AIセキュリティ

Sixteen Months After AIDA Died: Canada’s Federal AI Gap, “light, tight, right,” and the Provincial Patchwork

Published2026-05-20Updated2026-08-01Ryuta Hamamoto

On January 6, 2025, Justin Trudeau announced his resignation and the Canadian Parliament entered prorogation.

Sixteen Months After AIDA Died: Canada’s Federal AI Gap, “light, tight, right,” and the Provincial Patchwork
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

On January 6, 2025, Justin Trudeau announced his resignation and the Canadian Parliament entered prorogation. In that moment Bill C-27 fell off the order paper, and AIDA (Artificial Intelligence and Data Act) died with it.

Sixteen months later, Innovation, Science and Industry is led by Evan Solomon and the new slogan is "light, tight, right." But as of May 2026, no successor bill has been tabled. While AI regulation moves worldwide, Canada alone continues a federal-level regulatory gap.

How to read that gap, and what Ontario and Quebec have done while Ottawa waits, is unavoidable for Japanese companies planning Canada expansion.

TL;DR

  • AIDA died with Bill C-27 in the January 2025 Parliament prorogation. As of May 2026, no successor bill
  • New Minister Evan Solomon: "light, tight, right." Original AIDA will not return as-is
  • Voluntary Code of Conduct: ~40 signatories, no legal force
  • Provinces fill gaps: Ontario Bill 194 (public-sector AI, July 2025) and Quebec Law 25 (private privacy + ADM)
  • Japanese strategy: "provincial patchwork + PIPEDA." Waiting on federal law will take a long time

The morning AIDA died: Bill C-27 timeline

How AIDA died. First the timeline1:

Period Event
June 2022 Bill C-27 introduced (CPPA + PIDPTA + AIDA three-pack)
November 2023 Government tables major amendments (response to criticism)
2024 full year House Industry, Science and Technology Committee: amendments and re-amendments
January 6, 2025 Trudeau resigns; Parliament prorogues; Bill C-27 dies
June 2025 Evan Solomon becomes Innovation Minister; signals AIDA will not return in original form
As of May 2026 No successor bill tabled

Bill C-27 bundled three statutes:

  • Consumer Privacy Protection Act (CPPA): PIPEDA successor with much stronger penalties
  • Personal Information and Data Protection Tribunal Act (PIDPTA): specialized privacy tribunal
  • Artificial Intelligence and Data Act (AIDA): federal AI law

The three-pack dragged AIDA down. Industry wanted privacy reform fast and AI law careful. One omnibus could not absorb that split. Schwartz Reisman Institute analysis also flags failure to spin AIDA into a standalone bill early as a major structural cause of demise2.

I present this to Japanese AI-governance leads as the cost of premature bundling. Multiple legal topics in one bill diffuse debate until nothing survives. Not unique to AIDA. A universal legislative pattern.

AI Security training, taken seriously

A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.

light, tight, right: what the slogan means

Since June 2025, Evan Solomon has repeated "light, tight, right." On the surface three adjectives. Decoded3:

  • light: regulation light enough not to choke innovation
  • tight: tight focus on real risks
  • right: right-sized for Canada's economy

It is Canada's positioning against EU AI Act (heavy and comprehensive), US federal (chaotic), and China (heavy and state-led). Of the three words, I find right-sized most important.

Canada's GDP is about $2 trillion; population under 40 million. Under 20% of the EU. Original AIDA leaned heavily on EU AI Act design. Frankly, it did not fit Canada's economic scale, and Minister Solomon seems to have internalized that.

Direction of a new bill is not officially published as of May 2026. Commentators expect forms such as:

  1. AI clauses inside existing PIPEDA / CPPA: amend privacy law rather than a standalone AI act
  2. Sector guidance: finance, health, employment guidance from the Office of the Privacy Commissioner
  3. International standards references: ISO/IEC 42001, NIST AI RMF named in statute

Closest analogue: UK-style existing regulators plus sector guidance. The common-law style discussed in UK DUA Act Section 80 and AI Growth Lab. That is my base case for Canada's next bill.

Ontario Bill 194: public-sector AI first

While Ottawa stalls, provinces move. Most important: Ontario Bill 194 (Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024)4.

Royal Assent November 2024; mandatory PIA and breach-notification duties in force July 1, 2025. Public sector only: provincial government, education, healthcare under provincial jurisdiction. Private companies out of scope.

