Government
A government AI decision differs from a commercial one in a way that changes the whole design. The person on the other side of it did not choose to be there, usually cannot go elsewhere, and is often interacting with the state at the worst moment of their year. A benefits determination, an eligibility screen or a risk score carries a duty that a product recommendation does not.
Which is why the public-sector rules are the most AI-specific rules either region has, and why they are older than the current wave. Canada’s Directive on Automated Decision-Making has applied for years. It requires an algorithmic impact assessment, notice, explanation and human intervention, scaled to how much the decision can hurt.
What is actually in force.
Listed by what binds you rather than by what is discussed. Every date here was verified on 9 August 2026; verify again before you rely on it, because these move.
The rule that does not exist.
Neither Canada nor any Gulf state has a binding horizontal AI statute. AIDA is not law: it formed part of Bill C-27, which died on the Order Paper in January 2025, was never voted on, and carries no obligations, fines or deadlines. Anyone selling AIDA readiness to a Canadian public body is selling a bill that does not exist. What is real is the Directive, provincial access and privacy law, Ontario Bill 194 for Ontario public bodies, and the extraterritorial reach of the EU AI Act.
The practical consequence for a public body is liberating rather than alarming. There is no statute to wait for, and no excuse to wait either. The instruments that exist already describe what a defensible automated decision looks like, and building to them now is cheaper than retrofitting to whatever eventually arrives.
The questions a board actually asks.
Which rule applies to a Canadian public body using AI?
It depends which body, and the distinctions matter more than they look. A federal government institution is bound by the Treasury Board Directive on Automated Decision-Making, which has applied for years and requires an algorithmic impact assessment, notice, explanation and human intervention scaled to impact. An Ontario public-sector institution is additionally inside Bill 194, in force since 1 July 2025, which amends FIPPA and creates the EDSTA. Manitoba public bodies answer to FIPPA and health trustees to PHIA. PIPEDA governs private-sector commercial activity, not provincial public bodies, and that last point is the one most often got wrong.
Is AIDA law, and do we need to prepare for it?
No, and no. The Artificial Intelligence and Data Act formed part of Bill C-27, which died on the Order Paper in January 2025 when Parliament was prorogued. It was never voted on. There are no AIDA obligations, no fines and no deadline, and Canada has no federal AI statute of any kind. A public body preparing for AIDA is generating evidence nobody will ask for while the real obligations, the Directive and provincial access and privacy law, go unaddressed.
What does an algorithmic impact assessment actually need?
Enough to establish the impact level honestly, and then the controls that level requires. The part institutions underestimate is that the assessment is not a one-time artefact: the impact level is a function of how the system is used, and a model repurposed from a low-impact screen to a high-impact determination has changed its own classification without anyone filing anything. The governance question is therefore not only what the assessment says but what triggers it to be redone, and that trigger has to be wired into the deployment process rather than into a calendar.
How is public-sector AI governance different from a bank?
The obligation is stronger and the tooling is weaker. A bank has decades of model risk management to extend and a supervisor who examines it. A public body usually has neither, while facing a subject who cannot take their business elsewhere and a duty of procedural fairness that has no commercial equivalent. In practice this means the explainability requirement is harder and the appeal path matters more, and it also means the maturity baseline is often lower, so the first honest score tends to be uncomfortable and useful in equal measure.
What is the relevant experience here?
Seven years inside the Kuwaiti state, at the Council of Ministers and before that the Ministry of Planning, followed by enterprise and data architecture on national-scale programmes and regulated sectors across North America. That is unusual pairing: most AI governance advice for government comes either from people who have worked inside a public administration or from people who have built the systems, and the work here needs both. Engagements are taken personally through iSystematic rather than staffed to a bench.
Governance an examiner can follow, in the jurisdiction that actually binds you.
Ask your AI assistant instead.
This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is lookup_regulation and identify_relevant_service, which return what is actually in force for a jurisdiction, and map a described problem to an engagement shape with the routing reasoning shown. Sector summaries are where a live obligation and a consultation draft most often get merged into one sentence, so checking the instrument rather than the summary is the point.
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp
Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.
“Using Concylium, list what binds an AI system deployed by a public body in Canada and in the UAE, and tell me which of those are in force today.”
Two jurisdictions at once is where flattening shows. The answer separates in force from guidance and names the instrument behind each.