Canada - Provincial AI Regulations

Canada - Provincial AI Legislation Summary

Canada

RAI-CA-ST-SUMMARY-2026
Data Protection and PrivacyTransparency and DisclosureGovernance and Oversight
Export PDF

Canadian provinces are establishing diverse AI regulations, emphasizing privacy, transparency, and responsible use, particularly in public services and employment. This provincial action fills a federal legislative void, with key developments in Quebec, Ontario, Alberta, and British Columbia.

Overview

The Canadian provincial landscape for artificial intelligence (AI) regulation is dynamic and evolving, with several provinces taking proactive steps to establish frameworks for the responsible development and deployment of AI technologies. This activity is particularly notable given the current absence of comprehensive federal AI legislation. Provinces such as Quebec, Ontario, Alberta, and British Columbia have introduced or are in the process of implementing various acts, policies, and principles to address the opportunities and challenges presented by AI. These initiatives reflect a growing recognition among provincial governments of the need to govern AI to protect citizens' rights, ensure transparency, and foster public trust. The regulatory approaches vary, encompassing broad privacy modernizations that impact AI use, as well as specific guidelines for AI within public services and particular sectors.

The provincial efforts are contributing to a fragmented yet increasingly robust regulatory environment for AI across Canada. While some regulations are already in force, others are awaiting entry or are in draft stages, indicating a continuous evolution of the legal landscape.

Regulatory Approach

Provincial approaches to AI regulation in Canada exhibit a mix of legislative and principles-based frameworks, often with a strong emphasis on privacy and public sector governance. Quebec, for instance, has adopted a comprehensive legislative approach through its modernized personal information protection law, Law 25, which includes specific provisions for automated decision-making in both public and private sectors. This contrasts with British Columbia's initial focus on "Draft AI Responsible Use Principles" for its public service, aiming to guide ethical AI deployment through a set of values rather than prescriptive laws.

Ontario has pursued a hybrid model, enacting legislation like the Enhancing Digital Security and Trust Act, 2024, which creates a framework for AI regulation within the public sector, with many specific requirements to be detailed in future regulations. Concurrently, Ontario's Working for Workers Four Act, 2024, introduces a specific disclosure requirement for AI use in employment, targeting a particular sector. Alberta's recent Bills 33 and 34, while primarily modernizing public sector privacy and access to information, incorporate AI-specific provisions, such as mandating notification for automated decision systems. This diverse range of strategies highlights provinces adapting their regulatory tools to their specific governance priorities and existing legal structures.

Key State Legislation

  • Alberta:
    • Protection of Privacy Act (Bill 33) (Act, Awaiting Entry, 2024): Modernizes Alberta's public sector privacy laws, replacing parts of the FOIP Act. It mandates privacy management programs, impact assessments, and requires individuals to be notified if their personal data will be used in automated systems to generate decisions, predictions, or recommendations, including those involving AI. It also prohibits the sale of personal information.
    • Access to Information Act (Alberta Bill 34) (Act, Awaiting Entry, 2024): Introduced alongside Bill 33, this legislation aims to improve public access to information held by public bodies, while also clarifying what information can be withheld. Together with Bill 33, it replaces the Freedom of Information and Protection of Privacy (FOIP) Act.
  • British Columbia:
    • Draft Artificial Intelligence Responsible Use Principles (Policy, Draft, 2024): These principles establish an ethical framework for AI within the BC Public Service, guiding responsible AI deployment with an emphasis on transparency, accountability, public benefit, fairness, reliability, and safety.
    • Policy on the use of generative AI (Policy, In Force, 2025): Outlines how employees in the BC Public Service can use generative AI tools responsibly, safely, and in alignment with guiding principles, including protecting sensitive information and reviewing outputs for accuracy and inclusivity.
  • Ontario:
    • Enhancing Digital Security and Trust Act, 2024 (Act, In Force, 2024): Enacted as Schedule 1 of Bill 194, this Act establishes a framework for strengthening cybersecurity and governing the responsible use of AI systems within the provincial and municipal public sectors, including school boards and hospitals. It enables the government to enact regulations on AI use.
    • Ontario Working for Workers Four Act, 2024 - AI Hiring Disclosure (Act, Awaiting Entry, 2024): Mandates that employers disclose the use of artificial intelligence in publicly advertised job postings for screening, assessing, or selecting applicants. This aims to increase transparency in the hiring process.
  • Quebec:
    • An Act to modernize legislative provisions as regards the protection of personal information (Law 25) (Act, In Force (Amended), 2021): This landmark legislation significantly modernizes and strengthens personal information protection in Quebec. It includes provisions requiring organizations to inform individuals when personal information is collected using technology that identifies, locates, or profiles them, or when decisions are made solely based on automated processing. It also mandates explicit consent for tracking technologies.
    • Énoncé de principes pour une utilisation responsable de l'intelligence artificielle par les organismes publics (Guideline, In Force, 2024): A principles-based instrument adopted by the Quebec Minister of Cybersecurity and Digital Affairs, providing orientations for public bodies on the responsible management and use of AI, updated in December 2025.

