Chapter 10: Privacy & Surveillance

Chapter 9 introduced personal sovereignty: the question of whether individuals retain meaningful control over how AI systems use their data, their…

Chapter 9 introduced personal sovereignty: the question of whether individuals retain meaningful control over how AI systems use their data, their likenesses, and their decisions. This chapter goes deep on the privacy and surveillance dimensions of that question: what AI systems are actually collecting about you, what they're inferring about you that you didn't explicitly disclose, who has access to those collections and inferences, what protections currently exist, and what the absence of comprehensive Canadian AI privacy regulation means in practice. The chapter distinguishes two concepts that public discussion routinely collapses. Privacy is the question of what specific information about you is collected and disclosed without your consent. Surveillance is the question of how the systems built around that information collection produce ongoing monitoring of behaviour, decision-making, and life chances. They are related but not identical. A system can violate privacy without producing surveillance — a one-time data breach is the simplest case. And surveillance can run without violating privacy in the conventional sense: an aggregation of consented disclosures that, in combination, produces inferential capacity the individual disclosures didn't suggest. AI is structurally implicated in both, and most dangerous when both happen at once. You will leave this chapter with: working definitions of privacy and surveillance as they apply to AI; the federal Treasury Board AI Register's coverage and the specific gaps in what it discloses; the workplace AI surveillance question anchored in CUPE's primary documentation; Quebec's Law 25 framework as the operational model Ottawa hasn't matched; the post-AIDA regulatory gap named honestly; and the working test for evaluating any AI privacy claim. ---

What AI systems actually collect — and what they infer

Most public discussion of "AI and privacy" frames the question as: what specific information has been collected about me? That's the right starting question but the wrong stopping point. The deeper question, and the one the AI moment makes urgent, is: what is being inferred about me from information that, on its own, seemed unrelated to the inference?

A worked example. You search "headache symptoms persistent" on a major search engine. You read three articles about migraine treatments. You watch one YouTube video about chronic pain management. You order a heating pad on a major retailer. Across these four interactions, no individual data point discloses a medical condition. In aggregate, an AI system processing your behavioural data has inferential evidence consistent with chronic pain or migraine sufficient to target advertising, adjust insurance risk profiles, modulate creditworthiness assessments, or inform employment screening, none of which you consented to.

🧌 GOBLIN CHECK — You never told anyone about the headaches. You told a search bar, a video site, and a checkout cart — separately, innocently, like a person living a life. The inference engine's entire job is introducing your data points to each other at a party you weren't invited to. Consent forms cover the data points. Nothing currently covers the introductions.

This is the structural privacy problem AI creates. Individual data points that seem innocuous become highly revealing when processed at scale by systems designed to find inferential patterns. The data points themselves may have been collected with consent — terms-of-service agreements, cookie banners, opt-in disclosures. The inferences drawn from them were almost certainly not.

Three categories of AI-relevant data collection worth distinguishing:

Explicit collection. What you actively share: search queries, social media posts, photographs uploaded, voice notes recorded, location pins shared. You know this is being collected because you took the action that shared it. The privacy issues here are conventional: data breach, secondary use beyond the disclosed purpose, transfer to third parties, retention beyond the necessary duration.

Implicit collection. What's collected about you without your explicit action: browsing behaviour, time spent on pages, mouse movements and scroll patterns, location inferred from network signals, contacts inferred from communication patterns, social graph inferred from co-occurrence. Privacy regimes have grown to cover much of this, but with substantial enforcement gaps.

Inferential extraction. What's inferred about you from the explicit and implicit data, often using AI techniques. This is the layer the AI moment makes different. The inferences are often more revealing than the underlying data, and often categorically different in sensitivity. Your search history may not include "I am pregnant," but the pattern of searches in early pregnancy is recognizable enough that systems can infer it before some pregnancies are humanly recognized. Your purchase history may not include "I am politically active around climate," but the combination of subscriptions, donations, and reading patterns produces an inference. Your communication patterns may not include explicit mental health disclosures, but the rhythm and content of communication produces inferences about depression, anxiety, or crisis.

EXAMPLE — the cart knew first. You never told the store you were pregnant. You bought unscented lotion and a couple of supplements, and the coupons started arriving anyway. AI systems rarely learn your secrets from what you tell them — they infer them from what you do. "I never shared that" and "they don't know that" turn out to be very different sentences.

In the AI era, the privacy question turns less on the data being collected than on what can be inferred from it after AI processing, and on what protections exist against those inferences being used in ways the individual did not consent to.

A specific Canadian finding worth foregrounding. The Office of the Privacy Commissioner of Canada (OPC) has issued guidance that under Canadian privacy law (PIPEDA, the federal private-sector law), the inferences drawn about an individual by an AI system are personal information about that individual, subject to PIPEDA's protections — even if the underlying data was collected with consent. This is the right legal position, but enforcement has been limited. The OPC has documented investigations into Tim Hortons app location tracking (2022) and Clearview AI's biometric scraping (2021), among other high-profile cases, but the resources for systematic enforcement at the scale AI deployment is now occurring are not currently in place. The federal AI strategy does not commit to expanded OPC resourcing.

Canadian public opinion on AI privacy is sharper than the policy response would suggest. The OPC's 2024-25 privacy opinion research documented that 88% of Canadians reported some concern about their personal information being used to train AI systems, including 42% who reported being extremely concerned. The same research found that only 28% had a fair amount or great deal of trust in "Big Tech" to protect personal information, and only 12% had equivalent trust in social media companies. The OPC's 2025-26 business survey separately documented that 16% of Canadian businesses report using AI in operations, most often for research/document drafting, marketing, text and data analysis, and customer service. The gap between 88% public concern about AI training data and the regulatory framework that does not require disclosure of training data composition is the clearest expression of the regulatory-vacuum finding the guide returns to throughout. The Canadian public has made its concern about AI privacy plain; the policy response has not yet matched it.

GOBLIN FACTS — concern is not hypothetical. OPC opinion research documented 88% concern about AI training-data use and only 28% trust in Big Tech to protect personal information. That is the public-confidence backdrop for Canadian privacy policy.

