(Disponible uniquement en anglais)
Via email: AIConsultations-ConsultationsIA@ised-isde.gc.ca
Innovation, Science and Economic Development Canada
235 Queen Street
Ottawa, ON K1H 0H5
To responsible department:
Re: ISED Consultation on AI Transparency
We write on behalf of the Canadian Bar Association's Privacy and Access Section and Intellectual Property Law Section (CBA Sections) in response to Innovation, Science and Economic Development Canada (ISED)'s consultation on AI transparency.
The CBA is a national association of over 40,000 lawyers, law students, notaries and academics, and our mandate includes seeking improvement in the law and the administration of justice. The CBA Privacy Section comprise lawyers across Canada with in-depth knowledge of privacy and access to information law and policy, and of intellectual property law. The Intellectual Property Law Section deals with legal issues around ownership, licensing, transfer and protection of intellectual property and related property rights. Our work includes patents, trademarks, copyright, industrial designs, plant breeders’ rights and trade secrets.
AI Generated Content
1. Would it help you trust what you see online if you could tell whether something was created by AI or by a person? When and for what kinds of content is most important to know if something was created or modified by AI?
Transparency about AI-generated content can support public trust, but the CBA Sections caution against treating all uses of AI in content creation in the same manner.
The threshold question should be when the use of AI is sufficiently material to warrant disclosure. AI tools are increasingly embedded in ordinary drafting, editing, translation, image enhancement and other commonly used applications. Requiring disclosure whenever AI has played any role in producing content could result in overly broad notices that provide little meaningful information to the public. Over time, ubiquitous disclosure may also lead to notice fatigue and reduce the value of disclosures in situations where authenticity is genuinely important. Central to that threshold is the distinction between content that is AI-generated and content that is merely AI-assisted. That distinction is developed further in response to Question 2.
The need for transparency is strong where a person is likely to rely on content as an authentic record of what someone said, did or created.
Examples may include realistic synthetic audio, images or video depicting identifiable persons; content that falsely represents that a person said or did something; impersonation or fraud; false content that could have substantial impact on persons; deceptive commercial representations; and content used in legal, governmental, electoral or other contexts where individuals are expected to rely on the authenticity of the material.
Deepfakes merit particular attention. In its October 2025 submission on Canada's AI Strategy1, (the National Sprint Submission) the CBA recommended that the federal government consider stronger legal protections against the unauthorized commercial exploitation of a person's likeness or voice through
AI-generated deepfakes. The submission proposed consideration of a federal tort of appropriation of personality or, in the case of commercial artists, a federal right of publicity. It also suggested that Canada consider protections for personal attributes such as an individual's face and voice.
At the same time, not every modification made with the assistance of AI should require disclosure. Minor editing, formatting, accessibility assistance or other uses that do not materially affect the substance or authenticity of content should generally not attract the same obligations as synthetic content capable of misleading the public.
A similar distinction is reflected in other CBA work concerning AI disclosure. In its May 2025 submission on immigration modernization2, the CBA recommended a mandatory disclosure rule where AI is used to create pleadings or evidence before the Immigration and Refugee Board, while distinguishing non-essential administrative technologies. This supports a contextual approach under which disclosure is tied to the significance of AI use rather than the mere presence of AI technology.
The CBA Sections therefore recommend that any transparency framework begin by establishing a clear and proportionate disclosure threshold, rather than simply requiring disclosure whenever AI has been used.
The CBA Sections suggest the following as a starting formulation. Disclosure should be required where both of the following are met.
First, either (a) AI has generated the content, or (b) AI has altered the content so that it no longer accurately represents what a person said, did or created, or so that it imitates a person's voice, likeness, or distinctive creative style, or depicts something that did not occur.
Second, the content is presented in a context where an ordinary viewer, listener or reader would take it to be an authentic record of real events, or the work of a human author, rather than a creative, illustrative or obviously synthetic work.
Disclosure should not be required where AI has been used to assist in producing content without changing what the content represents, including drafting assistance, translation, formatting, accessibility support and routine image correction.
The CBA Sections recognize that the line between generation and assistance is one of degree rather than kind, and that drafting assistance in particular lies on a spectrum. The question should be whether a human exercised substantive authorial judgment over the content, not whether a human was involved at some point in its production.
A threshold in these terms focuses transparency requirements on circumstances where they are most likely to provide meaningful protection, without creating unnecessary obligations for routine or low-risk uses of AI. It also gives effect to the distinction between AI-generated and AI-assisted content set out above.
2. What would best help Canadians determine when content is AI-generated, for example invisible or visible watermarks, disclaimers or provenance metadata?
