← Back to Insights
Data Sovereignty

The CLOUD Act and Solicitor-Client Privilege: What Our AI Vendor Review Actually Found

A Canadian firm's compliance review of AI chat tools for client files — what the CLOUD Act meant in practice, and why Canadian AI mattered more than expected.

By Augure·
Business professionals in a meeting around a table.

This is a composite account. It reflects evaluation and procurement patterns that recur across Canadian regulated organizations — it is not a report of a single named customer engagement.

The thing that stopped our review wasn't the CLOUD Act itself. It was realizing none of the associates could tell me, without checking, which AI tool they'd pasted a client's settlement numbers into the week before.

That's the actual risk. Not some hypothetical FBI subpoena landing on a US cloud provider's desk — though that's the legal mechanism everyone cites — but the fact that lawyers had been treating chatbots like a search engine, not like opposing counsel's discovery request. A mid-size firm I've been advising on tooling ran into this last year, and the fix ended up being less about the CLOUD Act itself and more about finding an AI platform where the privilege question didn't need to be argued case by case. If you're a Canadian lawyer trying to figure out whether your AI chat tool creates a privilege problem, the short answer is: it depends where the data sits and who owns the company running it, and most firms don't actually know either.

What the CLOUD Act covers, and what it doesn't

The US CLOUD Act lets American law enforcement compel data from any provider under US jurisdiction, regardless of where the servers physically sit. That's the part everyone gets right when they explain it. What gets missed is that jurisdiction attaches to the company, not the country hosting the servers — so a "Canadian data centre" operated by a US-parented vendor doesn't necessarily get you out of scope. Our security reviewer flagged this early, and it reframed the whole exercise. We stopped asking "where's the data stored" and started asking "who's the corporate parent, and does any part of this stack sit under a US entity."

That distinction mattered more than anything else in the review.

Before we landed on that framing, we'd actually spent the first two weeks trying to solve this contractually — asking vendors to add a data-location clause to the master services agreement and thinking that would settle it. It wouldn't have. A contractual promise about server location does nothing to change which government can compel the company to produce data, regardless of where that data physically sits. Our security reviewer was the one who pointed out we were negotiating the wrong clause entirely, and we shelved that draft.

Why solicitor-client privilege made this urgent

Privilege doesn't survive contact with a third party who has an independent legal right to access the communication. That's a simplification of a much older doctrine, but it's the version that mattered to us. If a US cloud provider can be compelled to produce data under the CLOUD Act — even data belonging to a Canadian client, stored ostensibly in Canada — there's a real argument that the privileged character of that communication has been compromised the moment it touched that infrastructure. Nobody on our team could point to a Canadian case squarely on point. That's part of what made the conversation uncomfortable: we were making a risk call on a question the courts haven't fully settled.

My read was that we didn't need a settled case to justify caution. We needed to avoid being the fact pattern.

One associate pushed back hard on this, and it's a fair objection: if the CLOUD Act risk is theoretical and unlitigated in Canada, why treat it as a hard gate rather than one factor among several? My answer, and I'm not sure it fully satisfied him, was that privilege waiver doesn't require a finding of actual disclosure — the risk that a court finds the privilege compromised by exposure to a compellable third party is enough to create a duty to avoid the exposure in the first place. We were managing a duty of care, not waiting for a breach.

The questions we actually asked vendors

We built a short list and sent it to every AI vendor we were considering, including two US chatbot providers, one hybrid product, and Augure. The questions were roughly:

  • Where does inference actually happen — not "where's your head office," but which servers process the prompt?
  • Who is the corporate parent, and are there US investors with board influence?
  • Is customer data used to train models, and can that be disabled contractually?
  • What sub-processors touch the data, even for things like email delivery or billing?
  • What happens to data during failover, and where does that route?

The failover question tripped up two vendors who hadn't thought about it themselves. One came back and admitted their disaster recovery ran through a US region even though primary processing was Canadian. That's the kind of answer you don't get unless you ask the boring, specific question instead of the marketing one.

Where Augure fit, and where it didn't fully close the loop

Augure's answer on jurisdiction was the cleanest of the group: no US corporate parent, no US investors, and customer conversations and documents are never handled by US-jurisdiction providers, so the CLOUD Act's reach over US-controlled providers doesn't extend to that content. That's a scoped claim, not an absolute one, and I appreciated that nobody on their side tried to oversell it into "you're fully protected." Inference for some model tiers runs on Canadian infrastructure; other tiers, and failover, run through vetted EU partners under zero-data-retention agreements — never the US. Email delivery and payment processing still touch US-based services, which they disclosed without us having to dig for it in a sub-processor table. For the kind of cross-border transfer assessment our privacy lead had to do under Quebec's Law 25, that level of disclosure was more useful than a vaguer "everything's Canadian" claim would have been, because it let her actually map the flows instead of taking it on faith.

Pricing landed at C$20/month per user for the tier with persistent memory and priority models, which felt reasonable next to what associates were already expensing on personal ChatGPT subscriptions nobody had approved. The Max tier at C$80/month with deep research agents wasn't something we needed yet — most of our use case was contract language and client correspondence review, not open-ended research.

One thing that turned out not to matter at all: encryption-at-rest specifications. Every vendor we looked at had solid encryption, and it became a non-issue within the first week. I'd expected that to be a bigger differentiator going in. It wasn't. The jurisdiction question ate all the oxygen.

The CLOUD Act point our counsel wouldn't move on

Outside counsel we brought in for a second opinion put it plainly: the CLOUD Act point is the one they would not move on, full stop, regardless of contractual assurances from a vendor about data location. Their view was that a US-parented company operating a Canadian data centre still creates a compellability risk that no data processing agreement fully eliminates, because the legal authority attaches at the corporate level. That single piece of guidance did more to shape the final vendor shortlist than anything in our internal risk assessment.

The CLOUD Act's text says a covered entity must preserve, back up, or disclose the contents of a communication regardless of whether it's stored inside or outside the United States. We didn't need a Canadian court to interpret that for us. The plain language was enough to change the shortlist.

What we'd do differently

We spent too long on a feature comparison spreadsheet before we'd nailed down the jurisdictional question, which is backwards. If I ran this again I'd ask the corporate-parent and sub-processor questions in the first call, not the third, and treat everything else — pricing, UI, model quality — as secondary until that gate was cleared. We also should have looped in the Law Society's guidance on technology competence earlier; it doesn't dictate a specific vendor, but it does put an affirmative duty on lawyers to understand the tools they're using, and that duty was doing more work in our internal memo than I'd initially given it credit for.

I'm still not fully sure how a Canadian court would rule on the privilege question if it were ever tested directly against a CLOUD Act production order. Nobody I talked to was sure either. What we settled on was a defensible position rather than a guaranteed one: Canadian AI tooling, a Canadian corporate entity, documented data flows, and a paper trail showing we asked the right questions before a client ever raised it.

More detail on how Augure handles data residency and jurisdiction is on their site, if you want to run your own version of this comparison.

A

About Augure

Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.

Ready to try sovereign AI?

Start free. No credit card required.

Get Started