Nathaniel Arfin

Policy document · 7 September 2026 · For discussion, not government policy

Canadian AI Policy: Accountability at Home, Capability Pooled Abroad

A strategy for safety, legislation, and allied market power

A strategy for safety, legislation, and allied market power

Strategy document | 7 September 2026 | For discussion, not government policy

Partagez les preuves et les capacités. Ne transférez jamais l'autorité. Gardez le recours là où se prend la décision. Share the evidence and the capabilities. Never transfer the authority. Keep the remedy where the decision is taken.

What this document is

Here is the argument, in three moves. First: what AI safety actually consists of for a government deciding whether to authorize, procure, deploy, or restrict an AI-enabled system — which is not what most safety conversations assume it is. Second: what domestic legislation would have to contain to make that definition enforceable, and what an honest interim looks like while the statute doesn't exist. Third: how Canada builds the power that neither safety nor legislation can be exercised without — through a multilateral alliance whose central instrument is pooled market power.

Everything rests on one distinction. Evidence and capability should move freely among partners; legal authority should not move at all — and every remedy should stay attached to whoever actually decides. Everything else follows from that line.

This document authorizes nothing. It names the situation, states what Canada should be building toward, and asks specific ministers to begin specific feasibility work under stated conditions. That is what a strategy is, at this stage.

1. Safety first: what safety actually looks like

Safety is answerability, not performance

Ask most people what "AI safety" means and they'll describe a technical checklist: capability benchmarks, red-teaming, error rates, alignment testing. Those matter. But they are not the whole story, and two cases — one British, one Ontarian — show exactly what a safety regime built on that checklist alone misses, in opposite directions.

In 2017, the UK Information Commissioner found that the Royal Free NHS had handed Google DeepMind the records of over 1.5 million patients without a lawful basis — for an application that was clinically valuable and technically sound. Read that again. The model worked. The failure ran through data governance, institutional authority, transparency, and accountability: the system performed, and the arrangement was still a governance failure with a privacy violation at its centre.

Ontario's SAFER tool is the mirror image. SAFER — an automated risk-scoring tool used in Ontario's provincial correctional system to help set security classification — governs movement, visits, programming, and family contact for people held on remand who have not been convicted of anything. Its defenders say a human is in the loop. A human in the loop is not oversight. The score's causal contribution to observed racial disparities is not established, the people most affected cannot meaningfully obtain or challenge their scores, and no reviewer's override is meaningful without the authority, information, independence, and practical ability to reject the score. Neither case turned on how capable or how autonomous the system was. Both turned on who was exposed, who could contest, and who could stop it.

So the definition this strategy adopts is this one: a system is safe to the extent that someone specific can be held answerable for it — by name, with stated evidence, under a stop condition someone can actually trigger.

"Someone specific" is doing deliberate work. A safety regime that leans on a vendor's good practice, an operator's judgment, an auditor's eventual report, or a minister's general responsibility answers "who decides?" and leaves untouched what anyone harmed can do about it. Safety without a nameable claimant is a management preference, not a right — and it does not survive the first incident.

Three disciplines follow. They apply to any deployment Canada touches, domestic or allied:

Name the decision owner. Every AI-enabled intervention in government — procurement, deployment, expansion, restriction, pause — has a specific accountable authority behind it. If the owner cannot be named, the decision has not actually been made; it has drifted through a procurement calendar or a vendor relationship. A completed assessment whose recommendations no named owner must act on is documentation theatre: a form standing in for a decision already settled.

State the status of every claim. Claims carry five possible states: observed or documented, reported, contested or alleged, unknown, refuted. A benchmark result is capability under stated conditions — not evidence of exposure, harm, or lawful use. A corporate case study documents reported use, not independent effect. An official regulatory finding establishes what it found, in its jurisdiction, and nowhere else. "A governance case's reasoning questions travel; its legal rules and institutional facts do not transplant." This is not pedantry. It is what makes a reliance decision — leaning on shared evaluation evidence from partners — honest rather than quietly outsourced.

