AI agent governance in Canada
Canada's proposed federal AI statute did not become law. The binding requirement for anyone deploying AI agents in Canadian financial services is OSFI Guideline E-23 on model risk management, which applies from May 2027 and covers a far broader definition of model than most institutions currently inventory.
Get an Agent Trust Gap BriefThe short answer
AIDA — the AI and Data Act proposed within Bill C-27 — died on the order paper. Coverage that still describes Canada as being about to have a federal AI act is out of date. That absence has not left a vacuum: for federally regulated financial institutions, model risk supervision is where agent governance actually lands.
OSFI Guideline E-23 is the date that matters: May 2027. It expands model risk management expectations well beyond traditional quantitative models. An AI agent that informs or takes decisions is within scope of that thinking, and the guideline expects inventory, proportionate risk rating, validation, and ongoing monitoring across the model lifecycle.
Institutions that already run mature model risk functions have a head start. The gap is usually inventory — agents are procured and deployed by teams that have never filed anything with model risk.
The instruments that actually bind
Named, dated, and separated from the guidance that carries no force of law. Where an instrument does not mention agents directly, that is stated rather than implied away.
| Instrument | Status | Bearing on agents |
|---|---|---|
| AIDA (Bill C-27) | Did not pass | No federal AI statute resulted. Treat any plan built on AIDA obligations as void and re-baseline. |
| OSFI Guideline E-23 | Applies May 2027 | Model risk management for federally regulated financial institutions. Broad model definition; lifecycle expectations covering inventory, risk rating, validation and monitoring. |
| PIPEDA | In force | Federal private-sector privacy law. Applies to whatever personal information an agent reads, stores or transmits. |
| Quebec Law 25 | In force | Stricter provincial privacy regime including automated-decision transparency. Applies independently of federal law. |
| Provincial sectoral rules | Varies | Health, employment and consumer protection remain provincial. Confirm per province where the agent operates. |
Last verified 2026-08-07. This is a summary of published instruments for orientation, not legal advice. Obligations depend on your role, deployment and sector — confirm against the primary text and your counsel.
What this means for an agent deployment
Regulation in this region does not generally name "AI agents". It names outcomes: traceability, human oversight, accountability for automated decisions, incident reporting. An agent that acts — books, pays, sends, changes records — has to produce evidence of those properties on demand.
- Re-baseline any AIDA-era plan. If your roadmap references AIDA obligations, it is planning against a statute that does not exist.
- Inventory agents as models now, not in 2027. The hardest part of E-23 readiness is discovering what is already deployed. Inventory takes longer than documentation.
- Risk-rate proportionately. E-23 expects effort scaled to risk. A scheduling agent and a credit-decisioning agent should not receive identical treatment, and saying so in writing is part of the compliance posture.
- Build monitoring evidence, not just validation evidence. Ongoing monitoring is where model risk programmes usually fail examination — and agents drift faster than statistical models.
- Check Quebec separately. Law 25's automated-decision transparency duties apply on their own terms regardless of federal position.
Common questions
Did Canada pass an AI act?
No. AIDA, proposed within Bill C-27, did not become law. Canada has no comprehensive federal AI statute. Sources describing an imminent Canadian AI act are out of date.
What is OSFI Guideline E-23?
OSFI's model risk management guideline for federally regulated financial institutions, applying from May 2027. It uses a broad model definition and sets lifecycle expectations — inventory, risk rating, validation, ongoing monitoring.
Is an AI agent a model under E-23?
If it informs or makes decisions, institutions should expect it to be treated within model risk management. The guideline's definition is deliberately broad; assuming exclusion because the system is called an agent is not a defensible position.
What should a Canadian FI do first?
Inventory. You cannot risk-rate, validate or monitor what you have not enumerated, and discovery consistently takes longer than institutions plan for.
Does Quebec Law 25 add anything for agents?
Yes. It includes automated-decision transparency obligations that apply independently of federal law, so a Quebec deployment needs its own answer.
What OSFI and privacy regulators ask in Canada
The control set barely changes across jurisdictions; the interrogation does. These are the instruments an examiner cites here, and the question each one turns into.
| Instrument | Status | What the examiner actually asks |
|---|---|---|
| OSFI E-23 | Effective May 2027 | Is the agent in the model inventory? Validated, monitored, and can you explain one decision on demand? |
| PIPEDA / Law 25 (Quebec) | In force | Automated decision transparency and the right to an explanation - can you produce it for this action? |
| AIDA (proposed) | Pending | Would this qualify as a high-impact system, and is the governance evidence ready if it lands? |
Instruments and dates as verified 2026-08-12. Not legal advice.