AIDA: What the AI Law Canada Business Owners Ignore Means for You
Canada is writing its first real AI law, and most businesses have no idea what "high-impact AI system" will mean for them. Here's the plain-English version and what to do before the rules land.
By Valdra Team
A clinic in Mississauga runs a chatbot that triages patient symptoms before a nurse calls back. A Halifax lender uses a model to score loan applications in seconds. A Montreal retailer points facial analysis at the entrance to flag "suspicious" shoppers. None of these companies thinks of itself as an "AI company." Every one of them would land squarely inside the scope of the law Canada is building right now.
That law is AIDA, the Artificial Intelligence and Data Act. It arrived in Parliament as Part 3 of Bill C-27, bundled with a long-overdue overhaul of the federal privacy regime. The bill died when Parliament prorogued in early 2025, and plenty of business owners quietly filed it under "never happening." That read is wrong. The political appetite to regulate AI hasn't faded, the EU has already shipped its AI Act, and Canada does not enjoy being the only G7 country without a framework. AIDA, or something close to it, is coming back. The smart move is to understand it before it's law, not after.
What AIDA Actually Regulates
Most coverage gets one thing backwards: AIDA is not a blanket "all AI" law. It targets a specific category the bill calls high-impact systems. The original draft left that term to be defined later in regulation, which drew justified criticism, but a 2023 round of amendments and a companion guide from the federal government sketched out where the line would fall. Picture systems that shape employment decisions, the provision of goods and services, biometric identification, content moderation at scale, and health or safety outcomes. The triage chatbot, the loan-scoring model, the facial analysis at the door, all three are textbook high-impact use cases.
If your AI sorts résumés, prices insurance, decides who gets credit, moderates a large platform, or makes a call that touches someone's body or safety, assume you're in scope. If it autocompletes your marketing copy or reorders an inventory spreadsheet, you almost certainly aren't.
The obligations attached to high-impact systems are the familiar pillars of responsible AI, written into statute. Assess and mitigate the risks of harm and biased output. Keep records describing how the system works, what data trained it, and the measures you took. Maintain human oversight and ongoing monitoring. Publish a plain-language description so the public knows the system exists and what it does. None of this is exotic. It's roughly what a careful organization should already be doing. The shift is that "should" becomes "must," with a regulator behind it.
The AIDA AI Law Canada Business Owners Keep Underestimating
Two numbers tend to wake people up. The first is the penalty ceiling. AIDA layers administrative monetary penalties on top of true offences, and the most serious offences reach up to $25 million or 5% of global revenue, whichever is greater. Lesser contraventions still carry fines as high as the greater of $10 million and 3% of gross global revenue. That's EU-grade money, not the kind of fine you absorb as a cost of doing business.
The second number is who gets caught. AIDA isn't aimed at OpenAI and Google. It reaches the firm that *uses* their tools to make consequential decisions. A 40-person staffing agency running an off-the-shelf candidate-ranking tool can be a person responsible under the act, the same as the vendor who built it. Pointing upstream won't get you out.
The companies most exposed to AIDA are the ones convinced the rules don't apply to them, because they bought the model instead of building it.
There's a jurisdictional wrinkle worth naming. AIDA is a federal law that reaches into international and interprovincial trade and commerce, the same constitutional hook PIPEDA uses. Quebec, meanwhile, already folded automated-decision rules into Law 25. Since the provisions came into force on September 22, 2023, a Quebec organization that makes a decision about someone based exclusively on automated processing must inform that person, and on request explain the personal information used and the main factors, let them access that data, correct inaccuracies, and submit observations to someone who can review the decision. The Commission d'accès à l'information enforces it today, with audit powers, binding orders, and monetary penalties. Operate in Quebec and you're not waiting for AIDA, you're already living under a version of it.
Where the Privacy Regulators Already Are
People treat AI governance as untouched ground. It isn't. The Office of the Privacy Commissioner of Canada has been active here for years. Its joint investigation into Clearview AI, run alongside the privacy authorities of Quebec, British Columbia, and Alberta, concluded that scraping billions of faces to build a facial-recognition database amounted to mass surveillance and was unlawful under Canadian privacy law. No AIDA required. The OPC has since published guidance on generative AI and signed international statements on the privacy risks of data scraping.
That history matters because AIDA will not arrive in a vacuum. It would sit on top of PIPEDA, or its proposed successor the Consumer Privacy Protection Act that travelled in the same bill, plus provincial privacy statutes, Ontario's PHIPA for health information, and Quebec's Law 25. An AI system that makes biased lending decisions is an AIDA problem *and* a human-rights problem *and*, if it mishandles personal data, a privacy-commissioner problem. These regulators coordinate. One bad deployment can draw fire from three directions at once.
So the readiness work is not really a separate discipline called "AI compliance." It's an extension of the privacy and data governance you should already be running. If your PIPEDA house is in order, you're most of the way to an AIDA house.
How to Get Ahead Before the Rules Land
You don't need the final statute to do the work that will matter under any version of it. Start with an inventory. Most organizations genuinely don't know how many AI and automated-decision tools are running across their departments, because marketing bought one, HR bought another, and nobody told IT. You can't govern what you can't see. List every system that touches a hiring, lending, pricing, eligibility, or safety decision.
For each one, write down three things: what decision it influences, what personal data it consumes, and whether a human can meaningfully override it. That single exercise surfaces most of your risk. The candidate-ranking tool nobody can explain. The chatbot quietly logging health symptoms. The fraud model that's never been tested for disparate impact across neighbourhoods.
Then handle the unglamorous documentation. A short risk assessment per high-impact system. A record of the data sources. A named human owner. A plain-language notice for the people affected. This is the paperwork AIDA will demand, the paperwork Law 25 already demands in Quebec, and the paperwork that protects you in any complaint, AIDA or not.
A few concrete priorities, in rough order:
- Find your high-impact systems first. Decisions about people, not productivity tools.
- Test for bias before a regulator does, and document the test and what you changed.
- Keep a human in the loop on consequential calls, and be able to prove it.
- Tell people when an AI is involved, in language a normal person understands.
- Tie it into your existing privacy program rather than standing up a parallel one.
The businesses that will struggle are the ones treating this as a one-week legal scramble when the bill passes. The ones that will be fine keep a living record of what their AI does, who it affects, and how they've reined in the risk. That posture costs far less built gradually than built under a regulator's deadline.
Here's the honest read. The AIDA AI law Canada business owners have been told to ignore is the most predictable regulatory shift on the horizon, and the groundwork overlaps almost entirely with privacy obligations you're already on the hook for. Getting ahead isn't about guessing the final wording. It's about knowing your systems and writing things down. For a single place to watch Bill C-27 and benchmark your readiness as the rules firm up, track AIDA and Bill C-27 progress with Valdra.
AI governance and privacy compliance, simplified.
Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.
Try Valdra