policy · Effective Jan 1, 2025
CA regulates AI through CAN-ASC-6.2 Accessible and Equitable Artificial Intelligence Standard.
CAN-ASC-6.2 Accessible and Equitable Artificial Intelligence Standard · effective 2025
Updated 60 days ago · 3 sources · confidence: medium
Overview
Canada's federal approach to artificial intelligence (AI) regulation is characterized by an evolving, multi-faceted strategy that balances fostering innovation with ensuring responsible and ethical development and deployment. The country has adopted a human-centric and risk-based philosophy, aiming to leverage AI's benefits while mitigating potential harms to individuals and society. While a comprehensive, horizontal AI statute (the Artificial Intelligence and Data Act, or AIDA) was proposed as part of Bill C-27 but ultimately withdrawn, Canada has actively implemented a range of soft law instruments, strategic policies, and sector-specific guidelines at the federal level. These include mandatory directives for federal government institutions, voluntary codes of conduct for the private sector, and significant investments in AI research and safety through initiatives like the Pan-Canadian Artificial Intelligence Strategy and the Canadian Artificial Intelligence Safety Institute.The current regulatory landscape reflects a pragmatic recognition of AI's rapid evolution, favoring agile, iterative approaches that can adapt to new technological developments. The focus is on embedding principles of transparency, accountability, fairness, and human oversight into AI systems and their governance. This includes a strong emphasis on data protection, given the foundational role of data in AI, and a commitment to international collaboration to align regulatory efforts globally. Canada's strategy also highlights the importance of accessibility and equity in AI, as demonstrated by the National Standard for Accessible and Equitable AI, ensuring that AI systems are designed to be inclusive of persons with disabilities.
Regulatory approach
Canada's federal regulatory approach to AI is predominantly characterized by a blend of soft law instruments, sector-specific binding guidelines, and a strong commitment to a risk-based framework. Rather than a single, overarching prescriptive law for the entire private sector (which was the intent of the withdrawn AIDA), the current environment relies on a combination of voluntary codes, operational directives, and prudential guidelines. This allows for flexibility and adaptability in a rapidly evolving technological landscape, encouraging responsible innovation while setting expectations for accountability. The risk-based methodology is evident in instruments like the Treasury Board of Canada Secretariat's (TBS) Directive on Automated Decision-Making, which mandates federal institutions to assess the impact level of AI systems and apply proportionate mitigation measures.For the private sector, voluntary instruments like the Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems provide a framework for organizations to adopt best practices in advance of, or alongside, potential future binding legislation. In specific regulated sectors, such as financial services, binding guidelines issued by bodies like the Office of the Superintendent of Financial Institutions (OSFI) explicitly incorporate AI and machine learning into existing model risk management frameworks, ensuring prudential oversight. This hybrid approach allows Canada to foster an innovation-friendly environment while incrementally building regulatory capacity and addressing specific areas of concern, often drawing on international best practices and principles from organizations like the OECD. Several federal bodies play crucial roles in Canada's AI governance landscape, reflecting a distributed approach to oversight. Innovation, Science and Economic Development Canada (ISED) is central to developing and promoting national AI policy, including the Pan-Canadian Artificial Intelligence Strategy and voluntary codes of conduct. ISED also houses the Canadian Artificial Intelligence Safety Institute (CAISI), which focuses on advancing the scientific understanding of AI risks, developing testing methodologies, and coordinating with international counterparts. CAISI's mandate is research-focused, feeding evidence into policy processes rather than direct regulation or enforcement.The Treasury Board of Canada Secretariat (TBS) is responsible for governing the use of AI within the federal public service. Its Directive on Automated Decision-Making mandates federal departments to assess and mitigate risks associated with automated decision systems through tools like the Algorithmic Impact Assessment (AIA). TBS ensures that public sector AI deployments adhere to principles of transparency, fairness, and accountability, with internal compliance mechanisms and oversight by the Office of the Chief Information Officer. For the financial sector, the Office of the Superintendent of Financial Institutions (OSFI) issues prudential guidelines, such as Guideline E-23, which explicitly covers model risk management for AI/ML systems in federally regulated financial institutions. OSFI exercises supervisory tools and enforcement powers to ensure compliance with its guidelines, including remedial plans and restrictions on operations.Accessibility Standards Canada develops national standards like CAN-ASC-6.2 for accessible and equitable AI, which, while voluntary, can be recommended to the Minister responsible for the Accessible Canada Act and may inform regulatory instruments for federally regulated entities. The Standards Council of Canada (SCC) plays a role in developing AI-related standards and conformity assessment pilots, often funded through the Pan-Canadian AI Strategy, to support future regulatory compliance or voluntary certification. The Office of the Privacy Commissioner of Canada (OPC) remains a key oversight body for privacy matters related to AI under existing privacy legislation, such as the Personal Information Protection and Electronic Documents Act (PIPEDA), and continues to advocate for stronger data protection and algorithmic transparency. While the proposed AI and Data Commissioner and Personal Information and Data Protection Tribunal (under the withdrawn Bill C-27) would have significantly augmented federal enforcement, the current framework relies on existing mandates and the internal compliance mechanisms of government departments and regulated entities.