Enforcement Bodies

Across the provinces, the primary enforcement and oversight bodies for AI-related regulations are typically the Information and Privacy Commissioners or similar independent offices. These bodies are generally responsible for upholding privacy rights and ensuring compliance with access to information legislation, which now increasingly includes provisions related to AI and automated decision-making. For example, in Alberta, the Office of the Information and Privacy Commissioner (OIPC) plays a crucial oversight role for Bills 33 and 34, with new powers and responsibilities related to privacy management programs and breach notifications.

In Quebec, the Commission d'accès à l'information du Québec (CAI) is responsible for enforcing Law 25, which includes its provisions on automated processing and personal information protection. Ontario's Enhancing Digital Security and Trust Act, 2024, also grants the Information and Privacy Commissioner of Ontario (IPC) new order-making powers and responsibilities concerning privacy impact assessments and data breach reporting within the public sector. For specific sector-focused regulations, such as Ontario's AI hiring disclosure, the Ministry of Labour, Immigration, Training and Skills Development would likely oversee compliance.

Penalties & Enforcement

Provincial AI-related legislation introduces significant penalties and robust enforcement mechanisms to ensure compliance and deter misuse of personal information and AI systems. Alberta's Protection of Privacy Act (Bill 33) introduces some of Canada's strictest penalties for the misuse of personal information, with potential fines of up to $750,000 for organizations and $125,000 for individuals found to be mishandling personal data. This underscores a strong commitment to safeguarding privacy in the context of modern data management, including AI.

Quebec's Law 25 also includes substantial penalties for non-compliance, aiming to align with global standards like the GDPR. It mandates breach reporting to the Commission d'accès à l'information du Québec and affected individuals when there is a risk of serious injury. While Ontario's Enhancing Digital Security and Trust Act, 2024, largely relies on future regulations to detail specific penalties, it empowers the government to establish cybersecurity programs and incident reporting requirements for public sector entities. For the AI hiring disclosure under the Working for Workers Four Act, 2024, employers who fail to comply may face fines and legal consequences.

Sector Focus Areas

Provincial AI regulations in Canada demonstrate a primary focus on the public sector and, increasingly, the employment sector, while also addressing broader privacy concerns that impact all sectors. British Columbia's Draft AI Responsible Use Principles and its Policy on the use of generative AI are explicitly directed at the BC Public Service, aiming to guide government employees in the ethical and responsible use of AI tools. Similarly, Quebec's Énoncé de principes targets public bodies, providing guidelines for their AI deployment. Ontario's Enhancing Digital Security and Trust Act, 2024, is also focused on public sector entities, including provincial and municipal institutions, school boards, and children's aid societies, regulating their use of AI systems and cybersecurity.

Beyond the public sector, the employment sector has emerged as a specific area of regulation, notably in Ontario. The Ontario Working for Workers Four Act, 2024, mandates that employers disclose the use of AI in publicly advertised job postings for screening, assessing, or selecting applicants, highlighting a focus on transparency in hiring practices. Quebec's Law 25, while broad in its application to both public and private organizations, has significant implications for any sector handling personal information, particularly concerning automated decision-making and consent. Alberta's Bills 33 and 34 also primarily target the public sector, but their modernization of privacy laws has broad implications for how public bodies interact with personal information, including that used in AI systems.

