Artificial Intelligence and Data Act
· About Artificial Intelligence and Data Act
Key Takeaways
- Canada has no federal Artificial Intelligence and Data Act in force. The proposed AIDA was Part 3 of Bill C-27, and Bill C-27 died on the Order Paper when Parliament was prorogued on 6 January 2025, so no organization ever had to comply with AIDA as enacted law.[2][3][4]
- No federal AI statute has replaced AIDA as of September 2026. Reputable 2026 commentary and legal analyses consistently state that Canada still lacks a comprehensive federal AI law, although policymakers have signaled future AI legislation.[1][2][8][13]
- AIDA’s intended scope would have targeted private-sector AI systems used in interprovincial or international trade and commerce. The proposal would have captured organizations developing or making available “high-impact” systems and would have imposed governance, risk, and reporting duties on those actors.[1][7][15]
- Because AIDA never came into force, there are no AIDA-specific fines or deadlines today. Compliance teams must instead manage AI through existing Canadian privacy, human rights, consumer protection, competition, and sector-specific rules.[2][8][14]
- The practical compliance baseline in Canada is now fragmented. Organizations deploying AI in Canada should align current controls to PIPEDA, Québec privacy rules, sectoral guidance, and governance frameworks such as ISO 27001, NIST CSF 2.0, and ISO 42001.[2][8][12][13]
What It Is
The Artificial Intelligence and Data Act (AIDA) was the AI-law proposal contained in Part 3 of Bill C-27, a broader federal privacy-and-digital-governance bill.[2][14] Its policy aim was to regulate AI systems in private-sector trade and commerce through a risk-based model focused on “high-impact” systems and related organizational duties.[1][15]
AIDA was never enacted. Bill C-27 died when Parliament was prorogued on 6 January 2025, which terminated the bill before it could become law; commentators and law firms consistently describe AIDA as lapsed and not reintroduced as of September 2026.[1][2][3][14] Because AIDA did not pass, there is no operative enforcement body, no effective date, and no phase-in schedule in force today.[1][2][13]
Who Must Comply
There is no current AIDA compliance population because the statute never came into force.[1][2] For the same reason, there are no AIDA applicability thresholds, no statutory exemptions, and no extraterritorial reach to operationalize today.
Had AIDA become law, it would have applied to organizations involved in the design, development, and making available of AI systems in the course of international or interprovincial trade and commerce, with heightened duties for systems designated as high-impact.[1][15] That proposed model would likely have reached non-Canadian providers selling or deploying AI into Canada, but that remains hypothetical because the bill died before enactment.[1][13]
Core Requirements
- Risk governance program — AIDA would have required organizations to establish governance measures to identify, assess, and mitigate risks associated with high-impact AI systems, including policies, procedures, and accountability structures.[1][15]
- Impact and harm controls — The proposal focused on preventing biased output, adverse impacts, and “serious harm,” which the bill linked to physical, psychological, economic, and property harm.[1][15]
- Transparency obligations — Organizations would have had to make certain information available about the use of high-impact systems and their impacts, consistent with the bill’s disclosure-oriented framework.[1][15]
- Recordkeeping and monitoring — AIDA contemplated documentation, monitoring, and post-deployment oversight so that organizations could evidence how systems were managed and changed over time.[1][15]
- Incident reporting — The proposal would have required reporting of material incidents involving high-impact systems to the responsible federal authority, although the precise operational mechanics never became law.[1][15]
- Compliance with regulations and orders — The bill empowered regulation-making and enforcement powers, meaning organizations would have needed to follow detailed requirements that were expected to be set out after royal assent.[1][15]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | Bill C-27 introduced | 16 June 2022 | AIDA first appeared as Part 3 of the omnibus bill.[2][14] | | Bill C-27 stalled in committee | 2024 | The bill did not advance to enactment before prorogation.[1][12] | | Bill C-27 died on the Order Paper | 6 January 2025 | AIDA ceased to progress and never became law.[1][2][14] | | Status as of September 2026 | 23 September 2026 | No federal AI statute is in force; no AIDA deadlines apply.[2][8][13] |
Because AIDA never became law, there are no maximum fines, administrative monetary penalties, or criminal sanctions currently attached to AIDA.[1][2][13] Any enforcement exposure now comes from other laws, such as privacy statutes, human rights laws, consumer-protection rules, or Competition Act provisions, depending on the conduct.[2][8][14]
How to Comply
- Inventory AI use cases and owners — Identify every model, vendor tool, and automated decision system in production, including where personal information is processed and who approves deployment.
