veille Resource, Regulatory Guide
AMF, Québec

The AMF AI Guideline: what Québec financial institutions must do by May 1, 2027.

The Autorité des marchés financiers is the sole prudential regulator of Québec caisses, insurers, and registered dealers. Its guideline on the use of AI is final and takes effect May 1, 2027. A related incident-reporting regulation is already in force. Federal OSFI compliance does not exempt you from any of it.

StatusFinal guideline, effective May 1, 2027
Penalty regimeUp to $2M/day (Bill 92, FMAT)
RegulatorAutorité des marchés financiers (AMF)
Read this first, our honesty note

Veille's AMF coverage is anchored verbatim to the official AMF texts and is in validation with Québec counsel. This guide is an informational aid, not legal advice. Section references and dates below are drawn from the published AMF instruments; confirm anything you rely on with your own counsel.

Overview

What the AMF governs, and why it is yours.

The Autorité des marchés financiers is Québec's integrated regulator for the financial sector. For institutions chartered under Québec law, it is the sole prudential and market-conduct supervisor: there is no federal OSFI layer above it. Its expectations are set through guidelines and, increasingly, through binding regulation.

On AI specifically, the AMF has published a final Ligne directrice sur l'utilisation de l'intelligence artificielle (Guideline on the Use of Artificial Intelligence). It sets expectations for how you govern, inventory, rate, validate, and disclose the AI systems, called systèmes d'intelligence artificielle or SIA in the text, that you deploy in underwriting, credit, claims, pricing, and client service.

Scope

Who the AMF regulates.

The AMF authorizes and supervises financial institutions doing business in Québec:

  • Financial services cooperatives, the caisses, including the Desjardins network and its Federation
  • Insurers chartered under Québec law
  • Deposit institutions and trust companies incorporated in Québec
  • Registered dealers and advisers, including firms overseen through CIRO, for market conduct

For these institutions, OSFI has no jurisdiction. If you also hold a federal charter, OSFI's E-23 applies in addition, but it never replaces the AMF. A tool that only encodes OSFI leaves your actual supervisor uncovered.

Timeline

One deadline landed, one is coming.

Apr. 23, 2025
In force now: the Regulation respecting the management and reporting of information security incidents (A-8.2, r. 0.1). Binding. Incidents must be reported to the AMF within 24 hours.
Mar. 2026
Final text published: the AMF's Guideline on the Use of AI is issued in final form, dated March 2026.
May 1, 2027
AI guideline takes effect. The guideline states plainly that it applies from May 1, 2027. A draft third-party risk guideline is expected on the same date.

The AI guideline

Five things the guideline expects of you.

LD IA §4.1-4.2 Governance and senior accountability
A member of senior management must be accountable for all of the institution's AI systems, the board must be regularly apprised of AI-related trends, risks, and changes, and senior management must promote a responsible-use culture. The guideline requires, verbatim, that "un membre de la haute direction soit imputable pour l'ensemble des SIA de l'institution." Unowned, unregistered AI is a governance gap on day one.
LD IA §6.1 A centralized inventory of every AI system
The institution must regularly identify all its models and AI systems and record the material ones in a centralized register: "Elle devrait consigner les SIA dont elle juge le risque non négligeable au sein d'un répertoire centralisé, tel le répertoire des modèles." This is the single most immediate requirement, and the one most institutions cannot satisfy today because no one has a complete list. It is exactly what Veille's discovery layer builds.
LD IA §6.2-6.3 A risk rating for each system
Each AI system must be assigned a risk rating built from quantitative and qualitative factors, explicitly including the system's degree of autonomy, and kept current. That rating then modulates how much validation, documentation, and oversight the guideline expects: higher risk, higher intensity. A single autonomous model and a low-stakes internal tool are not held to the same bar, and the guideline expects you to be able to show why.
LD IA §7.1 Validation, and continuous monitoring
Validation of an AI system must cover explainability, cybersecurity, bias and discrimination on prohibited grounds, hallucinations, and intellectual property, and the institution must monitor the system on an ongoing basis. This list goes visibly beyond a traditional model-risk exercise: bias, hallucination, and IP checks are AMF-specific expectations that a federal-only model-risk program does not capture. A model validated once in January and left alone is not compliant.
LD IA §8.3 Transparency to the client
The institution must inform clients when they interact with an AI system and, when a client is the subject of a decision made or recommended by an AI system, explain that decision clearly and simply. This overlaps with Loi 25's automated-decision rule (art. 12.1) but is a distinct AMF duty, sitting under fair treatment of clients and enforced by the AMF, not the CAI. You answer to both.

