Canada AIDA: readiness for a regime that does not exist yet
Read this page as preparation, not as a compliance claim. AIDA was part of a bill that died when Parliament was prorogued in January 2025, and Canada has no federal AI statute. The reason to read it anyway is that the shape of the regime is informative, and the readiness controls are the same ones the enforceable instruments already require.
- The instrument
- The Artificial Intelligence and Data Act, proposed as part of the Digital Charter Implementation Act 2022 and never enacted
- Status
- Not law: never enacted, and not revived in its original form
- Who it applies to
- Canadian organisations, and anyone selling AI systems into Canada, who want to be ready without overstating what exists.
Where AI-FW fits
There is nothing to comply with yet, so treat this as a readiness mapping. AI-FW does not make anyone AIDA compliant, because AIDA is not in force. What it can do is keep the controls an AIDA-shaped regime would have asked for, and that adjacent Canadian law already asks for, running and evidenced.
What stays with you
Read this list first. It is the boundary of what a product can do for you, and it is where the remaining work sits.
- Anything in the sense of AIDA compliance, because the Act never became law
- Deciding whether a system would meet a high-impact threshold, and the reasoning that documents it
- Publishing the plain-language descriptions a regime of this shape would expect, and the contact route for individuals and the regulator
- The harm-reporting runbook and its statutory clock, which cannot honestly be built against a bill that has not passed
- Compliance with the instruments that are in force, which remain your obligations
What the framework asks, and what the product does
The obligations that touch the AI path, paired with the capability that answers each one. Everything else in this framework is organisational work, listed above.
Certain systems making critical decisions would carry heightened duties
Model and agent inventory with per-model purpose and endpoint, so classification starts from a complete list rather than a memory
Documented assessment of harms and mitigation
Risk profiles, per-agent and per-user scoring with decay, violation history, and the mix of data categories in play
Measures that are actually in place and running
Guard rules for prohibited patterns, sensitive data and unapproved endpoints, plus approval gates for sensitive actions
Ongoing monitoring, not a one-off review
Activity and error views, drift detection, and scheduled assessments that raise findings when a control is switched off
Records sufficient to demonstrate compliance
Transaction and access records with actor, model, outcome and timestamp, plus an audit event for every enforcement change
A plain-language description of how a high-impact system is used
The factual inventory a published description has to reflect: which model, which categories, and who owns it
Report material harm within a statutory window
Error and violation telemetry with attribution, so a timeline can be reconstructed when a window does start to apply
A responsible person, identifiable to the public
Attestations recording the accountable human per control, and role separation that shows who can change what
Protect personal information while enabling anonymised research use
Detection and masking of personal and special-category data at the boundary
Providers of general-purpose AI would carry extra duties
Provider attribution and version pinning in the inventory, and parameter policies that prevent silent model substitution
A rule pack to start from
The enforcement that makes the controls real. Severity runs 1 to 5, and a rule that is switched off reports as a gap, so these are meant to be live from day one.
The control a high-impact classification would depend on
Overlaps with federal and provincial privacy law that is in force today
Keeps the inventory meaningful while a regime is prospective
Security readiness, independent of any particular statute
The exfiltration case that privacy law already covers
What the evidence pack contains
Per period, and without prompt or response content, which is what makes it safe to hand over.
- Control statusesA readiness position, clearly labelled as such
- Classification attestationsA named person has classified each system in the inventory
- Mitigation rule stateRunning, not planned
- Monitoring historyShows the controls were watched across the period
- Inventory snapshotEvery model and agent, classified as high-impact or general
Customer responsibilities and sources
- Comply with the Canadian instruments that are in force: federal privacy law, provincial privacy regimes, and the Treasury Board directive if you are a federal institution.
- Determine whether any system would meet a high-impact threshold, and document the reasoning.
- Prepare plain-language descriptions and a contact route, so the publication work is ready if a regime arrives.
- Draft the harm-reporting runbook, and leave the statutory clock blank until a bill passes.
- Re-validate any mapping when a successor bill is tabled: clause references and thresholds will change.
Common questions
No. It was proposed as part of a bill that died when Parliament was prorogued on 6 January 2025, and it was not revived in its original form afterwards. Canada has no federal AI-specific statute, and federal work has continued through voluntary measures and adjacent privacy reform instead. Do not represent AIDA compliance to anyone, because there is nothing to comply with.
Because the enforcement controls an AIDA-shaped regime would have asked for are the same ones that in-force Canadian privacy law, and most other frameworks, already ask for. If those controls are running and evidenced, the readiness question mostly answers itself, and what is left is documentation.
Work to the instruments that exist: federal privacy law, Quebec's privacy reform, Ontario's public-sector rules, Alberta's automated-decision provisions, and the Treasury Board directive if you are federal. Keep the AI inventory current, keep the guard rules on, and keep the evidence. That combination makes a future transition cheap rather than urgent.
Validate it yourself with our Technical Plan
Ask us to run this framework against your own environment: the rules that would be created, what the assessment reports, and what the evidence pack contains for a real period.
This page maps product capabilities to published expectations. It is not legal, audit or certification advice, and it creates no compliance representation. Applicability and sufficiency are judgements for your counsel and, where relevant, your auditor, assessor or certification body. Framework details are current as reviewed; check the primary sources above, and the page itself, before relying on a date or a threshold.