Attach a stop condition. Every deployment states, in advance, what evidence or conditions would trigger pause, restriction, or termination — and names who has the standing and the practical capacity to trigger it, and who is empowered to act. A stop condition that requires a capacity nobody possesses is not a control; it is an aspiration with a form number. Where the exposed party and the decision owner are different parties — a prisoner and a correctional ministry; a patient and a procurement authority — the record makes that gap explicit, so the authority that can act is told, in terms it must answer, who cannot reach it.

These disciplines are reasoned, not invented, and reasoned here as they would be for any jurisdiction: authority in Canada is distributed across federal, provincial, territorial, municipal, and Indigenous governments, so Canada cannot defer to one comprehensive code the way a single-statute jurisdiction can. For every instrument — statute, directive, guidance, voluntary code, strategy, procurement term — it must ask what the instrument is, whom it binds, what duty it creates, and what remedy it offers. That is a heavier discipline than one code would demand. It is also the one Canada's constitutional structure actually imposes.

What safety looks like when the capability is pooled

The above applies to a single system. But safety at the level of the stack — compute, models, infrastructure, supply chains — runs through a different channel, because the stack is not a system any one government authorizes. No middle power can secure it alone. Governing stack-level risk — coercive dependency, opaque infrastructure, capability concentrated in unaccountable providers — is therefore not a domestic statute question or an alliance question. It is both at once, and the sections below are the domestic and international halves of the same design.

2. What domestic legislation should look like

Canada is in a specific, structural bind, and it should be named plainly. There is a national AI strategy (AI for All, June 2026) that commits to safety-first governance in law, and a minister responsible for the portfolio. There is no federal AI statute: the Artificial Intelligence and Data Act died on the Order Paper at prorogation in January 2025. A strategy directs money and attention. It creates no enforceable duty, confers no right, and provides no remedy. Authority and remedy have been separated at the level of the state: naming the minister answers who decides, and leaves untouched what anyone harmed can do.

The honest framing is not "Canada needs to catch up by passing any bill." It is: Canada needs legislation shaped by the doctrine above, and by Canada's constitutional structure — not imported from a single-statute jurisdiction that doesn't share it. Four design requirements separate a Canadian AI act from a copy of someone else's:

1. A common safeguard floor, applied differently by each order of government. The act should define what every AI-enabled government decision must satisfy, at any level of government, wherever it occurs: lawful authority; rights and privacy review; identification of affected interests; representative evaluation; meaningful accountability, with a named decision owner; accessible recourse; and explicit stop conditions. This is content, not structure: it is what any Canadian AI statute must contain — and what a provincial statute, a territorial directive, or a municipal procurement rule must contain to participate in the same defence of the same rights. Ontario's Auditor-General findings this year — approximately 12,000 staff reaching some 400 AI websites (about 60% rated unsafe), 3% completing responsible-use training, a facial-matching validation on 214 people, and all 20 approved AI scribe vendors producing inaccuracies with 11 of 20 lacking third-party audit — show deployment conditions and procurement controls deciding outcomes on their own, in a jurisdiction acting with no common floor. That is what the absence of a floor looks like.

2. An AI Risk Evidence Record with legal status, not just a field list. The reasoning disciplines in Section 1 — named owner, stated evidence status, stop condition — need an instrument to live in. Canada already has a structured assessment aid (the federal Algorithmic Impact Assessment). What it lacks is a record that ties evidence provenance, causal assumptions, affected interests, controls, residual risk, decision ownership, and revision conditions to a named accountable authority — with a bilingual, accessibility-tested, subgroup-disaggregated evaluation requirement, and Indigenous data-governance questions flagged ahead of design. A statutory evidence record is where answerability becomes enforceable: it attaches a consequence to refusing to state what was decided, on whose behalf, with whose evidence, subject to what revision. This strategy treats the record as a design proposal to be piloted and legislated in stages, not as something ministers can be asked to bind by executive fiat — see the asks at the close.

3. A distinct Indigenous data and decision-power chapter. First Nations, Inuit, and Métis peoples hold distinct governments, rights, protocols, and knowledge systems relevant to AI data collection, evaluation, reuse, and outputs. The distinction that matters legally and morally is the decision-power ladder — information, consultation, co-design, consent, oversight, refusal — and the requirement that a completed consultation never be recorded as consent. A consultation is not consent. A statute must name which rung applies where, before any engagement, and make the answer auditable. Engagement must precede, not follow, infrastructure siting and any use of Indigenous data, knowledge, or languages. This element of the analysis has not itself been reviewed by the rights-holders it names; it must be, on their terms, before anything here is treated as settled.

