Canadian AI Policy: The 2026 Reference

Last updated: April 22, 2026. Reviewed quarterly.

Canadian AI policy in 2026 is a layered, slightly chaotic landscape: federal directives that bind public-sector deployments, a privacy law (PIPEDA) that the Privacy Commissioner now reads broadly to cover AI, three increasingly serious provincial regimes, and sector-specific guidance from financial regulators and procurement bodies. This page is the running map of what is actually binding, what is coming, and what Canadian operators should be tracking. Read alongside our deeper explainer on the AIDA Act and Marcus Laporte’s column on what replaces AIDA.

Federal: what’s binding now

Treasury Board Directive on Automated Decision-Making. In force since 2019. Mandatory for federal departments and, by procurement extension, their vendors. Requires Algorithmic Impact Assessments by risk tier (I–IV). The closest thing Canada has to a stable AI risk-tier framework. Read the directive on the Treasury Board’s site.

PIPEDA, as interpreted by the OPC. The Office of the Privacy Commissioner of Canada now reads the Personal Information Protection and Electronic Documents Act broadly to cover most AI systems handling personal data. The recent Grok investigation made the OPC’s posture explicit.

OSFI guidance on model risk. Federally regulated financial institutions are bound by OSFI’s evolving guidance on AI/ML model risk, which interacts with existing model-risk-management expectations.

Bill C-27 — which would have introduced AIDA — died in committee in 2025. See our AIDA explainer.

Provincial: the patchwork

Quebec — Law 25. The strictest provincial privacy regime in Canada, with direct implications for AI deployments touching Quebec residents’ data. Quebec is consistently the leading indicator for federal Canadian privacy and AI rules; what Quebec passes today often becomes Ontario’s rule in two years.

Ontario — broader public-sector AI procurement guidance. Issued quietly in late 2025, with consequences for any vendor selling to school boards, hospitals, municipalities, or provincial agencies.

British Columbia — OIPC interpretation. The Office of the Information and Privacy Commissioner has signalled it intends to interpret existing privacy law to cover AI systems.

Alberta — sovereignty and governance moves. See our coverage of Alberta’s AI sovereignty work and municipal AI accountability initiatives.

Strategy & sovereignty

The federal government’s broader AI strategy continues to evolve through the Pan-Canadian AI Strategy consultation and a sovereign AI computing strategy. The current direction: continued funding for Mila, Vector, and Amii through CIFAR; targeted compute investment; and a posture that treats AI as both an industrial-strategy question and a national-security question.

Whether this strategy will produce a meaningfully different outcome from a pure private-sector approach is the question Marcus Laporte’s column tracks most closely. The short version: the federal government has more levers than the press treatment usually suggests, and is increasingly willing to use them — particularly through procurement.

What operators should track

  • Quebec. The leading indicator for federal Canadian regulation. New Quebec AI rules in 2026 will likely shape Ontario’s rules in 2027.
  • The OPC’s AI casework. Each new investigation tells you how PIPEDA is being applied to AI in practice. Watch the press releases.
  • Federal procurement guidance. Even if you don’t sell to government, federal procurement rules tend to set the floor for private-sector vendor expectations.
  • Provincial public-sector procurement. Ontario and BC are quietly building the most consequential rules for vendors selling to provincial agencies.
  • The next federal AI bill. Unlikely before 2027, but its shape is becoming visible. The replacement column has the current read.

Sources & further reading