Canada - AI Regulation Overview
Canada AI Regulation Overview
Canada
RAI-CA-NA-SUMMARY-2026Canada's federal AI regulation combines voluntary measures, sector-specific guidelines, and strategic investments. A proposed comprehensive AI Act was withdrawn, but the government maintains a risk-based approach through initiatives like the Pan-Canadian AI Strategy and the Directive on Automated Decision-Making for public sector AI use.
Overview
Canada's federal approach to artificial intelligence (AI) regulation is characterized by an evolving, multi-faceted strategy that balances fostering innovation with ensuring responsible and ethical development and deployment. The country has adopted a human-centric and risk-based philosophy, aiming to leverage AI's benefits while mitigating potential harms to individuals and society. While a comprehensive, horizontal AI statute (the Artificial Intelligence and Data Act, or AIDA) was proposed as part of Bill C-27 but ultimately withdrawn, Canada has actively implemented a range of soft law instruments, strategic policies, and sector-specific guidelines at the federal level. These include mandatory directives for federal government institutions, voluntary codes of conduct for the private sector, and significant investments in AI research and safety through initiatives like the Pan-Canadian Artificial Intelligence Strategy and the Canadian Artificial Intelligence Safety Institute.The current regulatory landscape reflects a pragmatic recognition of AI's rapid evolution, favoring agile, iterative approaches that can adapt to new technological developments. The focus is on embedding principles of transparency, accountability, fairness, and human oversight into AI systems and their governance. This includes a strong emphasis on data protection, given the foundational role of data in AI, and a commitment to international collaboration to align regulatory efforts globally. Canada's strategy also highlights the importance of accessibility and equity in AI, as demonstrated by the National Standard for Accessible and Equitable AI, ensuring that AI systems are designed to be inclusive of persons with disabilities.
Regulatory Approach
Canada's federal regulatory approach to AI is predominantly characterized by a blend of soft law instruments, sector-specific binding guidelines, and a strong commitment to a risk-based framework. Rather than a single, overarching prescriptive law for the entire private sector (which was the intent of the withdrawn AIDA), the current environment relies on a combination of voluntary codes, operational directives, and prudential guidelines. This allows for flexibility and adaptability in a rapidly evolving technological landscape, encouraging responsible innovation while setting expectations for accountability. The risk-based methodology is evident in instruments like the Treasury Board of Canada Secretariat's (TBS) Directive on Automated Decision-Making, which mandates federal institutions to assess the impact level of AI systems and apply proportionate mitigation measures.For the private sector, voluntary instruments like the Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems provide a framework for organizations to adopt best practices in advance of, or alongside, potential future binding legislation. In specific regulated sectors, such as financial services, binding guidelines issued by bodies like the Office of the Superintendent of Financial Institutions (OSFI) explicitly incorporate AI and machine learning into existing model risk management frameworks, ensuring prudential oversight. This hybrid approach allows Canada to foster an innovation-friendly environment while incrementally building regulatory capacity and addressing specific areas of concern, often drawing on international best practices and principles from organizations like the OECD.
Key AI Legislation
Canada's federal AI regulatory landscape currently comprises a mix of policies, guidelines, and standards, with proposed comprehensive legislation having been withdrawn. Key instruments include:
- CAN-ASC-6.2 Accessible and Equitable Artificial Intelligence Standard (2025): The first National Standard of Canada specifically addressing accessible and equitable AI, developed by Accessibility Standards Canada. It provides principles and process-oriented requirements for AI systems to be usable by and equitable for persons with disabilities.
- Canada-EU Memorandum of Understanding on Artificial Intelligence (2025): A non-binding political instrument formalizing cooperation between Canada and the EU on AI, focusing on harmonizing standards, exchanging information, and expanding scientific cooperation.
- Guideline E-23 — Model Risk Management (Office of the Superintendent of Financial Institutions) (2025): A final, principles-based guidance document from OSFI that updates and broadens expectations for model risk management in federally regulated financial institutions to explicitly include AI/ML-based systems.
- Implementation Guide for Managers of Artificial Intelligence Systems (Innovation, Science and Economic Development Canada) (2025): A non-binding operational resource supporting organizations that manage AI systems, complementing the Voluntary Code of Conduct.
