Artificial Intelligence in Canada

Regulatory guidance / voluntary codes in Canada

In September 2023, the Canadian Minister of Innovation, Science and Industry announced a Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems (Voluntary Code) to provide Canadian companies with common standards until formal regulation is in effect, with the aim of enabling them to demonstrate voluntarily that they are developing and using generative AI systems responsibly. The Voluntary Code sets out identified measures to which companies must adhere when nominating themselves as signatories to it relating to the following:

  • Accountability – Firms understand their role with regard to the systems they develop or manage, put in place appropriate risk management systems, and share information with other firms as needed to avoid gaps.
  • Safety – Systems are subject to risk assessments, and mitigations needed to ensure safe operation are put in place prior to deployment.
  • Fairness and Equity – Potential impacts with regard to fairness and equity are assessed and addressed at different phases of development and deployment of the systems.
  • Transparency – Sufficient information is published to allow consumers to make informed decisions and for experts to evaluate whether risks have been adequately addressed.
  • Human Oversight and Monitoring – System use is monitored after deployment, and updates are implemented as needed to address any risks that materialize.
  • Validity and Robustness – Systems operate as intended, are secure against cyber attacks, and their behaviour in response to the range of tasks or situations to which they are likely to be exposed is understood.

The level of obligation in respect of each of the measures to be undertaken varies depending on whether a signatory is either a developer or a manager of a generative AI system and whether or not the system is available for public use or not.

In December 2023, Canadian privacy regulators announced Principles for responsible, trustworthy and privacy-protected generative AI technologies (Privacy Principles) to help organisations that are developing, providing, or using generative AI technologies apply key Canadian privacy principles:

  • Legal Authority and Consent – Organisations should ensure they have legal authority for collecting and using personal information (and when consent is the legal authority, it should be valid and meaningful).
  • Appropriate Purposes – Organisations should only collect, use, and disclose personal information for appropriate purposes.
  • Necessity and Proportionality – Organisations should establish the necessity and proportionality of using generative AI, and of personal information within generative AI, to achieve the intended purposes.
  • Openness – Organisations should be open and transparent about the collection, use, and disclosure of personal information and the potential risks to individuals’ privacy.
  • Accountability – Organisations should establish accountability for compliance with privacy legislation and principles and make AI tools explainable.
  • Individual Access – Organisations should facilitate individuals’ right to access their personal information by developing procedures that enable it to be meaningfully exercised.
  • Limiting Collection, Use, and Disclosure – Organisations should limit the collection, use, and disclosure of personal information to only what is needed to fulfil the explicitly specified, appropriate identified purposes.
  • Accuracy – Organisations should ensure that personal information is as accurate, complete, and up-to-date as is necessary for purposes for which it is to be used.
  • Safeguards – Organisations should establish safeguards to protect personal information and mitigate potential privacy risks.

Continue reading

  • no results

Previous topic
Back to top