industry, hosted on Microsoft’s own corporate-responsibility site.


The reason the argument works for them is the reason it should worry a sovereignty analyst. When the middle commoditizes, value moves to the ends, down into power, land, water, minerals, silicon; up into accreditation, procurement standing, institutional trust, jurisdiction. What was understated is that the ends were already owned when the middle emptied out, and that the two ends are precisely the strata that cannot re-clock. Model releases land weekly. Procurement cycles run in years. Grid interconnects run in decades. Whoever was positioned at the ends when the shift happened holds the position uncontested, not through superior capability, but because the interval in which it could have been contested closed faster than any institution can move.


Which is also why the four triggers this series has used since Paper 4 apply to open weights. Jurisdictional reach over a local weight file is essentially nil, and model-level lock-in evaporates when substitution costs approach zero. Those are real gains and the strongest sovereignty case for open weights. But opacity moves into the weights: an institution can run a downloaded checkpoint and never audit the training corpus, the alignment choices, or the behaviours baked in at training time, and those now sit beyond any jurisdiction a Canadian court can subpoena. A weight file is a compiled binary with no source. And capture was never a model property: an integrator deploying fully open models can build the same unwindable grip through ontologies and workflows, which is why Palantir could sign the letter without contradicting a word of its business model. Unwinding takes three years while the stack turns over in three months. The integration is permanent relative to the clock, and the clock is the only permanence that matters.


The Refusal


The event grabbing the headlines this week demonstrated what a closed dependency costs at the moment it matters, and the public framing of it has been wrong.


During an active security incident, Hugging Face found that a closed frontier model from an American vendor refused its requests. Clément Delangue’s account is specific about the mechanism: closed model APIs flag and refuse a great deal of legitimate security work, because analysing an attack looks a lot like preparing one, and in the middle of a live incident you cannot have your tools refusing to examine malicious payloads or getting your account flagged. The company completed the work with an open model from Z.ai.


No model went rogue. A guardrail fired as designed, at the wrong moment, against a legitimate operator, and the escape hatch was Chinese weights. But the anthropomorphizing runs wild.


That is a sovereignty finding this series has not previously had to name. Vendor alignment policy is now a live component of national incident-response capability. A Canadian institution running incident response on a closed American API has no input into how those refusals are tuned, no notice when they change, and no recourse when they fire mid-incident. The dependency is not the model’s capability. It is the vendor’s policy, applied at machine speed, in a jurisdiction that has already demonstrated it will pause foreign access to models when it chooses.


Canada Takes What It Can Get


Canada has one company positioned at the ends of the barbell, and its trajectory has been exactly right. Cohere merged with Germany’s Aleph Alpha in April, into a jurisdiction with no CLOUD Act equivalent, backed by a Canada–Germany joint AI declaration signed in February. In May it partnered with Calian to bring North into Canadian defence environments. In June it anchored the Merritt build with Bell, Hypertec and BUZZ HPC — 2,304 Grace Blackwell GPUs in purpose-built British Columbia infrastructure, live by early 2027, with Ottawa holding a $240 million position through the Sovereign AI Compute Strategy. Down the stack into Canadian power and land, up into defence accreditation and allied-jurisdiction trust. The company read the market correctly and fled the middle in both directions at once.


Compare Mistral, which is roughly Cohere’s peer: a non-American model company with a smaller capital base, building domestic infrastructure, selling jurisdictional trust. In one week Mistral received a multi-billion-dollar compute agreement from Microsoft, model placement in Foundry and Copilot Studio, a route into regulated European enterprise, and a signature on the letter that is setting the terms of the open-weights fight.


Cohere received none of it, and is on no leaderboard that matters, and was neither a signatory to Friday’s letter nor a target of the blacklist threat, nor mentioned in any coverage of either.


The difference is not capability. Cohere’s sovereignty engineering is arguably better, an actual merger into a friendlier jurisdiction, an actual defence integration, actual domestic iron in the ground. The difference is that Europe is a market large enough that selling sovereignty into it is worth a hyperscaler’s multi-billion-dollar commitment. Canada is not. Europe had a sovereignty crisis in June and a commercial partner had monetized it by July. Canada’s equivalent crisis produces no such offer, because there is no comparable revenue at the other end of it.
That is the middle-power condition stated as a transaction rather than a mood, and it is worth stating without embarrassment. Ottawa could run a two-day loop between signal and response and remain a rule-taker. The constraint is not reaction time. It is that the venues where the terms get set: American policy letters, American export-control decisions, American leaderboards, the coverage that drives both, do not have Canadian seats, and building infrastructure does not buy one.


So Canada takes what it can get. Whatever survives the American open-weights fight will be what is available to deploy here, on terms set elsewhere, at prices set during a leveraged compute boom. If Washington restricts access to Chinese open models, the sovereign inference floor that KTransformers opened closes again, and every Canadian institution planning a self-hosted deployment loses its foundation without any Canadian decision having been made. If Washington leaves them open, Canadian ministries inherit unauditable Chinese weights as the default sovereign option. Either resolution arrives here as a fact rather than a choice.


What the Public Cannot Know


The public is not in this conversation, and the reason is not inattention. Canada is occupied this month with bridges and forest fires, which are real, immediate and correctly urgent. But even a fully attentive public could not evaluate what is being decided, because the information required is structurally unavailable.
Palantir’s Canadian renewals surface through access-to-information requests, undisclosed by default. The Calian integration terms inside the Department of National Defence are not public. Ottawa’s $240 million position at Merritt carries no disclosed contract terms. Training provenance on any frontier weight file, Chinese or American, is unauditable by anyone, including the government deploying it. The distillation allegation against Moonshot, which may determine whether open weights remain lawfully available here, rests on claims the administration has floated without evidencing. The refusal thresholds inside a closed API are set by a vendor and disclosed to no one.
There is no suppression campaign, and this paper does not allege one. There does not need to be. Every input a citizen would require to judge whether a Canadian AI deployment is sovereign is either exempt from disclosure, commercially confidential, or held by a foreign executive who has no obligation to publish it. Opacity is the first of this series’ four triggers, and applied to the Canadian state rather than to a vendor it returns the same reading it always has.


That is what makes the phrase take what we can get precise rather than rhetorical. Canada will deploy what the resolution of an American argument leaves available, and the disclosure regime guarantees the deployment will be irreversible before anyone outside the contracting parties can assess it.


Two Words, Marketing


Sovereign and open have become the trust vocabulary of the post-commodity market, and both are accountability-shaped rather than accountability-bearing. Sovereign, in current Canadian usage, mostly means domestic. Open, in current deployment usage, mostly means downloadable. A ministry running unauditable Chinese weights inside an undisclosed domestic integration contract satisfies both labels and trips every trigger in the framework.
Both words also verify more slowly than deployment happens, which is what makes them useful to the people using them. The audit arrives after the integration is irreversible. That is not incidental to the branding; it is the branding’s function.


The correction is definitional. Sovereignty is freedom from coercion plus the ability to structure dependencies so they cannot become leverage. By that standard a sovereign deployment requires disclosed contracts, reversible integrations, auditable behaviour, and jurisdictionally answerable operators. Domestic ownership delivers one of those four. An open licence delivers a different one. Neither delivers the set — and Friday’s letter argues for the licence while its signatories hold the layers where the other three are decided.


The Ledger, Extended


Our open vulnerability ledger ran to seven entries. This week adds two the core samples cannot hold.


V8: Talent concentration. The seven-dependency model places human capital at the base of the stack alongside foundries, and the core samples omit it. Weights are free and inference runs in a server closet, and the number of people in Canada who can stand up, secure and audit a sovereign frontier deployment is small enough to be a rounding error in a federal staffing plan. A commodity model plus an uncontested talent pool is dependency with a domestic mailing address.


V9: Absence of standing. Canada holds no seat in the venues where the terms of AI sovereignty are set: the policy coalitions, the export-control decisions, the leaderboards, the coverage that drives both. Mistral’s week is the proof: comparable capability, better commercial position, because its home market is large enough to be worth selling sovereignty to. This vulnerability is not addressable by procurement, compute spending or speed, and the rest of the ledger is downstream of it.


Monday


When the weights land, the commodity middle becomes a verifiable fact rather than a leaderboard number, and every Canadian institution inherits the same choice it has had since this series began: build accountability into the two ends of the stack, or dress the old dependencies in the new vocabulary.
The letter arrived three days before the fact it depends on became checkable. Meta signed it three months after abandoning the position it describes. Microsoft bought European sovereignty on American silicon four days before signing it. The argument was settled before the evidence arrived, in rooms Canada was not in, by parties hedging dependencies they cannot exit — and on Monday the terms take effect here regardless, under contracts no one outside them will read.

Featured

Jennifer Evans
Jennifer Evanshttps://patternpulse.ai
Principal, patternpulse.ai, and cofounder, Tech Reset Canada. AI policy, research and analysis. Entrepreneur since 2002, marketer since 1998, machine learning since 2009. Based in Toronto and Southeast Asia.