- Canadian Artificial Intelligence Safety Institute (CAISI) (2024): A federal research and coordination centre established to advance scientific understanding of risks from advanced AI systems and develop testing and evaluation approaches.
- Guide on the use of generative AI (Treasury Board of Canada Secretariat) (2024): Operational guidance for Canadian federal institutions and public servants on the responsible use of generative AI tools, emphasizing a risk-based approach and FASTER principles.
- Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems (2023): A non-binding set of commitments and operational measures for organizations developing or managing advanced generative AI systems, promoting accountability, safety, fairness, transparency, human oversight, and validity.
- Directive on Automated Decision-Making (Treasury Board of Canada Secretariat) (2019): A mandatory policy for federal departments developing, procuring, or deploying automated decision systems that affect clients' rights, interests, or privileges, establishing a risk- and impact-based framework.
- Algorithmic Impact Assessment (AIA) tool (Treasury Board of Canada Secretariat) (2019): An open, government-provided risk assessment questionnaire that operationalizes the Directive on Automated Decision-Making, helping federal departments identify, score, and manage risks from automated decision systems.
- Pan-Canadian Artificial Intelligence Strategy (PCAIS) (2017): A federally-funded national strategy to strengthen Canada’s competitive position in AI research, talent development, commercialization, and standards.
Governance & Enforcement Bodies
Several federal bodies play crucial roles in Canada's AI governance landscape, reflecting a distributed approach to oversight. Innovation, Science and Economic Development Canada (ISED) is central to developing and promoting national AI policy, including the Pan-Canadian Artificial Intelligence Strategy and voluntary codes of conduct. ISED also houses the Canadian Artificial Intelligence Safety Institute (CAISI), which focuses on advancing the scientific understanding of AI risks, developing testing methodologies, and coordinating with international counterparts. CAISI's mandate is research-focused, feeding evidence into policy processes rather than direct regulation or enforcement.The Treasury Board of Canada Secretariat (TBS) is responsible for governing the use of AI within the federal public service. Its Directive on Automated Decision-Making mandates federal departments to assess and mitigate risks associated with automated decision systems through tools like the Algorithmic Impact Assessment (AIA). TBS ensures that public sector AI deployments adhere to principles of transparency, fairness, and accountability, with internal compliance mechanisms and oversight by the Office of the Chief Information Officer. For the financial sector, the Office of the Superintendent of Financial Institutions (OSFI) issues prudential guidelines, such as Guideline E-23, which explicitly covers model risk management for AI/ML systems in federally regulated financial institutions. OSFI exercises supervisory tools and enforcement powers to ensure compliance with its guidelines, including remedial plans and restrictions on operations.Accessibility Standards Canada develops national standards like CAN-ASC-6.2 for accessible and equitable AI, which, while voluntary, can be recommended to the Minister responsible for the Accessible Canada Act and may inform regulatory instruments for federally regulated entities. The Standards Council of Canada (SCC) plays a role in developing AI-related standards and conformity assessment pilots, often funded through the Pan-Canadian AI Strategy, to support future regulatory compliance or voluntary certification. The Office of the Privacy Commissioner of Canada (OPC) remains a key oversight body for privacy matters related to AI under existing privacy legislation, such as the Personal Information Protection and Electronic Documents Act (PIPEDA), and continues to advocate for stronger data protection and algorithmic transparency. While the proposed AI and Data Commissioner and Personal Information and Data Protection Tribunal (under the withdrawn Bill C-27) would have significantly augmented federal enforcement, the current framework relies on existing mandates and the internal compliance mechanisms of government departments and regulated entities.
