Artificial Intelligence and Data Act

Artificial Intelligence and Data Act

Canada

RAI-CA-NA-BILLC27-2022

Bill C-27

Withdrawn(Withdrawn)
BillGovernance and OversightRisk ManagementFundamental Rights
Export PDF

Canada's proposed Artificial Intelligence and Data Act (AIDA) aimed to regulate AI systems with a risk-based approach but was ultimately withdrawn in 2025.

Overview

The Artificial Intelligence and Data Act (AIDA) was proposed Canadian federal legislation, introduced as Part 3 of Bill C-27, the Digital Charter Implementation Act, 2022, in June 2022. It represented Canada's initial comprehensive attempt to establish a regulatory framework for artificial intelligence (AI) systems within the country. The primary objective of AIDA was to ensure the responsible design, development, and deployment of AI systems that could significantly impact the lives of Canadians, aiming to balance fostering innovation with robust protection for citizens. The Act sought to achieve this by setting foundational requirements for AI governance, particularly focusing on the safety and non-discriminatory nature of AI systems.

AIDA adopted a risk-based approach, distinguishing itself from some other global AI regulations by centering on the actual impact AI systems could have on individuals, rather than solely on their technical specifications. This approach was intended to provide flexibility and adaptability as AI technology continued to evolve. The legislation aimed to hold businesses accountable for the AI activities under their control, requiring them to implement governance mechanisms and policies to address risks. Despite its ambitious goals and extensive parliamentary review, Bill C-27, including AIDA, ultimately did not become law, as it died on the Order Paper in January 2025 due following the prorogation of Parliament.

Definitions

AIDA included key definitions central to its regulatory scope. An "artificial intelligence system" was defined as a technological system that, autonomously or partly autonomously, processes data related to human activities through techniques such as genetic algorithms, neural networks, or machine learning, to generate content, make decisions, recommendations, or predictions. This broad definition aimed to be future-proof, encompassing various evolving AI technologies.

The legislation's focus was largely on "high-impact systems," although the specific criteria for what constituted a high-impact system were left to be established in future regulations. However, the companion document and other analyses indicated that such systems would include those with the potential for serious physical or psychological harm to individuals, damage to property, or substantial economic loss. Examples of systems of interest included screening systems impacting access to services or employment, biometric systems for identification, systems influencing human behavior at scale, and systems critical to health and safety. The concept of "harm" was explicitly defined to include physical or psychological harm to an individual, damage to an individual's property, or economic loss to an individual.

Governance and Institutional Framework

The proposed governance structure for AIDA envisioned a significant role for the Minister of Innovation, Science and Industry, who would have been empowered to administer and enforce the Act. A key institutional innovation was the planned creation of an office headed by an Artificial Intelligence and Data Commissioner. This Commissioner was intended to serve as a center of expertise, supporting both the development of regulations and the ongoing administration of the Act.

The AI and Data Commissioner's responsibilities would have included monitoring company compliance, ordering third-party audits, and sharing information with other regulators and enforcement bodies as appropriate. The role was designed for gradual evolution, starting with education and assistance, and eventually expanding to include compliance and enforcement functions once the Act came into force. This framework aimed to ensure that policy and enforcement could adapt dynamically as AI technology progressed, fostering a responsive regulatory environment.

Key Focus Areas

AIDA's key focus areas revolved around a risk-based approach to AI regulation. For all AI systems, persons involved in their design, development, making available, or managing their operation were required to assess whether their system was a high-impact system and keep records of this assessment. For high-impact AI systems, stricter obligations were proposed. These included establishing measures to identify, assess, and mitigate risks of harm or biased output, and continuously monitoring the effectiveness of these measures.

Transparency was another critical component, with requirements for providers and operators of high-impact systems to publish plain-language descriptions of their systems on public websites. These descriptions were to include information about the system's intended purpose, capabilities, limitations, and potential impacts, allowing users to make informed decisions. Furthermore, AIDA proposed prohibitions against specific harmful uses of AI, such as knowingly possessing or using unlawfully obtained personal information to design or develop an AI system, or making an AI system available for use if it was known or reckless to cause serious harm or substantial economic loss.

Implementation Framework

The implementation of AIDA was designed to be a phased process, emphasizing an agile approach to regulation given the rapid evolution of AI technology. Following the anticipated Royal Assent of Bill C-27, the government intended to conduct broad and inclusive consultations with various stakeholders, including industry, academia, civil society, and Canadian communities. These consultations would have been crucial for informing the development of detailed regulations, which were meant to build upon the foundational framework established by AIDA.

