Canada After AIDA Stalled: What Actually Governs Your AI Today
Canada's AI and Data Act was proposed but never enacted. That does not mean AI is unregulated there — PIPEDA and provincial privacy law apply right now.
Canada's Artificial Intelligence and Data Act (AIDA) was proposed as part of Bill C-27 and targeted high-impact AI. It was never enacted.
This creates a specific and fairly common misunderstanding: because the flagship AI bill did not pass, businesses assume AI is unregulated in Canada. It is not.
What AIDA would have required
Useful to know, because a successor is widely expected to revisit the same ground:
- Risk assessments and transparency for high-impact AI, for developers.
- Human oversight and accountability for high-impact systems, for deployers.
What actually governs you today
The binding layer is privacy and human-rights law:
- PIPEDA applies to personal data processed by AI systems — which covers most business AI use.
- Provincial regimes add their own requirements. Quebec's Law 25 in particular already requires transparency around automated decision-making.
- Human-rights law applies to discriminatory outcomes regardless of whether a human or a model produced them.
The absence of an AI-specific statute is not the absence of AI regulation. Privacy law reaches most of what an SME does with AI, and it is in force now.
What SMEs should do
- Meet PIPEDA properly for any AI touching personal data: lawful handling, transparency in your privacy notice, and appropriate safeguards.
- If you serve Quebec residents, disclose automated decision-making. This obligation exists today and is frequently missed.
- Prepare with a recognised framework. NIST AI RMF or ISO/IEC 42001 adoption positions you well for whatever succeeds AIDA, and delivers value immediately in procurement.
- Do not wait for the successor bill. The requirements AIDA proposed — risk assessment, human oversight, transparency — are the same ones appearing in every serious regime. Building them now is not speculative.
What Quebec's Law 25 asks for specifically
Quebec is the province most likely to catch a business out, because its automated-decision transparency duty is already live while everyone is watching for federal law.
In practice it means that where a decision about someone is made exclusively by automated processing, you inform them of that fact, and on request you can explain the personal information used and the principal factors that led to the outcome. People must also be able to submit observations to someone able to review the decision.
If you use AI in hiring, credit, pricing or eligibility decisions affecting Quebec residents, that is a present obligation, not a future one.
The strategic read
Canada is a draft-status jurisdiction, but the underlying trend is stable. Every comprehensive AI regime converging today asks for broadly the same things.
An SME that documents its AI inventory, assesses risk proportionately, and keeps humans accountable for consequential decisions is well placed in Canada — and, not coincidentally, in the EU, Colorado, Brazil and everywhere else.
The mistake to avoid is treating "AIDA did not pass" as permission to defer. The obligations that reach you today come from privacy and human-rights law, and those are already enforced.
Frequently asked questions
Is AIDA law in Canada?
No. AIDA was proposed as part of Bill C-27 but was not enacted. Businesses should plan on the basis of existing privacy and human-rights law, while expecting a successor proposal in future.
So is AI unregulated in Canada?
No. PIPEDA governs personal data in AI systems today, provincial regimes such as Quebec's Law 25 add automated-decision transparency duties, and human-rights law applies to discriminatory outcomes.