Canada was one of the first countries to put a general AI statute in front of its legislature. The Artificial Intelligence and Data Act, AIDA, was tabled in June 2022 as Part 3 of Bill C-27, the Digital Charter Implementation Act. It never became law. When Parliament was prorogued on 6 January 2025, Bill C-27 died on the Order Paper, and bills that die at prorogation do not carry over. As of October 2026 Canada still has no federal AI statute.

That makes AIDA easy to dismiss and a mistake to ignore. Its structure, built around high-impact systems, assessment, mitigation, monitoring, records, public description and harm notification, is the template every Canadian regime keeps reaching for, and laws that already bind you contain pieces of it. This article explains what AIDA said, why it failed, what governs AI in Canada today, and how to build one control plane that absorbs whatever comes next. It is engineering guidance, not legal advice.

Where AIDA stands in October 2026

Start with the timeline, because most of the confusion online comes from articles written while the bill was alive. Bill C-27 was introduced on 16 June 2022 with three parts: the Consumer Privacy Protection Act, a tribunal act, and AIDA. It spent 2023 and 2024 at the House of Commons industry committee, which never finished. Prorogation ended it, and the April 2025 election produced a Minister of Artificial Intelligence and Digital Innovation, who has said AIDA will not return as drafted.

Since then the government has moved on narrower tracks. On 15 June 2026 it tabled Bill C-36, the Protecting Privacy and Consumer Data Act, which would replace the privacy part of PIPEDA, create a new Digital Safety and Data Protection Commission, and require organizations to be transparent about automated decision-making used for significant decisions about individuals. An online-safety bill, C-34, was tabled days earlier. Neither is an AI act, and both are still bills: check LEGISinfo before citing them.

How the bill was built

AIDA was framework legislation: a short statute that set duties in general terms and left the important definitions to regulations. It applied to regulated activities carried out in the course of international or interprovincial trade and commerce. Regulated activities had two halves: processing or making available data for designing, developing or using an AI system, and designing, developing, making available or managing the operations of an AI system.

An AI system was defined broadly as a technological system that, autonomously or partly so, processes data related to human activities through a genetic algorithm, a neural network, machine learning or another technique in order to generate content or make decisions, recommendations or predictions. The person responsible was anyone who designed, developed, made available or managed the operation of a system. Harm meant physical or psychological harm to an individual, damage to property, or economic loss to an individual. Biased output meant content, decisions or recommendations that adversely differentiate, without justification, on a prohibited ground under the Canadian Human Rights Act.

Three choices mattered. Harm was individual, leaving collective harms out. The key term, high-impact system, was left to regulations. And the Minister held the powers, assisted by an AI and Data Commissioner inside the same department that promotes the industry.

The duties as a lifecycle

The operative duties were a short chain, and it is worth reading them as a lifecycle rather than a list. Anyone carrying out a regulated activity who processed or made available anonymized data had to establish measures about how data is anonymized and how it is used. A person responsible for an AI system had to assess whether it was a high-impact system. If it was, the person had to establish measures to identify, assess and mitigate risks of harm or biased output, establish measures to monitor compliance with those mitigations and their effectiveness, and keep records describing the measures and the reasons supporting the high-impact assessment.

Two duties faced outward. Whoever made a high-impact system available, or managed its operation, had to publish on a public website a plain-language description of the system: how it is intended to be used, the types of content it generates or decisions it makes, and the mitigation measures in place. And the person responsible had to notify the Minister as soon as feasible if use of the system resulted or was likely to result in material harm.

The Minister could order records, require an audit, order a system's use to cease where there was a serious risk of imminent harm, and publish contraventions.

An AIDA-shaped lifecycle: the controls the bill would have required, mapped to engineering stepsRegisterinventory entryAssesshigh-impact? (s. 7)Mitigatebias, harm (s. 8)Publishplain language (s. 11)Deploywith monitors (s. 9)Harm signalcomplaint, drift, auditNotify regulatormaterial harm (s. 12)monitoringRecords (s. 10)every step writes evidence, retainedSection numbers refer to AIDA as tabled in 2022; treat them as a design template, not current law.
AIDA's duties as a lifecycle. The bill is dead, but every live Canadian regime asks for some subset of these artifacts, so build the pipeline once.

