A Toronto software company's metered API is called, on a typical afternoon, from customers or automated systems in over thirty countries within the space of an hour. Each call generates revenue instantly, settled the moment it occurs. Somewhere in that hour, the company likely crossed a foreign VAT or GST registration threshold it has no process for detecting in real time, in a jurisdiction whose consumption tax rules were finalized years before anyone building the company's software imagined revenue could arrive this way.

Key Takeaway

International tax law's oldest organizing concept, the permanent establishment doctrine, ties a country's right to tax a business to that business's physical presence within its borders. This concept, largely unchanged since it evolved for brick-and-mortar commerce, does not map cleanly onto a business whose only connection to a market is instant, continuous, machine-metered API traffic. The OECD's proposed fix, Pillar One's Amount A, reallocates taxing rights to market jurisdictions regardless of physical presence, but currently applies only to roughly 100 of the very largest multinationals globally and has stalled well past its original implementation deadline. For the vastly larger population of small and mid-sized software and API businesses, the real, live compliance burden runs through a fragmented, jurisdiction-by-jurisdiction patchwork of VAT and GST digital-economy registration thresholds, which instant, continuous API revenue makes genuinely difficult to monitor in real time using processes designed for discrete, invoiced sales.

The Doctrine Under Strain

The permanent establishment (PE) concept has anchored international tax law for the better part of a century, conditioning a country's right to tax a foreign business's profits on that business maintaining a fixed place of business, an office, a factory, a dependent agent, within its borders[1]. Current academic analysis frames the underlying problem precisely: this framework evolved in an era of brick-and-mortar commerce and manufacturing, where production, sales, and service delivery were straightforwardly tied to tangible assets and physical locations, and it strains badly against digital business models capable of generating substantial value in a jurisdiction with no physical footprint there at all[1]. A metered API is, in this sense, the purest possible expression of the problem the PE doctrine was never built to handle: it has no storefront, no local staff, no local server necessarily, and no discrete, negotiated sales transaction a tax authority could point to as the moment value was created within its borders. Value is generated continuously, in whatever jurisdiction the calling system happens to be, at whatever moment the call happens to fire.

The Significant Economic Presence Alternative

The alternative concept gaining the most traction as a replacement for pure physical-presence nexus is "significant economic presence," an idea traceable to the OECD's 2015 BEPS Action 1 final report and subsequently advanced by proposals including one from the G24 group of developing economies[2]. Under this approach, taxable nexus in a jurisdiction could be established through factors entirely independent of physical presence: revenue derived from users or customers in that jurisdiction, the number of local users or digital contract conclusions, and localized digital-interface factors such as a local-language, local-currency-priced version of a service[2]. A business with genuinely zero physical activity in a jurisdiction could, under this framework, still be deemed to have significant economic presence there, and therefore a taxable nexus, purely on the strength of revenue and digital-engagement factors[2]. This is the conceptual foundation underneath essentially every digital services tax enacted globally, and increasingly underneath VAT and GST digital-economy registration rules as well, discussed below.

Pillar One, And Its Real Scope

The OECD's own proposed multilateral solution, Pillar One's Amount A, would reallocate a portion of the residual profits of the largest, most profitable multinationals to the market jurisdictions where their customers and users are located, regardless of physical presence, specifically to provide a coordinated alternative to the patchwork of unilateral digital services taxes covered elsewhere in this publication[3]. It is important to be precise about scope, because this is the detail most coverage of Pillar One glosses over: it applies only to multinational enterprises with global turnover above €20 billion and a profitability margin above 10%, reallocating taxing rights over approximately 100 of the world's largest and most profitable companies globally[4]. The nexus threshold within that scope is itself instructive for understanding the broader direction of travel: under the draft rules, nexus in a market jurisdiction is triggered once an in-scope multinational derives at least €1 million in revenue from that jurisdiction over a 12-month period, dropping to €250,000 for smaller jurisdictions with GDP under €40 billion[4]. That is a revenue-based, presence-independent nexus test, exactly the kind of threshold a continuously metered, cross-border API business generates almost by default, once it has any meaningful customer base outside its home jurisdiction. Pillar One itself, however, does not apply to the vast majority of software and API businesses, which fall far below its €20 billion scope threshold.

