Sovereign AI: using AI without giving up your data

Sovereign AI means deciding where your data goes, which models process it and who can verify it. It does not mean running everything locally without discernment. It means choosing, and being able to prove it.

Why stay in control

Confidentiality

Client files, contracts, trade secrets: once sent to an external service, you no longer control how they are kept or used.

Obligations

Quebec's Law 25, your contracts and your commitments to your clients govern how you use the information you hold.

Dependency

A vendor can change its terms, its models or its offering. An open architecture keeps your option to switch.

Traceability

Knowing who asked what, of which model, with which data. That is what lets you answer a question from management, a client or a regulator.

How: three mechanisms

A local stack for sensitive data, explicit routing, and an audit log.

1. A local stack

Open models running on your servers or in a Canadian cloud that you control. Your documents are indexed on site, and the assistant respects the access rights already in place in your systems.

Local AI stack Five stacked layers: infrastructure, models, data, AI gateway and applications. An audit log covers every layer. Applicationsdocument assistant, agents, integrationsAI gatewayauthentication, permissions, routing, filteringDataRAG index, access rights inherited from your systemsModelsopen models run locallyInfrastructureyour servers or a Canadian cloud you control Audit log
Every layer stays under your control. The audit log covers them all.

2. Explicit routing

A gateway applies your policy: anything sensitive stays on the local model. An external model can be used for tasks that involve no personal information, if you have decided so in writing.

Routing based on data sensitivity A request reaches the gateway, which assesses how sensitive the data is. Requests that contain personal or confidential information go to the local model. Others may go to an external model if your policy allows it. Every decision is recorded in the audit log. Requeststaff or app Gatewayassesses sensitivityapplies the policy Local modelsensitive data External modelif the policy allows it Audit logwho, what, which model
By default, anything sensitive stays with you. The exception is a written decision, not a forgotten setting.

3. An audit log

Every exchange is recorded: user, date, model used, routing decision. The log is kept for a period you set and protected like any other information.

The journey of a piece of data

Example: an employee asks for a summary of a client file. Here is what happens to the personal information it contains.

The journey of a piece of data in a sovereign AI An employee asks a question that contains personal information. The AI gateway detects and masks that information and applies the routing policy. The sensitive file is processed by the local model and does not leave your perimeter; the exchange is recorded in the audit log. An external model only receives non-sensitive tasks, with names replaced, and only if your policy allows it. YOUR PERIMETER 1. An employee's question“Summarize Jean Tremblay's file” 2. AI gatewaydetects and masks personal informationapplies your routing policy 3. Local modelthe file stays with you 4. Audit logwho, what, which model Answer to the employeewithout the file leaving your perimeter External modelnon-sensitive tasksname replacedwith [NAME] only if your policy allows it
Personal information stays local and every step is logged. The external model only sees what you have authorized, masked.

What Law 25 requires, in general

Law 25 modernized Quebec's Act respecting the protection of personal information in the private sector. Several of its obligations bear directly on AI projects:

  • A person in charge of the protection of personal information. By default, this is the person with the highest authority in the organization. Their title and contact information are published on the website.
  • Governance policies and practices for personal information, published in plain language.
  • A privacy impact assessment (PIA) for any project to acquire, develop or overhaul an information system that processes personal information, and before communicating personal information outside Quebec.
  • Transparency about automated decisions. A person subject to a decision based exclusively on automated processing must be informed of it. On request, they can learn the personal information used, the reasons and principal factors behind the decision, and submit observations to someone able to review it.
  • Consent that is manifest, free, enlightened and specific, and profiling or location features turned off by default.
  • Confidentiality incident management: an incident register, and notice to the Commission d'accès à l'information (Quebec's access to information commission) and to the persons concerned when there is a risk of serious injury.
  • Limited retention: destruction or anonymization of the information once the purpose for which it was collected has been achieved.

This is not legal advice. This page summarizes general obligations. For your specific situation, consult your legal advisor or the website of the Commission d'accès à l'information du Québec.

See also: AI governance and Law 25 compliance · Private AI hosted on your premises · L7 — Law 25 register and PIA

Let's talk about your situation

Every organization has its own systems, data and constraints. We always start by understanding your situation. Scope and investment are proposed afterwards, in writing.