AI governance is the internal structure an organization puts around an AI system — who is accountable for it, what gets checked before and after it is used, and how problems get caught and fixed — as distinct from any external law that might also apply to the same system.
The United States’ NIST AI Risk Management Framework (a US, not Canadian, source, though the closest thing to a working vocabulary Canadian sources point readers toward) organizes governance around four functions, and states the first of them plainly: “Govern 1.1: Legal and regulatory requirements involving AI are understood, managed, and documented”
Canada has two real, but limited, domestic instruments. Innovation, Science and Economic Development Canada’s Voluntary Code of Conduct asks signatories to commit to outcomes including that “organizations understand their role with regard to the systems they develop or manage, put in place appropriate risk management systems, and share information with other organizations as needed to avoid gaps” — but it binds only its signatories, and nothing in it is mandatory law.
The Treasury Board’s Directive on Automated Decision-Making is genuinely mandatory governance — but only for federal government departments using a system to make an administrative decision about a client, not for private Canadian businesses. No single Canadian law sets binding governance requirements across the private sector.
A mid-sized firm deploying an AI tool to triage customer complaints has no statute telling it exactly what governance to put in place. What it can borrow, honestly labelled as borrowed rather than required, is the shape of both Canadian instruments: a named person accountable for the tool (the Voluntary Code’s accountability outcome), and a documented check on what the tool does and why before it goes live (the structure of the Treasury Board’s pre-production algorithmic impact assessment, even though that specific requirement does not apply outside government).
Governance is therefore, for a private Canadian organization today, a design choice rather than a compliance checklist — which is exactly why naming who owns a decision, and what gets reviewed before and after it ships, matters more than which framework’s vocabulary is used to describe it.
See also: responsible AI, algorithmic impact assessment, how Canada regulates AI without an AI act.
Keeping a named person accountable for what an automated system decides, without slowing every decision down to a crawl, is an operating problem — ai-operations covers how that balance actually gets held day to day.