Treadstone Associates
Article · 8 min read

Who is accountable when AI decides?

An AI system does not carry accountability the way a person or a business does — it has no licence to lose, no employer to answer to, and no obligation a regulator can enforce against it directly. Every Canadian source that speaks to this treats accountability as something that has to be assigned to a specific person or organization before a system goes anywhere near a real decision, and stays assigned no matter how the decision was actually produced.

Treadstone Associates · Updated 2026

Key takeaways

  • • Canadian privacy law does not let accountability disappear into a vendor or a tool: PIPEDA requires a “designated individual” accountable for an organization’s compliance, and that responsibility stays with the organization even when a third party processes the data.
  • • The federal government’s own directive on automated decision-making assigns accountability to a named departmental official before a system goes into production — it does not apply to private business, but it is the clearest Canadian model of what assigning accountability actually looks like.
  • • Courts already show what happens when a professional treats an AI output as though it decided something on its own: the person who filed it is still held to account, regardless of whether they personally used the tool.
  • • The rule that generalizes: AI drafts, extracts, scores, or summarizes. A person decides, signs, and answers for the result.

The starting principle: a person is always named

Under PIPEDA’s Schedule 1, accountability for an organization’s handling of personal information is not a floating responsibility — it rests with a named person. Clause 4.1.1 states it directly: “Accountability for the organization’s compliance with the principles rests with the designated individual(s), even though other individuals within the organization may be responsible for the day-to-day collection and processing of personal information.” That structure matters the moment an AI tool enters the picture, because clause 4.1.3 closes the obvious escape route: “An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.” Handing data to an AI vendor is a transfer for processing, not a transfer of responsibility. If the vendor’s system mishandles it, the designated individual at the business that chose the vendor is still the one accountable under PIPEDA — not the vendor, and certainly not the model.

The only Canadian rule that names who signs off on an automated decision

The Treasury Board’s Directive on Automated Decision-Making is explicit about scope: it binds federal government departments, not private businesses. Within that scope, though, it is the most concrete accountability structure Canada has produced. It assigns responsibility to “the assistant deputy minister responsible for the program using the automated decision system, or any other senior official named by the deputy head” — a specific role, not a department in the abstract — and makes that official responsible for completing, approving, and publishing an Algorithmic Impact Assessment “prior to the production of any automated decision system,” then reviewing and updating it “on a scheduled basis, including when the functionality or scope of the automated decision system changes,” with the whole directive itself reviewed every two years. A private business is not bound by any of this. But the shape of it — name a specific accountable person before deployment, document the decision to deploy, and revisit that decision on a schedule — is a usable template for any business that wants to be able to answer “who approved this” when someone asks.

What the voluntary code adds for everyone else

ISED’s Voluntary Code of Conduct commits its signatories to an Accountability outcome: organizations “understand their role with regard to the systems they develop or manage, put in place appropriate risk management systems, and share information with other organizations as needed to avoid gaps.” It is voluntary and binds only the roughly four dozen organizations that signed it — mostly large technology vendors and institutions. It also states, in terms that matter regardless of whether a business signs it, that the code “does not in any way change existing legal obligations that organizations may have – for example, under the Personal Information Protection and Electronic Documents Act.” Signing a voluntary transparency commitment does not substitute for the accountable-individual structure PIPEDA already requires.

What it looks like when a court decides who was accountable

Ontario’s Superior Court of Justice has already applied this principle to lawyers using AI, and its wording generalizes past the legal profession: “it is the responsibility of all counsel and litigants to guarantee accuracy when preparing materials for use in court proceedings, and particularly when using AI, regardless of whether they directly interacted with the technology … The court will not tolerate inadvertence in this regard.” The practice direction lists what happens when that responsibility is not met — the court’s powers “include, but are not limited to, public reprimand of the counsel or litigant, the imposition of cost orders, adjourning a hearing or dismissing the matter, the initiation of contempt proceedings, and in regards to counsel, referral to the Law Society of Ontario.” None of those consequences fall on the AI tool. They fall on the person who filed the document, whether or not that person personally typed the prompt. The Federal Court’s own interim principles build the same expectation into how the Court treats its own use of AI, committing to ensure “that members of the Court and their law clerks are aware of the need to verify the results of any AI-generated outputs that they may be inclined to use in their work” under a principle it labels “Human in the loop.”

A practical test

Put the three sources together and a usable test falls out: for any AI-assisted output your business relies on, can you name the specific person who is expected to review it, and is that the same person who would be asked to answer for it if it turned out wrong? If the honest answer is “nobody in particular, we just use what the tool gives us,” that is the gap PIPEDA’s designated-individual requirement and the federal directive’s named-official requirement are both built to close. An explainable system makes that review possible; it does not replace the requirement that someone actually do it.

A worked example

A brokerage uses an AI tool to draft a first-pass risk summary on incoming applications. If a summary later turns out to have missed something material, PIPEDA’s accountability principle does not let the business point at the vendor’s model — the designated individual accountable for how that tool is used inside the business is the one who answers for it, exactly as they would if a junior staff member had drafted the summary by hand and nobody had checked it.

Common questions

Can a business blame the AI vendor if an automated decision goes wrong?

Not under PIPEDA. Schedule 1, clause 4.1.3 makes the organization responsible for personal information “including information that has been transferred to a third party for processing,” and requires the organization to use contractual or other means to keep an equivalent level of protection while a third party handles it. Accountability does not transfer with the data.

Does a person have to review every AI-assisted decision by law?

Only within a specific scope right now: the Treasury Board’s Directive on Automated Decision-Making requires it for federal government departments making administrative decisions about clients, including notice before the decision and a meaningful explanation after it. No equivalent law currently applies to private Canadian businesses, though ISED’s voluntary code and Canadian courts’ own practice directions point the same direction.

What happens when a professional does not check AI-generated work before relying on it?

Ontario’s Superior Court of Justice practice direction sets out real consequences: public reprimand, cost orders, adjourning or dismissing a matter, contempt proceedings, and referral to the Law Society of Ontario for counsel. The responsibility for accuracy sits with the person who filed the material, “regardless of whether they directly interacted with the technology.”

Related: what AI explainability really buys you, and why shadow AI is a problem.

Know exactly who signs off before an AI tool touches a real decision.

A short call maps where accountability currently sits across your AI-assisted work.