Doing Business In..._2026

CANADA Trends and Developments Contributed by: Brent Arnold, Carole Piovesan, Tamara Adler, Michael Pascu and Dilan Brar, INQ Law

ernment public sector or government employees in using generative AI. Sector-specific oversight Regulators and standard-setting bodies are also weighing in on AI governance. Several developments matter for businesses operating in Canada: • The Office of the Superintendent of Financial Insti - tutions (OSFI) has finalised Guideline E-23, extend - ing its model-risk expectations to systems built on AI and machine learning, with effect from 2027. In collaboration with other key institutions relevant to financial services, OSFI has also endorsed the EDGE principles (which set out Explainability, Data, Governance and Ethics as four pillars for responsi - ble AI adoption in financial services) and the AGILE Framework (a five-part framework consisting of Awareness, Guardrails, Innovation, Learning, and Ecosystem Resiliency, building on EDGE to capture AI’s benefits while managing fast-evolving risks). • Through the Standards Council of Canada, the country helped develop ISO/IEC 42001, the first international management-system standard for AI. • Provincial law societies, including those in Ontario, British Columbia, and Alberta, have issued guid - ance on the use of AI in legal practice, and the federal Privacy Commissioner has published prin - ciples for generative AI. Looking ahead The best route ahead appears to be a layered approach, built from federal policy, privacy law, provin - cial statutes, and sectoral rules. Whether the federal government will revive a dedicated AI law is uncertain, but any new bill is unlikely to mirror the 2022 model. A separate consultation on copyright and AI contin - ues, and public trust remains a recognised barrier to wider adoption. In the meantime, organisations should assume that meaningful obligations already exist; the immediate task is to identify where automated deci - sions are made about individuals and to be ready to explain and contest them. Data Governance and Compliance Trends In Canada, data governance is shifting from policy- based privacy and data compliance to evidence-based accountability. Where businesses were once expected

to maintain policies and include key data protection terms in contracts, now, irrespective of what a busi - ness does, there is a much weightier expectation from boards, vendors servicing businesses, and custom - ers alike, to demonstrate how personal information is governed across its entire life cycle. This is particularly crucial as businesses implement analytics tools and processes, and cloud infrastruc - ture, onboard integrated digital platforms, and adopt AI. In this environment, privacy compliance turns on whether the business is able to consistently identify what data it holds, why it is authorised to use it, where it is stored or transferred, who has access to it, wheth - er it remains accurate, and whether it is able to show how decisions about personal information uses are documented and reviewed. Bill C-36 Bill C-36 aims to modernise the federal private- sector privacy framework by enacting the proposed Protecting Privacy and Consumer Data Act. The bill echoes this evidence-based accountability trend by pointing to a more structured accountability model that requires businesses to maintain a privacy man - agement programme; document their privacy poli - cies, practices, and procedures; and provide those materials to the regulator upon request. It also pro - poses privacy impact assessment (PIA) requirements for certain higher-risk activities, including transfers or disclosures of personal information outside Canada or when choosing to rely on the proposed legitimate interest exception to consent. The practical point is that businesses operating in Canada need to show: • what was assessed; • what risks were identified; • what mitigations were chosen; and • why the business considered the use and mitiga - tions appropriate. These proposed elements indicate that compliance is becoming less about having the right policy on file and more about being able to demonstrate, through both records and repeatable processes, that risks are

155 CHAMBERS.COM

Powered by