Canada - Generative AI Guidance

Guide on the use of generative AI (Treasury Board of Canada Secretariat)

Canada

RAI-CA-NA-GUGATXX-2024
Effective: February 12, 2024
In Force(In Force)
GuidelineGovernance and OversightRisk ManagementData Protection and Privacy
Export PDF

The Guide on the use of generative AI establishes a risk-based framework for Canadian federal institutions and public servants, issued by the Treasury Board of Canada Secretariat in 2023. It sets core principles and safeguards to mitigate privacy, security, and operational risks. The guideline is in force as of February 12, 2024.

Summary

The Guide on the use of generative AI (Treasury Board of Canada Secretariat) is an operational guidance document intended for Canadian federal institutions and public servants considering the use or deployment of generative artificial intelligence tools. First published in September 2023 and reissued in a second version in February 2024, the Guide clarifies where generative AI is likely to be low risk (e.g., drafting internal emails, brainstorming) and where it poses higher risk (e.g., public-facing chatbots, systems that summarize or make inferences about client data). The Guide sets out a risk‑based approach and a set of six guiding principles labelled FASTER — Fair, Accountable, Secure, Transparent, Educated and Relevant — that institutions must apply when evaluating generative AI use cases. It emphasizes that federal institutions must be cautious, evaluate risks, and only implement generative AI in contexts where risk can be managed effectively.

The Guide cross‑references existing government instruments, most notably the Directive on Automated Decision‑Making (which applies when generative AI is used to support or make administrative decisions) as well as the Policy on Service and Digital, Directive on Security Management and information‑management requirements under the Access to Information Act and the Library and Archives of Canada Act. It requires that institutions consult legal, privacy and security specialists and undertake appropriate documentation of decisions and system design. When an automated decision‑making threshold is met, institutions must complete an Algorithmic Impact Assessment and follow the Directive’s transparency, testing and reporting requirements.

Operational recommendations include avoiding entry of personal or sensitive information into publicly hosted generative AI tools; preferring GC‑managed or appropriately secured instances for sensitive processing; seeking opt‑out or non‑training settings where available; testing for biases and model weaknesses before and after deployment; conducting adversarial and penetration testing for public deployments; monitoring performance and adverse impacts post‑deployment; and engaging affected stakeholders (including bargaining agents and client representatives) during design, testing and evaluation. The Guide also highlights legal risk areas such as privacy (Privacy Act), intellectual property, procedural fairness and human rights; it recommends environmental considerations (e.g., data centre sustainability) and suggests documentation and attribution practices for public communications that include AI‑generated content.

Although the Guide is descriptive and not itself a statute that imposes criminal penalties, it is positioned as an official Treasury Board Secretariat instrument that federal institutions are expected to follow; non‑compliance can lead to policy breaches, administrative discipline, privacy complaints and legal liability under existing statutes and government personnel rules. The Guide is explicitly iterative: TBS states it will update the guidance as technology and regulatory environments evolve, and it provides links to further tools and resources such as concise summary do’s/don’ts, training, and the Canadian Centre for Cyber Security’s guidance on generative AI.

Primary official sources include the Government of Canada guidance page for the Guide and the Government of Canada Publications record (English and French editions). Secondary analysis and stakeholder commentary (privacy and access groups, departmental reports) document the Guide’s February 2024 update and emphasize its role in bringing generative AI governance into alignment with the Government of Canada’s broader AI and digital policies.

Full article

Read full text ↗

Overview

The Treasury Board of Canada Secretariat (TBS) published the Guide on the use of generative AI to provide preliminary, practical guidance to federal institutions that are exploring or deploying generative artificial intelligence tools. The Guide distinguishes between low‑risk uses (for example internal drafting, brainstorming, research assistance) and higher‑risk uses such as public‑facing chatbots or systems that summarize client data or inform administrative decisions. It promotes a risk‑based approach, encourages experimentation within controlled environments, and advises institutions to limit use to contexts where risks can be effectively managed. The document is available as official government guidance on Canada.ca and as a Government of Canada Publications entry; the Guide has been updated to a second version to incorporate internal and external feedback. For the official HTML guide see Guide on the use of generative artificial intelligence (Canada.ca).

