Canada - Quebec - Responsible AI Use Guidelines

Statement of Principles for the Responsible Use of Artificial Intelligence by Public Organizations

Énoncé de principes pour une utilisation responsable de l'intelligence artificielle par les organismes publics

Canada

RAI-CA-QC-NDPPUXX-2024
Effective: June 27, 2024
In Force(In Force)
GuidelineGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

A principles-based statement adopted by the Quebec Minister of Cybersecurity and Digital Affairs on 27 June 2024 that sets ten guiding principles for responsible use of AI by public-sector organizations. It provides proportionate, lifecycle-oriented guidance on lawfulness, equity, privacy, accountability, traceability, and governance and is annexed to the ministerial order published in the Gazette officielle du Québec.

Overview

The Énoncé de principes, annexed to Arrêté n° 2024-02 adopted on 27 June 2024 and published in the Gazette officielle du Québec (7 August 2024), sets ten guiding principles for the responsible use of artificial intelligence by Quebec public bodies. The statement is lifecycle-oriented and emphasizes proportionate risk management, applicability to supplier relationships, and respect for fundamental rights and existing legal regimes. The full official text is published in the Government of Quebec Gazette and is available from the official publisher; the statement is complemented by ministerial directions and sectoral guidance such as the Guide of good practices for generative AI (October 2024). For the authoritative text see Gazette officielle du Québec — Énoncé de principes (PDF) and the Ministry publications page at Ministère de la Cybersécurité et du Numérique — Publications.

Definitions

The statement adopts the OECD Council definition of an "AI system": an automated system that, for explicit or implicit objectives, infers how to generate outputs such as predictions, content, recommendations or decisions that may affect environments. It further frames key terms used across the instrument — lifecycle phases (planning, data collection, model construction or adaptation, testing and validation, deployment, operation and monitoring, decommissioning), "organisms publics" as those listed in article 2 of the LGGRI, "supplier" to include vendors and external service providers, and "proportionality" which requires that measures applied be commensurate with the risks and benefits of a given AI use-case. The document references complementary legal instruments including privacy and access legislation and the Declaration of Values of the Quebec public administration and encourages alignment with OECD and other international instruments.

Governance and Institutional Framework

The statement requires public organizations to embed the principles into institutional governance: designate accountable officials (e.g., project owners, chief information officers, privacy officers), establish internal oversight structures (AI governance boards or committees), and integrate AI oversight into enterprise information resource governance. It instructs organizations to ensure supplier contracts and procurement processes embed the same principles and to incorporate contractual clauses that secure traceability, data protection, liability allocation, maintenance and update commitments, and security requirements. The guidance is intended to be operationalized through existing governance instruments under the LGGRI and to be verified by the Minister’s oversight powers; the statement is therefore designed to be referenced in internal policies, procurement templates and compliance reporting. For background and publication details, see the Gazette deposit at official PDF and the Ministry publications index at Ministère publications.

Key Focus Areas

The instrument organizes guidance around ten core principles that operationalize into multiple focus areas: (1) respect for persons and the rule of law (ensuring legal collection and use of training and operational data, adhering to privacy law and human rights), (2) inclusion and equity (mitigating bias, promoting accessibility and equitable service outcomes), (3) transparency and traceability (documenting model provenance, inputs, outputs and decisions and providing explanations when reasonable), (4) security and data protection (adopting appropriate safeguards for information assets and confidential data), (5) reliability and quality (validation, testing and monitoring to ensure systems perform as intended), (6) proportionality (matching safeguards to the risk level), (7) accountability and governance (clear assignment of roles and decision rights), (8) competence and skills (training staff and ensuring technical expertise for development and oversight), (9) environmental sobriety (consideration for computational resources and sustainability), and (10) openness to audit (maintaining records to allow independent verification and oversight). These focus areas are intended to be applied throughout the lifecycle of AI systems and to extend to third-party vendors and partners, such that procurement, contract oversight and vendor management must reflect the same expectations. The statement also highlights the need for privacy impact assessments and other legal assessments where personal data are involved.

