Practical AI and SaaS for Business

AI Governance in Canada: OPC, Bill C-27, and the Proposed AIDA Regulation

Canada is mid-reform. Its current AI governance landscape combines existing privacy law (PIPEDA) enforced by the Office of the Privacy Commissioner, proposed new privacy legislation that would replace PIPEDA, and a proposed Artificial Intelligence and Data Act that would create binding AI-specific requirements. Understanding which parts of this are in force and which are still proposed is the starting point.

Last verified: 18 July 2026. References checked against current legislation.

Editorial Perspective

You're a small e-commerce business owner in Ontario, and this year you added AI to handle customer service and automated refund decisions. The trouble is Canada's AI rules are split across a current federal law, a bill still in Parliament, and a separate Quebec law, and nobody has said plainly which one binds you today. In five minutes you'll know what PIPEDA already requires, what AIDA would add if it passes, and whether Quebec reaches you. No legal background needed.

This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.

In short: Canada's current binding AI governance framework is primarily PIPEDA (Personal Information Protection and Electronic Documents Act), enforced by the Office of the Privacy Commissioner (OPC). The OPC has published guidance on AI and PIPEDA obligations. Bill C-27 (Digital Charter Implementation Act 2022) proposes to replace PIPEDA with a new Consumer Privacy Protection Act (CPPA) and to create a new Artificial Intelligence and Data Act (AIDA). As at June 2026, verify the current legislative status of Bill C-27 directly, as it has been progressing through Parliament. The Canadian AI governance landscape is actively evolving.

This article describes the Canadian AI governance landscape with particular attention to distinguishing what is currently in force from what has been proposed and abandoned. Bill C-27, including the Artificial Intelligence and Data Act (AIDA), died on the order paper when Parliament was prorogued in January 2025, and was not re-tabled after the April 2025 election. Canada currently has no federal AI-specific legislation in force or before Parliament. This article does not provide legal advice; Canadian-qualified counsel should be consulted for compliance obligations in the Canadian context. The OPC is the authoritative source for current PIPEDA obligations: priv.gc.ca.

Current Framework: PIPEDA and OPC Oversight

PIPEDA (Personal Information Protection and Electronic Documents Act) is Canada's current federal private sector privacy law. It applies to organisations that collect, use, or disclose personal information in the course of commercial activity. For AI, PIPEDA's core principles apply to any AI system that processes personal information about Canadian individuals:

  • Consent: Individuals must consent to the collection, use, and disclosure of their personal information, with limited exceptions. AI training on personal data requires a basis for collection and use under PIPEDA's consent framework.
  • Purpose limitation: Personal information can only be used for the purposes for which it was collected. Using customer data to train AI models may require additional consent if the AI training purpose was not disclosed at collection.
  • Safeguards: Organisations must protect personal information with security appropriate to its sensitivity. This applies to how personal data is stored and processed by AI systems.
  • Openness and access: Individuals have the right to know about an organisation's information practices and to access their own personal information.

The OPC enforces PIPEDA and has published guidance specifically on AI and privacy: priv.gc.ca.

Consider a small e-commerce business owner in Ontario running an AI tool that auto-approves or declines refund requests over a set dollar amount. Under PIPEDA, that counts as an automated decision affecting a customer. Instead of quietly approving or declining and moving on, she now adds one line to the confirmation email explaining that the decision was assisted by an automated system and that the customer can ask for a human review. That's a five-minute policy change, not a legal project.

The Office of the Privacy Commissioner (OPC)

The OPC is Canada's federal privacy regulator. For AI, the OPC applies PIPEDA and has been an active participant in developing Canada's AI governance approach. The OPC has:

  • Published guidance on AI and privacy, including specific guidance on automated decision-making systems
  • Collaborated with provincial privacy commissioners on joint guidance for AI systems
  • Investigated AI-related privacy complaints under PIPEDA
  • Provided recommendations to Parliament on privacy reform and AI regulation

The OPC's AI and technology guidance is available at: priv.gc.ca. Provincial equivalents (such as the Information and Privacy Commissioner of Ontario and BC's OIPC) have also published AI-relevant guidance within their jurisdictions.

Bill C-27: What Was Proposed, and Why It Died

Legislative status note: Bill C-27 was introduced in the Canadian Parliament in June 2022. As at June 2026, the bill's current legislative status should be verified directly at the Parliament of Canada website: parl.ca. Legislative timelines can change, and this article cannot reliably describe the current status of a bill progressing through Parliament in real time.

Bill C-27 (Digital Charter Implementation Act 2022) proposed three components before dying on the order paper in January 2025:

  • Part 1. Consumer Privacy Protection Act (CPPA): Would have been a new federal private sector privacy law replacing PIPEDA, adding stronger consent requirements, expanded individual rights, higher penalties, and a new Privacy Tribunal.
  • Part 2. Personal Information and Data Protection Tribunal Act: Would have established the Privacy Tribunal referenced above.
  • Part 3. Artificial Intelligence and Data Act (AIDA): Would have been Canada's first AI-specific legislation, creating obligations for high-impact AI systems (anonymisation of training data, human-rights risk assessments, mitigation measures, human oversight requirements, and a prohibition on certain seriously harmful systems).

Bill C-27 died when Parliament was prorogued in January 2025, and the snap federal election that followed in April 2025 meant it was never re-tabled in its original form. Canada has no federal AI-specific legislation in force or currently before Parliament as a result. Whether a future bill revives this approach, integrating AI governance into a broader data protection framework rather than a standalone AI statute, remains to be seen.

