Enhancing trust in artificial intelligence through increased transparency

Table of Contents

Executive Summary

Artificial intelligence (AI) technologies already power many of the services, products, and processes that Canadians use every day, making it increasingly important to ensure these systems are developed, deployed, and governed in a safe and trustworthy manner.

On June 4, 2026, the Government launched Canada's new AI strategy, AI for All, which identifies protecting Canadians and safeguarding democracy as a central pillar. The strategy highlights that AI will only deliver on its promise if Canadians are confident that AI systems can be safely used. To address some of the most pressing issues, the Government committed to a number of initiatives, many of which are already underway. These include modernizing privacy legislation and creating an online safety regulatory framework, investing in AI safety and reliability infrastructure, and protecting data held by the Government while reinforcing Canada's digital and data sovereignty.

Building on these efforts, the Government announced its intention to advance AI transparency so that Canadians can better understand when and how they are interacting with AI systems and AI-generated content. While increased transparency will not address all AI-related risks, it can serve as a foundation for informed decision-making, accountability, good business practices, as well as help identify where further government intervention may be needed.

To support its work on advancing transparency, the Government is now seeking feedback from Canadians. This document focuses on five areas where the Government could potentially take action on AI transparency:

  • Detecting and identifying AI-generated content;
  • Empowering individuals to know when they are interacting with an AI system;
  • Improving the availability of consistent and understandable information about AI systems, including their development, capabilities, and limitations;
  • Enabling the tracking of serious incidents related to AI systems; and
  • Advancing ways to better track the activity and interactions of AI agents.

For each of these areas, the document outlines the nature of the transparency challenge, reviews current market and jurisdictional initiatives, and invites Canadians to share their views through a series of questions. The views and experiences of all Canadians on these areas will be central in informing the Government's next steps. The Government also welcomes views on any other areas and issues of interest to Canadians related to AI transparency.

Introduction

Artificial intelligence (AI) technologies already power many of the services, products, and processes that Canadians engage with every day. As researchers and companies push the boundaries of AI innovation and discover new uses for it, Canadians will increasingly encounter AI in their daily lives, making questions about how it is developed, deployed, and governed increasingly urgent.

In October 2025, the Government of Canada conducted a public consultation to inform the creation of a renewed national AI strategy. The Government asked Canadians for their thoughts on how to accelerate the safe adoption of AI, scale up AI champions and attract investment, strengthen sovereign digital infrastructure, support new skills, and build public trust in AI systems. The Government received more than 11,300 responses from workers, entrepreneurs, researchers, students, and community leaders across the country, supplemented by 32 reports from a 28-member task force of experts, demonstrating how important these issues are to Canadians.

Informed by this consultation, Canada's new AI strategy, AI for All, was launched on June 4, 2026. It sets out Canada's approach to AI across six pillars: protecting Canadians and safeguarding democracy, empowering Canadians with AI skills, powering AI adoption for shared prosperity, building a sovereign AI foundation, scaling Canadian champions, and building trusted international partnerships. Together, these pillars set out a whole of government strategy that is responsive to Canadians' priorities — from competitiveness and job creation to sovereignty, safety, and inclusion.

Pillar 1 (Protecting Canadians and safeguarding democracy) is a foundational component of the strategy: AI will only deliver on its promise if the AI systems Canadians use are safe and trustworthy, and their governance is grounded in reliable performance, transparency, and clear accountability. A range of actions to further these goals are already underway:

  • To address some of the most pressing AI related issues, the Government is modernizing our regulatory frameworks: The Protecting Privacy and Consumer Data Act, Bill C-36, will provide Canadians with stronger protections with respect to their personal information, while the Safe Social Media Act, Bill C-34, will create a new online safety regime that will introduce obligations for social media services and chatbots to protect children, increase platform accountability, and address the spread of harmful content online. In addition, the Government has advanced targeted measures to combat non-consensual sexualized deepfakes (the recently passed Protecting Victims Act, Bill C-16), and AI-enabled electoral misinformation (the recently passed Strong and Free Elections Act, Bill C-25);
  • To further invest in the infrastructure of AI safety and reliability, the Government is investing $50 million to expand the Canadian AI Safety Institute, developing a Trusted AI Certification program to help Canadians and businesses identify responsible AI systems, and renewing funding for the Standards Council of Canada's AI program; and
  • To protect data held by the Government of Canada and reinforce Canada's digital and data sovereignty, the Government is continuing its review of the Privacy Act and will work with frontier AI companies and international partners to ensure that Canadians and critical systems are protected from cyber and national security threats from advanced AI systems. The Government will also accelerate applied research, testing, and deployment of Canadian technologies for fraud and extortion prevention, cyber defence, threat detection, and data protection.

Building on these other measures, the Government announced its intention to work on AI transparency so that Canadians can better understand when and how they are interacting with AI systems and AI-generated content. Increased transparency can support informed consumer behaviour, foster trust, enable experimentation, research, and innovation, and reinforce fair competitive behaviour amongst companies.

To shape this work, the Government is now soliciting Canadians' reflections on a series of questions: which measures would be most useful and in which contexts, where existing market responses and legal frameworks are already adequate, where genuine gaps remain, and what interventions would be proportionate and effective to strengthen AI transparency in Canada. While the strategy commits the Government to advancing work on AI transparency, it does not predetermine the outcomes. Whether further action is needed and what form any action should take are questions this consultation will inform.

The following section provides context on AI technology, the AI value chain, the risks that have emerged as adoption has advanced, and the existing Canadian policy environment. Following that, the discussion centres on five areas where transparency issues arise, and where the Government could potentially take action:

  • AI-Generated Content: Detecting and identifying AI-generated content;
  • AI Interaction: Empowering individuals to know when they are interacting with an AI system;
  • Information about AI Systems: Improving the availability of consistent and understandable information about AI systems, including their development, capabilities, and limitations;
  • AI Incidents: Enabling the tracking of serious incidents related to AI systems; and
  • AI Agents: Advancing ways to better track the activity and interactions of AI agents.

For each of these five areas, the document describes the nature of the transparency challenge, reviews current market and jurisdictional initiatives, and poses questions to gather input. The experiences and views of all Canadians on these areas will be central to the Government's deliberations moving forward. In addition, the Government also welcomes input on any other issues of interest related to AI transparency.