Why Pillar One Stalled

The Multilateral Convention to Implement Amount A of Pillar One was released for signature on October 11, 2023, with an OECD economic impact assessment estimating it would reallocate taxing rights over roughly USD 200 billion in profits annually, generating an estimated USD 17 to 32 billion in additional annual global tax revenue[5]. As discussed elsewhere in this publication in the context of the digital services tax reversal saga, the extended deadline for adoption and signature, originally set for June 30, 2024, passed without the necessary agreement, and Pillar One remains, as of this writing, unimplemented[6]. This matters directly for the API tax crisis this article addresses: the one coordinated, multilateral attempt to replace physical-presence nexus with a workable digital-era alternative has stalled, leaving the fragmented patchwork of unilateral national and sub-national measures discussed below as the operative reality for the foreseeable future, not a temporary bridge to a cleaner system arriving soon.

The Academic Case For Abandoning Physical Presence Entirely

Beyond the specific OECD proposals discussed above, a broader academic literature has developed arguing the physical-presence standard should be abandoned as an organizing principle for digital-era taxation entirely, rather than merely supplemented with digital-specific carve-outs. Olbert and Spengel's influential tracing of the conceptual history of this debate argues that the permanent establishment concept's reliance on physical presence was always a proxy for a deeper underlying question, where economic value is actually created, and that the proxy has simply stopped tracking the underlying question accurately as production and service delivery have decoupled from physical location[1]. This framing is useful for a business owner trying to understand why the compliance landscape feels so unsettled: the debate is not a minor technical dispute over where to draw a line, but a genuine disagreement about whether the line-drawing exercise itself, physical presence as the test, is fundamentally the wrong question for a business model like a metered API to be answering at all.

The VAT/GST Patchwork That Actually Applies To You

For the overwhelming majority of API and software businesses, far below Pillar One's scope threshold, the live, operative compliance burden runs through value-added and goods-and-services tax registration rules for digital and remote services, a body of law that has expanded dramatically over the past decade specifically to capture exactly the kind of borderless digital revenue this article describes. Roughly half of all European OECD countries now have some form of digital services tax[7], but the more universally applicable obligation is VAT and GST registration itself: dozens of countries, including Canada under its own GST/HST digital economy rules discussed elsewhere in this publication, now require a non-resident digital service provider to register and begin collecting consumption tax once revenue from that jurisdiction crosses a defined threshold, commonly in the range of $20,000 to $100,000 in local currency terms depending on the specific country, entirely independent of whether the provider has any physical presence there at all.

The practical scale of this obligation for a genuinely global API business is easy to understate until it is stated plainly: a business with meaningful customer traction in even twenty to thirty countries is, in principle, tracking twenty to thirty separate revenue thresholds, in twenty to thirty separate currencies, against twenty to thirty separate registration and filing regimes, each with its own effective date, its own definition of what counts as in-scope digital revenue, and its own filing cadence once registration is triggered.

The Threshold-Monitoring Problem

This is where the "instant" and "continuous" character of API-driven revenue creates a genuinely distinct operational problem, not merely a larger version of a familiar one. A conventional cross-border sales process, a negotiated contract, an invoiced shipment, a signed subscription agreement, generates a discrete, humanly-noticeable event: someone in the business is aware, in real time, that a new customer relationship in a new country has begun, which creates a natural trigger for someone to ask whether that country's tax registration obligations now need attention. Metered API revenue generates no equivalent human-noticeable event. A developer or an automated system in a country the business has never had a sales conversation with can begin calling the API and generating billable revenue with literally no human at the API-providing business aware it has happened, until, potentially, a compliance review or an audit surfaces it much later, by which point a registration threshold may have been crossed and un-remedied for a period long enough to generate real penalty and interest exposure.