There is unlikely to be a single technical solution capable of reliably identifying all AI-generated content. The CBA Sections recommend a layered approach that combines technical measures, meaningful disclosure and public education.
Where technically feasible, developers of generative AI systems should support mechanisms that enable the provenance of generated content to be identified. These may include metadata, digital credentials, cryptographic provenance mechanisms or watermarking.
Provenance infrastructure serves a further purpose that is easily overlooked. The mechanisms that allow AI involvement to be identified are the same mechanisms that allow human contribution to be attributed. Generative systems depend on human-created works and human-generated data, yet the individuals who supply those inputs are frequently invisible in the resulting output. A framework built only to detect machine involvement, with no capacity to record human contribution, addresses half of the question it is directed at. This consideration should inform how provenance standards are designed, not only how they are enforced.
However, such tools have limitations. Metadata may be removed, watermarks may be altered or defeated, and actors intending to deceive are unlikely to comply voluntarily with transparency requirements. Conversely, the absence of a watermark or provenance marker should not be understood as evidence that content is authentic.
The federal government's discussion paper (discussion paper) itself recognizes these challenges. It notes that technical methods for identifying AI-generated content vary in effectiveness and that watermarking, particularly for text, may be vulnerable to modification or removal. It also recognizes the potential value of provenance information while identifying privacy and other considerations that may arise from these technologies.
For higher-risk forms of synthetic content, technical provenance mechanisms should therefore be complemented by clear, user-facing disclosures. A visible notice may be more meaningful where an image, video or audio recording has been materially generated or manipulated in circumstances where a reasonable person might otherwise believe it to be authentic.
The form of disclosure should also communicate useful information. A generic statement that content “contains AI” may not assist users in understanding what occurred. Where appropriate, disclosure should distinguish between content that was:
- wholly generated by AI;
- materially altered using AI; or
- subject only to incidental or minor AI-assisted editing.
Canadian law already recognizes that a single undifferentiated label may not convey useful information. Country-of-origin claims are not generally required, but where a business chooses to make one about a non-food product, the Competition Bureau's enforcement guidelines apply graduated thresholds: a “Product of Canada” claim is treated as requiring at least 98% Canadian content, while a “Made in Canada” claim is treated as requiring at least 51% and must be accompanied by a qualifying statement indicating that the product contains imported content. In both cases the last substantial transformation must have occurred in Canada. Competition Bureau: “Product of Canada” and “Made in Canada” Claims.
The analogy is imperfect, and content provenance raises distinct considerations. But the underlying design problem is similar. A bare “contains AI” mark tells a reader little about the degree or significance of the AI involvement, just as an unqualified origin claim tells a consumer little about how much of a product is actually Canadian. The tiered approach set out above is intended to address that difficulty. A tiered approach only assists the public if the tier claimed can be relied on. Disclosure categories should therefore be capable of substantiation by the party applying them.
The federal government should avoid prescribing a single proprietary technological solution. Canada should instead support internationally interoperable technical standards so that provenance information remains useful when content crosses platforms and borders.
This recommendation is consistent with the CBA's October 2025 National Sprint submission3, which advocated a standards-setting framework anchored in transparency, auditing and interoperability. The CBA observed that, while secrecy may be appropriate for certain components of AI development, standards based on transparency, auditing and interoperability would be preferable in other areas and could support responsible innovation while discouraging misuse.
The National Sprint submission on AI modernization also emphasized the importance of education and skills as part of Canada's broader approach to AI. More broadly, the CBA's February 2026 resolution4 concerning AI's impact on the legal profession called for practical resources, competency frameworks and guidance to support responsible and competent AI use.
Public education should therefore accompany technical measures. Canadians should understand both the value and the limitations of AI-content labels and provenance technologies. Transparency measures should not inadvertently create a presumption that labelled content is unreliable or, conversely, that unlabeled content is authentic.
The CBA Sections recommend that the federal government favour interoperable provenance standards, meaningful disclosure in higher-risk circumstances and public literacy, rather than relying on a single watermarking or labelling technology.
3. Who in the AI value chain — developers, deployers or others — should be responsible for providing transparency around AI-generated content? Why?
Responsibility should reflect the role that each actor plays in creating, deploying and distributing
AI-generated content.
The AI value chain may involve developers of foundational or generative models, organizations that integrate those models into products or services, users who create content, and platforms that distribute the resulting material. No single actor will necessarily possess all of the information or control required to provide effective transparency.
Developers are generally best positioned to provide technical mechanisms that permit AI-generated content to be identified, including provenance information or watermarking where technically feasible. They are also best placed to document the capabilities and limitations of those mechanisms.
