Canada does not currently have a dedicated federal AI statute in force. The Artificial Intelligence and Data Act (AIDA), which would have introduced risk-based obligations for "high-impact" AI systems, was proposed as part of a broader bill that did not pass before the parliamentary session in which it was introduced ended — and as of this writing, no direct federal successor has been enacted. Agent operators with Canadian exposure need to govern today through the patchwork of privacy, human-rights, and sector law that already applies, while watching for renewed federal activity.
This is a genuinely fluid situation, and it is one where getting the status wrong is easy: it is tempting to either assume AIDA's obligations already apply (they do not, because the instrument that would have created them did not become law) or to assume Canada has no AI-specific expectations at all (also wrong, because a voluntary code and several existing statutes already reach agentic AI). Treat both assumptions as traps.
What actually governs agent deployments in Canada today
Federal privacy law. The Personal Information Protection and Electronic Documents Act (PIPEDA) applies to any commercial activity involving personal information, including the personal data an agent processes, retrieves, or generates. Automated decision-making that affects individuals draws direct scrutiny from the Office of the Privacy Commissioner, independent of any AI-specific statute.
Provincial privacy law. Quebec's private-sector privacy law (commonly referred to by its earlier name, Bill 64, now part of Quebec's Act respecting the protection of personal information in the private sector) already imposes transparency and human-review obligations on automated decision systems that produce decisions based exclusively on automated processing — a category that squarely includes many agent workflows. Quebec's requirements are, in several respects, more specific than the federal baseline, and they apply regardless of where your company is headquartered if you process the personal information of Quebec residents.
Human rights law. Federal and provincial human-rights codes prohibit discriminatory outcomes regardless of whether the discriminating actor is a person or an automated system. An agent that produces disparate outcomes in employment, housing, or credit access is exposed under this law with or without an AI-specific statute.
Sector regulation. Federally regulated financial institutions face guidance from the Office of the Superintendent of Financial Institutions on the use of AI and model risk more broadly, building on longstanding model-risk-management expectations. Other sectors — health, telecommunications — have their own regulators layering AI-relevant expectations onto existing frameworks.
The voluntary code of conduct. A federal voluntary code of conduct for advanced generative AI systems set out commitments around safety testing before deployment, monitoring for misuse, transparency about AI-generated content, human oversight of consequential decisions, and accountability for outcomes. It binds only signatories and carries no statutory penalty — but it is a clear signal of what Canadian policymakers consider baseline good practice, and it maps closely to what a future statute would likely require.
Direction of travel
The federal government has not abandoned the goal of AI-specific legislation; the bill that would have introduced AIDA simply did not complete the legislative process in time. Renewed legislative activity — a reintroduced bill, a narrower sectoral statute, or amendments folded into privacy-law reform — is plausible at any point, and could arrive with materially different obligations than the original proposal. Agent operators should not build a compliance program around AIDA's specific proposed mechanics (a "high-impact system" classification tied to enumerated use cases, mandatory impact assessments, and a dedicated AI and data commissioner). Build instead around the durable pattern that recurs across every serious AI governance proposal, including Canada's: risk classification, human oversight, transparency, record-keeping, and accountability.
The six obligation categories to prepare for
| Obligation | Canadian legal hook today | Likely to persist in any future statute |
|---|---|---|
| Transparency | PIPEDA meaningful-consent principles; Quebec automated-decision disclosure | Yes |
| Human oversight | Quebec's right to have an automated decision reviewed by a person | Yes |
| Risk/impact classification | Not yet codified federally; implicit in human-rights exposure | Yes — this was AIDA's central mechanism |
| Record-keeping | PIPEDA accountability principle | Yes |
| Incident reporting | PIPEDA breach-of-security-safeguards reporting to the Privacy Commissioner | Yes |
| Data localization | No general federal requirement; sector-specific rules exist for some regulated data | Uncertain — depends on future statute's scope |
Control mapping: what you need to be able to produce
Agent inventory with jurisdiction tagging. Record which Canadian provinces' residents each agent's decisions touch, since Quebec's obligations are meaningfully more specific than the federal baseline. A single national inventory that does not distinguish Quebec exposure will understate your actual obligations. See building an AI agent inventory for a structure that scales to multi-jurisdiction tagging.
