Canada’s new artificial intelligence strategy promises to write a fundamental right to privacy into law. In the same document, it commits Canada to 60 per cent of businesses using AI by 2034, projecting $200 billion in growth.
Only one of those promises comes with a target the government can be held to, and the strategy shows why. The protections in it are built to make Canadians feel safe enough to use AI — but feeling safe is different from being protected.
One can see the difference in how each safeguard is put together. Start with the plan’s goal. Its premise, which runs through the strategy, is that the benefits of AI come from using it. The goal is widespread adoption. People will not use a technology they distrust, so trust is needed to achieve it. The document says as much: safety is a requirement for trust and trust enables confident adoption.
Whether the strategy can also keep AI safe is determined by whether it limits what a company is allowed to do, besides telling users what the company does. Its voluntary Trusted AI certificate illustrates this divergence.
The document explains that it intends to help people choose between products in the marketplace. A label like that sets no requirement a company must meet, and it says nothing about the products that don’t carry the label.
The strategy also funds an AI Safety Institute to evaluate models and publish its findings but gives it no authority to stop a system from being deployed. The safety institute promises transparency and watermarking, both of which tell people that AI was involved without providing limits to what AI systems are allowed to do.
The Carney government’s embrace of AI will put lives at risk
AI scribes in health care raise risks for patients and privacy
The strategy also commits to new privacy and online safety laws that could limit what companies can do. The promise of privacy offers more control over personal information and a pledge that it will not be used inappropriately. That includes what the strategy calls surveillance pricing: charging you more once a company works out how much you will pay.
The right to privacy looks like the exception, but instead it exposes the strategy’s approach. The bill that followed, C-36, hands a new regulator power over surveillance pricing. But surveillance pricing runs on inference.
A company predicts what someone similar to you will pay by reading patterns across many other people and sets your price accordingly. Even with every setting locked down and nothing shared, a higher price can still be set because of what a model infers about your traits drawn from data you never shared. A rule built around your personal information misses harms caused by inferences from information about other people.
One should concede that many helpful government plans sell their protection by pointing to economic benefits. But something designed to work on levels of trust and not on trustworthiness will stop working there even if a government means every word of the protections. And the strategy does provide recourse when it chooses to.
It offers tools against deepfakes and accountability for those responsible for online harm, giving a remedy for fabricated content. For the automated decisions it acknowledges will run hiring, lending and health care, it answers with disclosure. Bill C-36, by contrast, makes a company tell you that an automated system decided your loan and lets you ask which data it used. It does not affect what that system may decide about you.
This matters most to the people who will rely on these safeguards. A protection built merely to reassure users has little to offer when reassurance and protection diverge because a safeguard would slow down a harmful but profitable activity. A label or a disclosure on a settings page will not stop online harm because none of them is built to do that.
The instrument that might have set a floor is gone. Canada’s attempt at a binding AI law, the Artificial Intelligence and Data Act, died with prorogation in 2025, and the government has since said it will not return as drafted. The strategy does not propose a binding AI law to take its place. The government has instead tabled privacy and online-safety bills to constrain what companies can do. Each deals with a named harm, from sexualized deepfakes to the misuse of personal data, but none sets a floor for AI. That leaves the certificate and the institute carrying the weight, and neither of them is intended to be binding.
None of this argues against developing and using AI. Canada has every reason to want it used widely and well, and the strategy puts money behind educating people. The problem is that the government was precise about what it will be accountable for and placed that accountability on growth, leaving substantive rights and obligations without a commitment it can be held to. To fix this, the bills that form part of the strategy should limit what companies can do with what they have inferred.
Until that changes, the plan will do what it was built to do. It will make Canadians feel safe enough to adopt AI. Being protected is the other promise, but the strategy does not have a means to keep that one.

