Governance
There is no federal AI law. 4 things bind you anyway.
AIDA died with Bill C-27 in January 2025 and nothing has replaced it. What still binds a Canadian company was mostly written before anyone used the word.

- Published
- Series
- Governance
- Federal AI statute in force
- None
- Bill C-27 died
- 6 Jan 2025
- Regimes that apply anyway
- 4
- Stated as at
- 3 Aug 2026
The gap
What died, and what did not.
Bill C-27 died on the order paper on 6 January 2025 when Parliament was prorogued, and the Artificial Intelligence and Data Act died inside it. No federal AI statute has been in force since, and as at the date on this page none has been tabled.
The mistake that produces is expensive. An executive reads that AIDA is dead and files the whole subject under someday, missing that 4 regimes already reach the company. 3 of them predate the term, which is exactly why they get missed: nobody looks for AI obligations in a privacy act or a banking guideline.
01
Quebec, and the clause with teeth.

- What triggers it
- A decision based exclusively on the automated processing of personal information. Law 25, article 12.1, fully in force since September 2024.
- What you owe, and when
- You must inform the person that the decision was made that way, no later than the moment you inform them of the decision itself. Not on request, and not afterwards.
- What they can then ask for
- The personal information used, the principal factors and parameters that led to the decision, and the right to have inaccurate information corrected.
- The right that costs you a process
- They may submit observations to a member of your staff who is in a position to review the decision. That person has to exist, and has to be able to change the answer.
- Who it reaches
- Any private body carrying on an enterprise in Quebec. Where the model runs and where the company is incorporated do not enter into it.
The word doing the work is "exclusively", and it is where most of the risk sits. A company reads it as an exemption, puts a person at the end of the pipeline, and treats the requirement as answered. A reviewer who approves 400 outputs a day without the information or the authority to overturn one is not a human in the loop, and building that is worse than not building it: it converts a disclosure problem into a misrepresentation.
02
Ontario, if anything you sell touches the public sector.

The Enhancing Digital Security and Trust Act, 2024, enacted as Schedule 1 of Bill 194, governs AI use across the Ontario provincial and municipal public sector, including school boards and hospitals. Covered entities have to stand up an accountability framework, manage risk, keep human oversight, and disclose where AI is used. Technical detail is set by regulation.
A private company reads that and concludes it does not apply. It usually does, through a contract rather than the statute: a covered entity that cannot meet its own obligation pushes the requirement down to whoever supplied the system. The place this shows up is a procurement questionnaire, and the honest question is not whether the Act binds you but whether your documentation survives a buyer who is bound by it.
03
Federally regulated finance, whether or not you are a bank.

- The instrument
- OSFI Guideline E-23 on model risk management, which applies to federally regulated financial institutions and whose scope covers machine learning and AI models, not only the statistical ones it was originally written around.
- What it asks of them
- A model inventory, validation before deployment, independent review proportionate to risk, ongoing monitoring, and a named person accountable for each model through its life.
- Why it is your problem
- If your customer is a bank, an insurer or a federally regulated lender, their model risk function is your compliance surface. It will ask for validation evidence, documented limitations and monitoring plans.
- What it costs a vendor
- A pilot built to prove the output is impressive produces none of that. The gap between a working demonstration and a validated model is most of the deployment timeline, and it is the subject of the second note in this series.
04
Privacy law, which never stopped applying.

PIPEDA federally, with substantially similar provincial regimes in Alberta, British Columbia and Quebec. Consent, purpose limitation, accountability and breach reporting. None of it carries an AI exemption and none of it needs one: training a model on personal information is a use of that information, and a use requires a purpose the person actually agreed to.
Sectoral regulators sit on top of that and are the ones most often forgotten. Securities, health, employment standards and human rights law apply to a decision made by a system exactly as they apply to the same decision made by a person. An automated screen that produces a disparate outcome is a human rights question in every province, and it was one before anybody wrote an AI statute.
The memo
6 questions a board should be able to answer.

Which decisions here are made exclusively by a machine?
Not which systems use AI. Which decisions about a person come out of one without a human who can change the answer. Most companies cannot produce this list, and producing it is the entire first meeting.
For each one, what do we tell the person, and when?
The Quebec timing requirement is at the moment of the decision. If the answer is a paragraph in a privacy policy, the answer is no.
Who is the named owner of each model in production?
A person, not a team. Every model risk framework in the country converges on this and it is the requirement companies satisfy last.
What happens when the output is wrong?
The path has to exist before it is needed, and somebody on it has to have the authority to overturn the result rather than to explain it.
What personal information trained it, under what consent?
Asked at the board rather than in the data team, because the answer is usually held by whoever signed a vendor agreement 3 years ago.
Which of our customers' regulators reach us by contract?
The most common surprise on this list. A company with no regulator of its own inherits several the day it sells to a bank, a hospital or a ministry.
Nothing on that list requires a statute to be worth answering, which is the point of putting it at the foot of a note about a law that does not exist. A company that can answer all 6 is ready for whatever is tabled. A company that cannot was already exposed under the 4 regimes above.
Standing
This page states the law as at one date.
Everything above was checked on 3 August 2026. A single tabled bill changes the first section and possibly the framing of the whole note, which is why the date is printed at the top rather than buried in a footer. This is a note from a private network, not legal advice, and no reader should act on it without their own counsel.
Read next
The rest of the method.
The rest of this is said in a room.
A note publishes the method. What it cannot publish is the 2 hours of argument that produced it, which is the part membership is actually for.