Definitions

The Guide defines generative AI as systems that produce content (text, audio, code, video, images) in response to a user's prompt, often by predicting likely continuations based on training data. It references the Directive on Automated Decision‑Making definition of artificial intelligence for scope. Key operational distinctions include: (1) tools hosted and controlled by the Government of Canada vs. publicly hosted third‑party tools; (2) transient, non‑business‑value uses (e.g., quick brainstorming) vs. uses that create records or inform administrative decisions; and (3) proprietary vs. open‑source models with differing transparency, data‑provenance and contractual considerations.

Governance and Institutional Framework

TBS places responsibility on federal institutions to govern generative AI uses through existing institutional roles and policy instruments. Public servants must consult legal counsel, privacy and security experts, the institutional Chief Information Officer and Chief Data Officer, diversity and inclusion specialists (including GBA+), and bargaining agents where appropriate. The Guide integrates with the Directive on Automated Decision‑Making, the Policy on Service and Digital and the Directive on Security Management, requiring algorithmic impact assessments, documentation standards, and approvals where institutional risk thresholds are met. TBS’s Office of the Chief Information Officer and the Responsible Data and AI team provide advice and point resources; the Guide also references the Canadian Centre for Cyber Security for technical security guidance (Generative Artificial Intelligence (AI) - ITSAP.00.041).

Key Focus Areas

The Guide’s principal operational focus areas include: risk assessment and mitigation, privacy and data protection, bias and fairness testing, documentation and record management, security and resilience, transparency and user notification, procurement and supplier contract due diligence, environmental considerations, and workforce training. The FASTER principles (Fair, Accountable, Secure, Transparent, Educated, Relevant) act as an organizing framework for these focus areas. Specific expectations include: not entering personal or sensitive information into public third‑party tools; using GC‑managed instances for sensitive processing; incorporating opt‑out or non‑training contractual terms where feasible; and testing models across languages and population groups to assess differential performance. The Guide places special emphasis on scenarios that could affect legal rights or procedural fairness (for example, eligibility assessments or case summaries) and therefore may fall under the Directive on Automated Decision‑Making.

Implementation Framework

Implementation is guided by a staged, risk‑based methodology: (1) identify the purpose and risk profile of the proposed use; (2) consult stakeholders (legal, privacy, security, GBA+ and client groups); (3) conduct pre‑deployment testing including bias, accuracy, robustness and security testing; (4) document decisions, retention and approval steps in line with information management rules; (5) procure or configure tools with contractual protections (data residency, non‑training, IP clarity); (6) deploy with monitoring and user notification; and (7) maintain continuous evaluation and audits. The Guide advises completing an Algorithmic Impact Assessment where the system might inform administrative decisions and recommends planning for independent audits and red‑teaming for systems made publicly accessible. It also points to training modules and a concise do’s/don’ts summary to support day‑to‑day use.

Monitoring and Evaluation

The Guide requires institutions to monitor deployed systems for accuracy, bias, accessibility, security incidents and unintended impacts on clients and employees. Monitoring should include periodic re‑testing of model outputs, performance across official languages, analysis of adverse incident reports, and metrics for user satisfaction and error rates. Where the Directive on Automated Decision‑Making applies, additional reporting, logging and transparency obligations follow. The Guide also encourages institutions to schedule periodic reviews aligned with technology updates and to plan for independent audits and third‑party evaluations when risk levels are high.

Penalties, Liability, and Appeals

The Guide itself is a policy instrument and not a statute that creates formal criminal penalties; however, federal institutions remain subject to the Privacy Act, Access to Information Act, labour and employment rules, and other legal obligations. Non‑compliance with Treasury Board policies can lead to administrative or disciplinary measures, privacy complaints to the Office of the Privacy Commissioner (Office of the Privacy Commissioner of Canada), orders or findings, reputational harm, and civil liability where statutory or common‑law duties are breached. The Guide notes that institutions should design grievance and redress procedures for individuals affected by AI‑informed administrative outcomes and ensure procedural fairness mechanisms are available where decisions could deprive rights or benefits.

Relationship to Other Instruments

The Guide explicitly complements and does not replace the Directive on Automated Decision‑Making, the Policy on Service and Digital, the Directive on Security Management and existing information‑management and records retention obligations. It references the Algorithmic Impact Assessment tool, the Guideline on Service and Digital (Appendix E) for documentation and business value determination, and procurement rules for third‑party services. Institutions are advised to use the Guide alongside sector‑specific rules and to update internal policies to maintain consistency with TBS guidance.

