§ 01Government

Government

AI governance for public bodies in Canada and the Gulf

A government AI decision differs from a commercial one in a way that changes the whole design. The person on the other side of it did not choose to be there, usually cannot go elsewhere, and is often interacting with the state at the worst moment of their year. A benefits determination, an eligibility screen or a risk score carries a duty that a product recommendation does not.

Which is why the public-sector rules are the most AI-specific rules either region has, and why they are older than the current wave. Canada’s Directive on Automated Decision-Making has applied for years. It requires an algorithmic impact assessment, notice, explanation and human intervention, scaled to how much the decision can hurt.

Written by Nabeel Khan, author of AI Governance & Compliance Frameworks for the Middle East · seven years in Kuwait government, the Council of Ministers and the Ministry of Planning · author of the MESA Framework · engagements are taken personally through iSystematic, not staffed to a bench
§ 02What applies

What is actually in force.

Listed by what binds you rather than by what is discussed. Every date here was verified on 9 August 2026; verify again before you rely on it, because these move.

In force
Treasury Board Directive on Automated Decision-MakingFederal government institutions in Canada. An algorithmic impact assessment, notice that a decision was automated, an explanation of how it was reached, and human intervention, each scaled to the assessed impact level. It is the closest thing Canada has to an AI-specific rule, it has applied for years, and it is the single best template available for what a defensible public-sector AI decision looks like even where it does not formally bind you.
1 July 2025
Ontario Bill 194Royal Assent 25 November 2024 and in force since 1 July 2025. It amends FIPPA and creates the Enhancing Digital Security and Trust Act. Public sector only. That scope limit is worth stating precisely, because it is routinely misread as a general Ontario AI law, and a private-sector organisation building a compliance programme against it is building against the wrong instrument.
Provincial
Access and privacy law, and who it actually bindsThis is where advice most often goes wrong, so it is worth being exact. Manitoba public bodies answer to FIPPA and health trustees to PHIA. Quebec has Law 25. PIPEDA governs private-sector commercial activity rather than provincial public bodies, which is the confusion that produces programmes aimed at the wrong statute. Each of these maps cleanly enough onto ISO/IEC 42001 and the NIST AI Risk Management Framework that a single control set can answer all of them.
Gulf
National AI programmes and the government use caseSDAIA sets Saudi direction, including generative-AI guidance written specifically for government, and certified itself to ISO/IEC 42001 in July 2024. Kuwait supervises through CITRA. Neither is a binding AI statute, and public-sector deployments in the Gulf tend to run ahead of the rules rather than behind them, which puts the governance burden on the institution rather than on the regulator. The GCC hub covers the region.
Everywhere
Explainability as an obligation rather than a featureThe common thread across every instrument above is that a person affected by an automated decision can ask why, and the answer has to be true, specific to their case, and comprehensible. That is an architecture requirement long before it is a policy one. A system that cannot reconstruct which inputs, which model version and which policy produced a given decision cannot answer the question at all, and no amount of documentation added afterwards will fix it.
§ 03What does not apply

The rule that does not exist.

Neither Canada nor any Gulf state has a binding horizontal AI statute. AIDA is not law: it formed part of Bill C-27, which died on the Order Paper in January 2025, was never voted on, and carries no obligations, fines or deadlines. Anyone selling AIDA readiness to a Canadian public body is selling a bill that does not exist. What is real is the Directive, provincial access and privacy law, Ontario Bill 194 for Ontario public bodies, and the extraterritorial reach of the EU AI Act.

The practical consequence for a public body is liberating rather than alarming. There is no statute to wait for, and no excuse to wait either. The instruments that exist already describe what a defensible automated decision looks like, and building to them now is cheaper than retrofitting to whatever eventually arrives.

§ 04Questions

The questions a board actually asks.

Which rule applies to a Canadian public body using AI?

It depends which body, and the distinctions matter more than they look. A federal government institution is bound by the Treasury Board Directive on Automated Decision-Making, which has applied for years and requires an algorithmic impact assessment, notice, explanation and human intervention scaled to impact. An Ontario public-sector institution is additionally inside Bill 194, in force since 1 July 2025, which amends FIPPA and creates the EDSTA. Manitoba public bodies answer to FIPPA and health trustees to PHIA. PIPEDA governs private-sector commercial activity, not provincial public bodies, and that last point is the one most often got wrong.

Is AIDA law, and do we need to prepare for it?

No, and no. The Artificial Intelligence and Data Act formed part of Bill C-27, which died on the Order Paper in January 2025 when Parliament was prorogued. It was never voted on. There are no AIDA obligations, no fines and no deadline, and Canada has no federal AI statute of any kind. A public body preparing for AIDA is generating evidence nobody will ask for while the real obligations, the Directive and provincial access and privacy law, go unaddressed.

What does an algorithmic impact assessment actually need?

Enough to establish the impact level honestly, and then the controls that level requires. The part institutions underestimate is that the assessment is not a one-time artefact: the impact level is a function of how the system is used, and a model repurposed from a low-impact screen to a high-impact determination has changed its own classification without anyone filing anything. The governance question is therefore not only what the assessment says but what triggers it to be redone, and that trigger has to be wired into the deployment process rather than into a calendar.

How is public-sector AI governance different from a bank?

The obligation is stronger and the tooling is weaker. A bank has decades of model risk management to extend and a supervisor who examines it. A public body usually has neither, while facing a subject who cannot take their business elsewhere and a duty of procedural fairness that has no commercial equivalent. In practice this means the explainability requirement is harder and the appeal path matters more, and it also means the maturity baseline is often lower, so the first honest score tends to be uncomfortable and useful in equal measure.

What is the relevant experience here?

Seven years inside the Kuwaiti state, at the Council of Ministers and before that the Ministry of Planning, followed by enterprise and data architecture on national-scale programmes and regulated sectors across North America. That is unusual pairing: most AI governance advice for government comes either from people who have worked inside a public administration or from people who have built the systems, and the work here needs both. Engagements are taken personally through iSystematic rather than staffed to a bench.

Governance an examiner can follow, in the jurisdiction that actually binds you.

Fin · Government
Book the 30-minute Fit Call →