Context

AI capabilities and adoption

AI is not a new technology. Researchers and businesses have been developing and using AI for decades, using it to solve problems ranging from spam filtering to fraud detection to medical imaging. The advancements of recent years, including the advent of widely accessible, user-facing generative AI systems able to quickly answer any question in natural language (like ChatGPT in 2022), were spurred by three main factors: technical improvements to the algorithms to create AI models (e.g., deep learning, transformers), increased access to large amounts of data, and advances in compute power. Around the same time that user-facing AI chatbots were becoming popular, systems capable of generating photorealistic images, and then video, from text prompts were also growing in popularity and becoming increasingly sophisticated. Since then, research and commercial attention has shifted toward the development of agentic AI systems capable of taking sequences of actions using tool calling and multistep reasoning.

As the technology has advanced, open-source models have proliferated, enabling enterprising individuals, businesses, researchers, and state actors to download, modify, and use the technology for their own purposes. As companies have continued to innovate, the technology has matured from splashy novelty to useful, off-the-shelf business products. Canada's AI adoption rate is growing accordingly. According to Statistics Canada, data from the second quarter of 2026 shows that 19.2% of Canadian companies reported having used AI to produce goods or deliver services over the 12 months preceding the survey, up from 12.2% a year earlier and triple the proportion reported in 2024.Footnote 1 As AI tools are integrated into tools that Canadians already regularly use, such as familiar web browsers and email applications, the number of Canadians who are using AI across professional and personal contexts continues to increase.Footnote 2

Canadians today may encounter AI across a wide range of contexts. Some interactions are direct and highly visible: using a conversational AI assistant, an AI-powered search tool, or a generative AI system to draft a document or create an image. Many others are indirect and may be invisible: for instance, when AI is involved in screening a job application, assessing a credit or insurance claim, or providing customer service.

AI value chain

The development of an AI-powered product typically involves multiple organizations and individuals across the AI value chain, including organizations and individuals involved in data collection and curation, model design and training, AI system build out, and ultimately the businesses and individuals who use those systems in their own operations. This means that a single AI-powered tool may reflect the work and decision making of many different organizations and individuals, all of whom may have limited visibility into how others in the value chain have been operating, and what guardrails have been applied. In this document, developers refers to those who build AI models and systems, deployers refers to the organizations that integrate AI into the products, services, and processes they offer or operate, and users refers to the individuals and organizations that ultimately use them. However, in many cases the same company or organization wears multiple hats, as when AI model developers build out and deliver consumer products based on their models.

'AI' is also used to refer to a wide variety of different products that perform very different functions. When talking about AI, consumer-facing systems like AI chatbots are often top of mind, but not all AI systems are consumer-facing. Many AI systems are business-to-business products designed to do things like automate data pipelines or enable the retrieval of information in response to queries.

These distinctions matter because governance responsibilities do not map neatly onto a single actor, and AI systems built for internal business purposes raise different transparency questions than public-facing chatbots. Because AI systems and deployment contexts vary so widely, any approach to enhancing AI transparency will need to reflect that complexity.

AI risks

The growth in AI adoption brings real opportunities for Canadians but also increases risks. Public polling, as well as results from Canada's AI strategy consultation, show that Canadians are concerned about AI risks, with particular concerns about privacy, job displacement, the proliferation of false information online, and the environmental footprint of AI infrastructure.Footnote 3

Different uses of AI pose different kinds of risks. Generative AI systems made widely available to the public can generate misleading or false content, potentially causing downstream harms. Malicious individuals can use these same systems to commit fraud, carry out scams or cyberattacks, or create non-consensual intimate images. AI systems used to make determinations about individuals can malfunction and result in biased decisions. As AI systems are incorporated into business and educational contexts as well as Canadians' personal lives, they can trigger changes that systemically impact communities; Canadians' concerns about job losses, the impact of AI on human skills and competencies, and the environmental impacts of AI fall into this latter category.Footnote 4 In each case, different interventions may be most appropriate to address the problem that arises.

What is transparency, why does it matter?

In its broadest meaning, transparency refers to the availability of information about AI systems, such as when they are being used, how they work, and their capabilities and limitations. Depending on the context, adequate transparency may require disclosure, reporting, notices, or explanations. Such disclosures, notices, explanations, or reports can be made by a range of actors, such as developers or deployers of AI systems, and the recipient of this information can be other companies in the AI value chain, users, or to government entities such as regulators or policymakers.

Transparency can contribute to risk mitigation in a variety of ways; for a consumer interacting with a customer service chatbot, transparency might mean knowing they are talking to an AI system rather than a human. For a worker whose performance is being assessed by an algorithmic tool, it might mean understanding what factors the system considers and how to contest a decision. For a business procuring an AI product, it might mean access to technical documentation about how the system was built and how to use it. For a regulator or auditor, it might mean access to information about a system's design and outputs, as well as knowing which actors were involved in which decisions relating to the system's performance. For a researcher or civil society organization, it might mean aggregate data about how AI systems are being deployed and what harms are emerging. These are related but distinct transparency needs, and they call for different kinds of notices, disclosures, explanations, and recordkeeping, from different actors to different recipients, at different points in the AI lifecycle.

It is also important to be clear about what transparency can and cannot do. Transparency will not address all risks from AI, but it can be a foundation for informed decision-making, accountability, good business practices, and — where appropriate — further government intervention.

Policy environment

Governments have a range of instruments available to advance AI transparency. This includes enacting legislation to create binding obligations, advancing work on standards to enable interoperable and effective quality assurance ecosystems, supporting research and development, issuing voluntary guidance or codes of conduct to shape expectations and allow for flexibility, and setting out procurement requirements to drive supplier behaviour. In practice, effective governance approaches that promote transparency are likely to draw on several of these instruments in combination, calibrated to the nature of the risk and the context of deployment.

Canada already has a foundation to build on. A number of Canadian laws apply to the development and deployment of AI. These include the Personal Information Protection and Electronic Documents Act (PIPEDA) and the Privacy Act, which set out rules for the collection, use, and disclosure of personal information in commercial and federal government contexts;Footnote 5 the Copyright Act that provides creator and rightsholder protections for certain uses of their content as well as exceptions to those protections; the Canadian Human Rights Act that prohibits discrimination; and the Criminal Code that defines the conduct that constitutes criminal offences.