Enforcement & penalties
Currently, federal AI regulations in Canada primarily consist of guidelines, policies, and voluntary codes, which do not carry direct statutory fines or criminal penalties for non-compliance. For instance, the Voluntary Code of Conduct on Advanced Generative AI Systems relies on reputational consequences and the prospect of future binding legislation for adherence, rather than immediate statutory sanctions. Similarly, the Implementation Guide for Managers of AI Systems provides best practices without imposing fines. However, non-compliance with mandatory policy instruments, such as the Treasury Board of Canada Secretariat's Directive on Automated Decision-Making for federal institutions, can lead to administrative escalations, remediation requirements, procurement restrictions, and internal accountability measures within the public service.In federally regulated sectors, existing regulatory bodies leverage their established enforcement powers. The Office of the Superintendent of Financial Institutions (OSFI), for example, can address non-compliance with its Guideline E-23 on Model Risk Management (which includes AI/ML systems) through supervisory directions, remedial plans, restrictions on operations, and administrative monetary penalties under existing legislative authorities. The Office of the Privacy Commissioner of Canada (OPC) enforces the Personal Information Protection and Electronic Documents Act (PIPEDA) through investigations, audits, and the power to make recommendations and publish findings, with potential for court-ordered compliance. While the proposed Artificial Intelligence and Data Act (AIDA) and Consumer Privacy Protection Act (CPPA) (part of the withdrawn Bill C-27) would have introduced significant administrative monetary penalties (AMPs) and criminal offences for serious contraventions, these provisions did not come into force. Any future binding legislation is expected to include a robust enforcement framework with substantial penalties to ensure compliance.
Data protection
Canada's federal data protection framework is primarily governed by the Personal Information Protection and Electronic Documents Act (PIPEDA), which applies to private-sector organizations that collect, use, or disclose personal information in the course of commercial activities. PIPEDA is based on ten fair information principles, including accountability, identifying purposes, consent, limiting collection, limiting use, disclosure, and retention, accuracy, safeguards, openness, individual access, and challenging compliance. The Office of the Privacy Commissioner of Canada (OPC) is responsible for overseeing compliance with PIPEDA, investigating complaints, conducting audits, and issuing recommendations.While PIPEDA has been foundational, it has faced calls for modernization to address the complexities of the digital and AI era. The proposed Consumer Privacy Protection Act (CPPA), introduced as Part 1 of the withdrawn Bill C-27, aimed to replace key parts of PIPEDA. The CPPA would have strengthened individual rights, introduced enhanced consent requirements, mandated privacy management programs, and created a more robust enforcement regime with significant administrative monetary penalties and a new Personal Information and Data Protection Tribunal. Although the CPPA did not become law, its policy aims, particularly concerning algorithmic transparency (e.g., a right to explanation for automated decisions) and data mobility, are expected to inform future federal privacy legislation. Currently, organizations must continue to adhere to PIPEDA and other applicable provincial privacy laws, ensuring that personal information used in AI systems is collected, used, and protected in accordance with existing legal obligations.
Sector-specific rules
Canada has begun to implement sector-specific AI regulations, particularly in areas where the risks are deemed higher or where existing regulatory mandates provide a clear pathway. A prominent example is the financial sector, where the Office of the Superintendent of Financial Institutions (OSFI) has issued Guideline E-23 — Model Risk Management. This guideline explicitly broadens the definition of "model" to encompass analytical applications, including AI/ML-based systems, used by federally regulated financial institutions (FRFIs). It mandates a risk-based approach to model governance across the entire lifecycle, from development and testing to deployment and monitoring, with specific considerations for explainability, fairness, and robustness in advanced AI models.Within the federal public sector, the Treasury Board of Canada Secretariat's (TBS) Directive on Automated Decision-Making serves as a mandatory, sector-specific policy. It applies to federal departments that develop, procure, or deploy automated decision systems that make or assist administrative decisions affecting clients' rights, interests, or privileges. The Directive requires departments to complete an Algorithmic Impact Assessment (AIA) to determine an AI system's impact level and implement proportionate mitigation measures, including enhanced transparency, human oversight, and bias assessment. While Canada does not yet have comprehensive federal legislation for AI in sectors like healthcare or autonomous vehicles, existing regulatory bodies in these domains (e.g., Health Canada for medical devices, Transport Canada for vehicle safety) are expected to adapt or introduce new guidance as AI integration becomes more prevalent. The National Standard for Accessible and Equitable AI (CAN-ASC-6.2) also has sector-agnostic implications but is particularly relevant for sectors delivering public services or products to persons with disabilities.
