A number of compliance calendars and AI regulation trackers currently list a Canadian AI Act taking effect on 1 January 2027.
There is no such statute. Canada has no comprehensive federal AI law in force and none scheduled to come into force.
This article exists for two reasons. The first is that organisations are planning against a deadline that does not exist, which wastes capacity that Q1 2027 genuinely needs elsewhere. The second is more useful: the absence of a Canadian AI Act does not mean AI is unregulated in Canada, and the rules that do apply are less visible than a headline statute would be.
What happened to AIDA
The Artificial Intelligence and Data Act (AIDA) was Part 3 of Bill C-27, introduced in June 2022 alongside proposed replacements for Canada’s federal private-sector privacy law. It would have established a risk-based regime for “high-impact” AI systems, with obligations on assessment, mitigation, monitoring and record-keeping, and an AI and Data Commissioner.
AIDA never became law. Bill C-27 died on the Order Paper when Parliament was prorogued on 6 January 2025. A bill that dies at prorogation does not carry over; it must be reintroduced and go through the legislative process again.
Following the April 2025 federal election, the government created a Minister of Artificial Intelligence and Digital Innovation, a post held by Evan Solomon. Solomon has stated publicly that AIDA will not return as drafted, and that a future framework should be — in his phrase — “light, tight, right.”
In February 2026, the government published a summary of its national AI strategy consultations. The themes flagged for possible future regulation include safety evaluation, adversarial testing and red-teaming, structured human oversight, traceability through the model lifecycle, and clearer allocation of responsibility and liability across the AI supply chain. That is a consultation summary, not a bill.
Nothing in that sequence produces an operative obligation on 1 January 2027.
Why the myth persists
Three mechanisms, all worth understanding because they will produce the next error too.
Tracker inheritance. AIDA appeared in AI regulation trackers from 2022 onward with projected effective dates. When the bill died, some trackers updated the status and others updated only the date. Downstream sources copy the entry without re-verifying the underlying instrument.
Name collision. “AI Act” is now a generic label. The EU AI Act is the referent most people hold, and a tracker row reading “Canada — AI Act — 1 Jan 2027” is read as an analogue of it rather than as a claim requiring verification.
Genuine adjacent deadlines. 1 January 2027 is a real AI compliance date — for California’s ADMT regulations and for New York’s RAISE Act, which imposes safety protocols, 72-hour critical-safety-incident reporting and Department of Financial Services disclosure on frontier developers over $500 million in revenue. A tracker that correctly lists two North American AI obligations on 1 January 2027 and incorrectly attributes a third to Canada is not obviously wrong on its face.
We repeated this error ourselves in an earlier article in this series before verifying it, and have corrected it. The general lesson is worth stating: for any regulatory deadline entering a compliance plan, verify the instrument — the bill number, its status, the section, and the coming-into-force provision — not the tracker row. A deadline you cannot trace to a citation is not a deadline.
What actually governs AI in Canada
PIPEDA
The Personal Information Protection and Electronic Documents Act is the operative federal private-sector privacy law, and it applies to AI systems processing personal information without needing to mention AI at all.
The provisions that bite hardest on AI development are the ordinary ones: meaningful consent for collection, use and disclosure; limiting collection to what is necessary for identified purposes; limiting use and disclosure to the purposes for which information was collected, absent new consent; accuracy; and individual access.
The purpose limitation requirement is where most AI programmes have a genuine problem. Personal information collected to deliver a service and subsequently used to train a model is being used for a new purpose. Whether the original consent covers that use is a real question with a frequently unfavourable answer, and it does not depend on any AI-specific statute existing.
The Office of the Privacy Commissioner has been active in this space, including through joint work with provincial counterparts and international regulators on generative AI, and has published principles for responsible generative AI development.
Quebec’s Law 25
The most substantive AI-relevant obligations in Canada are provincial, and they are in Quebec.
