Canada has no comprehensive federal AI law. Its one attempt, the Artificial Intelligence and Data Act (AIDA), died when Parliament was prorogued in January 2025, and the current government has said it will not revive it. AI is instead governed by existing law, above all privacy law such as the federal PIPEDA and Quebec's Law 25, human rights law, and sector rules, alongside voluntary federal frameworks and the June 2026 AI for All strategy. This page sets out the instruments, the dates, and which ones are binding versus voluntary, with links to the primary sources for each.
Last reviewed: 22 July 2026 · A factual snapshot; AI policy is evolving, so confirm against the primary sources linked below
Canada came close to a comprehensive federal AI statute and then stepped back from it. AIDA, part of Bill C-27, would have created a risk-based regime for high-impact AI systems, but the bill died when Parliament was prorogued on 6 January 2025 and was not revived after the 2025 election. The Carney government, through Canada's first Minister of AI, has signalled a lighter, more targeted approach rather than an omnibus AI act.
So the rules that actually bind an organisation today come from existing law applied to AI: the federal Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Law 25 (the most demanding privacy law in the country, with binding automated-decision rights), the Canadian Human Rights Act and provincial codes, the Treasury Board directive for federal government use, and, from 2027, OSFI's model-risk guideline for financial institutions. On top of that sits a voluntary federal layer: the generative-AI Code of Conduct, the OPC's guidance, and the AI for All strategy.
Innovation, Science and Economic Development Canada (ISED) launched a voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems, an interim measure pending formal regulation. It sets voluntary commitments for developers and managers of advanced generative systems and has been signed by roughly 50 organisations. It remains in effect in 2026.
The second tranche of Quebec Law 25 (enacted as Bill 64) took effect, adding binding transparency and review rights for automated decisions. Where a decision is based exclusively on automated processing of personal information, the organisation must inform the individual and, on request, disclose the personal information used and the principal factors, allow correction, and let the person submit observations to a human who can review the decision.
The Office of the Privacy Commissioner of Canada (OPC) published Principles for responsible, trustworthy and privacy-protective generative AI technologies. These are voluntary guidance on how existing federal privacy law applies to generative AI; they interpret the law rather than create new obligations.
Canada launched the Canadian Artificial Intelligence Safety Institute (CAISI) as a research and coordination body on AI safety. It is not a regulator and does not issue binding rules; it supports research and international cooperation on advanced-AI risks.
Parliament was prorogued and Bill C-27, the Digital Charter Implementation Act, died on the Order Paper. With it fell the Artificial Intelligence and Data Act (AIDA), which had been Part 3 of the bill and would have been Canada's first comprehensive federal AI law. AIDA never received Royal Assent.
After the April 2025 federal election, Prime Minister Mark Carney's government created a Ministry of Artificial Intelligence and Digital Innovation and appointed Evan Solomon as Canada's first Minister of AI. The government has said it will not revive AIDA as drafted, favouring a "light, tight, right" approach of AI adoption plus targeted rules.
The Office of the Superintendent of Financial Institutions (OSFI) finalised Guideline E-23 on Model Risk Management, expanding its scope across federally regulated financial institutions and adding explicit expectations for AI and machine-learning models (explainability, bias, model drift, autonomous decision-making). It comes into effect on 1 May 2027.
Prime Minister Carney and Minister Solomon launched Canada's National Artificial Intelligence Strategy, AI for All, a non-binding five-year roadmap that supersedes the earlier Pan-Canadian AI Strategy. It signals modernised privacy and online-safety legislation and continues the sovereign AI compute programme, but it is policy and direction, not binding law.
The government introduced Bill C-36, the Protecting Privacy and Consumer Data Act, to reform federal private-sector privacy law. It carries some AI-transparency duties (disclosure for consequential automated decisions and deletion rights covering deepfakes) but is a privacy-reform bill, not a comprehensive AI Act or an AIDA successor. As of mid-2026 it is at second reading, so it is a bill rather than law.