International alignment
Canada is actively engaged in international efforts to align its AI regulatory framework with global best practices and principles. A significant step in this direction is the Canada-EU Memorandum of Understanding on Artificial Intelligence, signed in December 2025. This non-binding instrument formalizes cooperation between Canada and the European Union on various AI-related activities, including harmonizing standards and regulatory approaches, exchanging information on AI governance, expanding scientific cooperation, and facilitating access to compute infrastructure. This MoU signals Canada's intent to align with the EU's human-rights-based and trustworthy AI development philosophy, particularly in light of the EU's Artificial Intelligence Act.Beyond bilateral agreements, Canada is a strong proponent of multilateral initiatives and principles. It actively participates in fora such as the G7, the Organisation for Economic Co-operation and Development (OECD), and the Global Partnership on Artificial Intelligence (GPAI). The Pan-Canadian Artificial Intelligence Strategy explicitly directs sustained cooperation with international initiatives, and the proposed Artificial Intelligence and Data Act (AIDA) (though withdrawn) referenced alignment with OECD definitions of AI systems. The Canadian Artificial Intelligence Safety Institute (CAISI) is also mandated to coordinate with international counterparts through the International Network of AI Safety Institutes, accelerating Canadian technical leadership on safety research and model evaluation. This commitment to international alignment aims to reduce regulatory fragmentation, promote interoperability, and ensure that Canadian AI development adheres to globally recognized ethical and safety standards.
What's next
Canada's federal AI regulatory landscape is poised for significant future developments, particularly following the withdrawal of Bill C-27, which included the proposed Artificial Intelligence and Data Act (AIDA), the Consumer Privacy Protection Act (CPPA), and the Personal Information and Data Protection Tribunal Act (PIDPTA). These bills, which aimed to establish a comprehensive, risk-based federal framework for private-sector AI and modernize privacy law, died on the Order Paper in January 2025. Despite this setback, the policy goals and the underlying principles of these withdrawn bills are widely expected to inform new legislative proposals. The government has signaled its continued commitment to regulating high-impact AI systems and strengthening privacy protections, indicating that a revised or new version of AI and privacy legislation is likely to be introduced in the future, potentially incorporating lessons learned from stakeholder consultations and international developments.Ongoing consultations and the work of bodies like the Canadian Artificial Intelligence Safety Institute (CAISI) will continue to shape future policy. CAISI's research on AI risks, testing methodologies, and international coordination will provide crucial evidence for upcoming regulatory instruments. Furthermore, the Pan-Canadian Artificial Intelligence Strategy (PCAIS) continues to fund standards development through the Standards Council of Canada, which could lead to the adoption of new technical standards and conformity assessment frameworks that may eventually be referenced in binding regulations. The iterative nature of existing guidelines, such as the TBS Directive on Automated Decision-Making, also suggests ongoing updates to reflect technological advancements and evolving best practices. The government's overall trajectory points towards a continued effort to establish a robust and adaptive regulatory environment for AI, balancing innovation with safety, ethics, and human rights, with new legislative initiatives expected to emerge in the coming parliamentary sessions.
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
advisory
Develop and promote national AI policy; oversee CAISI; foster innovation and commercialization.
advisory
Establish mandatory policy requirements for federal departments using automated decision systems; ensure responsible AI use in the public sector.
sectoral
Regulate and supervise federally regulated financial institutions (FRFIs), including managing model risk for AI/ML systems.
advisory
Develop national accessibility standards, including for AI systems, to promote an accessible Canada.