Penalties and enforcement

AIDA had three enforcement layers. Administrative monetary penalties were authorized, with the amounts and procedure left to regulations. Regulatory offences covered contraventions of the core duties and obstruction of the Minister or an auditor; for an organization convicted on indictment the maximum fine was the greater of 10 million dollars and 3 percent of gross global revenues. Two general offences sat in a separate part: possessing or using personal information knowing it was obtained unlawfully, in order to build or use an AI system; and making a system available knowing it was likely to cause serious harm, or with intent to defraud the public and cause substantial economic loss, where that harm or loss occurred. Those carried up to the greater of 25 million dollars and 5 percent of gross global revenues.

Summaries of Bill C-36 report the same two tiers for its privacy penalties; expect them in an AI successor too.

The 2023 amendments: the best guide to a successor

In November 2023 the then minister sent the committee a letter describing amendments the government would bring. They answer the main criticisms and are the best evidence of where a successor will land. The letter proposed listing initial classes of high-impact systems in the statute rather than leaving all of it to regulations: employment decisions such as hiring, pay, promotion and termination; decisions about whether to provide a service to an individual, its type and its cost; processing biometric information to identify people or infer behaviour; moderating and prioritizing content on online platforms and search engines; health care and emergency services; decisions by courts and administrative bodies; and assisting police in law enforcement.

It also proposed obligations for general-purpose systems such as large language models, clearer split of duties between developers and deployers, a stronger commissioner, and alignment with the EU AI Act. If you already map systems to the EU high-risk list, the overlap is large.

Why it died and what governs AI instead

AIDA failed for reasons that predict the design of its successor. Critics objected that it was drafted without consultation, left its substance to future regulations, had a regulator inside the promoting department and ignored group harms. Industry objected to uncertainty about high-impact. The clock ran out.

Instead, general law already reaches AI. PIPEDA governs personal information in commercial activity, including the purposes for which training data was collected. Quebec's private-sector privacy act, as amended by Law 25, has since September 2023 required an organization that makes a decision based exclusively on automated processing of personal information to tell the person, explain on request the information and principal factors used, and let the person submit observations to someone who can review the decision. The Treasury Board Directive on Automated Decision-Making binds federal institutions and requires an Algorithmic Impact Assessment that sorts a system into impact levels I to IV, with obligations such as peer review and human involvement scaling up. OSFI's Guideline E-23 sets enterprise model-risk expectations, explicitly including AI models, for federally regulated financial institutions. Human rights codes, the Competition Act's rules on misleading claims and sector regulators fill the rest, and the 2023 Voluntary Code of Conduct on advanced generative AI lists six principles: accountability, safety, fairness and equity, transparency, human oversight and monitoring, and validity and robustness.

Canadian AI obligations in October 2026: what binds, what is proposed, what is voluntaryAIDA (Bill C-27, Part 3)tabled 2022, died Jan 2025Bill C-36 (PPCDA)privacy reform, tabled Jun 2026Successor AI frameworkpromised, not yet tabledPIPEDAin force, federal private sectorQuebec Law 25s. 12.1 automated decisionsTBS Directive on ADMfederal institutions, AIAOSFI E-23model risk, FRFIsVoluntary Code (2023)advanced generative AIHuman rights + consumer lawdiscrimination, misleading claimsSector regulatorshealth, finance, employmentOne internal control planeinventory, impact tiering, testing, records, incident noticeRed: dead. Amber: proposed. Green: binding today. Blue: soft law and general law that already reaches AI.
The Canadian regime in October 2026. No single AI statute binds a private company; several general laws and one federal directive do, and all of them feed the same internal control plane.

One control plane for every regime

The practical answer to a moving target is to build controls around the artifacts that every regime asks for, keyed to one inventory. Four artifacts cover almost everything: an inventory entry per system with owner, purpose, model lineage and the decisions it touches; an impact tier with the reasons recorded; a test record covering performance, bias across groups and robustness; and an incident log with a notification path. The plain-language description is generated from the inventory entry rather than written separately, so it cannot drift from what the system does.