Penalties & Enforcement
Currently, federal AI regulations in Canada primarily consist of guidelines, policies, and voluntary codes, which do not carry direct statutory fines or criminal penalties for non-compliance. For instance, the Voluntary Code of Conduct on Advanced Generative AI Systems relies on reputational consequences and the prospect of future binding legislation for adherence, rather than immediate statutory sanctions. Similarly, the Implementation Guide for Managers of AI Systems provides best practices without imposing fines. However, non-compliance with mandatory policy instruments, such as the Treasury Board of Canada Secretariat's Directive on Automated Decision-Making for federal institutions, can lead to administrative escalations, remediation requirements, procurement restrictions, and internal accountability measures within the public service.In federally regulated sectors, existing regulatory bodies leverage their established enforcement powers. The Office of the Superintendent of Financial Institutions (OSFI), for example, can address non-compliance with its Guideline E-23 on Model Risk Management (which includes AI/ML systems) through supervisory directions, remedial plans, restrictions on operations, and administrative monetary penalties under existing legislative authorities. The Office of the Privacy Commissioner of Canada (OPC) enforces the Personal Information Protection and Electronic Documents Act (PIPEDA) through investigations, audits, and the power to make recommendations and publish findings, with potential for court-ordered compliance. While the proposed Artificial Intelligence and Data Act (AIDA) and Consumer Privacy Protection Act (CPPA) (part of the withdrawn Bill C-27) would have introduced significant administrative monetary penalties (AMPs) and criminal offences for serious contraventions, these provisions did not come into force. Any future binding legislation is expected to include a robust enforcement framework with substantial penalties to ensure compliance.
Data Protection Framework
Canada's federal data protection framework is primarily governed by the Personal Information Protection and Electronic Documents Act (PIPEDA), which applies to private-sector organizations that collect, use, or disclose personal information in the course of commercial activities. PIPEDA is based on ten fair information principles, including accountability, identifying purposes, consent, limiting collection, limiting use, disclosure, and retention, accuracy, safeguards, openness, individual access, and challenging compliance. The Office of the Privacy Commissioner of Canada (OPC) is responsible for overseeing compliance with PIPEDA, investigating complaints, conducting audits, and issuing recommendations.While PIPEDA has been foundational, it has faced calls for modernization to address the complexities of the digital and AI era. The proposed Consumer Privacy Protection Act (CPPA), introduced as Part 1 of the withdrawn Bill C-27, aimed to replace key parts of PIPEDA. The CPPA would have strengthened individual rights, introduced enhanced consent requirements, mandated privacy management programs, and created a more robust enforcement regime with significant administrative monetary penalties and a new Personal Information and Data Protection Tribunal. Although the CPPA did not become law, its policy aims, particularly concerning algorithmic transparency (e.g., a right to explanation for automated decisions) and data mobility, are expected to inform future federal privacy legislation. Currently, organizations must continue to adhere to PIPEDA and other applicable provincial privacy laws, ensuring that personal information used in AI systems is collected, used, and protected in accordance with existing legal obligations.
Sector-Specific Rules
Canada has begun to implement sector-specific AI regulations, particularly in areas where the risks are deemed higher or where existing regulatory mandates provide a clear pathway. A prominent example is the financial sector, where the Office of the Superintendent of Financial Institutions (OSFI) has issued Guideline E-23 — Model Risk Management. This guideline explicitly broadens the definition of "model" to encompass analytical applications, including AI/ML-based systems, used by federally regulated financial institutions (FRFIs). It mandates a risk-based approach to model governance across the entire lifecycle, from development and testing to deployment and monitoring, with specific considerations for explainability, fairness, and robustness in advanced AI models.Within the federal public sector, the Treasury Board of Canada Secretariat's (TBS) Directive on Automated Decision-Making serves as a mandatory, sector-specific policy. It applies to federal departments that develop, procure, or deploy automated decision systems that make or assist administrative decisions affecting clients' rights, interests, or privileges. The Directive requires departments to complete an Algorithmic Impact Assessment (AIA) to determine an AI system's impact level and implement proportionate mitigation measures, including enhanced transparency, human oversight, and bias assessment. While Canada does not yet have comprehensive federal legislation for AI in sectors like healthcare or autonomous vehicles, existing regulatory bodies in these domains (e.g., Health Canada for medical devices, Transport Canada for vehicle safety) are expected to adapt or introduce new guidance as AI integration becomes more prevalent. The National Standard for Accessible and Equitable AI (CAN-ASC-6.2) also has sector-agnostic implications but is particularly relevant for sectors delivering public services or products to persons with disabilities.
