A business does not need an AI-specific law to be bound by one. Follow a single AI product through its Canadian life — the data that trains it, the content it produces, the claims made about it — and three ordinary statutes are already there at every step, none of them written with AI in mind.
Key takeaways
It is worth stating plainly what the machine-verified record shows: the Copyright Act’s full text contains zero occurrences of “artificial intelligence,” “computer-generated,” “machine learning” or “text and data” anywhere in its 353,984 characters. PIPEDA does not mention AI either, and neither does the Competition Act’s performance-claim provision. None of that means AI escapes them. Follow one hypothetical product through its life in Canada and each statute is waiting at the exact point where it is relevant.
Say the tool is trained partly on customer data a business already holds, and it processes new customer inputs once it is live. PIPEDA’s core obligation does not require the word “AI” to reach that: an organization “may collect, use or disclose personal information only for purposes that a reasonable person would consider are appropriate in the circumstances” (PIPEDA, s.5(3)). That test is about the purpose behind the collection and use, not the technology carrying it out — feeding personal data into a model is a use of that data like any other, subject to the same reasonableness test as any other use. If the business hands that data to an outside AI vendor to process, PIPEDA’s accountability principle follows the data there too: the organization “is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing,” and must use contractual or other means to keep a comparable level of protection while a processor holds it (PIPEDA, Schedule 1, cl. 4.1.3). A general-practice explainer of the underlying test, not written for AI, is at treadstonelaw.ca’s PIPEDA test.
Now the harder question: was training the model on someone else’s copyrighted material lawful in the first place? Canada has no answer built for that question specifically, because the Act was never amended to give one. What it has is s.29, fair dealing, in full: “Fair dealing for the purpose of research, private study, education, parody or satire does not infringe copyright” (Copyright Act, s.29). Read that list again: it does not say “or any other fair purpose,” it does not say “commercial use,” and it does not say “training a machine-learning model.” It is a closed list of five purposes, and training a commercial AI product does not obviously fall inside any of them. The United Kingdom has a specific computer-generated-works provision (CDPA s.9(3)) that assigns authorship to whoever arranged the computer’s creation of a work; Canada has nothing equivalent, and no text-and-data-mining exception either. A business relying on scraped or licensed-unclear content to train a model is relying on the ordinary fair-dealing test doing work it was never drafted to do — not on a purpose-built AI carve-out that does not exist.
Once the tool ships, how it is marketed is its own exposure. The Competition Act’s deceptive-marketing provisions make it reviewable conduct to make “a representation to the public in the form of a statement, warranty or guarantee of the performance, efficacy or length of life of a product that is not based on an adequate and proper test thereof, the proof of which lies on the person making the representation” (Competition Act, s.74.01(1)(b)). That single clause is the most consequential commercial-risk citation available for AI marketing anywhere in Canadian statute, because of where it puts the burden: not on a regulator to prove the claim is false, but on the business to prove it tested the claim before making it. Claim the tool is “99% accurate” or “cuts review time in half” without having run the test that would substantiate it, and the exposure exists whether or not anyone ever measured the actual number.
None of these statutes was rewritten for AI, and that is exactly the point — each was drafted broadly enough around a purpose (protecting personal information, protecting original expression, preventing unsubstantiated claims) that a new technology does not create a gap. The federal government’s own consultation on a code of practice frames the current period as one where voluntary guidance will “help them to prepare their processes and products before formal regulation takes effect” (ISED, code of practice consultation) — language that assumes formal AI-specific regulation is still ahead, not that none applies today. The three statutes above are why that assumption is true without contradiction: “no AI act yet” and “AI is unregulated” are two different claims, and only the first one is accurate.
Put the three steps together and the exposure does not arrive one clause at a time in practice — it arrives together, on launch day. A brokerage builds an AI intake tool trained partly on five years of its own client files and partly on industry articles scraped from the web, and markets it as “98% accurate at flagging incomplete files.” The client-file training data brings PIPEDA’s purpose test into play the moment those files are repurposed for a use the clients were not told about. The scraped articles bring the closed fair-dealing list into play, because “training a commercial product” is not research, private study, education, parody or satire, whatever else it might resemble. And the “98% accurate” figure brings s.74.01(1)(b) into play the instant it is published without a test behind it — not if a regulator later disputes it, but the moment the claim is made. None of the three statutes needed to know a large language model existed to reach all three problems at once.
Related: what AIDA proposed and where it stands and federal vs provincial AI rules in Canada.
No — the absence of a mention cuts the other way. Without a text-and-data-mining exception or a training-specific carve-out, an AI trainer relying on someone else’s content has to fit inside the existing closed fair-dealing list (research, private study, education, parody or satire), which was not written with commercial AI training in mind.
The accountability stays with the business whose customer data it is. PIPEDA’s Schedule 1 makes the organization responsible for personal information even after it is transferred to a third-party processor, so hiring an AI vendor does not transfer the compliance obligation along with the data.
The business making the claim. Section 74.01(1)(b) of the Competition Act puts the burden of proof on whoever makes a performance representation, not on a regulator or a customer to disprove it.
A short conversation can walk through where your specific product sits against PIPEDA, copyright and the Competition Act.