What Applies to AI in Canada Today?

Canada does not have a single economy-wide AI law, but AI is not unregulated. Understand the privacy, human-rights, public-sector, financial-services and sector-specific requirements that can apply today.

Canada does not have a single economy-wide AI law. That does not mean AI is unregulated.

The most dangerous Canadian AI compliance assumption is that nothing applies until Parliament enacts a dedicated AI law.

The proposed Artificial Intelligence and Data Act, commonly known as AIDA, did not become law. But privacy laws, human-rights protections, government directives, financial-services expectations and sector-specific requirements already apply to many uses of AI.

Canada’s AI governance challenge is not an absence of requirements. It is that those requirements are distributed across different laws, regulators, sectors and jurisdictions.

The practical question is not simply: Which AI law applies to our organization?
It is: Which requirements apply to this AI system, for this use, involving these people and data, in this jurisdiction?

That question must be answered for each AI system, not once for the organization as a whole.

Executive Summary

  • Canada does not currently have a comprehensive economy-wide statute dedicated to AI. AIDA was proposed as part of Bill C-27 but did not become law.
  • Existing privacy and human-rights laws can apply to AI development, procurement and use today.
  • Canada’s Directive on Automated Decision-Making and mandatory Algorithmic Impact Assessment govern qualifying administrative decision systems used by covered federal departments.
  • Quebec already has specific transparency and review requirements for certain decisions based exclusively on automated processing of personal information.
  • OSFI Guideline E-23 is final supervisory guidance and introduces enterprise-wide, risk-based model governance expectations for federally regulated financial institutions beginning May 1, 2027.
  • Healthcare, employment, financial services and other regulated activities can introduce additional requirements.
  • Bill C-36 would modernize federal private-sector privacy law, while Bill C-34 would create safety and transparency duties for regulated services that include certain AI chatbot services. Both bills remain proposed legislation.
  • Organizations should not wait for one comprehensive AI statute. They should build a system-level inventory, determine applicability, assign controls and continuously monitor for changes.

Canada’s AI governance landscape is layered

Different requirements can apply to the same AI system at the same time.

A third-party model used by a financial institution to support a customer eligibility decision, for example, may raise privacy, human-rights, model-risk, vendor-governance and consumer-protection considerations. The applicable requirements arise from what the system does, not simply from the fact that it uses AI.

Governance layer Current status When it matters
Federal and provincial privacy laws Current law When personal information is collected, used, disclosed, retained, transferred or generated through an AI system; the applicable statute depends on the organization, activity and data flow
Human-rights laws Current law When AI affects protected areas such as employment, housing or services, subject to the applicable federal or provincial regime
Quebec automated decision requirements Current law When an organization uses personal information to make a decision based exclusively on automated processing
Directive on Automated Decision-Making Mandatory federal policy for covered departments When a qualifying automated system fully or partially automates an administrative decision
OSFI Guideline E-23 Final supervisory guideline effective May 1, 2027 When a federally regulated financial institution identifies and governs models, with lifecycle requirements proportionate to model risk
Medical device requirements Current statutory and regulatory framework When machine-learning software meets the legal definition of a medical device
Bills C-34 and C-36 Proposed legislation; not law When monitoring possible future duties for regulated AI chatbot services, digital safety, privacy and significant automated decisions
AI for All and the transparency consultation Government strategy and consultation; not law When tracking possible future policy on AI transparency, synthetic content, serious incidents and AI agents

Not every requirement applies to every AI system. This is why accurate inventory, classification and applicability analysis are foundational governance capabilities.

AIDA is not law

AIDA was introduced as part of Bill C-27 on June 16, 2022. The bill passed second reading and was referred to committee, but it did not complete committee consideration, report stage or third reading.

The first session of the 44th Parliament was prorogued on January 6, 2025. Bill C-27 did not proceed, and AIDA never received Royal Assent. It is not Canadian law.

Official source: Parliament of Canada, Bill C-27

Organizations should not describe themselves as ‘AIDA compliant’ or treat the requirements from the former bill as current Canadian law.

AIDA remains relevant as regulatory history and may provide context for future policy discussions. However, a future Canadian AI bill may differ substantially in scope, terminology, oversight and obligations.

Governance programs should therefore be adaptable. They should connect requirements to individual AI systems and allow those mappings to change as legislation, regulatory guidance and system use evolve.

Privacy law already applies to AI

The Personal Information Protection and Electronic Documents Act, or PIPEDA, remains Canada’s federal private-sector privacy law. Alberta, British Columbia and Quebec have general private-sector privacy laws that have been declared substantially similar to PIPEDA. In many intra-provincial circumstances, the provincial law applies instead; PIPEDA continues to apply to federally regulated businesses and to personal information moving across provincial or national borders in commercial activities.

Official source: Office of the Privacy Commissioner of Canada, Provincial laws that may apply instead of PIPEDA

Depending on the circumstances, organizations using AI may need to address:

  • Accountability for personal information
  • Appropriate and documented purposes
  • Meaningful consent or another valid legal authority
  • Limits on collection, use, disclosure and retention
  • Data accuracy
  • Security safeguards
  • Openness and transparency
  • Individual access and correction rights
  • Oversight of service providers and third-party systems

These are not theoretical concerns.

In May 2026, Canada’s federal, Alberta, British Columbia and Quebec privacy regulators released joint findings concerning OpenAI’s development and deployment of ChatGPT using GPT-3.5 and GPT-4. Among other conclusions, the Offices found that OpenAI’s initial collection, use and disclosure of personal information from publicly accessible websites and licensed third-party sources for model training was overbroad and inappropriate. The report also addressed shortcomings involving consent, openness, accuracy, access and correction, retention and accountability.

Official source: Office of the Privacy Commissioner of Canada, Joint Investigation of OpenAI

One particularly important distinction emerged from the investigation: information that is publicly accessible on the internet is not automatically ‘publicly available’ within the meaning of Canadian privacy legislation.

The broader lesson is clear. Existing privacy law can reach training data, user interactions, model outputs that contain personal information, and the operating practices surrounding an AI system.

Human-rights obligations apply throughout the lifecycle

An AI-specific statute is not required before an automated decision can create discrimination risk.

Depending on the applicable federal or provincial regime, human-rights laws can apply when AI affects employment, lending, housing, education, healthcare and access to services. An apparently neutral model can still produce adverse outcomes for protected groups because of its training data, selected variables, proxies, thresholds or the way people rely on its output.

The Ontario Human Rights Commission and Law Commission of Ontario state that Ontario and Canadian human-rights laws apply to AI systems. Their Human Rights AI Impact Assessment recommends integrating assessment throughout the AI lifecycle and makes clear that a human-rights assessment complements, rather than replaces, privacy and other impact assessments.

Official source: Ontario Human Rights Commission, Human Rights AI Impact Assessment

A responsible assessment should consider more than aggregate model accuracy. It should examine:

  • Who may be affected
  • Whether particular groups experience different outcomes
  • Whether the data reflects the relevant population
  • Whether variables act as proxies for protected characteristics
  • Whether accommodations are available
  • How people can question or challenge a decision
  • Whether human review is meaningful
  • Whether outcomes continue to be monitored after deployment

A strong privacy assessment does not replace a human-rights assessment. The two examine different risks and should work together.

Federal rules go beyond fully automated decisions

The federal Directive on Automated Decision-Making applies to covered federal departments that use automated decision systems to fully or partially automate an administrative decision. An administrative decision is one that has the potential to affect legal rights, privileges or interests.

The Directive is broader than many organizations realize.

It can apply when:

  • A system makes the final decision
  • A human makes the final decision but relies on a system-generated score, recommendation, classification or summary
  • Automation is used at an intermediate stage of the decision process
  • The system uses rules, regression, machine learning, generative AI or another analytical technique

A human in the loop does not automatically place a system outside the Directive.

The scope is not unlimited. The government’s scope guide identifies five elements: use by a covered department; development or procurement after April 1, 2020, or a significant later modification; use within an administrative decision-making process; replacement or assistance of human judgment; and use in production. Research and experimentation that do not affect real clients are outside the Directive, although other privacy, security and information-management requirements can still apply.

Official source: Government of Canada, Scope of the Directive on Automated Decision-Making

Covered systems must complete the federal Algorithmic Impact Assessment. The assessment contains 65 risk questions and 41 mitigation questions and determines an impact level that scales the applicable requirements.

Official source: Government of Canada, Algorithmic Impact Assessment

The Directive does not generally regulate private-sector organizations. However, technology providers serving covered federal departments may encounter its documentation, testing, transparency and evidence requirements through procurement and contract processes. That is a practical consequence of the federal policy, not a direct extension of the Directive to the private sector.

Quebec already regulates certain automated decisions

Quebec’s private-sector privacy legislation contains specific requirements when an organization uses personal information to make a decision based exclusively on automated processing.

The organization must inform the affected person about the automated nature of the decision. On request, it must also provide information about:

  • The personal information used
  • The reasons and principal factors or parameters behind the decision
  • The individual’s right to correct the personal information used

The person must also have an opportunity to submit observations to someone capable of reviewing the decision.

Official source: Quebec Private Sector Privacy Act, section 12.1

Quebec’s public-sector access and privacy statute contains a substantially parallel rule for public bodies in section 65.2.

Official source: Quebec public-sector access and privacy statute, section 65.2

This requirement is narrower than a general AI law. It is triggered by the use of personal information and a decision based exclusively on automated processing. Nevertheless, it demonstrates why organizations need to record where an AI system operates, what role it plays in a decision and whether meaningful human involvement exists.

Financial institutions should prepare now for OSFI Guideline E-23

OSFI Guideline E-23 establishes principles-based expectations for enterprise-wide model risk management at all federally regulated financial institutions. The final guideline becomes effective on May 1, 2027.

Official source: OSFI, Guideline E-23, Model Risk Management

E-23 requires a risk-based approach. Institutions should identify and track models in use or recently decommissioned, including vendor and third-party models, but not every identified model must undergo the same lifecycle governance. Models with non-negligible inherent risk belong in the enterprise model inventory.

For those models, the inventory should be:

  • Accurate and current
  • Subject to robust controls
  • Updated when a model is modified
  • Updated when its use, risk rating or performance changes
  • Inclusive of relevant vendor and third-party models
  • Capable of supporting management and regulatory reporting

Risk ratings should use clear, measurable criteria. OSFI identifies qualitative factors such as business use or purpose, model complexity or autonomy, reliability of data inputs, customer impacts and regulatory risk, alongside quantitative factors such as potential operational, security or financial impacts.

This is an important shift from static model documentation to continuous governance. Performance deterioration, data changes, model modifications, infrastructure changes or a new use can all require reassessment.

An annual review alone is not enough when the system itself can change throughout the year.

Healthcare AI can trigger medical device requirements

Not every healthcare AI tool is a medical device. Classification depends on the software’s intended use and whether it meets the applicable legal definition.

Where a machine-learning system qualifies as a medical device, Health Canada’s regulatory framework can introduce requirements related to classification, licensing, safety, effectiveness, clinical evidence, transparency and lifecycle changes.

Health Canada’s current pre-market guidance, dated April 1, 2026, addresses new and amended applications for Class II, III and IV machine-learning-enabled medical devices. Machine-learning-enabled devices can range from Class I to Class IV, but the application guidance is directed to Classes II, III and IV. It addresses intended use, patient population, data representativeness, clinical degree of autonomy, performance monitoring, transparency and predetermined change control plans.

Official source: Health Canada, Machine Learning-Enabled Medical Devices

This illustrates a broader principle: sector classification can be as important as AI risk classification.

The use case matters more than the technology label

The same underlying model can create very different governance requirements depending on how it is used.

Consider a general-purpose language model used in four settings:

  • Drafting an internal meeting summary
  • Screening job applicants
  • Recommending whether a customer qualifies for credit
  • Supporting a federal benefits eligibility decision

The underlying technology may be similar, but the affected people, legal context, potential impact and evidence requirements are not.

This is why classifying a vendor or model once is insufficient. Governance should be performed at the AI-system or use-case level.

At a minimum, each system record should identify:

  • Business purpose and intended use
  • System owner and accountable decision-maker
  • Model, vendor and third-party dependencies
  • Data used and generated
  • People and groups affected
  • Role in the decision process
  • Level of human involvement
  • Jurisdictions and sectors
  • Potential impacts
  • Applicable laws, policies and frameworks
  • Required controls and evidence
  • Monitoring and reassessment triggers

A practical governance operating model

Governance information should move with the AI system throughout its lifecycle.

Intake

Create a structured record for the AI system. Capture its purpose, owner, users, affected stakeholders, data, vendors, jurisdictions and decision context.

Assess

Classify the system’s risk and determine which legal, regulatory, policy and internal requirements apply. Record the rationale, not only the result.

Approve

Assign controls, evidence requirements, owners and approval steps based on the system’s use and risk.

Monitor

Track changes in the model, data, vendor, use case, affected population, control status and performance. Define events that require reassessment.

Report

Generate management reporting, audit evidence and regulatory information from the same governance record rather than reconstructing it later.

The lifecycle is not strictly linear. Monitoring can reveal a change that sends the system back for assessment and approval.

What executives should do now

Organizations do not need to wait for another federal bill before improving AI governance.

A practical first 90-day agenda should include:

1.Define the governance perimeter

Include internally developed models, embedded AI features, third-party AI services, generative AI and agentic systems.

2.Build the initial inventory

Start with systems that affect customers, employees, patients, citizens, financial decisions or other high-impact processes.

3.Perform applicability triage

Determine which privacy, human-rights, public-sector, financial-services, healthcare and provincial requirements may apply to each system.

4.Assign accountable owners

Every system should have a business owner, a technical owner and clearly identified governance responsibilities.

5.Connect requirements to controls and evidence

Do not maintain regulations, controls and system records in separate documents that cannot be reconciled.

6.Define reassessment triggers

Examples include a new use, new population, material model change, vendor update, performance decline, incident, data change or regulatory development.

7.Bring procurement into the process

Third-party AI should be assessed before purchase or deployment, not discovered later during an audit or incident.

What is changing next

Bill C-36 was introduced on June 15, 2026 and proposes the Protecting Privacy and Consumer Data Act. For automated decision systems, the bill would require a public general account of uses that make predictions, recommendations or decisions about individuals with a legal or similarly significant effect. On request, an affected individual would be entitled to an explanation identifying the type and source of personal information used and the reasons or principal factors behind the result, plus an opportunity to make written representations to an employee able to review it. As of August 24, 2026, Bill C-36 is at second reading in the House of Commons and is not law.

Official source: Parliament of Canada, Bill C-36

Bill C-34, the proposed Safe Social Media Act, was introduced on June 10, 2026. It would enact a Digital Safety Act covering regulated social media services, regulated AI chatbot services and certain other online services. The proposed regime includes child-protection, responsible-operation and transparency duties, but important scope details would depend on regulations. As of August 24, 2026, Bill C-34 is also at second reading in the House of Commons and is not law.

Official source: Parliament of Canada, Bill C-34

The federal government launched Canada’s National Artificial Intelligence Strategy, AI for All, on June 4, 2026. The strategy is government policy, not legislation. In July, the government opened a consultation on detecting AI-generated content, identifying interactions with AI, providing understandable information about AI systems, tracking serious incidents and tracking the activities and interactions of AI agents. The consultation is open from July 23 to September 23, 2026.

Official source: Government of Canada, AI Transparency Consultation

These proposals and policy initiatives may influence future obligations, but they should not be confused with current law.

The correct response is neither to ignore them nor to treat them as final requirements. Organizations should monitor their development and maintain governance processes that can incorporate new requirements without rebuilding the entire program.

The FairFuture AI Perspective

Canada’s AI governance landscape is not empty. It is fragmented.

The defensible unit of governance is the AI-system record. The system’s purpose, risk, applicable requirements, decisions, controls, evidence and monitoring history should remain connected throughout its lifecycle.

This creates a governance foundation that can respond to current Canadian requirements while remaining ready for future legislation.

FairFuture AI is building an enterprise AI governance and compliance platform designed to centralize AI governance, simplify compliance and maintain continuous oversight through five connected capabilities.

Intelligent Intake

Turn project documents or a plain-language description into a structured AI system record, creating a centralized inventory of internal, third-party and agentic AI.

Risk Classification

Classify each AI system based on its purpose, context, impact, affected stakeholders, jurisdiction and applicable requirements, with a clear rationale for every result.

Compliance Automation

Translate regulatory requirements and internal policies into reusable controls, owners, approvals, evidence requests and automated workflows.

Continuous Monitoring

Track changes in systems, models, data, vendors, controls and incidents, with alerts when review or action is required.

Evidence & Reporting

Capture evidence as governance work happens and generate dashboards, audit reports and regulator-ready packages through standard views or natural-language requests.

Now onboarding early-access partners across financial services, government and healthcare.

Talk to us about your organization’s Canadian AI governance priorities, regulatory requirements or readiness challenges.

Official Sources