The previous chapters have repeatedly returned to one finding: on multiple AI policy dimensions, Canada in 2026 has weaker regulatory protections than peer jurisdictions, with the gaps concentrated in specific identifiable places — political deepfakes, comprehensive privacy frameworks for AI, mandatory data-centre disclosure, training-data consent requirements, workplace AI surveillance limits, Indigenous data sovereignty integration. Each chapter has noted the gap relevant to its specific topic. This chapter steps back and asks the institutional question: how is AI actually governed in Canada, and why does the regulatory landscape look the way it does? The answer is that Canada's AI governance is fragmented across federal departments, provincial jurisdictions, sectoral regulators, professional bodies, and international commitments, without a comprehensive coordinating framework, without a designated AI regulator, and without the binding legislative authority that comparable jurisdictions have established. The federal AI for All strategy is investment-focused rather than regulatory-focused. The Artificial Intelligence and Data Act (AIDA) that would have established comprehensive federal AI regulation died with Parliament's January 2025 prorogation, and the Carney government has not committed to reviving it. The result is the institutional environment the rest of the guide's analysis has been operating against. One federal bill is moving, though it is online-harms legislation rather than AI law. In June 2026 the Carney government tabled the Digital Safety Act, Ottawa's fourth attempt at online-harms regulation since 2021. Its headline is a ban on social-media accounts for Canadians under 16, with platforms able to apply for an exemption if they can show adequate safeguards; it would also create a Digital Safety Commission of Canada, a standing federal digital regulator of a kind the AI file has so far done without. It is worth watching for two reasons. First, it is the clearest current test of whether Ottawa can stand up a digital regulator with real authority rather than another voluntary code. Second, it sits in the familiar gap between announced and operational: officials concede the under-16 ban would realistically not apply until late 2027 or 2028, once the bill passes and the commission is built. The AI connection is indirect but real, because the harms it targets (recommender systems tuned for engagement, the data they harvest on minors) are AI systems, and a commission built for digital safety is the kind of body a future AI mandate could later be handed to. Three earlier attempts died before passing; whether this one survives the same competing pressures is the open question. This is not the same as saying Canada has no AI governance. Multiple institutional resources are working on AI policy: the Office of the Privacy Commissioner, provincial privacy commissioners, the Treasury Board (within the federal public service), sectoral regulators (CRTC, OSFI, Health Canada, others), the Auditor General, the judiciary. The institutional resources are real. They are also working without the comprehensive coordinating framework that AI policy at the current scale of deployment would typically require, and the guide asks readers to track both facts simultaneously. You will leave with several things. The federal-provincial split that shapes Canadian AI governance, and what it implies for any comprehensive framework. The specific federal departments and institutions doing AI policy work — Treasury Board, ISED, Justice, the Privacy Commissioner, the three AI institutes, CAISI. The failed AIDA backstory and what its absence means operationally. The international frameworks Canada has signed and has not signed, and the comparative international landscape they sit in. The structural pattern of Canadian governance via sectoral regulators rather than comprehensive law. And the institutional pathways that exist for closing the documented governance gaps. ---
The federalist constraint
Canadian AI governance starts with a constitutional structure that most international comparisons don't fully engage. The Canadian Constitution divides jurisdictional authority between the federal government and the provinces in ways that fundamentally shape what AI governance can be enacted at which level.
Federal jurisdiction relevant to AI includes: criminal law (giving Ottawa authority over criminal AI uses — Bill C-16 sits in this category); trade and commerce, including the federal private-sector privacy framework (PIPEDA); copyright (the Canadian newspapers v. OpenAI case will turn on federal copyright law); telecommunications regulation (giving the CRTC authority over some AI deployment in telecom and broadcast); aspects of competition law (relevant to AI market concentration); and federal employment (relevant to AI deployment in the federal public service).
Provincial jurisdiction relevant to AI includes: most employment regulation outside the federal public service; healthcare (where most AI healthcare deployment occurs); education (including AI in schools and post-secondary institutions); most consumer protection; provincial privacy law in some provinces (Quebec, BC, Alberta, Manitoba); the administration of justice in most matters; and most general civil law including the tort and contract framework that AI-related disputes navigate.
The practical implication: federal AI legislation cannot directly regulate most healthcare AI, most workplace AI, most educational AI, most consumer-facing AI in regulated sectors, or most provincial government AI deployment. The federal level can establish frameworks that apply within its jurisdiction (criminal law, federal public service, federally-regulated industries) and can attempt to influence provincial policy through funding incentives, coordination agreements, and voluntary frameworks. It cannot directly impose comprehensive AI regulation on provincially-regulated activity.
This is the structural reason Quebec's Law 25 (Chapter 10) covers about 23% of the Canadian population in ways the federal government cannot mandate for the other 77%, and why the Quebec-leads-Ottawa-follows pattern the guide has documented across multiple chapters is constitutionally significant rather than accidental. Provincial governments have the constitutional authority to regulate AI in domains the federal government cannot reach directly; some provinces (Quebec most prominently) have used that authority; others have not.
🧌 GOBLIN CHECK — Every "why doesn't Canada just pass the EU AI Act?" take runs aground on the same rock: 1867. Healthcare, employment, education — the places AI actually touches a life — are mostly provincial turf. The goblin didn't make the rules. The goblin merely notes that anyone selling you a one-statute fix hasn't read the Constitution Act, and probably shouldn't be selling you anything.
