CFOtech Canada - Technology news for CFOs & financial decision-makers
Canada
Canada's tech problem is its growing technology dependency

Canada's tech problem is its growing technology dependency

Mon, 31st Aug 2026 (Today)
Andre Duttmann
ANDRE DUTTMANN Executive Director Linux Association of Canada

Canada is having an important conversation about sovereignty.

We talk about energy security, Arctic sovereignty, domestic manufacturing, defence capabilities and the resilience of Canadian supply chains. Increasingly, we are also talking about artificial intelligence and the importance of building Canadian capacity in one of the defining technologies of our time.

There is another layer of sovereignty that deserves the same attention.

Digital sovereignty.

Modern Canada depends on digital infrastructure for almost everything. Governments deliver essential services through it. Businesses operate through it. Hospitals, universities, financial institutions and critical infrastructure rely on it. Our communications, records and increasingly our decision-making processes exist within digital systems.

Yet much of that technological foundation is controlled by organizations outside Canada.

That does not mean foreign technology is inherently bad, nor does it mean Canada should attempt to build every processor, operating system, cloud platform or application within its borders.

It does mean we should ask a simple question more often:

If access to a critical technology changed tomorrow, how much control would Canada actually have?

Sovereignty is about choice

Digital sovereignty is sometimes misunderstood as technological isolationism.

It should mean almost the opposite.

A digitally sovereign country is not one that refuses to use foreign technology. It is one that maintains enough control over its infrastructure, skills, data and technology choices that it is not trapped by them.

The Government of Canada now defines digital sovereignty in similar terms: the ability to exercise autonomy over digital infrastructure, data and intellectual property and to make independent decisions regardless of where the underlying technology was developed or is supported.

Importantly, Ottawa also acknowledges that complete digital autonomy is neither realistic nor desirable in an interconnected world.

That distinction matters.

The objective should not be independence from everyone else. It should be avoiding excessive dependence on anyone else.

We need to look beyond where the server sits

For years, much of the Canadian conversation around digital sovereignty concentrated on data residency. Where is the data physically stored?

That remains important, particularly for governments and organizations handling sensitive information. But a server located in Toronto, Montreal or Calgary does not automatically make the technology running on it Canadian or sovereign.

Who owns the platform? Who controls the software? Can the customer move its information elsewhere? Are the data formats portable? Can another provider operate the system? Can Canadian specialists maintain it? What jurisdiction governs the company providing the service? And what happens if prices, licensing conditions, political circumstances or corporate priorities change?

Those questions describe a much broader concept of sovereignty.

The federal government's evolving position reflects this. Its current digital sovereignty framework goes beyond data location and considers operational resilience, supply chains, institutional control, cybersecurity, technical capability and reliance on global suppliers.

That is an encouraging development.

Convenience can quietly become dependency

Technology dependency rarely arrives as the result of one terrible decision.

Usually, it happens through hundreds of perfectly reasonable ones.

A department adopts a platform because it solves an immediate problem. A business chooses a cloud service because deployment is faster. Another application becomes integrated with it. Employees are trained on the ecosystem. Data accumulates. Workflows are redesigned around it.

Five years later, changing providers is no longer a procurement decision. It is an organizational crisis.

This is the fundamental problem with vendor lock-in. The danger is not simply that one supplier might charge more. The greater risk is that an organization gradually loses the practical ability to choose something else.

At national scale, the consequences become much more significant.

Canada's own government has recognized this risk. Shared Services Canada has identified diversification, continuity and reducing excessive reliance on external suppliers as important elements of digital sovereignty.

That tells us something important.

Technology procurement is no longer merely an IT decision. It can be an economic resilience decision, a security decision and, in some circumstances, a sovereignty decision.

Open source belongs in this conversation

This is where open-source technology becomes particularly relevant.

Open source is sometimes presented primarily as a cheaper alternative to commercial software. That seriously undersells its strategic importance.

The important word is not free. It is control.

When software is genuinely open, its source code can be inspected. It can be modified. Expertise can exist in more than one company. Organisations can operate it themselves or contract different providers to support it.

That does not magically eliminate dependency.

An organization can build an extraordinarily complicated open-source environment that only a handful of people understand. Open-source projects can disappear. Security vulnerabilities exist in open and proprietary software alike.

Digital sovereignty requires good architecture, competent people, sustainable projects and responsible governance regardless of licensing model.

But open source changes one crucial element of the relationship.

The ability to continue using the technology is not necessarily tied to the continued permission of a single vendor.

