← Insights / Compliance

Canada's AIDA stalled until 2025–2026, but OPC enforcement on generative AI is live now—what replaces the regulatory gap

When Canada's Artificial Intelligence and Data Act stalled in January 2025 following the prorogation of Parliament, some businesses quietly exhaled. With no standalone AI legislation on the books, the assumption was that the regulatory clock had paused too. It had not.

Compliance 30 August 2026 6 min read

Canada's AI Act Is on Hold — But Enforcement Isn't Waiting

When Canada's Artificial Intelligence and Data Act stalled in January 2025 following the prorogation of Parliament, some businesses quietly exhaled. With no standalone AI legislation on the books, the assumption was that the regulatory clock had paused too. It had not.

The Office of the Privacy Commissioner of Canada moved swiftly to fill the gap, launching investigations into OpenAI and X Corp. under existing privacy law. Meanwhile, across the border, the United States has quietly assembled a fragmented but increasingly consequential AI compliance environment — one that catches foreign businesses off guard precisely because it lacks a single, legible framework to track. For professional services firms operating across North America, the message is clear: the absence of a landmark AI act does not mean the absence of risk.

What Happened to AIDA — and What Comes Next

Bill C-27, which contained AIDA, ceased parliamentary progress in January 2025. The legislation is expected to be reintroduced by Canada's new federal government, which took office in April 2025, but even under an optimistic timeline, phased enforcement sits 24 to 36 months beyond royal assent. For practical purposes, a standalone Canadian AI act is not arriving imminently.

That regulatory gap has not gone unfilled. Canada's "AI for All" strategy, launched in June 2026, signals the government's intention to govern AI through a combination of reformed privacy law, new online safety legislation, and sector-specific guidance — rather than waiting for a dedicated AI statute. It is a pragmatic pivot, and one that has real implications for how businesses need to think about compliance now.

The federal privacy law, PIPEDA, is the primary framework in the interim. Amendments to PIPEDA — and a proposed new federal private sector privacy statute — are expected in late 2025 or early 2026. When enacted, they are set to introduce a tribunal-based enforcement regime, data mobility rights, and targeted measures addressing children's privacy and AI-generated deepfakes. Ontario has already moved ahead with its Enhancing Digital Security and Trust Act, which sets accountability requirements for public sector AI use. The broader compliance environment is consolidating around privacy law, not waiting for AI-specific legislation to catch up.

The OPC Is Not Standing Still

The Office of the Privacy Commissioner's activity since late 2023 has been substantive and escalating. Its guidance on generative AI, issued in December 2023, established clear expectations around consent, transparency, and data minimisation. That guidance is not aspirational — it reflects how the OPC is reading existing PIPEDA obligations and applying them to AI systems in active use.

By mid-2026, the OPC had launched Commissioner-initiated complaints against X Corp. and X.AI concerning PIPEDA compliance, and a joint investigation into OpenAI. These are not routine inquiries. They signal an enforcement posture that treats generative AI deployment as squarely within the scope of current privacy law, regardless of whether dedicated AI legislation exists.

For businesses using AI tools to process personal data relating to Canadian individuals — whether those businesses are based in Toronto, London, or Singapore — PIPEDA obligations apply. The absence of AIDA does not alter that position.

The United States: Deregulatory at the Federal Level, Active Everywhere Else

The Trump administration's approach to AI has been explicitly pro-innovation. Executive Order 14179, signed in January 2025, revoked Biden-era AI safety directives. A subsequent executive order in December 2025 sought to establish a unified national AI policy, with provisions that may constrain conflicting state-level rules — though exemptions exist for areas including child safety.

What this means in practice is that federal AI regulation in the US is deliberately restrained — but the vacuum is being filled aggressively at the state level, and through existing federal enforcement authority.

Colorado's AI Act was repealed and replaced by SB 189 in May 2026, with the new law taking effect on 1 January 2027. The revised legislation focuses on automated decision-making technology that materially influences consequential decisions — a formulation that will be immediately recognisable to firms using AI for hiring, credit assessment, client eligibility screening, or marketing personalisation. California and Texas have their own AI-related legislation either enacted or in progress. For businesses with any US footprint, tracking state-level developments is no longer optional.

The Federal Trade Commission continues to exercise its authority under Section 5 of the FTC Act to pursue deceptive AI practices. Recent enforcement actions against NGL Labs and Cox Media Group demonstrate that the FTC is scrutinising both how AI is marketed and how it performs. The term "AI washing" — overstating the capabilities or safety of AI products — is now firmly in the FTC's vocabulary. A proposed policy statement issued in July 2026 suggests that scrutiny of accuracy claims in AI systems is intensifying further. Congress also passed the TAKE IT DOWN Act in 2025, specifically targeting AI-generated deepfakes, demonstrating that targeted federal legislation is viable even where comprehensive AI law is not.

What This Means for International Professional Services Firms

The jurisdictional complexity here is the central compliance challenge. An accountancy practice in the UK processing data on Canadian clients through an AI-powered document tool, a US-based HR consultancy using automated screening for roles that include Canadian applicants, or a marketing agency in the UAE running AI-driven campaigns targeted at US consumers — each of these scenarios carries real regulatory exposure that does not require AIDA to exist.

Several obligations are live right now and apply to firms regardless of where they are headquartered:

Privacy law as the AI compliance baseline. In Canada, PIPEDA governs. Consent, transparency about automated processing, and data minimisation are not future requirements — they are current ones. Firms should audit whether their AI deployments involving Canadian personal data meet these standards.

US state law cannot be treated as a domestic concern. The patchwork of state AI laws affects any business with US customers, employees, or operations. Colorado's SB 189 taking effect in January 2027 gives firms a defined deadline for reviewing their automated decision-making processes.

FTC exposure is not limited to US companies. Deceptive claims about AI capabilities or safety can attract FTC scrutiny where US consumers are involved. International firms marketing AI-enhanced services to US clients should review how those services are described and evidenced.

Deepfake legislation is cross-jurisdictional. Both Canada and the United States are legislating specifically on AI-generated deepfakes. Professional services firms in media, marketing, HR, and legal services need to understand where this applies to their workflows.

Documentation and accountability are universal expectations. Whether under PIPEDA today or AIDA in the future, regulators expect firms to demonstrate that AI systems are governed with clear accountability, meaningful human oversight, and documented decision trails.

The Compliance Window Is Now

The regulatory trajectory in North America is moving in one direction. Enforcement is active under existing frameworks. New legislation is in development. And the expectation that businesses are proactively governing their AI use — rather than waiting for a compliance deadline to force the issue — is already embedded in how regulators are operating.

Professional services firms that treat the AIDA delay as a reprieve are misreading the environment. The reprieve has already been spent.

Ops Intel works with professional services businesses across the UK, North America, the EU, and beyond to map their AI compliance obligations, identify gaps, and build governance frameworks that are proportionate, practical, and audit-ready. If your firm is using AI and is uncertain where it stands under Canadian or US law, now is the right time to find out.

Get in touch with Ops Intel to book a compliance assessment.

Follow us in Google

See Ops Intel first when AI rules change

One click tells Google you want our compliance briefings near the top of your results — and marks us as a preferred source inside Google's AI answers. It applies to your Google account only, and you can undo it any time.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit