Blog
Legal and technical analysis for regulated-sector buyers navigating AI compliance under PHIPA, MFIPPA, and Law Society of Ontario guidance.
Why Sovereign AI Matters: The Case for AI That Answers to Your Law, Not Someone Else's
Sovereign AI is not a compliance checkbox — it is a strategic and existential question for any organisation that handles sensitive data. Here is why it matters, who it affects, and what genuine sovereignty actually requires.
AI in Ontario Hospitals and Clinics: What PHIPA Actually Requires Before You Deploy
Ontario hospitals and medical clinics face specific PHIPA obligations before deploying any AI tool that touches patient data. Data location alone does not satisfy the law — here is what does.
Ontario Municipalities and AI Tools: The MFIPPA Section 41 Problem No One Is Talking About
MFIPPA s.41 prohibits Ontario institutions from storing or processing personal information outside Canada without explicit statutory authority. Most AI tools municipalities are piloting right now violate this provision.
Canadian EMR Vendors Integrating AI: What Your Privacy Officer Needs to Know About PHIPA and PIPEDA
Ontario's EMR vendors are under pressure from clinics to add AI features. Most are evaluating US-based LLM APIs. Here is the privacy officer's checklist before any PHI touches an external model.
Why AWS Canada Is Not Actually Sovereign (And Why It Matters for PHIPA)
Geographic residency is not legal sovereignty. The CLOUD Act (18 U.S.C. § 2713) can compel AWS to hand over data from Canadian servers. Ontario clinics storing PHI on AWS Canada remain exposed.
What the Law Society of Ontario's Cloud Guidance Actually Requires From Your AI Vendor
The LSO requires lawyers to understand where data is processed, who has access, and what happens on subpoena. Most AI tools fail all three. Here is what genuine compliance looks like.
Cryptographic Attestation: What an Ed25519 Sovereignty Receipt Actually Proves
A policy promise is not proof. An Ed25519 signature is. We explain the exact mechanism behind our attestation documents and why your auditor can verify them independently.
SR&ED and Canadian AI Infrastructure: What Counts as Qualifying Expenditure
SR&ED covers work to resolve technological uncertainty. Building a sovereign inference stack qualifies. Running a commercial API on top of it does not. The line matters for claim structuring.
Get notified of new posts
We publish 1–2 posts per month on sovereign AI, Canadian compliance frameworks, and regulated-sector AI adoption.
Subscribe via email