Under the Act respecting the protection of personal information in the private sector as amended by Law 25, an organisation that uses personal information to render a decision based exclusively on automated processing must:
- inform the individual of that fact at the time of or before the decision, and
- on request, inform them of the personal information used, the reasons and principal factors and parameters that led to the decision, and their right to have the information corrected, and
- give the individual the opportunity to submit observations to a member of personnel in a position to review the decision.
That is a functioning automated decision-making regime with notice, explanation and human review — conceptually close to what California’s ADMT rules will require from January 2027, and it has been in force since September 2023.
Law 25 also brings privacy impact assessment obligations, data portability, breach notification, and administrative monetary penalties reaching the greater of CAD 10 million or 2% of worldwide turnover, with penal fines up to the greater of CAD 25 million or 4%.
For most organisations, Quebec is the binding Canadian constraint on automated decision-making, and it is already live. Programmes waiting for a federal AI Act are waiting past an obligation they already have.
The Directive on Automated Decision-Making
For organisations selling into or operating with the federal government, the Treasury Board’s Directive on Automated Decision-Making applies to federal institutions’ use of automated systems for administrative decisions. It requires an Algorithmic Impact Assessment, with requirements scaling by impact level — notice, explanation, human intervention, peer review, and testing obligations.
It is not private-sector law, but it flows to vendors through procurement, and it is the most developed AI-specific governance instrument Canada has actually implemented.
The voluntary code
Innovation, Science and Economic Development Canada published a Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems, covering accountability, safety, fairness, transparency, human oversight and validity.
It is voluntary and creates no legal obligation. Its practical relevance is reputational and contractual: signatory status appears in procurement and in enterprise vendor assessments, and commitments made under it can become representations.
Pending legislation worth watching
Two bills are live and receive far less attention than AIDA did:
- Bill C-36, which would create the Protecting Privacy and Consumer Data Act — the successor vehicle to C-27’s privacy reforms.
- Bill C-34, which would create digital safety duties for regulated services, including certain AI chatbot services.
Neither is a comprehensive AI act. C-34’s treatment of AI chatbot services is the provision most likely to produce a concrete obligation for AI deployers in the near term, and it is the one to track.
Sectoral regulators
OSFI Guideline E-23 on model risk management applies to federally regulated financial institutions and covers AI and machine learning models within its model risk framework. Health Canada regulates AI-enabled medical devices. Provincial human rights and employment regimes apply to AI-assisted employment decisions without needing AI-specific amendment.
What this means for a compliance plan
Remove the 1 January 2027 Canada AI Act entry. It is not a deadline. Redirect the capacity to California ADMT and the New York RAISE Act, which are on that date and are real.
Assess Quebec Law 25 automated decision-making compliance now. If you render decisions about Quebec residents based exclusively on automated processing, the notice, explanation and human-review obligations already apply. This is the most commonly missed live obligation in Canada.
Run the PIPEDA purpose-limitation analysis on your training data. Personal information repurposed for model training is the exposure, and it exists today.
Track C-34 rather than waiting for an AIDA successor. The next binding Canadian AI obligation is more likely to arrive through digital safety duties on chatbot services than through a comprehensive act.
Build to the strictest applicable regime and map down. An organisation meeting EU AI Act obligations and California’s ADMT requirements will comfortably clear anything Canada is likely to enact, given the stated “light, tight, right” direction. Canada is not the binding constraint for a multinational, and treating it as a separate programme is misallocated effort.
The broader point
The useful discipline here is not about Canada. It is that a compliance calendar is only as good as the citation behind each row.
An entry with a jurisdiction, an instrument name and a date looks identical whether it is traceable to a coming-into-force provision or inherited from a tracker that never updated after a prorogation. The two are indistinguishable in a spreadsheet and very different in a board briefing.
Every deadline in a plan should carry its citation. The ones that cannot are not deadlines — they are rumours with dates attached.
This article is provided for informational purposes only and does not constitute legal advice.



