AI Regulations in Canada (2026): the Artificial Intelligence and Data Act, PIPEDA, and What Actually Applies

If you searched for the artificial intelligence and data act expecting to find a Canadian AI law you need to comply with, here is the short version: that law does not exist. AIDA died on the Order Paper when Parliament was prorogued in January 2025, and as of today there is no general AI statute in force anywhere in Canada.
That does not mean AI is unregulated here. It means the rules that apply to your chatbot, voice agent or hiring tool were written for something else (privacy, human rights, consumer protection) and now apply to AI by extension. That gap between "no AI law" and "no rules" is where most Canadian businesses get nervous, and where a lot of the advice online gets vague. This piece maps out, in plain English, what actually governs AI use in Canada today, who enforces it, and what an operator deploying a real system needs to do about it.
What was the Artificial Intelligence and Data Act?
The Artificial Intelligence and Data Act (AIDA) was introduced as Part 3 of Bill C-27, the Digital Charter Implementation Act, tabled in the House of Commons in June 2022. According to Innovation, Science and Economic Development Canada (ISED), the department that published AIDA's companion document, it was Canada's first attempt at a dedicated, cross-sector AI law. The bill was built around a risk-based framework: obligations would scale with how much potential harm a given AI system could cause. The heaviest requirements would have landed on what the bill called "high-impact systems": hiring tools, credit decisions, and other consequential automated decisions about people.
Under AIDA as proposed, organizations responsible for high-impact AI systems would have had to assess and mitigate risks of harm and bias, keep documentation to show they did it, and monitor systems after deployment. In some cases they would also have had to notify a new AI and Data Commissioner of serious incidents. Non-compliance carried the threat of significant penalties, similar to the enforcement teeth of privacy legislation elsewhere.
None of it became law. Bill C-27, AIDA included, died on the Order Paper when Parliament was prorogued in January 2025. A bill dying on the Order Paper is not a technicality: it means the legislative process stops completely and the bill ceases to exist.
It does not become law in a weaker form, it does not stay "in effect until replaced," and it does not carry over automatically. Canada's federal government could reintroduce a similar framework in a future Parliament, but as of today, nothing has replaced it. The Montreal AI Ethics Institute summed up the moment plainly in its post-mortem on the bill, describing it as the death of Canada's AIDA.
50-word summary: The Artificial Intelligence and Data Act was Canada's proposed AI law (AIDA), part of Bill C-27, tabled June 2022. It would have created risk-based obligations for high-impact AI systems, enforced by a new commissioner. It died on the Order Paper at the January 2025 prorogation and was never passed. No replacement is currently before Parliament.
So is AI unregulated in Canada? No, here's what applies
The Artificial Intelligence and Data Act's death left a gap where a dedicated AI law would sit, but it did not create a legal vacuum around AI itself. Several existing frameworks already reach into how you can collect data, make decisions and treat customers with an AI system, whether or not the word "AI" appears anywhere in the statute. Here is what is actually live in Canada right now:
- PIPEDA (the federal Personal Information Protection and Electronic Documents Act): governs how private-sector organizations collect, use and disclose personal information, including anything your chatbot, voice agent or CRM captures.
- Quebec's Law 25: adds a specific disclosure duty for automated decisions affecting individuals, on top of general privacy obligations, for any business dealing with Quebec residents.
- Provincial and federal human rights legislation: prohibits discriminatory outcomes in hiring, credit and services, and applies regardless of whether a human or an algorithm made the call.
- Sector-specific regulation: banking, insurance, healthcare and other regulated industries layer their own rules on top of general privacy and human rights law.
- The Voluntary Code of Conduct for advanced generative AI: a government-endorsed, opt-in commitment (announced September 2023) that enterprise buyers increasingly ask vendors about even though it carries no legal force.
Each of these gets its own section below, because "it's covered by privacy law" is not specific enough to act on.
PIPEDA: the law that already covers your AI
Now that the Artificial Intelligence and Data Act is not in force, PIPEDA is the law doing most of the actual work here, and it applies to your AI systems today whether or not you have thought about it that way. PIPEDA governs how organizations collect, use and disclose personal information in the course of commercial activity, and it does not carve out an exception for information that passes through an AI model instead of a human employee.
That matters because AI systems handle personal information constantly, often without anyone flagging it as a "collection" event. A customer's message to your chatbot is personal information. A caller's voice and the transcript your voice agent generates are personal information. Any data used to fine-tune or ground a model against your customer records is personal information. Under PIPEDA, each of those counts as collection, and collection triggers obligations: you need a legitimate purpose, you generally need consent (or a recognized exception), you need to limit use to what you disclosed, and you need reasonable safeguards to protect the data.