Two-layer core:

  • FIPPA amendments: mandatory PIA, breach notice, "real risk of significant harm" standard (PIPEDA-derived)
  • Enhancing Digital Security and Trust Act 2024 (new): cybersecurity and AI-use rules

AI provisions sit mainly in the new act. Public bodies using AI must:

  • Publish transparency reports on AI use
  • Conduct risk assessments
  • Name oversight officers
  • Retain audit records

Ontario's Information and Privacy Commissioner has called it "advanced, but lacking courage to extend to the private sector"5. An asymmetry inside one country: advanced public-sector AI rules, private-sector AI left to a Voluntary Code.

For Japanese vendors selling AI to Ontario government, public hospitals, or education institutions, Bill 194 is mandatory. Especially PIA templates and 72-hour breach notification capability, often required early in contract talks.

Quebec Law 25: notice duties for automated decisions

Quebec's Law 25 (enacted 2021; staged 2022–2024) is Canada's only GDPR-like comprehensive privacy law. It does not brand itself as AI regulation, but notice duties for automated decision-making (ADM) make it a de facto AI rule.

Three ADM duties:

  • Prior notice when AI automated decisions are used
  • Explanation of personal-information use and main factors in the decision
  • Data subjects may request human review

Structure nearly matches UK DUA Act Section 80 Articles 22A–D. Quebec staged these rules from 2024, while the UK only brought analogous rules into force in February 2026.

Penalties are steep: up to C$25 million or 4% of prior-year worldwide revenue, whichever is higher6. GDPR-style. The harshest figures inside Canada.

For Japanese companies in the Quebec market, Law 25 is baseline. Note extraterritorial application: handling Quebec residents' personal information can trigger Law 25 even if HQ is in another province or country. A Toronto or Vancouver base still hits Law 25 when serving Montreal users with AI.

Limits of the Voluntary Code—and a Japanese strategy

The Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems, published September 2023 by then-Minister François-Philippe Champagne7, was meant to bridge the federal gap. As of May 2026, roughly 40 signatories: Cohere, OpenText, BlackBerry, and other Canadian AI firms.

Frankly, the Code is not functioning. Three reasons:

  1. Zero legal force: no sanctions for breach
  2. Testing and audit duties skewed to developers/operators: no third-party audit requirement
  3. No user-education provisions: unclear what end users should use as decision criteria

As Schwartz Reisman notes, the Code was designed as an interim while waiting for AIDA8. AIDA died. The interim remained. That is the accurate picture.

My recommended posture for Japanese Canada entry: signing the Voluntary Code is a business choice, not the compliance core. Signature can help market trust with Canadian customers, but legal foundations must sit on PIPEDA and provincial law.

Canada AI governance design with WARP SECURITY

Designing Canada AI governance means reading three asymmetries. Federal vs provincial: federal gap, provinces advancing. Public vs private: Ontario public Bill 194, private sector largely Voluntary Code. Province vs province: Quebec GDPR-like, Ontario public-sector heavy, others near rule-free.

TIMEWELL's WARP SECURITY runs workshops that turn these asymmetries into priority maps by market-entry scenario with Japanese Canada expansion teams.

Example: a health-AI firm selling to both Toronto's central public hospitals and Montreal private clinics needs Bill 194 PIA templates and Law 25 ADM notice templates as separate product compliance packs. Same product, two contract and compliance sets. Whether executives grasp that early changes how many deals are lost.

Canada's fragmentation is less spectacular than the US 50-state patchwork, but complex enough that "Canada is one market, one rule set" always trips teams. WARP workshops collapse target provinces into a one-page matrix: applicable rules, required documents, timelines. Executive decision grain.

Waiting on federal law is an option I do not recommend. A new bill is unlikely before late 2026 and more realistically 2027 or later. Firms that build province-by-province now will adapt faster when federal law finally arrives.

Latest as of August 2026

While Canada's federal gap continues, the EU, often used as comparator, is advancing. But "the EU AI Act fully applies on August 2, 2026" is not an accurate reading, and the distinction matters.