---

The federal AI Register — what it discloses and what it doesn't

In November 2025, the Treasury Board of Canada launched the federal AI Register, Canada's first public listing of AI systems in use by the federal government. The launch documentation, released under the AI Strategy for the Federal Public Service (the internal-use track distinct from AI for All — see Chapter 5), disclosed 42 institutions and 400-plus AI systems in active use across the federal public service.

This is a major transparency event. It is also a partial one, and the partiality is worth understanding closely.

What the Register discloses. For each AI system listed, the Register provides the institution using it, a description of the purpose, the type of AI technique (classification, generative, predictive, etc.), the kind of decisions or actions the system supports, the data inputs, the human oversight model, and (in many cases) the date the system was put into service. The Register is searchable, filterable, and downloadable in machine-readable format — meeting reasonable definitions of "transparency" as a procedural matter.

The historic finding. The launch documentation explicitly states that "AI has been in use in the Government of Canada for decades, with systems dating as far back as 1994." Chapter 1 used this as the entry point for de-mystifying the AI moment, and the Register is its primary source. Canadian federal AI use goes back decades; what is new is the public disclosure of it.

What the Register doesn't disclose, by stated scope choice. The Register explicitly excludes:

AI embedded within "low-risk commercial products" such as virtual assistants or spell checkers. This is the largest exclusion. Microsoft Office's Copilot integration, increasingly used across the federal public service, would be within scope of this exclusion as a "commercial product." The boundary between "low-risk commercial product" and "high-risk operational AI" is a categorical judgement made by the disclosing institution, not by an independent body.

National security AI uses. CSIS, CSE, military intelligence systems, and other national-security AI deployments are either absent from the Register or present with minimal detail. The Register documentation does not specify what national-security AI is excluded versus included.

Provincial and municipal AI use. The Register is federal-only. Provincial AI deployments (Service BC's algorithmic risk assessment systems, Ontario's child protection AI tools, Quebec's various AI-supported public administration systems) are not in any equivalent public register. Municipal AI use (city-level facial recognition pilots, transit pattern analysis, emergency response systems) is similarly unregistered.

Third-party AI systems used by federal contractors. If a federal department contracts with a private vendor to provide a service, and the vendor uses AI to deliver that service, the AI may not appear in the Register because it's deployed by the vendor rather than by the federal department directly.

The coverage question. The federal government has approximately 300 institutions across departments, agencies, Crown corporations, and other bodies. The Register at launch covered 42 — about 14% of total institutions. The remaining 86% either don't use AI (plausible for smaller bodies) or aren't reporting (also plausible). Without an independent audit, the gap can't be resolved.

The balance sheet on the AI Register: it is a substantively better transparency mechanism than any previous Canadian federal AI disclosure, it covers approximately one-seventh of federal institutions, it excludes the categories where transparency would matter most (national security, low-risk-commercial-products that may not be low-risk, contractor-deployed AI), and it sits in policy isolation, with no equivalent at provincial, municipal, or private-sector levels. The Register is a good first move that the federal government has not followed up. AI for All did not commit to expanding it.

---

The marquee case: AI in immigration and at the border

If you want the clearest test of how Canada governs its own use of AI, watch the border. Immigration is the highest-volume, highest-stakes place the federal government runs automated tools on individual people, and it is also where the language gets slippery in exactly the way the goblin's method is built for.

Start with the most common confusion. Reporters, applicants, and even some court filings describe visa refusals as the work of an AI called "Chinook." Chinook is real, and it is not AI. It is a Microsoft Excel–based tool that pulls an applicant's file out of the case-management system and lays it out so an officer can move faster, with a module that generates boilerplate refusal notes. IRCC's own position is blunt: Chinook "does not utilize artificial intelligence, nor advanced analytics for decision-making." Because it is classified as a non-AI processing aid, it falls outside the federal Directive on Automated Decision-Making, so the tool that shapes how an officer sees a file, and drafts the refusal, carries no Algorithmic Impact Assessment. That is the accountability gap critics keep pointing at, and it is invisible if you accept the "Chinook is the AI" framing.

The actual machine learning is a separate system. Since 2018, and for applications from every country since January 2022, IRCC has used advanced analytics to sort temporary-resident applications by complexity and to make positive eligibility determinations on the most routine files, which it says are processed roughly 87 percent faster as a result. The load-bearing safeguard is a hard rule: the model never refuses anyone. It can green-light eligibility and route everything else to officers, but every refusal is made by a human. This system, unlike Chinook, does carry published Algorithmic Impact Assessments, and IRCC has filed more of them than any other federal department; it has since extended the approach to visitor records, work permits, and spousal applications, and in February 2026 published its first departmental AI strategy.

The courts have mostly sided with the government on the narrow legal question while leaving the door open on the real one. In Haghshenas (2023) the Federal Court held that whether AI was used is "irrelevant," because an officer made the decision and judicial review tests the decision, not the software. But later rulings are less settled: judges have warned that templated refusals must still show the officer engaged with the file, and that if an assisted tool gives an officer a "truncated vision" of an application, the resulting decision "may well be unreasonable." The 2024 Mehrara decision went furthest, flagging concern about risk-indicator tools and about IRCC's practice of deleting the materials its processing technology generates. The trajectory points toward a future, evidence-based challenge that could land differently.

The critique that started the conversation is older. In 2018 the University of Toronto's Citizen Lab and International Human Rights Program published Bots at the Gate, warning that automating decisions in a discretionary, high-stakes system built for people with the weakest legal protections risked entrenching discrimination, and calling for a freeze until binding standards and independent oversight were in place. A parliamentary committee picked up the thread in 2022, scrutinizing Chinook against higher refusal rates for applicants from francophone African countries. Here the goblin has to be careful in both directions: refusal rates did rise as these tools spread, but the rise also tracks study-permit caps and integrity crackdowns, and no one has established that the technology caused the refusals. The correlation is on the record; the causation is not.

At the physical border, the surveillance version of the same story is further along. The Canada Border Services Agency has built a facial-recognition app to track people under deportation orders, with its matching algorithm withheld as a trade secret, and has piloted an AI "traveller compliance" tool that scores travellers for officer attention, which researchers warn carries a real risk of bias. An AI lie-detector tested in an Ottawa lab has, for now, stayed in the lab.

