FIPPA, MFIPPA, and AI in Ontario's Public Sector
Ontario's access and privacy framework for public institutions predates generative AI by three decades, but it governs AI use today — and it changed materially in 2025. This guide covers which statute applies to whom, how freedom-of-information rules reach AI-generated records, and what the new obligations actually require.
Which statute applies: FIPPA vs MFIPPA
Start with a distinction that is frequently blurred in vendor materials: the Freedom of Information and Protection of Privacy Act (FIPPA, R.S.O. 1990, c. F.31) covers provincial institutions — ministries, agencies, universities, hospitals designated under the Act. Municipalities, local boards, police services boards, and similar local bodies are covered by the Municipal Freedom of Information and Protection of Privacy Act(MFIPPA, R.S.O. 1990, c. M.56). The two statutes are parallel in structure — access rights, privacy protections, Information and Privacy Commissioner (IPC) oversight — but they are separate laws, and recent amendments have not landed on both equally. A municipal CTO reading about "new FIPPA obligations" needs to know which of them actually bind their organization today, and the honest answer, covered below, is: directly, none of the 2025 privacy amendments — but the direction of travel is unambiguous.
AI-generated records are FOI-responsive records
Both statutes define "record" broadly: recorded information in any form, however produced. Nothing in that definition exempts machine-generated content. A draft report produced by a language model, the prompt a staff member typed to get it, a chatbot transcript with a resident, an AI-generated summary circulated before a decision — where these are in an institution's custody or control, they are records, and they can be responsive to a freedom-of-information request. Exemptions (such as advice or recommendations, or personal privacy) apply on their ordinary terms, but there is no "the AI wrote it" exemption.
The operational consequences arrive before any request does. If staff use consumer AI tools outside institutional systems, responsive records may exist in accounts the institution cannot search — a records management failure waiting to become an FOI failure. Retention schedules written for documents rarely say anything about prompts and intermediate outputs. And institutions that cannot identify where AI is in use cannot conduct a defensible search. The fix is prosaic: bring AI tools inside managed environments, decide deliberately which artefacts (prompts, drafts, final outputs) are retained and for how long, and make those decisions in the records schedule rather than by tool default.
Transparency duties for automated decision-making
When an institution uses an automated system in decisions that affect members of the public — eligibility screening, prioritization, enforcement triage — two accountability pressures converge. The access regime means the system's outputs and surrounding documentation may be requestable; an institution that cannot explain how a score was produced will struggle to process the request, defend the decision, or survive an IPC review of either. And the IPC and Ontario Human Rights Commission's joint principles for responsible AI use (January 2026) set out transparency, accountability, human oversight, and recourse expectations for organizations using AI in Ontario. Those principles are guidance, not law — but they are a credible preview of how the province's regulators will assess complaints involving automated decisions, and aligning with them is considerably cheaper than litigating against them.
The practical standard to hold vendors and internal teams to: for any decision affecting an individual, the institution can state what data went in, what the system recommended, who reviewed it, and why the final decision was made. If any of those four cannot be answered, the system is not ready for decisions that affect the public.
The 2025 FIPPA privacy amendments
Amendments to FIPPA's privacy provisions came into force on 1 July 2025. For provincial institutions they introduce, among other things: written privacy impact assessments before certain collections of personal information, with updates on significant change; privacy-breach analysis, including assessment against a real risk of significant harm (RROSH) threshold with reporting to the IPC; annual reporting and recordkeeping obligations; and expanded IPC oversight of institutional privacy practices. For any provincial institution deploying AI on personal information, the PIA duty is now statutory rather than best practice — and a "pilot" that processes real personal information is a collection like any other.
Two scoping cautions, stated plainly. First, these are FIPPAamendments: they bind provincial institutions, and they are not a blanket obligation on hospitals' health-information activities, which remain governed by PHIPA. Second, they do not amend MFIPPA — municipalities are not directly subject to them today. Whether and when parallel MFIPPA amendments will follow is genuinely uncertain; we are not aware of an in-force equivalent as of this writing, and municipalities should track IPC publications on FIPPA/MFIPPA updates rather than assume either that the duties apply now or that they never will. Adopting the FIPPA discipline voluntarily — written PIAs, breach analysis, breach records — is the low-regret position.
The Responsible AI Directive and EDSTA 2024
Ontario's Responsible Use of Artificial Intelligence Directive took effect on 1 December 2024. It is binding on Ontario ministries and provincial agencies, imposing risk management, human oversight, disclosure, monitoring, and reporting duties for AI use in the Ontario public service. It does not bind municipalities — but it is the most concrete statement available of what the province considers responsible public-sector AI practice, which makes it a strong voluntary benchmark for municipal AI programs and a useful yardstick when evaluating vendors who also sell to the province.
Sitting behind the directive is the Enhancing Digital Security and Trust Act, 2024(EDSTA, in force 29 January 2025), the enabling framework for public-sector accountability, risk management, oversight, disclosure, recordkeeping, and cybersecurity provisions around digital technology and AI use. Its AI duties apply to prescribed public-sector entities as regulations prescribe them — meaning the statute's reach will grow by regulation over time, and duties not yet prescribed should not be overstated today. The correct posture for public-sector bodies is monitoring: EDSTA is the mechanism through which new binding AI obligations are most likely to arrive, with comparatively short notice.
Public accountability practices worth adopting now
Independent of which obligations formally bind a given institution, four practices consistently hold up — to FOI requests, IPC scrutiny, council questions, and public trust. An AI use register: a maintained inventory of AI systems in use, their purpose, the data they touch, and their owner — the precondition for every other control, and increasingly published proactively by leading institutions. Decision logs for automated or AI-assisted decisions affecting individuals, capturing inputs, outputs, and the human determination. Human review of adverse decisions: no decision that denies a benefit, service, or entitlement is finalized by an automated system alone, and the reviewer has real authority to depart from the recommendation. And vendor transparency terms: contracts that require enough documentation of model behaviour to answer an FOI request or an IPC inquiry without the vendor's permission. Institutions that build these now will find each future obligation — FIPPA-style PIAs, EDSTA regulations, an eventual MFIPPA update — an increment rather than a scramble.
References
Questions about how this applies to your organization? Book a confidential discussion
This content is for informational purposes only and does not constitute legal advice. Requirements change; validate current obligations with qualified legal, privacy, and security professionals.