4. Interoperability as a legislative requirement, not an aspiration. The act should require that its evidence records are structured to inform, and be informed by, equivalent instruments in partner jurisdictions — the EU AI Act's conformity assessments (the AI Act being the European Union's binding, single-market AI regulation, enforceable in part by the European AI Office), US and allied-sector assurance regimes, Canada's federal Algorithmic Impact Assessment, provincial analogues — without pretending those instruments are equivalent in law. This is the domestic anchor for Section 3: a statute that makes Canadian authorities legible to partners is a sovereignty instrument, because it lets pooled markets treat Canadian compliance findings as portable — and treat non-compliance as finding-tested, not discretionary.

Until that statute exists, the authorities that exist must be used and named honestly: the amended federal Directive on Automated Decision-Making (a Treasury Board instrument binding covered federal institutions) and the Algorithmic Impact Assessment for federal deployments, procurement conditions for joint challenges, provincial and municipal analogues where they apply, and the readiness plan below.

The readiness plan — the act, prepared, not yet argued

Statutory work should be prepared, not rushed. The companion document From Readiness to Royal Assent: A Roadmap to Canadian AI Legislation (docs/ai-legislation-roadmap.md) states what the act must achieve, what is within federal control, what Bill C-27/AIDA proposed and what its critics established, and the staged gate structure from readiness to introduction. The 90-day feasibility window this document requests includes its stage 1 — a Justice Canada–led legislative readiness item, returning with: which authorities the evidence record needs, which conduct the floor would regulate, what enforcement powers it would need, what remedies affected people could invoke, the federal–provincial–territorial (FPT) arrangements required, the interface with Indigenous rights-holders, and interactions with proposed privacy and online-safety bills. The plan asks for no bill. It asks for the map, so that a bill is argued from a stated design rather than improvised from pressure.

3. Scaling power: allied markets, pooled capability, collective response

No middle power can secure the full AI stack — compute, models, energy, data, talent, evaluation capacity, market leverage — alone. The strategy's first two sections define safety and say what legislation should contain. This section is about what makes both credible: the ability to enforce, and the access to something worth enforcing against.

A middle power regulates by controlling access to something the regulated want. A middle power alone controls nothing worth that price. The United States and China organize technology ecosystems at a scale Canada cannot match; the European Union is building nineteen AI Factories and up to seven gigafactories, currently framed around European users. Canada's 2026 strategy names the direction — a strategic multilateral alliance pooling research, talent, compute, and procurement. Canada and Germany launched the Sovereign Technology Alliance in February 2026; Norway and Finland are publicly exploring participation. No pooled capability exists yet. This section is how the alliance converts alignment into power.

The alliance

The alliance needs a public identity before it can expand beyond its bilateral core. Naming is treated as a go/no-go test in its own right: any proposed identity proceeds only if partners support it and it clears federal linguistic, trademark, and identity review. Canada and Germany would remain bilateral co-founders. The European Union, represented by the European Commission within its competences, would be invited as a founding institutional partner; France as a founding design partner. No partner is presumed committed. National and Union authority are kept separate throughout.

Three workstreams convert that architecture into capability, and each pairs a pooled capability with a Canadian governance condition under Section 1's disciplines:

Compute. Reciprocal, pre-negotiated access to sovereign compute — national or tightly governed high-performance AI computing capacity — for approved researchers, firms, and public-interest workloads: a federated catalogue, reserved capacity, common security and data-residency standards. No eligibility is assumed. Access is negotiated, with a named allocation authority and Canadian-priority and cost-recovery arrangements resolved before any promise.

Shared evaluation record. A common report format and joint evaluations, so that testing in one member country can inform assessment in another — with the European AI Office participating where general-purpose models or AI Act implementation are engaged. The record creates no model approval, no presumption of conformity, no transfer of liability: it informs assessment. It does not replace it. It carries Section 1's five evidence states, versioning, model-change triggers, and reassessment rules in its format, not as a footnote.

