Canada - Responsible AI Development

Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems

Canada

RAI-CA-NA-VCCRDXX-2023
Effective: September 27, 2023
In Force(In Force)
GuidelineGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

The Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems guides organizations building generative AI in Canada on safety and risk management, published by Innovation, Science and Economic Development Canada in 2023. This non-binding guideline took effect on September 27, 2023.

Summary

The Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems was announced by the Honourable François‑Philippe Champagne on September 27, 2023 and is hosted by Innovation, Science and Economic Development Canada (ISED). The Code provides a compact set of voluntary commitments and operational measures aimed at organizations that develop or manage the operations of advanced generative AI systems with general‑purpose capabilities, and identifies additional measures for systems that are widely made available. The Code is explicitly an interim, non‑binding instrument designed to help industry adopt consistent safety and governance practices in advance of or alongside eventual binding legislation such as the Artificial Intelligence and Data Act (AIDA) proposed in Bill C‑27.

The Code is organized around six core principles: accountability; safety; fairness and equity; transparency; human oversight and monitoring; and validity and robustness. Under those principles it encourages organizations to: implement proportionate risk‑management frameworks; conduct pre‑deployment impact assessments and bias testing; perform technical safety, robustness and adversarial testing; publish appropriate transparency information about capabilities, limitations and uses; adopt labelling or other measures to identify AI‑generated content where feasible; establish channels for incident reporting and monitoring; and protect data and privacy in accordance with existing privacy laws. The Code also emphasizes collaboration between developers and managers of generative systems, data and model provenance documentation, and the sharing of safety‑relevant information to reduce systemic harms.

Although voluntary, the Code has been promoted through public announcements, and numerous Canadian and multinational companies have publicly signed on as pledging to apply the Code’s measures in their operations. The government has supplemented the Code with related materials, including a consultation report summarizing stakeholder input and an implementation guide for managers of AI systems (published March 6, 2025). The Code is explicitly tied to Canada’s broader AI policy architecture: it is presented as complementary to privacy and consumer protection laws (notably PIPEDA), and as a bridging instrument pending the eventual coming into force of AIDA and related regulation. The Code encourages alignment with international efforts and standards and references participation in multilateral discussions (for example at G7 and OECD venues).

Key practical features include guidance on risk classification and proportionate mitigation, documentation and recordkeeping (for auditing and oversight), human oversight mechanisms, and secure model and data management to guard against misuse and attacks. Because it is voluntary, statutory enforcement mechanisms and fines do not apply directly under the Code; however, the government signals potential reputational consequences for signatories, a public signatory registry, and the prospect that future mandatory rules (AIDA or other instruments) will enforce stricter obligations. The Code therefore functions both as a policy tool to accelerate best practices and as a signaling mechanism to industry and international partners. Ultimately, it seeks to balance support for innovation and adoption of generative AI in sectors like healthcare and finance with protections for safety, privacy, equity and fundamental rights.

Full article

Read full text ↗

Overview

Canada’s Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems was published by Innovation, Science and Economic Development Canada and announced on September 27, 2023. The Code articulates non‑binding commitments and operational measures for organizations that develop or manage advanced generative AI systems, and it is explicitly intended as an interim instrument to guide responsible practice while formal legislation such as the Artificial Intelligence and Data Act (AIDA) is developed. The Code prioritizes six core principles—accountability; safety; fairness and equity; transparency; human oversight and monitoring; and validity and robustness—and encourages proportionate, lifecycle‑based risk management. The government has also published complementary materials, including a public press release and an implementation guide for managers of AI systems; the primary government landing page for the Code is available at Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems and the launch was announced in a ministerial release at Minister Champagne launches voluntary code of conduct.

Definitions

The Code defines its scope around "advanced generative AI systems" and distinguishes between organizations that "develop" such systems and those that "manage the operations" (deployers/operators). It targets systems with general‑purpose generative capabilities while acknowledging narrower, application‑specific systems. Key definitional concepts include lifecycle phases (design, development, testing, deployment, monitoring); impact assessment (including safety, fairness, privacy and human rights impacts); and terms such as "widely available" to indicate systems subject to broader public exposure and therefore requiring enhanced mitigations. The Code also clarifies that it does not change existing legal obligations under federal privacy and other statutes, for example the Personal Information Protection and Electronic Documents Act (PIPEDA).