Keep the tiering rules as versioned code. The sketch below seeds them with the 2023 high-impact classes and the Quebec test; update the table when a successor defines the classes.

from dataclasses import dataclass, field

HIGH_IMPACT_CLASSES = {          # AIDA 2023 proposal; replace when a successor defines them
    "employment", "service_eligibility_or_price", "biometric_identification",
    "content_moderation_ranking", "health_or_emergency", "adjudication", "law_enforcement",
}

@dataclass
class AISystem:
    name: str
    owner: str
    decision_classes: set
    uses_personal_info: bool
    fully_automated: bool            # no human reviews before the decision takes effect
    affects_quebec_residents: bool
    federal_institution: bool = False
    general_purpose_model: bool = False
    obligations: list = field(default_factory=list)

def tier(s: AISystem) -> str:
    hits = s.decision_classes & HIGH_IMPACT_CLASSES
    if hits:
        s.obligations += ["impact assessment with recorded reasons",
                          "bias and harm testing per group before release",
                          "monitoring with thresholds and an owner",
                          "public plain-language description",
                          "material-harm escalation path (target: 72h to legal)"]
    if s.uses_personal_info and s.fully_automated and s.affects_quebec_residents:
        s.obligations += ["Law 25 s.12.1 notice at decision time",
                          "explain principal factors on request",
                          "human reviewer channel for observations"]
    if s.federal_institution:
        s.obligations += ["TBS Algorithmic Impact Assessment, publish result"]
    if s.general_purpose_model:
        s.obligations += ["pre-release misuse evaluation", "AI-content labelling"]
    return "high" if hits else ("medium" if s.uses_personal_info else "low")

The 72-hour target is an internal choice, not a statutory number; AIDA said as soon as feasible.

Worked example: an LLM resume ranker

Take a concrete case. A Toronto staffing firm uses an LLM to rank applicants for warehouse roles. Recruiters see the top twenty of each pool; the rest are rejected automatically after fourteen days with no human look. Some applicants live in Quebec.

Employment is a high-impact class, so the tiering function marks it high-tier. Because the automatic rejections involve personal information, take effect without human review and reach Quebec residents, the Law 25 duties attach today, regardless of any federal bill: rejected Quebec applicants must be told the decision was automated, must be able to learn the principal factors, and must be able to have a person review it. PIPEDA's purpose limits apply to the resumes themselves; reusing past applicants' files to fine-tune the ranker needs a basis.

Testing then finds that the ranker scores applicants with employment gaps lower, and gaps correlate with parental leave and disability: AIDA's biased-output pattern and a potential human rights complaint today. Remove gap features from the prompt, rerun the selection-rate comparison across inferred groups, sample the automatic rejections for human review, and record all of it.

Failure modes

Programs built around AIDA fail in recognizable ways.

  • Waiting for the statute. Teams paused governance work when the bill died, while Quebec's automated-decision duties and human rights law kept applying. Absence of an AI act is not absence of AI obligations.
  • Citing a dead bill as law. Contracts still claim AIDA compliance. Describe the controls instead.
  • Checkbox human review. A reviewer approving 99.8 percent of outputs in four seconds each is not meaningful review.
  • A description that drifts. Written once, stale soon. Generate it from the inventory.
  • No group data, so no bias test. Use inferred groups for testing only, never as features.
  • Vendor opacity. Put testing evidence and incident notice in procurement contracts.

Trade-offs

Over-building for a hypothetical statute wastes effort; under-building leaves you exposed to laws that already apply. Build the four artifacts for everything high-tier now, since they serve Law 25, human rights defence, model risk and EU alignment at once, and keep notices and filings as thin generated views. A single control plane costs more up front than per-law checklists but does not need rebuilding each time Ottawa or a province acts. If you operate in the EU, map to the EU AI Act as the strictest common denominator.

What to do next

A checklist you can run this quarter:

  1. Inventory every AI system, including vendor models and LLM features inside products, with an owner and the decision classes it touches.
  2. Tier each system with versioned rules seeded from the 2023 high-impact classes and record the reasons.
  3. Identify every fully automated decision about Quebec residents and implement the notice, explanation and human-review channel now.
  4. Run group-level bias and robustness tests for high-tier systems and file the results.
  5. Write a material-harm escalation runbook with a clock and drill it once.
  6. Remove any claim of AIDA compliance from contracts, notices and marketing.
  7. Track Bill C-36, C-34 and any AI bill on LEGISinfo, and map their clauses onto the control plane when text is final.
  8. Read the EU AI Act guide and the NIST AI RMF guide to align the same artifacts with other regimes, the regulation deep dive for the global picture, AI in finance regulation if OSFI applies, and audit preparation to package evidence.
Key takeaway: AIDA is dead, but its shape is not. Build the inventory, impact tiering, testing records, public description and harm escalation it described, because Quebec's Law 25, PIPEDA, the federal directive, OSFI and human rights law already demand most of them, and the successor framework will almost certainly demand the rest. Cite controls, not a bill that never passed.