Implementation Framework

The statement instructs organizations to incorporate the principles into existing management frameworks rather than create stand-alone processes: embed requirements in project governance, procurement criteria, information asset inventories and risk registers; require privacy and ethical impact assessments where warranted; classify AI initiatives according to potential risk to rights and services and apply proportionate controls; implement verification steps (testing, simulation, staging environments) before production deployment; and maintain documentation for traceability and audit. The document encourages the use of standardized templates and checklists, encourages cross-functional teams (legal, privacy, cybersecurity, operations, policy) and recommends designation of an AI responsible officer within each organization to coordinate compliance. It also signals that the Minister may verify application of these orientations under LGGRI provisions, and organizations should therefore prepare to provide documentary evidence of governance, assessments, test plans, contractual clauses and monitoring records.

Monitoring and Evaluation

Monitoring is framed as continuous and risk-based: organizations must maintain operational monitoring of AI system performance, drift detection, incident reporting and logs sufficient to enable traceability and post-incident analysis. Periodic re-evaluation of systems (including retraining validation) is required where models interact with evolving data or environments. The statement calls for metrics and key performance indicators relevant to accuracy, fairness, security and privacy and for escalation procedures where thresholds are breached. It also anticipates annual reporting and inventory obligations introduced by related ministerial orders, requiring organizations to declare AI-related assets, projects and initiatives to central information governance authorities according to specified schedules.

Penalties, Liability, and Appeals

The principles document itself does not create novel criminal penalties; rather it is an orientation annexed to a ministerial arrêté and its respect may be subject to verification pursuant to LGGRI (article 22.2). Consequences for non-compliance are therefore likely to flow from administrative oversight, corrective measures, contractual remedies (where procurement contracts include compliance clauses), civil liability under existing law, and internal disciplinary procedures. The statement calls on organizations to clearly allocate liability and redress responsibilities in contracts and to ensure accessible remedies for individuals affected by AI-driven decisions, including mechanisms for appeal, contestation and human review. It recommends maintenance of records to substantiate compliance and to support investigations or appeals when outcomes are challenged.

Relationship to Other Instruments

The Énoncé explicitly references and aligns with the LGGRI and with Quebec privacy and access legislation (e.g., Loi sur l'accès aux documents des organismes publics et sur la protection des renseignements personnels) and administrative values such as the Declaration of Values of the Quebec public administration. It situates itself as complementary to other ministerial arrêtés (for example, Arrêté n° 2024-01 concerning reporting of AI initiatives) and to sectoral guides like the Ministry of Education’s Guide on generative AI usage. It also notes methodological alignment with international instruments (OECD AI Recommendation) and encourages organizations to integrate existing cybersecurity standards, procurement rules and privacy impact assessment requirements into AI governance materials. The official annexation and publication in the Gazette render the orientations formal ministerial directions to public bodies covered by LGGRI (see the official PDF for the wording).

International Alignment

The statement adopts an expressly internationalist posture: it relies on the OECD Council definition and references the OECD recommendation on AI, and it states that the approach is designed to align with major international frameworks including the EU AI Act's risk-based approach and the NIST AI Risk Management Framework. It highlights the importance of interoperability with international procurement standards and cross-border data flows, while maintaining compliance with domestic privacy and access laws. This cross-referencing is intended to help Québec public organizations adopt practices that will be compatible with both national and international compliance regimes and with vendor-supplied certifications or attestations.

Implementation Timeline

EventDateRemarks
Ministerial adoption (Arrêté n° 2024-02)2024-06-27Annexed to arrêté; orientations determined for LGGRI compliance
Gazette publication2024-08-07Official publication in Gazette officielle du Québec
Complementary generative AI guide published2024-10-XXOperational guidance for externally hosted generative AI tools (Ministry publication)
Annual AI asset/project declaration (related arrêté n°2024-01)Annually by 15 JuneOrganizations must declare AI assets and initiatives per ministerial requirements

Compliance Checklist

RequirementAction
Legal & privacy conformityConduct privacy/legality impact assessments and document results
GovernanceDesignate accountable officials; create oversight committee
Procurement & contractsEmbed clauses for traceability, liability, updates and security
Testing & validationMaintain test plans, validation results and staging environments
MonitoringImplement runtime monitoring and incident logs; schedule periodic reviews
DocumentationMaintain lifecycle records enabling audit and verification
TrainingProvide role-based training and competency development for staff

Sources and References

SourceType
Énoncé de principes pour une utilisation responsable de l'intelligence artificielle par les organismes publics — Gazette officielle du Québec (PDF)Primary Source
Plain English

The Quebec government has issued a new guideline, adopted on June 27, 2024, that establishes ten guiding principles for the responsible use of artificial intelligence by public-sector organizations and their external suppliers. This framework applies to all Quebec public bodies, as defined by the province's governance laws, and extends to any third-party vendors or service providers involved in developing, deploying, or operating AI systems on their behalf.

