“Is there an AI law in Canada?” is the question a compliance officer gets from a board, a client or a founder at least once a month now, and the honest answer in September 2026 is still no, not a general one. The Artificial Intelligence and Data Act, the part of Bill C-27 that was meant to be Canada’s answer to the EU’s AI Act, died on the order paper when the parliamentary session ended on January 6, 2025. Nothing has replaced it.
That does not mean nothing applies. For a crypto trading platform, a payments company, a fintech or a bank, AI is already regulated in Canada, just not under that name. The rules sit inside securities law, prudential guidance, privacy law, competition law and the anti-money-laundering regime, and several of them carry dates that matter this year and next. This is the map as of September 5, 2026, with every document linked.
What died with Bill C-27
Bill C-27 bundled three things: a new private-sector privacy law, a tribunal to enforce it, and AIDA. LEGISinfo still shows the bill frozen at “consideration in committee in the House of Commons” for the session that ran from November 22, 2021 to January 6, 2025. When that session ended, the bill lapsed with it. Industry, Science and Economic Development Canada’s page on AIDA is now stamped as archived and names no successor.
A search of every bill in the current Parliament, the 45th, turns up no bill with “artificial intelligence” in its title. The nearest things are a privacy bill (below), a digital-safety bill introduced June 10, 2026, and a private member’s bill on deepfakes that sits outside the order of precedence. So the framework Ottawa promised in 2022 is, for now, a strategy and a set of consultations rather than a statute.
What Ottawa built instead: a minister, a strategy, a consultation
The government’s answer to AIDA’s death was structural rather than legislative. On May 13, 2025, Prime Minister Carney named Evan Solomon Canada’s first Minister of Artificial Intelligence and Digital Innovation. An AI Strategy Task Force followed in September 2025 as part of a 30-day national sprint, and a public consultation ran from October 1 to 31, 2025, drawing more than 11,300 respondents who, in ISED’s summary, asked for “transparent governance, risk-based regulation and Indigenous data sovereignty principles.”
The result is AI for All, the national strategy launched on June 4, 2026. It is mostly money and targets: $700 million in sovereign compute through an expanded Compute Access Fund, a $500 million Canadian Tech Growth Fund, $50 million for the Canadian AI Safety Institute, $200 million for health, a goal of raising business adoption “from 12 percent today to 60 percent by 2034,” and “up to 250,000 new jobs through the adoption of AI by 2031.” Two lines matter more to a compliance desk than the dollar figures. The strategy says “Canada will modernize consumer privacy legislation to enshrine a fundamental right to privacy,” and that “Canada will create a Canada Trusted AI Certification program.” Neither has a date.
The one live process with a deadline is the AI transparency consultation that opened July 23, 2026 and closes September 23, 2026. It asks about detecting and labelling AI-generated content, telling people when they are dealing with an AI system, tracking serious AI incidents, and “advancing ways to better track the activities and interactions of AI agents.” That last item is the one for anyone building agents that move money, including the stablecoin-paying agents Canadian founders are prototyping. The release makes no commitment to legislation.
The money side was set earlier. Budget 2025, tabled November 4, 2025, proposed $925.6 million over five years for “large-scale sovereign public AI infrastructure” and $25 million for a Statistics Canada program to measure AI adoption, on top of the $2 billion Canadian Sovereign AI Compute Strategy announced in December 2024. Budget 2026 had not been tabled as of this writing.
If you are a registrant: CSA Staff Notice 11-348
For a crypto trading platform, a dealer or an adviser, the operative document is CSA Staff Notice and Consultation 11-348, published December 5, 2024. It does not create new rules. It explains how existing ones apply, which is how the Canadian Securities Administrators tend to regulate new technology, and it is blunt about accountability: “Market participants are responsible for the outputs of the technology they use, including AI systems, and must ensure that those outputs do not result in conflicted decisions.”
The practical expectations, in the notice’s own words:
- AI systems used by registrants “should provide an appropriate degree of explainability so that registered firms are able to meet applicable record keeping requirements.”
- Policies should cover “robust testing prior to deployment,” a “human-in-the-loop, where humans can effectively monitor the input and/or output of an AI system,” and “adequate AI literacy of those using the outputs.”
- “Registrants cannot outsource registerable activity” to a system. A model can draft a suitability note; a registered individual owns it.
- Firms “should consider existing disclosure obligations when deploying AI systems,” and inflated claims about AI capability, which the notice calls “AI washing,” can offend the rules that already govern misleading statements.
Comments closed March 31, 2025. The OSC’s AI hub has added a May 6, 2025 report on how issuers describe AI in their financial disclosures, alongside its September 2024 research on AI and retail investing, but lists no 2026 rule proposal. For the platforms on the CSA’s registered list, that means the standard today is 11-348 plus the ordinary registrant obligations, applied to whatever model is in the stack.
We could not find a standalone notice on AI from CIRO, the dealer self-regulator, as of September 5, 2026. Its existing supervision and suitability rules apply to any tool a dealer uses, AI or not.
