Canada - Ontario - AI Governance Act (Bill 194)
Enhancing Digital Security and Trust Act, 2024
Canada
RAI-CA-ON-EDST2XX-2024Ontario's Enhancing Digital Security and Trust Act, 2024 mandates cybersecurity and responsible AI use, and enhances privacy protections for public sector entities.
Summary
Read full text ↗Plain English
Overview
The Enhancing Digital Security and Trust Act, 2024 (EDSTA) was enacted as Schedule 1 of Bill 194, officially known as the Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024. This significant piece of legislation received Royal Assent on November 25, 2024, and the EDSTA itself came into force on January 29, 2025. The overarching Bill 194 aims to provide new tools to prevent and respond to cybersecurity threats, lay the foundation for the ethical use of artificial intelligence (AI) in the public sector, and expand privacy protections for personal information. It applies broadly to public sector entities in Ontario, including institutions defined under the Freedom of Information and Protection of Privacy Act (FIPPA) and the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), as well as children's aid societies and school boards. The Act also introduces important amendments to FIPPA, enhancing and modernizing privacy safeguards within the province. The government's stated belief is that AI systems in the public sector should be used in a responsible, transparent, accountable, and secure manner that benefits the people of Ontario while protecting privacy. Furthermore, it recognizes that digital information and technology related to children warrants special protection.
Definitions
While the full, detailed definition of 'artificial intelligence system' is expected to be prescribed by future regulations, the Act's preamble and related government documents indicate that it refers to machine-based systems that infer from input to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. Public sector entities, to which the EDSTA applies, are defined as institutions within the meaning of the Freedom of Information and Protection of Privacy Act (FIPPA), institutions within the meaning of the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), children's aid societies, and school boards. Notably, the Legislative Assembly of Ontario is explicitly excluded from this definition. The Act also addresses 'digital technology' and 'digital information' as they relate to individuals under age 18, with specific provisions for children's aid societies and school boards.
Governance and Institutional Framework
The EDSTA establishes a robust governance structure, granting significant powers to the Lieutenant Governor in Council and the Minister of Public and Business Service Delivery. The Lieutenant Governor in Council is empowered to make regulations governing cybersecurity at prescribed public sector entities, including requirements for developing and implementing cybersecurity programs and incident reporting. The Minister has the authority to make regulations setting technical standards for cybersecurity and AI systems, and to issue directives to public sector entities respecting cybersecurity. These directives may be general or particular in their application.
A key institutional player is the Information and Privacy Commissioner of Ontario (IPC). Amendments to FIPPA, brought about by Bill 194, significantly expand the IPC's authority. The IPC now has enhanced powers to investigate privacy compliance, conduct reviews, and administer orders. This includes the ability to request copies of Privacy Impact Assessments (PIAs) and related documentation for review. The IPC's expanded role underscores a commitment to stronger independent oversight and enforcement of privacy and digital security mandates across the public sector.
Complementing the EDSTA, the Government of Ontario has also implemented the 'Responsible Use of Artificial Intelligence Directive', which took effect on December 1, 2024. This Directive aims to guide Government of Ontario ministries and provincial agencies in the responsible, transparent, and accountable use of AI. It establishes principles for AI use and requires ministries and agencies to engage in AI risk management, disclose AI use cases, and report on identified risks. The Directive sets requirements for AI risk management, disclosure, and accountability associated with AI use in public programs and services.
Key Focus Areas
- AI System Requirements: The EDSTA mandates that public sector entities comply with requirements respecting the use of artificial intelligence. These requirements, largely to be detailed in regulations, include providing information to the public about their use of AI, developing and implementing accountability frameworks, taking steps for risk management, and ensuring an individual provides oversight of the AI system's use. Regulations may also set technical standards for AI systems.
- Cybersecurity Programs and Incident Reporting: Public sector entities will be required to develop and implement comprehensive cybersecurity programs. These programs are expected to include elements such as the assignment of internal responsibility, education and awareness initiatives, and incident response protocols. The Act also enables regulations to mandate reporting on cybersecurity incidents, with different requirements for various types of incidents, and to set technical standards for cybersecurity.
