A review that changed nothing on paper, and everything in practice
CUSMA's first mandatory Joint Review — triggered on the agreement's sixth anniversary, as required by the treaty text — concluded July 1, 2026, with the United States declining to confirm renewal (Global Affairs Canada). U.S. Trade Representative Jamieson Greer put it plainly: Washington "did not agree to renew the USMCA in its current form" (GHY International). The pact doesn't lapse — it stays in force to July 2036 — but it now runs on annual review cycles instead of the automatic 16-year rollover Canada and Mexico both wanted. Digital trade was explicitly named as one of the areas the review needed to "adapt to a changing world," alongside AI and energy.
That framing matters because one clause sat untouched through all of it: CUSMA Article 19.12. It reads, in full: "No Party shall require a covered person to use or locate computing facilities in that Party's territory as a condition for conducting business in that territory." Unlike Article 19.11 next door, which permits data-transfer restrictions in pursuit of a "legitimate public policy objective," Article 19.12 carries no such carve-out — a gap Canadian trade scholars have flagged as unusual even by comparison with the CPTPP, which preserves an explicit public-policy exception for the equivalent rule.
Why USTR started paying attention
The review didn't happen in a vacuum. USTR's 2026 National Trade Estimate Report, submitted to Congress and the President on March 31, 2026, named Canada's sovereign-cloud and digital-sovereignty measures as trade barriers for the first time — a category that, per University of Ottawa law professor Michael Geist's reading of the report, didn't exist in the 2025 edition at all (Michael Geist). Two specific measures drew the citation: the federal Shared Services Canada proposal, which would require government cloud purchases to "process, transmit, and store all data exclusively in Canada" under providers not subject to foreign-law access without Ottawa's consent, and Alberta's Sovereign Compute Environment procurement, which layers on Canadian-ownership thresholds and an outright ban on providers reachable under the U.S. CLOUD Act.
Both measures are procurement conditions, not general-market mandates — the kind of thing WTO government-procurement carve-outs would normally shield. But Article 19.12's total absence of exceptions leaves that distinction untested, and Washington's decision to name the programs in an official trade-barriers report — rather than let them sit as a bilateral irritant — signals it intends to treat the line as real.
The case for sovereign cloud, stated fairly
The steelman here isn't paranoia. Canadian federal and provincial governments hold citizen health records, tax data, and law-enforcement files; routing that infrastructure through providers legally compellable by a foreign government's process — the CLOUD Act being the recurring example — is a genuine governance question, not manufactured protectionism. The EU has spent years building comparable sovereign-cloud architecture (Gaia-X, the drive toward EUCS certification) without anyone calling it disguised trade war. Ottawa's $890 million AI Sovereign Compute Infrastructure Program, running FY2026-27 through seven fiscal years to build a "Canadian-located, Canadian-governed" AI supercomputer, is explicit that data residency and operational control are the point, not a side effect (ISED). A government is entitled to decide where its own procurement dollars go and under whose legal jurisdiction its own citizens' data sits.
Why the current path is still the wrong one
The steelman only carries so far, though, because Canada signed a treaty that says exactly what it now finds inconvenient. Article 19.12 isn't ambiguous, and it isn't new — it's been sitting in Chapter 19 since CUSMA's 2020 entry into force. Building a $890-million procurement architecture around "Canadian-governed, Canadian-located" mandates without first securing the treaty carve-out CPTPP negotiators thought to include is a sequencing error, not a sovereignty stand. Legal scholars reviewing the review process have already pointed out that blanket data-residency requirements — as opposed to narrowly tailored ones covering, say, classified or critical-infrastructure data — are the version most exposed to a CUSMA challenge, and that provincial add-ons (Quebec tying electricity access for data centres to data-governance compliance, for instance) compound the exposure by dragging energy policy into the same dispute (Policy Options / IRPP).
The proportionate fix isn't to abandon sovereign compute — it's to narrow the mandate to what actually needs residency (classified government workloads, critical-infrastructure control systems) and pursue an explicit Article 19.12 amendment for that narrower category during the annual review cycle Canada now has through 2036, rather than litigating the broad version by accident. A blanket localization rule invites exactly the trade friction USTR just signaled it's willing to escalate, for protection no narrower rule wouldn't already provide. Canada has ten years of scheduled reviews to negotiate the exception properly. Building irreversible procurement facts on the ground before doing so trades a strong negotiating position for a weak legal one.