If you are a bank, insurer or trust company: OSFI E-23
The federally regulated institutions that custody, bank or insure the crypto sector answer to OSFI, and OSFI has done the one thing Parliament has not: it wrote AI into a binding guideline with a date. The final Guideline E-23, Model Risk Management, published September 11, 2025, takes effect May 1, 2027 for banks, foreign bank branches, life and property and casualty insurers, fraternals, and trust and loan companies.
Its definition of a model is deliberately wide: “An application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI/ML methods, which processes input data to generate results.” Institutions are told to staff model risk “with the requisite skills and experience, particularly for novel technologies, like AI,” to weigh “the level of transparency and explainability required” and the “potential for the model to lead to biased outcomes,” and to build “processes for handling AI/ML’s unique challenges, such as autonomous decision making.”
The scale of what E-23 governs is in OSFI and the Financial Consumer Agency of Canada’s 2024 risk report: about 50 percent of federally regulated financial institutions used AI in 2023, and 70 percent expected to by 2026. The follow-on FIFAI II report of March 23, 2026, co-authored by OSFI, the Global Risk Institute, Finance Canada, FINTRAC, the FCAC and the Bank of Canada, proposes an “AGILE” framework (Awareness, Guardrails, Innovation, Learning, Ecosystem Resiliency) and records that “deepfake attacks have seen a twentyfold increase over the last three years.”
Privacy: PIPEDA today, Bill C-36 tomorrow, Quebec already
Privacy is where AI regulation actually lives in Canada, and the Privacy Commissioner says so plainly.
Personal information is at the heart of artificial intelligence, and therefore privacy legislation should, in my view, be at the heart of AI regulation. Philippe Dufresne, Privacy Commissioner of Canada, remarks of March 5, 2026
Federally, PIPEDA still governs, backed by the Commissioner’s nine principles for generative AI, updated May 6, 2025. The replacement is Bill C-36, the Protecting Privacy and Consumer Data Act, introduced by Minister Solomon on June 15, 2026 and at second reading as of this writing. ISED’s release says PIPEDA “was written before artificial intelligence (AI) at scale, before deepfakes, before algorithmic decision making,” promises that organizations will have to be “transparent about their use of automated decision making for significant decisions about individuals,” and sets penalties “of up to $10 million or 3% of global revenue, whichever is greater,” with fines “of up to $25 million or 5% of global revenue” for the most serious offences.
Quebec is already there. Section 12.1 of the province’s private-sector privacy act requires anyone who “uses personal information to render a decision based exclusively on an automated processing of such information” to tell the person, to give “the reasons and the principal factors and parameters” on request, and to let them “submit observations.” A platform that auto-declines account openings or auto-flags withdrawals for Quebec customers is inside that section now.
Anti-money-laundering and fraud
FINTRAC has not issued guidance on how reporting entities may use AI, but its own posture is clear: the agency’s 2024-25 annual report says it is “enhancing its risk detection and analysis processes through automation, data analytics, artificial intelligence and machine learning.” The threat side is spelled out in Finance Canada’s 2025 National Inherent Risk Assessment: “Generative AI tools can produce counterfeit identification documents, which can be used to establish shell companies or open bank accounts,” generative AI “can automate and obscure financial transactions,” and “the use of chatbots and AI-generated persuasive emails is expected to further escalate fraud and scams.” For a platform’s onboarding team, that reads as a warning about synthetic ID documents arriving at scale.
Competition and the central bank
Two more voices round out the picture. On May 20, 2026 the Competition Bureau, the Privacy Commissioner, the Copyright Board and the CRTC published joint principles stating that “firms remain accountable for their conduct, regardless of whether AI is involved or not,” and the Bureau said in January it is “committed to closely monitoring developments relating to algorithmic pricing.”
The Bank of Canada’s 2026 Financial System Survey, published May 28, 2026, found respondents “generally view AI less as a standalone source of financial stability risk and more as a risk amplifier that could intensify existing vulnerabilities,” with integration (58 percent) and talent (56 percent) the main barriers. A Bank research note in August 2026 added a reality check on the hype: “only 8% of businesses in the survey said they use AI significantly in their core operations.”
The consumer side of the same technology, the deepfake ads and cloned voices that regulators warn about, is covered in our guide to AI crypto scams in Canada, and the compute behind it is the subject of our report on Canada’s bitcoin miners becoming AI data centres.
Provincially, Ontario’s Bill 194 received Royal Assent on November 25, 2024 and defines an AI system, but it binds public-sector bodies only and comes into force by proclamation. We could not confirm any AI-specific statute in Alberta or British Columbia.
What to watch next
Three dates. September 23, 2026, when the transparency consultation closes and Ottawa decides whether “tracking AI agents” becomes a rule. The progress of Bill C-36 through the fall sitting, since it is the vehicle for the automated-decision transparency the strategy promised. And May 1, 2027, when E-23 starts to bite. CryptoCanucks will track each of them in the law tracker, alongside the crypto-specific rules the same firms already follow. The Canadian AI companies that will feel these rules first, from Cohere to the research institutes, are in the directory, and the policy conversations happen in person at ALL IN 2026 in Montréal on September 16 and 17.