Already in force

The binding pieces, do not wait for 2027.

A-8.2, r. 0.1, art. 2 & 5 24-hour incident reporting (binding, in force)
Unlike the guideline, this is a regulation, and it has been in force since April 23, 2025. An information-security incident is defined as any attack on the availability, integrity, or confidentiality of information systems or the information they hold. You must have incident-management procedures and must notify the AMF within 24 hours of an incident being reported to your managers. An AI system that fails, leaks, or is manipulated is an incident. This is the AMF obligation most likely to bite first.
ICT guideline (2020) + draft third-party guideline (2025) ICT risk and third-party AI
The AMF's ICT and cybersecurity guideline (in force since 2020) already requires you to understand and manage your technology risk, maintain security hygiene, and hold board-level ICT expertise, the foundation the AI expectations sit on. A draft third-party risk guideline (published October 2025, in-force date expected on the same May 1, 2027) would require a centralized register of all third-party arrangements with criticality and risk assessment, which directly covers your AI vendors and cloud-hosted models. Most of your AI is bought, not built, so this is where much of your exposure lives.

Penalties

The AMF has teeth now.

Guidelines are enforced through the AMF's supervisory powers, remediation, and, ultimately, restrictions. But the penalty regime is no longer abstract: Bill 92 (2025) gives the Financial Markets Administrative Tribunal real monetary authority.

$2M / day
Maximum administrative penalty the Financial Markets Administrative Tribunal (FMAT) may impose under Bill 92, per day, per contravention, on insurers, financial services cooperatives, savings companies, and trust companies. This is a per-day ceiling, not a total cap.
$250 to $2,500
Administrative monetary penalty per contravention type under the information-security incident regulation, the one already in force. Small per line, but it attaches to a binding, dated obligation you can breach today.
To confirm with counsel

Penalty amounts and exactly which contraventions they attach to are drawn from the published instruments and remain to be confirmed with Québec counsel. We flag it rather than overstate it.

AMF vs OSFI

Why a federal-only tool leaves you exposed.

OSFI's Guideline E-23 on model risk and the AMF's AI guideline share a compliance date, May 1, 2027, and both want a model inventory and validation. But they are not interchangeable. E-23 governs federally regulated institutions. If you are a caisse, a Québec insurer, or a Québec trust company, OSFI does not supervise you at all, and the AMF guideline asks for things E-23 does not: explicit bias and hallucination testing, an autonomy-weighted risk rating, and client-facing AI transparency.

The practical rule for a Québec institution: AMF and Loi 25 are your baseline; OSFI E-23 applies on top only if you also hold a federal charter. Veille is built in that order.

How Veille helps

AMF coverage in Veille AI.

Veille's discovery layer builds the centralized AI inventory the guideline requires (§6.1), assigns and tracks a risk rating per system (§6.2-6.3), and drafts the governance, validation, and client-transparency artifacts the guideline expects, in French and English, with a human validating each one before it counts. The 24-hour incident-reporting obligation is wired to the same evidence vault.

Honest scope

The AMF module is anchored verbatim to the official AMF instruments and is in validation with Québec counsel. The AMF guideline takes effect May 1, 2027, so its obligations are marked effective on that date and count toward your compliance score from then. For a caisse, a Québec insurer, or an OCRI dealer, it is the framework that matters most, and it is already in the library. We can introduce you to our legal reviewer partners.

Audit

See your AMF posture in 48 hours.

We'll map your AI systems against the AMF guideline and Loi 25, plus OSFI E-23 if you're federally regulated, and deliver a written gap report in French and English, no commitment required.

Request your free audit