Canada has no artificial intelligence statute. That single fact is the one most AI policy advice gets wrong about this country, and getting it wrong sends Canadian employers looking for compliance obligations that do not exist while missing the three that do.
The rules that actually bind a Canadian company using AI at work are privacy rules and employment rules, not AI rules. They come from three places: the federal privacy statute and how it treats sending personal information to a vendor outside the country, Quebec’s Law 25, and — as of this January — a single line in Ontario’s Employment Standards Act. This guide covers what each one requires and what it means for the wording of your AI acceptable use policy.
Legal status verified 27 July 2026 against the primary sources linked throughout this page — Parliament’s LEGISinfo record, the consolidated federal and Quebec statutes, and Ontario’s e-Laws. Legislative status changes; check the linked sources before relying on any of it. This is not legal advice.
Canada came close. The Artificial Intelligence and Data Act (AIDA) was Part 3 of Bill C-27, the Digital Charter Implementation Act, 2022, introduced in the 44th Parliament in June 2022. It would have imposed risk assessment, mitigation, record-keeping and disclosure duties on “high-impact” AI systems.
It never became law. Parliament’s own record shows C-27 reached second reading and referral to committee on 24 April 2023 and stopped there. It never received Royal Assent, and it was not reinstated when the next session began. AIDA has no legal force in Canada and never has.
Nor has it come back. As of this writing there is no bill before the current Parliament with “artificial intelligence” in its title. What is moving is privacy reform: Bill C-36, an Act to enact the Protecting Privacy and Consumer Data Act and amend PIPEDA, received first reading on 15 June 2026 and sits at second reading. It is not law either, and no one should be building a compliance programme around a bill that has not passed. But it is the thing to watch, and it is worth noting what it signals: Ottawa is legislating AI-adjacent risk through privacy law, not through an AI act.
What this means for your policy: do not write “as required by the Artificial Intelligence and Data Act” into anything. Several template vendors still do. It is a factual error, and in a document you may one day hand to a regulator or a plaintiff’s counsel, it is the kind of error that undermines everything around it.
Almost every general-purpose AI assistant your staff will reach for is operated by a company outside Canada. Some vendors offer regional data residency on enterprise plans; on consumer tiers you generally do not get that choice, and you usually cannot tell from the product interface where a given prompt is processed. So the moment an employee pastes a customer list into a chatbot, personal information under your control has been handed to a foreign processor.
The federal Personal Information Protection and Electronic Documents Act (PIPEDA) handles this through accountability rather than through a border. It contains no prohibition on transferring personal information outside Canada. What it contains is Principle 4.1.3 in Schedule 1:
An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.
Read that against how AI tools are actually adopted inside a company and the problem is obvious. The obligation is yours, it survives the handoff, and it requires contractual or equivalent protection. An employee signing up for a free tier with a work email has created exactly the situation Principle 4.1.3 describes, with none of the contractual protection it demands — and has done it without procurement, legal, or IT ever seeing the terms.
That is the concrete reason a Canadian AI policy needs a tool tier list rather than a general instruction to “be careful.” The distinction that matters legally is not which tool is best, it is which tools you have a contract with.
The Office of the Privacy Commissioner has also published principles for generative AI (last modified 6 May 2025). They are guidance, not law, but they set out what the regulator expects: demonstrable accountability, a defined internal governance structure, privacy impact assessments, and — a point worth lifting straight into a policy — that accountability for a decision rests with the organization, never with the automated system that helped make it.
If you have a single employee or customer in Quebec, this section governs you, and it is materially stricter than the federal baseline. The relevant statute is the Act respecting the protection of personal information in the private sector, as overhauled by Law 25 (2021, c. 25). Four provisions bear directly on AI use.
This is the one that catches people. Before communicating personal information outside Quebec, a business must conduct a privacy impact assessment, taking into account the sensitivity of the information, the purposes it will be used for, the protection measures including contractual ones, and the legal framework of the destination jurisdiction. The information may be communicated only if that assessment establishes it would receive adequate protection, and the communication must be the subject of a written agreement.
Crucially, section 17 says the same applies where the business “entrusts a person or body outside Québec with the task of collecting, using, communicating or keeping such information on his behalf.” That is a precise description of an AI vendor. Under PIPEDA, sending personal information to a US-hosted AI tool triggers a contractual obligation. Under Law 25 it triggers a documented assessment that has to be done first, and that has to conclude the data will be adequately protected.