Key Canadian Bodies for AI Governance

ISED (Innovation, Science and Economic Development Canada): The federal ministry leading AI policy, including development of the National AI Strategy and coordination of the Pan-Canadian AI Strategy (which funds AI research through CIFAR and the three national AI institutes: Mila, Vector Institute, Amii). ISED: ic.gc.ca.

NRC (National Research Council): Oversees AI standards development and contributes to international AI standards through ISO and CEN/CENELEC engagement. Canada participates actively in international AI standards bodies.

Treasury Board Secretariat: Has issued the Government of Canada Directive on Automated Decision-Making, which applies to federal government AI systems. This is not private sector legislation but establishes the framework for how federal departments deploy AI. The directive requires impact assessments, human review mechanisms, and notification for government AI systems at defined risk levels.

What This Means for Businesses Using AI in Canada

For businesses operating in Canada or processing personal information about Canadian individuals, the current practical AI governance questions are:

  • PIPEDA applies now: Privacy obligations under PIPEDA cover any AI system that processes personal information about Canadians in a commercial context. The OPC's AI guidance clarifies how PIPEDA principles apply to AI systems, including automated decision-making.
  • Automated decision-making transparency: The OPC has indicated that organisations using AI to make significant automated decisions should disclose this to affected individuals and provide meaningful explanation. This is guidance under current PIPEDA obligations, not a statutory right at the federal level, since AIDA died with Bill C-27 in January 2025.
  • No federal AI-specific legislation is currently before Parliament: Bill C-27 and AIDA died on the order paper in January 2025 and were not re-tabled. The OPC has committed to updated PIPEDA guidance on automated decision-making following AIDA's expiry, worth checking for updates rather than assuming AIDA will return in its original form.
  • Quebec Law 25: Quebec has enacted its own provincial privacy reform (Law 25 / Bill 64), fully in force since September 2024. Quebec's framework includes specific, already-binding provisions on automated decision-making, notification, explainability, and human review. Businesses with Quebec customers, not just Quebec-based businesses, should verify their obligations under Law 25.

Related reading: our Claude AI review looks at how Anthropic handles data retention and training-data use, the same questions PIPEDA's consent principles and the proposed Bill C-27 transparency rules are designed to force into the open.

Methodology (Real-World, Verified)

This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.

Try our free AI Privacy Risk Scorer to score your current AI tool setup against data-privacy best practice.

Try our free AI Policy Generator to generate a customised AI policy for your business.

What is PIPEDA and how does it apply to AI?

PIPEDA (Personal Information Protection and Electronic Documents Act) is Canada's federal private sector privacy law. It applies to organisations that collect, use, or disclose personal information in the course of commercial activity. For AI systems, PIPEDA's principles apply to the collection of training data, the use of personal information in AI processing, and any disclosure of personal information through AI outputs. The OPC has published specific guidance on how PIPEDA applies to AI: priv.gc.ca/en/privacy-topics/technology/artificial-intelligence/.

What is AIDA and when does it apply?

AIDA (Artificial Intelligence and Data Act) is the proposed AI-specific legislation included as Part 3 of Bill C-27 (Digital Charter Implementation Act 2022). If enacted, AIDA would create obligations for organisations that develop or deploy high-impact AI systems in commercial contexts in Canada. As at June 2026, AIDA is proposed legislation, not yet in force. The current legislative status of Bill C-27 should be verified at parl.ca. AIDA obligations do not apply until the bill is passed and the relevant provisions come into force.

Does Quebec have separate AI governance rules?

Yes. Quebec enacted Law 25 (An Act to modernize legislative provisions as regards the protection of personal information, also known as Bill 64), which came into force in phases from September 2022 to September 2023. Law 25 includes privacy requirements that go beyond PIPEDA in certain respects, including specific provisions on automated decision-making: organisations must inform individuals when a decision is based exclusively on automated processing, and must allow individuals to request human review. Businesses operating in Quebec should assess their obligations under Law 25 in addition to PIPEDA.

How does Canada's AI governance approach compare to the EU?

Canada's proposed AIDA shares some structural similarities with the EU AI Act, including a focus on high-impact or high-risk AI systems and requirements for risk assessment and human oversight. However, the EU AI Act is already in force with detailed technical requirements and a registration system for high-risk AI systems, while AIDA is still proposed legislation as at June 2026. The EU AI Act is also horizontal legislation with broad application, while AIDA focuses specifically on high-impact AI systems in commerce. The EU framework is more prescriptive and further advanced in implementation.

What is the Government of Canada Directive on Automated Decision-Making?

The Government of Canada Directive on Automated Decision-Making applies to federal government departments and agencies using AI systems to make or support administrative decisions. It requires impact assessments before deployment, appropriate human oversight mechanisms (including human review for high-risk decisions), and notification to affected individuals. This directive applies to the federal public service, not to private sector organisations. It is nonetheless a useful reference for how the Canadian government approaches AI risk assessment in practice.

Understanding the regulatory landscape is the first step. Turning it into practice inside your business is the next one. Our free AI acceptable use policy template gives you a starting point for documenting which tools are approved, what data can enter them, and what needs human review.

Find official guidance for your region

Requirements vary by jurisdiction. This article provides general information only. Consult your regional authority or a qualified professional for advice specific to your situation.

The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.

Canada is one of five major jurisdictions actively developing AI governance frameworks. Our regional hub maps all of them in one place, including how they compare and where obligations overlap for businesses operating across borders.

See AI Governance by Region