Instant Revenue Versus Invoiced Revenue

It is worth being precise about why existing compliance processes, built for invoiced or subscription revenue, do not simply extend to this pattern by analogy. An invoiced or subscription revenue stream is inherently batched and reviewable: a finance team can run a monthly or quarterly report of revenue by customer billing country and check it against known thresholds, because the underlying transactions are few enough, and slow enough, to review this way. A continuously metered API generating revenue from potentially thousands of distinct calling systems across dozens of countries in a single day produces a review burden of a fundamentally different order, directly analogous to the general ledger volume problem discussed elsewhere in this publication's treatment of machine-to-machine transaction architecture. The threshold-monitoring problem this article describes and the general ledger architecture problem discussed in that companion piece are, in an important sense, the same underlying issue, viewed from two different functional angles: both stem from transaction volume and velocity that outpaces the periodic, batch-oriented review processes most finance functions were built around.

The View From Canada Specifically

Nothing about this dynamic is unique to software companies in the abstract; it applies with equal force to any Canadian business whose product is delivered as a service consumed instantly, continuously, and remotely, which is an accurate description of a metered API by definition.

For a Canadian API or software business, this crisis runs in both directions simultaneously, and both deserve explicit attention. Outbound, a Canadian business selling metered API access globally faces exactly the fragmented VAT and GST threshold-monitoring problem described throughout this article, in every foreign jurisdiction its traffic reaches. Inbound, the same Canadian business is itself the "foreign" provider from the perspective of every other country's tax authority, subject to their significant-economic-presence-style nexus tests the moment its revenue from that jurisdiction crosses their specific threshold, regardless of the fact that the business is headquartered in, and primarily thinks of itself as operating from, Canada.

This publication's separate treatment of Canada's own GST/HST digital economy registration rules addresses the domestic half of this picture, the rules a foreign provider must follow to sell into Canada. This article's focus is the mirror image: the compliance burden a Canadian provider accumulates selling outward, into dozens of other jurisdictions each running their own version of the same significant-economic-presence logic Canada itself applies to foreign digital providers selling here. A Canadian business that has carefully built GST/HST compliance for its own domestic obligations, while overlooking that it faces an equivalent, multiplied-by-dozens-of-countries obligation on its outbound revenue, has solved only half of a symmetrical problem.

A Worked Case: The API That Crossed Thirty Borders Before Lunch

Return to the Toronto software company from the opening. A retrospective compliance review, prompted by an unrelated financing due diligence process, found that API revenue from a European jurisdiction with a relatively low digital-services VAT registration threshold had crossed that threshold roughly eight months earlier, entirely through organic, machine-driven API traffic from a handful of automated integrations the sales team had never been directly involved in setting up. No single event had ever flagged this internally; revenue had simply accumulated, call by call, across a threshold nobody was actively monitoring in real time.

The remediation involved retroactive registration, an assessment of penalty and interest exposure for the intervening period, an assessment mitigated in this case by the jurisdiction's voluntary disclosure provisions, which reduced but did not eliminate the exposure, and the far more valuable outcome: building an automated, threshold-monitoring process going forward that queried revenue by calling-system country of origin on a weekly rather than quarterly cadence, specifically because quarterly review had proven too slow to catch a threshold crossing before meaningful exposure had already accumulated.

The Numbers At A Glance

For quick reference: Pillar One Amount A applies only to multinationals with global turnover above €20 billion and profitability above 10%, roughly 100 companies worldwide. Its nexus threshold within that scope is €1 million in market-jurisdiction revenue over 12 months, dropping to €250,000 for smaller economies. The Multilateral Convention was released for signature October 11, 2023; the extended implementation deadline of June 30, 2024 passed without agreement, and Pillar One remains unimplemented as of this writing. Individual VAT and GST digital-economy registration thresholds, the rules that actually apply to most smaller API businesses, commonly range from roughly $20,000 to $100,000 in local currency terms, varying by jurisdiction, and require active, ongoing monitoring rather than a one-time assessment.