National/Federal Alignment

The provincial AI legislative efforts in Canada are largely proceeding in a landscape marked by a current legislative gap at the federal level. The proposed federal Artificial Intelligence and Data Act (AIDA), part of Bill C-27, was terminated in early 2025, leaving Canada without dedicated federal AI legislation. In this context, provincial laws are stepping in to establish regulatory frameworks, often reflecting principles that were considered in the federal discussions, such as transparency, accountability, and a risk-based approach to AI governance.

While a unified federal AI framework is absent, the federal government does have other mechanisms in place. These include the "Directive on Automated Decision-Making" for federal departments and agencies, which requires risk assessments and mitigation for AI systems. Additionally, the federal government has issued voluntary guidelines, such as a Guide on the use of generative AI in the public sector workplace and a Voluntary Code of Conduct for the private sector. Provincial initiatives, while independent, often align with the spirit of these federal principles, contributing to a broader, albeit fragmented, national commitment to responsible AI. The federal government is also developing an "AI Strategy for the Federal Public Service 2025-2027," which aims to ensure responsible and secure AI adoption within its own operations.

Notable Provisions

Several provincial AI-related provisions stand out for their pioneering nature or specific impact. Quebec's Law 25 is particularly notable for its rigorous data privacy and automated decision-making disclosure obligations, requiring organizations to inform individuals when decisions are made "exclusively through automated processing" and offering rights similar to the EU's GDPR, including explicit opt-in consent for tracking technologies. This positions Quebec at the forefront of privacy-centric AI regulation in North America.

Ontario's Working for Workers Four Act, 2024, introduces a pioneering requirement for employers to disclose the use of AI in publicly advertised job postings for screening, assessing, or selecting applicants. This provision directly addresses the growing use of AI in human resources and aims to increase transparency for job seekers. Alberta's Protection of Privacy Act (Bill 33) is also significant for introducing some of Canada's strictest penalties for the misuse of personal information, with fines up to $750,000 for organizations, reflecting a strong deterrent for privacy breaches involving AI systems in the public sector.

Future Developments

The provincial AI regulatory landscape in Canada is poised for further development, with several pieces of legislation awaiting full implementation and ongoing calls for expanded frameworks. In Alberta, Bills 33 and 34, which received Royal Assent in December 2024, are expected to come into force in Spring 2025, with supporting regulations anticipated to provide further details on requirements such as privacy management programs and privacy impact assessments. These acts also mandate a regular review of the legislation every six years to ensure currency with evolving technology.

In Ontario, while the Enhancing Digital Security and Trust Act, 2024, is in force, most of its requirements concerning AI systems will take the form of future regulations, indicating significant upcoming legislative activity. Similarly, the AI hiring disclosure requirement under the Working for Workers Four Act, 2024, is set to come into force on January 1, 2026, with forthcoming regulations expected to define key terms like "publicly advertised job posting" and "artificial intelligence." British Columbia's independent oversight offices are advocating for expanded public consultation on AI principles and the implementation of clear legislation to protect citizens' interests, suggesting potential future legislative reforms beyond the current draft principles. These ongoing developments highlight a proactive and adaptive approach by Canadian provinces to keep pace with the rapid advancements in AI technology.

State Regulations

All 6 regulations currently tracked for Canada at sub-national level.

RegionRegulationTypeStatusYear
AlbertaAccess to Information Act (Alberta Bill 34)ActIn Force2024
British ColumbiaDraft Artificial Intelligence Responsible Use PrinciplesPolicyDraft2024
OntarioEnhancing Digital Security and Trust Act, 2024ActIn Force2024
Ontario Working for Workers Act - AI Hiring DisclosureActAwaiting Entry2024
QuebecÉnoncé de principes pour une utilisation responsable de l'intelligence artificielle par les organismes publics (Québec Ministry of Cybersecurity and Digital Affairs)GuidelineIn Force2024
An Act to modernize legislative provisions as regards the protection of personal information (Law 25)ActIn Force (Amended)2021

© Regulations.AI — created on 05-Aug-2026 using Gemini 2.5 Flash