Canadian Privacy & AI Law

AIDA (Bill C-27)

Artificial Intelligence and Data Act (AIDA), Part 3 of Bill C-27, died on the Order Paper in January 2025

Canada's proposed AI law died when Parliament was prorogued in January 2025, and no successor AI act has been tabled since. What AIDA would have required, what actually governs Canadian AI use now, and what to watch next.

Canada (federal, never enacted)Died with Bill C-27 in January 2025; no successor AI act as of August 2026Verified 2026-08-31

What it means for AI and data privacy

AIDA was Canada's attempt at a national AI law: obligations for high-impact AI systems, mandatory risk assessment and mitigation, transparency duties, and an AI and Data Commissioner to enforce it all. It died on the Order Paper when Parliament was prorogued on January 6, 2025, and as of August 2026 no successor AI act has been introduced. That does not mean Canadian AI use is unregulated. PIPEDA and provincial privacy laws (Quebec's Law 25 above all) apply fully to personal information in AI tools, the Voluntary Code of Conduct on advanced generative AI sets developer expectations, and the Treasury Board Directive on Automated Decision-Making binds federal institutions. The current government has signalled it will regulate AI through privacy reform rather than a standalone statute: Bill C-36, tabled in June 2026, would replace PIPEDA's privacy part with penalties up to the greater of C$25 million or 5% of gross global revenue. Waiting for a Canadian AI act before governing AI use is waiting for a law that may never come in that form.

Who it applies to

  • Nobody, as binding law: AIDA never came into force
  • Organizations that built compliance roadmaps around AIDA and now need to know what replaced it
  • Canadian organizations subject to what actually governs AI use today: PIPEDA, provincial privacy laws, and sector rules
  • Federal institutions bound by the Treasury Board Directive on Automated Decision-Making
  • AI developers and deployers watching for successor legislation

Enforcement and penalties

AIDA's proposed penalties never took effect: the bill contemplated administrative monetary penalties, fines for regulatory offences up to the greater of C$10 million or 3% of global revenue, and up to the greater of C$25 million or 5% of global revenue for the most serious offences, with criminal liability for reckless or fraudulent AI conduct. None of it became law. Today, the enforcement that actually reaches AI misuse of personal data in Canada comes from privacy law: the OPC under PIPEDA (limited direct penalties), Quebec's CAI under Law 25 (fines up to C$25 million or 4% of worldwide turnover), and provincial regulators in Alberta and British Columbia. Bill C-36, the June 2026 privacy reform, would add federal penalties up to the greater of C$25 million or 5% of gross global revenue.

Key provisions for AI and data privacy

AIDA ss. 7-9 (as drafted, never enacted)

What AIDA would have required: high-impact systems, assessed and mitigated

The bill required anyone responsible for a high-impact AI system to assess whether the system was high-impact, establish measures to identify, assess, and mitigate risks of harm and biased output, and monitor the effectiveness of those measures. Classes of high-impact systems (employment screening, service eligibility, biometrics, content moderation, health) were sketched in amendments before the bill died.

Though never enacted, this remains the clearest signal of what a future Canadian AI law will likely demand: know which of your AI uses can affect people's opportunities and rights, document the risks, and put mitigation in place. Organizations that build that inventory and control discipline now are hedged against whichever successor vehicle eventually carries the obligations.

AIDA s. 11 (as drafted, never enacted)

What AIDA would have required: plain-language transparency

Persons making high-impact systems available, or managing their operation, would have had to publish plain-language descriptions of the system: how it is used, the types of content it generates and decisions it makes, and the mitigation measures in place. An AI and Data Commissioner within ISED would have administered and enforced the act.

The transparency duty previewed a norm that already exists elsewhere (the EU AI Act, Quebec's s. 12.1) and that enterprise customers increasingly demand in procurement regardless of statute. Being able to describe, in plain language, where AI is used in your organization and what data it touches is table stakes for diligence questionnaires today, statute or no statute.

PIPEDA and provincial privacy laws (in force now)

What governs now: privacy law applies fully to AI

With AIDA gone, personal information in AI tools is governed by the laws that never went away: PIPEDA federally, Quebec's Law 25, and the Alberta and BC PIPAs. The OPC and provincial regulators' December 2023 joint principles on generative AI spell out how existing law applies to prompts and training data.

The practical rule set for Canadian organizations today is privacy law: employee prompts containing personal information are uses and disclosures requiring authority, consent analysis, and safeguards. The gap AIDA would have filled (AI-specific risk and transparency duties) does not suspend the rules that already exist. IBM found in 2025 that 63% of organizations have no AI governance policy at all, a gap no prorogation excuses.

Voluntary Code of Conduct on Advanced Generative AI (September 2023, in effect)

What governs now: the voluntary code for generative AI developers and managers

ISED's voluntary code commits signatories developing or managing advanced generative AI systems to accountability, safety, fairness and equity, transparency, human oversight, and validity and robustness, in advance of binding regulation. Major Canadian AI firms and institutions signed it.