International Alignment

The Guide references international policy considerations and draws on best practices and research, aligning Canada’s approach with OECD and EU policy themes such as transparency, human‑centric AI and risk‑based governance. TBS positions the Guide as part of the Government of Canada’s broader AI strategy and ongoing international engagement; it encourages institutions to monitor global regulatory developments and to adopt interoperability and transparency measures that facilitate cross‑border data governance and procurement compliance.

Implementation Timeline

MilestoneTarget date
Original publication (first edition)2023-09-04
Second version published (incorporating stakeholder feedback)2024-02-12
Ongoing updates and maintenance (TBS commitment)Continuous (periodic reviews)

Sources and References

SourceType
Guide on the use of generative artificial intelligence (Canada.ca)Primary Source
Guide on the use of generative AI (Government of Canada Publications, 2024 edition)Primary Source
Privacy and Access Council of Canada — Update: Guide on the use of generative AI (21 Feb 2024)Secondary/Stakeholder Note

Requirements for a company

What an organisation has to do under Canada - Generative AI Guidance, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

0

Nothing in this category.

Must not do

0

Nothing in this category.

Should do

7
  • Use Government of Canada managed instances when processing sensitive information with generative AI.Canadian federal institutions
  • Consult legal counsel, privacy, security, and data experts prior to deploying generative AI tools.Canadian federal institutions
  • Complete an Algorithmic Impact Assessment where generative AI systems support or inform administrative decisions.Canadian federal institutions
  • Test generative AI models across languages and demographic groups for bias, accuracy, security, and robustness before deployment.Canadian federal institutions
  • Provide clear user notification and transparency when deploying public-facing generative AI systems or chatbots.Canadian federal institutions deploying public-facing AI
  • Incorporate opt-out or non-training contractual terms when procuring third-party generative AI services.Canadian federal institutions procuring AI tools
  • +1 more in the table below

Should not do

1
  • Do not enter personal or sensitive information into public third-party generative AI tools.Canadian federal institutions and public servants

Who must do what

The obligations under Canada - Generative AI Guidance, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Canadian federal institutions and public servantsDo not enter personal or sensitive information into public third-party generative AI tools.
not entering personal or sensitive information into public third‑party tools
Before using generative AI toolsKey Focus AreasRecommended
2Canadian federal institutionsUse Government of Canada managed instances when processing sensitive information with generative AI.
using GC‑managed instances for sensitive processing
Before processing sensitive dataKey Focus AreasRecommended
3Canadian federal institutionsConsult legal counsel, privacy, security, and data experts prior to deploying generative AI tools.
Public servants must consult legal counsel, privacy and security experts, the institutional Chief Information Officer and Chief Data Officer
Before deploymentGovernance and Institutional FrameworkRecommended
4Canadian federal institutionsComplete an Algorithmic Impact Assessment where generative AI systems support or inform administrative decisions.
completing an Algorithmic Impact Assessment where the system might inform administrative decisions
Before deploymentImplementation FrameworkRecommended
5Canadian federal institutionsTest generative AI models across languages and demographic groups for bias, accuracy, security, and robustness before deployment.
conduct pre‑deployment testing including bias, accuracy, robustness and security testing
Prior to deploymentImplementation FrameworkRecommended
6Canadian federal institutions deploying public-facing AIProvide clear user notification and transparency when deploying public-facing generative AI systems or chatbots.
deploy with monitoring and user notification
Upon deploymentImplementation FrameworkRecommended
7Canadian federal institutions procuring AI toolsIncorporate opt-out or non-training contractual terms when procuring third-party generative AI services.
incorporating opt‑out or non‑training contractual terms where feasible
During procurementKey Focus AreasRecommended
8Canadian federal institutionsContinuously monitor deployed generative AI systems for accuracy, bias, security incidents, and unintended client impacts.
monitor deployed systems for accuracy, bias, accessibility, security incidents and unintended impacts on clients and employees
Monitoring and EvaluationRecommended

© Regulations.AI · updated on 13-Jun-2026 · reviewed against official sources on 07-Sep-2026 using Gemini 3.6 Flash