Sectoral laws, such as the Food and Drugs Act for medical devices and the Motor Vehicle Safety Act for automotives, can also address deployment risks raised by the integration of AI tools in specific contexts. Moreover, some provinces have begun to regulate aspects of AI deployment. For example, Ontario's Working for Workers Four Act requires provincially regulated employers to disclose AI use in hiring processes,Footnote 6 while the Enhancing Digital Security and Trust Act mandates the establishment of AI accountability frameworks in Ontario's public sector, to ensure transparency and responsible AI use.Footnote 7

Beyond legislation, the Government has been promoting safe and responsible AI through other initiatives. The Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems (the Code) provides guidance on AI risks management for AI developers and deployers. The Canadian AI Safety Institute (CAISI) funds and undertakes research to advance the science of AI safety, contributing to the evidence base that transparency and safety policy work depends on. Meanwhile, the Standards Council of Canada has been working to ensure that Canadian interests are represented in international standards-setting bodies, and accredits organizations that certify companies' compliance with AI standards, promoting the adoption of AI standards domestically.

Canada's National AI Strategy: AI for All sets out an ambitious vision to build on these foundations, identifying a number of legislative and non-legislative measures to protect Canadians from AI risks, including by advancing work on AI transparency.

Issues for consideration

AI-Generated Content

Since November 2022, generative AI systems have dominated public discussion about AI. These systems have given Canadians the ability to generate realistic synthetic audio, images, and video at scale, but have also enabled the creation and spread of misleading and harmful content online.

Canadians are encountering AI-generated content across a wide range of contexts. In some situations, the AI origin is visible or expected, but more often, it is not. Canadians encounter news reporting, product reviews, and audio-visual content across the internet, often without any indication of whether it was written by a person, generated by an AI system, or produced through some combination of both.

Creative industries are grappling with related questions, as AI systems trained on existing works can generate music, images, and text in the style of human artists. AI-generated tracks mimicking prominent musicians are now reaching millions of listeners on streaming platforms.Footnote 8 Across these contexts, questions arise about whether Canadians should be able to tell when content is AI-generated, what that would mean in practice, and who should be responsible for making that possible.

A particular concern within this broader landscape is that generative AI greatly enables the creation and dissemination of deceptive or misleading content. The spread of mis- and dis-information is not new, but generative AI has significantly lowered the cost and technical barriers to creating and disseminating it. The impacts on Canadians are serious and can be life-threatening; realistic AI-generated content has already appeared in financial scams targeting Canadians and during events like wildfire emergencies.Footnote 9

Greater transparency about AI-generated content could help Canadians navigate this landscape, but what that means in practice is not straightforward. For instance, there are different views on what transparency should cover: whether the goal is to inform Canadians whenever AI was involved in producing content, or more narrowly to help them identify AI-generated content that misrepresents reality.

Moreover, there is disagreement about how much AI involvement counts as AI-generated. A smartphone photograph may pass through on-device AI processing before it is saved. A journalist may use AI to produce a first draft and then rewrite it substantially. A designer may alter a real photograph using AI-assisted editing tools. A musician may generate an instrumental backing track with AI and layer original vocals over it. In each case, reasonable people may disagree about whether the result should be characterized as AI-generated, and different approaches to these questions lead to very different outcomes.

There are also questions about what form transparency should take. Visible and invisible labels can help users and platforms identify AI-generated content, while public literacy initiatives can help Canadians build the capacity to interpret and act on those signals. Transparency measures can also apply at different points: content can be marked at the moment it is generated, or labelled where it is distributed and encountered, and these interventions serve different objectives. Disclosures can vary in granularity as well, from a simple label to layered information about how AI was used in producing the content. Disclosure requirements may improve informed decision-making, but they can also create new problems, including the risk that ubiquitous labelling leads users to discount the signal entirely, or to assume that unlabelled content is authentic by default.

Case study: AI-generated deepfakes are costing Canadians

According to the Canadian Anti-Fraud Centre, scammers are increasingly using generative AI tools to facilitate their activities.Footnote 10 This includes creating deepfakes of prominent individuals to promote fraudulent investments. For example, in 2023, an Ottawa couple lost a significant sum after acting on the advice of a deepfake video of a notable individual promoting a fraudulent investment opportunity.Footnote 11 AI-enabled fraud also poses significant risks to Canadian businesses. A recent KPMG survey of large Canadian businesses found that nearly three-quarters of respondents lost between one and five percent of their annual profits to AI-powered fraud over the preceding year.Footnote 12 These organizations reported that two of the most common attacks they encountered included deepfake documents and voice impersonation calls of company executives.

Market responses

Recognizing the challenges with unlabelled synthetic content, many developers of generative AI systems and digital platforms have worked to devise technical means of labelling AI-generated content, with approaches broadly falling into ways to invisibly mark synthetic content and disclose when it is being hosted.

Many generative AI developers now mark AI-generated content with hidden watermarks and include provenance information in metadata. Hidden watermarks consist of subtle signals inserted in the content itself, such as slight alteration of pixels in an image, that allow the content to be identified as AI-generated with detection tools. For example, Google's SynthID enables the embedding of hidden watermarks into AI-generated images, audio, text, or video.Footnote 13 Metadata, by contrast, does not alter the digital file itself, but stores provenance information, such as details about the content's origin, modifications made to it, and whether AI was involved in creating or editing it, in a separate channel within the digital file. The Coalition for Content Provenance and Authenticity (C2PA), comprising major actors in the digital sector, has developed a technical specification enabling the secure attachment of metadata to digital content.Footnote 14 The maturity of these techniques varies by modality. Approaches for marking audio, images, and video are comparatively well developed, while watermarks applied to text remain brittle and easy to remove, and many experts consider them insufficiently mature for reliable use.