The honest synthesis is that immigration is where Canada's AI-governance instruments meet their hardest case. The efficiency pressure is real, the volume growth that produced it is real, and the human-in-the-loop safeguard is real on paper. The open questions are whether "human in the loop" quietly becomes a rubber stamp, whether the one tool that most shapes the officer's view is exactly the one the accountability framework does not cover, and whether the people least able to contest an opaque decision are the ones it falls on hardest.

---

The same pattern, past the border: welfare, policing, and the courts

Immigration is the most-litigated face of administrative AI, but it is not the only one, and the rest of the pattern rhymes. Wherever a Canadian government decides something about a person who has little power to argue back, some kind of automated system is now in the room. Three places show the range, and the same two traps.

The first trap is the word "AI" doing work the software cannot. Ontario's social-assistance computer, SAMS, is the cautionary tale. Launched in 2014 to run Ontario Works and disability benefits, it is a rules-based case-management system, not machine learning; nothing in it "scores" a claimant. It failed spectacularly anyway. The province's Auditor General found it went live with sixteen percent of its functions untested and a one-in-eight failure rate on the rest, the only system ever connected to government accounting without passing payment testing, and it produced roughly $140 million in benefit-calculation errors. The lesson is the one the immigration file already taught: you do not need a neural network to do algorithmic harm, and calling a deterministic system "AI" both overstates its sophistication and lets the real machine-learning systems hide behind the confusion. The deeper finding, from researchers who sat inside Ontario Works, is that automation quietly eats discretion: a caseworker fighting the software for one client has less time for the next, so the system's output becomes the decision in all but name. Other countries show how much worse rules-based welfare automation can get: Australia's "Robodebt" scheme invented hundreds of thousands of unlawful debts before a royal commission called it crude and cruel, and a Dutch benefits-fraud algorithm wrongly accused tens of thousands of families, many singled out by ethnicity, and helped bring down the government.

Policing is where the genuine AI, and the genuine surveillance, shows up. The clearest case is Clearview AI, the facial-recognition company that scraped billions of images off the open web. In 2021 Canada's privacy commissioners jointly called it mass surveillance and ruled it illegal, and a separate finding concluded the RCMP's own use of it broke the Privacy Act; the RCMP first reported 78 searches, then the vendor's records showed 521. Toronto police denied using it, then admitted officers had run thousands of images through it. Beyond Clearview, Canadian forces run their own facial recognition against mug-shot databases (Calgary was first, in 2014) and have adopted newer vendors since, one of which was tied to the wrongful arrest of a Black man in the United States. A handful of services have also tried predictive policing, mostly the location-based kind that flags where a break-in is likely, and the better Canadian deployments built in safeguards and refused to predict individual people. The recurring critique is not that the math is fake but that a model trained on decades of policing data learns the biases in that data, and aims more attention at communities that were already over-policed. The oversight response has been real but toothless: privacy commissioners and a parliamentary committee have called for a binding legal framework, and even a moratorium, and Canada still does not have one.

The courts are the highest-stakes version, and they produced the country's leading case. In Ewert v. Canada (2018) a Métis prisoner challenged the actuarial risk-assessment tools the Correctional Service uses to score dangerousness, on the grounds they had never been validated for Indigenous people. The Supreme Court agreed the Service had breached its legal duty to make sure the information it relies on is accurate. Read it carefully, because it is narrower than it is usually quoted: the Court ruled on a statute, not the Charter, and it did not declare the tools invalid, only that their accuracy for Indigenous offenders had never been confirmed. The Charter equality and liberty arguments were rejected. That distinction matters in a system where Indigenous adults are now a third of the prison population at roughly ten times the non-Indigenous rate, and where a tool that over-classifies them as high-risk does not create that disparity so much as launder it into a number. The Correctional Service has since funded work on a culturally informed tool; as of 2026 it is not yet in use.

Two threads tie these together. The first is who is on the receiving end: welfare recipients, criminalized people, migrants, the communities least equipped to demand reasons or hire a lawyer, the population the American scholar Virginia Eubanks calls the residents of the "digital poorhouse." The second is a jurisdictional gap with teeth. The federal Directive on Automated Decision-Making, the one rule that requires impact assessments and human review, reaches only federal departments and only public-facing systems. Welfare, policing, and the courts are overwhelmingly provincial. So the domains where automated decisions land hardest on the most vulnerable are largely the ones the country's main accountability instrument cannot touch. The Law Commission of Ontario's response was blunt: stop deploying high-risk government AI until there is a binding framework in law, because "systemic legal issues cannot be addressed through individual litigation, 'ethical AI' guidelines, or piecemeal legislation." Whether any province builds one is the open question. For now the safeguard of last resort is the ordinary administrative-law right to a real explanation, which is precisely what a black box cannot give.

---

Workplace AI surveillance — the CUPE primary documentation

The most significant Canadian AI surveillance issue in 2026 is workplace AI surveillance: the deployment of AI-powered monitoring tools by employers to track employee behaviour, productivity, communication, and (in some cases) emotional state. The Canadian Union of Public Employees has been the most consistent and best-resourced Canadian institutional voice on this issue, and the guide leans on CUPE's March 2026 Senate submission as the primary source.

The scope of what workplace AI surveillance now includes — drawn from CUPE's documentation and from broader Canadian and US reporting:

Keystroke monitoring. AI-powered systems that record every keystroke an employee makes, generate productivity scores based on typing patterns, and identify "idle time" when typing falls below thresholds. Deployed at scale at major Canadian financial institutions, call centres, and government departments. The Ontario Privacy Commissioner has issued guidance on the practice but no Canadian jurisdiction has prohibited it.

Communication monitoring. AI systems that scan employee email, chat, and (in some deployments) phone calls for content matching specified patterns — productivity indicators, compliance violations, "negative sentiment," union organizing language. Deployed at scale across the financial sector and increasingly in other regulated industries.

