Policy document · 7 September 2026 · For discussion, not government policy
From Readiness to Royal Assent
A roadmap to Canadian AI legislation
A roadmap to Canadian AI legislation
Policy document | 7 September 2026 | For discussion, not government policy
This document states the safety objectives that Canadian AI legislation should serve, the constitutional boundaries that determine what is actually within Canada's control, a factual account of the Artificial Intelligence and Data Act and the objections that met it, and the design decisions that follow from both. It closes with a staged gate structure from readiness to introduction. It recommends no bill. It is a companion to the strategy Canadian AI Policy: Accountability at Home, Capability Pooled Abroad (7 September 2026) and is written to stand alone. Instrument statuses are as of the evidence cutoff; re-verify at any decision point.
1. The safety objectives the statute must serve
The companion strategy defines safety as answerability: someone specific, by name, with stated evidence, under a stop condition someone can actually trigger. A passed statute that answers only "the minister is responsible" is not a safety statute; it is a press release with sections. Translated into legislative objectives, this becomes five obligations on the statute itself — each stated as an objective, because the bill's job is to make every obligation enforceable:
- A named, accountable decision owner for every AI-enabled government decision, with the owner's consequence-earning duties written into the act itself.
- An AI Risk Evidence Record with legal status — the field structure is described in the strategy — attaching consequence to refusing to state what was decided, on whose behalf, with whose evidence, subject to what revision.
- Accessible remedy for affected persons — a route any individual exposed to a consequential decision can actually invoke. Not only enforcement machinery available to the state after the harm has already occurred.
- Independent oversight with investigation powers of its own, not embedded in the department that promotes AI development.
- A distinct Indigenous data and decision-power chapter hard-wiring the information–consultation–co-design–consent–oversight–refusal ladder, with the pre-condition that engagement precedes siting and any use of Indigenous data, knowledge, or languages.
Two further objectives apply to the statute as a whole: an interoperability requirement (records structured to be legible to the EU AI Act, allied assurance regimes, and the federal Algorithmic Impact Assessment, without claiming legal equivalence), and the common safeguard floor applied per order of government (federal, provincial, territorial, municipal), so each level carries the same floor content within its own powers and no single level claims supremacy over the rest.
2. What "within our control" has to mean before drafting starts
The hardest lesson from the last attempt is jurisdictional, and it is not negotiable. The Supreme Court of Canada's Reference re Impact Assessment Act (2023) delivered the warning every federal AI drafter should read before writing a word: an intention to regulate does not create jurisdiction. Declaring that the act is about "international and interprovincial trade and commerce in AI systems" does not make a university researcher's bench or a provincial court's workload federally regulable.
A roadmap built to survive that warning works from the instruments Canada can actually enforce, in declining order of certainty:
- Federal operations and spending: the government's own decisions, procurement, and contracting — the strongest available anchor. Ottawa may set conditions on its own purchases and programs, and the non-voluntary relationship between Canadians and their government is where the risk is highest and the authority is clearest. Start there.
- Federal works and undertakings and genuinely interprovincial or international commerce: a defensible trade-and-commerce anchor exists, but it must be drafted against the Impact Assessment Act guidance, with a constitutional mindset about what "high-impact" captures — and what it cannot.
- Federal–provincial–territorial arrangements: the safeguard floor is designed as content each order of government may enact within its own heads of power. That is a deliberate contrast with a uniform-code approach: it avoids constitutional overreach while still producing a common minimum. It must be negotiated, not asserted.
- Standards and market conditionality: compliance requirements attached to market access and procurement conditions — the allied-market instrument of the strategy — operate through each member's own authorities, and they are the one lever that reaches foreign providers without extraterritoriality.
- Statement of what is out of reach: pure domestic basic research and intraprovincial private activity are beyond the federal anchors as currently understood. The statute must not pretend otherwise. Pretending — two years ago — is how a bill dies.
The roadmap therefore treats "within our control" as a drafting rule, not a talking point: every obligation in the act is tagged to the head of power that carries it, and anything untagged moves to an FPT arrangement or is cut in the first draft — before it is tested in court, not after.