Coordinated procurement — wildfire and smoke situational awareness. A common problem statement and evidence framework; separately competed, separately authorized procurements under the Canada–EU Comprehensive Economic and Trade Agreement (CETA) and each buyer's own procurement law; transparent performance, accessibility, and security benchmarks; a pathway for compliant suppliers to sell across participating markets. The European AI Office is not required here. Participating buyers' own laws are.

The allied market

The workstreams build capability. The allied market is where capability becomes power.

Participating members would converge on a common set of transparency, safety, evaluation, and security requirements for providers — vendors, labs, model suppliers, cloud and infrastructure operators — seeking access to participating markets. Compliance with one member's requirements confers standing across the allied market. Failure — opacity where transparency was required, unsafe deployment, refusal of evaluation — makes a provider subject to exclusion by all participating members. The provider faces the consequences of non-compliance in the combined market, not one jurisdiction at a time.

The mechanism is deliberately described so its limits are stated, not implied: the requirements are jointly defined through the evaluation-record and standards work; the bar is coordinated, not automatic — each member administers exclusion within its own authority, through its own procurement rules, regulators, and market-access instruments (CETA coverage, EU procurement law, state-aid and competition rules preserved, with no named firm advantaged). Pooling lies in having one compliance perimeter and jointly made enforcement decisions, separately executed. That is what keeps the mechanism inside the doctrine: evidence and market consequence move together across partners; each legal act remains Canada's, the EU's, or another member's own.

The allied market also carries a collective-response mechanism within the participating group: any member facing coercive use of stack dependency — a cutoff, a weaponized dependency, pressure applied through a provider — can invoke consultation, with partners committing to a menu of coordinated responses drawn from the same market instruments: aligned procurement demand, reciprocal compute reservation, preference for the affected member's trusted suppliers, coordinated export and allow-list positions. Each response is separately authorized. None is triggered automatically. The power is in the standing commitment to consult, and in the fact that every lever it can reach — market access, compute capacity, procurement demand — is a lever the alliance actually holds.

For a provider whose economics depend on trusted-market access, this is a stronger and cheaper discipline than any regulation Canada could enact alone: a compliance perimeter that travels with the provider into every participating market, one that cannot be routed around by choosing a friendlier regulator. The deterrent is the same fact that makes the markets worth pooling. Canada alone cannot credibly secure either half. The requirements without the pooled market are conditions nobody must meet; the pooled market without the requirements is just a bigger market with no standards. Each half is the other's enforcement mechanism.

What this track explicitly does not do

Security and defence cooperation proceeds only through existing protected channels. No new compute-infrastructure funding decisions ride on this strategy — access and co-investment optionality only; every dollar is a separate business case. No private-sector conduct is regulated by strategy language, guidance, or alliance norms: conduct rules enter through the statute readiness in Section 2 or through each member's own law. Each exclusion re-enters scope only by Cabinet escalation — the same mechanism that expands the strategy governs its growth.

What this asks of government

Ownership. The Minister of Artificial Intelligence and Digital Innovation owns the strategy — the name on its cover — jointly with the Minister of Foreign Affairs and with the concurrence of the Minister of Industry, with named co-sponsors per track: Global Affairs Canada and Innovation, Science and Economic Development Canada for the alliance; Justice Canada and the Treasury Board of Canada Secretariat for legislation and the shared record; Public Safety Canada and Natural Resources Canada for the wildfire mission. The Privy Council Office holds a named escalator: any track crossing another minister's authority moves to whole-of-government ownership, and Cabinet governs scope expansion from there.

The ask. A 90-day feasibility and partner-engagement phase across three tracks, under existing mandates, with no financial, procurement, infrastructure-access, or international commitment:

  1. Alliance: as set out in the alliance stakeholder document — co-design with Germany; joint soundings with the European Commission and France, then Norway and Finland; one detailed project feasibility case (recommended: wildfire and smoke situational awareness) and two concept screens; EU-competence and authority mapping; procurement, competition, state-aid, and security review; costed options and go/no-go assessment. Planning envelope unchanged: 8–10 seconded personnel and $300,000–$500,000 incremental operating funds for 90 days, released only against a workplan with a confirmed source of funds.
  2. Evidence record: pilot the AI Risk Evidence Record inside the wildfire challenge as the alliance's first joint project, co-designed with the Canada–EU Digital Partnership Council's existing public-good mandate — the bilateral channel that already commits both sides to cooperating on AI for public-good uses such as wildfire and flood modelling — with five-status evidence labelling, named decision owners, stop conditions, bilingual and accessibility-tested documentation, and Indigenous data-governance questions flagged before design.
  3. Legislative readiness: a Justice Canada–led mapping inside the same window, of the statutory authorities, enforcement powers, remedies, and FPT arrangements the evidence record and safeguard floor require — the map, not the bill.

