AIDA ss. 7-9 (as drafted, never enacted)
What AIDA would have required: high-impact systems, assessed and mitigated
The bill required anyone responsible for a high-impact AI system to assess whether the system was high-impact, establish measures to identify, assess, and mitigate risks of harm and biased output, and monitor the effectiveness of those measures. Classes of high-impact systems (employment screening, service eligibility, biometrics, content moderation, health) were sketched in amendments before the bill died.
Though never enacted, this remains the clearest signal of what a future Canadian AI law will likely demand: know which of your AI uses can affect people's opportunities and rights, document the risks, and put mitigation in place. Organizations that build that inventory and control discipline now are hedged against whichever successor vehicle eventually carries the obligations.
AIDA s. 11 (as drafted, never enacted)
What AIDA would have required: plain-language transparency
Persons making high-impact systems available, or managing their operation, would have had to publish plain-language descriptions of the system: how it is used, the types of content it generates and decisions it makes, and the mitigation measures in place. An AI and Data Commissioner within ISED would have administered and enforced the act.
The transparency duty previewed a norm that already exists elsewhere (the EU AI Act, Quebec's s. 12.1) and that enterprise customers increasingly demand in procurement regardless of statute. Being able to describe, in plain language, where AI is used in your organization and what data it touches is table stakes for diligence questionnaires today, statute or no statute.
PIPEDA and provincial privacy laws (in force now)
What governs now: privacy law applies fully to AI
With AIDA gone, personal information in AI tools is governed by the laws that never went away: PIPEDA federally, Quebec's Law 25, and the Alberta and BC PIPAs. The OPC and provincial regulators' December 2023 joint principles on generative AI spell out how existing law applies to prompts and training data.
The practical rule set for Canadian organizations today is privacy law: employee prompts containing personal information are uses and disclosures requiring authority, consent analysis, and safeguards. The gap AIDA would have filled (AI-specific risk and transparency duties) does not suspend the rules that already exist. IBM found in 2025 that 63% of organizations have no AI governance policy at all, a gap no prorogation excuses.
Voluntary Code of Conduct on Advanced Generative AI (September 2023, in effect)
What governs now: the voluntary code for generative AI developers and managers
ISED's voluntary code commits signatories developing or managing advanced generative AI systems to accountability, safety, fairness and equity, transparency, human oversight, and validity and robustness, in advance of binding regulation. Major Canadian AI firms and institutions signed it.
For most organizations the code matters as a market signal rather than an obligation: it defines what responsible practice looks like in Canada and shows up in vendor diligence. If your AI vendors have not signed or cannot describe equivalent measures, that is a data point for the risk assessment privacy law already requires of you.
TBS Directive on Automated Decision-Making (in force for federal institutions)
What governs now: binding rules for federal government AI
The Treasury Board Directive on Automated Decision-Making requires federal institutions using automated decision systems to complete an Algorithmic Impact Assessment, provide notice and explanations, ensure human intervention proportionate to impact level, and test for bias. It has been in force since 2019 and is periodically updated.
The directive binds federal institutions, not private companies, but it is Canada's most developed operational AI governance regime and a template regulators and courts will reach for. Its core moves, impact assessment before deployment, tiered human oversight, and documented testing, are the same ones AIDA would have imposed and the same ones a defensible private-sector program needs.