Regulatory guides
Practical, citation-backed guidance on the rules that govern AI adoption in Canadian regulated industries. Written by practitioners, reviewed against primary sources, and free to read — no forms, no gate. Each guide distinguishes binding law from directives, guidance, and standards.
Healthcare privacyHow Ontario's health-privacy law applies to AI systems handling personal health information — custodian accountability, consent, safeguards, and the compliance gaps we see most.
Read the guideClinical AIA 15-point readiness checklist covering consent workflows, recording governance, retention, human validation, and vendor assessment — before the first encounter is recorded.
Read the guideHospital cyber securityThe cyber-security regulation in force July 2026 for prescribed Ontario hospitals: programs, maturity assessments, incident reporting, and what it means for AI systems in scope.
Read the guidePublic sectorFOI implications of AI-generated records, the 2025 FIPPA privacy amendments, Ontario's Responsible AI Directive, and accountability practices for municipal AI use.
Read the guideStandardsWhat the AI management system standard actually requires, how it maps onto Canadian obligations, and honest guidance on when certification is worth pursuing.
Read the guideFederal legislationAIDA died with Bill C-27 in January 2025. What remains binding today, what's proposed now, and the future-proof controls worth building regardless of which bill passes.
Read the guide Guides are informational only and do not constitute legal advice. Last reviewed July 2026.