Governance and Institutional Framework

The Code establishes a governance expectation that organizations adopt clear internal accountability structures (e.g., responsible senior lead(s), risk committees, and cross‑functional review) and proportionate governance processes tied to system scale and impact. Signatories are encouraged to maintain documentation and records to support auditing and regulatory readiness and to maintain clear agreements between developers and managers that address information sharing, incident notification and remediation responsibilities. The Government of Canada (through Innovation, Science and Economic Development Canada) acts as the steward and promoter of the Code while continuing to develop binding instruments such as AIDA; other public bodies with complementary roles include the Office of the Privacy Commissioner of Canada for privacy guidance and oversight and sectoral regulators who retain existing mandates over safety, consumer protection and financial regulation. The Code further references an evolving advisory architecture (Advisory Council on Artificial Intelligence; Safe and Secure AI Advisory Group) established to provide technical and governance advice to the government.

Key Focus Areas

The Code centers on six interrelated focus areas. 1) Accountability: implement proportionate risk management frameworks, designate accountable leads, and maintain documentation of decisions and mitigations. 2) Safety: perform pre‑deployment impact and safety assessments, adversarial and red‑teaming testing, and monitor real‑world harms. 3) Fairness & equity: conduct bias assessment and mitigation across the model lifecycle and maintain demographic and performance testing where applicable. 4) Transparency: publish capability, limitation and provenance statements, and adopt measures to identify AI‑generated content where feasible. 5) Human oversight & monitoring: incorporate human‑in‑the‑loop or human‑on‑the‑loop controls, escalation pathways, and incident response processes. 6) Validity & robustness: ensure testing, model evaluation, secure model packaging and versioning, and procedures to address misuse and model drift. The Code additionally encourages collaboration among developers and managers (data and model provenance sharing), responsible disclosure practices, and alignment with sectoral obligations in regulated domains such as healthcare and finance.

Implementation Framework

The Code recommends a lifecycle approach: identify system purpose and risk profile during design; collect and document training and evaluation data provenance; perform pre‑deployment impact and safety assessments; carry out technical testing (robustness, adversarial, bias metrics); deploy with clear user guidance and content labelling practices; and implement continuous monitoring and incident reporting. Signatories are encouraged to adopt proportionate controls based on anticipated impact and exposure—systems that are "widely available" or integrated into critical services are expected to apply additional mitigation measures. The government supports implementation with resources including an Implementation Guide for Managers of AI Systems published March 6, 2025 and by maintaining a public registry of signatories to foster transparency and peer learning.

Monitoring and Evaluation

Monitoring responsibilities under the Code include ongoing technical performance evaluation, tracking of harms or near misses, and maintenance of incident logs. The Code asks signatories to adopt monitoring tools, define metrics for safety and fairness, and commit to periodic review cycles. The government monitors uptake through signatory counts and public announcements; additional evaluation is expected to come from multi‑stakeholder advisory groups and periodic updates to guidance materials. While the Code does not create an audit regime, maintaining documentation and technical evidence enables both internal governance and future conformity with binding regulation when it is enacted.

Penalties, Liability, and Appeals

As a voluntary instrument, the Code contains no statutory fines or formal administrative penalty mechanisms. Legal obligations and liability remain governed by existing law (for example, privacy obligations under PIPEDA and sectoral safety and consumer protection laws). However, practical sanctions for non‑compliance with voluntary commitments can include public removal from signatory lists, reputational consequences, and potential commercial effects (e.g., impacts on procurement eligibility or partner relationships). The Code also signals that future mandatory legislation (AIDA) may impose enforceable obligations and penalties; organizations are therefore advised to treat Code commitments as preparatory compliance measures to reduce legal and operational risk.

Relationship to Other Instruments

The Code is expressly positioned as complementary to Canada’s legislative and regulatory agenda for AI. It references the proposed Artificial Intelligence and Data Act (AIDA) (Bill C‑27) and existing statutory regimes such as PIPEDA. It is consistent with Treasury Board policies on automated decision‑making for the public sector and aligns with sectoral regulation (e.g., health product safety, financial services rules) as applicable. The Code also references stakeholder consultation outputs and serves as an operational bridge to international standards and collaborative instruments.

