Topics in AI
    8 min read

    Ottawa Is Consulting on AI Transparency. Europe Shipped It

    ISED opened a public consultation on AI transparency on July 23, closing September 23. It asks the questions the EU answered on August 2. For a small Canadian firm buying software today, the gap is the story.

    ByJames R. GosnellEducational content. Not legal advice.

    Ottawa Is Consulting on AI Transparency. Europe Shipped It

    Six days before the EU AI Act's disclosure rules became enforceable with a ceiling of 15 million euros, Innovation, Science and Economic Development Canada opened a survey asking Canadians what AI disclosure should look like. Both governments are working on the same problem. Only one of them has an answer that a firm can build against.

    What ISED put on the table on July 23

    The federal consultation on AI transparency runs from July 23 to September 23, 2026. It was announced by Evan Solomon, Minister of Artificial Intelligence and Digital Innovation, and it sits under the National Artificial Intelligence Strategy released on June 4. The centrepiece is a discussion paper titled "Enhancing trust in artificial intelligence through increased transparency." Submissions go through an anonymous survey or by email, and ISED plans to publish a "What We Heard" report after it closes.

    The paper is more candid than these documents usually are. It reviews invisible watermarking and provenance metadata, notes that the Coalition for Content Provenance and Authenticity has a working technical specification backed by Amazon, Google, Meta, Microsoft, and OpenAI, and then says the quiet part: a determined bad actor can strip or evade those signals, and technical approaches struggle to keep pace with the technology. That is an accurate description of the state of the art. It is also an admission that the mechanism Brussels just made mandatory has known holes.

    The five questions Ottawa is asking

    ISED organised the consultation around five areas. Detecting AI-generated content. Letting individuals know when they are dealing with an AI system. Improving the availability of information about what a given system can and cannot do. Tracking serious incidents. And tracking the activity of AI agents.

    The first two map almost exactly onto Article 50 of the EU AI Act, which is now in force. The third resembles the model documentation duties that Europe imposed on general-purpose providers a year ago. The last two are the interesting ones, because they are not primarily about labelling output at all. Serious incident tracking and agent activity tracking are logging questions. They ask whether anyone can reconstruct, after the fact, what a system did and when.

    That framing matters more for a Canadian professional services firm than the watermarking debate does. A small firm is rarely the provider of a generative model. It is almost always the deployer of one, and the deployer's exposure is a record-keeping problem.

    This is the third document in three months

    Ottawa has produced a lot of paper on AI this year and very little binding law. AIDA died on the order paper in January 2025 and has not been reintroduced. The National AI Strategy landed June 4 alongside the Privacy Commissioner's annual report on AI. Bill C-36, the Protecting Privacy and Consumer Data Act, was tabled in June as the first serious overhaul of federal private-sector privacy law in twenty-five years, carrying expanded deletion rights and new transparency duties where automated systems make significant decisions about people. Whether it survives a Parliament that killed its predecessor is an open question.

    A consultation that closes in late September, followed by a report, followed by a policy instrument, followed by drafting, is a 2028 timeline at best. Firms making software decisions this quarter cannot wait for it.

    What actually binds a Canadian firm today

    Three things do. Quebec's Law 25 has been fully in force since September 2024, and section 12.1 already requires an organization that makes a decision based exclusively on automated processing to say so, to explain the personal information used and the principal factors behind the decision, and to let the person submit observations to a human. The penalty ceiling is 25 million dollars or 4 percent of worldwide turnover. That is a live transparency obligation with teeth, and it applies to a Montreal firm right now whatever ISED concludes in September.

    Federal PIPEDA and its provincial equivalents apply to the personal information moving through those systems. And the EU AI Act reaches any Canadian deployer whose output is used inside the Union, which is a smaller carve-out than most firms assume once a client has European customers.

    The pattern is that Canadian firms are already governed on AI transparency, just not by a Canadian AI statute. Waiting for the federal rule means waiting past obligations that are already enforceable.

    Buying software against a rule that does not exist yet

    For a solo practitioner or a five-lawyer firm choosing systems in 2026, the practical question is not which regime wins. It is which record-keeping decisions are safe under all of them. Read the five ISED focus areas next to Law 25 section 12.1 and the EU's Article 50, and the overlap is narrow and consistent: know when a system acted, know what it acted on, and be able to show a human that record later.

    That is an argument for choosing tools that log by construction rather than tools that add an audit view in a later release. It is the design premise behind SupaCorp, the entity management platform for Canadian solo and small firms, where the corporate record is the product. Incorporations, annual returns, minute books, and registers already carry a legal expectation that every change is attributable and reconstructable, and a firm filing across federal, Ontario, BC, Alberta, and Quebec is already letting the strictest rule set the standard for all of them. Software built that way answers an AI transparency question the same way it answers a corporate records question, because the log is the same log. Software that treats the audit trail as a reporting feature gets retrofitted every time a regulator changes the question, and small firms pay for the retrofit.

    What to watch before September 23

    Watch whether the "What We Heard" report treats agent activity tracking as a records obligation or folds it back into content labelling, because those lead to very different software requirements. Watch whether C-36 clears second reading before the fall session ends. And watch how many Canadian vendors file submissions, because the transparency rules that eventually land will look a lot like whatever the firms who showed up said they could already do.