Treadstone Associates
Guide

How to track Canadian AI guidance

Canada has no dedicated AI regulator and no AI statute in force, which makes “just check the regulator’s website” useless advice. This guide is the actual list of where the real guidance comes from, in the order worth checking it.

Treadstone Associates · Updated 2026

Key takeaways

  • • No single Canadian body owns AI guidance. It comes from privacy regulators, a federal department, and a stalled bill — each covering a different slice.
  • • Bill C-27, which would have enacted the Artificial Intelligence and Data Act, has not become law; its own record on LEGISinfo must be quoted with its date, never summarised as “in force” or “not in force.”
  • • ISED’s Voluntary Code of Conduct is the closest thing to a national AI standard today, and it binds only the organisations that sign it.
  • • The honest way to track this is a short list of specific pages, checked periodically — not a general habit of “staying current on AI news.”

STEP 01 OF 11

Start from the fact that there is no single source

Unlike privacy law, which sits mostly in one statute per jurisdiction, Canadian AI guidance is scattered across a federal department, the joint federal-provincial-territorial privacy regulators, a stalled bill, and a voluntary industry code. There is no AI equivalent of checking one regulator’s bulletin page.

Accept this before building a tracking habit, because it changes what “tracking Canadian AI guidance” actually means: watching four or five specific pages, not subscribing to one feed.

STEP 02 OF 11

Check where the bill actually stands, and quote it exactly

Bill C-27 would have enacted the Artificial Intelligence and Data Act, alongside consumer-privacy legislation. Its own LEGISinfo record, read directly, is unambiguous about how far it got: shown against the 44th Parliament, 1st session (22 November 2021 to 6 January 2025) — a session the page itself marks “The information below relates to a prior session” — with current status “At consideration in committee in the House of Commons” and latest activity “Second reading and referral to committee on Monday, April 24, 2023” — see LEGISinfo’s record for Bill C-27.

Never write that AIDA is, or is not, in force — the honest answer is that this specific bill did not complete the legislative process in that Parliamentary session, and nothing has replaced it yet. Quote the page and the date you checked it; do not paraphrase into a status the page does not state.

STEP 03 OF 11

Bookmark ISED’s Voluntary Code page, and read it as a signatory list, not a law

Innovation, Science and Economic Development Canada’s Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems, published September 2023, is the most concrete Canadian federal document on point — six committed outcomes (Accountability, Safety, Fairness and Equity, Transparency, Human Oversight and Monitoring, Validity and Robustness) with a detailed measures table split by developer, manager, and whether the system is public-facing. Read it at ised-isde.canada.ca.

The page states plainly that “this code does not in any way change existing legal obligations that organizations may have”, and that it binds only its signatories — a list of 46 organisations named on the page itself. Check the signatory list periodically rather than assuming it, since the page notes it may change.

STEP 04 OF 11

Check ISED’s consultation page for what comes after the voluntary code

ISED ran a separate consultation on developing a Canadian code of practice for generative AI, now recorded as “Current status: Closed”. Its own framing of the purpose is worth noting: the resulting code “will provide voluntary guidance to companies developing and using AI systems, and it will help them to prepare their processes and products before formal regulation takes effect” — see the consultation page.

That sentence is the government’s own acknowledgment that formal regulation has not yet taken effect — useful as a dated data point, not as a prediction of when it will.

STEP 05 OF 11

Check the OPC’s generative-AI principles page, and note it is joint

The Office of the Privacy Commissioner of Canada, together with its provincial and territorial counterparts, published Principles for responsible, trustworthy and privacy-protective generative AI, dated 2025-05-06, at priv.gc.ca. It sets out nine principles — Legal Authority and Consent, Appropriate Purposes, Necessity and proportionality, Openness, Accountability, Individual Access, Limiting Collection Use and Disclosure, Accuracy, and Safeguards.

This is a joint document, not a solely federal one — it represents where Canada’s privacy regulators, plural, currently stand on generative AI specifically. It is the single most detailed Canadian regulatory statement on the topic, and it is worth re-reading in full periodically rather than relying on a summary of it, including this one.

STEP 06 OF 11

Check the specific provinces with their own privacy-AI activity

Québec’s privacy regulator, the CAI, has published guidance directly under Law 25 — including a specific automated-decision notice-and-review rule and dedicated hiring guidance, both at cai.gouv.qc.ca. Alberta’s OIPC maintains a standing AI resource page at oipc.ab.ca/resources/ai, including a Privacy Impact Assessment template for AI and comments to the provincial government on AI governance. Ontario’s IPC also publishes AI-tagged material on its Commissioner’s Blog at ipc.on.ca.

None of these substitute for the joint federal-provincial-territorial page in Step 5, but each carries provincial detail the joint page does not, especially Québec’s, which has the most concrete hard rule in the country.

STEP 07 OF 11

Watch the Canadian Artificial Intelligence Safety Institute, for the direction of travel

CAISI, established as part of the government’s AI plan and led by ISED with the National Research Council of Canada and CIFAR, exists “to advance the science of AI safety, in collaboration with international partners”, naming risks including “synthetic content, including impersonation and fraud” — see its page on ised-isde.canada.ca.

