Skip to main content

The AI transparency consultation has closed. What a board should do while Ottawa decides

The federal AI transparency consultation closed on 23 September. It binds nobody, but its five questions describe records every organisation should already keep. Four things worth doing this quarter.

The federal consultation on AI transparency closed on 23 September 2026. It is not a bill and it binds nobody. But it tells you, in the government’s own words, which questions Canadian organisations will be asked next, and every one of them can be answered from records you either keep already or should.

The consultation was launched on 23 July 2026 by the Minister of Artificial Intelligence and Digital Innovation, and the discussion paper asked about five things:

  • identifying content that AI has generated or altered;
  • telling people when they are dealing with an AI system rather than a person;
  • accessible information about what a system can and cannot do;
  • tracking and reporting serious AI incidents;
  • recording what AI agents do, when, and on whose authority.

The government has said only that the feedback “will inform the government’s next steps”. There is no response date and no draft text. Anyone telling you what the rules will say is guessing.

Why waiting is the wrong plan

All five topics describe records. Whatever form the rules take, the organisations that cope will be the ones that can already say which AI systems they run, where those systems touch customers or staff, and what happened when something went wrong. None of that needs a law to be worth having, and most of it is already expected by customers’ security questionnaires and by insurers.

There is also law in force today. In Quebec, Law 25 has required since September 2023 that people are told when a decision about them is made exclusively by automated processing. And Bill C-36, which would replace much of PIPEDA, is at second reading in the House of Commons. It is not law, and it may change, but it points the same way.

Four things worth doing this quarter

  • Write the register. A one-page list of the AI systems and features in use, including the ones switched on inside products you already pay for, with an owner for each.
  • Mark where AI meets people. Which of those systems produce content that customers see, or take part in decisions about customers or staff. That is where disclosure duties will land first.
  • Decide what an AI incident is. Add it to your incident procedure: a wrong answer that reached a customer, a leak through an assistant, an agent acting outside its authority. Record them from now, even if nobody asks yet.
  • Log what agents do. If anyone has built an agent that acts rather than answers, make sure its actions are logged under an identity someone owns.

Our free Copilot readiness check and AI acceptable use policy template cover most of the groundwork. What each of the five proposals would mean in practice is set out in What Canada is asking about AI transparency.

The question your board should ask

“If the government’s response arrived tomorrow, could we produce a dated list of the AI we use and where it touches people?”

If the answer is no, that is the first job, and it costs an afternoon, not a programme. We never assess work we have advised on, and we never sell the fix for anything we assess, so if you want a second pair of eyes on the list, the first conversation is free.

Checked on 30 September 2026 against the Government of Canada announcement and discussion paper, and LEGISinfo.

Leave a Reply

Your email address will not be published. Required fields are marked *

Standards we assess against

ISO/IEC 27001:2022 · ISO/IEC 27701:2025 · ISO 9001:2015 · ISO/IEC 42001:2023 · ISO/IEC 23894:2023 (guidance) · ISO/IEC 42005:2025 (guidance)

Français : La première heure — rédigé en français, pas une traduction automatique.

Canada Cyber-Safe is an independent assessment practice. We are not a certification body and we do not issue certificates.