International Alignment

The Code reflects Canada’s intent to align with international deliberations and good practice—citing participation in G7, OECD and like‑minded partnerships—and harmonizes with other voluntary commitments (for example, the White House voluntary AI commitments and OECD AI guidance). By promoting transparency, data provenance, safety testing and incident information sharing, the Code aims to facilitate cross‑jurisdictional interoperability of practices and to contribute to emerging international standards for generative AI governance.

Implementation Timeline

EventDateNotes
Official launch (ministerial announcement)2023-09-27Press release
Ongoing signatory recruitment (multiple announcements)2023-11 to 2024-11 (and ongoing)Periodic news releases on new signatories; government-maintained registry
Implementation guide published2025-03-06Implementation Guide for Managers of AI Systems
Advisory/technical groups refreshed and launched2024-11 to 2025-03Advisory Council and Safe & Secure AI Advisory Group involvement

Sources and References

SourceType
Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI SystemsPrimary Source
Minister Champagne launches voluntary code of conduct relating to advanced generative AI systems (press release)Primary Source
Implementation Guide for Managers of AI SystemsPrimary Source

Requirements for a company

What an organisation has to do under Canada - Responsible AI Development, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

0

Nothing in this category.

Must not do

0

Nothing in this category.

Should do

8
  • Designate accountable senior leaders to oversee AI risk management and governance processes.Organizations developing or managing advanced generative AI systems
  • Implement a risk management framework proportionate to system scale, capability, and potential impact.Organizations developing or managing advanced generative AI systems
  • Perform pre-deployment safety assessments and adversarial red-teaming testing to identify potential system harms.Organizations developing or managing advanced generative AI systems
  • Conduct bias assessments and apply mitigation measures across the entire generative AI model lifecycle.Organizations developing or managing advanced generative AI systems
  • Publish clear public statements outlining system capabilities, known limitations, and data provenance.Organizations developing or managing advanced generative AI systems
  • Adopt technical measures to identify and label AI-generated content where feasible.Organizations developing or managing advanced generative AI systems
  • +2 more in the table below

Should not do

0

Nothing in this category.

Who must do what

The obligations under Canada - Responsible AI Development, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Organizations developing or managing advanced generative AI systemsDesignate accountable senior leaders to oversee AI risk management and governance processes.
adopt clear internal accountability structures (e.g., responsible senior lead(s), risk committees, and cross‑functional review)
Governance and Institutional FrameworkRecommended
2Organizations developing or managing advanced generative AI systemsImplement a risk management framework proportionate to system scale, capability, and potential impact.
implement proportionate risk management frameworks, designate accountable leads, and maintain documentation of decisions and mitigations.
Key Focus AreasRecommended
3Organizations developing or managing advanced generative AI systemsPerform pre-deployment safety assessments and adversarial red-teaming testing to identify potential system harms.
perform pre‑deployment impact and safety assessments, adversarial and red‑teaming testing, and monitor real‑world harms.
Before deploymentKey Focus AreasRecommended
4Organizations developing or managing advanced generative AI systemsConduct bias assessments and apply mitigation measures across the entire generative AI model lifecycle.
conduct bias assessment and mitigation across the model lifecycle and maintain demographic and performance testing where applicable.
Key Focus AreasRecommended
5Organizations developing or managing advanced generative AI systemsPublish clear public statements outlining system capabilities, known limitations, and data provenance.
publish capability, limitation and provenance statements, and adopt measures to identify AI‑generated content where feasible.
Before deploymentKey Focus AreasRecommended
6Organizations developing or managing advanced generative AI systemsAdopt technical measures to identify and label AI-generated content where feasible.
adopt measures to identify AI‑generated content where feasible.
Key Focus AreasRecommended
7Organizations developing or managing advanced generative AI systemsEstablish human-in-the-loop or human-on-the-loop oversight controls and clear escalation pathways.
incorporate human‑in‑the‑loop or human‑on‑the‑loop controls, escalation pathways, and incident response processes.
Key Focus AreasRecommended
8Organizations managing operations of generative AI systemsTrack real-world harms, model drift, and near misses, maintaining detailed incident logs for continuous evaluation.
ongoing technical performance evaluation, tracking of harms or near misses, and maintenance of incident logs.
Monitoring and EvaluationRecommended

© Regulations.AI · reviewed against official sources on 07-Sep-2026 using Gemini 3.6 Flash