This is also the structural reason the European Union's AI Act provides a model that is not directly applicable to Canada at the federal level. The EU AI Act regulates AI deployment across many sectors (healthcare, education, employment, consumer-facing applications) that in Canada are provincial jurisdiction. Adopting equivalent Canadian regulation would require either provincial cooperation (formal agreements among the federal government and provinces, of the kind that exist for some other domains like climate policy and labour markets) or constitutional reinterpretation that the current government has not signalled appetite for.
The constraint is real. Canadian AI regulation cannot match the EU's comprehensive scope at the federal level alone. Whether it could match that scope through coordinated federal-provincial action is a separate question with its own political and institutional complexity. AI for All does not commit to that coordinated approach.
---
The federal institutional landscape
Within federal jurisdiction, AI policy is distributed across multiple departments and institutional bodies, each with its own mandate, expertise, and accountability structure. The roster matters less than the pattern it produces, so this section maps the institutions by what they actually do and where their authority runs out.
The lead is Innovation, Science and Economic Development Canada (ISED), which runs AI for All, manages the Pan-Canadian AI Strategy alongside CIFAR and the three institutes, oversees the AI Compute Access Fund, and is the policy lead on AI-specific regulation when such regulation is contemplated. ISED is structurally an industrial-strategy department, and its institutional culture leans toward economic development rather than regulatory protection of citizens. That lean is not a criticism (ISED is doing what its mandate directs), but it shapes the framing of federal AI conversations toward enabling development and deployment.
The Treasury Board of Canada Secretariat owns the internal-use track: the AI Strategy for the Federal Public Service, the AI Register launched in November 2025, the procurement framework, the Algorithmic Impact Assessment requirement, and the directive on automated decision-making. Its authority over how federal departments acquire and use AI is real, and many of Canada's most significant AI governance commitments to date have arrived this way (through directives that can be issued without legislation), but it does not extend to the broader economy or to provincial governments.
Justice Canada handles criminal-law AI policy, including Bill C-16 (Chapter 13). Its role is reactive by design: criminal law engages AI primarily when specific harms require a response, operating after the fact through prosecution rather than establishing the proactive framework comprehensive governance would require. The Office of the Privacy Commissioner (OPC), an independent officer of Parliament, is one of Canada's most established AI-relevant institutions — it has issued AI guidance interpreting PIPEDA, conducted high-profile investigations (Clearview AI, the Tim Hortons app, others), and engaged in international privacy coordination. But its enforcement authority is bounded by a statute drafted in 2000 that contains no AI-specific provisions, so it interprets old law rather than enforcing new. Privacy Commissioner Philippe Dufresne has called for substantial PIPEDA modernization including AI-specific provisions; the legislative reform has not been delivered.
Several departments cover narrower slices. Canadian Heritage owns cultural policy including copyright, where the AI-training question meets the creative sector (Chapter 11); its creator-oriented framework has produced some intra-government tension with ISED's industrial lean. National Defence and Public Safety cover national-security AI: military, intelligence (CSIS, CSE), and RCMP deployment. Most of it is excluded from the AI Register and operates under classified or limited-disclosure frameworks, making it the largest documented exclusion from Canadian AI transparency — one the federal strategy does not engage. Health Canada regulates AI medical devices coming to market while most clinical deployment sits in provincial systems, placing healthcare AI squarely in the federal-provincial overlap.
The research-and-safety layer runs through CIFAR and the three AI institutes (Mila, Vector, Amii), with AI for All committing over $200M across them plus the Canadian AI Safety Institute (CAISI), itself committed at $50M and partnered with the institutes, CIFAR, and the National Research Council. The institutes do research, talent development, and increasingly commercialization and policy advisory work; the Chapter 7 bias label applies, since they are federally-funded AI for All beneficiaries. CAISI is too new to have a documented track record, and its eventual contribution will depend on its leadership, mandate clarity, and independence from the institutes it partners with.
Rounding out the picture: Statistics Canada supplies the empirical baseline (the 31% finding from Chapter 16, the adoption rates, the labour-market data), backed by a 2025 budget commitment of $25M over six years to its AI and Technology Measurement Program — meaningful but modest. The Auditor General, an independent officer of Parliament, has begun examining federal AI deployment, one of the few mechanisms producing systematic independent assessment. And a set of sectoral regulators carry AI-relevant mandates within their domains: the CRTC in broadcasting and telecommunications, OSFI in federally-regulated financial institutions, the Canadian Human Rights Commission through discrimination cases. Each issues guidance within its lane; none is positioned to provide comprehensive AI governance.
The structural picture. Canadian federal AI governance is performed by a distributed set of institutions, each with partial mandate and partial authority over AI matters in its domain. No single federal institution has comprehensive AI governance authority. AIDA would have established such a regulator (the AI and Data Commissioner), and its failure left a comprehensive-regulator gap that the distributed-institution model does not fully fill.
<!-- DIAGRAM TODO (interactive edition): governance map — who regulates what across federal (ISED/TBS/Justice/OPC/sectoral regulators), provincial (Quebec Law 25, Ontario EDSTA, etc.), and the gaps in between. Pairs with the worked example in Section Six. Figure 16.1 -->
---
AIDA and the post-AIDA regulatory gap
The Artificial Intelligence and Data Act (AIDA) was the cornerstone of the previous Trudeau government's attempted federal AI regulation, introduced in 2022 as Part 3 of Bill C-27. The chapter has noted AIDA's failure repeatedly across previous chapters; this section engages it directly as the central institutional fact shaping Canadian AI governance in 2026.
What AIDA would have provided. A federal risk-based framework for AI systems classified as "high-impact" — defined to include AI used in employment, biometric identification, content moderation, and other consequential applications. Mandatory algorithmic impact assessments for high-impact AI. Transparency requirements for organizations deploying high-impact AI. New offences and penalties for serious harms from AI. A new federal regulator (the AI and Data Commissioner) with enforcement authority. Coordination provisions with provincial privacy regulators.