Some online platforms, including YouTube and Meta, have adopted policies regarding disclosures on synthetic content.Footnote 15 Companies typically ask users to disclose if their content is AI-generated, which triggers a disclosure attached to the content.Footnote 16 Meta also labels content that its systems detect as being produced with the help of AI. Meta's own experience illustrates one challenge with platform-level disclosures: early implementations flagged content as AI-generated when content was modified in minor ways, such as with retouching tools, prompting criticism that the label was too broad to be meaningful and leading to adjustments in how the policy was applied.Footnote 17 Meta's content labelling is now accompanied by user-facing educational components intended to help people interpret what they encounter.Footnote 18

Beyond technical and platform-based approaches, increased AI literacy can help Canadians to identify AI-generated and misleading content. A range of Canadian actors, including the national AI institutes, the Department of Canadian Heritage's Digital Citizen Initiative, and the Canadian Institute for Advanced Research (CIFAR) have invested in public literacy as a complementary tool.Footnote 19

The adoption and effectiveness of these approaches varies considerably. As well, significant technical and implementation challenges remain, as technical approaches to marking and identification struggle to keep pace with rapid technological advances.Footnote 20 Marking and provenance tools are also most effective when those creating content cooperate. Determined bad actors can strip or evade these signals, which suggests that identifying deliberately deceptive content may require different approaches than supporting good-faith disclosure. Provenance infrastructure can also raise concerns of its own: some have cautioned that systems designed to track the origin of content could be used to identify who created or published it, raising privacy and freedom of expression considerations.

Additionally, debate continues about where in the AI value chain transparency obligations should sit. Recent experience in the European Union (EU) Code of Practice development process, for instance, saw marking and labelling requirements removed or streamlined from an early draft following concerns about the compliance burden, illustrating that governance questions are as unsettled as technical ones.Footnote 21

Regulatory environment

Canada does not currently require developers or deployers of generative AI systems to disclose AI-generated content. However, if enacted as proposed, Part 1 of the Safe Social Media Act, the Digital Safety Act, would require operators of regulated social media companies to implement adequate measures to label synthetic content that is likely to be mistaken for an authentic visual or audio recording of a person, object, place, entity, or event on their platforms. This obligation only applies to operators of regulated social media services where synthetic content is shared, and does not create obligations on developers and deployers of AI systems used to generate this content.Footnote 22

Moreover, Canada has signalled its expectations for transparency to developers and deployers of AI systems. The Government's Code, launched in 2023, outlines best practices for developers and deployers to mitigate risks associated with generative AI, including a recommendation that developers establish and implement a reliable and freely available method to detect content generated by the system.Footnote 23

A number of jurisdictions around the world including California,Footnote 24 the EU,Footnote 25 South Korea,Footnote 26 and ChinaFootnote 27 now require AI companies to support the identification and detection of AI-generated or manipulated content.Footnote 28 Most of these regimes are recent, and evidence on whether they have meaningfully improved the public's ability to identify AI-generated content remains limited.

Discussion

The Government is considering a range of possible approaches to improve transparency about AI-generated content and is interested in receiving stakeholder feedback on the following questions:

  • Would it help you trust what you see online if you could tell whether something was created by AI or by a person? When and for what kinds of content (e.g., image, video, audio) is it most important to know if something was created or modified by AI?
  • What would best help Canadians determine when content is AI-generated (e.g., invisible or visible watermarks, disclaimers, provenance metadata)?
  • Who in the AI value chain (developers, deployers, or others) should be responsible for providing transparency around AI-generated content? Why?
  • Do existing market practices, technical tools, and legal frameworks make it easy enough to know when content is AI-generated? If not, where do gaps remain and what actions (e.g., regulatory measures, guidance and codes of conduct, standards and technical solutions, research and development, literacy initiatives, procurement requirements) do you think the Government should take?

AI Interaction

Canadians are increasingly interacting with AI systems across a range of settings. Businesses are deploying customer service chatbots and voice assistants to help their customers get the information they need faster and in a more personalized way. Individuals are using companion chatbots to alleviate loneliness and build social skills in a low-pressure environment. AI can also be used to augment human-to-human interactions, such as live translation features or other auditory enhancements over phone calls. Across these contexts, the extent to which users are able to reliably identify they are interacting with AI can vary considerably. An individual using a chatbot to generate audiovisual content would almost certainly know that they are interacting with an AI system, whereas a consumer engaging with a customer service chatbot that is not identified as such may be unaware that they are interacting with a machine, rather than a human.

The specific ways in which Canadians encounter AI can vary, and different types of AI interactions raise different transparency considerations. Often, the interaction is communicative: an AI system engages a person directly through conversation or voice, and the question is whether the person knows their counterpart is a machine. In other cases, AI is used in processes that affect a person who may never interact with the system at all, for instance when AI is used to assess a job application or process a claim, which raises questions as to whether people should be informed that AI played a role in a decision or process concerning them. In still other cases, AI shapes what people see and experience online, as with algorithms recommending content, and whether this constitutes an interaction at all is itself debated.

Across these use cases, transparency around AI interactions may enable Canadians to make more informed choices around when and how they are engaging with AI and prevent situations where they could be misled. For instance, knowing when one is engaging with a chatbot and not a human customer service representative can help a customer contextualize the information that they are receiving and better understand how to engage in that interaction. Knowing that what one sees online is mediated by a recommendation algorithm can also inform consumer behaviour.

However, there are different views on when transparency around AI interactions is necessary or desirable. Knowing when one is interacting with an AI system is important in some contexts, but may be less important in others. For instance, AI systems are often used as part of back-end business processes which have minimal impacts on users and their rights. There is a risk that excessive disclosure can create unnecessary compliance burdens on businesses while offering users limited benefits. It could also contribute to "banner blindness" or "disclosure fatigue", where individuals become desensitized to the measures in place to inform them.

There are also a variety of views on what should constitute adequate transparency around AI interactions. Meaningful disclosure may require more than a simple blanket statement, as Canadians made aware that they are engaging with an AI system may not be adequately informed if they do not know how that interaction affects them. In some cases, meaningful disclosure might need to include details about the system's role, what it is designed to do, whether and how the system engages or uses one's personal information, and what human oversight mechanisms are in place. Questions about disclosing a system's broader capabilities and limitations are discussed below. Views differ as well on how any disclosure expectations should be scoped. Some emphasize the risk of deception, focusing on systems that could be mistaken for humans. Others would prioritize the stakes of the interaction, focusing on contexts where AI is involved in consequential exchanges or decisions, such as financial, health, or employment matters. Still others favour sector-specific approaches.

Transparency in AI interactions can involve different actors in the value chain, including chatbot developers whose design choices influence the way they respond to human prompts and deployers who may have similar control over how an application responds to users. The form that interaction disclosures take can also vary, ranging from text or audio outputs upon initiation of an interaction, to videos explaining the use of an AI system, to consent forms provided to users or impacted individuals when an AI system will be used to evaluate them.