- Privacy Protection Enhancements (FIPPA Amendments): Bill 194 introduces several key amendments to the Freedom of Information and Protection of Privacy Act (FIPPA). These include a mandatory requirement for institutions to conduct Privacy Impact Assessments (PIAs) before collecting personal information and to keep them current with any significant changes to information processing purposes. Institutions must also implement reasonable safeguards to protect personal information from theft, loss, or unauthorized use/disclosure. Mandatory breach notification requirements are introduced, compelling institutions to report breaches to the IPC and notify affected individuals if there is a 'real risk of significant harm'. Furthermore, the IPC's powers are expanded to include investigation and order-making, and whistleblower protections are established for those reporting privacy wrongdoings.
- Digital Technology Affecting Individuals Under 18: The Act specifically addresses digital technology and information relating to individuals under 18 years of age. It allows for regulations to be made governing the collection, use, retention, and disclosure of prescribed digital information by children's aid societies and school boards. These regulations may also set technical standards for such information and the digital technology involved. The Minister is also empowered to issue directives to children's aid societies and school boards regarding digital technology made available for use by individuals under 18.
Implementation Framework
A significant portion of the EDSTA's specific requirements and obligations will be fleshed out through forthcoming regulations. While the Act provides the legislative framework, many of the detailed procedures, technical standards, and compliance mechanisms for both cybersecurity and AI systems are yet to be established by these regulations. Public sector entities are encouraged to begin preparing for compliance, even as these regulations are being developed, by reviewing their current practices in anticipation of the new requirements. The staggered effective dates for different parts of the legislation (EDSTA in January 2025, some FIPPA amendments in July 2025) also reflect a phased implementation approach.
Monitoring and Evaluation
Monitoring and evaluation of compliance with the EDSTA and its associated regulations will primarily fall under the purview of the Information and Privacy Commissioner of Ontario (IPC). The amendments to FIPPA grant the IPC expanded authority to conduct investigations into information practices and to issue orders compelling institutions to make necessary changes to ensure compliance. This enhanced oversight capacity allows for rigorous monitoring of how public sector entities handle personal information, manage cybersecurity risks, and implement AI systems responsibly. The requirements for public sector entities to submit reports on cybersecurity incidents and disclose information about AI use will also serve as mechanisms for monitoring and evaluation. The 'Responsible Use of Artificial Intelligence Directive' also mandates ministries to report on AI use cases and risk management annually.
Penalties, Liability, and Appeals
While the EDSTA itself does not explicitly detail a schedule of criminal or civil penalties, the expanded powers granted to the Information and Privacy Commissioner of Ontario (IPC) under the amended FIPPA include the ability to issue orders. These orders can compel institutions to change their information practices or take other necessary actions to ensure compliance. Non-compliance with such orders would likely lead to further enforcement actions. The Act specifically states that nothing in the Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, the EDSTA, or any regulation or directive issued under it, establishes a private law duty of care owing to any person. Furthermore, failure to comply with the Act or its regulations/directives does not affect the validity of any policy, Act, regulation, directive, instrument, or decision. In cases of conflict between a provision of the EDSTA or its regulations/directives and a provision of any other Act or regulation, the provision in the other Act or regulation prevails.
Relationship to Other Instruments
The Enhancing Digital Security and Trust Act, 2024, is intrinsically linked to and forms part of the broader legislative landscape in Ontario. It was enacted as Schedule 1 of the Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024 (Bill 194). Crucially, Bill 194 also introduces significant amendments to the Freedom of Information and Protection of Privacy Act (FIPPA), modernizing privacy protections for public sector entities. These amendments include new requirements for Privacy Impact Assessments, mandatory breach reporting, and expanded powers for the Information and Privacy Commissioner of Ontario. The Act's scope also extends to institutions defined under the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA).
Furthermore, the EDSTA operates in conjunction with the Ontario government's 'Responsible Use of Artificial Intelligence Directive,' which became effective on December 1, 2024. This Directive provides internal guidance for Government of Ontario ministries and provincial agencies on the responsible, transparent, and accountable use of AI, including requirements for AI risk management and disclosure. The EDSTA provides the legislative backing for many of the principles outlined in this Directive, creating a comprehensive framework for AI governance in the public sector. The Act's definition of AI systems, once fully prescribed by regulations, is expected to align with international standards, such as the OECD definition of AI systems, demonstrating a move towards harmonization.