Deployers are better positioned to understand the context in which an AI system is being used. Where an organization incorporates generative AI into a product, service or communication, it should be responsible for ensuring that appropriate disclosures are provided where the applicable transparency threshold is met.
Platforms and other intermediaries that distribute content may also have an important role in preserving provenance information and communicating reliable information to users, particularly where content is disseminated at scale.
Finally, individuals and organizations should remain responsible for the representations they make. The use of AI should not enable a person or organization to avoid obligations that would otherwise apply under existing law, including laws relating to fraud, deceptive marketing, defamation, privacy, copyright or other unlawful conduct.
The CBA Sections recommend that responsibility be allocated according to knowledge, control and proximity to the relevant risk.
Allocating responsibility in this way also requires that it be possible to establish, after the fact, what each actor did. Transparency obligations have limited practical effect if no participant is expected to retain a record of the decisions it made. Each actor should therefore be able to demonstrate how it discharged its role: developers, the provenance mechanisms applied to generated content and their known limitations; deployers, the basis on which the disclosure threshold was assessed in a given deployment; and platforms, their handling of provenance information passing through their systems. This is consistent with the emphasis on auditing in the CBA's October 2025 National Sprint submission5, and it is what makes substantiation of a disclosure category practicable rather than notional.
This approach is consistent with the CBA's previous work on automated decision-making. In its January 2025 submission6 concerning artificial intelligence and automated decision-making in immigration law, the CBA emphasized transparency, accountability and meaningful human oversight in the deployment of automated systems.
Likewise, the CBA's May 2025 immigration modernization submission recommended disclosure where AI is used in adjudicative processes, together with AI impact assessments, privacy assessments and greater transparency concerning decision-making frameworks. These recommendations recognize the responsibility of the institution deploying the technology within the relevant decision-making context.
The CBA's February 2026 resolution7 on AI's impact on the legal profession reflects the same broader accountability principle. It identifies risks involving confidentiality, privacy, bias and diminished professional oversight, and calls for principled governance and responsible human involvement in AI use.
The federal government should therefore avoid assigning the entire disclosure obligation to one participant in the AI value chain. Responsibilities should instead be complementary:
- developers should provide the technical capabilities and information necessary for transparency;
- deployers should determine when disclosure is required in the context in which the system is used;
- platforms and distributors should preserve and communicate reliable provenance information where appropriate; and
- users and organizations should remain responsible for misleading or otherwise unlawful representations made using AI.
It should also seek to avoid duplicative obligations. Where several actors participate in the same value chain, their respective transparency responsibilities should be coordinated rather than repetitive.
4. Do existing market practices, technical tools and legal frameworks make it easy enough to know when content is AI-generated? If not, where do gaps remain and what actions should Government take?
Existing Canadian laws and market practices address some of the risks associated with AI-generated content, but they do not provide a comprehensive framework for identifying synthetic content.
Depending on the circumstances, existing laws concerning fraud, deceptive marketing, privacy, copyright, defamation and criminal conduct may apply to harmful AI-generated content. Courts, professional regulators and other institutions are also developing rules concerning disclosure and responsible use of AI in particular settings.
The discussion paper similarly recognizes that Canada already has a legal foundation relevant to AI, including privacy legislation, the Copyright Act, human rights legislation, the Criminal Code and sector-specific laws. It also recognizes that transparency measures may draw on a mix of legislation, standards, guidance, research, procurement and other policy instruments.
The CBA has previously favoured careful consideration of existing legal frameworks before introducing new AI-specific rights. In its response8 concerning Copyright in the Age of Generative Artificial Intelligence, the CBA recommended retaining the existing human-authorship basis of copyright and did not support creating a new sui generis copyright right for purely AI-generated works on the evidence then available.
That approach illustrates the importance of identifying the precise legal or policy gap before introducing a new legislative solution.
That said, the current transparency environment is not without gaps.
First, there is no generally accepted threshold governing when the use of AI in content creation should be disclosed.
Second, technical approaches to provenance and watermarking remain inconsistent and may not operate effectively across different systems and platforms.
Third, responsibility for preserving and communicating provenance information across the AI value chain is not always clear.
Fourth, existing legal mechanisms may not fully address certain forms of synthetic impersonation and the unauthorized commercial exploitation of an individual's likeness or voice. In its October 2025 National Sprint submission9, the CBA recommended consideration of a federal tort of appropriation of personality or, in the case of commercial artists, a federal right of publicity. The submission also suggested consideration of protections relating to personal attributes such as an individual's face and voice in response to deepfakes.