Movement and location tracking. AI systems that use badge access, security camera footage, and (in warehouse settings) wearable devices to track employee movements, time-on-task, and break duration. Amazon's warehouse worker monitoring has been documented extensively in the US; how much of the same tooling operates in its Canadian fulfilment centres is far less documented, and nothing in current Canadian law requires that documentation to exist.

Emotion and attention recognition. AI systems that use facial expression analysis, voice tone analysis, and biometric sensors to infer emotional state, engagement level, and stress. Marketed as "wellness" tools or "engagement" tools, deployed in call centres, healthcare settings, and increasingly in customer-facing service roles. The scientific validity of emotion recognition AI is contested (see Chapter 15), but commercial deployment is proceeding regardless.

Performance evaluation AI. Systems that aggregate the above inputs to produce composite "productivity scores," "engagement scores," or "risk ratings" for individual employees — often used as inputs to performance reviews, promotion decisions, discipline decisions, and termination decisions. The legal status of AI-driven employment decisions in Canada is mostly unregulated. Ontario's Working for Workers Act, effective January 1, 2026, requires employers with 25+ employees to disclose AI use in screening job applicants but does not regulate AI use in ongoing employment decisions.

CUPE's specific legal asks in the March 2026 Senate submission, drawn from the union's own document and presented in their own terms:

  • Ban the use of biometric, facial recognition, and emotion recognition AI systems in workplaces.
  • Prohibit significant employment decisions (hiring, promotion, discipline, termination, wage-setting) from being made based on AI output.
  • Require notification to workers when AI was used in any decision affecting them.
  • Mandate explanation of AI-driven decisions and human review and appeal mechanisms.
  • Require bias and discrimination audits of any AI system deployed in workplaces, both before deployment and annually after.
  • Stipulate that companies and organizations receiving public funding for AI development cannot use that funding while cutting jobs through AI deployment.

The bias label for these positions: civil society advocacy from an organization representing 800,000 Canadian workers by its own count, with substantial primary research and documented constituency interest. The lean is toward worker protection. The underlying evidence (documented surveillance practices, documented harms, documented technical capabilities already in use) is independently verifiable.

The federal response so far. AI for All does not commit to any of CUPE's asks. The AI and Labour Advisory Council announced by Minister Solomon (Chapter 5) is a consultation mechanism, not a regulatory commitment. Whether the advisory work produces binding rules is unresolved. The structural picture: Canada in 2026 has minimal regulation of workplace AI surveillance and the federal AI strategy does not commit to filling that gap. Quebec's Law 25 (next section) provides partial coverage for some practices through its broader privacy framework, but workplace-specific protections are limited.

---

Quebec Law 25 as the federal-government-of-last-resort

A pattern the guide has noted across multiple chapters is that Quebec, on AI-adjacent policy areas, has consistently moved earlier and more comprehensively than the federal government. The pattern holds in privacy. **Quebec's Law 25, the Act to modernize legislative provisions as regards the protection of personal information, passed September 2021 with implementation phased through 2024, is the most comprehensive Canadian privacy regime currently in force.**

What Law 25 provides, in practice:

Consent requirements for automated decision-making. Where an enterprise uses personal information to make a decision based exclusively on automated processing, the enterprise must inform the individual at the time of or before the decision, and on request must inform the individual of the personal information used, the reasons and principal factors leading to the decision, and the right to have the information corrected. This is the closest existing Canadian regulation to a general right to explanation of AI decisions.

Privacy Impact Assessment requirements. Enterprises must conduct privacy impact assessments before any project involving the acquisition, development, or significant change of an information system or electronic service delivery involving personal information. The assessment must be commensurate with the sensitivity of the information, the purposes, the quantity, the distribution, and the medium used.

Right to data portability. Individuals have the right to have their personal information communicated, in a structured, commonly-used technological format, to another person or entity.

Mandatory breach notification. Enterprises that have reasonable grounds to believe a confidentiality incident has occurred must notify the Commission d'accès à l'information and affected individuals.

Significant financial penalties for non-compliance. Up to CA$25 million or 4% of the enterprise's worldwide turnover for the previous fiscal year, whichever is higher. This is GDPR-equivalent enforcement scale.

The catch. Law 25 covers approximately 23% of the Canadian population (Quebec's share of national population), in one province. The federal government has not enacted equivalent protections. AIDA, the previous government's attempted federal AI regulation, died in January 2025 when Parliament was prorogued. AI for All does not commit to reviving AIDA or to enacting equivalent federal protections. Minister Solomon has publicly stated he will not revive AIDA in its previous form.

For Canadians outside Quebec, the privacy regime governing AI use is PIPEDA (federal private sector) and provincial private-sector privacy laws (BC, Alberta, Manitoba have private-sector privacy commissioners; other provinces are covered by PIPEDA federally). PIPEDA was drafted in 2000 and predates the consumer AI era by two decades. The OPC has been issuing AI-specific guidance interpretations of PIPEDA, but the underlying statute does not contain AI-specific provisions.

The practical asymmetry this produces. A Quebec resident interacting with an AI-driven decision system has, in principle, the right to be told the decision was AI-driven, to know what data was used, to know the principal factors, and to have the decision reviewed. A resident of any other Canadian province has, in most cases, none of these rights as a matter of statute. The asymmetry is not a feature of the federal AI strategy; it is the absence of a federal AI strategy on this specific question.

A useful frame for the rest of the guide: on AI privacy specifically, Quebec is the working baseline for what good Canadian regulation looks like, and Ottawa is not currently committed to matching it. Reasonable people disagree about whether Ottawa should match it (the federalist consideration), about whether Quebec's regime works well in practice (the evidence is mixed but generally positive), and about whether the model would scale to a national framework. The asymmetry between Quebec and the rest of the country, though, is a matter of record.

Beyond Quebec, several provinces have moved on specific AI-related privacy and governance matters worth noting briefly. This is not a single Quebec leadership against a uniform federal vacuum so much as a fragmented provincial landscape, and a handful of frameworks are worth knowing by name.