For most organizations the code matters as a market signal rather than an obligation: it defines what responsible practice looks like in Canada and shows up in vendor diligence. If your AI vendors have not signed or cannot describe equivalent measures, that is a data point for the risk assessment privacy law already requires of you.

TBS Directive on Automated Decision-Making (in force for federal institutions)

What governs now: binding rules for federal government AI

The Treasury Board Directive on Automated Decision-Making requires federal institutions using automated decision systems to complete an Algorithmic Impact Assessment, provide notice and explanations, ensure human intervention proportionate to impact level, and test for bias. It has been in force since 2019 and is periodically updated.

The directive binds federal institutions, not private companies, but it is Canada's most developed operational AI governance regime and a template regulators and courts will reach for. Its core moves, impact assessment before deployment, tiered human oversight, and documented testing, are the same ones AIDA would have imposed and the same ones a defensible private-sector program needs.

Practical compliance steps

  1. 1Stop waiting for a Canadian AI act: govern AI use under the privacy laws in force now, PIPEDA and provincial statutes
  2. 2Inventory where AI is used across the organization, including unapproved browser tools, and which uses could qualify as high-impact under AIDA-style criteria
  3. 3Apply the OPC's December 2023 generative AI principles: establish legal authority before personal information enters prompts, and limit what goes in
  4. 4Put a technical control at the point of entry that redacts personal and confidential data in prompts, since privacy-law safeguards apply today regardless of AI legislation
  5. 5Check AI vendors against the Voluntary Code of Conduct and document the assessment for procurement files
  6. 6If you serve or are a federal institution, align with the TBS Directive on Automated Decision-Making, including Algorithmic Impact Assessments
  7. 7Track Bill C-36 and provincial bills each session, and assign someone to reassess obligations when successor legislation moves

How Sanitized AI maps to this

AIDA-style risk identification (ss. 7-9 as drafted)

Admin visibility into which AI tools employees actually use, and what categories of sensitive data were caught in prompts, is the inventory any AIDA-successor risk assessment will start from.

Privacy-law safeguards in force now (PIPEDA, Law 25)

Personal information in prompts is caught and redacted before submission, the point-of-entry safeguard that current law already requires while AI-specific legislation remains pending.

Transparency and accountability expectations

Usage and interception reporting lets an organization describe, with evidence, where AI is used and what data it touches, the plain-language account AIDA would have mandated and diligence questionnaires already demand.

Frequently asked questions

Is AIDA still going to become law in Canada?

Not in its original form. AIDA died with Bill C-27 when Parliament was prorogued on January 6, 2025, and as of August 2026 no successor AI act has been introduced. The current government has signalled it prefers to address AI through privacy-law reform, notably Bill C-36 tabled in June 2026, rather than a standalone AI statute. A future AI-specific bill remains possible but none is on the table.

What happened to Bill C-27?

Bill C-27 bundled three acts: the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act, and AIDA. It had passed second reading and was in committee when Parliament was prorogued in January 2025, which cleared the Order Paper and killed the bill. Its privacy reforms were revived in different form as Bill C-36 in June 2026; its AI act was not.

What law governs AI use in Canada right now?

There is no comprehensive federal AI law. Personal information in AI tools is governed by PIPEDA and provincial privacy laws, with Quebec's Law 25 the strictest, including its automated-decision transparency rule. Federal institutions are bound by the TBS Directive on Automated Decision-Making, generative AI developers can sign the Voluntary Code of Conduct, and sector regulators (financial, health, securities) apply their existing rules to AI.

What would AIDA have required for high-impact AI systems?

As drafted, persons responsible for high-impact systems would have had to assess the system's impact, establish and monitor risk-mitigation measures against harm and biased output, publish plain-language descriptions of the system, and notify the minister of material harms. Fines would have reached the greater of C$25 million or 5% of global revenue for the most serious offences, with an AI and Data Commissioner enforcing.

Does Canada's Voluntary Code of Conduct on generative AI apply to my company?

Only if you sign it, and it targets developers and managers of advanced generative AI systems rather than everyday business users. Its practical relevance for most organizations is as a benchmark: it describes what responsible generative AI practice looks like in Canada and is a reasonable checklist for assessing AI vendors while binding legislation is absent.

Should we wait for new Canadian AI legislation before setting AI policies?

No. Privacy law already applies to every prompt containing personal information, Quebec already fines up to C$25 million or 4% of worldwide turnover, and the exposure is current: IBM found in 2025 that shadow AI involvement added an average of $670K to breach costs and that 97% of organizations suffering AI-related breaches lacked proper AI access controls. The organizations that governed AI under existing law will also be the ones ready when successor legislation lands.

Primary sources

This guide summarizes the cited primary sources as of the verification date. It is general information, not legal advice.

The gap in every framework is the prompt box.

Sanitized AI catches sensitive data in prompts before it leaves and shows administrators which AI tools employees actually use.

Get a demo

Related standards