TL;DR: Canada's AIDA (Part 3 of Bill C-27) was never enacted. Parliament prorogued in January 2025 before the bill passed. There is no federal AI-specific law in Canada as of mid-2026. AI in Canada is currently governed by PIPEDA for data protection, Quebec Law 25 for automated decision transparency in Quebec, and voluntary federal frameworks.
Canada was on track to be among the first countries with dedicated federal AI legislation. Then it wasn't. If you have been tracking AIDA (the Artificial Intelligence and Data Act) and wondering what happened to it, this article gives you the complete picture: what AIDA was, why it died, what governs AI in Canada right now, and what compliance actually looks like for companies operating in Canada in 2026.
What AIDA was and why it never became law
AIDA was Part 3 of Bill C-27, the Digital Charter Implementation Act, 2022. The bill also contained Part 1 (the Consumer Privacy Protection Act, or CPPA, a PIPEDA replacement) and Part 2 (the Personal Information and Data Protection Tribunal Act). All three parts were bundled into a single omnibus bill introduced in June 2022.
AIDA targeted what it called "high-impact AI systems": systems that have a significant effect on individuals in areas like health, safety, employment, or financial services. Under AIDA, organizations responsible for high-impact AI systems would have been required to:
- Identify and assess the risks of harm or biased output that the system presents
- Implement mitigation measures proportionate to those risks
- Monitor the system's operation on an ongoing basis
- Maintain records of risk assessments and mitigation measures
- Publish plain-language descriptions of the system's purposes and decision-making processes
- Notify the AI and Data Commissioner of serious risks or harms
The penalty structure was significant: civil penalties up to the greater of 3 percent of global annual revenue or $10 million CAD for contraventions of the administrative requirements. Criminal penalties for intentional violations with knowledge of harm reached up to 5 percent of global revenue or $25 million CAD.
AIDA also proposed creating a new AI and Data Commissioner with powers to audit, investigate, and issue binding orders.
Why it died: Prime Minister Justin Trudeau prorogued Parliament on January 6, 2025, in response to political pressure within the Liberal party following cabinet resignations. Prorogation ends all legislative business not yet passed. AIDA had cleared second reading in the House of Commons but had not finished committee review or third reading. It died completely. The subsequent federal election in April 2025 returned a Liberal minority government, but AIDA was not reintroduced as of mid-2026.
What governs AI in Canada right now
Without AIDA, there is no single federal AI law in Canada. Instead, AI is governed by a combination of existing privacy law, provincial legislation (particularly in Quebec), human rights law, and sector-specific regulation.
PIPEDA and the CPPA
The Personal Information Protection and Electronic Documents Act (PIPEDA) is Canada's federal private-sector privacy law. It applies to organizations that collect, use, or disclose personal information in the course of commercial activity. AI systems that process personal information about individuals are subject to PIPEDA's requirements: consent, purpose limitation, accuracy, accountability, and individual access rights.
The Consumer Privacy Protection Act (CPPA), which was Part 1 of Bill C-27, shares AIDA's fate: it also died with prorogation. PIPEDA remains the governing federal privacy law. That said, PIPEDA's consent and accountability principles impose real obligations on AI systems. If your AI makes decisions using personal data without appropriate consent, uses data beyond its stated purpose, or cannot provide individuals with access to their information, you have a PIPEDA compliance problem today.
Quebec Law 25
Quebec's Law 25, also known as Law 64 or Bill 64 (formally "An Act to modernize legislative provisions as regards the protection of personal information"), is the most significant active AI-specific legal requirement in Canada. It went into effect in phases: September 2022, September 2023, and September 2023 for its final provisions.
Quebec Law 25 contains two provisions that directly affect AI systems:
Automated decision-making transparency (Section 12.1). When a person's personal information is used to make an automated decision about them that produces legal or significant effects, the organization must inform the person before the decision that a technology is being used, explain how it uses the information to reach the decision, and inform the person of their right to have a human review that decision. "Significant effects" is interpreted broadly to include employment decisions, financial decisions, and access to services.
Right to human review. A person subject to an automated decision has the right to request that a human review the decision. Organizations must have a mechanism to accommodate this request. There is no exemption for small organizations.
Territorial scope: Quebec Law 25 applies to any organization that collects personal information about Quebec residents, regardless of where the organization is based. A startup in California with Quebec customers must comply with these provisions for those customers.
Enforcement is real. The Commission d'acces a l'information du Quebec (CAI) has enforcement powers including administrative penalties up to 25 million CAD or 4 percent of worldwide turnover for the most serious violations.
Canadian Human Rights Act
The Canadian Human Rights Act prohibits discrimination in employment and in services provided by federally regulated entities. AI systems used in hiring, performance management, compensation, or customer service decisions can violate the Canadian Human Rights Act if they produce discriminatory outcomes based on protected grounds (race, sex, disability, age, and others), even if no discriminatory intent is present.
