The government of Ottawa has proposed regulations on AI chatbots, with fines that would apply quickly to violations once the rules take effect. There are two bills defining what a "chatbot" is under Canadian law. The bills are broad enough for them to cover products that had been invented years ago, long before anyone considered compliance.
It took only five days between the two bills that were filed this June, which is pretty quick for Ottawa's standards. Bill C‑34 defined the terms and set up the enforcement framework, while Bill C‑36 expands on it and is a separate privacy overhaul focusing on data protection. If your product or website responds to customers in any way, even something as simple as a support widget answering billing questions, the new rules would likely affect you.
Marc Miller, Minister of Canadian Identity and Culture and Minister responsible for Official Languages, tabled Bill C-34 on June 10. Officially called the Safe Social Media Act, it would create a new Digital Safety Act covering social platforms and AI systems designed to mimic human relationships.
Five days later, Evan Solomon, Minister of Artificial Intelligence and Digital Innovation, brought forward Bill C-36, the Protecting Privacy and Consumer Data Act. Here's where the numbers get real: standard violations would draw administrative penalties up to $10 million or 3% of global revenue, whichever is greater, and the most serious offenses would climb to $20 million or 5%. A single regulator, the Digital Safety and Data Protection Commission of Canada, would enforce both laws.
Early provisions under the Safe Social Media Act were mainly geared towards platform accountability and content moderation. Customer support systems came into the picture only when the definition was widened enough to accommodate them. Neither bill has passed yet, both remain before Parliament.
Strip away that legal mumbo-jumbo and 4 obligations should stand out as the most important.
Minister Solomon voiced his opinion when the bill was being tabled. The goal is more about giving businesses "clearer rules to innovate responsibly." Something to strive for when trying to regulate any industry.
Handing a new company your card number and your personal details is a small leap of faith, whether that company runs a chatbot or an online casino. Mark Keast, a journalist and casino expert at Casino.org, spends a lot of time watching Canadians make that leap: "Canada has massive volume in terms of online casino sites to wade through and choose from. With anything, go in with a measured approach. Set a budget and stick to it, as you get to know the terrain north of the border."
Swap "casino site" for "AI subscription" and the advice doesn't really change. Consumer-facing AI keeps expanding past customer support, and Formula 1 makes a good example: Ferrari's recent push to build AI-driven fan content taps into a sport with a growing Canadian fanbase and betting partnerships of its own, showing how far personalization and data collection have spread into many industries.
Anthropic took a similar route with its legal-focused Cowork plugin, tucking compliance guardrails directly into a tool meant for a heavily regulated profession. In Canada, Legal Aid Ontario requires roster lawyers to confirm annually, through their Lawyer Self-Report, that they've read and are following the Law Society of Ontario's generative AI guidance. It looks like AI companies in Canada are also catching on, starting to build compliance into their systems from the get-go rather than wait for the regulators.
It's the scope that confuses people, and it would cover all AI that has been built to create a human-type relationship. It would apply to all customer service bots and sales bots, in addition to companion applications, because the legislation classifies according to function and not intention.
Personal data would also include inferred data, according to IAPP's analysis of Bill C-36, where the way in which a system infers an individual's income is equivalent to a name or email address. The recommendation engines that were designed for predictive purposes would be bound by a disclosure rule that was not considered when they were designed. This should be viewed as a win for consumers and privacy.
The majority of chatbots currently in production predate Bill C-36, and while regulators probably won't focus on businesses after enforcement rolls around (the Commission itself won't exist until the bills pass, and the user threshold still isn't set), that grace period isn't going to last forever. It's better to get your ducks in a row now before the pressure of new regulations starts to mount.
Share your thoughts about this article.
Be the first to post a comment!