AIDA and After: Where Federal AI Legislation Stands
The Artificial Intelligence and Data Act was Canada's first attempt at federal AI legislation — and it is not law. This guide states plainly what happened to AIDA, what actually binds organizations federally today, what the current bill does and does not change, and what is worth preparing no matter how the legislative picture resolves.
What happened to AIDA
The Artificial Intelligence and Data Act (AIDA) was Part 3 of Bill C-27, introduced in the 44th Parliament alongside proposed private-sector privacy reform. Bill C-27 died on the Order Paper when Parliament was prorogued in January 2025. AIDA is not law. It never came into force, it created no obligations at any point, and no organization is — or ever was — required to comply with it.
This is worth stating bluntly because the market has not caught up. Vendor decks, conference talks, and compliance checklists still cite "AIDA requirements" as though they were live or imminent. Any document that presents AIDA as a current obligation is describing a bill that no longer exists. Treat that as a signal about the document's overall reliability.
What AIDA would have required
Described in the past conditional, because that is the accurate tense: AIDA would have established a federal regime for AI systems in the course of international and interprovincial trade, organized around the concept of high-impact systems. Organizations responsible for such systems would have faced risk-assessment and mitigation duties, requirements to monitor systems in operation, and transparency obligations, with much of the operative detail — including which systems counted as high-impact — left to regulations that were never made.
The framing matters more than the defunct details: a risk-tiered regime concentrating duties on systems with significant potential for harm, backed by risk management, monitoring, and disclosure. That shape is common to most serious AI legislative proposals internationally, which is precisely why preparation is possible even while the specific Canadian vehicle remains unsettled.
What is binding federally today
Two instruments do real work at the federal level right now, and neither is AI-specific legislation.
PIPEDA. The Personal Information Protection and Electronic Documents Act governs personal information in covered commercial and federally regulated contexts, with full Part 1 coverage in force since January 1, 2004 (earlier stages applied from 2001 and 2002). Its principles — consent, limiting collection and use, safeguards, openness, individual access, accountability, and breach obligations — apply to AI systems processing personal information in covered contexts, because PIPEDA is technology-neutral. Two cautions: PIPEDA is not a universal rule for every sector — most Ontario hospital personal health information, for instance, is governed by PHIPA, not PIPEDA — and PIPEDA reform was the other part of the same Bill C-27 that died, so the current Act remains the operative text.
The TBS Directive on Automated Decision-Making and the Algorithmic Impact Assessment. For covered federal government automated-decision contexts, the Treasury Board directive imposes binding requirements, and the AIA tool is mandatory. Outside those covered federal contexts, the AIA is an optional benchmark — a genuinely useful one, covering data quality, procedural fairness, privacy, explanation, recourse, testing, and monitoring — but it is never a legal requirement for provincial or private-sector organizations, and should not be presented as one.
Bill C-36: the current federal measure
The current federal measure under parliamentary consideration is Bill C-36 (45th Parliament, 1st Session), introduced on June 15, 2026. Its status is the entire story for compliance purposes: it is proposed and not in force. It creates no current obligations and no enforceable compliance deadline. We deliberately do not summarize its contents here — a bill's text can change at every stage, and building controls against a draft invites rework. The honest planning posture is to track its progress through LEGISinfo, not to "comply" with a bill.
Timing and final shape are genuinely uncertain. Bills die — AIDA is the proof — and bills that pass emerge amended. Anyone offering a confident date for federal AI legislation coming into force is speculating.
What to prepare now, regardless
The wrong conclusion from the above is that nothing needs doing until a bill passes. Four capabilities appear in essentially every AI governance instrument — enacted, proposed, or voluntary — and each takes months to build well. They are the future-proof investment.
- AI inventory. A maintained register of AI systems in use, including embedded features in procured software, with owners, data flows, and vendors. Every plausible future regime starts by asking what you run; so does every current privacy and security obligation.
- Risk assessment. A repeatable process for assessing AI systems before deployment and on material change — impact on individuals, data sensitivity, failure modes, and mitigations, in writing. The AIA and the NIST AI Risk Management Framework 1.0 (January 2023) are workable free templates to adapt.
- Human oversight. Defined points where a person reviews, can override, and remains accountable for consequential AI-assisted decisions — with the workflow designed so oversight actually happens rather than existing as a policy sentence.
- Incident capability. The ability to detect, escalate, document, and where required report AI-related incidents, wired into your existing security incident process. Every proposed regime includes monitoring or reporting duties in some form; the underlying muscle is the same.
Organizations that build these four now will meet whatever passes with configuration changes. Organizations that wait for legal certainty will start from zero under a deadline. The uncertainty is real; the direction of travel is not.
References
Questions about how this applies to your organization? Book a confidential discussion
This content is for informational purposes only and does not constitute legal advice. Requirements change; validate current obligations with qualified legal, privacy, and security professionals.