What Actually Mitigates This

Drawing directly from the mechanism described above, several concrete practices follow for any business with, or anticipating, meaningfully international API or software revenue. Increase the monitoring frequency of revenue-by-jurisdiction reporting to match the actual velocity of the underlying revenue, weekly or even daily automated threshold checks rather than quarterly manual review, specifically because the gap between threshold crossing and detection is what converts a manageable registration task into a costly retroactive remediation. Build jurisdiction detection into the billing infrastructure itself rather than relying on a downstream finance review to reconstruct it, since IP geolocation, billing address, and payment method data are all available at the point of transaction and far cheaper to capture then than to reconstruct retroactively across months of historical API logs. Maintain a current, actively updated threshold reference table covering every jurisdiction generating meaningful revenue, since these thresholds themselves change periodically as countries update their digital-economy tax rules, and a static, one-time compliance assessment goes stale exactly as quickly as the underlying law does. Engage cross-border tax expertise proactively rather than reactively, since the cost of an ongoing monitoring relationship is, in essentially every case we have observed, materially lower than the cost of a retroactive multi-jurisdiction remediation discovered during financing due diligence or an audit.

The Machine-Driven Wrinkle

A final, forward-looking complication deserves mention, connecting directly to this publication's broader treatment of agentic commerce. As the machine-to-machine payment infrastructure discussed elsewhere in this series matures, an increasing share of cross-border API revenue will originate not from a human developer in a given country integrating a service, but from an autonomous AI agent, itself potentially operating on behalf of a principal located in an entirely different jurisdiction, making the call. This raises a genuinely unresolved question current international tax doctrine has no settled answer for: for purposes of establishing significant economic presence or a VAT/GST registration threshold, is the relevant jurisdiction the location of the calling agent's infrastructure, the location of the human or business the agent is ultimately acting on behalf of, or some third test not yet articulated in any current framework? No OECD guidance, national tax authority ruling, or academic consensus currently answers this question definitively. Businesses operating API infrastructure that agentic buyers are increasingly likely to call should treat this as a live, unresolved compliance risk to monitor as guidance develops, rather than an settled question with a clear answer today.

Why This Matters Beyond Just The Registration Itself

It is worth stating a further, less obvious consequence directly, because it changes the urgency calculus for a business tempted to treat this as a low-priority compliance backlog item. A pattern of accumulated, un-remedied cross-border VAT and GST exposure does not merely sit quietly as a contingent liability until discovered; it surfaces, almost inevitably, precisely at moments when a business can least afford the distraction, financing due diligence, an acquisition process, or a foreign tax authority's own automated detection systems, which are themselves increasingly sophisticated at identifying unregistered digital providers through payment processor data-sharing arrangements and cross-border information exchange agreements between tax authorities. A business that discovers its own multi-jurisdiction exposure proactively, through the kind of monitoring process this article recommends, controls the timing, sequencing, and framing of remediation. A business that has that exposure surfaced by a counterparty's due diligence team, or by a foreign tax authority's own enforcement action, controls none of it, and typically pays materially more in penalties, professional fees, and deal friction as a direct result of the timing alone, independent of the substantive tax liability being identical in both scenarios.

The Limits Of This Analysis

Several caveats matter. International tax law in this area is genuinely unsettled and moving on multiple fronts simultaneously, Pillar One's implementation status, individual countries' VAT and GST digital-economy thresholds, and emerging guidance on agentic and AI-driven transactions specifically, and the specific figures and status described in this article reflect a snapshot as of mid-2026 that should be verified against current sources before any compliance decision is made. This article addresses general international tax principles and patterns rather than the specific rules of any individual jurisdiction, and a business with meaningful multi-jurisdiction API revenue requires jurisdiction-specific advice from qualified international tax counsel, not a general framework article, to actually determine its current obligations. Finally, the agentic-buyer jurisdiction question raised above is presented explicitly as an open, unresolved issue rather than a settled legal position, because no settled position currently exists in any jurisdiction examined for this article.

