← Insights / Compliance

Canada's AIDA delayed until 2025–2026: How professional services should prepare during the interim regulatory gap

Canada's proposed Artificial Intelligence and Data Act — AIDA, part of Bill C-27 — is not law. When Parliament prorogued in January 2025, AIDA was halted mid-process. A new federal government emerged from the April 2025 election, and the expectation is that AIDA will be reintroduced, with phased enf

Compliance 23 August 2026 6 min read

Canada's AIDA Is Delayed. Here's Why Global Professional Services Firms Should Act Now Anyway

Canada's proposed Artificial Intelligence and Data Act — AIDA, part of Bill C-27 — is not law. When Parliament prorogued in January 2025, AIDA was halted mid-process. A new federal government emerged from the April 2025 election, and the expectation is that AIDA will be reintroduced, with phased enforcement beginning 24 to 36 months after royal assent. That timeline places meaningful obligations potentially two to three years away.

For some businesses, that sounds like breathing room. It is not. The interim period carries its own compliance risks, and firms that wait for AIDA to pass before taking action are misreading the landscape entirely.

The Gap Is Not Empty

The absence of AIDA does not mean the absence of obligations. Canada's existing privacy framework — the Personal Information Protection and Electronic Documents Act (PIPEDA) — remains in force and applies directly to AI systems that collect, process, or use personal data. The Office of the Privacy Commissioner of Canada (OPC) has made clear through 2025 guidance that PIPEDA's requirements for transparency, informed consent, and accountability extend fully to AI chatbots and biometric tools.

Professional services firms — accountants, HR consultancies, solicitors, marketing agencies — routinely handle sensitive client data. When that data touches an AI system, whether for document drafting, candidate screening, client communications, or campaign personalisation, PIPEDA obligations are engaged. Regulatory silence on AI specifically is not a licence to proceed without safeguards.

Additionally, the Canadian AI Safety Institute (CAISI), launched in November 2024 with a £30 million commitment, signals the direction of Canadian policy unambiguously. Its mandate covers evaluating advanced AI models, developing safety testing methodologies, and coordinating with international counterparts. Even in the interim period, CAISI's work is shaping what "responsible AI" looks like in Canada — and firms building internal governance frameworks now will find it considerably easier to align with AIDA when it arrives.

The US Picture: Fragmentation Is Its Own Risk

South of the border, the situation is structurally different but no less demanding. There is still no comprehensive federal AI regulation in the United States. President Trump's January 2025 Executive Orders revoked prior AI directives and signalled a preference for deregulation at the federal level, explicitly aiming to challenge conflicting state-level rules.

But state activity has not slowed. At least 31 US states enacted AI-related laws or resolutions in 2024 and 2025, covering algorithmic bias, deepfake content, government use of AI, and more. For any firm operating across multiple US states — or serving US-based clients remotely — this patchwork creates genuine compliance complexity. There is no single standard to meet. There are dozens of potentially overlapping standards, and that number continues to grow.

For international professional services firms with US client relationships or US-facing operations, tracking state-level obligations is no longer a peripheral concern. It is a core compliance function.

Enforcement Is Already Happening

The regulatory gap does not mean an enforcement gap. The Federal Trade Commission's Operation AI Comply, launched in 2024 and intensifying through 2025 and into 2026, targets firms that exaggerate or misrepresent their AI capabilities — a practice the FTC calls "AI washing." Marketing agencies and consultancies making inflated claims about AI-powered services are directly in scope.

The Securities and Exchange Commission has separately pursued enforcement actions against investment advisors for AI misrepresentations, identifying this as a standing enforcement priority. The message from both agencies is consistent: claims made about AI must be accurate, substantiated, and verifiable. In December 2025, the FTC's revised approach in the Rytr LLC matter indicated a shift towards prioritising demonstrated harms, but that refinement does not reduce the overall enforcement pressure. It redirects it.

For professional services businesses, this means that client-facing materials, proposals, and platform descriptions that reference AI capabilities require the same rigorous review applied to any regulated claim. If your firm cannot demonstrate what its AI tools actually do — and cannot show that they do it reliably — those claims present legal exposure.

One of the most significant near-term risks for professional services firms using AI tools is intellectual property liability. In the US, copyright infringement lawsuits against AI companies surged in 2025, with over 70 cases filed by October. The £1.2 billion settlement in Bartz v. Anthropic in September 2025, stemming from the use of pirated works in model training, established that this is not theoretical risk — it is financial reality.

In Canada, cases such as CanLII v Caseway AI and La Presse v OpenAI have raised pointed questions about data scraping and the provenance of training data. Firms that use third-party AI tools need to understand how those tools were trained and what indemnification, if any, their vendor agreements provide. Procurement due diligence on AI vendors is now a legal risk management function, not merely a technical one.

For solicitors and any professional services firm that produces or relies on legal documentation, a specific and escalating risk deserves direct attention. In Canada, the number of court decisions referencing AI-fabricated legal citations rose from seven in 2024 to 87 in 2025. The Federal Court issued disclosure guidelines in May 2024, amended in June 2025, requiring disclosure of AI use in submissions and warning of adverse cost consequences for non-compliance.

Using AI to assist in drafting legal submissions is not prohibited. Using AI-generated content without verification — and without disclosure where required — is a professional conduct issue with real consequences. Firms must build verification steps into any workflow where AI contributes to legal or regulatory documents.

What the Interim Period Requires

AIDA's delay does not reduce the case for preparation. It reframes it. Rather than building governance frameworks to meet a specific legislative deadline, firms should use the interim period to establish durable foundations that will serve them under AIDA, under US state laws, and under whatever comes next in the EU, the Middle East, or Asia-Pacific.

That means conducting an honest audit of where AI is used across the business, what data those systems touch, and what claims are being made about them internally and externally. It means reviewing vendor agreements for IP and liability provisions. It means establishing disclosure and verification protocols for AI-assisted work product. And it means assigning clear internal accountability for AI governance — not as a one-time project, but as an ongoing function.

The firms that treat the current regulatory gap as an opportunity to build proper foundations will find the transition to formal compliance far more manageable than those waiting to be told what to do.


Ops Intel works with professional services businesses across the UK, North America, the EU, and beyond to build AI compliance frameworks that are practical, proportionate, and built to last. If your firm is uncertain about its current exposure — under PIPEDA, US state law, or the AI regulations taking shape globally — contact our team for a compliance assessment. We will help you understand exactly where you stand and what needs to change.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit