For Canadian boards, owners and executives
The questions arrive long before the incident does
A customer sends a security questionnaire. An insurer asks what has changed since last renewal. A director wants to know whether anybody checked the AI tool before it was switched on. None of these are technical questions. All of them need an answer somebody outside your business will believe.
Will not sign until the questionnaire comes back clean.
Prices the renewal on what you can show, not what you say.
Carries the duty, and is the last to find out.
Two Canadian laws most businesses have not read
You are already required to do more than you think
The federal privacy law
It governs personal information handled in the course of commercial activity across most of Canada.
What it actually asks of you: keep a record of every privacy breach, including the ones you decided were harmless, for two years, and produce them for the Privacy Commissioner on request. Where a breach creates a real risk of significant harm, report it and tell the people affected as soon as feasible.
Most Canadian businesses keep no such record at all.
The one that already covers AI
Canada has no AI Act. Quebec did not wait for one.
What it actually asks of you: since September 2023, if a decision about a person is made exclusively by automated processing, you must tell them. On request you must say what personal information you used and the reasons and main factors behind it, and let them put their case to a human who is in a position to change the answer.
That describes a great deal of what companies are currently calling AI.
Neither of these needs a new law to reach you. They are in force today.
What is actually coming, and when
The dates already in your diary
Four things that reach Canadian organisations. Two are in force today. One is open now and closes this month. One has passed into law and still binds nobody.
Automated decisions about people
Law 25, section 12.1. Where a decision about a person is made exclusively by automated processing, you must tell them so at the time you tell them the decision. They may then ask what personal information was used, and the principal factors and parameters behind it.
It attaches whether or not anybody in your organisation calls the system AI, which is why it catches people out.
The board question: which decisions about people do we already make with no human in the loop, and could we name them today?
Certification in the defence supply chain
The Canadian Program for Cyber Security Certification. Level 1 was announced on 14 April 2026 and applies to select defence contracts, with suppliers completing and attesting to the Level 1 criteria. During the introductory phase it is required on contract award rather than at the bidding stage.
It is the first of three levels. No dates have been published for the other two, and anyone quoting you one is guessing.
The board question: do we sell to anyone who sells to defence — and if that attestation landed on us, who here would sign it?
The AI transparency consultation
Not a bill. The federal government is asking what AI transparency should require: identifying AI-generated content, telling people when they are dealing with a machine, standardised information on what a system can and cannot do, reporting serious AI incidents, and tracking what AI agents do.
Submissions need not be long, and small Canadian businesses are consistently under-represented in exactly the consultations that end up binding them.
The board question: if we had to describe where AI touches decisions about people here, could anyone produce that list? What each of the five would mean →
The Critical Cyber Systems Protection Act
Part 2 of Bill C-8. It is law, and it binds nobody yet. The substantive obligations begin on a day to be fixed by the Governor in Council. The incident reporting window is to be set by regulation at no more than 72 hours. The penalties, up to $15 million for an organisation, are ceilings still to be fixed.
Both schedules — including the one naming which classes of operator are covered — are blank.
The board question: is anyone selling us readiness for a schedule nobody has written? Where the start date will appear →
Two further bills, C-36 and C-34, were introduced in June 2026 and sit at second reading. Neither is law. What actually governs AI in Canada →
Checked on 9 September 2026. We date this section, because a governance claim without a date is not a governance claim.
How we work
What we will not tell you
We will not tell you that the Critical Cyber Systems Protection Act requires anything of you today. It does not. It received Royal Assent on 16 June 2026, and its obligations begin on a day the Governor in Council has not yet fixed, against schedules that are still blank.
You will find Canadian firms selling readiness for it as though it already binds you. When it starts, we will tell you what changed, what it asks of you, and by when. Not before.
The same rule covers everything else on this site. If we say a duty applies to you today, we will show you where it comes from and when it started. Where we are not sure, we will say that instead — and where a date here turns out to be wrong, tell us and we will correct it and say what changed.
What we do
Five ways in. Every one ends with something your board can act on.
If you are an owner rather than a board, and there is nobody here whose job this is, start here instead — most of what you need is free.
AI Deployment Review
Before you switch it on: what the deployment would actually expose, the oversight you need around it, and whether Quebec's Law 25 automated decision rules reach you.
From CAD $6,000Board & executive session
A facilitated half-day, and the evidence pack that proves it happened.
From CAD $4,500Cyber simulation
Find out what your people do before it matters. Nothing goes near live systems.
From CAD $5,000Virtual CISO
Senior security judgement without the hire, and someone accountable for it.
From CAD $3,500 / monthIndependent assessment
A dated report against a defined control set that you can hand to a customer or an insurer.
Typically CAD $6,000–CAD $9,000Before you talk to anyone
Where do you stand?
Ten questions about whether you could show it, not whether you feel secure. Five minutes, no email required, and nothing you answer leaves your browser. You get the gaps back in the order we would fix them.
No mystery scoring
The control set, published in full
Thirty-six governance controls, what evidence satisfies each one, and what it maps to in Canadian law. We publish it so you can see what is being asked of you before you engage us, or work through it yourself if you would rather not.
Free, and nothing to sign up for
Where to watch
The five sources worth following if you are accountable for this in a Canadian organisation, and the board question that goes with each. Canadian regulators first, one international source, no newsletter.
Recognise any of these
What bad looks like
The eight failures we keep finding in Canadian organisations — the supplier nobody assessed, the account with no second factor, the backup nobody restored. Written as patterns rather than named companies, with the question a board should ask about each one.
Why anyone believes our answer
We either help you fix it, or we assess you. Never both.
An assessment is only worth something if the person doing it has no stake in the result. If we have designed your controls or written your policies, we will not then turn round, assess you and tell the world you passed.
It costs us work. We think that is the point.
Latest briefings
What changed, what it means, and the question a Canadian board should ask next.
Start with a conversation
Tell us what has been asked of you and who is asking. We will tell you what we think it needs, and whether that is us. The first conversation is free and there is no obligation at the end of it.
Tell us about your organisation+1 647 361 2215
Canada Cyber-Safe is based in Toronto. We work with Canadian organisations only.