Because there is no federal AI Act, the distinction that matters most is whether an instrument carries legal force or is a voluntary framework an organisation is encouraged to follow. The table below sorts the main instruments accordingly.
| Instrument | Status | Applies to / owner |
|---|---|---|
| Personal Information Protection and Electronic Documents Act (PIPEDA) | Binding | Private-sector organisations using personal data, including in AI (enforced by the OPC) |
| Quebec Law 25, automated-decision rights (s.12.1) | Binding | Organisations making decisions based exclusively on automated processing of Quebec residents' data (CAI) |
| Canadian Human Rights Act and provincial human rights codes | Binding | Any AI use that could discriminate (technology-neutral; human rights commissions and tribunals) |
| Treasury Board Directive on Automated Decision-Making | Binding on government | Federal departments using automated decision systems (mandatory Algorithmic Impact Assessment) |
| OSFI Guideline E-23 (Model Risk Management) | Supervisory, effective 1 May 2027 | Federally regulated financial institutions (OSFI) |
| Voluntary Code of Conduct on advanced generative AI (Sept 2023) | Voluntary | Developers and managers of advanced generative AI (roughly 50 signatories) |
| OPC principles for generative AI (Dec 2023) | Voluntary guidance | Organisations using generative AI with personal data |
| AI for All national strategy (June 2026) | National strategy, not a rule | Whole-of-government direction, not an obligation on firms |
| Bill C-36, Protecting Privacy and Consumer Data Act | Proposed (second reading) | Would reform federal private-sector privacy law with AI-transparency duties |
For the wider picture across jurisdictions, see our AI regulation by country comparison, and our detailed article on Canada governing AI without a federal law.
Two practical points follow. First, the obligations that can actually be enforced today come from existing law applied to AI, not from an AI Act: privacy law (PIPEDA federally, and Quebec's Law 25 most demandingly, including its automated-decision rights), human rights law, and sector rules such as OSFI's expectations for financial institutions. Second, the federal AI-specific layer is, for now, voluntary framework and strategy: the generative-AI Code of Conduct, the OPC's guidance, and the AI for All roadmap set expectations but are not, in themselves, law.
The direction of travel is worth watching. A new Minister of AI, Bill C-36's privacy reform with AI-transparency duties, and the AI for All strategy all point to more structured rules over time. Until then, the weight of day-to-day AI governance sits with each organisation's own framework and controls. Our AI GRC guide covers how those pieces fit together, and a short governance assessment benchmarks where an organisation stands against a structured model.
No. Canada's one attempt at a comprehensive federal AI statute, the Artificial Intelligence and Data Act (AIDA), was part of Bill C-27 and died when Parliament was prorogued on 6 January 2025. The current government has said it will not revive AIDA as drafted, favouring a "light, tight, right" approach. AI is instead governed by existing laws and voluntary frameworks.
AIDA was Part 3 of Bill C-27, introduced in June 2022. It never received Royal Assent. When Parliament was prorogued on 6 January 2025, the bill died on the Order Paper, and the subsequent 2025 election ended it for good. As of mid-2026 no comprehensive AI-specific federal statute has replaced it. Note that bill numbers reset each Parliament, so Bill C-27 in the current Parliament is an unrelated bill, not AIDA.
There is no single AI regulator. The Office of the Privacy Commissioner enforces the federal privacy law (PIPEDA); Quebec's Commission d'acces a l'information enforces Law 25; the Canadian Human Rights Commission and provincial bodies handle discrimination; OSFI and the FCAC cover financial services; the Treasury Board directs federal government use of automated systems; ISED leads national strategy; and CAISI is a research body, not a regulator.
Federally, PIPEDA is binding and applies to personal data used in AI by private-sector organisations. In Quebec, Law 25 is the most demanding privacy law in Canada and includes binding transparency and review rights for decisions based exclusively on automated processing, in force since 22 September 2023. The OPC's principles for generative AI are voluntary guidance layered on top of the binding law.
Yes. After the 2025 federal election, Prime Minister Mark Carney's government created a Ministry of Artificial Intelligence and Digital Innovation and appointed Evan Solomon as Canada's first Minister of AI in May 2025. The government's direction is set out in the June 2026 AI for All national strategy, which is policy rather than binding law.
OSFI Guideline E-23 on Model Risk Management, finalised in September 2025 and coming into effect on 1 May 2027, adds explicit expectations for AI and machine-learning models at federally regulated financial institutions. The 2024 OSFI-FCAC report on AI uses and risks and the 2026 FIFAI reports are informational rather than binding guidance.
A short, free assessment benchmarks where your organisation stands against a structured AI governance model, useful precisely because so much of Canada's federal AI layer is voluntary.
This page is general information describing the state of Canada AI policy as at 22 July 2026, not legal or compliance advice. Policy and regulatory positions change; always confirm the current position against the primary sources linked above and obtain advice from your own qualified counsel before relying on it.