International Alignment
While the direct legislative text does not explicitly detail international alignment, the intent behind the Enhancing Digital Security and Trust Act, 2024, and its associated policies, such as the Responsible Use of Artificial Intelligence Directive, indicate a move towards aligning with global best practices in AI governance and cybersecurity. The Ontario Human Rights Commission (OHRC) has emphasized the importance of recognizing human rights in Bill 194 and requiring non-discrimination in AI use, noting that such an approach would align Ontario with international standards for effective AI policies. This suggests an awareness and intention to incorporate principles that are globally recognized in the development and deployment of AI and digital security frameworks. The broad scope of AI systems as machine-based systems generating predictions, content, recommendations, or decisions, as implied by the Act, reflects a general understanding consistent with definitions used in other jurisdictions and international bodies.
Implementation Timeline
| Date | Event |
|---|---|
| 2024-05-13 | Bill 194, Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, tabled (First Reading) |
| 2024-11-25 | Bill 194 received Royal Assent |
| 2024-12-01 | Responsible Use of Artificial Intelligence Directive took effect |
| 2025-01-29 | Enhancing Digital Security and Trust Act, 2024 (EDSTA) came into force |
| 2025-07-01 | Some amendments to the Freedom of Information and Protection of Privacy Act (FIPPA) come into force |
Compliance Checklist
| Requirement | Description |
|---|---|
| Cybersecurity Program Development | Public sector entities must develop and implement comprehensive cybersecurity programs in accordance with forthcoming regulations. |
| Cybersecurity Incident Reporting | Establish procedures for reporting cybersecurity incidents to the Minister or a specified individual, as prescribed by regulations. |
| AI Use Disclosure | Public sector entities must inform the public about their use of artificial intelligence systems. |
| AI Accountability Framework | Develop and implement an accountability framework respecting the use of AI systems. |
| AI Risk Management | Take prescribed steps to manage risks associated with the use of AI systems. |
| Human Oversight of AI | Ensure an individual provides oversight of the use of an artificial intelligence system in prescribed circumstances. |
| Privacy Impact Assessments (PIAs) | Conduct and keep current PIAs before collecting personal information or making significant changes to its use or disclosure, unless otherwise prescribed. |
| Personal Information Safeguards | Implement reasonable safeguards to protect personal information from theft, loss, unauthorized use, or disclosure, and against unauthorized copying, modification, or disposal. |
| Mandatory Breach Reporting | Report privacy breaches to the IPC and notify affected individuals if there is a real risk of significant harm. |
| Compliance with Directives/Regulations | Adhere to any technical standards, regulations, or directives issued by the Minister or Lieutenant Governor in Council regarding cybersecurity and AI. |
| Protection of Minors' Digital Information | Comply with regulations and directives concerning the collection, use, retention, and disclosure of digital information relating to individuals under age 18. |
Sources and References
| Source | URL |
|---|---|
| Legislative Assembly of Ontario - Bill 194, Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024 | https://www.ola.org/en/legislative-business/bills/parliament-43/session-1/bill-194 |
| Government of Ontario - Enhancing Digital Security and Trust Act, 2024, S.O. 2024, c. 24, Sched. 1 | https://www.ontario.ca/laws/statute/24e24#BK1 |
| Government of Ontario - Responsible Use of Artificial Intelligence Directive | https://www.ontario.ca/page/responsible-use-artificial-intelligence-directive |
| Legislative Assembly of Ontario - Bill 194, Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, SO 2024, c. 24 | https://www.ontario.ca/laws/statute/24s24 |
| Toronto Metropolitan University - Enhancing Digital Security and Trust Act (EDSTA) | https://www.torontomu.ca/privacy/legislation/edsta/ |
| Ontario Newsroom - Regulations and Statutes in Force as of January 1, 2024 | https://news.ontario.ca/en/backgrounder/1003923/regulations-and-statutes-in-force-as-of-january-1-2024 |
Ontario's Enhancing Digital Security and Trust Act, 2024 (EDSTA) sets new rules for cybersecurity, the responsible use of artificial intelligence, and privacy protection for public sector entities across the province. This includes government ministries, municipal bodies, children's aid societies, and school boards, though the Legislative Assembly of Ontario is specifically excluded.
