Canada Artificial Intelligence and Data Act (AIDA)
The Artificial Intelligence and Data Act (AIDA), proposed as Part 3 of Bill C‑27 (Digital Charter Implementation Act), is a pending Canadian federal law that would establish a risk‑based regulatory framework for high‑impact artificial intelligence systems. The Act would impose obligations on providers and operators of high‑impact AI systems, including conducting risk assessments, implementing monitoring and mitigation measures, maintaining detailed documentation, and providing transparency notices to affected individuals. It defines “high‑impact” AI based on criteria such as the system’s scope, level of autonomy, and potential for significant harm. The Act also includes provisions for exemptions, enforcement powers for the Minister of Innovation, Science and Industry, and alignment with existing privacy legislation. As of now, AIDA remains a proposed statute and has not yet been enacted.
Canada Artificial Intelligence and Data Act (AIDA) is a compliance framework from Canada with 10 domains and 20 controls that map to 23 other frameworks. The largest domains are Design and Development Requirements (4 controls), Governance (4 controls), Operations (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (10)
Accountability and Governance
Assurance
| Code | Title |
|---|---|
| AIDA-19 | Audit and Assurance |
Deployment and Operations
| Code | Title |
|---|---|
| AIDA-9 | Robustness and Validation |
Design and Development Requirements
Fairness
| Code | Title |
|---|---|
| AIDA-17 | User Redress |
Governance
High-Impact AI System Classification
| Code | Title |
|---|---|
| AIDA-3 | Harm Assessment |
Operations
Security
| Code | Title |
|---|---|
| AIDA-15 | Security of AI Systems |
Third-Party
| Code | Title |
|---|---|
| AIDA-14 | Third-Party AI Components |
Your Compliance Coverage
If you comply with Canada Artificial Intelligence and Data Act (AIDA), you already cover:
OECD AI Principles
55%
11 controls mapped
Compare →NIST AI Risk Management Framework (AI RMF 1.0)
35%
7 controls mapped
Compare →OECD Recommendation on Artificial Intelligence (2024 Update)
25%
5 controls mapped
Compare →+ 20 more: ISO/IEC 27557:2022 - Organisational Privacy Risk Management (20%), NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (20%)
See all 23 mapped frameworks ↓Maps to 23 other frameworks
What is Canada Artificial Intelligence and Data Act (AIDA) and who does it apply to?
Canada Artificial Intelligence and Data Act (AIDA) is a compliance framework from Canada with 10 domains and 20 controls. The Artificial Intelligence and Data Act (AIDA), proposed as Part 3 of Bill C‑27 (Digital Charter Implementation Act), is a pending Canadian federal law that would establish a risk‑based regulatory framework for high‑impact artificial intelligence systems. The Act would impose obligations on providers and operators of high‑impact AI systems, including conducting risk assessments, implementing monitoring and mitigation measures, maintaining detailed documentation, and providing transparency notices to affected individuals. It defines “high‑impact” AI based on criteria such as the system’s scope, level of autonomy, and potential for significant harm. The Act also includes provisions for exemptions, enforcement powers for the Minister of Innovation, Science and Industry, and alignment with existing privacy legislation. As of now, AIDA remains a proposed statute and has not yet been enacted. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Canada Artificial Intelligence and Data Act (AIDA) actually require?
Canada Artificial Intelligence and Data Act (AIDA) has 20 controls organised across 10 domains. The largest domains are Design and Development Requirements (4 controls), Governance (4 controls), Operations (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Canada Artificial Intelligence and Data Act (AIDA) do I already cover?
Canada Artificial Intelligence and Data Act (AIDA) maps to 23 other compliance frameworks. The top mapping partners are OECD AI Principles (55% coverage), NIST AI Risk Management Framework (AI RMF 1.0) (35% coverage), OECD Recommendation on Artificial Intelligence (2024 Update) (25% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Canada Artificial Intelligence and Data Act (AIDA)?
Start your Canada Artificial Intelligence and Data Act (AIDA) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Canada Artificial Intelligence and Data Act (AIDA) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 20 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required