  • Ontario. The Enhancing Digital Security and Trust Act (EDSTA), in force since 2025, pairs public-sector AI governance with cybersecurity; its Responsible Use of AI Directive sets requirements for provincial deployment; a March 2026 proposal would extend the EDSTA framework further; and the Working for Workers Act (effective January 1, 2026) requires employers with 25+ employees to disclose AI use in hiring screening.
  • Manitoba. Bill 51, advancing through the legislature, would create an explicit public-sector AI and cybersecurity framework, making Manitoba one of the few Canadian legislatures with AI-specific legislation in play; its outcome is not yet determined.
  • Nova Scotia. The Personal Information International Disclosure Protection Act (PIIDPA) supplies what is, in the reviewed sources, the clearest statutory public-sector data-residency rule among major Canadian provinces — public bodies and municipalities must keep personal information in Canada absent specific exceptions — making its data-residency baseline the strongest provincial provision the guide documents, even if its AI-specific governance lags Ontario's.
  • British Columbia and Alberta. BC's Freedom of Information and Protection of Privacy Act (FIPPA) section 33.1 governs offshore disclosure by public bodies (the earlier blanket prohibition was repealed in 2021, replaced by a conditional regime), while BC's Personal Information Protection Act (PIPA) and Alberta's Personal Information Protection Act (PIPA) cover their respective provincial private sectors; none of these contains AI-specific provisions equivalent to Quebec's Law 25, and Alberta's engagement has run mainly through skills and ecosystem investment (Amii) rather than binding regulation.

The throughline: there is no comprehensive federal private-sector AI privacy law, and Quebec's Law 25 remains the baseline the rest of the country is measured against.

ALIGNMENT — whose rules even reach this? When an AI system makes a decision about you, your protection depends less on the technology than on where you live and who you work for. Quebec's Law 25 gives you a right to an explanation; federal PIPEDA, drafted in 2000, mostly doesn't; a sector regulator might, or might not. Before asking whether the decision was fair, find out whether any rule reaches it at all.

The structural picture. Canadian AI privacy regulation is fragmented across federal PIPEDA (2000-vintage, no AI-specific provisions, with OPC interpretive guidance), Quebec's Law 25 (the strongest framework, covering 23% of the population), Ontario's EDSTA and Responsible Use Directive (public sector focus, with March 2026 modernization proposals), Manitoba's Bill 51 (under consideration), Nova Scotia's PIIDPA (strongest residency baseline), BC's FIPPA and PIPA (post-2021 offshore-disclosure framework), and Alberta's PIPA (general private sector, no AI specifics). The fragmentation is the regulatory environment Canadians actually live in. Where you live in Canada substantially determines what AI privacy protections you have. The federal AI strategy does not commit to closing this fragmentation through harmonized federal-provincial action.

---

The biometric and facial recognition layer

One surveillance category deserves separate treatment because the technical capability is now substantially ahead of the regulatory framework: biometric identification and facial recognition AI.

The technical capability, in 2026, is mature. Commercial facial recognition systems can identify individuals with near-perfect accuracy under good conditions (well-lit, frontal images, high-quality cameras), and with substantially-reduced-but-still-usable accuracy under degraded conditions (low light, partial occlusion, low-quality images, side angles). The systems can match against databases of millions of faces in milliseconds. The training data for these systems is, as Chapter 3 covered, drawn substantially from public-internet images — including images of individuals who did not consent to be in facial recognition training data.

The Clearview AI case is the most-documented Canadian instance. Clearview AI, a US-based company, scraped approximately 3 billion images from public-internet sources (Facebook, Instagram, Twitter/X, LinkedIn, employer websites, news sites, photographer portfolios) without consent of the individuals depicted or the platforms hosting the content. The company built a commercial facial recognition service marketed primarily to law enforcement. The Office of the Privacy Commissioner of Canada, jointly with provincial counterparts, found in February 2021 that Clearview AI's collection, use, and disclosure of personal information without consent violated Canadian privacy laws. Clearview was ordered to cease offering its service in Canada and to delete the images of Canadians in its database. The company contested the order. Multiple Canadian law enforcement agencies, the RCMP and Toronto Police among them, had used Clearview AI before the order, in some cases without explicit authorization from their own oversight bodies. This is the documented Canadian baseline: a US facial recognition system, trained on non-consenting Canadian images, used by Canadian police without proper oversight, found to violate Canadian privacy law, with enforcement of the violation finding still partially unresolved.

The structural questions this raises:

What about consensual deployment? Commercial deployment of facial recognition by retailers, building managers, transit systems, and event venues is increasingly common in Canada. The legal status varies by province and by specific deployment context. Quebec's Law 25 covers some of this; PIPEDA covers some of this; municipal regulations cover almost none of it. The OPC has been issuing guidance but the deployments outpace the guidance.

What about live facial recognition? Real-time facial recognition (as distinct from forensic comparison of stored images after the fact) raises additional concerns about mass surveillance, chilling effects on public assembly, and concentration of power. The European Union AI Act categorically prohibits real-time biometric identification in publicly accessible spaces for law enforcement purposes with narrow exceptions. Canada has no equivalent prohibition. Canadian law enforcement has not publicly disclosed extensive real-time facial recognition deployment, but the technical capability exists, and the regulatory absence means deployment can proceed without specific authorization.

What about emotion recognition AI? Already discussed in Section 3 as a workplace surveillance concern, the same systems are being deployed in border security, anti-fraud systems, and customer-facing services. The scientific validity is contested (research by Lisa Feldman Barrett and others has substantially undermined the claim that universal facial expressions reliably indicate specific emotions), but the commercial systems are sold and deployed regardless. The EU AI Act prohibits emotion recognition in workplaces and educational settings. Canada has no equivalent prohibition.

The cumulative picture: facial recognition, biometric identification, and emotion recognition AI are categories where the technical capability has substantially outpaced the regulatory framework in Canada. The OPC and provincial commissioners are doing meaningful work, but they're constrained by statutes that predate the technology. Comprehensive AI-specific privacy and biometric regulation is exactly what AIDA would have provided. AIDA's failure left the gap. AI for All does not commit to filling it.