Key areas for regulatory development included defining the precise criteria for high-impact systems, establishing standards and certifications to ensure AI systems met Canadian expectations, and detailing the specific requirements for risk mitigation, transparency, and data governance. This iterative approach, involving continuous collaboration and adaptation, aimed to ensure that the regulations remained effective in protecting the public interest while avoiding undue burdens on the Canadian AI ecosystem and fostering innovation.

Monitoring and Evaluation

Under the proposed AIDA, monitoring and evaluation were integral to ensuring ongoing compliance and the responsible operation of AI systems. Persons responsible for high-impact AI systems were mandated to not only establish measures for identifying, assessing, and mitigating risks of harm or biased output but also to continuously monitor the effectiveness of these measures. This included keeping detailed records describing the measures taken and their outcomes.

The Minister of Innovation, Science and Industry, supported by the AI and Data Commissioner, would have possessed significant oversight and enforcement tools. These included the power to compel the production of records and information from regulated entities to verify compliance. In situations where a high-impact system could result in harm or biased output, the Minister could order an independent audit. Furthermore, in cases of serious risk of imminent harm, the Minister had the authority to order the cessation of use or making available of a high-impact system, and could also order the publication of information related to compliance or system risks, while safeguarding confidential business information.

Penalties, Liability, and Appeals

AIDA outlined a tiered system of penalties for non-compliance, designed to promote adherence rather than solely punish. This framework included administrative monetary penalties for contraventions of regulatory requirements. For more serious infractions, the Act proposed criminal offences. These offences covered actions such as knowingly possessing or using unlawfully obtained personal information for AI system development, or making an AI system available knowing or being reckless that it was likely to cause serious harm or substantial damage to property, and if such harm or damage actually occurred.

The proposed penalties were substantial, with fines potentially reaching up to $25 million or 5% of global revenue, whichever was greater, for certain offences. The Act also included provisions for the Minister to issue orders, such as requiring the publication of information related to compliance or system audits, and in cases of serious imminent harm, ordering the cessation of an AI system's use. The enforcement mechanisms were intended to provide the Minister and the AI and Data Commissioner with robust tools to ensure accountability across the AI lifecycle.

Relationship to Other Instruments

The Artificial Intelligence and Data Act was introduced as Part 3 of Bill C-27, the Digital Charter Implementation Act, 2022. This broader legislative package also included the Consumer Privacy Protection Act (CPPA) and the Personal Information and Data Protection Tribunal Act. AIDA was intended to complement these privacy-focused laws, recognizing that effective AI oversight requires comprehensive data protection.

AIDA was designed to build upon existing Canadian legal frameworks, including consumer protection and human rights laws. It aimed to ensure that high-impact AI systems met the same expectations for safety and human rights that Canadians were accustomed to in other regulated sectors. The intent was for the new AI regulations to be interoperable with existing and future regulatory approaches, integrating seamlessly with Canada's broader legal landscape and supporting a holistic approach to digital governance.

International Alignment

Canada's approach to AI regulation through AIDA was consciously designed with international alignment in mind. The framework, including key definitions and concepts, was intended to reflect and align with evolving global norms in the AI space. This included principles established by the Organization for Economic Co-operation and Development (OECD) AI Principles, as well as frameworks like the European Union's AI Act and the US National Institute of Standards and Technology (NIST) Risk Management Framework.

The goal of this international interoperability was to facilitate Canadian companies' access to global markets and to ensure that Canada remained competitive in the global AI landscape. By adopting a risk-based approach and seeking consistency with international standards, AIDA aimed to position Canada as a leader in responsible AI governance, while also allowing for a uniquely Canadian perspective that balanced innovation with protection.

Implementation Timeline

MilestoneDateNotes
AIDA introduced as part of Bill C-272022-06-16Bill C-27, the Digital Charter Implementation Act, 2022, including AIDA, was tabled in the House of Commons.
Parliamentary Review and Committee Examination2022-06 to 2025-01Bill C-27 underwent parliamentary review and committee examination, with proposed amendments considered.
Bill C-27 Died on Order Paper2025-01-06Parliament was prorogued, causing Bill C-27, including AIDA, to cease its legislative progress and not become law.
Voluntary Code of Conduct Announced2023-09A Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems was announced to provide temporary standards until formal regulation.