Case study: When AI chatbots give wrong information, who is responsible?

In May 2026, a Toronto man decided to sell his car, which required major repairs, back to the dealership where he had purchased the car and where the repairs were being done.Footnote 29 After submitting an online inquiry, the dealership initiated a text conversation with him under the name "Quinn", who offered to buy back the car for $27,162.79. Quinn also told the man that the dealership would consider his counteroffer of $28,500, and even set up a meeting time to complete the transaction. The man then received a call from a sales consultant at the dealership, who revoked the offer and explained that Quinn was in fact an AI chatbot that made the offer in error. At no point in the man's interaction with Quinn did it indicate that it was not a real human. The sales consultant informed the man that the dealership would, at most, buy back the car for $20,000.

Ultimately, the dealership honoured the original offer after the man brought his story to the media. However, this case illustrates that users interacting with AI-enabled customer service may have limited ways to assess whether the information they receive is current, complete, or consistent with the organization's actual policies — or whether the organization will stand behind it.

Market responses

Deployers are taking a range of approaches to AI interaction disclosures, which can vary depending on sector and interface. For some, it may be appealing to do so because they believe that the perception of deploying AI can be a competitive advantage. In other cases however, deployment that could prompt negative public scrutiny could disincentivize deployers from clearly notifying users, such as in contexts where a higher degree of privacy is expected. Deployers of AI chatbots or voice assistants typically provide some indication to the user that they are communicating with an AI system, whether through an explicit disclosure upon the initiation of the interaction or implicitly based on the name of the system. Some businesses that use AI in the background, such as to process personal information, may also indicate so, at times to comply with regulatory requirements.

However, these disclosures can be inconsistent or unclear. For example, some organizations clearly describe their systems as AI-powered whereas others may only do so using softer terms without explicit reference to AI, such as "virtual assistants" or "built-in intelligence", providing users with limited information about whether they are interacting with AI or what the system is authorized to do. The level of detail included and whether disclosures are meaningful can also vary significantly.

Regulatory environment

In Canada, some provinces have begun requiring deployers of AI systems to notify users in certain contexts. Ontario's Working for Workers Four Act, for example, amended the Employment Standards Act to require provincially regulated employers to disclose the use of AI to screen, assess, or select applicants in hiring processes.Footnote 30

To address some of the issues identified here, the Government introduced Bill C-34, the Safe Social Media Act, which proposes new rules to mitigate the risk that chatbots engage in harmful behaviour, such as by deceptively posing as a human, or as a medical, legal, or other licensed professional, actively encouraging emotional dependency with the chatbot, or promoting self-harm, violence, or suicide.Footnote 31 The Government also introduced Bill C-36, the Protecting Privacy and Consumer Data Act, which will provide Canadians with stronger protections over their personal information, including requirements for greater transparency in how automated decision systems, such as AI systems, use personal information to make significant decisions.Footnote 32

Finally, signatories to the Code also commit to ensuring that AI systems that they manage and that could be mistaken for humans are clearly and prominently identified as AI systems, including through taking concrete steps to ensure that users are aware that they are communicating with an AI system.

Several jurisdictions, including the EU, a number of U.S. states, and South Korea,Footnote 33 have put in place requirements to ensure that end-users know when they are interacting with an AI system. These frameworks differ in their scope, compliance obligations, and which parts of the value chain are responsible for compliance. For example, the EU AI Act requires providers of AI systems to ensure that all AI systems intended to interact directly with users are designed and developed in such a way that users are informed that they are interacting with an AI system, unless it is obvious considering the circumstances and context of use.Footnote 34 Legislation in California and New York require operators of companion chatbots to notify users that they are communicating with an AI system,Footnote 35 while Colorado and Maine require developers or deployers of AI systems that interact with consumers to disclose that the user is interacting with an AI system and not a human.Footnote 36 Utah's legislation sets out disclosure rules for suppliers of mental health chatbots, as well as disclosure rules for suppliers using chatbots to interact with consumers.Footnote 37 The exact means by which system providers and operators are expected to comply in these jurisdictions are often specified in regulations and guidelines.Footnote 38 As these obligations are relatively recent, their practical impacts on the marketplace remain to be seen.

Discussion

The Government is considering a range of possible approaches to improve transparency about AI interaction and is interested in receiving stakeholder feedback on the following questions:

  • When and why is it most important to know that you are interacting with an AI system? Are there contexts where you don't need to know that you're interacting with AI?
  • What factors make a disclosure of AI use meaningful and effective for the user?
  • Who in the AI value chain (developers, deployers, or others) should be responsible for providing transparency around AI interactions? Why?
  • Are existing market practices and legal frameworks sufficient to support transparency around AI interactions? If not, where do gaps remain and what actions (e.g., regulatory measures, guidance and codes of conduct, standards and technical solutions, research and development, literacy initiatives, procurement requirements) do you think the Government should take?

Information about AI Systems

In order to use AI systems safely and effectively, Canadians need to have sufficient information about what AI-powered products are designed to do and how to use them responsibly. As business adoption increases, it is also important that businesses have enough information to inform their decision-making about using AI in their business processes. In this context, transparency around AI systems engages two broad considerations: information about what an AI system can and cannot do (its capabilities, limitations, and appropriate uses) and information about how it was designed, including the data on which it was trained. Both shape whether users, deploying organizations, and others affected by AI systems can rely on them appropriately.

A foundational question for users is understanding what an AI system is designed to do and whether it is appropriate for the task at hand. AI systems can vary significantly in terms of intended purpose, deployment context, and risk profile, even when they appear similar from a user perspective. While some AI systems are designed for broad consumer use, such as drafting text, summarizing information, generating code, or assisting with search, others are developed for specialized domains such as medicine, finance, or legal services, where outputs may be integrated into professional workflows. Understanding what the system is designed to be used for can help users determine whether they want to use it at all, whether it is suitable for a particular decision or task, and whether additional verification or human review may be necessary.