Comparable concerns are being addressed in other jurisdictions. In the United States, the NO FAKES Act of 202610 would create a federal intellectual property right in an individual's voice and visual likeness that is not assignable during the individual's lifetime but is licensable, and that may subsist for a period after death, subject to conditions. The Senate Judiciary Committee reported the bill with an amendment on 18 June 2026. It has not been enacted.
Denmark has notified the European Commission of draft amendments to its Copyright Ac11t providing protection against realistic digitally generated imitations of personal characteristics and of performers, requiring the consent of the person imitated and lasting 50 years after death. The amendments have not yet come into force. Notably, the explanatory notes to the notified draft indicate that Denmark does not intend to create a new copyright for citizens so much as to supplement existing personality-rights principles.
The United States has also enacted the TAKE IT DOWN Act12, which criminalizes the non-consensual publication of intimate visual depictions, including digital forgeries, and requires covered platforms to operate a notice-and-removal process
These measures are at different stages and rest on different legal foundations, but they suggest that the CBA's earlier recommendation is consistent with the direction of reform elsewhere.
A related question follows directly from the attribution point raised in response to Question 2. Each of the measures above protects personal attributes against unauthorized replication, but none addresses the position of those whose works and data are used to build generative systems in the first place. Provenance infrastructure that can record human contribution is a precondition for addressing that question: rights in human inputs cannot be allocated, licensed or enforced if the inputs cannot be traced.
The CBA Sections recommend that Government examine whether existing frameworks adequately address the position of those who supply the human-created works and data on which generative systems depend.
In its October 2025 National Sprint submission, the CBA took the view that Canada's existing copyright framework is already relatively balanced in this respect: unlike jurisdictions proposing broad text and data mining exceptions, the fair dealing provisions in section 29 of the Copyright Act, as interpreted by the courts, permit text and data mining for research and private study without undermining the interests of rights holders (provided those judicial limits are maintained and not expanded by legislative amendment). Consistent with that position, the more pressing question is not the creation of a new exception, but whether the rights that already subsist in human-created inputs can be identified, licensed, and enforced at the scale on which those works are now used. The CBA recommended strengthening opportunities for enforcement and licensing, which depend in practice on the ability to trace how and where such works have been used. This reinforces the point made above: provenance and attribution standards that can record human contribution are a precondition for making rights in human inputs effective.
That inquiry is distinct from the copyright question discussed above, and the distinction matters. The CBA Sections' position on AI-generated outputs rests on human authorship: a work produced without a human author does not attract copyright, and creating a right in such works would sever copyright from the authorship principle that grounds it. An inquiry into inputs raises the opposite situation. The works and data used to train generative systems are, by definition, human-created, and many are already the subject of subsisting rights. The question there is not whether to recognize a new class of authorless works, but whether existing rights operate effectively at the scale and in the manner in which those works are now used. Declining to create rights in machine outputs is therefore consistent with examining whether rights in human inputs are adequately protected. Any such examination should be informed by how provenance and attribution standards develop.
Fifth, particular contexts may justify more specific disclosure requirements because the authenticity of material is especially important. For example, the CBA's May 2025 immigration modernization submission13 recommended mandatory disclosure where generative AI is used to create pleadings or evidence before the Immigration and Refugee Board.
Sixth, the discussion of transparency has so far focused on the risk that AI involvement will be concealed. The opposite risk also exists. Content or products may be marketed as AI-generated when they are not or presented as human-made or AI-free without any basis for the claim. In its March 2024 discussion paper14 on artificial intelligence and competition, the Competition Bureau noted the United States Federal Trade Commission's guidance on how businesses can avoid false or misleading representations about AI products, which includes exaggerating what an AI product can do and fabricating that a product uses AI when it may not
Where a claim of that kind is made to promote a product or a business interest, section 74.01(1) of the Competition Act15 may apply: a representation that is false or misleading in a material respect is reviewable conduct, and a representation as to a product's performance or efficacy must be based on an adequate and proper test, the burden of proof resting on the party making the representation.
It is less clear that these provisions reach a self-applied provenance label on content that is not itself being promoted commercially. If Government adopts tiered disclosure categories, it should consider how a claimed category is to be substantiated and by whom.
Parliament has taken a comparable step in a related context. Section 74.01(1)(b.1) of the Competition Act16 requires that a representation as to a product's environmental benefits be based on an adequate and proper test, with the burden of proof on the person making the representation. That provision was introduced in response to concerns about unsubstantiated environmental claims, and it remains in force following the 2026 amendments (SC 2026, c 3), which altered the separate business-activity provision in paragraph (b.2) but left paragraph (b.1) unchanged.).
