Before Bill C-27 was ever introduced, the federal government had already bound itself to a rule for its own use of automated decision-making. It has been in force since 2019, and it works nothing like a proposed AI statute — it is an internal government directive with its own scope, its own clock, and its own assessment process.
Key takeaways
The Treasury Board’s Directive on Automated Decision-Making predates the entire AIDA debate by three years, and it is easy to lose track of that fact once federal AI policy conversations start assuming everything traces back to Bill C-27. This directive is a separate, already-binding instrument, and understanding what it actually requires of a department — not just that it exists — is the more useful thing to know.
The dates are specific and worth quoting exactly: “This directive takes effect on April 1, 2019, with compliance required by no later than April 1, 2020,” and it “applies to all automated decision systems developed or procured after April 1, 2020” (TBS, Directive on Automated Decision-Making, s.1.1–1.2). Systems that already existed before that date got a further grace period: those developed or procured before June 24, 2025 have until June 24, 2026 to comply with new or updated requirements, and Agents of Parliament get the same 2026 deadline. The whole directive is reviewed every two years, as determined by the Chief Information Officer of Canada — so this is not a document written once and forgotten, it is on a standing revision cycle.
Scope is narrower than “any government AI system.” The directive “applies to any automated decision system in production used to make an administrative decision or a related assessment about a client,” and explicitly “excludes automated decision systems used solely for research and experimentation purposes, and those operating in test environments” (TBS, s.5.1–5.2). Two things follow from that wording. First, a system still being tested or piloted is outside the directive entirely — the obligations only bite once it reaches production. Second, “a related assessment about a client” is broader than “a final decision” — a system that scores or triages an application, without itself issuing the final ruling, can still fall inside scope if that scoring is a related assessment feeding into the eventual decision about that person.
Before a department can put a qualifying system into production, someone senior has to be accountable for it — the directive names “the assistant deputy minister responsible for the program using the automated decision system, or any other senior official named by the deputy head” — and that person is responsible for “completing, approving and publishing the final results of an algorithmic impact assessment in an accessible format on the Open Government Portal prior to the production of any automated decision system” (TBS, s.6.1.1). That assessment is not a formality — its output is the system’s Impact Assessment Level, one of four, and that level determines everything else the directive requires. It also has to be reviewed and updated on a schedule, and whenever the system’s functionality or scope changes — a department cannot complete the assessment once and treat it as permanent while the system itself keeps evolving.
Appendix B sets the four Impact Assessment Levels against the reversibility and duration of the impact on a person’s rights, equality, dignity, privacy, autonomy, health, economic interests, and against the sensitivity of the underlying data. At Level I, impacts are “little to no, easily reversible, and brief”; by Level IV, they are “very high, irreversible and perpetual.” The mechanics of how that scale compares to other countries’ risk-sorting methods are covered separately in how AI systems get sorted by risk — what matters here is what the level unlocks inside this one directive: heavier transparency duties, more rigorous testing and monitoring expectations, and (per the directive’s own structure) escalating requirements under Appendix C as the level rises. A Level I system and a Level IV system are not held to the same bar, by design.
Two of those escalations are concrete enough to name directly. Appendix C ties formal sign-off itself to the level: an assistant deputy minister approves a Level I or II system, a deputy head must approve a Level III system, and only the Treasury Board itself can approve a Level IV system. (TBS, Directive on Automated Decision-Making, Appendix C) Peer review escalates the same way: a Level II or III system needs at least one qualified outside reviewer consulted and the review published, and a Level IV system needs at least two. The level a department’s own algorithmic impact assessment produces therefore decides who, inside government, has to personally sign off before the system can go into production at all.
The directive names three companion instruments a department is expected to use rather than reinvent: the Algorithmic Impact Assessment tool itself, a Guide on the Use of Generative AI for departments deploying generative systems specifically, and a Guide to Peer Review of Automated Decision Systems for having the work checked by someone else in government. None of the three is discretionary window-dressing — the impact assessment tool is literally what produces the level that everything else in the directive keys off of.
Say a department built an automated triage tool for a benefits program back in 2021, well inside the directive’s scope, but the requirements themselves have been updated since. Because the tool was developed before June 24, 2025, it is not immediately non-compliant the moment a new requirement is added — the directive gives it until June 24, 2026 to meet the updated version. That grace period is not indefinite, and it is not automatic exemption from the directive altogether; it is a fixed runway to bring an already-operating system into line with whatever changed. A brand-new system built today has no equivalent runway — it has to meet the current requirements from the moment it goes into production, because the transition clock only ever applied to systems that predated the update.
Related: how public bodies in Canada disclose AI use and is there an AI registry in Canada.
No. It applies to systems “in production,” and explicitly excludes systems used solely for research, experimentation, or operating in a test environment.
The department itself, through the Algorithmic Impact Assessment tool, under the accountability of the assistant deputy minister responsible for the program (or another senior official the deputy head names) — there is no independent external body assigning the level.
The directive applies to systems developed or procured after April 1, 2020, but existing systems from before June 24, 2025 were given until June 24, 2026 to meet new or updated requirements — so an older system is not automatically exempt forever.
A short conversation can walk through what an Impact Assessment Level would mean for your specific system.