May 13, 2026 · news
Government of Canada and TELUS advance work to build sovereign AI infrastructure
Open source →May 5, 2026 · international_agreement
Joint investigation by Canadian privacy regulators into OpenAI’s ChatGPT leads to better protections for personal information
Open source →May 3, 2026 · news
Delayed federal AI strategy coming soon, says AI minister
Open source →Apr 30, 2026 · international_agreement
US, Australia, Canada, New Zealand and UK release joint guidance on careful adoption of agentic AI services
Open source →Apr 27, 2026 · news
guideline · Effective Jan 1, 2025
guideline · Effective Jan 1, 2025
policy · Effective Oct 27, 2024
policy · Effective Jan 1, 2024
guideline · Effective Jan 1, 2024
guideline · Effective Jan 1, 2023
policy · Effective Jan 1, 2022
policy · Effective Jan 1, 2022
policy · Effective Jan 1, 2022
policy · Effective Jan 1, 2019
policy · Effective Jan 1, 2019
policy · Effective Jan 1, 2017
act · Effective n/a
policy · Effective n/a
Sources:
policy · Effective n/a
policy · Effective n/a
policy · Effective n/a
The Canadian government introduced Bill C-27, also known as the Digital Charter Implementation Act, 2022. If passed, this package of laws will implement Canada's first AI legislation, the Artificial Intelligence and Data Act (AIDA); reform Canadian privacy law; and establish a tribunal specific to privacy and data protection. The AIDA has 3 objectives: (1) regulate 'high-impact AI systems', (2) establish the AI and Data Commissioner as the regulator and enforcer, and (3)establish new criminal sanctions to restrict uses of AI that cause serious harm.
advisory
Lead and facilitate the development of standards and conformity assessment solutions in Canada, including for AI.
data_protection
Oversee compliance with federal privacy legislation (PIPEDA) in the private sector; provide guidance on privacy implications of AI.
advisory
Implement key programs of the Pan-Canadian Artificial Intelligence Strategy; administer investigator-led research for CAISI.
Federal Government reveals six pillars for national AI strategy in Spring Economic Update 2026
Apr 21, 2026 · news
Innovation, Science and Economic Development Canada launches Artificial Intelligence Sovereign Compute Infrastructure Program
Open source →Apr 16, 2026 · news
Canada 'very seriously' considering age restrictions for social media, AI chatbots
Open source →Apr 14, 2026 · news
Anthropic receives praise from Canada's AI Minister for Mythos approach
Open source →Apr 9, 2026 · news
Bank of Canada, major lenders meet on Anthropic AI cyber risk
Open source →Mar 16, 2026 · international_agreement
Canada hosts first-ever national summit on AI and culture, announces advisory council
Open source →Mar 13, 2026 · international_agreement
Canada and Norway issue joint statement on sovereign technology and AI
Open source →Mar 5, 2026 · law_amended
B.C. premier says OpenAI CEO Sam Altman will apologize to Tumbler Ridge, push for stronger regulations
Open source →Mar 5, 2026 · news
Canadian and Australian music rights organizations release statement on AI and copyright
Open source →Mar 5, 2026 · law_amended
Canada and Japan sign strategic pact on defence, energy and AI
Open source →Mar 4, 2026 · news
US, Japan, New Zealand, South Korea, Singapore, UK and Canada join Australia's guidance on supply chain risks and mitigations for AI
Open source →Mar 4, 2026 · news
Australia and Canada elevate partnership in critical minerals, defence, and AI
Open source →Feb 26, 2026 · news
Canada AI minister and OpenAI to discuss AI safety in response to school schooting
Open source →Feb 25, 2026 · news
Canada’s Defence Industrial Strategy to strengthen security, create prosperity, and reinforce strategic autonomy
Open source →Feb 19, 2026 · news
Canada’s AI minister hails ‘natural alliance’ with India ahead of Prime Minister Carney's visit
Open source →Feb 19, 2026 · news
Canada and India strengthen ties to advance new partnerships in AI and digital innovation
Open source →Feb 13, 2026 · international_agreement
Canada and Germany sign AI joint declaration and launch Sovereign Technology Alliance
Open source →Jan 14, 2026 · enforcement_action
Canada Privacy Commissioner expands investigation into X following reports of AI-generated sexualized deepfake images
Open source →Jan 12, 2026 · news
Bhutan, Canada partner to strengthen AI policy and governance
Open source →Jan 10, 2026 · news
Canada not considering a ban on X over deepfake controversy, AI minister says
Open source →Dec 31, 2025 · news
Spy watchdog reviewing Canadian security agencies’ use of AI
Open source →Dec 8, 2025 · international_agreement
Canada and the European Union enhance digital partnership focusing on AI cooperation
Open source →Dec 8, 2025 · news
International Network of AI Safety Institutes rebrand away from "safety" to focus on scientific measurements