Why AIDA failed. Multiple factors operated at once, and a full accounting requires naming all of them rather than reducing the failure to a single cause:
First, the bill was introduced without adequate prior consultation, particularly with Indigenous communities, civil society organizations, and worker representatives. The consultation process improved substantially during parliamentary committee study, but the early framing damaged the bill's political coalition.
Second, the bill's definitions were broad and somewhat vague: "high-impact AI" was defined in ways that produced uncertainty about which deployments would be covered. Industry submitters criticized the breadth; civil society submitters criticized the loopholes the breadth might allow.
Third, the bill's enforcement model, through a new commissioner with limited resources, was criticized as both underpowered (civil society) and as overpowered (industry), depending on which provisions readers focused on.
Fourth, the bill was packaged together in Bill C-27 with comprehensive privacy reform (CPPA) and a privacy tribunal framework. The package's overall complexity slowed legislative progress.
Fifth, the January 2025 prorogation of Parliament (under the Trudeau government) killed Bill C-27 along with all other government bills not yet passed. The bill was procedurally dead at that point regardless of substantive debate.
Sixth, the Carney government has not committed to reviving AIDA. Minister Solomon has stated publicly that AIDA in its previous form will not be reintroduced. Some elements may appear in future legislation; no specific framework has been announced.
The post-AIDA institutional reality. Canada has no comprehensive federal AI-specific statute in force. Specific AI-related federal action has occurred (Bill C-16, the AI Register, various sectoral regulator guidance) but no equivalent to the EU AI Act, the UK Online Safety Act, Australia's eSafety Commissioner framework, Singapore's PDPA-plus-AI-Governance-Framework approach, or the various US state-level frameworks. The Office of the Privacy Commissioner operates under a 2000-vintage privacy statute. The Treasury Board's federal-public-service AI policy is internal-government-facing. Provincial regulation varies dramatically — Quebec's Law 25 covers some AI matters in Quebec; most provinces have substantially less.
The voluntary-framework layer. Between AIDA's failure and AI for All's investment-focused framing, the federal government has pursued a voluntary-framework path. The Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems, launched by ISED in September 2023, had Ada, BlackBerry, Cohere, Coveo, OpenText, and TELUS as signatories from launch. CGI, IBM, Mastercard, Salesforce, and others joined subsequently. Microsoft is not among them as of June 2026. The Code commits signatories to accountability, safety, fairness, transparency, human oversight, and validity-and-robustness standards in advanced generative AI development and deployment. It is voluntary: no enforcement mechanism, no penalty for non-compliance, no mandatory disclosure. The Code sits in the gap between failed comprehensive legislation and statutory regulation. It is a real federal AI governance instrument that exists in the institutional landscape but does not bind signatories to specific requirements. Treating it as a substantive governance mechanism mistakes voluntary commitment for binding regulation; treating it as nothing misses one of the federal government's actual institutional choices in the AI policy space. It is a voluntary framework, with the limits voluntary frameworks structurally have.
GOBLIN FACTS — count the signatures, then count the teeth. ISED's Voluntary Code of Conduct on generative AI had 46 signatories as of June 2026 and zero enforcement: no penalty, no audit, no mandatory disclosure. Microsoft had not signed at all. A signatory list tells you who was willing to be seen signing. It doesn't tell you what happens when someone breaks the code, because nothing does.
The political-economy reading. The Carney government's choice not to revive AIDA, combined with the AI for All strategy's investment-rather-than-regulation framing, signals that the current federal direction is to address AI policy through industrial strategy and voluntary frameworks rather than through comprehensive regulation. This is a choice. Other choices were available and remain available, and a different government could make a different one. The current direction is not the only possible Canadian path; it is the path the current government has selected.
The chapter notes this without taking a position on whether the choice is correct. The guide's methodology asks readers to recognize policy choices as choices (not as inevitable outcomes) and to engage the alternatives that exist or have existed. Comprehensive AI regulation through legislation analogous to the EU AI Act is one alternative. Sectoral regulation through enhanced authority for existing regulators (OPC, CRTC, OSFI, others) is another. Voluntary industry frameworks with government coordination is a third. Each alternative has trade-offs that AI for All's current approach also has trade-offs the strategy does not always foreground.
---
International frameworks Canada has signed (and has not)
Canadian AI governance operates within international frameworks that Canada has variously signed, not signed, or partially engaged. The international layer is significant because it sets normative baselines, creates coordination mechanisms across jurisdictions, and shapes what Canadian AI exports and imports face in foreign markets.
The OECD AI Principles. Adopted by Canada and over 40 other OECD member states in 2019, with subsequent updates. The Principles are non-binding but represent the most-cited international AI governance framework. Canada is in good standing with the OECD framework.
The G7 Hiroshima AI Process. A coordination effort among G7 countries on advanced AI governance, including the International Code of Conduct for Advanced AI Developers (October 2023). Canada participates actively. The Code of Conduct is voluntary and applies to advanced AI developers; its substantive impact on AI governance in any specific jurisdiction depends on national implementation.
The Council of Europe Framework Convention on AI. Adopted May 2024 and opened for signature that September, the first internationally-binding treaty on AI, focused on human rights, democracy, and the rule of law. Canada signed on February 11, 2025, on the margins of the Paris AI Action Summit, joining the European Union, the United Kingdom, the United States, Japan, and others. What Canada has not done is ratify it. A signature without ratification and implementing legislation is a commitment in the same family as the Voluntary Code: real as a signal, not yet binding as law. (The treaty itself is not yet in force; the European Union became its first ratifying party in May 2026.)
