OTTAWA — The federal government has begun laying the groundwork for new artificial intelligence transparency rules that could change how Canadians encounter chatbots, deepfakes, automated decisions and increasingly autonomous AI agents.
What Ottawa has launched, however, is a consultation—not legislation.
The distinction matters. Canada has not yet proposed a general law requiring every AI-generated image to carry a label, every chatbot to disclose itself or every technology company to report when its systems cause harm. Instead, the government is asking Canadians what should be made transparent, who should be responsible and what action Ottawa should take.
The consultation opened July 23 and will accept submissions until September 23. According to Innovation, Science and Economic Development Canada, it will examine five areas:
- Detecting and identifying AI-generated content;
- Informing people when they are interacting with AI;
- Providing understandable information about AI systems, including their development, capabilities and limitations;
- Tracking serious AI incidents; and
- Tracing the actions and interactions of AI agents.
The government says the responses will inform its “next steps,” but it has not committed to introducing a dedicated AI transparency bill or provided a date when binding requirements could take effect.
That leaves Canada at an important but preliminary stage: the government has identified the problems it may regulate, without deciding what the rules will be, whether they will be mandatory or which regulator would enforce them.
Ottawa says AI adoption depends on trust
Artificial Intelligence and Digital Innovation Minister Evan Solomon announced the consultation as part of the federal government’s new national strategy, AI for All.
“AI adoption moves at the speed of trust,” Solomon said in the government’s July 23 announcement.
Solomon said Canadians need to understand when they are interacting with AI, when material has been generated or altered by it, and what an AI system can and cannot do.
The language reflects a central argument in the government’s strategy: transparency is not only a consumer-protection measure. Ottawa sees public confidence as necessary to persuade workers, businesses and government institutions to use AI more widely.
That creates a difficult balancing act. Rules that are too weak may do little to prevent deception or expose dangerous systems. Rules that are excessively broad could produce meaningless warning labels, impose large compliance costs on smaller companies or disclose technical information that creates cybersecurity and intellectual-property risks.
The consultation asks questions in all of these areas, but it does not indicate which trade-offs the government prefers.
What an AI-generated-content rule could cover
The most recognizable issue is synthetic content: images, audio, video and text created or substantially altered by AI.
The government’s discussion paper examines several methods of identifying that material.
One is a visible label—such as a notice informing viewers that an image or video was AI-generated. Another is machine-readable provenance data that records where a file originated and how it was altered. Developers can also embed hidden signals, commonly called watermarks, into generated content.
Each approach has limitations.
A visible label can be cropped out or omitted by someone spreading deceptive material. File metadata can disappear when content is compressed, copied or uploaded to another platform. Watermarks may be damaged by editing, and detection systems can produce uncertain results.
No single method can reliably prove that every unmarked file is authentic. A transparency system would therefore need to explain what a label actually establishes—and avoid giving people false confidence in anything that lacks one.
The government must also determine where responsibility lies. Possible obligations could fall on the company that developed the AI model, the service used to generate the content, the person publishing it, the social-media platform distributing it, or some combination of all four.
Ordinary editing presents another problem. A rule would need to distinguish between a wholly fabricated video and a photograph that used AI for noise reduction, background removal or colour correction. If almost every piece of digital content receives the same warning, the label may lose its usefulness.
Canadians could be told when they are speaking to a machine
The second issue is interaction disclosure.
A consumer contacting a company may believe a customer-service representative is a person when the response is actually being generated by a chatbot. AI-generated voices can now make the distinction even more difficult over the telephone.
A future rule could require businesses and government services to disclose an AI interaction at the beginning of a conversation. But Ottawa would still have to define what counts as an AI system and when disclosure is necessary.
Simple automated telephone menus have existed for decades. Many modern services combine scripted responses, predictive software, generative AI and human supervision. A workable rule would have to cover materially deceptive interactions without attaching warnings to every piece of software that performs an automated function.
The European Union has already moved further. Under Article 50 of the EU AI Act, certain providers must inform people when they are interacting with an AI system, while generative systems must make synthetic output detectable in a machine-readable format. Deepfakes and some AI-generated material dealing with matters of public interest are subject to additional disclosure requirements. Those obligations begin applying on August 2, 2026, according to the European Commission.