The parallel is instructive rather than determinative. It shows that where a particular category of claim is both commercially valuable and difficult for consumers to verify, Parliament has been willing to impose a claim-specific substantiation requirement rather than rely solely on the general prohibition on false or misleading representations. Claims about the provenance of content may raise a similar problem.
The CBA Sections recommend that Government pursue a proportionate, standards-based approach rather than a universal labelling obligation. Measures could include:
Establishing a clear, risk-based disclosure threshold, and where disclosure is required, expressing it through tiered categories that distinguish content wholly generated by AI from content materially altered using AI, rather than a single undifferentiated label.
- Prioritizing higher-risk forms of synthetic content, including realistic audiovisual impersonation, deepfakes, fraud and materially deceptive content.
- Clarifying responsibilities across the AI value chain, including developers, deployers, distributors and users; providing that each actor be able to demonstrate how it discharged its transparency role, so that allocated responsibilities can be verified after the fact; and coordinating those responsibilities so that they are complementary rather than duplicative.
- Providing for the substantiation of AI-related claims, including claims that content is AI-generated, human-made or AI-free, and considering whether existing deceptive marketing provisions adequately address unsubstantiated provenance claims.
- Supporting interoperable technical standards for content provenance rather than uniquely Canadian or proprietary requirements, using guidance, standards and codes of conduct while technologies continue to evolve rather than prematurely prescribing specific technical solutions, and using government procurement to encourage responsible provenance practices.
- Supporting research on the reliability, durability, privacy implications and circumvention of provenance technologies, and promoting AI and media literacy so Canadians understand both the capabilities and the limitations of AI-content detection.
- Reviewing existing legal protections for deepfakes and impersonation, including whether targeted additional protections are required for unauthorized exploitation of a person's likeness or voice, or distinctive creative style, and examining whether existing frameworks adequately address the position of those who supply the human-created works and data on which generative systems depend.
The objective should not be to label every use of AI. Rather, transparency measures should enable Canadians to identify situations where synthetic or materially altered content may reasonably affect their ability to evaluate what they see, hear or read.
The CBA Sections support meaningful transparency concerning AI-generated content. However, transparency requirements should be proportionate to the risk and should provide useful information rather than simply increase the volume of notices presented to Canadians. The federal government should first establish when disclosure is necessary, then determine which actors are best positioned to provide that disclosure and which technical or other measures are appropriate. A flexible, interoperable and risk-based approach is more likely to preserve public trust while allowing Canadians and Canadian businesses to benefit from legitimate uses of generative AI.
AI Interaction
1. When and why is it most important to know that you are interacting with an AI system? Are there contexts where you don't need to know that you're interacting with AI?
As AI becomes increasingly integrated into a wide range of everyday services, public familiarity with its technology grows, and certain functions and interactions begin to appear routine, much as earlier technologies did over time. Nevertheless, Canadians need clarity about the acceptable limits of AI use and when they are interacting with an AI rather than a person, particularly in circumstances where the stakes are high and individual rights may be affected. Such circumstances include the disclosure of personal information and the making of consequential decisions. Such decisions require review by a human or an authorized body, so that accountability is preserved and outcomes rest on sound judgment rather than on automated output alone. This is especially pertinent in medical, financial, public services, legal and employment contexts, where the consequences for individuals may be substantial and enduring. Individuals should therefore be able to receive an explanation and, where the consequences are significant, to access a human to review or correct the decision.
Whether disclosure and human review are required should turn on context and proportionality rather than on the mere presence of automation. The trigger should be the significance of the outcome to the individual: where an automated or AI-assisted process produces a decision or outcome likely to have a substantial and enduring impact on a person, both the involvement of AI and the availability of human recourse should be affirmatively disclosed, and the depth of that disclosure and review should be proportionate to the significance of the impact.
The CBA Sections submit that these considerations are even more pressing in the case of vulnerable individuals, and minors in particular, who may be more readily influenced by the tone, apparent empathy or authority attributed to an automated system.
Legislative attention elsewhere reflects the seriousness of that concern. In the United States, the GUARD Act would prohibit providers from making AI companions available to minors, require age verification, and require chatbots to disclose their non-human status. The Senate Judiciary Committee advanced the bill unanimously on 30 April 2026 and it awaits consideration by the full Senate; a House companion bill remains in committee. The bill followed congressional testimony from parents of children harmed after extensive chatbot interactions, against a background of child-welfare and product-liability litigation against AI companies.
The fraud dimension is growing in parallel. Voice cloning, deepfake impersonation, AI-enabled romance scams and sextortion targeting teenagers and young adults all depend on the target not knowing that the counterpart is synthetic.