CAISI is not a regulator and does not issue binding rules. It is worth watching as an indicator of where federal attention is heading, particularly on the safety and synthetic-content questions this hub covers elsewhere.

STEP 08 OF 11

Know the difference between a US source and a Canadian one before you cite either

A meaningful share of what circulates as “AI regulation news” is American or European and does not apply here. The clean test: does the page belong to a Canadian federal department, a Canadian court, or a Canadian privacy regulator? If not, it may still be useful — the U.S. NIST AI Risk Management Framework is cited by name in the OPC’s own principles, footnote 16 — but label it as non-Canadian in anything you write, every time.

This habit alone prevents the single most common error in this space: writing that “Canada requires” something that is actually a US or EU rule, or a voluntary code with no binding force here.

STEP 09 OF 11

Build a short, specific watch list instead of a general news habit

Five pages cover most of what actually changes: the LEGISinfo record for C-27 (or its successor bill, if one is introduced), ISED’s Voluntary Code page, the joint OPC generative-AI principles page, Québec’s CAI Law 25 page, and whichever provincial privacy regulator applies to where you operate. Check these on a set schedule — quarterly is reasonable given how infrequently any of them actually change — rather than trying to follow AI policy news as a continuous stream.

A specific list like this is checkable in under half an hour and catches the changes that actually matter to a Canadian business, which general AI news coverage frequently does not distinguish from US and EU developments.

STEP 10 OF 11

When something changes, verify it before repeating it

A regulator page changing is a real event worth noting; a media summary of that change is a second, separate thing that can drift from what the page actually says. When you notice a change on your watch list, read the primary page yourself and note the date you read it, rather than repeating a secondhand summary — the same discipline applies to using this guide itself six months from now.

This matters specifically because Canadian AI guidance has moved before in ways secondhand summaries got wrong — a URL path changing, a page being retitled, a consultation closing without becoming law. Read the primary source, every time.

STEP 11 OF 11

Document what you checked and when, for your own record

If your business needs to show due diligence about AI regulatory awareness — to a customer, an insurer, or your own management — a simple log of which pages you checked and what they said on that date is more useful than a general assertion that you “monitor AI regulation.” This is also the raw material for what to document when a business uses AI, which covers the broader record-keeping question.

That documentation matters for a concrete legal reason, not only for prudence. Under PIPEDA, an individual may file a written complaint with the Privacy Commissioner against an organization for contravening the Act, and separately, if the Commissioner is satisfied there are reasonable grounds to investigate, “the Commissioner may initiate a complaint” without waiting for one to be filed. PIPEDA, s.11 A dated log of what was checked, and when, is what a business actually has to show if either happens.

A dated log costs almost nothing to keep and is the difference between a real answer and a vague one when someone eventually asks what your business actually does to stay current.

Common mistakes

Saying AIDA is, or is not, in force. Neither statement is accurate. Bill C-27 did not complete the legislative process in the session LEGISinfo records; quote the page and its date, as in Step 2, rather than summarising a status it does not state.

Treating the ISED Voluntary Code as a law. It binds only its signatories and says so on its own page. A business that has not signed it is not bound by it, whatever a summary elsewhere implies.

Citing a US or EU rule as if it were Canadian. The EU AI Act and various US state laws circulate widely in AI coverage and have no force in Canada. Label any non-Canadian source as such, every time, per Step 7.

Following general AI news instead of the specific pages. General coverage rarely distinguishes a genuine Canadian regulatory change from US or EU news, or from a think-piece with no regulatory weight at all. The five-page list in Step 8 is a better use of the same time.

The watch list, in one place

  • • LEGISinfo — Bill C-27’s record (or its successor, if introduced).
  • • ISED — the Voluntary Code of Conduct page and its signatory list.
  • • OPC — the joint generative-AI principles page.
  • • Québec’s CAI — Law 25’s automated-decision and AI-hiring guidance.
  • • Your own province’s privacy regulator — for anything specific to where you operate.

Five pages, checked on a set schedule, cover the material majority of what actually changes in Canadian AI guidance — a far smaller commitment than following AI policy news as a continuous stream, and considerably more reliable.

Frequently asked

Is there a single Canadian AI law I should be watching for?

Not currently. Bill C-27 was the closest candidate and did not complete the legislative process; if a successor bill is introduced, its LEGISinfo record is the place to check, quoted with its date, not summarised as in force.

Does the ISED Voluntary Code apply to my business automatically?

No. It applies only to organisations that have signed it, and the signatory list is published on the page itself. Check the current list rather than assuming your business, or a vendor you use, is or is not on it.

Is Québec’s Law 25 the strictest Canadian AI-adjacent rule?

Among what this guide covers, it is the only one with a genuinely hard requirement on point — the automated-decision notice-and-review duty. It applies to organisations subject to Québec’s private-sector privacy law, not nationally, so confirm whether it applies to your business specifically.

Tracking the rules is one input into a due-diligence process, not the whole of it.

What actually needs checking on a specific deal or vendor goes further than a watch list.