Canada’s consultation covers some of the same territory, but unlike the European framework, it is not yet connected to an enacted AI statute or a defined enforcement regime.
How much should AI companies have to reveal?
The third part of the consultation addresses information about AI systems themselves.
Developers sometimes publish “model cards” or “system cards” explaining what a system was designed to do, how it was tested, its known limitations and the circumstances in which it should not be used. The documents vary significantly in detail and are generally produced according to company practices rather than a common Canadian requirement.
Ottawa is asking whether Canadians need more consistent and understandable disclosures.
Meaningful transparency could include information about:
- The system’s intended purpose;
- Known limitations and failure rates;
- The types of testing performed;
- The kinds of data used in development;
- Safeguards against discrimination or misuse;
- Whether humans review important decisions; and
- The developer or organization responsible for the system.
The hardest question is not whether information should exist, but how specific it should be.
A broad statement that an AI system “may make mistakes” tells a consumer very little. But forcing a developer to disclose model architecture, proprietary training techniques or sensitive security testing could expose trade secrets or make the system easier to attack.
Disclosure also needs to match the audience. A technical report for independent researchers is different from the explanation a patient, job applicant or bank customer needs before an AI system affects them.
Reporting serious AI incidents
The consultation also considers whether Canada needs a better way to document serious failures involving AI.
Examples could include a facial-recognition system producing a damaging false match, an automated system discriminating against a protected group, a medical AI contributing to patient harm, or an AI agent being manipulated into disclosing information or carrying out an unauthorized transaction.
Some industries already have incident-reporting requirements. Medical-device, transportation and consumer-product regulations can apply when AI is incorporated into a regulated product. Privacy commissioners can investigate the improper handling of personal information.
What Canada does not have is a comprehensive national system for reporting significant AI incidents across sectors.
Creating one would require Ottawa to answer several consequential questions:
- What qualifies as a “serious” incident?
- Who must report it—the developer, vendor, business user or all three?
- How quickly must a report be filed?
- Which details should become public?
- How would commercially sensitive or personal information be protected?
- Would companies be penalized for failing to report?
A confidential reporting system could help regulators identify emerging risks. A public database could alert other users to recurring problems. But public disclosure could also discourage voluntary reporting or expose affected people unless strong privacy protections were built in.
AI agents raise a newer accountability problem
The fifth subject may ultimately be the most important.
AI agents do more than answer questions. They can navigate websites, complete forms, make bookings, purchase products, use software tools and communicate with other systems on a person’s behalf.
As those agents become more autonomous, a conventional chatbot notice may no longer be enough. Organizations may need to determine which agent performed an action, which user or company authorized it, what permissions it had and how it reached a decision.
That could lead to requirements for digital identification, activity logs or auditable records of agent-to-agent transactions.
Traceability would help investigate fraud, mistakes and unauthorized actions. It could also create a highly detailed record of what individuals ask their assistants to do. Ottawa would therefore need limits on how long those logs can be retained, who can access them and when they may be disclosed to authorities or private litigants.
The consultation does not propose a final model. Its inclusion of AI agents nevertheless shows that the government is looking beyond today’s deepfake and chatbot controversies toward systems capable of acting in the economy with limited human involvement.
Canada has rules around AI—but no comprehensive AI law
Canada’s current framework is fragmented.
The federal private-sector privacy law, PIPEDA, already applies when businesses collect, use or disclose personal information through AI. In May, federal and provincial privacy authorities found that OpenAI’s initial development of ChatGPT raised concerns involving overly broad data collection, consent, transparency, accuracy and accountability.
The federal Privacy Commissioner concluded that the complaint was well-founded and conditionally resolved after OpenAI implemented or committed to additional protections. The case demonstrated that existing privacy legislation can reach AI companies—but primarily when personal information is involved. It does not create a complete framework for synthetic-content labels, incident reporting or agent traceability. The commissioner’s findings are available in the joint OpenAI investigation report.
The government has also introduced Bill C-36, the Protecting Privacy and Consumer Data Act. The proposed legislation would increase transparency around automated decision systems, including some powered by AI, and could carry significant penalties for violations. But it remains a bill and is focused on personal-information practices rather than every AI-transparency issue raised in the new consultation. The government’s Bill C-36 backgrounder proposes penalties of up to $10 million or three per cent of global revenue, with higher fines for serious offences.