In practice, three PIPEDA principles matter most for AI deployments:
- Consent: people interacting with your AI system need to know it is AI, and in most cases need a clear route to understand what happens with what they tell it. Silent or buried disclosure is a weak position to defend.
- Purpose limitation: if you collect chat transcripts to resolve a support ticket, using that same data later to train a model or build a marketing list is a separate purpose that needs its own basis.
- Safeguards: this is where vendor questions get real. Where is the data processed and stored? Who can access transcripts? How long are they retained? If you cannot answer those questions about your own AI vendor, you cannot answer them for a regulator either.
The Office of the Privacy Commissioner of Canada has been explicit that PIPEDA applies to AI tools that process personal information, AIDA or no AIDA. This is not a future obligation waiting on new legislation. It is the law you are already operating under.
Quebec Law 25 and automated decisions
Quebec's Law 25 (formerly Bill 64) modernized the province's private-sector privacy regime, and it includes a provision that federal PIPEDA does not have in the same form: a specific disclosure duty when a decision is based exclusively on an automated process.
If your business uses an AI system to make, or substantially inform, a decision about a person, such as approving an application, scoring a lead, screening a resume, or setting a price, and a Quebec resident is on the other end of that decision, Law 25 requires you to inform them that the decision was automated. In some circumstances it also requires giving them a path to human review, and to ask questions about how the decision was made. This is a meaningfully higher bar than "we have a privacy policy somewhere."
The part that trips up Ontario and other non-Quebec businesses: Law 25 applies based on where the affected individual is, not where your company is headquartered. If you sell into Quebec, hire from Quebec, or serve Quebec customers through an AI-driven intake or screening flow, this law reaches you even if your business has no physical presence in the province. Treating Law 25 as "a Quebec company's problem" is a common and costly misread.
Quebec's privacy regulator, the Commission d'accÚs à l'information du Québec, oversees Law 25, investigates complaints, and publishes guidance on the automated-decision disclosure duty. If you are unsure whether your AI-driven intake flow triggers it, their published guidance is the primary source, not a blog post.
Hiring, credit and other high-stakes uses
Human rights law does not care whether a human or an algorithm made a discriminatory call, it cares about the outcome. Federal and provincial human rights legislation across Canada prohibits discrimination in employment, housing, credit and services on protected grounds such as race, sex, age and disability, and that prohibition applies fully to decisions made or shaped by AI. At the federal level, the Canadian Human Rights Commission is the body that receives and investigates these complaints, including ones arising from an automated hiring or screening decision.
This is where the Artificial Intelligence and Data Act's absence matters most, because AIDA would have added AI-specific documentation and bias-testing obligations on top of general human rights law. Without it, the underlying prohibition on discriminatory outcomes still stands, but there is no dedicated statutory requirement to proactively test an AI hiring tool for bias before you deploy it. That gap does not make bias in an AI screening tool legal, it makes it your problem to catch before a complaint does. A resume-screening model trained on historical hiring data can quietly reproduce the same skew that shaped that data, and "the AI decided" is not a defence under human rights law.
If AI touches hiring decisions in your business, this deserves its own deeper look at what "human in the loop" actually needs to mean in practice, not just on paper. We cover that in detail in our guide to AI in recruitment in Canada.
The Voluntary Code of Conduct
In September 2023, while the Artificial Intelligence and Data Act was still working its way through Parliament, the federal government launched the Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems as a stopgap. As the name says, it is voluntary: signing carries no legal obligation and non-signatories face no penalty for staying out.
What it commits signatories to is a set of practices around safety, fairness, transparency, human oversight and accountability for advanced generative AI systems, largely aimed at the organizations building foundation models rather than every business that uses one. Signatories include major Canadian and international AI developers and some large enterprise adopters.
Why bring it up at all if it is not binding? Because it has become a practical due-diligence signal. Enterprise buyers and larger Canadian organizations increasingly ask AI vendors whether they align with the Voluntary Code as part of procurement and vendor-risk conversations. It works as a stand-in for "does this vendor take responsible AI seriously" when there is no hard legal standard to point to. If you are selling or deploying AI into larger Canadian organizations, expect the question even though the code itself has no teeth and never had the enforcement mechanism the Artificial Intelligence and Data Act would have provided.