A live test of exactly this is arriving with the 2026 FIFA World Cup. For the Vancouver matches, the city plans to stand up as many as 200 new monitored cameras and integrate roughly 1,000 existing ones, on a security budget reported around $242 million. What makes it notable is the guardrail: the camera network carries an express prohibition on facial recognition, biometric analysis, and any automated identification of individuals, with a privacy impact assessment done alongside the provincial commissioner. It is one of the rarer Canadian cases where the rule arrived with the cameras rather than years behind them. The open question is whether the prohibition holds under operational pressure, or quietly erodes the way "temporary" surveillance so often becomes permanent.

The larger 2026 surveillance story is not AI-specific, and that is exactly why it belongs here. Bill C-22, the Lawful Access Act, would require providers to retain up to a year of Canadians' metadata (browsing, location, the time and targets of communications) and, in its Part 2, let the Minister of Public Safety issue secret orders compelling providers to build government access into their systems, under permanent gag rules and limited judicial check. Civil-society groups (OpenMedia, the Electronic Frontier Foundation, the Center for Democracy and Technology) call it an encryption-backdoor bill and want it withdrawn; the Privacy Commissioner took a narrower line, welcoming some of the bill's tailoring while pressing for necessity-and-proportionality limits and explicit protection against weakening encryption. Read the distance between those two positions as the bias map in action: both are privacy-protective, but one is campaigning and one is advising, and they are not saying the same thing. The AI connection is the substrate. Mass-retained metadata is precisely the dataset machine analysis turns from storage into surveillance, so a bill that never mentions AI still sets the outer limit of what AI surveillance in Canada will be allowed to see.

---

AI companions — the surveillance you confide in

Most of this chapter has been about data collected about you, often without your active participation. AI companions invert that. They are built to have you volunteer your most intimate thoughts, and to keep you coming back to do it.

What they are: AI companion and "AI friend" apps (Replika, Character.AI, and a fast-growing field) present a chatbot persona (a friend, a partner, a confidant, sometimes a stand-in therapist) that converses naturally, remembers what you told it, and is available at 3 a.m. when no one else is. Adjacent to them are AI "therapy" and mental-health chatbots marketed for emotional support. For some lonely or isolated people the comfort is real, and this guide does not dismiss that.

But look at the data relationship, because it is unlike anything else in this chapter. A person talking to an AI companion discloses loneliness, sexuality, relationship details, mental-health struggles, and moments of crisis, the most sensitive categories of personal information there are, to a commercial product whose business model usually depends on maximizing engagement. The intimacy is the extraction mechanism. Every disclosure is data; the system is optimized to elicit more of it; and what happens to that data (how it is stored, who can access it, whether it trains the next model in Chapter 3, what a breach would expose) is governed in Canada by the same aging PIPEDA framework that Section Four showed is already behind on far less sensitive information.

🧌 GOBLIN CHECK — A free app that wants to be your closest friend is not a charity; it is a business, and your secrets are the inventory. Before you confide in one, the goblin asks the unsentimental questions: is it optimized to help you, or to keep you here? Where does everything you tell it go? And if you said you were in crisis at 3 a.m., is there anyone — anyone at all — responsible for what it says back?

Then there is the harm that is not about data at all: dependency and manipulation, and it falls hardest on the young. A system engineered to be maximally engaging, agreeable, and always available is, for an adolescent or an isolated or struggling person, engineered to be hard to leave. The stakes stopped being hypothetical with Garcia v. Character.AI, a wrongful-death suit filed in 2024 after a 14-year-old died by suicide following an intense attachment to a companion bot; Google and Character.AI agreed to settle it in January 2026, and Character.AI has since barred users under 18 from open-ended chat. The deepfake harms of Chapter 13 are things done to a person's image; this is a harm that works through a relationship the person values, which makes it both harder to see and harder to regulate.

The Canadian regulatory picture is close to blank. No Canadian law specifically governs AI companions: not their data practices beyond general PIPEDA, not marketing claims (an app may imply therapeutic benefit without meeting any clinical standard), not age-appropriate design, not any duty of care when a user is in crisis. Bill C-16 (Chapter 13) reaches sexual deepfakes, not companion bots. Quebec's Law 25 gives Quebec users stronger data rights than other Canadians have, but it was not written with this in mind. So the most intimate AI product category, the one people pour their inner lives into, is among the least specifically regulated.

The synthesis: AI companions are a real comfort to some people and a real risk to others; the risk concentrates on the young and the vulnerable; and Canada currently regulates the category almost by accident, through privacy law that was not designed for it and a youth-safety regime (C-16) that points elsewhere. The portable question, when an app offers to be your friend or your therapist: what is it optimized for, what happens to everything you tell it, and who is responsible if it tells a person in crisis the wrong thing?

---

The post-AIDA regulatory gap

The Artificial Intelligence and Data Act (AIDA) was introduced in 2022 as Part 3 of Bill C-27, the Trudeau government's attempted comprehensive privacy and AI regulatory package. AIDA would have provided:

  • A federal framework for AI systems classified by risk level
  • Mandatory requirements for "high-impact" AI systems including algorithmic impact assessments, transparency measures, and human oversight
  • New offences and penalties for serious harms from AI systems
  • A regulator (the proposed AI and Data Commissioner) with enforcement authority
  • Requirements for AI providers operating in Canada

AIDA faced substantial criticism from multiple directions during its parliamentary review. Industry voices criticized the breadth of definitions and the regulatory burden. Civil society voices criticized the limited consultation, the absence of Indigenous perspectives in development, and the gaps in protection for marginalized communities. Academic voices criticized the inconsistency with the European Union's AI Act and the under-resourced enforcement model. Almost everyone criticized AIDA for different reasons, and the result was that the bill died when Parliament was prorogued in January 2025, leaving Canada without comprehensive federal AI regulation.