International Alignment
Canada is actively engaged in international efforts to align its AI regulatory framework with global best practices and principles. A significant step in this direction is the Canada-EU Memorandum of Understanding on Artificial Intelligence, signed in December 2025. This non-binding instrument formalizes cooperation between Canada and the European Union on various AI-related activities, including harmonizing standards and regulatory approaches, exchanging information on AI governance, expanding scientific cooperation, and facilitating access to compute infrastructure. This MoU signals Canada's intent to align with the EU's human-rights-based and trustworthy AI development philosophy, particularly in light of the EU's Artificial Intelligence Act.Beyond bilateral agreements, Canada is a strong proponent of multilateral initiatives and principles. It actively participates in fora such as the G7, the Organisation for Economic Co-operation and Development (OECD), and the Global Partnership on Artificial Intelligence (GPAI). The Pan-Canadian Artificial Intelligence Strategy explicitly directs sustained cooperation with international initiatives, and the proposed Artificial Intelligence and Data Act (AIDA) (though withdrawn) referenced alignment with OECD definitions of AI systems. The Canadian Artificial Intelligence Safety Institute (CAISI) is also mandated to coordinate with international counterparts through the International Network of AI Safety Institutes, accelerating Canadian technical leadership on safety research and model evaluation. This commitment to international alignment aims to reduce regulatory fragmentation, promote interoperability, and ensure that Canadian AI development adheres to globally recognized ethical and safety standards.
Future Developments
Canada's federal AI regulatory landscape is poised for significant future developments, particularly following the withdrawal of Bill C-27, which included the proposed Artificial Intelligence and Data Act (AIDA), the Consumer Privacy Protection Act (CPPA), and the Personal Information and Data Protection Tribunal Act (PIDPTA). These bills, which aimed to establish a comprehensive, risk-based federal framework for private-sector AI and modernize privacy law, died on the Order Paper in January 2025. Despite this setback, the policy goals and the underlying principles of these withdrawn bills are widely expected to inform new legislative proposals. The government has signaled its continued commitment to regulating high-impact AI systems and strengthening privacy protections, indicating that a revised or new version of AI and privacy legislation is likely to be introduced in the future, potentially incorporating lessons learned from stakeholder consultations and international developments.Ongoing consultations and the work of bodies like the Canadian Artificial Intelligence Safety Institute (CAISI) will continue to shape future policy. CAISI's research on AI risks, testing methodologies, and international coordination will provide crucial evidence for upcoming regulatory instruments. Furthermore, the Pan-Canadian Artificial Intelligence Strategy (PCAIS) continues to fund standards development through the Standards Council of Canada, which could lead to the adoption of new technical standards and conformity assessment frameworks that may eventually be referenced in binding regulations. The iterative nature of existing guidelines, such as the TBS Directive on Automated Decision-Making, also suggests ongoing updates to reflect technological advancements and evolving best practices. The government's overall trajectory points towards a continued effort to establish a robust and adaptive regulatory environment for AI, balancing innovation with safety, ethics, and human rights, with new legislative initiatives expected to emerge in the coming parliamentary sessions.
Key Regulations
All 15 regulations currently tracked for Canada at national level.