A business must conduct a privacy impact assessment for any project to acquire, develop or overhaul an information system involving the collection, use, communication, keeping or destruction of personal information, and must consult its privacy officer from the outset of the project. Rolling out an AI assistant across a department is such a project. The assessment must be proportionate to the sensitivity, purposes, quantity and distribution of the information involved.
Where a business uses personal information to render a decision based exclusively on automated processing, it must tell the person, no later than when it tells them the decision. On request it must also disclose the personal information used, the reasons and the principal factors and parameters that led to the decision, and the person’s right to have that information corrected. The person must be given the opportunity to submit observations to a member of staff who is in a position to review the decision.
Note the word exclusively. A genuine human review step takes a decision outside section 12.1 — which is a strong practical argument for writing a mandatory human-review requirement into your policy rather than treating it as best practice.
Consent must be clear, free and informed, given for specific purposes, and requested separately for each purpose in clear and simple language; if requested in writing it must be presented separately from other information. Section 8 requires that, at the point of collection, people are informed of the possibility that their information could be communicated outside Quebec — which means a new AI tool that changes where data goes can require a change to your collection notices, not just to your internal policy.
Ontario added a job-postings part to the Employment Standards Act, 2000 that came into force on 1 January 2026. Section 8.4(1) reads:
Every employer who advertises a publicly advertised job posting and who uses artificial intelligence to screen, assess or select applicants for the position shall include in the posting a statement disclosing the use of the artificial intelligence.
Three details decide whether it applies to you, and all three live in O. Reg. 476/24:
The compliance step itself is small: one sentence in the posting. The failure mode is organisational — the people who write job postings are usually not the people who chose the ATS, and nobody has told them the tool scores applicants.
Four edits cover the Canadian position without turning the document into a legal treatise.
None of this requires a Canada-specific policy document. It requires four paragraphs in the policy you already have, plus knowing which of your tools are on a contract.
If you want a policy built around this structure, you can generate a tailored policy kit that maps your data categories to specific tool restrictions and role-based rules. To see what your current tools actually commit to on data handling, our AI tool risk directory documents each vendor’s published terms.
About Shadow AI Policy: We build AI acceptable use policy tools for HR and operations teams at 50–500 person companies. We publish guides on shadow AI, acceptable use policies, and AI governance, updated as regulations and AI tools change.
No. Canada has no federal artificial intelligence statute in force. The Artificial Intelligence and Data Act (AIDA) was proposed as part of Bill C-27 in 2022, reached committee stage in April 2023, and died without receiving Royal Assent; it was not reinstated in the following session. There is currently no bill before Parliament with “artificial intelligence” in its title. What binds Canadian employers using AI is existing law: federal and provincial privacy statutes, employment standards legislation, human rights law, and sector regulation. Any template or advisor telling you to comply with AIDA is working from a bill that never passed.
PIPEDA does not prohibit processing personal information outside Canada, so there is no automatic bar. What it does require, under Principle 4.1.3 of Schedule 1, is that you remain responsible for that information and use contractual or other means to provide a comparable level of protection while a third party processes it. In practice that means the tool needs to be on a business agreement whose terms you have read, not a personal free-tier account. If any of the personal information relates to people in Quebec, the additional requirement in section 17 of Quebec’s private-sector privacy act applies: a privacy impact assessment before the data goes, concluding that protection is adequate, plus a written agreement.
If you have 25 or more employees on the day you post, the posting is publicly advertised, and the ranking feature is being used to screen, assess or select applicants, then yes — section 8.4 of the Employment Standards Act requires a statement in the posting disclosing the use of artificial intelligence. The regulation defines artificial intelligence broadly enough to capture a machine-based system that infers from input to generate predictions or recommendations, which is what resume ranking is. The practical first step is to ask your ATS vendor, in writing, which of their scoring or matching features are active on your account.
Usually not a separate document, but you do need Quebec-specific provisions inside the one you have. The three that matter most: no personal information about Quebec residents goes into a tool hosted outside Quebec until the section 17 privacy impact assessment is complete and a written agreement is in place; any project to adopt or overhaul a system handling personal information triggers an assessment under section 3.3, with the privacy officer involved from the outset; and any decision about a person made exclusively by automated processing carries notification, explanation and human-review-on-request duties under section 12.1. Requiring genuine human review of decisions is the cleanest way to stay outside that last one.
Tailored to your industry and the AI tools your team uses. Free preview, $79 one-time or $149/mo with monthly updates.
Generate my policy kit →