The common thread is that knowing whether one is dealing with a machine matters most, precisely where the interaction is designed to feel human, which is also where disclosure is least likely to be volunteered. That argues for a baseline disclosure obligation in high-stakes and human-simulating contexts rather than leaving the question to platform discretion.
2. What factors make a disclosure of AI use meaningful and effective for the user?
Disclosure matters when AI interaction could be mistaken for authentic human communication. A meaningful AI disclosure should enable users, consumers, or affected individuals to understand how the AI system affects them, determine whether it is trustworthy, and act accordingly if necessary. The effectiveness of such disclosure depends on the purpose of the interaction, the context and the specific role of the AI system. For instance, people should understand whether AI is making independent decisions, assisting a human expert, producing content for public use, or performing routine background sorting tasks. When the AI tool's scope is clearly defined, it is easier to understand the relevance of the disclosure to the intended audience.
Building on the impact-based trigger described above, the extent and prominence of disclosure should be determined by the interaction's significance to the individual, so that high-impact automated decisions require clearer, more actionable disclosure than routine or low-impact uses. Immigration is illustrative. To date, the Immigration, Refugees and Citizenship Canada (IRCC) states that advanced analytics enable it to automate some processing steps for routine applications, and that its models are put in place to "streamline processing" and approve "straightforward cases," and to sort and identify applications requiring additional checks, but never to automatically refuse applicants. Even so, where automated triage, random selection, risk-scoring based on technology that may be subject to bias, or template tools materially shape a consequential outcome, disclosure should track the system's actual influence on the decision rather than its formal characterization as mere "assistance," and affected individuals should be told that AI was involved, used, or applied, and how to obtain reasons, human review, and correction. Therefore, when authorities use AI, including agentic AI, in automated decision-making, reviews, and judgments that could significantly affect individual outcomes and applications, there is a higher need for disclosure.
The key aspect for meaningful disclosure is whether people can act on the information given. In serious situations such as when hiring, applying for government benefits, receiving healthcare, or seeking justice, the information provided should explain the procedures for requesting a human review, challenging erroneous conclusions, opting out where possible, and correcting any inaccuracies in the data used to make the decision.
3. Who should be responsible for AI-interaction disclosures?
In general, the organization deploying or operating the AI system in a user-facing context is responsible, because it controls the point of contact with users. However, in other circumstances, such as in high-stakes domains described previously and in human-like exchanges, the responsibility should be shared. This shared responsibility should be established and clearly communicated between different layers, such as platforms or distribution platforms. Such a framework should be established early in the design process, determining what information will be disclosed at each stage.
This role-based, shared allocation of responsibility is consistent with Canada's international commitments. As an OECD member, Canada supports the OECD Recommendation of the Council on Artificial Intelligence which includes transparency and explainability as one of its five value-based principles for trustworthy AI. This principle provides that AI actors, according to their respective roles, should "commit to transparency and responsible disclosure regarding AI systems" by providing meaningful, contextual, and consistent information. Among other things, it requires actors to make stakeholders "aware of their interactions with AI systems, including in the workplace," to enable "those adversely affected by an AI system to challenge its output." Furthermore, it calls on them, where feasible and useful, to provide "plain and easy-to-understand information on the sources of data/input, factors, processes and logic leading to the prediction, content, recommendation or decision."
Canada has begun to give effect to that principle domestically: in its 2024 review of implementation, the OECD noted that Canada's Directive on Automated Decision-Making sets a wide range of mandatory requirements to ensure the responsible use of AI by federal institutions. This aligns domestic transparency standards with the framework the Government is advancing through its National Artificial Intelligence Strategy, AI for All, which the current consultation supports. Allocating disclosure responsibility according to each actor's role, capability, and control is consistent with both the modern OECD Recommendation and Canada's evolving framework.
4. Are existing market practices and legal frameworks sufficient to support transparency around AI interactions? If not, where do gaps remain and what actions do you think the Government should take?
Current market practices and legal structures do not adequately ensure consistent and reliable disclosure of AI interactions. Although some organizations have started notifying users that they are interacting with an AI in the settings of their chatbots and voice assistants, these disclosures are made inconsistently or buried in terms of service. There are no common standards on when, how and to what extent such disclosures should be made. Canada's existing laws, such as the Personal Information Protection and Electronic Documents Act (PIPEDA,) the Competition Act's deceptive marketing provisions and measures proposed in Bill C-27, which died on the order paper in January 202517, addressed AI interactions indirectly. It is a good start; however, there is no general duty to inform people they are interacting with an AI system and, more critically, when facing agentic AI.
