AccuroAI
Products
What We Do
Solutions
Company
Resources
Book a demo
← Blog·AI Compliance10 min read

Canada After AIDA: What Binds Enterprise AI Now

Canada has no AI statute, and as of early October 2026 none is before Parliament. AIDA lapsed with Bill C-27, and its replacement, Bill C-36, is a privacy bill that has had first reading only. That does not leave enterprise AI unregulated. We read PIPEDA, Quebec's Law 25, the privacy regulators' OpenAI findings and OSFI Guideline E-23, and set out what applies today, what has a fixed date, and why the work starts with an inventory.

S
Sofia Reyes
Head of Compliance
Oct 10, 2026

Canada has no AI statute, and as of early October 2026 none is before Parliament. The Artificial Intelligence and Data Act (AIDA) was never passed. It sat inside Bill C-27, which was still in committee when that session of Parliament ended on 6 January 2025. The bill that replaced it, Bill C-36, is a privacy bill with no AI Act attached, and it has not moved since first reading on 15 June 2026.

That does not leave enterprise AI unregulated. Four things apply to it today or on a fixed date: the federal privacy law already in force, Quebec's rule on automated decisions, the privacy regulators' published position on generative AI, and a model risk guideline for banks and insurers that takes effect on 1 May 2027.

Each one asks the same first question. Which AI systems do you run, and which of them touch personal information or shape decisions about people?

Last verified: 10 October 2026, against LEGISinfo and the first-reading text of Bill C-36 on parl.ca, PIPEDA on the Justice Laws website, Quebec's Law 25 as enacted (S.Q. 2021, c. 25), the Privacy Commissioner's PIPEDA Findings #2026-002, OSFI Guideline E-23, and the federal AI strategy published by ISED.

What happened to AIDA?

Bill C-27, the Digital Charter Implementation Act, 2022, would have enacted three statutes: a Consumer Privacy Protection Act, a tribunal act, and AIDA. LEGISinfo records its last step as second reading and referral to committee on 24 April 2023. Later stages are marked "Not reached". The session ran from 22 November 2021 to 6 January 2025, when Parliament was prorogued, and the bill was not carried into the next one.

So AIDA is not law.

What does Bill C-36 say about automated decisions?

Bill C-36 was introduced by the Minister of Artificial Intelligence and Digital Innovation. Its long title is "An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts". It enacts a privacy statute and no AI statute.

The bill does define an "automated decision system", and defines it broadly, as "any technology that assists or replaces the judgment of human decision-makers through the use of a rules-based system, regression analysis, predictive analytics, machine learning, deep learning, a neural network or other technique." A system that only assists a human is inside it. Two duties attach.

  • A public account. Section 62(2)(c) would require an organization to make available "a general account of the organization's use of any automated decision system to make predictions, recommendations or decisions about individuals that could have a legal or similarly significant effect on them".
  • An explanation on request. Under section 63(4), where such a system was used about an individual, the organization "must, on request by the individual, provide them with an explanation of the prediction, recommendation or decision." Section 63(5) says the explanation must indicate the type of personal information used, its source, and "the reasons or principal factors" behind the result.

The penalties are large on paper: section 114 caps an administrative penalty at "the greater of $10,000,000 and 3% of the organization's gross global revenue". None of it is in force. LEGISinfo shows no second-reading activity, and section 147 leaves commencement to "a day or days to be fixed by order of the Governor in Council". Treat C-36 as a preview, not a deadline.

Which rules apply to enterprise AI in Canada right now?

InstrumentStatus as of October 2026Who it bindsWhat you need to evidence
AIDA (in Bill C-27)Never passed; the session ended 6 January 2025No oneNothing
Bill C-36, Protecting Privacy and Consumer Data ActFirst reading 15 June 2026; no second-reading activityNo one yetIf passed: a general account of automated decision systems, and explanations on request
PIPEDA (S.C. 2000, c. 5)In forcePrivate-sector organizations handling personal information in commercial activityPurpose, consent, safeguards and vendor protections for personal data sent to AI tools
Quebec private sector Act, s. 12.1In force since 22 September 2023Persons carrying on an enterprise, under Quebec lawWhich decisions are fully automated, the notice given, the factors used, and the human review route
Regulators' generative AI principles (7 December 2023)Published guidance, not lawDevelopers, providers and users of generative AIHow existing privacy duties were applied to each generative AI use
OSFI Guideline E-23Final; effective 1 May 2027All federally regulated financial institutionsA model inventory that includes AI and vendor models, with a risk rating for each
Voluntary Code of Conduct for generative AI (September 2023)VoluntarySignatories onlyYour own commitments

What does PIPEDA already require of an AI deployment?

PIPEDA never mentions AI, and it does not need to. It governs personal information, and prompts, uploads, transcripts and agent actions carry plenty of it. Section 5(3) allows collection, use or disclosure "only for purposes that a reasonable person would consider are appropriate". Clause 4.7 of Schedule 1 says personal information "shall be protected by security safeguards appropriate to the sensitivity of the information." Clause 4.1.3 keeps the organization responsible for information in its possession or custody, "including information that has been transferred to a third party for processing."

Keep that last clause in mind when an employee pastes a customer file into a chatbot. You remain accountable for it.

On 7 December 2023 the federal Privacy Commissioner and its provincial and territorial counterparts published principles for generative AI. The document says it is "intended to help organizations developing, providing or using generative AI apply key Canadian privacy principles." It is guidance, not law, and it shows how the people who enforce the law read it.

What did the OpenAI findings add?

On 6 May 2026 the federal commissioner and the regulators of Quebec, British Columbia and Alberta released PIPEDA Findings #2026-002, their joint investigation of OpenAI OpCo, LLC. The federal office found the complaint "well-founded and conditionally resolved". British Columbia and Alberta went further and found that OpenAI "has not obtained, and cannot obtain, consent under PIPA-BC and PIPA-AB" for models built on scraped data.