Per-decision audit record. For any agent decision based exclusively on automated processing that affects a Quebec resident, you need a retrievable record sufficient to support the individual's right to have the decision explained and, on request, reviewed by a person. This is not optional guidance — it is closer to the strictest binding obligation currently in force anywhere in Canada.
Human-review evidence. Where a person reviews or can request review of an automated decision, keep evidence that the review was substantive: what the reviewer saw, what they considered, and what they decided. A logged override capability that nobody has ever exercised is a weak defence.
Consent and purpose documentation. PIPEDA's meaningful-consent requirements mean you need a record of what personal information an agent uses, for what stated purpose, and that affected individuals were told in language they could reasonably understand — a standard that generic terms-of-service language rarely satisfies for agentic processing.
Breach and incident timeline. PIPEDA requires reporting breaches of security safeguards that create a real risk of significant harm, with records of every such breach kept regardless of whether it met the reporting threshold. Build the incident-timeline capability — detection time, assessment, notification, remediation — before you need it under time pressure; see an AI incident readiness checklist.
Bias and fairness testing evidence. Because human-rights exposure applies regardless of AI-specific statute status, keep evidence that consequential agent decisions were tested for disparate outcomes across protected characteristics, even though no Canadian statute currently mandates the specific test.
What good looks like
- Every agent is inventoried with the Canadian jurisdictions — federal and provincial — whose residents its decisions touch.
- Quebec-facing agents that make automated decisions produce an explanation and support a human-review request by default.
- Consent language for agent-processed personal information is specific enough to satisfy PIPEDA's meaningful-consent standard, not boilerplate.
- A breach-notification path exists that can assess "real risk of significant harm" and report to the Privacy Commissioner within a reasonable window.
- Fairness testing evidence exists for consequential decisions, independent of whether a specific statute requires it yet.
- The compliance program is built around the durable obligation categories above, not around AIDA's specific lapsed mechanics — so it survives whatever legislative form comes next.
Common questions
Does the lapse of AIDA mean Canada has no AI regulation at all?
No. It means Canada has no dedicated, comprehensive federal AI statute in force. Existing federal and provincial privacy law, human-rights law, and sector regulation already reach agent decisions, and Quebec's private-sector privacy law in particular already imposes automated-decision obligations that are, in places, more specific than what AIDA would have required. Treat "no AI Act" and "no obligations" as two separate questions with two separate answers.
Should we still build the AIDA-style "high-impact system" classification even though the bill lapsed?
It is a reasonable investment. The classification concept — identifying which AI systems have a significant enough effect on individuals to warrant heavier obligations — recurs across nearly every serious AI governance proposal globally, including AIDA's successor prospects. Building it now against the pattern, rather than against AIDA's specific lapsed text, means the work is not wasted if a differently-shaped bill eventually replaces it.
Which Canadian regulator is most likely to act first on agentic AI?
The Office of the Privacy Commissioner, through PIPEDA enforcement, and Quebec's privacy regulator are the most active today, since both have existing statutory hooks into automated decision-making. Federally regulated financial institutions should also expect OSFI to continue extending model-risk expectations to AI-driven decisions ahead of any horizontal AI statute.
This is not legal advice; confirm the current status of Canadian federal and provincial AI-related legislation with counsel before relying on it, since this is an area that can change without much advance notice.
Canada's near-term risk for agent operators is complacency, not overreach: the absence of a dedicated federal AI statute does not mean the absence of enforceable obligations. Teams that have already mapped controls to the EU AI Act or to US state AI laws should reuse that control mapping for Canada's privacy- and human-rights-driven baseline rather than treating Canada as unregulated territory.