Treadstone Associates
Article · 9 min read

Which Canadian regulators touch AI?

There is no Canadian AI regulator to look up. There is a list of existing bodies, each with its own mandate, that have each turned their attention to AI within the boundaries of what they already oversee. Here is who they are and what each one actually does.

Treadstone Associates · Updated 2026

Key takeaways

  • • Privacy regulators — the federal OPC plus Alberta, BC, Ontario and Québec’s own commissioners — are the most active Canadian voices on AI, because so much of what AI does involves personal information.
  • • The Competition Bureau applies existing deceptive-marketing law to AI performance claims, and coordinates with the OPC and CRTC through the Canadian Digital Regulators Forum.
  • • ISED and the Treasury Board are federal policy bodies, not enforcement regulators in the usual sense — one runs a voluntary code, the other binds only the federal government’s own departments.
  • • Courts and law societies are a distinct category again — they regulate how AI is used inside legal proceedings and legal practice, not how AI products are built or sold.

Asking which regulator handles AI in Canada assumes a single answer exists. It does not. What follows is a working list of the bodies that have actually published something on AI, organized by what each one is actually for — because knowing which hat a regulator is wearing when it talks about AI is most of the value of knowing it exists at all.

Privacy regulators — the most active voices, because AI runs on data

The Office of the Privacy Commissioner of Canada is the federal body, and its joint Principles for responsible, trustworthy and privacy-protective generative AI — developed with its provincial and territorial counterparts — is one of the most detailed Canadian regulatory documents on AI in existence, covering everything from red-teaming to data scraping to an active statement that the OPC and its British Columbia, Québec and Alberta counterparts “have an open investigation relating to a particular generative AI service” (OPC, generative AI principles) — without naming which service. Alberta’s OIPC keeps a standing AI resource index covering privacy-impact-assessment guidance, AI-generated imagery, and comments on how Alberta should govern AI generally (OIPC Alberta, AI resources). British Columbia’s OIPC and Ontario’s IPC are separate offices again, each publishing its own material. Québec’s Commission d’accès à l’information administers the province’s own statute under Loi 25, which contains a rule the federal statute does not — a notice-and-review duty for decisions made exclusively by automated processing (CAI, Loi 25 changes). None of these five bodies has authority over AI as such — each has authority over personal information, and steps in wherever AI happens to be processing it.

The Competition Bureau — existing consumer-protection law, applied to AI claims

The Competition Bureau is not a privacy body and does not need to be one to reach AI — its jurisdiction is deceptive marketing and anti-competitive conduct, and an AI performance claim is just a claim. Its Artificial intelligence and competition discussion paper is explicit that it is a discussion document, not enforcement guidance, and states plainly that “there is still no universal definition for AI” even as it lays out how existing law reaches AI-driven conduct (Competition Bureau, AI and competition). The Bureau does not work alone here — the same paper states that the Bureau is “engaging with the Office of the Privacy Commissioner (OPC) and the Canadian Radio-Television and Telecommunications Commission (CRTC) through the Canadian Digital Regulators Forum,” which is the clearest evidence available that Canada’s digital regulators coordinate with each other on AI rather than working in separate silos. The CRTC itself is worth naming for that reason — it is a genuine participant in this coordination, even where its own website is not the easiest source to cite directly on any given day.

Federal policy bodies — guidance and internal rules, not market-facing enforcement

ISED and the Treasury Board sit in a different category from the regulators above — neither one investigates a company’s AI product the way a privacy commissioner or the Competition Bureau can. ISED administers the Voluntary Code of Conduct, a signature-based commitment with 46 named organizations and no legal force beyond what a signatory chose to take on — the code itself states it “does not in any way change existing legal obligations that organizations may have” (ISED, Voluntary Code). The Treasury Board’s Directive on Automated Decision-Making is binding, but only on federal government departments using automated systems to make administrative decisions — it has no jurisdiction over a private business at all, described fully in Ottawa’s own rules for automated decisions.

A third federal body belongs on this list for financial-sector AI specifically: the Office of the Superintendent of Financial Institutions. Its Guideline E-23 “sets out OSFI’s expectations for how federally regulated financial institutions should manage risks associated with the use of models,” and states plainly that this “includes traditional actuarial models as well as emerging technologies such as artificial intelligence (AI) and machine learning.” (OSFI, Guideline E-23 backgrounder) Unlike the voluntary code, this one is binding on the banks, insurers, and trust and loan companies OSFI already regulates: “Guideline E-23 will come into effect in May 2027, following an 18-month transition period.”

Courts and law societies — a category of their own

These bodies regulate AI use inside legal proceedings and legal practice specifically, not AI products in the market. The Federal Court, Alberta’s three courts jointly, and Ontario’s Superior Court of Justice have each issued their own separate notice or practice direction on AI-assisted court filings, none binding on the others — the jurisdictional pattern behind that split is covered in federal vs provincial AI rules in Canada. Law societies are a further, separate layer again: the Law Society of Alberta’s own survey counted “eleven Canadian courts, nine law societies, two professional liability insurers, one provincial government, the Canadian Judicial Council, Canadian Bar Association and the College of Patent Agents and Trademark Agents” as having each issued their own generative-AI guidance, and noted that “none have attempted to ban its use” (Law Society of Alberta, Gen AI rules of engagement). None of these bodies has any authority over an AI vendor’s product itself — their reach stops at how a lawyer or a court uses AI in the course of legal work.

The pattern across all of them

Every body on this list arrived at AI the same way: it already had a mandate over something — personal information, competition, government operations, court procedure, professional conduct — and AI turned out to touch that thing. None of them was created for AI, and none of them has authority over AI in general. A business trying to work out who regulates it gets a more useful answer by asking what its AI system is actually doing — collecting personal data, making a claim to the public, assisting a government decision, appearing in a court filing — because the answer to that question points directly at which of these bodies, if any, has something to say.

Related: federal vs provincial AI rules in Canada and how Canada regulates AI without an AI act.

Common questions

Is there one Canadian body I should register my AI product with?

No. None of the bodies listed here operates a registration system for AI products generally — see is there an AI registry in Canada for the closest things that exist and why none of them qualifies.

Does the Competition Bureau need proof my AI product is unsafe to act?

Its deceptive-marketing jurisdiction turns on the claims made about a product's performance, not on a general safety assessment — the operative test under s.74.01(1)(b) of the Competition Act is whether a performance claim was backed by an adequate and proper test, with the burden on whoever made the claim.

Do law societies regulate AI vendors?

No. Their guidance governs how a lawyer or law firm uses AI in legal practice and in court filings — it says nothing about the vendors building or selling the AI tools themselves.

Trying to work out which of these actually apply to you?

A short conversation can map your specific AI use against the bodies that actually have something to say about it.