Two points matter beyond OpenAI. The report states that PIPEDA applies to organizations outside Canada where a "real and substantial connection" to Canada exists. It also faults the company for having "deployed this service without having first" established the accuracy of personal information in outputs and developed a retention policy. A statute from 2000 was enough to reach those conclusions.

What does Quebec require when a decision is fully automated?

Quebec is the one Canadian jurisdiction with an automated-decision rule that can be enforced today. Law 25 added section 12.1 to the Act respecting the protection of personal information in the private sector, and it came into force on 22 September 2023.

The trigger is narrow. It covers a person carrying on an enterprise who uses personal information "to render a decision based exclusively on an automated processing of such information". That person must tell the individual, "not later than at the time it informs the person of the decision." On request, the enterprise must also disclose the personal information used, "the reasons and the principal factors and parameters that led to the decision", and the right to have that information corrected. The individual must also get the chance to submit observations "to a member of the personnel of the enterprise who is in a position to review the decision."

Quebec's rule bites only where no human is involved. Bill C-36 would reach systems that merely assist one.

Section 90.1 lists a failure to inform the person, or to give them the opportunity to submit observations, "in contravention of section 12.1" among the grounds for a monetary administrative penalty. Section 90.12 sets the maximum for an enterprise at "$10,000,000 or, if greater, the amount corresponding to 2% of worldwide turnover for the preceding fiscal year." Separately, section 91 creates penal offenses with fines for enterprises of "$15,000 to $25,000,000, or, if greater, the amount corresponding to 4% of worldwide turnover". Section 91 does not name section 12.1, so whether a given failure also amounts to an offense is a question for Quebec counsel.

What is the deadline for banks and insurers?

One date is fixed. OSFI Guideline E-23, Model Risk Management, was published on 11 September 2025 and takes effect on 1 May 2027. It "applies to all federally regulated financial institutions, including foreign bank branches and foreign insurance company branches".

AI is inside the definition. A model is "an application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI/ML methods, which processes input data to generate results." Three expectations follow from that.

  • Inventory. "Institutions should identify and track all models in use or recently decommissioned", and the guideline expects that identification to cover "vendor and third-party models".
  • Risk rating. "Each model should be assigned a model risk rating."
  • Lifecycle. "Model governance covers the entire model lifecycle", from design and review through deployment, monitoring and decommission.

The harder inventory is the AI nobody registered, such as an assistant built into a SaaS product. Our financial services AI security playbook maps the other financial regulators.

Does the national AI strategy change any of this?

Not for compliance teams, so far. The strategy, "AI for All", was published in June 2026. Its legal commitments concern privacy and online safety: "Canada will modernize consumer privacy legislation" and "Canada will introduce online safety laws". We found no commitment to a general AI statute in the document.

Two older federal instruments are sometimes mistaken for rules on business. The Voluntary Code of Conduct on advanced generative AI, from September 2023, binds only the companies that signed it, and its own text says it "does not in any way change existing legal obligations". The Treasury Board's Directive on Automated Decision-Making, in effect since 1 April 2019, is addressed to federal departments.

What should a company operating in Canada do now?

  • Build one inventory. List every AI tool, embedded feature and agent, and mark which ones process personal information or feed decisions about people.
  • Sort decisions by human involvement. Fully automated ones trigger Quebec's section 12.1 today. Assisted ones would fall under Bill C-36 if it passes as drafted.
  • Write the explanation before someone asks. Record the personal information used, its source, the principal factors, and the person able to review the decision.
  • Check where prompts go. Under clause 4.1.3 you answer for personal information sent to an AI vendor, so the contract and the controls both matter.
  • If OSFI regulates you, start the model inventory now. Vendor AI is the slow part.

If you are unsure how far along you are, our AI governance maturity assessment is a free self-assessment that takes about 12 minutes. It is useful here because it shows which of the steps above to do first.

What can software carry, and what stays with people?

Software cannot write a Quebec notice or assign a model risk rating. Those are judgments for legal, compliance and model risk staff.

What it can carry is the inventory and the record. AccuroAI discovers 1,400+ AI tools, including the ones staff adopted without asking. It enforces policy at the point of use, redacting or blocking personal data in line with 40+ data classifiers before a prompt leaves, and it logs each event against a user and a tool. That evidence is mapped to 8 frameworks. It is a record of use, not a model validation. Our guide to the AI agent audit log lists the fields worth keeping.

Frequently asked questions

Does Bill C-36 regulate AI?

Only through privacy. It would add disclosure and explanation duties for automated decision systems that use personal information, and as of early October 2026 it has had first reading only. For a similar duty elsewhere, see our note on the Australian automated decision rule.

We have no office in Quebec. Does section 12.1 reach us?

How far the Act reaches a business serving Quebec residents from elsewhere is a question for counsel. The regulators did apply Canadian privacy law to a US company in the OpenAI matter.

How does this compare with Europe?

Quebec's rule resembles the GDPR's safeguards on solely automated decisions, though the texts differ. Our GDPR and enterprise AI guide covers the European side, and the AI compliance hub tracks other jurisdictions.

This is not legal advice. Quebec provisions are quoted from the 2021 statute as enacted; check the current consolidation on LégisQuébec and ask Canadian counsel before relying on it.

Sources

See AccuroAI in action.
30-minute demo tailored to your top AI risk.
Book a demo
More from the blog
See AccuroAI in action.

Book a 30-minute demo and see how security teams use AccuroAI to discover, govern, and protect every AI asset across their organization.

Book a demoRun the free assessment

15 enterprises secured · under 38ms p99 · live on your own estate in 72 hours