AI Incidents
1. Are Canada's existing sectoral incident-reporting regimes sufficient?
Canada's existing incident-reporting regimes capture some AI-related incidents but arguably do not add up to a comprehensive framework for AI incidents. Privacy legislation requires breach reporting where personal information is involved, and the Communications Security Establishment operates a voluntary channel for reporting cybersecurity incidents. A recent step in the right direction is the Critical Cyber Systems Protection Act (CCSPA), enacted via Bill C-8, which received Royal Assent on June 15, 2026, and requires "designated operators" to report cybersecurity incidents to the "Cyber Centre" within 72 hours and to comply with "any confidential cybersecurity direction." While these regimes are valuable, they are not all-encompassing, as they apply only to designated operators in specified federally regulated sectors (and the operator obligations await a coming-into-force order), and privacy breach-reporting is triggered only where personal information is at risk. AI-related incidents that fall outside these sectors, or that cause significant harms not tied to a personal-information breach, may escape any reporting obligation. The CBA Sections suggest that the sector-based, incident-focused model of CCSPA illustrates how targeted reporting obligations can be structured, and that a comparable approach could inform how AI-related incidents are addressed.
This gap is significant because AI does not merely create new categories of incident; it also amplifies existing cybersecurity threats. In its October 2025 National Sprint submission to ISED's consultation on Canada's AI Strategy, the CBA observed that "AI raises the stakes in cybersecurity", as "attackers can use models to scale social engineering and deepfakes, to accelerate vulnerability discovery, and to craft targeted evasion". Such incidents can result in several harms including fraud, impersonation, and compromise of personal information, and yet may not fall squarely within any single existing reporting regime.
AI incidents also include systems that produce biased or discriminatory outcomes, and systems that access, use, or learn from unauthorized data, including copyright-protected works used for unauthorized training of models and systems, as well as personal information. Such incidents may fall outside the cyber-incident reporting regime, and as such reinforce the need for a coordinated, risk-based approach.
A serious incident should be defined by the risk of potential harm to an individual's or group's dignity, autonomy, safety, or legally protected rights, including intellectual property rights. Reporting regimes should distinguish between minor operational failures and incidents where fundamental interests are impacted.
Consistent with that submission, the CBA Sections reiterate that any AI-incident reporting obligation should be risk-based and coordinated with, rather than layered on top of, existing sectoral and privacy-breach regimes, so that a proliferation of overlapping or low-value reports does not obscure the incidents that genuinely warrant attention. Standards built on transparency, auditing and interoperability can support responsible innovation while discouraging misuse, and this should inform how AI-related incidents are surfaced and reported.
AI Agents
1. Are you concerned about the use of AI agents? In what contexts is it most important to know when an AI agent is in use? Why?
Concerns about the use of personal information are high, particularly in the context of AI agents. Unlike traditional generative AI, AI agents perform a variety of actions, such as sending messages, accessing other services, completing forms, transferring funds or aggregating information from diverse sources to accomplish tasks. When agents require access to personal information that may exceed what an individual would voluntarily disclose in a single interaction, it adds significant risk. Further risk arises when an agent makes consequential decisions about an individual without them knowing a decision was made, let alone whether an agent made it or that any chance of recourse is available.
A prior question also arises: whether a given task should be delegated to an agent at all. Recent third-party assessment gives that question weight. In its Frontier Risk Report covering February to March 2026, METR concluded that AI agents deployed internally at frontier developers plausibly had the means, motive and opportunity to initiate small autonomous deployments operating without human knowledge or permission, although they did not have the means to make such deployments highly robust. The 2026 International AI Safety Report similarly documents laboratory cases in which models directed to achieve a goal "at all costs" disabled simulated oversight mechanisms and, when confronted, produced false statements to justify their actions.
Transparency regarding agent use is therefore necessary but not sufficient. Some tasks should not be delegated to an agent at all. A framework directed only at how agent involvement is disclosed does not reach the anterior question of whether a particular task is suitable for delegation, and the CBA Sections encourage the federal government to address both.
2. Who should be responsible for disclosing the use of AI agents? What kinds of information should they be recording regarding the activities of AI agents, and what kinds of disclosures should they be making, and to whom?
Depending on the context, the main responsibility belongs to whoever is deploying the agent and benefiting from it. Agent platform providers also have a responsibility to support identification, logging, and privacy-by-design. Accountability should be shared across the chain, supported by record-keeping that adequately explains and audits events, including which agents and versions were used, the authorizations granted, the actions and decisions with the rationale behind them, and the personal information accessed. This record-keeping should be proportional to the risks and impacts of the decision on the affected individuals.
