See how Trussed maps to your regulation in minutes

    No generic demo, just the controls relevant to your program.

    Book a session
    Compliance Guide

    Canada's AI Regulatory Landscape: AIDA, Bill C-27, and the Provincial Patchwork

    Canada currently has no enacted federal AI-specific statute. Bill C-27 and the proposed Artificial Intelligence and Data Act (AIDA) lapsed when Parliament was prorogued in January 2025. AI-related obligations today derive from existing privacy law and non-binding provincial guidance.

    Compliance Guide · AI Governance & Compliance · Canadian AI Law

    Current status (as of January 2025): AIDA is not law. It died on the Order Paper when Parliament prorogued before Bill C-27 completed committee review. No enacted federal AI-specific statute exists in Canada. Organizations should not describe their AI systems as "AIDA-compliant."

    The Legislative Status of AIDA and Bill C-27

    Bill C-27, the Digital Charter Implementation Act 2022, contained the proposed Artificial Intelligence and Data Act (AIDA) alongside privacy reform provisions known as the Consumer Privacy Protection Act. The bill had been referred to the House of Commons Standing Committee on Industry and Technology for clause-by-clause review, a process it had not completed when Parliament was prorogued in January 2025.

    Under Canadian parliamentary procedure, prorogation causes bills that have not received royal assent to die on the Order Paper. AIDA was never enacted and currently has no legal force.

    In 2023, Innovation, Science and Economic Development Canada released a companion document proposing amendments to AIDA, including a schedule-based approach to defining "high-impact AI systems" and an enforcement model built around a new AI and Data Commissioner housed within ISED. These proposals describe ISED's intended direction as of that document's publication, not enacted obligations. It is not established whether or when a successor bill will be reintroduced.

    Item Status
    AIDA / Bill C-27 Not enacted. Died on the Order Paper when Parliament prorogued in January 2025.
    Currently enforceable federal law PIPEDA (private-sector privacy) and the TBS Directive on Automated Decision-Making (federal institutions only).
    Currently enforceable provincial law Quebec's Law 25, which requires automated-decision transparency disclosures. Alberta and BC have substantially similar privacy statutes.
    Provincial AI-specific statutes None enacted. Ontario's trustworthy AI framework is non-binding guidance for the public sector.
    Proposed AIDA enforcement body An AI and Data Commissioner within ISED, with audit and penalty powers. Proposed only, not in force.

    What Currently Governs AI in Canada

    In the absence of AIDA, AI systems that process personal information in Canada remain subject to existing privacy statutes. The applicable statute depends on deployment jurisdiction and the type of personal information involved.

    PIPEDA (federal private sector)

    PIPEDA continues to apply as the federal private-sector privacy law in provinces without their own substantially similar legislation. It does not include AI-specific provisions, but its accountability, consent, and accuracy principles apply to AI systems that process personal information.

    Quebec's Law 25

    Quebec's Law 25 amends the province's private-sector privacy statute to require organizations to inform individuals when a decision is based exclusively on automated processing, and to explain the personal information and the principal factors and parameters used to reach that decision. This is the most specific AI-related binding obligation currently in force at the provincial level in Canada.

    TBS Directive on Automated Decision-Making

    The Treasury Board of Canada Secretariat's Directive on Automated Decision-Making requires algorithmic impact assessments for automated decision systems within federal institutions. The directive uses a structured scoring tool to determine the required level of human oversight. It binds federal institutions rather than private industry.

    Provincial guidance (non-binding)

    Ontario has published a trustworthy AI framework directed at public-sector AI use. No Canadian province has enacted a comprehensive AI-specific law comparable in scope to AIDA. Provincial AI governance is expressed primarily through privacy law amendments and non-binding guidance documents.

    What AIDA Would Have Required, If Enacted

    As proposed, AIDA would have imposed obligations on persons responsible for "high-impact" AI systems spanning design, development, and deployment stages, including documented risk assessment, mitigation measures, ongoing monitoring, and record-keeping.

    The 2023 companion document favored a schedule-based classification of high-impact systems over a single uniform standard, an approach structurally similar to risk-tiered frameworks elsewhere but narrower in scope as drafted. AIDA's proposed obligations emphasized documented risk assessment and mitigation rather than prescriptive technical standards, leaving decisions such as explainability method or audit-log format to the regulated organization.

    Enforcement, as proposed, would have been carried out by a new AI and Data Commissioner within ISED, with authority to order audits and impose administrative monetary penalties. None of these mechanisms are currently in force. Organizations should treat the companion document as a description of legislative intent from the 2023 to 2024 committee process, not as a binding compliance standard.

    Important

    Do not describe AI systems as "AIDA-compliant" or imply certification against AIDA in customer-facing materials. AIDA is not enacted law, and no compliance certification framework exists against it.

