Anyone trying to track “the AI rules” in Canada quickly runs into a problem: there is no single rulebook to track. A federal bill that would have created one has been stuck in committee for years, a voluntary code fills part of the gap without being law, and courts and privacy regulators each publish their own guidance on their own schedule.
Key takeaways
Bill C-27 would have enacted three things at once: the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act, and the Artificial Intelligence and Data Act (AIDA) — Canada’s proposed AI-specific statute. (parl.ca) As read from the bill’s own record on Parliament’s LEGISinfo site, the page opens with a historical banner — “The information below relates to a prior session.” — against the 44th Parliament, 1st session (22 November 2021 to 6 January 2025). Its current status is listed as “At consideration in committee in the House of Commons”, and its latest recorded activity is second reading and referral to committee on Monday, April 24, 2023.
Committee meetings continued after that — the record lists sessions running through September 2024 — but report stage is listed as “Not reached” and third reading as “Not reached”, with nothing added since. Whatever AIDA would eventually require of an organization building or deploying AI in Canada, that is the honest, current state of the bill: introduced, debated, referred to committee, and stalled there. Nothing published permits a stronger statement in either direction.
About a year before that committee work stalled, Innovation, Science and Economic Development Canada (ISED) ran a public consultation on how a Canadian code of practice for generative AI should work, drawing on roundtables with Canada’s Advisory Council on Artificial Intelligence, academia, civil society, the national AI research institutes, and industry. (ised-isde.canada.ca) That consultation is now listed as “Current status: Closed”, and its own page is explicit about the purpose of the code it produced: to give “voluntary guidance to companies developing and using AI systems” so they can “prepare their processes and products before formal regulation takes effect”.
The result, launched in September 2023, is the Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems. (ised-isde.canada.ca) Forty-six organizations have signed, including TELUS, IBM, Cohere, CIBC, Mastercard and Scale AI, and they commit to six outcomes: Accountability, Safety, Fairness and Equity, Transparency, Human Oversight and Monitoring, and Validity and Robustness. The code is candid about its own limits: “this code does not in any way change existing legal obligations that organizations may have – for example, under the Personal Information Protection and Electronic Documents Act”. Its preamble also explains, in its own words, why the government reached for broad principles rather than a fixed rulebook: the capability “to generate realistic images and video, or to impersonate the voices of real people, can enable deception at a scale that can damage important institutions, including democratic and criminal justice systems” — a risk broad enough that a narrow rule written in 2023 would likely have missed whatever technique came next.
Canada’s privacy commissioners did not wait for AIDA either. In December 2023 the federal, provincial and territorial privacy authorities announced a joint set of principles for generative AI, since updated and re-dated 6 May 2025. (priv.gc.ca) The document sets out nine principles, from legal authority and consent through to safeguards, and it is candid that enforcement is already active on specific cases without naming them: the Office of the Privacy Commissioner of Canada “and its counterparts in British Columbia, Quebec and Alberta also have an open investigation relating to a particular generative AI service”.
Courts have done the same, independently of each other and of Ottawa. The Federal Court’s notice on AI in filings, updated 7 May 2024 from an earlier December 2023 version, requires a Declaration when AI content in a filing “resembles that of a co-author”. (fct-cf.ca, Notice to the Parties and the Profession, May 7, 2024) A separate policy on the Court’s own use of AI, dated 29 September 2025, states the Court “will not use AI, and more specifically automated decision-making tools, in making its judgments and orders, without first engaging in public consultations”. (fct-cf.ca) Alberta’s three courts issued a joint notice of their own in October 2023 urging caution with large language models — but unlike the Federal Court, it does not require a lawyer to disclose that AI was used at all. (albertacourts.ca) Same country, two courts, two different answers to the same question.
Three checks handle most of the confusion. First, distinguish a statute from a court notice from a code: only the first binds everyone; a court’s notice binds only filings before that court; a code binds only its signatories. Second, read the date on the page — the OPC principles carry a 6 May 2025 stamp and the ISED code’s page was last modified 4 June 2026; a source with no visible date, or one several years old, may already be superseded. Third, check who the document actually addresses — the Treasury Board’s own Directive on Automated Decision-Making, for instance, binds federal government departments, not private businesses, however useful it is as a model of good practice.
A litigation team in Calgary drafts a memo with AI assistance and needs to know whether that has to be disclosed. There is no Alberta statute on point. If the memo is filed with the Court of King’s Bench of Alberta, the October 2023 tri-court notice governs — it urges verification against authoritative sources but does not require a disclosure statement. If the same memo were instead filed with the Federal Court, the May 2024 notice would very likely require a first-paragraph Declaration, because AI drafting a legal argument is exactly the kind of contribution the Court describes as resembling co-authorship. Same task, same country, two different answers, because two different courts wrote two different rules at two different times.
Related: how existing law already reaches AI-generated deception, how an existing confidentiality duty constrains AI use, why the code’s own watermarking measure is a moving target
Not yet. The bill that would have created one, the Artificial Intelligence and Data Act, is part of Bill C-27, which Parliament’s own records list as stalled in committee since April 2023 with no further stage reached. What exists instead is a voluntary code that binds only its signatories, plus the ordinary laws on privacy and deceptive marketing that already applied before generative AI existed.
No. The code states directly that it “does not in any way change existing legal obligations,” and its measures table applies only to the developers and managers who committed to it. A business that never signed is still bound by whatever already-existing law applies to what it does — just not by the code’s own commitments.
No. The Federal Court’s notice and Alberta’s tri-court notice both govern materials filed with that specific court — neither says anything about how a business uses AI internally or in a customer-facing product outside of litigation.
Whatever guidance applies today, an organization still needs its own internal discipline for using AI responsibly while the external rules catch up.