The Sovereign Technology Alliance. Launched by Canada and Germany in February 2026 and made a pillar of AI for All in June 2026, alongside twelve already-signed international AI partnerships (including the EU, the UK, India, and several Gulf states). The Alliance is intended to coordinate sovereign AI development among trusted allies. Substantive provisions, governance, and membership beyond the founding pair have not been fully announced; its eventual significance depends on subsequent development.
The EU AI Act extraterritorial reach. The EU AI Act applies to AI providers placing AI systems on the EU market or whose AI output is used in the EU, regardless of where the provider is headquartered. Canadian AI providers selling into the EU market are subject to EU AI Act requirements — including risk classification, conformity assessment, transparency provisions, and registration requirements. Canada has no equivalent statute, but Canadian companies operating internationally must comply with the EU framework regardless.
UN engagement. The UN Secretary-General's Advisory Body on AI, the UNESCO AI Ethics Recommendation, the UNHRC engagements on AI and human rights — Canada participates in multiple UN AI processes but has not been a leader in shaping them. The recently negotiated AI for Sustainable Development resolution is one area of Canadian engagement.
The Beijing Treaty on Audiovisual Performances (2012, WIPO). Canada has neither signed nor acceded to the treaty (Chapter 11). The treaty would extend moral rights to audiovisual performers in ways relevant to AI deepfake-of-performer concerns.
The G7-G20 broader AI engagement. Canada participates in AI discussions across both forums. The discussions are coordination-focused rather than binding-rule-making. Canada is positioned consistently with G7 partners on most AI policy matters.
The international finding. Canada is generally engaged in international AI policy frameworks, generally in good standing, generally aligned with other liberal-democratic G7 partners on most matters. The notable gap is ratification: Canada signed the Council of Europe Framework Convention in February 2025 but has not ratified it or tabled implementing legislation. Whether and when to ratify is a contested policy question; that the signature remains unimplemented is empirical and worth tracking.
There is a more ambitious version of Canadian engagement now being floated: not just participating in others' frameworks, but convening a bloc. Through 2026, AI-policy figures (and the federal government itself, in the AI for All "trusted partnerships" pillar) have pushed the idea of a middle-power coalition — aligned democracies that are neither the United States nor China, banding together to set safety guardrails and to build an alternative to depending on the handful of US frontier labs. The intellectual anchor is the second annual International AI Safety Report, the 100-plus-expert assessment chaired by Canada's Yoshua Bengio, which warned that risk-management gaps widen as capabilities climb. The political anchor is the moment described above: a G7 where European and Canadian leaders openly sought checks on American AI dominance, and where Carney argued that sovereignty requires "unhindered access to AI" and a push to "build out and diversify." Whether a middle-power coalition becomes a real institution or another communiqué is unknown. But it is the most concrete answer yet to the question this book keeps returning to: what a country Canada's size can actually do when it controls neither the chips nor the largest models.
---
The comparative international landscape
Canadian AI governance can be evaluated against peer jurisdictions through several dimensions. The chapter provides the comparison the guide has implied in earlier chapters but has not laid out comprehensively.
The European Union. The EU AI Act (effective August 2024, with phased implementation through 2026–2027) is the most comprehensive AI regulatory framework currently in force in any major jurisdiction. Risk-based classification (prohibited, high-risk, limited-risk, minimal-risk). Mandatory conformity assessment for high-risk AI. Transparency requirements for general-purpose AI models. Civil penalties up to 7% of global annual turnover or €35 million, whichever is higher, for prohibited-practice violations. The EU AI Act is the framework most-cited as the global regulatory benchmark.
The United Kingdom. A pro-innovation framework with sectoral regulators rather than a single AI law. Industry-leading institutional capacity through the AI Safety Institute (renamed the AI Security Institute in February 2025). Substantial enforcement through the Online Safety Act for AI-related online harms. The UK approach is sometimes characterized as the "third way" between EU comprehensive regulation and US largely-voluntary framework.
The United States. Federal regulation is patchy and largely voluntary. The Biden administration's Executive Order on AI (October 2023, partially superseded in 2025) established voluntary commitments and agency-specific requirements. The Trump administration substantially scaled back federal AI safety regulation through a January 2025 executive order, followed by its AI Action Plan in July 2025. State-level regulation provides the most binding requirements — California, Colorado, Texas, Illinois, Tennessee, others have AI-specific legislation in various domains. The TAKE IT DOWN Act provides federal coverage for non-consensual intimate images. The US federal framework in 2026 is substantially less comprehensive than the EU framework.
Two 2026 moves by Anthropic, one of the US frontier labs, complicate the "largely voluntary" picture. In a June 2026 essay, "Policy on the AI Exponential," CEO Dario Amodei shifted the company's public position from advocating transparency to calling for binding, enforceable frontier-model regulation, an FAA-style testing regime, and support for workers displaced by AI. Around the same time, Anthropic publicly refused US Department of Defense contract language that, it said, would have permitted unrestricted military use of its models, including inadequate limits on mass surveillance and fully autonomous weapons. Both are worth filing, with the lean attached: a well-resourced incumbent calling for binding rules is also calling for rules it is better placed to absorb than smaller competitors, and a public refusal is also a public-relations act. Still, the direction matters for Canada. The country's own governance rests on a voluntary code with, as the Goblin Fact above notes, zero enforcement; when even a frontier developer argues that voluntary is not enough, Canada's choice to stay voluntary reads less like the global consensus and more like a deliberate one.
