Countries / Canada
Canada
With AIDA dead since Jan 2025, Canada is regulating AI through its June 2026 'AI for All' strategy, a privacy bill (C-36) with automated-decision transparency, criminal deepfake law, federal and financial-sector directives and Ontario hiring rules.
In force (4)
-
AI for All
Six-pillar national strategy that replaces the lapsed AIDA approach with commitments to modernise privacy law, introduce online safety laws, give legal tools against deepfakes, work on watermarking of AI content, create a Canada Trusted AI Certification programme and fund the Canadian AI Safety Institute (CAD 50 million). It is policy, not law.
In forceEffective 4 Jun 2026 -
Protecting Victims Act (sexual deepfakes)
Expands the Criminal Code offence of non-consensual distribution of intimate images to cover sexual deepfakes, criminalises threatening to distribute such images, and raises the maximum penalty. Applies to individuals.
In forceEffective 18 Jul 2026 -
Directive on Automated Decision-Making
Binding policy instrument requiring federal institutions using automated decision systems to complete an Algorithmic Impact Assessment, give notice and explanations, ensure human intervention for higher-impact decisions, test for bias and publish results. Latest version dated 24 Jun 2025; systems procured before then had until 24 Jun 2026 to meet the updated requirements.
In forceEffective 1 Apr 2019 -
Ontario AI-in-hiring disclosure
Provincial rule requiring employers with 25 or more employees to state in publicly advertised job postings whether artificial intelligence is used to screen, assess or select applicants. Applies to employers in Ontario.
In forceEffective 1 Jan 2026
Adopted, not yet in force (1)
-
OSFI E-23
Supervisory guideline setting enterprise-wide model risk management expectations, explicitly covering AI/ML models, across the model lifecycle (inventory, risk rating, validation, monitoring, governance). Applies to federally regulated banks, insurers and trust and loan companies.
Enacted, not yet in forceApplies 1 May 2027
Proposed or in consultation (1)
-
Bill C-36 (privacy reform)
Government bill to replace federal private-sector privacy law, including a requirement that organisations be transparent about using automated decision systems for significant decisions about individuals, stronger protection for children's data, and limits on surveillance pricing. It applies to private-sector organisations handling personal information.
ProposedProposed 15 Jun 2026
What the rules require
Obligation types found across Canada's instruments. Filled dot: imposed by a binding instrument. Ring: guidance only.
| Risk classification | OSFI E-23 | |
| Prohibited uses | Protecting Victims Act (sexual deepfakes) | |
| Transparency to users | AI for All, Bill C-36 (privacy reform), Directive on Automated Decision-Making, Ontario AI-in-hiring disclosure | |
| Labelling AI content | AI for All | |
| Impact assessment | Directive on Automated Decision-Making, OSFI E-23 | |
| Human oversight | Directive on Automated Decision-Making, OSFI E-23 | |
| Data governance | Bill C-36 (privacy reform), OSFI E-23 | |
| Bias and non-discrimination | Directive on Automated Decision-Making | |
| Frontier model safety | AI for All | |
| Government use of AI | Directive on Automated Decision-Making | |
| Consumer rights | Bill C-36 (privacy reform) | |
| Penalties | Bill C-36 (privacy reform), Protecting Victims Act (sexual deepfakes) |
Timeline
- Protecting Victims Act (sexual deepfakes)Took effect
- Bill C-36 (privacy reform)Proposed
- AI for AllAdopted and took effect
- Ontario AI-in-hiring disclosureTook effect
- OSFI E-23Adopted
- Directive on Automated Decision-MakingAdopted and took effect