AI Regulation in Canada
Canada does not yet have a standalone, comprehensive AI law in force. The federal government's Directive on Automated Decision-Making applies to automated systems used within the federal government itself, requiring algorithmic impact assessments scaled to risk level before deployment, but it does not extend to private-sector AI use. Provincial privacy statutes — including Quebec's Law 25, with its specific provisions on automated decision-making and profiling — currently provide the most concrete enforceable obligations for AI systems processing personal data.
Federal courts have begun applying existing procedural rules to AI-specific harms rather than waiting for new legislation. Sanctions against litigants for AI-fabricated case citations signal that courts will treat AI-generated misinformation in legal and regulatory filings as a conduct issue under current rules, not a gap requiring new statutory authority. This pattern — enforcement through existing frameworks ahead of dedicated AI legislation — mirrors the approach taken by regulators in the US and UK.
Canada's national AI strategy has shifted toward emphasizing workforce literacy and sovereign AI infrastructure, reflecting a policy priority on domestic capability and compute independence alongside governance. For compliance teams, this means the near-term operative obligations remain provincial privacy law and sector-specific guidance, while a federal cross-sector AI law remains a developing rather than settled area to monitor.
Key themes
- 1.Directive on Automated Decision-Making — federal government AI use only
- 2.Quebec Law 25 — provincial privacy obligations for automated decision-making
- 3.Courts applying existing procedural rules to AI-fabricated content
- 4.National strategy emphasis on workforce literacy and sovereign AI infrastructure
Regulatory frameworks and guidance(0)
No policies found for this jurisdiction.
