Free · published in full · current at 29 August 2026
There is no Canadian AI Act
A great deal of what you will read says otherwise, and a great deal of it is trying to sell you something. Here is what actually binds a Canadian organisation using AI today, what does not, and what is coming.
What happened to the law everyone refers to
The Artificial Intelligence and Data Act — AIDA — was part of Bill C-27. It never passed. When Parliament was prorogued in January 2025 the bill died on the order paper, and with it AIDA. Canada has no general statute governing artificial intelligence in the private sector.
This matters because a large amount of published guidance, vendor material and consultancy marketing still refers to AIDA as though it were law, or implies that a Canadian AI compliance regime exists to be complied with. If a supplier tells you that you must be compliant with Canadian AI legislation, ask them which section of which statute. There is not one.
That is not the same as saying AI is unregulated here. It is regulated, but by instruments that were written for other purposes and that apply to AI because of what AI does with data and decisions. Those are the ones that will actually be used against you.
What binds you today
- PIPEDA, federally, and its provincial equivalents. The provision that bites hardest is purpose limitation: personal information collected for one purpose cannot simply be repurposed to train or ground a model without fresh consent. “We already held the data” is not an answer.
- Quebec’s Law 25, in force since September 2023, and the only Canadian instrument with a genuine automated decision-making regime. Where a decision is based exclusively on automated processing you must tell the individual, and on request explain the personal information used, the reasons and the principal factors, and give them the chance to have it reviewed by a person. Penalties run to $10 million or 2% of worldwide turnover. If you have Quebec staff or Quebec customers, this applies to you whether or not you are in Quebec.
- The Treasury Board Directive on Automated Decision-Making, which binds federal institutions rather than you — but which reaches private suppliers through procurement. If you sell to the federal government, expect its Algorithmic Impact Assessment to arrive in your contract.
- The Voluntary Code of Conduct on advanced generative AI, which is exactly what its name says: not binding. It matters because it turns up in customer questionnaires and vendor assessments, where “we are not a signatory” is a harder conversation than it should be.
- Your own contracts, which are the instrument most likely to catch you first. Confidentiality clauses that predate generative AI rarely contemplate a third-party model, and a clause forbidding disclosure to third parties without written consent does not care that the third party is a tool.
What is coming, and how far away it is
Two bills were tabled in June 2026. Neither is law. Both are worth reading now rather than later, because the second one has an undefined scope and a very large number attached to it. A third item is open right now and closes on 23 September — a federal consultation on AI transparency, which is not a bill at all but is the clearest public signal of where this is heading.
Bill C-36 — Protecting Privacy and Consumer Data Act
The third attempt at reforming federal private-sector privacy law, and the successor to the privacy half of C-27.
- At second reading in the House of Commons. No committee stage, no report stage, no third reading.
- Sponsored by the Minister of Artificial Intelligence and Digital Innovation — a portfolio that did not previously exist, which tells you something about where this is heading.
- Two previous attempts at this reform died. Treat the timetable with scepticism, and the direction as reliable.
Bill C-34 — Safe Social Media Act
Aimed at social media, but it explicitly catches AI chatbots, and that is the part most organisations have not noticed.
- Duties would include publishing a digital safety plan, reporting on harmful content and behaviour, and a duty to act responsibly.
- For chatbots, “harmful behaviour” includes posing as human and impersonating licensed professionals — which is a live question for anyone deploying a customer-facing assistant.
- Penalties up to 5% of global gross revenue or $20 million, whichever is greater.
- The user threshold that decides who is in scope has not been set. Until it is, nobody can tell you with confidence that a small organisation is exempt.
AI transparency
Not a bill. A federal consultation on what AI transparency should require here, and the clearest signal available of the direction of travel.
- Five areas: identifying AI-generated content, telling people when they are dealing with an AI, standardised information about what a system can and cannot do, reporting serious AI incidents, and tracking what AI agents do.
- Nothing in it binds anyone. It may produce legislation, guidance, a voluntary code, or nothing at all.
- Open to any organisation, and small Canadian businesses are consistently under-represented in exactly the consultations that end up binding them.
- What each of the five would mean in practice →
What this means if you are switching on Copilot, Gemini or Claude
The absence of an AI statute is not the reassurance it appears to be. The exposure in a typical rollout is not regulatory in the first instance — it is that the tool works exactly as designed.
The thing to understand before anything else
Copilot does not break your permissions. It respects them perfectly. That is the problem.
Years of “Everyone except external users” links, broken inheritance, ownerless sites and files shared once and forgotten have been safe largely because nobody could find them. A natural-language assistant that honours those same permissions makes every one of them searchable by anyone who already technically had access. The usual first incident is not a breach and not an attack: somebody asks what the salary bands are, and gets a correct answer from a file they were never meant to read but were always entitled to.
Which is why the work happens before you switch it on, and why it is mostly not AI work at all. It is permissions, classification and retention — the unglamorous things that were already overdue.
And the newer question: staff building their own agents
The rollout question is being overtaken by a harder one. Employees are now building agents — assistants that act rather than answer, with standing access to data and the ability to take steps on their own. Most organisations that have thought carefully about which staff may use AI have not yet asked who may publish an agent, what data it may reach, whose identity it acts under, what happens to it when its author leaves, or how it is decommissioned.
Very little of this is settled, by us or anyone. We would rather say that plainly than pretend otherwise. What we can say is that treating an agent as a piece of software with no owner and no leaver process is the same mistake as the shared administrator account, and it will end the same way.
Where we stand on this
We assess and we document. We do not remediate what we assess, which means we will not be the ones cleaning up your SharePoint permissions and also the ones telling you whether they are clean. That work belongs to you or your IT provider. Our part is the gap analysis, the governance and the plan — and saying honestly when a supplier is describing a legal obligation that does not exist.
The primary sources
Every claim on this page traces to one of these. We would rather you checked us than trusted us, and if we have got something wrong we would like to know.
- Bill C-36, Protecting Privacy and Consumer Data Act — LEGISinfo, Parliament of Canada. First reading 15 June 2026; at second reading.
- Bill C-34, Safe Social Media Act — LEGISinfo. First reading 10 June 2026; at second reading. Enacts the Digital Safety Act and creates a Digital Safety Commission.
- PIPEDA — Justice Laws Website, the consolidated federal statute.
- Act respecting the protection of personal information in the private sector — LégisQuébec. The statute Law 25 amended; the automated decision provisions are at section 12.1.
- Directive on Automated Decision-Making — Treasury Board of Canada Secretariat.
- Voluntary Code of Conduct on Advanced Generative AI Systems — ISED, September 2023.
This page is not legal advice and we are not lawyers. It is a statement of what the instruments say, current at 29 August 2026, with links to the primary sources so you can check us rather than trust us. Bills move; if you are reading this long after that date, check their status before relying on it.