The Artificial Intelligence and Data Act was supposed to be Canada's answer to the EU's AI Act: a dedicated federal statute setting out what businesses could and could not do with AI systems, with a regulator to enforce it. It never got there. AIDA was part of Bill C-27, and when Parliament was prorogued in January 2025, every bill still before the House of Commons died with it, AIDA included. It has not been reintroduced since, and the federal government has signalled that any replacement will be a new design rather than a revival of the old bill. For an owner who heard "Canada is working on an AI law" a couple of years ago and has not followed the story since, the reasonable-sounding conclusion is that Canada currently has no AI rules. That conclusion is wrong, and acting on it is the kind of gap that surfaces during an audit rather than during ordinary business.
What actually governs AI use in Canada was never a single statute, and none of it disappeared along with AIDA. PIPEDA, the federal privacy law, still applies in full to any personal information an AI system touches — collection, use, and disclosure rules do not stop applying because a model sits in the middle of the process. If your business operates in or serves customers in Quebec, Law 25 goes further and specifically regulates automated decision-making: tell someone when a decision that significantly affects them was made wholly or partly by automated means, disclose what information went into it and why it came out that way, and give them a path to have a human re-examine it. That is a present obligation with real penalties attached, and it is the closest thing Canada currently has to an enforceable AI-specific rule.
A separate set of obligations was never going to be written into an AI statute at all, because it already exists elsewhere and applies regardless of what technology produced the outcome. Human rights and employment law do not carve out an exception for algorithms. If an AI-assisted hiring tool screens out candidates in a pattern that would be illegal discrimination if a person did it deliberately, the fact that a model made the call does not change the legal exposure — it may make it harder to detect and defend, which is worse, not better. The same logic reaches AI-assisted lending, tenant screening, and pricing. Businesses waiting for a bright-line AI law to tell them what is off-limits are overlooking that a meaningful part of the answer was already settled by law that predates AI entirely.
Federally regulated financial institutions carry an additional, more specific duty that is easy to miss outside that sector: OSFI's model risk management guideline, E-23, sets expectations for how banks and insurers govern, validate, and monitor the models — including AI models — that inform business decisions. It is not a general AI law, but for the institutions it covers, it is a live governance requirement, not a draft awaiting royal assent.
None of this is limited to businesses that only operate domestically. A Canadian company selling into the EU, or with users there, now has to reckon with the EU AI Act's obligations for high-risk systems, which took effect in August 2026 on a timeline the EU set years ago. A business that assumed AI regulation was still a someday problem because Canada's own bill stalled may find a foreign regulator's clock ran out first, on a system built for a Canadian customer base but reachable from Europe.
The practical response is not to wait for Ottawa, and it is not a comprehensive legal review before touching another AI tool. It is the specific, unglamorous work the current patchwork actually asks for: know which processes make automated decisions that meaningfully affect a person — hiring, credit, pricing, service eligibility — and be able to explain in plain language what data went into that decision and why. If you have Quebec customers or employees, build the disclosure and human-review path Law 25 requires rather than assuming a head office in Ontario exempts you. And apply "a person doing this would clearly be discrimination" as the test for AI-assisted decisions too, because a regulator, a plaintiff's lawyer, or a human rights tribunal eventually will.
The absence of a dedicated Canadian AI statute is not a green light. It is a reminder that the rules already in force — privacy law, provincial automated-decision requirements, human rights law, and sector-specific guidelines where they apply — were written broadly enough to reach AI without needing to name it. Businesses that treat the current gap as permission are building on ground that could shift the moment a regulator, a complaint, or a new provincial law tests it. Businesses that treat it as an ordinary compliance obligation, no different in kind from privacy or employment law, are simply doing the work now instead of later, under worse conditions.
- ai regulation
- compliance
- data privacy
- canada
- ai governance