Frequently Asked Questions

Does Pillar One apply to my small or mid-sized software business?
Almost certainly not directly. Pillar One's Amount A applies only to multinational enterprises with global turnover above €20 billion and a profitability margin above 10%, roughly 100 companies worldwide. It also remains unimplemented as of this writing. The obligations that actually apply to most API and software businesses run through individual countries' VAT and GST digital-economy registration rules instead.
Why is metered API revenue harder to monitor for tax purposes than conventional sales?
Conventional cross-border sales generate a discrete, humanly-noticeable event when a new customer relationship begins in a new country. Continuously metered API revenue can accumulate from automated systems with no human at the provider business ever aware a new jurisdiction's threshold is being approached, until a periodic compliance review, if one occurs, surfaces it, potentially long after the threshold was crossed.
What is the "permanent establishment" doctrine and why does it matter here?
It is the traditional international tax law concept that ties a country's right to tax a foreign business to that business maintaining a physical presence within its borders. It evolved for brick-and-mortar commerce and does not map cleanly onto a business whose only connection to a market is continuous, machine-driven digital traffic with no physical footprint there at all.
What's the single most useful practical fix?
Increasing the frequency of revenue-by-jurisdiction monitoring to match the actual velocity of the underlying revenue, weekly or automated daily checks rather than quarterly manual review, since the gap between a threshold being crossed and being detected is what converts a manageable registration task into a costly retroactive remediation.
How does an AI agent making API calls on someone else's behalf affect tax jurisdiction?
This is a genuinely open question with no settled answer in current international tax doctrine. Whether the relevant jurisdiction for nexus purposes is the calling agent's infrastructure location, the location of the party the agent is acting for, or some other test has not been resolved by any OECD guidance or national tax authority ruling as of this writing.
IB

About The Insight Bureau Research Desk

The Insight Bureau is GSH Financial's research publication, written for Canadian business owners and the students who will eventually advise them. This article draws on current OECD publications and international tax scholarship; see References below.

References

  1. Frontiers in Political Science. (2025, August 11). New Rationales for Taxing the Digital Economy: Lessons from the OECD Pillar One Consultations. frontiersin.org/.../new-rationales-taxing-digital-economy
  2. Tax Foundation. Digital Taxation Around the World, citing the G24 proposal following OECD BEPS Action 1 (2015). taxfoundation.org/research/all/global/digital-taxation
  3. OECD. Reallocation of Taxing Rights to Market Jurisdictions. oecd.org/en/topics/reallocation-of-taxing-rights-to-market-jurisdictions
  4. Bloomberg Tax Research. (2025, March 24). OECD Inclusive Framework. pro.bloombergtax.com/.../beps-oecd-taxation-digital-economy
  5. KPMG UK. (2023, October). New Multilateral Convention to Implement Amount A of Pillar One Released. kpmg.com/uk/.../amount-a-of-pillar-one-released
  6. Baker McKenzie. (2025, March). Navigating the Digital Tax Landscape. bakermckenzie.com/.../navigating-the-digital-tax-landscape
  7. Tax Foundation Europe. (2026, May 4). Digital Services Taxes in Europe, 2026. taxfoundation.org/data/all/eu/digital-services-taxes-europe

This article discusses general international tax principles and current OECD status and is provided for general informational purposes. It is not tax advice for any specific business. International VAT, GST, and digital services tax obligations are highly jurisdiction-specific and change frequently; confirm your own multi-jurisdiction compliance position with qualified international tax counsel.