Canada - AI Regulation (Bill C-27)

Artificial Intelligence and Data Act (AIDA) (proposed, part of Bill C-27)

Canada

RAI-CA-NA-AIDAPXX-2022
Withdrawn(Failed, vetoed or pulled)
BillGovernance and OversightRisk Management
Export PDF

The Artificial Intelligence and Data Act (AIDA) was proposed as Part 3 of Bill C-27 (Digital Charter Implementation Act, 2022) to create a risk-based framework for private‑sector AI systems in interprovincial and international trade. It would have required measures for high‑impact AI systems to identify, assess and mitigate harms and biased outputs, introduced an AI and Data Commissioner role, and created administrative and criminal offences for certain AI-related misconduct.

Summary

The Artificial Intelligence and Data Act (AIDA) was introduced on June 16, 2022 as Part 3 of Bill C-27 (Digital Charter Implementation Act, 2022). AIDA set out a federal, risk‑based approach to regulate AI activity in the private sector that crosses provincial or international borders. The Act focused on ‘‘high-impact’’ AI systems — systems whose operation could reasonably be expected to cause significant harms to individuals or groups (including physical, psychological, economic or property harms) or to produce biased output contrary to human rights. AIDA did not apply to federal government institutions under the Privacy Act or to national security activities directed by certain national security actors. Instead, it targeted commercial activities connected to interprovincial or international trade and commerce.

Under the draft, persons responsible for high‑impact AI systems would be required to put in place measures to identify, assess and mitigate the risks of harm or biased output. Those measures were to be set out in regulations and could include governance arrangements, testing and validation, bias mitigation procedures, documentation and record keeping, monitoring and incident notification. The Minister of Innovation, Science and Industry (ISED) was given authority to make orders — including temporary cessation orders — where a regulated high‑impact AI system posed a serious and imminent risk of harm. The bill also provided for the appointment (by designation) of an AI and Data Commissioner to support the Minister and provide a centre of expertise for implementation, compliance assistance and eventual enforcement.

AIDA contemplated a phased implementation approach: initial focus on education, guidance and voluntary compliance followed by regulatory measures (to define high‑impact systems and regulated activities) and, later, administrative monetary penalties and criminal offences for the most serious acts. The Act proposed criminal offences such as knowingly using unlawfully obtained personal information to design or develop an AI system, making an AI system available while knowingly or recklessly creating a risk of serious harm, and making an AI system available with intent to defraud causing substantial economic loss. Administrative monetary penalties and regulatory offences were to be set out in regulation, with proportionality for business size and risk.

Throughout parliamentary consideration, stakeholders — including the Office of the Privacy Commissioner, civil society groups, industry and legal academics — provided submissions and requested clarifications on scope, definitions, interaction with privacy law (the CPPA / PIPEDA replacement), enforcement architecture, and protections for fundamental rights. The Government published a companion document (March 13, 2023) to explain implementation intent and timelines for consultations and regulations. Bill C‑27 completed second reading in the House of Commons and was referred to committee for study, but did not receive Royal Assent and did not come into force. The legislative record shows committee consideration through 2023–2024; the bill lapsed on the Order Paper when the parliamentary session ended (44th Parliament, 1st Session ended January 6, 2025). As a result, AIDA remains a proposed framework and any obligations and penalties described were never brought into force as law.

Full article

Read full text ↗

Overview

The Artificial Intelligence and Data Act (AIDA) was tabled as Part 3 of Bill C-27 (Digital Charter Implementation Act, 2022) to establish a federal, risk-based regulatory system for AI systems used in the private sector in interprovincial and international trade. AIDA focused on protecting Canadians from physical, psychological, economic and collective harms and addressing biased output that produces discriminatory outcomes. Key elements included obligations for persons responsible for "high-impact" AI systems to identify, assess and mitigate risks, administrative powers for the Minister of Innovation, Science and Industry (ISED), the creation of an AI and Data Commissioner role, and criminal offences for particularly egregious misconduct. For authoritative background and the government implementation roadmap, see the Government of Canada companion document and the Parliament of Canada legislative record: ISED - AIDA companion document (13 Mar 2023) and Parliament of Canada - Bill C-27 (LEGISinfo).

Definitions

AIDA’s core terms (as drafted within Bill C-27) are defined to enable a risk-based regulatory scope. Important definitions include "artificial intelligence system" (aligned with OECD formulations and interoperable with approaches such as the EU AI Act), "regulated activities" (specific lifecycle activities that regulations would target), "high-impact artificial intelligence system" (systems that may cause harm or biased output with serious consequences), and "biased output" (unjustified adverse differential impacts based on prohibited grounds). The bill also specified exemptions (e.g., certain national security and defence activities) and limited application to private-sector activities connected to interprovincial or international trade.

Governance and Institutional Framework

AIDA assigned primary administration to the Minister of Innovation, Science and Industry, supported by a designated AI and Data Commissioner (to be established as a statutory office within the department). The Government signalled an intent to operate a phased regulatory approach: early emphasis on education, voluntary compliance and guidance, followed by targeted regulations and enforcement mechanisms (including administrative monetary penalties and criminal enforcement for serious misconduct). The Commissioner’s role would include building expertise, coordinating with other regulators (privacy, sectoral supervisors, human rights bodies), supporting enforcement actions, performing studies into systemic effects of AI and serving as a national focal point for compliance assistance. For the government’s operational approach, see ISED companion document and the legislative summary prepared by the Library of Parliament: Library of Parliament: Bill C-27 Legislative Summary (PDF).