3. Bill C-27 and the Artificial Intelligence and Data Act — what it proposed
For the record, and because any successor bill will be judged against it:
Timeline. The Artificial Intelligence and Data Act (AIDA) was introduced in June 2022 as Part 3 of Bill C-27, the Digital Charter Implementation Act, 2022, tabled alongside a privacy-law reform (the Consumer Privacy Protection Act). It underwent parliamentary committee review and an amendment package introduced 28 November 2023, and died on the Order Paper when Parliament was prorogued on 6 January 2025. It never came into force.
What it proposed. A risk-based framework:
- A general duty on anyone designing, developing, making available, or managing an AI system for international or interprovincial trade and commerce to assess whether the system is a "high-impact system" — the November 2023 amendments replaced "high-impact" as a regulations-left definition with an initial schedule of high-impact classes (intended big-picture classes covering safety-critical sectors, eligibility-affecting systems, employment, biometric identification, health, and similarly consequential uses).
- For high-impact systems: measures to identify, assess, and mitigate risks of harm or biased output, to continuously monitor the effectiveness of those measures, and to keep records of both.
- Transparency obligations: plain-language public descriptions of a high-impact system's purpose, capabilities, limitations, and potential impacts.
- Incident response and reporting, as added in the November 2023 amendment package: a duty to assess suspected serious harm (including near-misses), to produce an incident report to the AI and Data Commissioner, and — where serious harm occurred or could not be mitigated — to cease operations until the system could be modified.
- Prohibitions with criminal penalties: knowingly possessing or using unlawfully obtained personal information for AI design or development; making an AI system available knowing or being reckless that it would cause serious harm or substantial damage to property, or substantial economic loss to an individual. Fines for prosecutable offences were proposed at up to $25 million or 5% of global revenue, whichever was greater; less serious contraventions would have carried administrative monetary penalties created by later regulation.
- Enforcement architecture: powers vested largely in the Minister of Innovation, Science and Industry, supported by an AI and Data Commissioner created within ISED — the November 2023 amendments moved investigation, audit, and scope-determination powers to the Commissioner and enhanced information-sharing, while leaving the Commissioner a civil servant inside the promoting department.
The objections it gathered. The bill was contested across parties and by civil-society and academic critics, on grounds that recur:
- Scope and certainty: "high-impact" was initially left to future regulation, and mid-stream amendments re-architected the act while it was being debated — producing a moving draft that critics called under-specified and unpredictable in exactly the provisions carrying penalties of up to $25 million or 5% of global revenue.
- Overreach vs. underreach: critics simultaneously alleged criminal penalties for conduct defined only in future regulation ("a law that defines no goals or oversight"), and argued the drafting strayed into pure R&D — university basic research — that the federal criminal or trade powers plausibly cannot touch, a constitutional exposure the Impact Assessment Act reference later underscored.
- The government exclusion paradox: a bill built to regulate commercial activity only, which categorically left government use — immigration, policing, benefits, custody classification — outside its scope. That inverts the risk hierarchy. The state's relationship to the citizen is non-voluntary, and the state was the party least covered.
- No individual remedy: compliance machinery for regulators, offences for prosecutors — and for a person harmed by a consequential automated decision, no statutory path of their own.
- Commissioner independence: the AI and Data Commissioner sat inside ISED reporting to the promoting minister — a structural conflict by design, at odds with the officer-of-Parliament model used by the Privacy, Competition, and Human Rights Commissioners.
- International misalignment: the "high-impact" architecture was deliberately not the AI Act's provider/deployer design; near-miss definitions and incident classes diverged from partners, and the allied-market mechanism — which requires portable compliance findings — was not part of its design.
- Promoter-regulator conflict: the act was drafted by the department whose economic-development mandate includes promoting the industry being regulated. Critics read that as a conflict built into the institutional design, and the November amendments did not move the Commissioner out.
- Process: limited prior consultation, and much of the operative content deferred to future regulations — consultation promised after passage rather than structured into drafting.
4. What this roadmap does differently
The allied-market design adds a rule worth stating plainly: each member adopts the common floor into its own law and keeps its own specific rules above the floor; the floor is the minimum any AI offering in that market must satisfy, and how each member reaches it stays within its own jurisdiction. Compliance in one market confers standing in all of them, because the floor is one.
