AIDA did not pass. What binds Canadian AI deployments in 2026?
A proposal has arrived offering readiness for the Artificial Intelligence and Data Act, possibly with a compliance deadline attached. Before anyone signs it, the parliamentary record is worth five minutes: that Act was a part of a bill, and the bill was never enacted.
Published 22 September 2026. Written by the SecHB practice, Greater Vancouver, British Columbia.
The short version
The Artificial Intelligence and Data Act was Part 3 of Bill C-27, the Digital Charter Implementation Act, 2022. C-27 did not become law. There is no federal AI statute in force in Canada, and therefore no compliance obligation under one, and no deadline under one.
That is a statement about one statute and nothing wider. It is not a statement that Canadian AI deployments are unregulated, which is the error to avoid in the other direction, and the rest of this page is mostly about what does reach them.
What the parliamentary record actually shows
The authoritative record is LEGISinfo’s page for Bill C-27 (44-1), and it is short enough to read in full. The bill is An Act to enact the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act and the Artificial Intelligence and Data Act and to make consequential and related amendments to other Acts, with the short title Digital Charter Implementation Act, 2022.
Four things on that page settle the question.
- The page opens with the notice
The information below relates to a prior session.
- The session is given as the 44th Parliament, 1st session, running from Monday, November 22, 2021 to Monday, January 6, 2025.
- The current status is
At consideration in committee in the House of Commons
, and the latest activity is second reading and referral to committee on Monday, April 24, 2023. - The consideration-in-committee stage is marked as not completed, and no Royal Assent stage appears anywhere on the page.
A bill that is frozen at committee in a session that has ended, with no Royal Assent recorded, did not become law. This page states that and stops there: LEGISinfo records the status and the dates, it does not record the procedural mechanism by which the bill ended, so neither does this article.
Why the confusion persists
Three reasons, none of them anybody’s bad faith.
The government published substantial material about the proposed framework while the bill was live, and it is still online. The AIDA companion document is explicit that it describes a proposed framework, and it now carries the notice This page has been archived on the Web
— but a reader who arrives at it from a search engine sees a government page describing obligations, and the archive banner is easy to scroll past.
Some consultancies built service lines around the proposal and have not retired the copy. No firm is named here, and none needs to be: the test is whether the page you are reading cites the parliamentary record, and most of them do not.
And the concepts in the proposal were reasonable, so they keep being repeated as though they were requirements. High-impact system classification, a named accountable person, published descriptions of system use — those are sensible practices. They were not enacted.
The scope of this claim, stated precisely
This article makes one claim: the Artificial Intelligence and Data Act was not enacted, and no federal AI statute is in force in Canada. It does not claim that Canada has no AI regulation, and that broader statement would be wrong.
Regulatory attention is not the same thing as a dedicated statute. Obligations reach AI deployments through instruments written for other purposes, federal directives govern how the federal government itself uses automated decision-making, and provincial law applies in its own jurisdictions. Whether a particular obligation reaches a particular organization is a question for that organization’s counsel.
What does bind a Canadian AI deployment
| Source | How it reaches an AI deployment |
|---|---|
| Federal privacy law | PIPEDA applies to personal information handled in the course of commercial activity, and an AI feature that ingests, infers from or discloses personal information is handling it. |
| Provincial privacy law | Several provinces have their own private-sector or public-sector privacy statutes, and Quebec’s Law 25 is the one most often raised in AI discussions. Which of them reaches a given organization is a question for counsel. |
| Consumer protection and human rights law | Misleading representations and discriminatory outcomes are already unlawful under general law. Producing them with a model is not a defence and does not need a new statute to be actionable. |
| Sectoral regulators | Financial services, health, insurance and public procurement all carry supervisory expectations that reach automated decision-making within their own sectors. |
| Contract | In practice this is the binding instrument most organizations meet first: a customer agreement, a data processing schedule or a vendor programme that says what you may do with a model and what you must be able to show. |
The federal one is worth naming precisely, because it is the instrument most often meant when somebody says “privacy law” in Canada: the Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5), whose consolidation on the Justice Laws Website was current to 2026-07-21 and last amended on 2025-03-04 when this page was written.
What Canadian government guidance exists, and its status
Guidance is not law, and the distinction matters when a proposal describes it as a requirement. The Canadian Centre for Cyber Security publishes Generative artificial intelligence — ITSAP.00.041, most recently dated December 2025 and published in its awareness series. It sets out the risks the Cyber Centre sees in generative AI — among them misinformation, phishing, poisoned datasets, and users providing sensitive corporate data or personal information in prompts — and the measures it suggests against them.
It binds nobody by itself. It is useful for a different reason: it is a Canadian government document a Canadian buyer recognizes, which makes it a reasonable frame to say your controls were built against.
If you were told you need AIDA readiness
Ask which instrument the work is being mapped to. If the answer is the Artificial Intelligence and Data Act, the premise is wrong, because that Act was a part of a bill that was not enacted. The underlying governance work may still be worth doing — under a frame that exists.
Prepare for the obligations that already apply and for the diligence your customers are already running: know what AI you use and on whose data, name an owner for the decisions, keep the evidence that your controls operate, and read your provider contracts. None of that becomes wasted work whatever a future statute says.
A future Parliament could introduce a similar bill, and nothing here should be read as a prediction either way. What is checkable today is the record: C-27 is shown on LEGISinfo as relating to a prior session, with the committee stage not completed and no Royal Assent.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
Could AIDA come back?
A future Parliament could introduce a similar bill, and nothing here should be read as a prediction either way. What is checkable today is the record: C-27 is shown on LEGISinfo as relating to a prior session, with the committee stage not completed and no Royal Assent.
Does Canada have no AI rules at all?
No, and that is the error to avoid in the other direction. The absence of a federal AI statute does not mean the absence of law: federal and provincial privacy legislation, consumer protection, human rights law, sectoral regulators and your own contracts all reach AI deployments already.
What should we prepare for instead?
Prepare for the obligations that already apply and for the diligence your customers are already running: know what AI you use and on whose data, name an owner for the decisions, keep the evidence that your controls operate, and read your provider contracts. None of that becomes wasted work whatever a future statute says.
We were told we need AIDA readiness. What now?
Ask which instrument the work is being mapped to. If the answer is the Artificial Intelligence and Data Act, the premise is wrong, because that Act was a part of a bill that was not enacted. The underlying governance work may still be worth doing — under a frame that exists.
Where to go from here
If the governance work is what you actually wanted, AI governance readiness builds it against frames that exist. If you sell into Europe, whether the EU AI Act reaches a Canadian supplier is the more urgent question, because that instrument is in force. If the privacy side is the live one, the Canadian privacy law map sets out which statute reaches what. The rest of the AI security practice sits behind those, and the other pieces are indexed under Writing.
Send the proposal or the questionnaire line that raised this, and the reply will say which obligation, if any, is actually behind it.