An AI system does not carry accountability the way a person or a business does — it has no licence to lose, no employer to answer to, and no obligation a regulator can enforce against it directly. Every Canadian source that speaks to this treats accountability as something that has to be assigned to a specific person or organization before a system goes anywhere near a real decision, and stays assigned no matter how the decision was actually produced.
Key takeaways
Under PIPEDA’s Schedule 1, accountability for an organization’s handling of personal information is not a floating responsibility — it rests with a named person. Clause 4.1.1 states it directly: “Accountability for the organization’s compliance with the principles rests with the designated individual(s), even though other individuals within the organization may be responsible for the day-to-day collection and processing of personal information.” That structure matters the moment an AI tool enters the picture, because clause 4.1.3 closes the obvious escape route: “An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.” Handing data to an AI vendor is a transfer for processing, not a transfer of responsibility. If the vendor’s system mishandles it, the designated individual at the business that chose the vendor is still the one accountable under PIPEDA — not the vendor, and certainly not the model.
The Treasury Board’s Directive on Automated Decision-Making is explicit about scope: it binds federal government departments, not private businesses. Within that scope, though, it is the most concrete accountability structure Canada has produced. It assigns responsibility to “the assistant deputy minister responsible for the program using the automated decision system, or any other senior official named by the deputy head” — a specific role, not a department in the abstract — and makes that official responsible for completing, approving, and publishing an Algorithmic Impact Assessment “prior to the production of any automated decision system,” then reviewing and updating it “on a scheduled basis, including when the functionality or scope of the automated decision system changes,” with the whole directive itself reviewed every two years. A private business is not bound by any of this. But the shape of it — name a specific accountable person before deployment, document the decision to deploy, and revisit that decision on a schedule — is a usable template for any business that wants to be able to answer “who approved this” when someone asks.
ISED’s Voluntary Code of Conduct commits its signatories to an Accountability outcome: organizations “understand their role with regard to the systems they develop or manage, put in place appropriate risk management systems, and share information with other organizations as needed to avoid gaps.” It is voluntary and binds only the roughly four dozen organizations that signed it — mostly large technology vendors and institutions. It also states, in terms that matter regardless of whether a business signs it, that the code “does not in any way change existing legal obligations that organizations may have – for example, under the Personal Information Protection and Electronic Documents Act.” Signing a voluntary transparency commitment does not substitute for the accountable-individual structure PIPEDA already requires.
Ontario’s Superior Court of Justice has already applied this principle to lawyers using AI, and its wording generalizes past the legal profession: “it is the responsibility of all counsel and litigants to guarantee accuracy when preparing materials for use in court proceedings, and particularly when using AI, regardless of whether they directly interacted with the technology … The court will not tolerate inadvertence in this regard.” The practice direction lists what happens when that responsibility is not met — the court’s powers “include, but are not limited to, public reprimand of the counsel or litigant, the imposition of cost orders, adjourning a hearing or dismissing the matter, the initiation of contempt proceedings, and in regards to counsel, referral to the Law Society of Ontario.” None of those consequences fall on the AI tool. They fall on the person who filed the document, whether or not that person personally typed the prompt. The Federal Court’s own interim principles build the same expectation into how the Court treats its own use of AI, committing to ensure “that members of the Court and their law clerks are aware of the need to verify the results of any AI-generated outputs that they may be inclined to use in their work” under a principle it labels “Human in the loop.”
Put the three sources together and a usable test falls out: for any AI-assisted output your business relies on, can you name the specific person who is expected to review it, and is that the same person who would be asked to answer for it if it turned out wrong? If the honest answer is “nobody in particular, we just use what the tool gives us,” that is the gap PIPEDA’s designated-individual requirement and the federal directive’s named-official requirement are both built to close. An explainable system makes that review possible; it does not replace the requirement that someone actually do it.
A worked example
A brokerage uses an AI tool to draft a first-pass risk summary on incoming applications. If a summary later turns out to have missed something material, PIPEDA’s accountability principle does not let the business point at the vendor’s model — the designated individual accountable for how that tool is used inside the business is the one who answers for it, exactly as they would if a junior staff member had drafted the summary by hand and nobody had checked it.
Not under PIPEDA. Schedule 1, clause 4.1.3 makes the organization responsible for personal information “including information that has been transferred to a third party for processing,” and requires the organization to use contractual or other means to keep an equivalent level of protection while a third party handles it. Accountability does not transfer with the data.
Only within a specific scope right now: the Treasury Board’s Directive on Automated Decision-Making requires it for federal government departments making administrative decisions about clients, including notice before the decision and a meaningful explanation after it. No equivalent law currently applies to private Canadian businesses, though ISED’s voluntary code and Canadian courts’ own practice directions point the same direction.
Ontario’s Superior Court of Justice practice direction sets out real consequences: public reprimand, cost orders, adjourning or dismissing a matter, contempt proceedings, and referral to the Law Society of Ontario for counsel. The responsibility for accuracy sits with the person who filed the material, “regardless of whether they directly interacted with the technology.”
Related: what AI explainability really buys you, and why shadow AI is a problem.
A short call maps where accountability currently sits across your AI-assisted work.