Key Focus Areas

AIDA’s substantive focus areas included: (1) risk management — mandatory measures to identify, assess and mitigate risks of harm and biased output for high-impact systems; (2) transparency and explainability — requirements for documentation, provenance, and, in some contexts, explanation to individuals affected by automated decisions; (3) testing, validation and safety evaluation — design and pre-deployment testing obligations and continued monitoring; (4) accountability and documentation — maintenance of records, model documentation and governance frameworks to be produced on request by regulators; (5) incident reporting and ministerial intervention — powers for the Minister to require cessation or remedial action where imminent serious risk is identified; (6) conformity, standards and third-party assessment pathways — regulatory instruments to define standards and conformity mechanisms for certain regulated activities; and (7) enforcement and deterrence — administrative monetary penalties (to be set by regulation) and criminal offences for knowing or reckless conduct that causes serious harm or economic fraud. The approach emphasized proportionality with business scale and sought international alignment with norms (EU AI Act, OECD principles, and NIST guidance).

Implementation Framework

Actual obligations and regulated activities were to be set through subordinate regulations following stakeholder consultations. The companion document set an indicative timeline (consultations, draft regulations, pre-publication and final publication in the Canada Gazette) and envisioned at least a two‑year buffer after Royal Assent before the initial regulatory package would come into force. Regulations were expected to define categories of high‑impact systems, specific technical and governance measures (including third‑party conformity and certification mechanisms where appropriate), and the scheme for administrative monetary penalties. AIDA also crafted an administrative pathway for ministerial orders to manage imminent risks. The government expressed intent to coordinate closely with sectoral regulators and provincial counterparts in areas such as health, finance and transportation, while allowing flexibility for research and non-commercial development activities.

Monitoring and Evaluation

Monitoring would combine proactive regulatory oversight (inspections and orders), Commissioner-led studies of systemic effects and coordination with other federal and provincial regulators. The companion document indicated early years would prioritize education and voluntary compliance; regulatory monitoring and graduated enforcement would follow as the ecosystem matured. The Act also provided for record production powers, documentation requests and the capacity to require compliance audits, with enforcement calibrated by the regulator to reflect organization size and systemic risk.

Penalties, Liability, and Appeals

AIDA proposed administrative monetary penalties to be established by regulation and criminal offences for the most serious wrongful conduct (e.g., knowingly using unlawfully obtained personal information, recklessly making an AI system available that causes serious harm, and intentional fraud using AI). It also anticipated administrative or tribunal review routes for appeals of certain regulatory decisions under the Tribunal Act included in Bill C-27. The Library of Parliament and the government companion paper describe the intended mix of AMPs, regulatory orders and prosecutable offences to balance deterrence and proportionality.

Relationship to Other Instruments

AIDA was explicitly designed to interoperate with the proposed Consumer Privacy Protection Act (CPPA) (also in Bill C-27), existing human rights law (including the Canadian Human Rights Act), sectoral regulation (e.g., Health Canada, financial regulators), and international frameworks (EU AI Act, OECD Principles). The bill envisaged coordination with the new Personal Information and Data Protection Tribunal (created by Bill C-27) for dispute resolution and penalty adjudication where relevant. The Library of Parliament legislative summary provides an integrated view of these linkages: Legislative Summary (PDF).

International Alignment

The Government signalled an intent to align AIDA with international standards and approaches (notably the EU AI Act, OECD AI Principles and NIST RMF) to facilitate cross-border commerce and interoperability of compliance regimes. The companion document emphasised alignment in definitions, a risk-based focus on high‑impact systems and use of international standards and conformity mechanisms to reduce duplication for global firms while protecting Canadian values and rights.

Implementation Timeline

MilestonePlanned/Actual dateNotes
Bill introduced (1st Reading)2022-06-16Introduced by Minister of Innovation, Science and Industry; Part 3 = AIDA.
ISED companion document published2023-03-13Companion paper explaining implementation approach and timeline (ISED companion document).
Second reading (House)2023-04-24Bill C-27 passed 2nd reading and was referred to the Standing Committee on Industry and Technology (INDU).
Committee consideration2023-09 to 2024-12 (meetings recorded)Multiple INDU meetings and stakeholder submissions; study not completed before session end.
Session end / Bill lapsed2025-01-06The 44th Parliament, 1st session ended on 2025-01-06; Bill C-27 did not receive Royal Assent and therefore did not come into force.

Sources and References

SourceType
Parliament of Canada - Bill C-27 (LEGISinfo)Primary Source
Innovation, Science and Economic Development Canada - AIDA Companion Document (13 Mar 2023)Primary Source
Library of Parliament - Legislative Summary of Bill C-27 (PDF)Primary Source
Office of the Privacy Commissioner - Submission on Bill C-27Primary Source

Requirements for a company

What an organisation has to do under Canada - AI Regulation (Bill C-27), at a glance. Not legal advice.

No current requirements. This instrument is withdrawn; it imposes nothing today.

© Regulations.AI · updated on 13-Jun-2026