Australia. The eSafety Commissioner provides centralized authority over online safety including AI. The 2024 AI policy framework emphasizes risk-based regulation. Criminal penalties of up to six years for non-consensual sexual deepfakes. Substantial civil penalties for platform non-compliance.
Singapore. The PDPA (Personal Data Protection Act) plus the AI Governance Framework provide a coordinated approach. Singapore is consistently rated highly on AI readiness and government AI capacity. The framework is voluntary in many provisions but with strong sectoral implementation.
South Korea. The AI Basic Act and supporting framework, with sectoral provisions and substantial penalties for high-risk AI deployment.
Japan. AI Strategy 2024 emphasizes risk-based regulation with sectoral implementation. The AI Promotion Act provides framework for both development and governance.
China. Comprehensive AI regulation through multiple agencies (Cyberspace Administration of China, Ministry of Industry and Information Technology, others). Substantial registration requirements for AI services, content moderation requirements, algorithmic transparency requirements. China's approach is comprehensive but operates within a fundamentally different legal-political context that limits direct comparability with liberal-democratic frameworks.
Canada. Bill C-16 (sexual deepfakes only), the Treasury Board AI Register and Federal Public Service AI Strategy (internal use only), PIPEDA (2000-vintage privacy law with OPC AI guidance), Quebec Law 25 (covers 23% of population, robust within its scope), Ontario's Working for Workers Act (AI hiring disclosure only), various sectoral guidance documents from OPC, CRTC, OSFI. No comprehensive federal AI statute. No designated federal AI regulator with cross-cutting authority. No binding AI risk classification framework.
The comparative bottom line. On AI regulatory comprehensiveness, Canada trails most comparable OECD jurisdictions. The framework is more comprehensive than the US federal level, less comprehensive than the EU level, modestly less comprehensive than the UK level, substantially less comprehensive than Australia/Singapore/South Korea, and operating in a different legal-political context than China. Where Canada has particular strengths (institutional capacity in the OPC, provincial leadership in Quebec, sectoral expertise in specific federal regulators) these are real but partial. Where Canada has particular weaknesses (comprehensive AI legislation, designated AI regulator, mandatory disclosure framework) these are structural and require legislation that the current government has not committed to.
The point isn't to bash Canada; it's to surface the empirical comparison the federal strategy framing tends to obscure. AI for All presents Canada as a global AI leader; the regulatory comparison places Canada behind most peer jurisdictions on the governance dimension. Both framings can be partially correct simultaneously — Canada can be a global leader on research capacity, talent development, and certain commercialization metrics while being a regulatory laggard on the governance dimension. The guide's methodology asks readers to track both rather than collapse to either.
---
Governance via sectoral regulators — Canada's de facto pattern
The structural pattern Canadian AI governance has settled into, by default rather than by deliberate design, is sectoral regulation through existing federal and provincial regulators rather than comprehensive AI-specific legislation. This pattern is worth examining directly because it shapes both what Canadian AI governance can do well and what it structurally cannot.
Where the sectoral pattern works. Specific federal and provincial regulators with domain expertise can produce nuanced guidance for their sector — Health Canada on medical device AI, OSFI on financial-sector AI, CRTC on broadcast AI, the OPC on privacy across sectors, the Canadian Securities Administrators on AI in securities markets. Each regulator can fold AI considerations into existing frameworks without entirely new legislation. The expertise is real, the guidance substantive, the implementation relatively fast.
And then the failure mode. AI applications that span sectors (which is most of them, since the underlying foundation models are general-purpose) receive inconsistent regulatory treatment depending on which sectoral regulator engages them. Foundation models used in healthcare may be regulated by Health Canada; the same foundation models used in finance may be regulated by OSFI; the same models used in employment may be subject to provincial labour regulation. The cross-sectoral consistency that comprehensive legislation could provide is absent under the sectoral pattern.
A worked example: one hiring tool, every regulator. Imagine a mid-size Ontario employer licenses an American AI screening tool for job applications. Who governs it? Ontario's Working for Workers Act requires the employer to disclose AI use in screening, but doesn't regulate what the tool actually does. PIPEDA governs the applicant data the tool processes, interpreted by the OPC, under a statute two decades older than the technology. If the tool's vendor also sells into Europe, the EU AI Act classifies the very same product as high-risk and requires conformity assessment, protections the Ontario applicant doesn't get. If the tool discriminates, the Ontario Human Rights Code applies, case by case, after the harm. If the employer were federally regulated (a bank, a telecom), employment-law jurisdiction would flip to Ottawa. And if the applicant lived in Quebec, Law 25 would give them the right to know an automated decision was made and to ask for its principal factors. Same tool, same résumé, six different regulatory answers, depending on facts the applicant can't see and didn't choose.
EXAMPLE — four leagues, ten rulebooks, no referee. Picture a hockey game where the feds set some rules, each province sets others, a few sectors bring their own, and nobody is clearly the ref. That's AI governance in Canada — not lawless, but a patchwork where the honest answer to "who's in charge?" is "it depends which part you mean." That is the sectoral pattern, experienced from below.
Specific gaps the sectoral pattern produces:
General-purpose foundation models. The Cohere, OpenAI, Anthropic, Google, and Meta foundation models that are increasingly deployed across Canadian sectors are not regulated by any single Canadian institution. Each sectoral regulator engages them through their domain lens; no regulator considers them as the cross-cutting infrastructure they actually are.
Training data practices. The Canadian newspapers v. OpenAI case (Chapter 11) is being adjudicated through Copyright Act provisions because there is no AI-specific framework for training data. The case will produce precedent; it will not produce systematic regulation.