August 2, 2026 is the AI Act's general date of application (Art.113, second paragraph). What starts on that date is mainly:

  • Chapter IV (Art.50 transparency obligations)
  • Chapter III Section 5 (Art.40–49: harmonised standards, conformity assessment, CE marking, registration)
  • Art.101 (European Commission power to fine GPAI providers), plus Chapter VI and Chapters VIII–XI

What does not start on that date is the substantive high-risk regime. Chapter III Sections 1–3 apply to Annex III high-risk AI (Art.6(2)) from December 2, 2027, and to Annex I product-embedded high-risk AI (Art.6(1)) from August 2, 2028. The authorised representative duty (Art.22), value-chain duties (Art.25), deployer duties (Art.26), and the fundamental rights impact assessment (FRIA, Art.27) switch on at those same high-risk dates. The transitional rule for already-placed systems (Art.111(2)) is likewise tied to the Chapter III application dates, catching legacy systems only where significant changes in their designs are made on or after those dates.

Penalties (Chapter XII, Art.99–100) and the GPAI chapter (Chapter V) have applied since August 2, 2025. Caps: €35 million or 7% of worldwide turnover for prohibited-practice breaches under Art.5, and €15 million or 3% of worldwide turnover for GPAI-related and other breaches, whichever is higher (Regulatory framework on AI (European Commission)). Prohibited practices (Art.5) and AI literacy (Art.4) have applied since February 2, 2025.

The AI Act's amending regulation, the Digital Omnibus (Regulation (EU) 2026/1744), is already law: adopted July 8, 2026, published in the Official Journal (OJ L 2026/1744) on July 24, 2026, in force from July 27, 2026. It did not move the general application date of August 2, 2026, and Art.50 transparency duties still apply from August 2, 2026 (the amendment touched only Art.50(7) on codes of practice). December 2, 2026 brings the newly added prohibitions in Art.5(1)(ba) (non-consensual sexual deepfakes) and (bb) (CSAM generation), and under the new Art.111(4) providers of synthetic-content generation systems placed on the market before August 2, 2026 must comply with Art.50(2) by that date.

The density gap versus Canada's "light, tight, right" has widened, but the EU side does not switch on all at once: the high-risk core sits at December 2, 2027 and August 2, 2028. Japanese firms spanning both markets should treat the EU as applicable penalties plus a staged timetable, and Canada as provincial patchwork. Two tracks. Privacy-foundation design themes also appear in Personal Information Protection Act 2026 amendment.

Summary

  • AIDA died in the January 2025 prorogation. No successor bill as of May 2026
  • Minister Solomon's "light, tight, right" positions Canada differently from the EU, US, and China
  • Federal gap is partly filled by Ontario Bill 194 (public sector) and Quebec Law 25 (private ADM)
  • Voluntary Code of Conduct has no force; ~40 signatories; functionally weak
  • Japanese strategy for now: provincial patchwork + PIPEDA

Canada's gap is the product of political accident (Trudeau's exit) and economic rationality (a mega-bill that did not fit Canada's scale). "Light, tight, right" sounds good, but slogans are not statutes. Canada-entry teams should watch that plain fact coldly.

I am also watching how AIDA's failure appears to inform the UK Regulating for Growth Bill line: do not pass one comprehensive AI act; amend and layer existing law. Canada's next bill will likely join that common-law family.

Further reading: UK DUA Act Section 80 and AI Growth Lab, US federal AI policy 2026, EU AI Act and the Digital Omnibus (Regulation (EU) 2026/1744).

References

Footnotes

  1. The Demise of AIDA: 5 Key Lessons - McInnes Cooper

  2. What's Next After AIDA? - Schwartz Reisman Institute

  3. 'We cannot be left behind:' How Canada is balancing AI regulation, innovation - IAPP

  4. New Ontario Bill 194 to Regulate Public-Sector Use of Artificial Intelligence Systems - Blakes

  5. Bill 194: Ontario's missed opportunity to lead on AI - Information and Privacy Commissioner of Ontario

  6. Global AI Governance Law and Policy: Canada - IAPP

  7. Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems - ISED Canada

  8. Uncovering gaps in Canada's Voluntary Code of Conduct for generative AI - Schwartz Reisman Institute

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

How well do you understand AI?

Take our free 5-minute assessment covering 7 areas from AI comprehension to security awareness.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Make AI security a skill your team actually has

WARP SECURITY is a two-day intensive aligned with OWASP, NIST, ISO/IEC 42001, and METI guidelines. Executives and practitioners can attend separately.

Related Articles