Canada has recognized some of this before. Federal guidance states that, where possible, open-source software should be used first in government architecture assessments. Federal Open First work has also highlighted open standards, interoperability, transition costs and reducing lock-in.

Those principles deserve renewed attention in the sovereignty debate.

Open standards may matter even more

There is another component that receives less attention than it should: open standards. Imagine an organization decides tomorrow that it wants to replace a major technology provider.

Can it actually take its information with it? Can another application read the files? Can another provider reproduce the environment? Can systems communicate without proprietary interfaces controlled by the company being replaced?

If the answer is no, theoretical choice means very little.

True digital sovereignty requires portability.

That means governments and large Canadian institutions should evaluate technology purchases not only according to what a system can do on the day it is purchased, but according to how easily Canada can leave it later.

Exit costs should be part of the purchasing decision. Interoperability should be part of the purchasing decision. Open formats should be part of the purchasing decision. The ability to operate critical systems through alternative providers should be part of the purchasing decision.

We spend considerable effort evaluating how technology enters an organization. We should become equally good at planning how it can leave.

Canadian capability matters as much as Canadian infrastructure

There is also a human side to sovereignty.

Owning infrastructure means relatively little if nobody in Canada knows how to operate, repair or develop the technology running on it.

That makes technical education part of the sovereignty equation.

Canada needs people who understand systems beneath the user interface: Linux administration, networking, cybersecurity, software development, open-source infrastructure, cloud architecture, artificial intelligence and data systems.

We should not aim simply to produce more consumers of technology. We need more people capable of building it.

A country with strong domestic technical expertise has options. It can adopt technology from around the world while retaining the knowledge necessary to integrate, audit, modify or replace it.

Without that capability, sovereignty becomes little more than a procurement label.

Buy Canadian - but don't stop there

Supporting Canadian technology companies is another important part of the equation.

Canadian-controlled providers and infrastructure can strengthen domestic capability and resilience. But a Canadian flag on a supplier's website cannot be the final test.

A Canadian company can still build a completely closed ecosystem from which customers cannot easily leave. Conversely, an international open-source project may give Canadian organizations substantial operational control.

Digital sovereignty therefore needs a broader test:

Does this technology increase Canada's ability to choose what happens next?

If the answer is yes, it strengthens sovereignty.

If adopting it makes changing direction progressively more difficult, we should at least recognize the dependency we are creating.

This is not an argument against global technology companies

Canada has benefited enormously from international technology. We should continue to.

Global technology companies bring extraordinary infrastructure, research, security expertise and innovation to the Canadian market. Attempting to recreate every major technology domestically would be economically unrealistic and technologically counterproductive.

The goal is not to replace one dependency with protectionism. It is to build resilience.

A healthy Canadian technology environment can include global cloud platforms, Canadian providers, open-source infrastructure, proprietary applications and public-sector systems.

What matters is that no single layer becomes so indispensable that Canada loses meaningful control over the layers above it.

Redundancy is normal in every other form of critical infrastructure. Digital infrastructure should not be treated differently.

Canada has an opportunity

The encouraging part is that this conversation has already begun.

The federal government is talking explicitly about digital sovereignty and examining issues including operational control, supplier concentration, continuity, vendor-neutral formats and the responsible use of open-source solutions.

Now that thinking needs to extend beyond Ottawa.

Provincial and municipal governments, universities, schools, healthcare organizations and Canadian businesses should be asking similar questions.

Not every workload needs to be sovereign. Not every application needs to be open source. Not every piece of data needs to remain inside Canada.

But every organization operating infrastructure that Canadians depend upon should understand where its dependencies are and what would happen if one of them suddenly became unavailable, unaffordable or unacceptable.

That is basic resilience planning.

Sovereignty is the ability to say no

Perhaps the simplest definition of digital sovereignty is this:

Canada should be able to say no.

No to a licensing change. No to an unacceptable contract. No to a platform that no longer meets our security requirements. No to storing certain information under a jurisdiction we consider inappropriate. No to a supplier that no longer serves Canada's interests.

Being able to say no does not mean we always will. It means the alternative exists.

Canada does not need to disconnect itself from the global technology ecosystem. We should remain deeply connected to it.

But connection and dependency are not the same thing.

The strongest position for Canada is one in which we can use the best technology the world has to offer while maintaining the skills, infrastructure, standards and alternatives necessary to remain in control of our own digital future.

That is not technological isolation. It is technological resilience.

And in an economy increasingly built on software, networks, cloud infrastructure and artificial intelligence, technological resilience is rapidly becoming another name for national resilience.