Public organizations must integrate these principles into their existing management frameworks, rather than creating separate processes. Key obligations include: - Establishing robust internal governance, which means designating accountable officials and setting up oversight structures like AI governance boards. - Conducting thorough risk and impact assessments, such as privacy impact assessments, for all AI initiatives and implementing safeguards proportionate to the identified risks. - Ensuring that contracts with AI suppliers clearly embed these principles, with specific clauses covering traceability, data protection, liability allocation, and security requirements. - Maintaining comprehensive documentation throughout the entire lifecycle of an AI system, from its initial planning and data collection to deployment, monitoring, and eventual decommissioning, to ensure transparency and auditability.

While this guideline does not introduce new criminal penalties, adherence is subject to verification by the Minister of Cybersecurity and Digital Affairs under existing legislation. Non-compliance can lead to administrative oversight, corrective measures, and contractual remedies. Organizations should be ready to provide documentary evidence of their governance, assessments, and monitoring efforts.

A crucial practical point for organizations is the requirement to make annual declarations of their AI assets and projects. This related ministerial order mandates that public bodies report their AI initiatives by June 15 each year, ensuring ongoing transparency and central oversight of AI use across the public sector.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 15 marked complete

Plain-English obligations under Canada - Quebec - Responsible AI Use Guidelines. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalGovernance and Institutional Framework

    Applies to: Public organizations using AI.

    The statement requires public organizations to embed the principles into institutional governance
  2. #2CriticalGovernance and Institutional Framework

    Applies to: Public organizations using AI.

    designate accountable officials (e.g., project owners, chief information officers, privacy officers)
  3. #3CriticalGovernance and Institutional Framework

    Applies to: Public organizations using AI.

    establish internal oversight structures (AI governance boards or committees)
  4. #4CriticalGovernance and Institutional Framework

    Applies to: Public organizations procuring AI systems.

    ensure supplier contracts and procurement processes embed the same principles
  5. #5CriticalGovernance and Institutional Framework

    Applies to: Public organizations procuring AI systems.

    incorporate contractual clauses that secure traceability, data protection, liability allocation, maintenance and update commitments, and security requirements.
  6. #6CriticalKey Focus Areas

    Applies to: Public organizations using AI.

    ensuring legal collection and use of training and operational data, adhering to privacy law and human rights
  7. #7CriticalKey Focus Areas

    Applies to: Public organizations using AI.

    adopting appropriate safeguards for information assets and confidential data
  8. #8CriticalKey Focus Areas

    Applies to: Public organizations using AI with personal data.

    highlights the need for privacy impact assessments and other legal assessments where personal data are involved.
  9. #9CriticalKey Focus Areas

    Applies to: Public organizations using AI.

    maintaining records to allow independent verification and oversight.
  10. #10CriticalMonitoring and Evaluation

    Applies to: Public organizations operating AI systems.

    organizations must maintain operational monitoring of AI system performance, drift detection, incident reporting and logs sufficient to enable traceability
  11. #11CriticalMonitoring and EvaluationAnnually by 15 June

    Applies to: Public organizations using AI.

    requiring organizations to declare AI-related assets, projects and initiatives to central information governance authorities according to specified schedules.
  12. #12CriticalPenalties, Liability, and Appeals

    Applies to: Public organizations using AI affecting individuals.

    ensure accessible remedies for individuals affected by AI-driven decisions, including mechanisms for appeal, contestation and human review.
  13. #13ImportantKey Focus Areas

    Applies to: Public organizations using AI.

    mitigating bias, promoting accessibility and equitable service outcomes
  14. #14ImportantKey Focus Areas

    Applies to: Public organizations using AI.

    documenting model provenance, inputs, outputs and decisions and providing explanations when reasonable
  15. #15ImportantKey Focus Areas

    Applies to: Public organizations using AI.

    validation, testing and monitoring to ensure systems perform as intended

© Regulations.AI — created on 13-Jun-2026