Minister Solomon has publicly stated that AI for All will not include reviving AIDA. Some elements may appear in future legislation but no specific framework has been announced. The federal AI regulatory picture as of mid-2026:

  • Treasury Board AI Register — applies to federal public service AI use, with the scope limits documented in Section 2.
  • PIPEDA — federal private-sector privacy law, drafted in 2000, with OPC interpretations applying to AI but no AI-specific provisions.
  • Bill C-16 (Protecting Victims Act) — introduced December 2025 and enacted June 18, 2026, with most provisions coming into force July 18, 2026; addresses sexual deepfakes specifically (see Chapter 13), not broader AI privacy or surveillance.
  • Sectoral regulations — Ontario's Working for Workers Act (AI hiring screening disclosure), individual provincial regulations on specific topics.
  • Provincial privacy laws — Quebec Law 25 (most comprehensive), BC/Alberta/Manitoba private-sector laws.
  • Common-law remedies — constitutional Charter challenges, tort claims, copyright lawsuits, all proceeding case by case.

This is among the most fragmented AI regulatory environments of any major OECD jurisdiction, with only the American state-by-state patchwork offering serious competition for the title. The European Union has the AI Act (effective August 2024, with phased implementation). The United Kingdom has a pro-innovation framework with sector-specific regulators. The United States has a patchwork of state laws (California, Colorado, others) and federal executive orders. China has comprehensive AI regulation through multiple agencies. Australia, Singapore, Japan, and South Korea all have national AI strategies with regulatory components.

Canada's regulatory absence is the result of a specific political path, not an accident: AIDA's failure, the political-economy choices about which legislative priorities to pursue, the calculation that AI for All's investment strategy could be advanced without binding the federal government to a regulatory regime. The absence is also the structural condition the rest of this chapter is responding to. Workplace surveillance, biometric deployment, inferential extraction, third-party AI in contracted services: all of these proceed in Canada with regulatory protections substantially weaker than peer countries.

A note on what Canada does have that other countries don't always have. The Office of the Privacy Commissioner, despite the dated statutes it operates under, has been a relatively assertive and well-respected regulator. Provincial privacy commissioners, particularly in Quebec, BC, and Ontario, have done substantial work. The Office of the Auditor General has begun examining federal AI use. The judiciary has begun receiving AI-related cases. These are real institutional resources, even within the absence of comprehensive federal AI legislation. Canada does have an institutional response; the gap is that it isn't proportionate to the deployment scale.

---

The working test

The working test the guide asks readers to apply to any specific AI privacy or surveillance claim — whether from a corporation, a government, or a coverage piece:

Collection. What data is being collected? Explicit, implicit, inferential? Is the consent meaningful (i.e., was there a real alternative to consenting), or is the consent perfunctory (a checkbox required to access a service)?

Inference. What inferences are being drawn from the data? Have those inferences been disclosed to the individual? Are the inferences subject to the same privacy protections as the underlying data?

Use. What decisions or actions are based on the data and inferences? Are the uses limited to the purposes disclosed at collection, or have they expanded?

Disclosure. Who has access to the data, the inferences, and the decisions? Internal employer, government, contractor, third party, foreign jurisdiction?

Oversight. Is the deployment subject to specific regulatory oversight? Is there an algorithmic impact assessment? Is there a privacy commissioner reviewing it? Is there meaningful appeal or recourse?

Verification. Can the disclosures the deploying entity makes about privacy and use be independently verified, or are they self-reported?

The test is structurally similar to the working test in Chapter 3 (training data) and the sovereignty test in Chapter 9, because the underlying methodology is the same: name what's actually happening on the ground, name the gaps in disclosure, name the gaps in regulation, and let readers decide whether the gaps are acceptable.

---

Where the privacy gap sits

CHAPTER RECAP — you now have: - The distinction between privacy (information disclosed without consent) and surveillance (systems of ongoing monitoring built around information collection) clarified at the conceptual level, and the inferential-extraction layer — what AI can infer from data that on its own wasn't sensitive — named as the structurally novel privacy problem AI creates. - The federal Treasury Board AI Register's coverage (42 institutions, 400+ systems disclosed, the 1994 historical anchor) and its scope limits (national security, low-risk commercial products, contractor-deployed AI, sub-federal AI all excluded). - Workplace AI surveillance anchored in CUPE's March 2026 Senate submission, with the specific deployment categories (keystroke monitoring, communication monitoring, movement tracking, emotion recognition, performance evaluation AI) and CUPE's specific legal asks named in their own terms. - Quebec's Law 25 as the operational baseline for what good Canadian AI privacy regulation looks like, covering 23% of the Canadian population, with the right to explanation of automated decisions and GDPR-equivalent penalties for non-compliance. - The biometric and facial recognition layer with the Clearview AI case as the documented Canadian baseline, the EU AI Act prohibitions named as the international comparator, and the regulatory gap in Canadian deployment of facial recognition and emotion recognition AI explicitly identified. - The post-AIDA regulatory gap named as among the most fragmented AI regulatory environments in the OECD, with the institutional resources (OPC, provincial commissioners, judiciary) that do exist credited within the broader gap. - AI companions and therapy chatbots as "the surveillance you confide in" — intimate disclosure as the extraction mechanism, plus dependency and youth-safety harms (the Garcia v. Character.AI wrongful-death suit, settled January 2026), against a near-blank Canadian regulatory picture: general PIPEDA only, no companion-specific data, marketing, age-design, or duty-of-care rules, and Bill C-16 pointed elsewhere. - The working test for evaluating any AI privacy or surveillance claim: collection, inference, use, disclosure, oversight, verification.

The next chapter (Chapter 11) takes the personal-sovereignty material that runs through Chapter 9 and this chapter, and goes deep on the specific IP and copyright contest: the Canadian newspapers' lawsuit against OpenAI, the Writers' Union of Canada and ACTRA positions, the academic disagreement between Carys Craig and Michael Geist on text-and-data mining exceptions, and the Beijing Treaty argument for performer rights. The personal sovereignty layer that this chapter has surveyed at the privacy and surveillance level gets its IP-specific deepening in Chapter 11.

You can now read any Canadian AI privacy or surveillance claim with the equipment to ask the right questions and to recognize the regulatory gaps as structural rather than incidental. Most current claims will fail most of those questions. Whether the failures should be addressed by policy, by sectoral regulation, by litigation, by collective bargaining, or by individual choice is contested. That the failures exist is empirical.

