Treadstone Associates
Ask an Expert · 4 min read

Can AI make a decision with no human?

Nothing stops a business from letting an AI tool decide something without a person in the loop. Whether that decision holds up once someone objects to it is a different question.

Treadstone Associates · Updated 2026

Short answer

It depends on what's at stake for the person the decision is about. For routine, low-impact tasks, yes — nothing in federal law requires a human to sign off on every automated step. Once a decision has a real effect on an identifiable person, Canadian privacy regulators expect an effective way for that person to challenge it, and Quebec's law goes further: it requires notice and a right to have the decision reviewed by a staff member whenever it was made exclusively by automated processing.

The federal baseline: a challenge mechanism, not a ban

Canada’s privacy commissioners don’t prohibit automated decisions — they attach a condition to significant ones. Their generative-AI principles direct organisations using generative AI systems as follows: “Ensure that impacted individuals are provided with an effective challenge mechanism for any administrative or otherwise significant decision made about them… allowing them the opportunity to request human review and/or re-consideration of the decision” (OPC, generative-AI principles). Read plainly: the AI can make the first pass, but the person affected has to be able to get an actual human to look at it if they push back.

Quebec doesn't wait for a complaint

Quebec’s Law 25 is more prescriptive, and doesn’t leave the review to a complaint process. The province’s guidance on the automated-decision rule states: “Les organisations doivent notamment informer la personne concernée lorsqu’elle fait l’objet d’une décision fondée exclusivement sur un traitement automatisé de ses renseignements personnels, et ce, au plus tard au moment où elles l’informent de cette décision” (organisations must notably inform the person concerned when they are the subject of a decision based exclusively on automated processing of their personal information, at the latest when they inform them of that decision), and “Les organisations doivent également donner l’occasion à la personne concernée de présenter ses observations à un membre de leur personnel en mesure de réviser cette décision” (organisations must also give that person the opportunity to make representations to a staff member able to review the decision) (CAI, Principaux changements apportés par la Loi 25). That is a concrete, standing entitlement in Quebec — not something a person has to litigate to get.

Ottawa runs its own, stricter version — but only on itself

The federal government binds its own departments to a more detailed regime, the Treasury Board’s Directive on Automated Decision-Making, which requires an algorithmic impact assessment before a system goes into production and both advance notice and a “meaningful explanation” after a decision is made (Treasury Board, Directive on Automated Decision-Making). That directive binds federal departments, not private businesses — see Ottawa’s own rules for automated decisions for what it actually requires and of whom. It’s a useful illustration of where Canadian policy is heading on this question, not a rule a private business has to meet today.

The practical line

A fully automated decision is on safer ground the more reversible and low-stakes it is — sorting an inquiry into a queue, flagging a file for review. The closer a decision gets to something with lasting effect on a specific person — credit, employment, service eligibility — the more a business should be able to show a real person can review and change it on request. What “a person reviewing it” actually has to mean in practice is covered at what “human in the loop” really means.

Where this goes next

Whether a target's automated decisions have a working human-review path is a real diligence question — a system with no way to challenge a decision carries a different risk profile than one that has it.