Users may also need information about the capabilities and limitations of the AI systems they use. This includes understanding what systems are generally good at, where they may perform poorly, and under what circumstances outputs may become unreliable or inaccurate. For example, large general-purpose AI models are often trained on broad datasets collected from across the internet. These systems are designed to perform a wide range of tasks ranging from creating summaries and drafting, to coding and search assistance. However, many such systems rely on information available only up to a specific training cut-off date (unless connected to external retrieval tools). Users may not understand that a model's knowledge may be incomplete or outdated, nor recognize when responses are generated based on probabilities found in the dataset rather than retrieved from verified sources. By contrast, specialized AI systems designed to provide information in narrower domains such as medicine, finance, or legal services may rely on curated datasets, domain-specific retrieval tools, structured workflows, and additional safeguards tailored to the context in which they are deployed. These differences can significantly influence the reliability and safety of generated outputs, including by reducing hallucinations or constraining outputs to authoritative information sources. As a result, two AI tools using similar underlying models can produce very different outputs and risk profiles depending on how they are designed and deployed.

A distinct set of transparency questions concerns not what an AI system does, but how it was created. Information about the data used to train and develop a model matters to a range of actors and for a range of reasons. Individuals may wish to know whether their personal information was used to train a system; researchers and auditors may need information about training data to assess a system for bias or other risks; and downstream deployers may need it to evaluate whether a model is appropriate for their context. The treatment of training data also has implications for the security and integrity of AI systems.

Transparency around model training is especially relevant with respect to questions regarding the use of copyright-protected material. As developers and deployers of AI models and AI-powered applications continue to collect and consume data for model training, creators and other rightsholders seek to know whether and when that data includes content protected by the Copyright Act in order to inform copyright licensing and potential enforcement efforts. Providing transparency at this scale, however, raises practical questions about what level of detail is feasible to disclose, how training datasets can be meaningfully documented, and how to balance the need to overcome information asymmetries where rights and uses are concerned with the protection of commercially sensitive information, such as proprietary algorithms.

Depending on their position, different audiences may also require different types of information to inform their business operations or uses of AI. For example, to use AI safely and responsibly, organizations integrating third-party AI models into their own applications may require more detailed technical information about training limitations, known failure modes, and security vulnerabilities than the general public does.

Case study: AI-generated output creating factually incorrect legal documents

The risks associated with not understanding AI system limitations are increasingly visible in practice.

A review of decisions published on the Canadian legal database (CanLII) between January 2024 and March 2026 identified 132 Canadian decisions issued by 44 different courts and tribunals in which at least one party cited a fictitious case as legal authority. The court or tribunal found or inferred that the fictitious cases had been generated using AI in 96 of those 132 decisions.Footnote 39

This illustrates how AI systems can produce highly persuasive and authoritative-sounding outputs that are factually incorrect, especially when systems are deployed outside of their intended context or where their limitations and risks are poorly understood.

Market responses

Many leading AI developers have voluntarily published documentation about their systems in the form of model or system cards.Footnote 40 Model cards typically describe a model's capabilities, limitations, and appropriate uses, helping prospective users determine whether it is suited to a task, while system cards describe how a deployed system behaves in practice, including the safeguards built around it. As a voluntary commitment and to comply with legislative requirements in other jurisdictions, developers may also publish safety frameworks outlining their approaches to identifying, assessing, and managing risks.Footnote 41 Transparency about training data specifically remains far less developed. While some developers publish high-level descriptions of the types of data used to train their models, detailed disclosure of training datasets is rare, and there is no widely adopted standard for documenting data provenance at the input stage.

AI developers have incentives to publicly communicate information about their systems to establish credibility, build user trust, attract investments, and differentiate their products in an increasingly competitive market. Demand for this information also comes from within the value chain itself: organizations deploying third-party AI systems increasingly seek detailed documentation from developers in order to assess and manage risks, making transparency a factor in business adoption decisions. However, developers may be reluctant to disclose information about their systems that could reveal proprietary methods, sensitive technical details, expose commercially sensitive information, or create security concerns. Developers may thus make choices about how information is framed and what level of technical detail is appropriate. As a result, an open question remains whether existing disclosures provide the information that users, researchers, policymakers, and other stakeholders actually need.

As a result, these transparency practices remain inconsistent across the industry. The type, quality, and accessibility of information disclosed varies between organizations, and there is currently no common standard governing what information should be disclosed when, to whom, and in what format. Some observers have suggested that standardized templates could make documentation easier to produce systematically and easier for readers to digest and compare, while others caution that overly prescriptive formats may not suit the diversity of AI systems. Because of this, system information can be difficult to compare across developers and may not always be independently validated with much of the information remaining self-reported with limited external auditing or verification mechanisms. In addition, the growing volume and technical complexity of model cards can make them difficult for the public to assess.

Regulatory environment

In Canada, there are initiatives encouraging AI developers or deployers to publicly disclose information about their systems or risk management frameworks. The Code calls on AI developers to publish information on capabilities and limitations of the system.Footnote 42 The accompanying guide for managers of AI systems encourages managers to provide information to users about the nature and capabilities of AI systems, including information on how they are developed, operated, and maintained.Footnote 43

Several jurisdictions have introduced or proposed measures requiring AI developers to disclose information about the capabilities and limitations of their systems and safety practices, including the EU, California, and South Korea.Footnote 44 For example, the EU AI Act requires that downstream integrators of general-purpose AI models and deployers of high-risk AI systems have access to information about the capabilities and limitations of the models and systems they use.Footnote 45 Similarly, California requires frontier developers to publish "transparency reports" that include basic information about their models, including the types of output they can produce, intended uses, and general restrictions and conditions on use.Footnote 46 Large frontier developers must additionally publish a "frontier AI framework" outlining their risk assessment and management policies, including mitigation measures, the identification and response to critical safety incidents, maintenance of cybersecurity, and internal governance practices to ensure compliance with the framework.Footnote 47

Some jurisdictions have also begun to address input transparency directly. The EU AI Act, for example, requires providers of general-purpose AI models to publish a sufficiently detailed summary of the content used to train the model, according to a template provided by the European AI Office.

Discussion

The Government is considering a range of possible approaches to improving transparency regarding AI system capabilities, limitations, and governance practices and is interested in receiving stakeholder feedback on the following questions:

  • What kinds of information about AI would you like to know in order to help you make informed choices about when and how to use AI? When and for which types of AI products is this information most important to you?
  • What kind of information about AI do businesses need to adopt AI safely and responsibly? Do businesses currently have access to the information that they need? How can the Government best balance the need to increase transparency (including input transparency) against the need to protect confidential business information?
  • Who in the AI value chain (developers, deployers, or others) is best placed to provide what information about AI systems, how they are created, and their capabilities and limitations?
  • Are existing disclosure practices and legal frameworks sufficient to provide the information that users and other stakeholders need? If not, where do gaps remain and what actions (e.g., regulatory measures, guidance and codes of conduct, standards and technical solutions, research and development, literacy initiatives, procurement requirements) do you think the Government should take?