Workplace AI surveillance. Documented in Chapter 10 and Chapter 16, workplace AI surveillance is regulated only sporadically through provincial labour law (Ontario's Working for Workers Act being the most-developed provision). Most Canadian workers have limited protection against AI surveillance in their workplaces.
Biometric identification. Documented in Chapter 10, facial recognition and other biometric AI is regulated through privacy law in ways that have produced findings against specific deployments (Clearview AI) but have not established proactive frameworks.
Algorithmic decision-making in significant matters. Quebec's Law 25 provides the right to explanation of automated decisions in Quebec. Other provinces and the federal level have inconsistent or absent equivalents.
Political deepfakes. Bill C-16 covers sexual deepfakes; political deepfakes are governed by general defamation, election law, and tort, none of which were designed for synthetic media.
Indigenous data sovereignty. The OCAP®, NISR, and CARE frameworks (Chapter 9) exist as Indigenous-led primary frameworks but are not integrated into federal AI policy. AI for All does not commit to OCAP/NISR/CARE integration in federally-funded AI work.
Environmental disclosure for AI infrastructure. The 22% Canadian data centre PUE reporting rate (Chapter 6) reflects the absence of mandatory disclosure that the EU requires through its data-centre reporting scheme (Directive (EU) 2023/1791 + Delegated Regulation 2024/1364).
The sectoral pattern fills some of these gaps partially and others not at all. Its defenders call it flexible and expertise-led, a way to avoid the rigidity of comprehensive legislation; its critics call it a recipe for inconsistency, gaps, and the absence of cross-cutting accountability. Both arguments have merit. The chapter notes the trade-offs without resolving them, and asks readers to recognize the sectoral pattern as Canada's de facto choice rather than a neutral default.
A concrete picture of how the sectoral pattern operates across Canadian provinces (beyond Quebec's Law 25, which the guide has documented extensively) is worth foregrounding for completeness. In plain terms: there is no single Canadian AI law, but several provinces and the federal public service each run their own partial rulebook, and the acronyms below matter less than that pattern. Ontario has built the Enhancing Digital Security and Trust Act (EDSTA), in force in 2025 with March 2026 modernization proposals, that pairs AI governance with cybersecurity at the public-sector level, alongside the Responsible Use of AI Directive governing provincial public-service AI deployment. Manitoba's Bill 51 advances through the legislature toward an explicit public-sector AI-and-cybersecurity framework. Nova Scotia's Personal Information International Disclosure Protection Act (PIIDPA) provides the clearest provincial public-sector data-residency baseline among the jurisdictions reviewed. British Columbia's FIPPA section 33.1 governs offshore disclosure under specific conditions following the 2021 repeal of the earlier prohibition. Federally, the Treasury Board Directive on Automated Decision-Making and the accompanying Algorithmic Impact Assessment tool establish working governance for federal automated decision systems, instruments that run without new legislation and provide the substantive Canadian framework that does exist at the federal-public-service layer. These are the institutional resources the sectoral pattern actually relies on, and reading the Canadian AI governance picture without them mistakes the absence of comprehensive legislation for an absence of any framework. The framework exists, in pieces, distributed across jurisdictions and across regulators, with the gaps and overlaps the chapter has documented.
---
AI and the cyber threat
If governance is about who can do what to whom, cybersecurity is the sharp end of it, and it is the one place the Canadian government has been loudest about AI. The Communications Security Establishment, Canada's signals-intelligence agency, made AI the first of five headline trends in its 2025-2026 National Cyber Threat Assessment. Its judgement is blunt: criminals and state actors are "almost certainly" already using large language models to write convincing phishing at scale, generative tools to produce deepfakes that impersonate trusted people, and AI to make ransomware "cheaper and faster to conduct and harder to detect." It names the People's Republic of China as the most sophisticated state cyber threat to Canada, and documents Russia-linked denial-of-service attacks that briefly knocked over federal and Quebec government sites, including the Prime Minister's Office's public page.
That is the threat side, and it is real. But the same technology defends. AI is increasingly used to hunt software vulnerabilities at machine speed: Anthropic reports that it and roughly fifty partners used one of its models to find more than ten thousand serious flaws, and that one partner caught a fraudulent US$1.5-million wire transfer with it. Read those numbers as what they are, a company's account of its own product rather than an audited result, but the capability is not imaginary.
So which way does AI tip the balance, toward attacker or defender? The most careful answer is the one the international expert community gave, in the report chaired by Canada's own Yoshua Bengio: AI clearly lowers the cost and skill needed to mount an attack, but as of 2025 "there is no substantial evidence yet" that it can automate the sophisticated end of cyber operations enough to hand attackers a decisive edge. The cost of attacking is falling; so is the cost of defending; who benefits more is genuinely open, and worth distrusting anyone who claims to have settled it. CSE itself, for all its threat framing, judged it "very unlikely" that AI would fundamentally undermine the integrity of Canada's 2025 federal election.
The governance hook is where this rejoins the chapter. Canada's main attempt to protect the systems all of this threatens, the Critical Cyber Systems Protection Act, shows the pattern this book keeps finding: it passed both chambers, then died on the order paper when Parliament was prorogued in January 2025, and had to be reintroduced as a fresh bill months later. The pieces actually in force are provincial, and they are the ones that fuse AI and cybersecurity governance rather than treating them as separate problems: Ontario's Enhancing Digital Security and Trust Act and Manitoba's public-sector bill, both noted above, regulate AI and cyber in one breath. That coupling is probably the right instinct, because the threat assessment makes the reason plain: the cheapest new cyberweapon and the most promising new cyber-defence are the same technology.
---
What institutional pathways exist for closing gaps
The chapter has named the governance gaps that previous chapters surfaced. Closing those gaps would require specific institutional action through specific pathways. Mapping the pathways is the chapter's constructive contribution.