    Compliance Actions to Take Now

    Because no single federal AI statute currently applies, compliance requires mapping each AI use case to the specific statutes that actually govern it based on jurisdiction and data type. The following actions reflect obligations that are enforceable today.

    • Map each AI use case to the specific statutes that apply, such as PIPEDA, Quebec's Law 25, Alberta PIPA, or BC PIPA, based on jurisdiction and personal information involved. Do not assume one national AI law governs the deployment.
    • Build a standing capability to produce automated-decision transparency disclosures covering personal information used and principal factors or parameters, to meet Quebec's Law 25 requirement and anticipate similar expectations in other provinces.
    • Assign explicit internal ownership for tracking the legislative status of AIDA or any successor federal AI bill. Bill C-27 already lapsed once after prorogation, and a successor bill may be reintroduced with amended scope.
    • For AI systems used in federal or provincial government contracts, benchmark internal risk documentation against the TBS Algorithmic Impact Assessment structure, since public-sector procurement may reference it directly.
    • Remove any customer-facing language that implies AIDA compliance or AI-specific federal certification, since no such framework is currently in force.

    Designing Controls That Outlast Legislative Uncertainty

    Because Canada's AI regulatory landscape remains unsettled, the most durable governance posture is one that can be remapped to new statutory requirements without redesigning underlying controls. The following design principles support that goal.

    Remappable risk classification

    Build internal AI risk-tiering similar in spirit to AIDA's proposed high-impact schedule, so systems can be reclassified without redesigning the underlying control structure if a successor bill introduces a different definition.

    Jurisdiction-tagged system inventories

    Maintain an inventory of AI systems tagged by deployment jurisdiction and personal-information involvement. Which statute applies, PIPEDA, Law 25, Alberta PIPA, or BC PIPA, depends on both factors.

    Audit logging and record-keeping

    Maintain processing records and automated-decision documentation sufficient to support Quebec's disclosure requirement and the monitoring and record-keeping obligations that AIDA's companion document described, even though the latter are not currently mandatory.

    Reference international standards where no domestic mandate exists

    Because no binding Canadian technical standard for audit logs, model documentation, or bias testing currently exists federally, cross-reference frameworks such as ISO/IEC 42001 or the NIST AI RMF as an interim baseline.

    Where Runtime Governance Fits

    Regardless of which statute currently applies to a given AI deployment, the operational requirement is consistent: classify systems by risk, enforce least-privilege access for the agents and tools involved, log decisions and actions for audit, and be able to demonstrate this at the point of execution rather than only in policy documents.

    Runtime governance platforms such as Trussed AI apply these controls, including agent identity, permissions, tool approval workflows, and audit logging, directly to AI agent and MCP-based deployments. This does not constitute compliance with AIDA, Law 25, or any other statute. It is an operational layer that can support the record-keeping and monitoring capabilities that current privacy law, and any future AI-specific law, are likely to require.

    Frequently Asked Questions

    Is AIDA currently in force in Canada?

    No. AIDA died on the Order Paper when Parliament was prorogued in January 2025. It was never enacted and has no legal force. No federal AI-specific statute currently exists in Canada.

    What law currently governs AI use in Canada?

    AI systems that process personal information are governed by existing privacy statutes: PIPEDA at the federal level, Quebec's Law 25 at the provincial level (which includes an automated-decision disclosure requirement), and substantially similar privacy laws in Alberta and British Columbia. Federal institutions are also bound by the TBS Directive on Automated Decision-Making.

    What does Quebec's Law 25 require for automated decisions?

    Organizations subject to Quebec's Law 25 must inform individuals when a decision affecting them is based exclusively on automated processing, and must explain the personal information used and the principal factors or parameters that determined the outcome.

    Does the TBS Directive on Automated Decision-Making apply to private companies?

    No. The TBS Directive applies to federal government institutions. It requires algorithmic impact assessments for automated decision systems and establishes oversight levels based on a structured scoring tool. Private-sector organizations are not directly bound by it, but those supplying AI systems to federal departments may encounter it in procurement requirements.

    Should we build compliance controls for AIDA now?

    It is reasonable to design controls with AIDA's framework in mind, since a successor bill may be reintroduced. The priority, however, should be meeting currently enforceable obligations under PIPEDA and Quebec's Law 25. Risk classification, audit logging, and automated-decision documentation are operationally sound investments regardless of which statute ultimately applies.

    Can we describe our AI product as AIDA-compliant?

    No. AIDA is not law. Claiming AIDA compliance in customer-facing materials is inaccurate and potentially misleading. No certification framework exists against AIDA, and no regulator has authority to enforce it.

    Operationalize AI Governance Ahead of Regulatory Certainty

    Canadian AI law is still taking shape, but runtime controls for risk classification, permissions, and audit logging can be built now and adapted as AIDA or successor legislation evolves.

    Request a Demo