AI Incidents

As AI systems become more advanced and more widely deployed, AI-related incidents are increasing, with impact across individuals, organizations, and society.Footnote 48 AI systems can cause harm when they fail or when they behave in unexpected ways. For example, facial recognition systems can produce inaccurate matches, particularly for certain demographic groups.Footnote 49. AI systems can also be deliberately exploited, for instance when malicious actors use prompt injection attacks that can manipulate AI systems into taking unauthorized actions.Footnote 50 While these risks can be mitigated, they cannot be fully eliminated and can lead to serious consequences, particularly in high-impact environments. As AI is increasingly integrated into products, services, and processes, a better and more timely understanding of AI incidents along with their causes and trends becomes increasingly important, so that companies, individuals, and governments can foresee and mitigate risks rather than address them only after they arise. This raises the question of how best to facilitate the reporting and sharing of timely and appropriate AI safety incident information amongst companies, researchers, policymakers, and the global community, and to inform authorities when appropriate.

Determining how best to achieve visibility on AI incidents raises real challenges. One concerns the cross-sectoral nature of the technology: when AI is used in sectors like health, transport, or consumer products, pre-existing mandatory reporting regimes already exist, with regulators that enforce the rules to ensure compliance. Another concerns the reporting threshold. Any new framework for reporting AI incidents would have to clearly identify what kinds of incidents constitute "AI incidents", and what threshold signifies an incident is serious enough to merit disclosure. These decisions would be necessary to avoid over-reporting of incidents and unreasonable burden on companies. Another key consideration concerns global interoperability; Canada will need to consider how to balance its needs with emerging international best practices related to mandatory reporting for AI incidents. A final concern relates to the need for balancing transparency with the protection of the confidentiality of sensitive business information.

A central reason for these challenges relates to the relationship between disclosure and liability. Reporting an incident can create a record that exposes a company to legal liability, regulatory action, or reputational harm, giving firms a strong incentive to stay silent — precisely the opposite of what effective risk mitigation requires. Other safety-critical sectors adopted models that reconcile disclosure with these concerns. In aviation, for example, a long-standing safety reporting regime is built on voluntary, confidential reporting that shields participants from most liability; in exchange, the industry gains a shared body of data that has shifted its approach from reactive to proactive and improved safety overall.Footnote 51 The resulting data is useful for researchers, policymakers, and companies themselves to improve their products.

A range of mechanisms could be considered to improve visibility on AI incidents, and no single approach is likely to fit every case. Mandatory reporting requirements (either public disclosure or confidential disclosure to a government entity) could build on or complement existing sectoral regimes. Voluntary, no-fault arrangements could help encourage participation where firms might otherwise stay silent. Mechanisms could also be considered to ensure that the lessons drawn from reported incidents are shared back out to other operators, helping the whole industry strengthen its systems. These approaches are not mutually exclusive, and the most effective response may combine elements of each.

A final question is who is best placed to report. Developers, deployers, and operators may each have visibility into different incidents, and the same organization may occupy more than one of these roles at once — a firm that deploys its own model is both developer and deployer. Incidents are often most visible to those operating a system in practice, while developers may be better positioned to identify the underlying cause and address it across all deployments of their systems.

Case study: Prompt injection attacks

Prompt injection attacks can fool AI systems into undertaking unauthorized actions, leading to serious consequences, such as sensitive data breaches and financial fraud.Footnote 52 In January 2025, security researchers identified a zero-click prompt injection vulnerability in Microsoft 365 Copilot, which is deployed across many Canadian organizations. The vulnerability would have allowed an email from an attacker to cause Copilot to access internal documents and transmit them to the attacker. Following coordinated disclosure practices common in cybersecurity, the vulnerability was reported to the developer, remediated, and only then publicly disclosed in June 2025. The case illustrates the questions that AI incident reporting raises: when, to whom, and in what level of detail should issues of this kind be disclosed, and how should any reporting expectations interact with established security practices designed to avoid alerting attackers before a fix is in place.Footnote 53

Market responses

At present, there is limited visibility into serious AI incidents and how AI companies respond, which limits the ability of governments, researchers, and the public to understand how often incidents occur and how they are addressed. While AI companies may document risk and safety processes internally, they are making highly impactful decisions with limited public visibility.Footnote 54 Moreover, these reports may be inconsistent in their scope, frequency, and level of detail.

AI incident trackers, such as the AI Incident Database and the OECD AI Incidents and Hazards Monitor, can help reduce this visibility gap.Footnote 55 They usually define AI incidents in broad terms, thus capturing harms arising both directly or indirectly from AI systems.Footnote 56 However, these trackers differ in methodology and in the scope of AI incidents they include in their databases, each presenting distinct strengths and weaknesses. For instance, the OECD AI Incidents and Hazards Monitor uses large language models (LLMs) to classify AI-related events and news articles, generate relevant metadata, and identify and aggregate duplicate events.Footnote 57 By contrast, the AI Incident Database relies on individuals submitting incidents following standardized guidelines, which must be subsequently approved for inclusion in the database by an editor.Footnote 58 While information contained in the database would thus be of higher quality, it is more limited in scope than those that employ automated pipelines. Notwithstanding differences in methodology, an important shared limitation is that these tools all rely on publicly reported events either officially by AI companies or through self-reporting by users.

