Canada has no AI-specific division of powers, because it never needed one. An AI system that touches personal information, a hiring decision and a court filing can land in front of a federal regulator, a provincial one, and a judge who answers to neither — on the same file, in the same week.
Key takeaways
Ask “which government regulates AI in Canada” and the honest answer is that the question is built on a false premise. Canada does not have an AI regulator, federal or provincial. What it has is a set of subject-matter areas — privacy, employment, the administration of justice, intellectual property — each already divided between Ottawa and the provinces, decades before anyone was training a model. An AI system does not create a new jurisdictional question. It just walks into the existing one.
The Personal Information Protection and Electronic Documents Act is a federal statute, and its own operative language explains why it reaches almost every private business: an organization may collect, use or disclose personal information only for purposes “that a reasonable person would consider are appropriate in the circumstances” (PIPEDA, s.5(3)), and that test does not carve out an exception for personal information run through an AI tool. But PIPEDA is not the only privacy law in the country. Québec has enacted its own private-sector personal information statute, amended by Loi 25, and the province’s privacy regulator — the Commission d’accès à l’information — administers a rule PIPEDA does not contain at all: where a decision about a person is based exclusively on automated processing of their personal information, the organization must inform them, no later than when it tells them the decision, and must let them make representations to a staff member able to review it (CAI, Loi 25 changes). Alberta and British Columbia each have their own privacy regulator too — the Office of the Information and Privacy Commissioner of Alberta publishes its own AI resource index, and BC’s OIPC is a separate office again. A business operating in all four provinces is not answering to one privacy regime with regional branches. It is answering to several.
Labour and employment law in Canada sits almost entirely with the provinces, and AI-in-hiring rules show exactly what that means in practice: two provinces that both decided to regulate the same problem wrote two different answers. Ontario’s Employment Standards Act now requires a publicly advertised job posting to include “a statement disclosing the employer’s use, if any, of artificial intelligence to screen, assess or select applicants for the position”, for employers with 25 or more employees, effective for postings from January 1, 2026 (ontario.ca, ESA guide). That is a disclosure duty tied to the hiring posting itself. Québec’s rule lives in privacy law, not employment law, and runs on a different trigger and a different timeline: AI use in a hiring process “devrait être communiqué aux candidats dès le début du processus” — disclosed from the very start of the process, not just on the posting — and a privacy-impact assessment is required before the system is deployed at all (CAI, hiring guidance). An employer hiring in both provinces is not complying with “the Canadian AI-hiring rule.” There isn’t one. There are two, and they do not describe the same duty.
The judiciary makes the split unusually visible, because courts publish their own rules and every court answers only for itself. The Federal Court, which hears federal-law matters, issued its own notice on AI-assisted filings and its own interim principles for the Court’s own use of AI. Alberta’s three courts — the Court of Appeal, the Court of King’s Bench and the Alberta Court of Justice — issued one joint tri-court notice, binding only in Alberta. Ontario’s Superior Court of Justice wrote its own section on AI into its Consolidated Civil Provincial Practice Direction, binding only there. None of the three answers to the others, and none of them is a national rule — a filer moving a file from an Alberta court to the Federal Court is moving between two different sets of expectations, not two applications of one.
Intellectual property is the tidiest line in this picture, because it runs only one way. Copyright is exclusively federal — the Copyright Act is a single national statute, and there is no provincial copyright regime sitting beside it the way there is a provincial privacy statute in Québec. Its fair-dealing provision, which is the operative test for whether training an AI system on someone else’s content infringes copyright, is a single closed list: dealing “for the purpose of research, private study, education, parody or satire does not infringe copyright” (Copyright Act, s.29) — and that list does not vary by province, because there is nowhere for a provincial variation to live. For the mechanics of what that closed list does and does not cover, see how Canada regulates AI without an AI act.
Take a brokerage with offices in Toronto and Montréal that adopts one AI tool to screen resumés for both. In Ontario, the tool triggers the ESA disclosure duty the moment a job posting goes up publicly, but only if the brokerage employs 25 or more people counted the way the Act counts them — individuals, not full-time-equivalents, aggregated across all its Ontario locations. In Québec, the same tool triggers a different duty on a different clock: candidates must be told from the start of the process, not just on the posting, and a privacy-impact assessment has to exist before the tool is ever used on a live candidate. Neither government defers to the other, and satisfying Ontario’s posting-level disclosure does nothing to satisfy Québec’s start-of-process one. If a rejected candidate in either province later sues, the claim proceeds in that province’s own courts, under that court’s own rules about AI-assisted materials if any are filed — and if the brokerage’s vendor contract for the tool itself is disputed, that is a question of contract and copyright law, which puts it back in front of a court applying a federal statute alongside whichever provincial contract law governs the agreement. Three governments, three tests, one tool.
Related: which Canadian regulators touch AI, and how public bodies in Canada disclose AI use.
No. There is no comprehensive federal AI statute in force, and even if one existed it would not automatically displace provincial employment, privacy or court rules — those are separate heads of jurisdiction, not sub-categories of an AI law.
All of them, for the piece of the picture each one governs. PIPEDA (or Québec’s own statute where it applies) governs the privacy side everywhere the activity touches; each province’s own employment rules govern hiring in that province; and any court filing follows that court’s own notice, not a national one.
No. It is a Québec statute administered by a Québec regulator, and it binds organizations to the extent their activity falls under that statute — it has no force in Ontario, Alberta or federally.
A short conversation can map which jurisdiction governs which part of what you’re building.