Within government, Ottawa maintains an AI register containing more than 400 systems being explored, developed or used by 42 federal institutions. The register provides information such as a system’s purpose, status and whether it was built internally or supplied by a vendor. It is an early version, excludes some low-risk commercial products and applies only to federal-government use—not AI deployed throughout the Canadian economy. Treasury Board President Shafqat Ali called it a step toward public trust when the register was released in November 2025.
Federal automated administrative decisions are also governed by a Treasury Board directive requiring impact assessments and varying levels of explanation and oversight. A directive, however, is an internal government policy rather than a general law covering private companies.
What happened to Canada’s previous AI bill?
Ottawa has attempted comprehensive AI legislation before.
Bill C-27, introduced in June 2022, contained the proposed Artificial Intelligence and Data Act, commonly known as AIDA. It would have established obligations for certain AI systems and created an enforcement structure.
The proposal faced criticism over its broad definitions, the amount of detail left to future regulations, the treatment of high-impact systems and the independence of its proposed regulator. Parliamentary study continued for more than a year, but the bill never completed committee consideration.
It died when the previous parliamentary session ended on January 6, 2025. Parliament’s official record shows that C-27 never reached report stage, third reading or the Senate. Its full legislative history is available through LEGIinfo.
The new government has not revived AIDA in its former form.
Instead, it has introduced a separate privacy bill, proposed online-safety legislation involving some AI chatbots and opened a focused transparency consultation. That sequence suggests Ottawa may be pursuing AI governance through several targeted laws, policies and technical standards rather than one omnibus AI act.
It is not yet clear whether that approach will produce more precise rules or leave gaps between regulators.
Timeline: Canada’s path toward AI transparency rules
June 16, 2022: Bill C-27 is introduced, including the proposed Artificial Intelligence and Data Act.
September 2023: The federal government launches a voluntary code of conduct for advanced generative-AI systems while AIDA remains before Parliament.
January 6, 2025: The parliamentary session ends before Bill C-27 completes committee review. AIDA does not become law.
October 1–31, 2025: Ottawa consults Canadians on a new national AI strategy. The government later reports receiving more than 11,000 submissions.
November 28, 2025: The federal government publishes the first version of its public AI register, covering more than 400 systems across 42 institutions.
February 5, 2026: Ottawa releases a summary of the national-strategy consultation.
May 6, 2026: Canadian privacy authorities publish findings from their investigation into OpenAI and ChatGPT.
June 4, 2026: The federal government launches AI for All, which promises new safeguards, improved AI transparency and stronger safety capabilities.
June 15, 2026: Bill C-36 is introduced to modernize private-sector privacy and consumer-data law, including rules around automated decisions.
July 23, 2026: The AI transparency consultation opens.
September 23, 2026: Public submissions close.
After September 23: ISED is expected to review the submissions and determine its next steps. The government has not announced when it will publish the responses, issue a policy report or introduce legislation.
What happens next?
Canadians and Canadian residents can participate through the government’s AI transparency consultation. Businesses, researchers, Indigenous organizations and civil-society groups have also been invited to submit responses.
After the consultation closes, several outcomes are possible.
Ottawa could develop legislation imposing mandatory disclosure and reporting obligations. It could amend another bill, create regulations under existing statutes, establish national standards, attach transparency conditions to federal procurement or continue using voluntary codes. Different measures could be used for different sectors.
If the government chooses legislation, another lengthy process begins. A bill would have to be drafted, introduced and approved by both the House of Commons and Senate before receiving royal assent. Many operational details could then require regulations and a second consultation process.
There is therefore no confirmed date when new nationwide AI transparency requirements will take effect.
The consultation’s real significance is that it identifies the questions Ottawa now considers urgent: whether Canadians can recognize synthetic content, whether machines must identify themselves, whether developers must explain their systems, whether serious failures must be reported and whether autonomous agents can be traced.
What remains unanswered is whether the government will turn those principles into enforceable rights and obligations—or rely on a collection of voluntary practices and overlapping laws that leave responsibility difficult to locate.
