- prologue
european union(“”EU”) has taken an important step towards regulating artificial intelligence (”).AI”). With the increasing use of generative AI, the EU Parliament has endorsed: artificial intelligence law (“EU AI Law”), intended to address potential risks and dangers associated with the use of AI.[1] The law takes a “risk-based approach” and introduces limits based on how dangerous lawmakers perceive an application to be. It also establishes controls for high-risk technologies, such as recommendation algorithms, and requires organizations to label AI-generated content.
The first AI law of its kind, the EU AI law has the potential to set a global standard for the regulation of AI systems, further underscoring the EU’s leading position in technology governance. The EU has introduced regulatory tools aimed at Silicon Valley tech giants. Following in the footsteps of the EU, several countries have announced efforts to develop their own AI regulatory frameworks. US organizations including Microsoft, OpenAI, and Google are lobbying for AI regulation around the world.[2]
- Canadian AI Regulatory Framework
AI applications offer tremendous benefits and are becoming increasingly valuable to companies across industries. As ongoing AI developments continue to bring new opportunities, companies considering developing, deploying, or using AI systems should recognize and address the concerns and potential risks associated with these technologies. is important. These concerns arise from various dimensions and include technical, ethical, legal and social aspects.
In particular, the development and use of AI systems are closely intertwined with data privacy. Because AI systems process personal information (“PIs”), organizations relying on such systems or AI service providers may not be permitted to collect, use, and communicate personal information belonging to their customers or employees, even if such collection, use, or communication relies on AI systems. is done in accordance with privacy laws. .
In Canada, the federal government has shown remarkable dedication to addressing these issues and promoting the responsible and safe use of AI.[3]
- Law 25 (formerly Bill 64)
in Quebec, Act on the Development of Laws and Regulations Concerning the Protection of Personal Information (“Law Article 25” and the previous bill 64) introduced amendments to the privacy regime governing the collection, use and communication of PI in the public and private sectors. Section 25 represents the latest and most important framework for privacy regulation in Canada.
Any organization operating in Quebec will be directly affected by Law 25, whether it has its headquarters in the province or simply conducts business there. To ensure compliance, companies must pay attention to the mandatory requirements laid down in Law 25. Requirements already in force include:
- Obligation to appoint a privacy officer.[4] and
- Obligation to give prompt notice information committee and individuals involved in the event of a confidentiality incident involving the risk of serious injury.[5]
Further amendments, effective September 22, 2023, will also bring significant changes to our privacy compliance framework. Future requirements include:
- Obligation to conduct a privacy impact assessment (“Pia”) Projects that acquire, develop, or overhaul any information system or electronic service delivery system that involves the collection, use, communication, storage, or destruction of PI.[6] and
- Obligation to conduct PIA for communication of PI outside Quebec.[7]
In particular, Law No. 25 introduces increased penalties for violations of the Privacy Law, which will come into effect on September 22, 2023. A private sector organization could face fines ranging from C$15,000 to C$25 million, or an amount equal to his 4% of all organizations worldwide. The previous fiscal year’s sales, whichever is greater.[8]
Canada’s federal privacy regulatory landscape is undergoing a significant transformation that will have far-reaching implications for businesses operating in Canada.Introduction of Legislation enacting the Consumer Privacy Protection Act, the Personal Information and Data Protection Court Act, the Artificial Intelligence and Data Act, and making related amendments to other laws as a result;that is, in short, Digital Charter Implementation Act 2022 (“Building C-27”) passed a second reading in the House of Representatives and was referred to the Industrial Technology Standing Committee for review on April 24, 2023, and represents an attempt to overhaul Canada’s federal privacy framework. increase.[9] If adopted in its current form, Bill C-27 would create three new laws. Consumer Privacy Act (“CPPA”), Personal Information and Data Protection Court Act (“PIDPTA“), and the artificial intelligence and data law (“Aida”).The adoption of these legislative measures will directly affect the operations of companies that develop, deploy or use AI systems in the field of international or interstate trade and commerce.
Under the CPPA, all organizations are required to establish a privacy management program.[10] Such a program should cover various aspects such as protecting PI and handling consumer requests and complaints for access to PI. Additionally, under the CPPA, an organization must grant the Canadian Privacy Commission access to the policies, practices, and procedures outlined in its privacy management program.[11]
In June 2022, AIDA was introduced as part of Bill C-27 to ensure responsible adoption of AI technology by Canadian companies. More specifically, AIDA builds on Canada’s existing consumer protection and human rights laws. An office headed by a new Artificial Intelligence and Data Commissioner will be created to assist in the regulation and administration of the Act, ensuring that policy and enforcement are aligned as AI systems evolve.[12] It also prohibits the reckless and malicious use of AI through the creation of new criminal law provisions.[13]
Implementation of the initial set of AIDA regulations is expected to follow the following path:[14]
- Public consultation on regulations (6 months).
- Preparation of draft regulations (12 months);
- Consultation on draft regulations (3 months); and
- The first set of regulations comes into effect (3 months).
This pathway would provide a period of at least two years after Bill C-27 receives royal approval before the new legislation takes effect. This means AIDA will come into force by 2025 at the earliest.[15] For more information on Bill C-27, see our previous article.
- Conclusion
The pending law on AI and Data Privacy Regulation exemplifies the legislators’ efforts to promote more responsible and safe use of AI in Canada. To align with these regulatory frameworks and ensure compliance with the new mandates imposed on them, companies will need to build tighter internal AI governance structures.
Given the speed of development of AI systems and the increasing number of commercial applications of these technologies, as well as the acceleration of regulatory reforms in Canada and abroad, businesses are faced with a variety of risk factors associated with their development, implementation and adoption. should be considered. Use of AI systems in serving customers who rely on those technologies. Organizations can adopt measures to more effectively mitigate the risks associated with the use of AI applications.
If you have any questions about how McCarthy Tetlow can help your business on any of the topics above, our experienced attorneys will be happy to help you develop a strategy to mitigate your commercial and legal risks. Let me do it.
[1] artificial intelligence law.
[2] Cat Zakrzewski and Cristiano Lima, Europe Advances AI Regulations, Challenges Tech Giants, Washington Post: https://www.washingtonpost.com/technology/2023/06/14/ eu-parliament-approves-ai-act/.
[3] Aviv Gaon and Ian Stedman, A Call to Action: Moving Forward with the Governance of Artificial Intelligence in Canada, 2019 56-4 Alberta Law Review 1137, 2019 CanLIIDocs 2093: https://canlii.ca/t/skqg.
[4] Section 25 of the Act, s. 3.1.
[5] Section 25 of the Act, ss. 3.5-3.8.
[6] Section 25 of the Act, s. 3.3.
[7] Section 25 of the Act, s. 17.
[8] Section 25 of the Act, s. 91.
[9] House Reference: Bill C-27 – Legislation to enact the Consumer Privacy Protection Act, the Personal Information and Data Protection Court Act, the Artificial Intelligence and Data Act, and to make consequential and related amendments to other legislation;.
[10] CPPA, s. 9(1).
[11] CPPA, s. 10(1).
[12] Aida s. 33.
[13] Aida s. 39.
[14] Artificial Intelligence and Data Act (AIDA) – Related Documents (seeAIDA Companion Document”).
[15] See AIDA appendix.