Enforcement Bodies
| Agency | Mandate | Key Powers | Website |
|---|---|---|---|
| Innovation, Science and Economic Development Canada (ISED) | Develop and promote national AI policy; oversee CAISI; foster innovation and commercialization. | Policy development, program funding, international cooperation, research oversight (via CAISI). | https://ised-isde.canada.ca/site/innovation-science-economic-development-canada/en |
| Treasury Board of Canada Secretariat (TBS) | Establish mandatory policy requirements for federal departments using automated decision systems; ensure responsible AI use in the public sector. | Issue directives (e.g., Directive on Automated Decision-Making), maintain the Algorithmic Impact Assessment (AIA) tool, internal compliance oversight, guidance. | https://www.tbs-sct.canada.ca/ |
| Office of the Superintendent of Financial Institutions (OSFI) | Regulate and supervise federally regulated financial institutions (FRFIs), including managing model risk for AI/ML systems. | Issue prudential guidelines, conduct supervisory reviews, issue supervisory directions, impose remedial plans, restrict operations, administrative monetary penalties. | https://www.osfi-bsif.gc.ca/Eng/Pages/default.aspx |
| Accessibility Standards Canada | Develop national accessibility standards, including for AI systems, to promote an accessible Canada. | Develop and publish standards (e.g., CAN-ASC-6.2), recommend standards to the Minister responsible for the Accessible Canada Act. | https://accessible.canada.ca/ |
| Standards Council of Canada (SCC) | Lead and facilitate the development of standards and conformity assessment solutions in Canada, including for AI. | Accredit standards development organizations, represent Canada in international standardization, develop AI-related standards and conformity assessment pilots. | https://www.scc.ca/en |
| Office of the Privacy Commissioner of Canada (OPC) | Oversee compliance with federal privacy legislation (PIPEDA) in the private sector; provide guidance on privacy implications of AI. | Investigate complaints, conduct audits, issue recommendations, enter into compliance agreements, seek court orders for compliance. | https://www.priv.gc.ca/en/ |
| Canadian Institute for Advanced Research (CIFAR) | Implement key programs of the Pan-Canadian Artificial Intelligence Strategy; administer investigator-led research for CAISI. | Administer research funding, manage research chairs, coordinate national AI institutes, lead scientific programs for CAISI. | https://cifar.ca/ |
Real enforcement actions
6 actions recordedPublic enforcement actions where regulators cited Canada - AI Regulation Overview. Helps you see how the law is actually applied in practice.
- May 6, 2026
Office of the Privacy Commissioner of Canada (OPC), Commission d'accès à l'information du Québec (CAI), Office of the Information and Privacy Commissioner for British Columbia (OIPC BC), Office of the Information and Privacy Commissioner of Alberta (OIPC AB) vs OpenAI OpCo, LLC
Sector: Artificial Intelligence
A joint investigation by Canadian privacy authorities found OpenAI's ChatGPT training practices violated privacy laws through over-collection of data, non-consensual data practices, and shortcomings in data subject access, with OpenAI committing to implement privacy-protective measures.
Source ↗ - Sep 23, 2025
Office of the Privacy Commissioner of Canada (OPC), Commission d'accès à l'information du Québec (CAI), Office of the Information and Privacy Commissioner for British Columbia (OIPC BC), Office of the Information and Privacy Commissioner of Alberta (OIPC AB) vs TikTok Pte. Ltd.
Sector: Social Media
A joint investigation by Canadian privacy regulators found TikTok collected and used children's personal information without legitimate need and that consents obtained from adults and youth were insufficient, leading to commitments from TikTok to implement new measures.
Source ↗ - Service ban / suspensionFeb 18, 2025
Commission d'acces a l'information du Quebec (CAI) vs Societe Metro Inc.
The CAI prohibited Metro Inc. from putting into service a biometric database and facial-recognition system to detect shoplifting/fraud, finding the project required express consent it could not obtain and constituted an invasion of privacy under Quebec's IT Act.
Source ↗ - Enforcement orderSep 4, 2024
Commission d'acces a l'information du Quebec (CAI) vs Imprimeries Transcontinental Inc.
The CAI ordered Imprimeries Transcontinental to cease using facial-recognition biometric technology to control employee access and destroy the biometric templates it had collected, for non-compliance with Quebec biometric privacy law.
Source ↗ - Apr 20, 2023
Information and Privacy Commissioner for British Columbia (OIPC BC) vs Canadian Tire Associate Dealers
OIPC Investigation Report 23-02 found four BC Canadian Tire stores contravened PIPA by using facial recognition (2018-2021) to collect customers' biometric data without notice, a demonstrated reasonable purpose, or consent.
Source ↗ - Enforcement orderDec 14, 2021
Information and Privacy Commissioner for British Columbia (OIPC BC) vs Clearview AI, Inc.
The BC Commissioner ordered Clearview AI to stop collecting, using and disclosing the biometric facial images of British Columbians and to delete images already collected, after finding its facial-recognition scraping breached BC privacy law.
Source ↗
Related Regulations
© Regulations.AI — created on 05-Aug-2026 using Gemini 2.5 Flash