veille
Issue 02, June 2026 AI regulatory watch
Regulatory Bulletin, Veille AI, Montréal

Ottawa legislates on privacy. Not on AI.

June played out in two capitals. In Ottawa, Bill C-36 reopens federal privacy reform and introduces automated-decision duties. In Brussels, the Council closed the deal deferring the AI Act's high-risk obligations. Neither changes what you must do today. Both change what you will have to document.

Canada European Union
From the editor

June produced federal movement for the first time since AIDA died. Bill C-36 was tabled on 15 June 2026 and would replace PIPEDA as the federal private-sector privacy law. It is not an AI act, and that needs saying plainly, because the confusion is already spreading. It is a privacy reform that governs automated decisions, which is not the same thing as an AI governance regime.

None of it is in force. A tabled bill is not an enacted law. The deadline that matters for a Québec financial institution is still 1 May 2027, when the AMF guideline and OSFI E-23 take effect on the same day. Our reading does not change: the useful work today, system inventory and documentation of automated decisions, is exactly what C-36, the AMF and E-23 would each require.

In this issue
Canada, 2 stories
  • Bill C-36, right to explanation and human review
  • AMF and OSFI E-23, no change, 1 May 2027 deadline
European Union, 1 story
  • Digital Omnibus on AI, Council approval, Annex III deferred
High impact C-36, federal, tabled

Bill C-36 is tabled. It creates a right to explanation and human review of automated decisions.

On 15 June 2026 the Government of Canada tabled Bill C-36, which would replace the Personal Information Protection and Electronic Documents Act. The text introduces the concept of an automated decision system, defined broadly enough to cover machine learning, predictive analytics and rules-based systems.

Two duties deserve compliance teams' attention. On request, an organization would have to provide a plain-language explanation of the prediction, recommendation or decision, and state which personal information was used. Where the decision carries a legal or similarly significant effect, the individual could also request human review.

The bill is not enacted. None of these duties is in force, and the real timetable will depend on passage and then on standing up the structures the text provides for. We track its progress and will encode its obligations only once they are enacted.

What this means for your organization

Do not reorganize anything for C-36. Check your article 12.1 instead. The proposed duties largely overlap what Law 25 has required in Québec since September 2023: inform, disclose the information used, offer human review, explain on request. An organization documenting article 12.1 properly today will have little to add if C-36 passes. One that is not will build the same debt twice.

Lower impact, worth watching AMF and OSFI E-23

No change from the financial regulators. Both deadlines stay at 1 May 2027.

Neither the Autorité des marchés financiers nor the Office of the Superintendent of Financial Institutions amended its text in June. The AMF guideline on the use of artificial intelligence, published 7 April 2026, takes effect 1 May 2027. Guideline E-23 on model risk management, published 11 September 2025, takes effect the same day.

We flag it because the absence of news is itself information. Both texts are final and published. There is no consultation left to wait for, no draft left to comment on, and no reason left to defer reading them.

What this means for your organization

The texts are written and the date is fixed. What has to be ready on 1 May 2027 gets decided now, because governance, system inventory, risk rating and validation do not happen in a quarter.

Medium impact EU AI Act, Digital Omnibus

The Council approves the high-risk deferral. The 2 August transparency deadline does not move.

The Council of the European Union gave final approval to the Digital Omnibus on AI on 29 June 2026. The text defers the obligations applying to Annex III high-risk systems from 2 August 2026 to 2 December 2027.

What was not deferred matters more to most Canadian organizations. The Article 50 transparency obligations still apply on 2 August 2026, as do the governance and enforcement provisions. The deferral targets high risk, not transparency.

What this means for your organization

Do not read this deferral as general relief. If you run a system that interacts directly with people, or that generates synthetic content, and EU residents are affected, your deadline is still 2 August 2026. Only Annex III systems gain sixteen months.