Agent records should also be subject to a defined retention period. An audit trail that expires before the affected individual learns that a decision was made is of no practical use to that individual.
3. What kinds of information do businesses need in order to confidently and safely use AI agents? Do businesses currently have access to the information that they need about AI agents?
Businesses need to understand how deploying AI agents affects their customers. They need a clear definition of the agent's capabilities, limitations and potential failures. They should also know how personal information flows, where it is stored, and how it is used for the agent's training; who can access it; and what privacy safeguards and controls are in place, including data minimization and human checkpoints. Businesses of all sizes should consider these, including smaller ones, who may need additional support to avoid risking their customers' data.
Businesses also need sufficient information to conduct thorough due diligence before adopting an AI agent. This includes how the system protects confidential and trade-secret information disclosed to or generated by it; the legitimacy of the data used to train the system, including compliance with copyright and other intellectual property rights, supported by appropriate representations and warranties; and the cybersecurity controls in place to guard against compromise of the agent and data breaches. These considerations are especially critical for agents used across multiple services, where a single incident or compromise can put confidential, private, or business information at immediate risk.
4. Are existing technical solutions, market practices, and legal frameworks sufficient to support transparency around agentic AI systems? If not, where do gaps remain and what actions do you think the Government should take?
Existing technical tools, market practices and laws do not yet provide sufficient transparency for agentic AI systems that perform multi-step tasks across services while processing personal information. Most current frameworks were designed for content generation or predictable automated decisions, not autonomous agents. Key gaps remain in standards for identifying and authenticating agents and in records that show what safeguards were applied to their actions.
For tasks that are delegated, however, governance standards already exist and Canada need not invent a framework. ISO/IEC 42001 establishes a certifiable AI management system, and ISO/IEC 23894 supplies AI-specific risk management guidance extending ISO 31000. The NIST AI Risk Management Framework is complementary. NIST's AI Agent Standards Initiative, launched in February 2026, addresses agent identity and authorization directly, together with its companion concept paper on accelerating the adoption of software and AI agent identity and authorization. That work is directed at the precise gap identified above. These are the reference points on which the market is converging, which supports backing interoperable international frameworks rather than uniquely Canadian requirements.
Tracking, audit trails, monitoring, simulation testing and human checkpoints are the substance of those standards. This is the same point made in response to Question 3 of the first section: allocating responsibility across the value chain achieves little unless each actor can show afterwards how it discharged its role. SOC 2 Type II is worth noting as a model rather than as a standard. It is a security attestation, not an AI framework, but it tests whether controls operated effectively over a period rather than whether they existed on the day of audit. That is the assurance question for agents.
A private assurance market is also forming. Certification bodies now accredit against ISO/IEC 42001, and independent AI-governance rating products have appeared. The Artificial Intelligence Underwriting Company publishes AIUC-1, a certification standard for AI agents, and AIQA Global publishes the AIQ score, a quantitative rating of enterprise AI governance whose methodology is expressly grounded in the NIST AI Risk Management Framework and ISO/IEC 42001, among other instruments.
Two points follow. First, the market is converging on the same reference standards, which supports backing interoperable international frameworks. Second, these are commercial products operating without a common accreditation floor, so one AI governance claim cannot readily be compared against another. That is the substantiation problem identified in response to Question 4 of the first section, reappearing in the assurance market itself.
No single measure can close these gaps. Government should pursue a combined approach: risk-based notice when people interact with an AI agent; clearer rules on liability, record-keeping and data protection; interoperable international standards; guidance and procurement requirements; research funding; and stronger literacy initiatives. Literacy should extend beyond general AI awareness. Canadians should be able to recognize when an agent is acting on personal data and know how to request reasons, corrections and human review. Small and medium-sized enterprises may also need support to assess vendor claims and configure appropriate guardrails. Professionals, regulators and public buyers will require sector-specific and technical fluency.
Yours truly,
(original letter signed by Julie Terrien for Brent Arnold and Mathew Brechtel)
Brent Arnold
Chair, Privacy and Access Law Section
Mathew Brechtel
Chair, Intellectual Property Law Section
End Notes
3 Supra, note 1.
5 Supra, note 1.
6 Supra, note 2.
7 Supra, note 4.
9 Supra, note 1.
10 NO FAKES Act of 2026, S 4591, 119th Cong.
12 TAKE IT DOWN Act, Pub L No 119-12 (2025).
13 Supra, note 2.
16 Supra, note 15 at s. s 74.01(1)(b.1).
17 The Artificial Intelligence and Data Act, proposed as Part 3 of the since-lapsed Bill C-27 (44th Parliament), died at prorogation in January 2025 and has not been reintroduced.