Canada has no federal AI statute. What it has, for the institutions where AI decisions carry the most consequence, is a model risk guideline with a date on it. OSFI Guideline E-23 takes effect on 1 May 2027, and the 2025 revision brought artificial intelligence and machine learning explicitly inside its scope.
That single fact reorders most Canadian AI governance conversations. The question is not whether regulation is coming. For a federally regulated institution it has arrived, it is specific, and the transition period is already running.
Listed by what binds you rather than by what is discussed. Verified at publication; verify again before you rely on it, because these move.
Most institutions read E-23 and plan a validation programme. The validation is tractable. What catches people is the inventory standard underneath it, because an inventory is only as good as its ability to answer a question after the fact.
An inventory that lists models is not an inventory. It has to carry the risk rating, the owner, the validation status, the approval and its date, and enough lineage to answer what changed and when. For AI systems that last requirement is where conventional model risk management breaks: the model is not the only thing that varies. The prompt changes, the retrieval corpus changes, the routing policy changes, and none of those is a deployment. An inventory blind to them is describing a system that no longer exists.
That is an architecture problem rather than a documentation problem, which is why the two halves of this practice are the same job. Governance the platform emits as it runs will still be true in May 2027. Governance maintained by hand will be stale by the second validation cycle.
OSFI released the 2027 version of Guideline E-23 on 11 September 2025 and it takes effect on 1 May 2027, after an eighteen-month transition. It applies to federally regulated deposit-taking institutions and insurers, including branches. It does not apply to federally regulated pension plans. The date matters more than it looks: eighteen months is enough time to build a model inventory and not enough to build one twice, so the sequencing decision you make now is the one you live with.
Both, and the 2025 revision is largely about making that explicit. The scope is all models that carry risk to the institution, which is deliberately broader than a list of model types, and the guideline adds context specifically for AI and machine learning. The practical consequence is that a model whose behaviour is learned rather than specified still has to be inventoried, risk-rated, validated and monitored, and the fact that nobody can read its logic is your problem to solve rather than an exemption.
No, and this is worth being exact about because a great deal of advice assumes otherwise. The Artificial Intelligence and Data Act formed part of Bill C-27, which died on the Order Paper in January 2025 when Parliament was prorogued. It was never voted on. There are no AIDA obligations, no AIDA fines, and no AIDA compliance deadline, and Canada has no federal AI statute of any kind. Anyone selling AIDA readiness is selling a bill that does not exist. The exposure that is real comes from OSFI E-23, privacy law, and the extraterritorial reach of the EU AI Act.
It depends which one you are. A federally regulated financial institution has OSFI E-23 from May 2027, alongside the existing operational-risk and third-party guidelines. Any private-sector organisation has PIPEDA, and provincially, Quebec Law 25. A federal government institution has the Treasury Board Directive on Automated Decision-Making, which has applied for years and is the closest thing Canada has to an AI-specific rule. An Ontario public-sector institution has Bill 194, in force since 1 July 2025. And any organisation whose output reaches the European Union is inside the EU AI Act regardless of where it sits.
E-23 sets a minimum standard for it, which is the part most institutions underestimate. An inventory that lists models is not an inventory; it has to carry the risk rating, the owner, the validation status, the approval and its date, and enough lineage that you can answer what changed and when. For AI systems the hard part is usually that the model is not the only thing that varies: the prompt, the retrieval corpus and the routing policy change without a deployment, and an inventory blind to those describes a system that no longer exists.
Independent assessment and architecture rather than a compliance filing. The Teardown scores the estate against the four MESA layers and produces a board-ready reading of where you actually are, which is the input to an E-23 programme rather than a substitute for one. The architecture work is the other half: governance that the platform enforces at runtime rather than a policy document describing one, because an inventory maintained by hand goes stale between validations.
The transition period is enough time to build a model inventory once. It is not enough to build one, discover it cannot answer a lineage question, and build it again. The sequencing decision is the one that matters, and it is cheapest now.
The Fit Call is thirty minutes and free, and it qualifies the work in both directions. If what you need is a validation vendor rather than an architect, you will be told that on the call.