The objections above are not resolved by re-litigating them. Each one leads to a design decision, and every decision below is a feature this roadmap commits to:
| Objection to AIDA | Design answer in this roadmap |
|---|---|
| Scope deferred to future regulation, penalties attached to moving definitions | The schedule and the floor are named in the act, with the readiness plan arriving before the bill, so scope arguments happen at drafting, not at prosecution |
| Government excluded while it is the highest-risk user | The statute begins with federal institution decisions — the non-voluntary relationship — and carries the AIA/evidence-record instruments as its core |
| No individual remedy | Affected-person recourse is an objective of the statute itself (item 3, section 1 above), not enforcement machinery borrowed from the privacy regime |
| Commissioner inside the promoting department | Independent oversight — officer-of-Parliament on the model Canadian law already uses; the promoting and regulating functions are separated across ministers |
| Constitutional exposure via broad trade-and-commerce drafting | Each obligation is tagged to its head of power in drafting; unanchored conduct is routed to FPT arrangements instead of asserted federally |
| Misaligned with partner regimes | Interoperability as a legislative requirement from section 1, designed around the shared evaluation record's format and the allied market's compliance perimeter |
| Regulatory + promotional functions in one ministry | The readiness plan assigns map and enforcement design to Justice; the AI minister's promotional mandate is insulated from the enforcing body |
| No workers' or community participation pathway | The decision-power ladder — information through refusal — is hard-wired for Indigenous rights-holders and applies as a participation floor for affected workers and communities |
| Consultation after passage | Consultation structures the drafting: the Indigenous chapter is reviewed on rights-holders' terms before the bill is tabled; the pilot evidence record supplies the field-tested instrument the statute then adopts |
5. The roadmap itself — staged, conditional, dated
| Stage | Timing | Deliverable | Decision owner |
|---|---|---|---|
| 1. Readiness | Days 1–90 of the feasibility window | Justice Canada–led map: authorities per safety objective, conduct in scope by head of power, enforcement powers, individual remedies, FPT arrangements, Indigenous interface, interactions with privacy and online-safety bills | Justice Canada, with TBS and ISED |
| 2. Pilot | Months 1–12 | Evidence record piloted inside the allied-market challenge; blinded evaluation published, whether or not flattering | Minister of AI and Digital Innovation; pilot decision owner named |
| 3. Design | Months 9–18 | Bill architecture built from the map and the pilot: named floor, evidence record with legal status, individual remedies, independent oversight, Indigenous chapter, interoperability requirements | Justice Canada, with the AI minister and FPT partners |
| 4. Consultation | Months 12–21 | Structured public, worker, and Indigenous consultation on the bill design, before introduction — reversing AIDA's consult-after-passage sequencing | Justice Canada and the AI minister |
| 5. Introduction | When stages 1–4 complete and Cabinet approves | A minister's decision on a bill — proceed, redesign, or defer — recorded with reasons | Cabinet |
The staged gate above is deliberately not a legislative calendar. Each stage's output is published evidence that the next stage consumes: the map, the pilot evaluation, the design note, the consultation record, the bill. Nothing proceeds because a date passed. It proceeds because the output it depends on exists. A stage that fails its gate restarts the roadmap at the failure point, not at the end.
6. What this document does not settle
Consistent with the doctrine: Parliament enacts the statute this roadmap prepares, or it does not, and no sentence here is law. Penalty figures from AIDA are historical — cited as what was proposed, never as what is recommended. The Indigenous chapter's sequencing (review before anything is treated as settled) applies to this document and to the companion strategy alike. Every claim carries its instrument status from the evidence cutoff; statuses are re-verified at any decision point.
Sources
- Bill C-27, Digital Charter Implementation Act, 2022, including the Artificial Intelligence and Data Act (introduced June 2022; died on the Order Paper 6 January 2025 at prorogation — lapsed proposed legislation, cited as history, not law).
- Minister of Innovation, Science and Industry, Provision of amendments to Bill C-27 / AIDA, 28 November 2023 (proposed amendment package as circulated).
- ISED, The Artificial Intelligence and Data Act (AIDA) — Companion document (official government description of the proposed framework at time of introduction).
- House of Commons committee record and 2025 legal analyses (Fasken; McInnes Cooper; Baker McKenzie) cataloguing prorogation effects and AIDA's objections as raised by parliamentarians and published commentary.
- Reference re Impact Assessment Act, 2023 SCC 23 (constitutional-jurisdiction warning authority for the drafting discipline in section 2).
- The companion documents carry current instrument-status checks; nothing above substitutes for a point-in-time legislative check at decision.