The Act, which came into force on January 29, 2025, introduces several key obligations. Public sector organizations must: - Develop and implement comprehensive cybersecurity programs and report incidents. - Use artificial intelligence systems responsibly, which means being transparent with the public about their use, establishing accountability frameworks, managing associated risks, and ensuring human oversight. The precise definition of an "artificial intelligence system" will be detailed in upcoming regulations. - Enhance privacy protections through significant amendments to the Freedom of Information and Protection of Privacy Act (FIPPA). These changes mandate Privacy Impact Assessments (PIAs) before collecting personal information, require reasonable safeguards for data, and introduce mandatory reporting of privacy breaches to the Information and Privacy Commissioner of Ontario (IPC) and affected individuals if there's a "real risk of significant harm." Some of these FIPPA amendments take effect on July 1, 2025. - Adhere to special provisions for digital information and technology concerning individuals under 18, particularly for children's aid societies and school boards.
The Information and Privacy Commissioner of Ontario (IPC) gains expanded powers to investigate compliance and issue orders compelling organizations to make necessary changes. While the EDSTA itself doesn't introduce new criminal or civil penalties, non-compliance with an IPC order would lead to further enforcement. A crucial practical point is that many specific requirements and technical standards will be fleshed out in future regulations, meaning entities need to anticipate and prepare for compliance even as the full details are still emerging. The Act also clarifies that it does not create a private right for individuals to sue based on its provisions.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 11 marked completePlain-English obligations under Canada - Ontario - AI Governance Act (Bill 194). Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Jul 1, 2025
Applies to: Public sector institutions collecting personal information.
“mandatory requirement for institutions to conduct Privacy Impact Assessments (PIAs) before collecting personal information and to keep them current.”
- #2Critical⏰ Jul 1, 2025
Applies to: Public sector institutions holding personal information.
“Institutions must also implement reasonable safeguards to protect personal information from theft, loss, or unauthorized use/disclosure.”
- #3Critical⏰ Jul 1, 2025
Applies to: Public sector institutions experiencing a privacy breach.
“Mandatory breach notification requirements are introduced, compelling institutions to report breaches to the IPC and notify affected individuals.”
- #4Critical
Applies to: Public sector entities in Ontario.
“Public sector entities must develop and implement comprehensive cybersecurity programs in accordance with forthcoming regulations.”
- #5Critical
Applies to: Public sector entities in Ontario.
“Establish procedures for reporting cybersecurity incidents to the Minister or a specified individual, as prescribed by regulations.”
- #6Critical
Applies to: Public sector entities using AI systems.
“Public sector entities must inform the public about their use of artificial intelligence systems.”
- #7Critical
Applies to: Public sector entities using AI systems.
“Develop and implement an accountability framework respecting the use of AI systems.”
- #8Critical
Applies to: Public sector entities using AI systems.
“Take prescribed steps to manage risks associated with the use of AI systems.”
- #9Critical
Applies to: Public sector entities using AI systems.
“Ensure an individual provides oversight of the use of an artificial intelligence system in prescribed circumstances.”
- #10Critical⏰ Jan 29, 2025
Applies to: Public sector entities in Ontario.
“Adhere to any technical standards, regulations, or directives issued by the Minister or Lieutenant Governor in Council regarding cybersecurity and AI.”
- #11Critical
Applies to: Children's aid societies and school boards.
“Comply with regulations and directives concerning the collection, use, retention, and disclosure of digital information relating to individuals under age 18.”
Related Regulations
Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024
Canada98% similar
Ontario Working for Workers Act - AI Hiring Disclosure
Canada90% similar
Énoncé de principes pour une utilisation responsable de l'intelligence artificielle par les organismes publics (Québec Ministry of Cybersecurity and Digital Affairs)
Canada89% similar
Canada - Provincial AI Legislation Summary
Canada89% similar
Bill for the Establishment of the National Agency for AI Governance
Morocco88% similar
© Regulations.AI — created on 03-Jan-2026 using Gemini 2.5 Flash