A practical AI compliance checklist for Canadian SMBs
None of the frameworks above are optional just because the Artificial Intelligence and Data Act is dead. Here is what an operator actually deploying AI (a chatbot, a voice agent, an AI hiring screen, a workflow automation touching customer data) should have in place:
- Map your personal data flows. Know exactly what personal information your AI system touches: prompts, transcripts, call recordings, training or grounding data. You cannot comply with PIPEDA for data you have not identified.
- Write real consent language. State plainly, at the point of interaction, that people are talking to an AI system and what happens to what they share. Buried disclosure is not meaningful consent.
- Build in human-in-the-loop for consequential decisions. Anywhere AI touches hiring, credit, pricing or similar outcomes, have a defined human review point, not just a theoretical escalation path.
- Ask vendors about data residency. Where is your AI vendor actually processing and storing data, and does that location matter for your regulatory exposure (PIPEDA, Law 25, sector rules)? If you are still comparing vendors, our guide on choosing an AI automation agency in Toronto covers the due-diligence questions worth asking before you sign.
- Set transcript and recording retention limits. Indefinite retention of chat and call data is a liability, not a feature. Define how long you keep it and delete on schedule.
- Build automated-decision disclosure into your flow. If you serve Quebec residents and a decision is fully automated, Law 25 requires telling them, and giving them a path to human review.
- Have an incident response plan. If an AI system leaks personal data or makes a materially wrong consequential decision, know who gets notified, how fast, and what gets fixed.
- Monitor for new legislation. A successor to the Artificial Intelligence and Data Act, if one is introduced, will not appear without warning. Assign someone to actually watch for it rather than assuming you will hear.
This is also, not coincidentally, close to how we build. As standard practice, NOVAIO retains call and chat transcripts for a client-agreed window, plays a disclosure line at the start of every AI-handled call so the caller knows they are speaking with AI, and routes any consequential decision to a named human owner rather than leaving it to the system. That covers a meaningful chunk of this checklist before you even start asking vendor questions. See how that applies to your setup on our solutions page, or read our related guides on AI customer service in Canada and AI receptionists for small business.
FAQ
Is AIDA (the Artificial Intelligence and Data Act) law in Canada right now?
No. The Artificial Intelligence and Data Act (AIDA) was part of Bill C-27, tabled in June 2022, and it died on the Order Paper when Parliament was prorogued in January 2025. It was never passed and is not in force. As Osler noted in September 2025, there is no law in Canada that sets out a general framework for regulating AI models and systems.
Will the Artificial Intelligence and Data Act come back?
Uncertain. A future government could reintroduce a similar risk-based AI framework, and Canada's federal AI strategy documents continue to signal interest in the area, but nothing has been tabled as of this writing. Treat any claim about upcoming Canadian AI legislation as speculation until a bill is actually before Parliament.
Does PIPEDA apply to my chatbot or voice agent?
Almost certainly, yes. If your AI system collects, uses or discloses personal information (which most chatbots, voice agents and CRM-integrated tools do) PIPEDA's consent, purpose limitation and safeguard requirements apply, regardless of whether the tool is described as "AI."
Are there fines for getting this wrong?
Yes, but they come from existing laws, not from an AI-specific statute. PIPEDA enforcement today runs through complaints to the Privacy Commissioner, investigations, and, where warranted, Federal Court applications: it does not carry significant monetary penalties. The proposed Consumer Privacy Protection Act, also part of Bill C-27, would have added those penalties, but it died along with the Artificial Intelligence and Data Act at prorogation. Quebec's Law 25 carries its own administrative and penal sanctions, among the strictest privacy penalties in Canada. Human rights complaints can result in damages and mandated remedial action. The absence of the Artificial Intelligence and Data Act does not mean the absence of consequences.
Do I need a lawyer before deploying an AI system in Canada?
For anything touching hiring, credit, healthcare or Quebec residents, talking to counsel before launch is a reasonable investment, not paranoia. This article explains what applies, it does not replace legal advice specific to your business.
The bottom line
This article is for general information only and is not legal advice. Canadian AI regulation is a moving target, and the specifics of how PIPEDA, Law 25, human rights law and sector rules apply to your business depend on facts we cannot know from here. Talk to a qualified lawyer before making compliance decisions.
What we can tell you: "there's no AI law yet" is not the same as "there are no rules," and the businesses that treat it that way are the ones who end up explaining themselves to a privacy commissioner. If you are deploying a chatbot, voice agent or automation and want a system built with the audit trail, human escalation and data handling already thought through, connect with NOVAIO and we will walk you through how our deployments handle it.