Two named line items beyond the feasibility envelope, each planned and released under the same confirmed-funds rule: resourced Indigenous rights-holder review of this strategy's Indigenous provisions, on the rights-holders' terms, before that content is treated as settled or published; and blinded evaluation of the pilot evidence record against a pre-specified rubric, with participant-burden measured. Dollar figures are planning-estimate language for officials to cost; accountable owners are named above.

Measures of success (published at 12 and 24 months, whether or not flattering):

TrackBy 12 monthsBy 24 months
AllianceGermany agrees to an expansion framework; the Commission and at least three additional countries adopt the instrument matched to their status; one joint evaluation published; one coordinated procurement launched; Canadian firms and researchers receive documented new access to partner infrastructure or marketsReciprocal compute allocations operational; the evaluation record recognized as usable evidence by multiple public institutions; at least one challenge solution piloted to production; private co-investment attributable; per-project publish-or-close decisions taken
Evidence recordPilot record completed inside the wildfire challenge; blinded independent scoring against a pre-specified rubric; participant burden measured; results publishedThe record format in use across at least three federal institutions or buyers; the readiness plan's recommendations before ministers
LegislationReadiness plan delivered inside the 90-day return package, published to parliamentarians and committeeA minister's decision on a bill — proceed, redesign, or defer — recorded with reasons
Allied marketCommon requirements perimeter and collective-response menu agreed in design; one tabletop coordinated-response exercise runTwo provinces or territories have adopted the safeguard floor's terminology in their own AI guidance; the compliance-travel mechanism operating across participating markets

Status. For discussion, not government policy. Nothing here estimates the probability or severity of any AI harm. Evidence cutoff 7 September 2026; instrument statuses re-verified at any decision point. All partner positions prospective until agreed; no commitment is created by any sentence above.

Key sources

  • Innovation, Science and Economic Development Canada, Canada's National Artificial Intelligence Strategy: AI for All, June 2026 (policy strategy; not legislation).
  • Innovation, Science and Economic Development Canada, Canada and Germany sign AI joint declaration and launch Sovereign Technology Alliance, February 2026; Canada–Norway and Canada–Finland joint statements, March and April 2026.
  • Government of Canada, Joint statement of the first Canada–European Union Digital Partnership Council, December 2025; 2025 Canada–EU Summit joint statement, June 2025.
  • European Commission, AI Factories (updated August 2026); EuroHPC Joint Undertaking, AI Gigafactories call, July 2026; AI Act, consolidated text, July 2026.
  • Treasury Board of Canada Secretariat, Directive on Automated Decision-Making (amended June 2025); Algorithmic Impact Assessment (federal administrative instruments).
  • Office of the Auditor General of Ontario, Use of Artificial Intelligence in the Ontario Government, May 2026 (official audit findings).
  • Information Commissioner's Office (UK), Royal Free–Google DeepMind trial failed to comply with data protection law, July 2017 (official finding; UK law, cited for governance reasoning only).
  • Law Commission of Ontario, AI and the Assessment of Risk in Bail, Sentencing and Recidivism, April 2025 (bail, sentencing, recidivism scope; context for custody classification questions, not authority on SAFER).
  • N. Arfin, Assessing AI Risk for Policymakers: Ten Reasoning Anchors for Canada's Layered Governance, draft manuscript, evidence cutoff 3 September 2026 (author-proposed synthesis, not adopted as government doctrine; Indigenous-sovereignty sections pending rights-holder review).
  • N. Arfin, stakeholder pitch on a Canada–Germany platform for sovereign AI cooperation, August 2026, and research brief on European Union and France as founding partners, August 2026 (both for discussion; all partner positions prospective).