The Canadian Human Rights Commission has published guidance on AI and human rights that provides practical standards organizations should meet. This is not a passive risk. The Commission can investigate complaints and the Canadian Human Rights Tribunal can order remedies including monetary compensation and systemic changes.
Directive on Automated Decision-Making (federal government only)
Canada's Directive on Automated Decision-Making applies only to federal government institutions, not to private companies. It requires government departments to assess the impact level of any automated decision system they use, apply safeguards proportionate to that impact level, and provide individuals with notice and an opportunity for human review.
Though not directly applicable to private-sector companies, the Directive signals the federal government's standards and provides a useful benchmark for AI governance programs. Its impact assessment methodology (Levels 1 through 4 based on harm severity) is practical and can be adapted for private-sector use.
Canada's Digital Charter and voluntary AI frameworks
Canada published its Digital Charter in 2019 and has maintained a voluntary AI framework, the Responsible Use of Artificial Intelligence Framework for the Government of Canada, that applies to government institutions. These do not impose legal obligations on private-sector companies but indicate the government's expectations.
What this means for companies operating in Canada
The absence of AIDA does not mean the absence of risk. Here is what companies actually need to do in 2026.
If you process personal data of Canadians: PIPEDA applies. Your AI systems must handle that data with consent, use it only for stated purposes, allow individual access, and implement appropriate security safeguards. This is not new, but AI-specific data processing often creates PIPEDA compliance gaps that teams overlook.
If you have Quebec-based customers or employees: Quebec Law 25 applies to your automated decisions. You need: a mechanism for informing individuals that an automated decision is being made using their data, a plain-language explanation of how the system reaches decisions, and a mechanism for human review upon request. Most teams with Quebec exposure do not have these mechanisms in place.
If you use AI in employment decisions: Canadian Human Rights Act obligations apply. You need to be able to demonstrate that your AI hiring, performance management, or compensation tools do not produce discriminatory outcomes based on protected grounds. Document what each tool does, what data it uses, and how you monitor for bias.
If you also have EU customers: EU AI Act obligations apply entirely independently of Canadian law. These are covered in detail in the EU AI Act compliance guide for small teams. Canadian companies with EU nexus need to address both frameworks.
What AIDA would have added
For context on the gap, here is what your obligations would have looked like had AIDA passed:
| Obligation | Status under current law | What AIDA would have added |
|---|---|---|
| Risk assessment for high-impact AI | Not federally required | Mandatory, documented, maintained |
| Mitigation measures | Not federally required | Mandatory, proportionate to risk |
| Ongoing monitoring | Not federally required | Mandatory |
| Public transparency reports | Not federally required | Mandatory |
| AI and Data Commissioner oversight | No equivalent | New federal enforcement body |
| Civil penalties for non-compliance | None specific to AI | Up to 3% global revenue |
The gap is meaningful. Companies that assumed AIDA was coming and waited to build governance programs have saved themselves compliance spend, but they have also avoided building governance structures that good practice recommends regardless of legal obligation.
Practical next steps for Canada-based teams
Given the current state, here is the order of operations:
-
Audit your PIPEDA compliance for AI data processing. Confirm consent basis, purpose limitation, and access mechanisms for all personal data flowing through AI systems.
-
Identify Quebec exposure. If you have Quebec-based customers, employees, or users, map every automated decision that uses their personal information. Implement Law 25's notice, explanation, and human review mechanisms for each.
-
Review employment AI for Canadian Human Rights Act compliance. Document what AI tools you use in hiring and HR, what data they use, and how you monitor for discriminatory outcomes.
-
Build toward voluntary best practice. The NIST AI RMF or ISO 42001 frameworks (covered in the ISO 42001 vs NIST AI RMF for small teams comparison) give you a governance structure that will satisfy whatever federal AI law Canada eventually passes.
-
Track legislative developments. A new federal privacy and AI bill is possible under the current government, but no firm timeline exists as of mid-2026. The AI regulation deadline calendar 2026 tracks active regulatory developments across jurisdictions.
The absence of AIDA is not a license to ignore AI governance. It is an invitation to build governance on existing legal foundations and voluntary best practice before a future federal law makes some of those practices mandatory.
Related reading
- EU AI Act compliance guide for small teams
- AI data privacy for small teams GDPR CCPA
- AI regulation deadline calendar 2026
- AI governance guide for small teams
- UK AI regulation 2026 post-Brexit
- ISO 42001 vs NIST AI RMF for small teams
- SEC AI Governance for Investment Advisers: 2026 Examination Priorities
- State Chatbot Disclosure Laws 2026: The Compliance Checklist Every Saa
- California SB 1047: what happened, what passed instead, and what appli
- Tennessee ELVIS Act: AI voice and likeness compliance guide 2026
- AI employee monitoring laws 2026: what employers can and cannot do
- Utah AI Policy Act compliance 2026: what businesses need to know
- Maryland Surveillance Pricing Law 2026: Grocery Stores Face New Person
