# AI rules in Canada

With AIDA dead since Jan 2025, Canada is regulating AI through its June 2026 'AI for All' strategy, a privacy bill (C-36) with automated-decision transparency, criminal deepfake law, federal and financial-sector directives and Ontario hiring rules.

- **Approach:** Sector regulators and guidelines
- **Key bodies:** ISED (Minister of AI and Digital Innovation), Treasury Board Secretariat, OSFI, Office of the Privacy Commissioner, Canadian AI Safety Institute
- **Strategy:** [Canada's National AI Strategy: AI for All](https://ised-isde.canada.ca/site/ised/en/canadas-national-artificial-intelligence-strategy-ai-all) (2026)
- **Last reviewed:** 4 Oct 2026

## Rules (6)
- [AI for All](https://wheresthe.ai/rule/ca-ai-for-all-national-ai-strategy-2026/index.md): In force, Strategy, effective 4 Jun 2026. Six-pillar national strategy that replaces the lapsed AIDA approach with commitments to modernise privacy law, introduce online safety laws, give legal tools against deepfakes, work on watermarking of AI content, create a Canada Trusted AI Certification programme and fund the Canadian AI Safety Institute (CAD 50 million). It is policy, not law.
- [Bill C-36 (privacy reform)](https://wheresthe.ai/rule/ca-bill-c36-protecting-privacy-consumer-data-2026/index.md): Proposed, Bill. Government bill to replace federal private-sector privacy law, including a requirement that organisations be transparent about using automated decision systems for significant decisions about individuals, stronger protection for children's data, and limits on surveillance pricing. It applies to private-sector organisations handling personal information.
- [Protecting Victims Act (sexual deepfakes)](https://wheresthe.ai/rule/ca-bill-c16-protecting-victims-act-deepfakes-2026/index.md): In force, Law, effective 18 Jul 2026. Expands the Criminal Code offence of non-consensual distribution of intimate images to cover sexual deepfakes, criminalises threatening to distribute such images, and raises the maximum penalty. Applies to individuals.
- [Directive on Automated Decision-Making](https://wheresthe.ai/rule/ca-tbs-directive-automated-decision-making/index.md): In force, Regulation, effective 1 Apr 2019. Binding policy instrument requiring federal institutions using automated decision systems to complete an Algorithmic Impact Assessment, give notice and explanations, ensure human intervention for higher-impact decisions, test for bias and publish results. Latest version dated 24 Jun 2025; systems procured before then had until 24 Jun 2026 to meet the updated requirements.
- [OSFI E-23](https://wheresthe.ai/rule/ca-osfi-guideline-e23-model-risk-2027/index.md): Enacted, not yet in force, Guideline, effective 1 May 2027. Supervisory guideline setting enterprise-wide model risk management expectations, explicitly covering AI/ML models, across the model lifecycle (inventory, risk rating, validation, monitoring, governance). Applies to federally regulated banks, insurers and trust and loan companies.
- [Ontario AI-in-hiring disclosure](https://wheresthe.ai/rule/ca-on-esa-ai-job-posting-disclosure-2026/index.md): In force, Regulation, effective 1 Jan 2026. Provincial rule requiring employers with 25 or more employees to state in publicly advertised job postings whether artificial intelligence is used to screen, assess or select applicants. Applies to employers in Ontario.

## Upcoming deadlines
- 1 May 2027: Guideline E-23 takes effect for federally regulated financial institutions ([OSFI E-23](https://wheresthe.ai/rule/ca-osfi-guideline-e23-model-risk-2027/index.md))

## Programmes and facts
- CAD 50 million to expand the Canadian AI Safety Institute (AI for All, 2026)
- Canada Trusted AI Certification programme announced (2026)

---
Canonical page: https://wheresthe.ai/j/ca/ · Not legal advice.