Compliance Checklist

CheckRequired Action
AI System InventoryIdentify and document all AI systems developed, deployed, or procured, noting their purpose, data types, outputs, and affected user groups.
High-Impact System AssessmentAssess whether AI systems qualify as "high-impact" based on potential for harm or biased output, and keep records of this assessment.
Risk Management ProgramEstablish and maintain measures to identify, assess, and mitigate risks of harm or biased output throughout the AI system's lifecycle.
Data GovernanceImplement robust data governance practices, including measures for anonymization and ensuring data quality, relevance, and representativeness.
Transparency and ExplainabilityPublish plain-language descriptions of high-impact AI systems, detailing their purpose, capabilities, limitations, and potential impacts.
Human OversightEstablish appropriate human oversight mechanisms for high-impact AI systems to ensure meaningful control.
Monitoring and ReviewContinuously monitor the effectiveness of risk mitigation measures and review assessments as systems evolve or conditions change.
Record-KeepingMaintain comprehensive records of risk assessments, mitigation measures, data anonymization practices, and other compliance activities.
Prohibited Uses AvoidanceEnsure AI systems do not use illegally obtained personal information and are not deployed in ways likely to cause serious harm or substantial economic loss with fraudulent intent.

Sources and References

SourceType
Plain English

Canada's proposed Artificial Intelligence and Data Act (AIDA) was a significant attempt to regulate Artificial Intelligence (AI) systems across the country, aiming to ensure their responsible design, development, and deployment. However, this legislation ultimately did not become law, dying in Parliament in January 2025.

Had it passed, AIDA would have applied to individuals and organizations involved in designing, developing, making available, or managing the operation of AI systems in Canada. Its focus was primarily on "high-impact systems"—those with the potential for serious physical or psychological harm, property damage, or substantial economic loss. Examples included AI used in employment screening, biometric identification, or systems critical to health and safety.

Key obligations for those operating high-impact AI systems would have included: - Establishing measures to identify, assess, and mitigate risks of harm or biased output. - Continuously monitoring the effectiveness of these risk measures. - Publishing plain-language descriptions of their systems, detailing purpose, capabilities, limitations, and potential impacts. The Act also proposed prohibitions against using unlawfully obtained personal information for AI development and making AI systems available if known to cause serious harm or substantial economic loss.

While AIDA never took effect, its proposed enforcement mechanisms were robust. Non-compliance could have led to administrative monetary penalties, and serious infractions carried criminal charges with fines potentially reaching $25 million or 5% of global revenue, whichever was greater. The Minister of Innovation, Science and Industry would have had powers to order audits, information disclosure, or even the cessation of a system's use in cases of imminent harm.

The biggest practical takeaway for Canadian businesses is that while AIDA itself is no longer active, the government's intent to regulate AI remains. A voluntary Code of Conduct for advanced generative AI systems was announced in September 2023, serving as a temporary guide in the absence of formal legislation. This signals that future regulatory efforts are likely to emerge, potentially drawing on similar principles.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

Read this article-by-article

Plain-English breakdown of 9 key articles, with cross-jurisdiction equivalents where applicable.

Open breakdown →

What you must do — compliance checklist

0 / 9 marked complete

Plain-English obligations under Artificial Intelligence and Data Act. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalAlways

    Applies to: All persons involved with AI systems.

    prohibitions against specific harmful uses of AI, such as knowingly possessing or using unlawfully obtained personal information to design or develop an AI system.
  2. #2CriticalBefore making available

    Applies to: Persons involved in AI system design, development, or operation.

    persons involved... were required to assess whether their system was a high-impact system and keep records of this assessment.
  3. #3CriticalBefore making available

    Applies to: Providers and operators of high-impact AI systems.

    These included establishing measures to identify, assess, and mitigate risks of harm or biased output, and continuously monitoring the effectiveness of these measures.
  4. #4CriticalOngoing

    Applies to: Persons responsible for high-impact AI systems.

    continuously monitor the effectiveness of these measures.
  5. #5ImportantOngoing

    Applies to: Persons involved in AI system design, development, or operation.

  6. #6ImportantBefore making available

    Applies to: Providers and operators of high-impact AI systems.

    Transparency was another critical component, with requirements for providers and operators of high-impact systems to publish plain-language descriptions of their systems.
  7. #7ImportantOngoing

    Applies to: Persons responsible for high-impact AI systems.

    keeping detailed records describing the measures taken and their outcomes.
  8. #8ImportantBefore making available

    Applies to: Persons responsible for AI systems.

    Key areas for regulatory development included... detailing the specific requirements for risk mitigation, transparency, and data governance.
  9. #9ImportantBefore making available

    Applies to: Providers and operators of high-impact AI systems.

© Regulations.AI — created on 11-Apr-2026 using Gemini 2.5 Flash