Open source →Dec 8, 2025 · news
Canada and UK strengthen ties on quantum and digital infrastructure
Open source →Dec 7, 2025 · news
Canada and EU deepen collaboration on AI and digital credentials and trust services
Open source →Dec 7, 2025 · news
Canada and Germany deepen collaboration on advanced technologies
Open source →Dec 2, 2025 · news
Canada releases world’s first standard for accessible, inclusive AI design
Open source →Nov 27, 2025 · news
Canada launches first register of AI uses in federal government
Open source →Nov 24, 2025 · law_amended
Ottawa urged to regulate AI chatbots in forthcoming online safety bill
Open source →Nov 21, 2025 · news
Australia-Canada-India Technology and Innovation (ACITI) Partnership signed, covering AI
Open source →Nov 20, 2025 · law_amended
UAE to invest up to $50 billion in Canada in industries such as AI, energy
Open source →Nov 4, 2025 · news
Canada federal budget dedicates over $1B to boost Canadian AI and quantum computing
Open source →Sep 25, 2025 · news
Canada launches AI Task Force with 30-day sprint for national strategy
Open source →Sep 16, 2025 · guideline_issued
Data protection authorities adopted joint statement on building trustworthy data governance frameworks to encourage development of innovative and privacy-protecting AI
Open source →Aug 3, 2025 · news
2025 APEC Digital and AI Ministerial Statement
Open source →Jul 18, 2025 · guideline_issued
Canada AI minister weighs plans on AI and copyright
Open source →Jul 16, 2025 · news
International network of AI safety institutes align approaches on agentic AI evaluations
Open source →Jun 22, 2025 · law_amended
Canada government won’t reintroduce old AI law but will address copyright issues
Open source →Jun 14, 2025 · international_agreement
UK and Canada issue joint statement enhancing collaboration, covering AI
Open source →Jun 9, 2025 · law_amended
New AI minister says Canada won’t ‘over-index’ on AI regulation
Open source →Jun 8, 2025 · news
Canada AI Safety institute announces research projects as global focus shifts to AI adoption
Open source →May 12, 2025 · news
Canada gets its first ever Federal Minister dedicated to AI
Open source →May 7, 2025 · news
ASEAN, Canada reaffirm commitment to advancing strategic partnership, covering AI
Open source →Mar 6, 2025 · news
Canada government announces refreshed advisory council, new advisory group and new guide on AI
Open source →Mar 3, 2025 · news
Canada launches strategy for the federal public service
Open source →Feb 10, 2025 · law_amended
Statement on Inclusive and Sustainable Artificial Intelligence for People and the Planet signed at AI Action Summit in Paris
Open source →Feb 10, 2025 · news
Canada and Japan sign Council of Europe’s global treaty on AI
Open source →Feb 10, 2025 · news
Canada government publishes findings from Consultation on Copyright in the Age of Generative AI
Open source →Feb 5, 2025 · news
Canada federal government bans DeepSeek
Open source →Jan 26, 2025 · news
Competition Bureau issues report on AI and competition
Open source →Jan 16, 2025 · law_amended
Canada's AI and Data Act terminates amid prorogation of Parliament
Open source →Jan 15, 2025 · news
Global Coalition on Telecommunications adopt principles on AI adoption in the telecommunications industry
Open source →Nov 11, 2024 · news
Canada launches its AI safety institute
Open source →Oct 27, 2024 · news
Global data protection authorities issue statement on data scraping, covering AI
Open source →Oct 10, 2024 · law_amended
OPC publishes statement calling for privacy law reform, covering AI
Open source →Sep 4, 2024 · news
UK, US and Canadian nuclear regulators release principles for deploying AI in the nuclear sector
Open source →Jun 25, 2024 · news
ISED opens consultation into AI Compute
Open source →May 26, 2024 · news
Eight organizations to join Canada's voluntary AI code of conduct
Open source →May 20, 2024 · international_agreement
World leaders sign up to Seoul Declaration and Statement of Intent toward International Cooperation on AI Safety Science
Open source →May 19, 2024 · news
UK-Canada sign partnership on AI safety
Open source →Apr 6, 2024 · law_amended
Canada announces budget of $2.4 billion for AI
Open source →Mar 19, 2024 · news
Competition Bureau seeks feedback on AI and competition
Open source →Dec 6, 2023 · news
Canadian privacy regulators launch principles for responsible development and use of generative AI
Open source →Nov 27, 2023 · law_amended
Proposed amendments to the Artificial Intelligence and Data Act (AIDA)
Open source →Oct 11, 2023 · news
Government of Canada launches consultation on the implications of generative artificial intelligence for copyright
Open source →Aug 15, 2023 · law_amended
Canadian government seeks input on voluntary code of practice for generative AI
Open source →Apr 3, 2023 · enforcement_action
Privacy investigation into OpenAI
Open source →