- Classify risk and impact — Map use cases to a risk register and separate high-impact decisions from low-risk automation; use the structure of NIST CSF 2.0 for governance, identify, protect, detect, respond, and recover functions.
- Build a documented AI management system — Align policy, roles, controls, audits, and continuous improvement with ISO 42001, which fits AI governance better than a generic policy stack.
- Integrate security controls — Use ISO 27001 to harden model hosting, access control, logging, supplier security, and incident response around training data, prompts, and outputs.
- Validate legal bases and notices — Check whether AI processing uses personal information and whether notices, consent, retention, and cross-border transfer controls satisfy existing privacy law, especially PIPEDA and Québec requirements where relevant.[2][8]
- Test for discrimination and explainability — Run bias, robustness, and adverse-impact testing before launch and at regular intervals, especially for hiring, credit, health, housing, and public-facing decisions.
- Contract for vendor accountability — Require disclosure, audit rights, security commitments, data-use limits, incident notice, and subprocessor controls in procurement and cloud contracts.
- Prepare incident and complaint workflows — Establish a process for consumer complaints, regulator inquiries, model rollback, and preservation of logs and prompts in case a deployment causes harm.
Related Regulations
- PIPEDA remains the baseline federal private-sector privacy law for many organizations and governs personal information used in AI systems; it overlaps heavily with AI governance where models process personal data.[2][8]
- Québec Law 25 adds stronger privacy obligations and automated-decision transparency requirements for organizations handling Québec personal information, making it especially relevant for AI-enabled profiling and decisioning.[2][8]
- Competition Act provisions on misleading advertising and deceptive marketing can apply to AI claims, benchmarks, and “AI-powered” product representations.[2][8]
- Human rights laws can constrain automated screening and decision systems where AI outcomes create discrimination risks in employment, housing, or services.[8][13]
- Sectoral guidance from financial and health regulators may impose additional expectations on governance, validation, and oversight even without a standalone federal AI statute.[2][8]
FAQ
Does AIDA apply to companies outside Canada?
No, because AIDA is not in force. The proposed law would likely have reached foreign companies offering AI systems in Canadian interprovincial or international commerce, but that is only a policy reading of the lapsed bill, not a current legal obligation.[1][15]
Is there any federal AI law in Canada right now?
No comprehensive federal AI statute is currently in force.[2][8][13] Organizations must instead comply with existing privacy, consumer, competition, and human rights laws, plus sector-specific rules where applicable.[2][8]
What happened to Bill C-27 and AIDA?
Bill C-27 died on the Order Paper when Parliament was prorogued on 6 January 2025.[1][2][14] That ended AIDA before it could become law or take effect, and it has not been reintroduced in enacted form as of September 2026.[2][13]
Are there AIDA fines or penalties to worry about?
No, because AIDA never became law.[1][2] Any enforcement risk now comes from other Canadian laws, such as privacy enforcement, competition proceedings, or human rights complaints, depending on the conduct.[2][8]
What should compliance teams do instead of AIDA implementation?
Treat AI as a governed technology program rather than a standalone AIDA project. Build an AI inventory, apply privacy and security controls, test for bias, and document accountability using frameworks such as ISO 27001, NIST CSF 2.0, and ISO 42001.[2][8][13]
Sources
- Parliament of Canada — Bill C-27 legislative record
- Government of Canada / Innovation, Science and Economic Development Canada — Artificial Intelligence and Data Act materials
- CASRAI — What Canada's AIDA Would Have Required
- Dentons — Doing business in Canada: Artificial intelligence and data
- DLA Piper — Canadian privacy and AI horizon shifts again
- University of Toronto SRI — What’s Next After AIDA?
- Chambers Practice Guides — Artificial Intelligence 2026: Canada
- Chambers Practice Guides — Doing Business in 2026: Canada
Put it into practice
- Generate the policy: NIST AI RMF policy generator (generatepolicy.com)
- Buy the policy pack: NIST AI RMF Implementation Policy (cyberpolicy.shop)
- Build it yourself: Pillar 06 Companion — The 2026 AI Risk Register (ciso.diy)