Federal legislative pathways. Comprehensive AI legislation (an AIDA successor) would require government introduction, parliamentary committee study, and passage through both Houses. The Carney government has not committed to this path. The legislative route exists if the political will emerges, but it demands a sustained coalition, drafting time, parliamentary calendar, and political capital.
Federal regulatory pathways through existing statutes. Some governance gaps could be closed through enhanced enforcement of existing laws: the OPC could be given expanded authority under updated PIPEDA, the Competition Bureau could engage AI market concentration under existing Competition Act provisions, the CRTC could extend its AI-related guidance under existing telecommunications and broadcasting regulation. This path is faster than legislation but limited by the underlying statute's scope.
Federal-public-service pathways. Treasury Board directives can establish significant governance for federal departments and agencies without new legislation — the AI Register and the Algorithmic Impact Assessment requirement were both established this way. The reach stops at the federal public service; it does not extend to the broader Canadian economy.
Federal-provincial coordination pathways. Federal-provincial agreements can establish comprehensive frameworks the federal level alone cannot reach. Climate policy, labour-market policy, and pharmaceutical pricing all operate through this kind of multilateral coordination. An AI framework agreement could close many of the governance gaps — but only with sustained negotiation and political alignment across jurisdictions that have different priorities.
ALIGNMENT — which rung on the ladder? Not mentioned. Mentioned but not operationalized. Promised but not funded. Funded but not regulated. Regulated but not enforceable. When you read an AI commitment, find the rung it is actually standing on. Most of them live a rung or two below where the headline puts them.
Provincial pathways. Individual provinces can act independently within their jurisdiction. Quebec has done so most comprehensively with Law 25. BC, Alberta, Manitoba have meaningful private-sector privacy frameworks. Ontario has begun with the Working for Workers Act. The provincial path is fragmented but can produce real protection within specific jurisdictions, and provincial action can pressure federal action over time.
Sectoral regulator pathways. Existing regulators can develop AI-specific frameworks within their sectors, as several have begun to do. The OPC's AI guidance, the CRTC's AI engagement, OSFI's emerging AI risk framework for financial institutions, Health Canada's evolving medical device AI framework — these are real institutional resources that can be strengthened without new legislation.
International coordination pathways. Canadian participation in international AI governance frameworks (OECD, G7, Council of Europe, UN) can establish frameworks that subsequently get implemented domestically. Ratifying and implementing the Council of Europe AI Framework Convention (signed by Canada in February 2025 but not yet ratified) would be one such step.
Judicial pathways. Canadian courts are increasingly receiving AI-related cases. The Canadian newspapers v. OpenAI case will produce significant copyright precedent. Various individual cases involving AI-driven employment decisions, privacy violations, and other harms are producing case-by-case precedent. The judicial pathway is slow, expensive, and uncertain but consequential where it produces clear precedent.
The institutional reality. Multiple pathways exist for closing the governance gaps the guide has documented. The pathways are not equally promising. Comprehensive federal legislation is the most direct but politically difficult. Sectoral regulator pathways are more accessible but produce fragmentary coverage. Federal-provincial coordination could be comprehensive but requires alignment that has been historically difficult to achieve. The choice of which pathways to pursue is itself a political question that engages tradeoffs of speed, coverage, durability, and political feasibility.
---
The architecture, mapped
CHAPTER RECAP — you now have: - The federalist constitutional constraint that shapes what Canadian AI governance can be enacted at which level — federal jurisdiction over criminal law, copyright, federal privacy, telecommunications; provincial jurisdiction over most healthcare, employment, education, and consumer protection. - The federal institutional landscape mapped — ISED leading strategy, Treasury Board leading internal use, Justice on criminal-law AI, the OPC on privacy, the three institutes plus CAISI on research and safety, the various sectoral regulators with AI-relevant mandates, and the structural absence of comprehensive AI governance authority in any single institution. - The AIDA failure as the central institutional fact of Canadian AI governance in 2026 — the multiple factors that contributed to the failure, the post-AIDA regulatory gap, and the current government's choice not to revive the bill. - The international framework picture — Canadian engagement with OECD AI Principles, G7 Hiroshima AI Process, UN engagement, and the still-unratified Council of Europe Framework Convention on AI (signed February 2025); EU AI Act extraterritorial reach on Canadian companies. - The comparative international landscape — Canada trailing most OECD peer jurisdictions on AI regulatory comprehensiveness, with specific strengths in institutional capacity and specific weaknesses in comprehensive legislation. - The sectoral regulator pattern as Canada's de facto governance approach — what it does well (expert-led sectoral guidance), what it fails to address (cross-sectoral applications, foundation models, training data, workplace surveillance, biometrics, Indigenous data sovereignty, environmental disclosure). - The institutional pathways available for closing governance gaps — federal legislation, federal regulation under existing statutes, Treasury Board directives, federal-provincial coordination, provincial action, sectoral regulators, international coordination, judicial precedent.
The next chapter (Chapter 18) takes the institutional architecture this chapter has mapped and focuses specifically on the transparency dimension — what Canadians can and cannot know about how AI is being deployed and what its effects are. The Stanford Foundation Model Transparency Index, the corporate self-disclosure pattern, the Canadian regulatory absence on mandatory disclosure, and the structural finding that institutional knowledge of AI deployment substantially lags AI deployment itself.
You can now read any Canadian AI governance claim with the institutional equipment to recognize which pathway is being engaged, what its strengths and limits are, and what alternatives exist. The conversation about Canadian AI governance in 2026 often collapses into "we need AIDA back" or "the strategy framework is enough" framings; the institutional picture is more complex and supports more pathways than either framing engages.
