Source basis
Official source basis
Last reviewed on 2026-09-08.
This profile is grounded in official laws, policy documents, regulator guidance, standards, and public-sector source materials listed below.
- Bill C-27, Digital Charter Implementation Act, 2022 — First Reading
- The Artificial Intelligence and Data Act (AIDA) — Companion document
- Directive on Automated Decision-Making
- Algorithmic Impact Assessment tool
- Personal Information Protection and Electronic Documents Act
- Privacy and artificial intelligence
- Directive on Automated Decision-Making
- Algorithmic Impact Assessment
Executive summary
Canada’s AI governance architecture is distributed across federal public-sector policy, privacy and sectoral law, safety and research institutions, and broader AI strategy. Its strongest binding operational controls are concentrated in federal administrative decision-making: the Directive on Automated Decision-Making requires risk assessment and proportional safeguards for automated systems used to make or support administrative decisions about clients, supported by a mandatory Algorithmic Impact Assessment. The federal government is also building transparency and capacity through a public AI Register, a 2025–2027 AI Strategy for the Federal Public Service, agentic-AI guidance and the Canadian AI Safety Institute. For private enterprises, compliance exposure remains more fragmented than in the EU or South Korea; suppliers to government should nevertheless expect strong documentation, risk, transparency and assurance expectations.
Governance architecture
Canada’s clearest binding AI governance mechanisms are concentrated in federal public-sector administration. The Directive on Automated Decision-Making and its Algorithmic Impact Assessment establish risk-based controls for covered federal automated decision systems. The federal AI strategy, AI Register, agentic-AI guidance, privacy oversight and Canadian AI Safety Institute add transparency, capability and safety layers. These instruments should not be generalized into a private-sector horizontal AI Act.
Major policies and frameworks
| Policy | Issuer | Year | Status | Summary |
|---|---|---|---|---|
| Directive on Automated Decision-Making | Treasury Board of Canada Secretariat | 2019 | Federal public-sector directive - binding within scope | Requires federal institutions to assess and manage automated decision systems through proportional safeguards, transparency, human involvement, data governance and monitoring. |
| Algorithmic Impact Assessment | Government of Canada / Treasury Board of Canada Secretariat | 2026 | Mandatory federal assessment instrument within scope | Risk-assessment tool supporting the Directive on Automated Decision-Making; it does not create a general private-sector AI law. |
| AI Strategy for the Federal Public Service 2025–2027 | Government of Canada / Treasury Board of Canada Secretariat | 2025–2027 | Federal public-service strategy | Strategy for responsible federal AI adoption, workforce capability, service improvement, governance and public trust. |
| Government of Canada AI Register | Treasury Board of Canada Secretariat | 2025–2026 | Public-sector transparency and implementation instrument | Public register of federal AI uses and systems; it is an institutional transparency mechanism, not a private-sector AI statute. |
| Guide on the Use of Agentic Artificial Intelligence | Government of Canada | 2026 | Official guidance - non-binding outside its administrative context | Risk-based federal guidance for considering agentic AI use, accountability, oversight and operational safeguards. |
| Canadian Artificial Intelligence Safety Institute | Innovation, Science and Economic Development Canada | 2026 | AI safety and evaluation institution | Institutional capacity for advanced-AI safety research, evaluation, guidance and international coordination; not a general AI regulator. |
| Bill C-27 / Artificial Intelligence and Data Act | Parliament of Canada | 2022 | Archived proposed legislation - not enacted | Historical proposed federal AI legislation from the 44th Parliament. Bill C-27 ended without enactment and must not be presented as current law. |
Policy timeline
2019-04-01
Directive on Automated Decision-Making takes effect
Federal public-sector directive establishes binding administrative-policy requirements for covered automated decision systems.
2020-04-01
Compliance required for systems within scope
Covered federal institutions must comply with the Directive and associated impact-assessment requirements.
2025
Federal Public Service AI Strategy 2025–2027 in operation
Federal strategy links responsible AI adoption with service transformation, governance and workforce capability.
2025-11-28
First Government of Canada AI Register launched
The federal government launched a public register reporting AI uses across institutions.
2026-05-22
Guide on the Use of Agentic AI published
Federal guidance adds an agentic-AI risk and accountability signal without creating a horizontal binding AI law.
2026-09-08
Observatory initial Canada profile review
Initial profile created from official federal, Parliament, regulator, AI safety and public-sector sources.