---

Bias label for this chapter: privacy-and-surveillance-focused analysis of the Canadian AI regulatory environment, with explicit naming of the gaps between technical capability and regulatory protection. Author lean: skeptical of "we comply with applicable laws" framings that elide the gaps in the applicable laws; sympathetic to the broader European and Quebec models of comprehensive privacy and AI regulation; willing to name workplace AI surveillance as a structurally significant Canadian deployment area despite its relative absence from federal AI strategy framing; explicit about the limits of inferring deployment specifics from primarily-civil-society documentation. Government framing (Treasury Board, ministerial statements) treated as primary on policy commitments and labelled accordingly. Civil society documentation (CUPE) treated as primary on deployment practices in member workplaces. Quebec regulatory documentation treated as primary on Law 25. The Office of the Privacy Commissioner of Canada's findings (Clearview AI investigation, others) treated as primary on the documented Canadian regulatory record.

Primary sources cited or relied on in this chapter: Treasury Board of Canada Secretariat, AI Register and AI Strategy for the Federal Public Service (November 28, 2025); Personal Information Protection and Electronic Documents Act (PIPEDA), federal Canada; An Act to modernize legislative provisions as regards the protection of personal information (Law 25), Quebec; CUPE Senate Brief (March 2026); Office of the Privacy Commissioner of Canada, joint findings on Clearview AI (February 2021); Office of the Privacy Commissioner of Canada AI guidance documents; Office of the Privacy Commissioner of Canada 2024-25 privacy opinion research and 2025-26 business survey; Ontario Working for Workers Act (effective January 1, 2026); Ontario Enhancing Digital Security and Trust Act (EDSTA) and March 2026 modernization proposals; Ontario Responsible Use of AI Directive; Manitoba Bill 51 documentation; Nova Scotia Personal Information International Disclosure Protection Act (PIIDPA); British Columbia Freedom of Information and Protection of Privacy Act (FIPPA) section 33.1 and Personal Information Protection Act (PIPA); Alberta Personal Information Protection Act (PIPA); European Union Artificial Intelligence Act (effective August 1, 2024); Bill C-27 / AIDA documentation (2022-2025); Bill C-16 Protecting Victims Act (December 9, 2025); Lisa Feldman Barrett research on emotion recognition validity. Detailed citations in the Sources appendix.

---

🧌 GOBLIN CHECK — You never told anyone about the headaches. You told a search bar, a video site, and a checkout cart — separately, innocently, like a person living a life. The inference engine's entire job is introducing your data points to each other at a party you weren't invited to. Consent forms cover the data points. Nothing currently covers the introductions.

🧌 GOBLIN CHECK — A free app that wants to be your closest friend is not a charity; it is a business, and your secrets are the inventory. Before you confide in one, the goblin asks the unsentimental questions: is it optimized to help you, or to keep you here? Where does everything you tell it go? And if you said you were in crisis at 3 a.m., is there anyone — anyone at all — responsible for what it says back?

Recap

  • The distinction between privacy (information disclosed without consent) and surveillance (systems of ongoing monitoring built around information collection) clarified at the conceptual level, and the inferential-extraction layer — what AI can infer from data that on its own wasn't sensitive — named as the structurally novel privacy problem AI creates.
  • The federal Treasury Board AI Register's coverage (42 institutions, 400+ systems disclosed, the 1994 historical anchor) and its scope limits (national security, low-risk commercial products, contractor-deployed AI, sub-federal AI all excluded).
  • Workplace AI surveillance anchored in CUPE's March 2026 Senate submission, with the specific deployment categories (keystroke monitoring, communication monitoring, movement tracking, emotion recognition, performance evaluation AI) and CUPE's specific legal asks named in their own terms.
  • Quebec's Law 25 as the operational baseline for what good Canadian AI privacy regulation looks like, covering 23% of the Canadian population, with the right to explanation of automated decisions and GDPR-equivalent penalties for non-compliance.
  • The biometric and facial recognition layer with the Clearview AI case as the documented Canadian baseline, the EU AI Act prohibitions named as the international comparator, and the regulatory gap in Canadian deployment of facial recognition and emotion recognition AI explicitly identified.
  • The post-AIDA regulatory gap named as among the most fragmented AI regulatory environments in the OECD, with the institutional resources (OPC, provincial commissioners, judiciary) that do exist credited within the broader gap.
  • AI companions and therapy chatbots as "the surveillance you confide in" — intimate disclosure as the extraction mechanism, plus dependency and youth-safety harms (the Garcia v. Character.AI wrongful-death suit, settled January 2026), against a near-blank Canadian regulatory picture: general PIPEDA only, no companion-specific data, marketing, age-design, or duty-of-care rules, and Bill C-16 pointed elsewhere.
  • The working test for evaluating any AI privacy or surveillance claim: collection, inference, use, disclosure, oversight, verification.

Sources

  • Treasury Board of Canada Secretariat, AI Register and AI Strategy for the Federal Public Service (November 28, 2025)
  • Personal Information Protection and Electronic Documents Act (PIPEDA), federal Canada
  • An Act to modernize legislative provisions as regards the protection of personal information (Law 25), Quebec
  • CUPE Senate Brief (March 2026)
  • Office of the Privacy Commissioner of Canada, joint findings on Clearview AI (February 2021)
  • Office of the Privacy Commissioner of Canada AI guidance documents
  • Office of the Privacy Commissioner of Canada 2024-25 privacy opinion research and 2025-26 business survey
  • Ontario Working for Workers Act (effective January 1, 2026)
  • Ontario Enhancing Digital Security and Trust Act (EDSTA) and March 2026 modernization proposals
  • Ontario Responsible Use of AI Directive
  • Manitoba Bill 51 documentation
  • Nova Scotia Personal Information International Disclosure Protection Act (PIIDPA)
  • British Columbia Freedom of Information and Protection of Privacy Act (FIPPA) section 33.1 and Personal Information Protection Act (PIPA)
  • Alberta Personal Information Protection Act (PIPA)
  • European Union Artificial Intelligence Act (effective August 1, 2024)
  • Bill C-27 / AIDA documentation (2022-2025)
  • Bill C-16 Protecting Victims Act (December 9, 2025)
  • Lisa Feldman Barrett research on emotion recognition validity.