---
Bias label for this chapter: institutional and structural analysis of Canadian AI governance, with explicit comparative international framing. Author lean: skeptical of "AI for All as comprehensive Canadian AI policy" framings that elide the regulatory dimension; sympathetic to comprehensive legislation as one pathway while recognizing the political constraints; willing to name Canada's trailing position in international comparative governance comprehensiveness as the empirically dominant finding; explicit that the manual treats this as comparative empirical analysis rather than as policy advocacy for any specific governance model. Government framing (AI for All, ministerial statements) treated as primary on commitments made. Institutional sources (OPC, Treasury Board, sectoral regulators) treated as primary on their respective domains. Comparative international frameworks (EU AI Act, UK Online Safety Act, others) treated as primary on their own provisions. Academic and civil society analysis of Canadian governance (Geist, Craig, CUPE, BC + AI, others as cited in previous chapters) treated as primary on their respective positions.
Primary sources cited or relied on in this chapter: Constitution Act, 1867 (Canada), relevant jurisdictional provisions; Bill C-27 / AIDA documentation (2022–2025); AI for All strategy launch documentation (June 4, 2026); Treasury Board AI Register and AI Strategy for the Federal Public Service (November 28, 2025); Treasury Board Directive on Automated Decision-Making and Algorithmic Impact Assessment tool; Personal Information Protection and Electronic Documents Act (PIPEDA, 2000) and OPC guidance documents; Quebec Act to modernize legislative provisions as regards the protection of personal information (Law 25, 2021); Bill C-16 Protecting Victims Act (December 9, 2025); Ontario Working for Workers Act (effective January 1, 2026); Ontario Enhancing Digital Security and Trust Act (EDSTA) with March 2026 modernization proposals; Ontario Responsible Use of AI Directive; Manitoba Bill 51 documentation; Nova Scotia Personal Information International Disclosure Protection Act (PIIDPA); British Columbia FIPPA section 33.1 and PIPA; ISED Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems (September 2023) with signatory list; European Union AI Act (effective August 1, 2024); UK Online Safety Act (2023); Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (May 2024); OECD AI Principles (2019, updated); G7 Hiroshima AI Process documentation including the International Code of Conduct (October 2023). Detailed citations in the Sources appendix.
---
🧌 GOBLIN CHECK — Every "why doesn't Canada just pass the EU AI Act?" take runs aground on the same rock: 1867. Healthcare, employment, education — the places AI actually touches a life — are mostly provincial turf. The goblin didn't make the rules. The goblin merely notes that anyone selling you a one-statute fix hasn't read the Constitution Act, and probably shouldn't be selling you anything.
Recap
- The federalist constitutional constraint that shapes what Canadian AI governance can be enacted at which level — federal jurisdiction over criminal law, copyright, federal privacy, telecommunications; provincial jurisdiction over most healthcare, employment, education, and consumer protection.
- The federal institutional landscape mapped — ISED leading strategy, Treasury Board leading internal use, Justice on criminal-law AI, the OPC on privacy, the three institutes plus CAISI on research and safety, the various sectoral regulators with AI-relevant mandates, and the structural absence of comprehensive AI governance authority in any single institution.
- The AIDA failure as the central institutional fact of Canadian AI governance in 2026 — the multiple factors that contributed to the failure, the post-AIDA regulatory gap, and the current government's choice not to revive the bill.
- The international framework picture — Canadian engagement with OECD AI Principles, G7 Hiroshima AI Process, UN engagement, and the still-unratified Council of Europe Framework Convention on AI (signed February 2025); EU AI Act extraterritorial reach on Canadian companies.
- The comparative international landscape — Canada trailing most OECD peer jurisdictions on AI regulatory comprehensiveness, with specific strengths in institutional capacity and specific weaknesses in comprehensive legislation.
- The sectoral regulator pattern as Canada's de facto governance approach — what it does well (expert-led sectoral guidance), what it fails to address (cross-sectoral applications, foundation models, training data, workplace surveillance, biometrics, Indigenous data sovereignty, environmental disclosure).
- The institutional pathways available for closing governance gaps — federal legislation, federal regulation under existing statutes, Treasury Board directives, federal-provincial coordination, provincial action, sectoral regulators, international coordination, judicial precedent.
Sources
- Constitution Act, 1867 (Canada), relevant jurisdictional provisions
- Bill C-27 / AIDA documentation (2022–2025)
- AI for All strategy launch documentation (June 4, 2026)
- Treasury Board AI Register and AI Strategy for the Federal Public Service (November 28, 2025)
- Treasury Board Directive on Automated Decision-Making and Algorithmic Impact Assessment tool
- Personal Information Protection and Electronic Documents Act (PIPEDA, 2000) and OPC guidance documents
- Quebec Act to modernize legislative provisions as regards the protection of personal information (Law 25, 2021)
- Bill C-16 Protecting Victims Act (December 9, 2025)
- Ontario Working for Workers Act (effective January 1, 2026)
- Ontario Enhancing Digital Security and Trust Act (EDSTA) with March 2026 modernization proposals
- Ontario Responsible Use of AI Directive
- Manitoba Bill 51 documentation
- Nova Scotia Personal Information International Disclosure Protection Act (PIIDPA)
- British Columbia FIPPA section 33.1 and PIPA
- ISED Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems (September 2023) with signatory list
- European Union AI Act (effective August 1, 2024)
- UK Online Safety Act (2023)
- Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (May 2024)
- OECD AI Principles (2019, updated)
- G7 Hiroshima AI Process documentation including the International Code of Conduct (October 2023).