Enterprise implications
Enterprises should treat Canada as an evolving governance environment rather than a jurisdiction with a single enacted horizontal AI statute. The immediate operational priorities are privacy governance, data stewardship, vendor and model documentation, human oversight, security controls, public-sector procurement readiness, voluntary generative AI commitments where relevant, and monitoring of any renewed federal AI legislation. Organizations selling into or partnering with Canadian federal institutions should pay particular attention to automated decision-making impact assessment expectations and transparency requirements.
Observatory interpretation
Canada’s distinctive signal is institutional layering. The policy system combines binding federal public-sector rules, privacy regulation, open impact-assessment tooling, voluntary generative AI commitments, AI safety institution-building, agentic-AI guidance and compute strategy. AIDA/Bill C-27 remains historical proposed legislation, so practical readiness depends on current administrative, privacy, procurement, safety and accountability controls rather than waiting for an enacted horizontal AI law.
Official resources
| Resource | Source | Type | Date | Legal force | Why it matters |
|---|---|---|---|---|---|
| Bill C-27, Digital Charter Implementation Act, 2022 — First Reading | Parliament of Canada | Law | 2022-06-16 | Proposed | Provides the official legislative source for Canada’s proposed federal AI law track, while not establishing binding AI law by itself. |
| The Artificial Intelligence and Data Act (AIDA) — Companion document | Innovation, Science and Economic Development Canada | Guidance | 2023 | Draft | Important for historical interpretation, but the archived status makes legal-status caveats essential. |
| Directive on Automated Decision-Making | Treasury Board of Canada Secretariat | Public-sector rule | 2019 | Binding | This is one of Canada’s clearest binding AI governance mechanisms for federal government use. |
| Algorithmic Impact Assessment tool | Government of Canada / Treasury Board of Canada Secretariat | Public-sector rule | 2026-05-28 | Guidance | Operationalizes risk classification and mitigation expectations for federal automated decision systems. |
| Personal Information Protection and Electronic Documents Act | Department of Justice Canada | Law | 2000 | Binding | AI systems involving personal information remain exposed to privacy-law obligations independent of any future AI statute. |
| Privacy and artificial intelligence | Office of the Privacy Commissioner of Canada | Guidance | Guidance | Shows how Canada’s privacy regulator frames AI-related privacy issues and accountability. | |
| Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems | Innovation, Science and Economic Development Canada | Framework | 2023 | Voluntary | Provides a near-term governance signal before any binding horizontal AI statute. |
| Canadian Artificial Intelligence Safety Institute | Innovation, Science and Economic Development Canada | Strategy | 2026-06-04 | Not applicable | Adds AI safety institution-building to Canada’s governance architecture. |
| Guidelines for secure AI system development | Canadian Centre for Cyber Security | Guidance | Guidance | Connects AI governance with cybersecurity controls and secure system development. | |
| Canadian Sovereign AI Compute Strategy | Innovation, Science and Economic Development Canada | Strategy | 2026-06-04 | Not applicable | Shows that Canada’s AI governance agenda includes compute capacity, data, intellectual property, and infrastructure strategy. |
| Pan-Canadian Artificial Intelligence Strategy | Innovation, Science and Economic Development Canada | Strategy | 2026-06-04 | Not applicable | Provides the innovation, standards, research, and talent context for Canada’s AI governance profile. |
| AI Strategy for the Federal Public Service 2025–2027 | Treasury Board of Canada Secretariat | Strategy | 2025 | Not applicable | Shows how federal AI governance is tied to institutional capability and workforce readiness. |
| Government of Canada AI Register | Treasury Board of Canada Secretariat | Public-sector rule | 2025-11-28 | Guidance | Provides an observable implementation and accountability signal for federal AI deployment. |
| Guide on the Use of Agentic Artificial Intelligence | Government of Canada | Guidance | 2026-05-22 | Guidance | Adds a current agentic-AI implementation signal without overstating guidance as binding law. |
Update log
2026-06-17: Initial source-backed Canada profile published from official federal, Parliament, regulator, AI safety, privacy, compute, and cyber source materials. AIDA/Bill C-27 is treated as proposed and historical, not binding law.
2026-09-08: Initial published profile created and reviewed from Government of Canada, Treasury Board, ISED and Parliament sources. The Directive on Automated Decision-Making is classified as federal public-sector policy, AIDA/Bill C-27 as historical proposed legislation that did not become law, and the AI strategy, AI Register, agentic-AI guidance and CAISI as strategy, transparency, guidance and institutional-capacity signals.