Regulatory environment

There are a few initiatives in Canada aimed at mitigating serious incidents involving AI systems. The Code recommends that AI developers maintain a database of reported incidents after deployment, and provide updates as needed to ensure effective mitigation measures, but the Code is voluntary and not enforceable.Footnote 59

Many sectors already have in place mandatory reporting schemes that, while not designed to address AI risks, could be leveraged to disclose AI-related incidents in these sectors. For instance, there are reporting schemes for health or safety incidents involving consumer productsFootnote 60 and medical devices,Footnote 61 as well as for accidents and incidents involving aircrafts, ships, pipelines, and trains.Footnote 62 The Government has also put in place mandatory rules to disclose serious cybersecurity incidents (Bill C-8, which includes the Critical Cyber Systems Protection Act). This framework would impose obligations on designated operators of critical cyber systems supporting vital services such as telecommunications, banking, and energy. Among these obligations, operators of critical cyber systems would be required to report cyber security incidents to regulatory authorities, including those due to AI.Footnote 63

Some jurisdictions, such as the EU and California, have adopted specific measures requiring the reporting of serious AI incidents to regulatory authorities to address visibility gaps. In the EU, providers of high-risk systems must report any serious incidentFootnote 64 to the relevant market surveillance authority.Footnote 65 Deployers of high-risk systems are required to report to the relevant market surveillance authority after informing the provider of the system.Footnote 66 Providers of general-purpose models with systemic risk must report relevant information about serious incidents and possible corrective measures to the European AI Office.Footnote 67 For its part, California requires frontier developers to report any critical safety incidentsFootnote 68 to the Office of Emergency Services.Footnote 69 Large frontier developers must also include in their transparency reports summaries of their assessments of catastrophic risks pursuant to their frontier AI framework, the results of those assessments, and the extent of third-party evaluator involvement.Footnote 70

Discussion

The Government is considering a range of possible approaches to improving transparency of AI incidents and is interested in receiving stakeholder feedback on the following questions:

  • Do the public and the Government have enough information about AI risks, incidents, and potential future harms? What types of information related to AI use and risk trends would be most useful so that Canadians and the Government can proactively address AI-related risks and harms?
  • How should a serious AI incident be defined, and what information would be most useful to better understand the causes and consequences, as well as the mitigation of these incidents? How could reporting requirements be structured to encourage proactive disclosure and also address concerns around confidentiality and liability?
  • Which individuals or actors (e.g., developers, deployers) are best placed to provide the most relevant information? Who (e.g., regulatory bodies, nonprofits, others) should collect this information and what should be done with it?
  • Are existing incident reporting frameworks in Canada (e.g., for consumer products, medical devices, transportation) sufficient to address serious incidents involving AI? If not, where do gaps remain and what actions (e.g., regulatory measures, guidance and codes of conduct, standards and technical solutions, research and development, literacy initiatives, procurement requirements) do you think the Government should take? Are there emerging international best practices that Canada could adapt or interoperate with?

AI Agents

As AI research and development progress, companies are now turning to the development of AI systems that can autonomously take action on behalf of users. Across a variety of contexts, Canadians may now encounter AI agents that they can direct to do their shopping, send their emails, or book their meetings.

Agentic capabilities have already been integrated into many of the consumer-facing chatbot systems that Canadians have become familiar with, transforming AI chatbots from advisor to assistant. For example, OpenAI's Operator, integrated into ChatGPT, can browse the web, fill forms, and complete booking-style workflows, allowing users to offload simple or repetitive tasks, like ordering groceries, to the agent.Footnote 71 Google's "Help me schedule" feature, available in Gemini, can read email and calendar context, propose meeting times, and create calendar invites.Footnote 72

Many of the same developers have also started to integrate agent-driven e-commerce functionality into their systems. For example, in September 2025, OpenAI integrated "instant checkout" into ChatGPT, enabling users to purchase items from e-commerce sites directly in chat.Footnote 73 Integrated with PayPal, Perplexity's chatbot application now enables users to do the same.Footnote 74 Similarly, Amazon's Alexa for shopping feature can add items to carts and complete purchases on behalf of users.Footnote 75

Beyond end-user-oriented applications, companies have also begun to find uses for AI agents. Agentic AI systems can automate costly and time consuming business activities, like coding and database creation and maintenance. Customer service agents can respond to user queries and take actions such as refunds, returns, and cancellations.Footnote 76

This boom in the sophistication and utility of AI agents and agentic AI in organizational contexts is due largely to the development of open standards such as the Model Context Protocol and the Agent2Agent protocol. These standards have simplified how developers connect individual agent systems to the data and tools that they need to act autonomously, and have promoted interoperability between multiple agents.Footnote 77

While AI agents offer convenience and productivity benefits, they also raise transparency and accountability questions because users may not always know what permissions have been granted to the agent, when an AI system is acting on their behalf, whether a human remains in control, or how to challenge or reverse an action that an agent has taken. Like other AI systems, agents can malfunction in a variety of ways — for example, by misusing tools they have been granted access to, by not following or going beyond directions they have been given, by hallucinating, or by misunderstanding user prompts — and when issues arise, users and organizations may find themselves without any understanding of what went wrong or what to do about it.

Following the release of open-source AI agents platforms like OpenClaw, AI agents are becoming increasingly accessible. Now, almost anyone with an internet connection can download and personalize an AI agent for their own purposes.Footnote 78 Individual users are already granting AI agents access to sensitive systems and personal information. Given the current technical limitations of agents, giving them access to sensitive information or permission to take actions, such as purchases, can lead to real consequences.

Case study: Agentic commerce

AI agents empowered to buy goods on behalf of users can make Canadians' lives easier, for example by automatically purchasing weekly groceries or household refills from an e-commerce site — but they can also malfunction, with potentially serious financial consequences.

Consider a consumer who instructs an AI agent to automatically repurchase a household item once a month, without confirming each transaction. In doing so, the consumer has given the agent access to their credit card, their shopping account, and potentially other personal information.

Misinterpreting the instruction, the agent orders twelve packages instead of a single package of twelve.

The agent has spent far more of the consumer's money than intended. Responsibility for the malfunction is not straightforward to assign between the consumer, the business operating the agent, and the original developer of the agent, and the consumer's avenues for redress may be unclear.

Questions of this kind are more pressing as agentic commerce becomes more common.

Beyond the challenges that they pose to users who may not realise what permissions or data they are handing over to their agent, the growing adoption of AI agents challenges our understanding of liability and heightens AI-related risks.Footnote 79 These risks emerge from the complex interplay between the model, the tools it can access, the data it can reach, the actions it can take, and interactions it may have with other agents in the process of executing tasks.

As agents have more complex interactions with other agents, it becomes more and more difficult to identify which agent did what, when, and why. Multi-agent interactions introduce reliability challenges due to miscoordination or conflicts between agents, as they have both shared and individual goals.Footnote 80 Additionally, as AI agents and multi-agent systems become more powerful, the consequences of malfunctions, such as executing unauthorized actions, can become more significant for Canadians and society at large.Footnote 81 AI agents can also increasingly be used for malicious purposes, including cyberattacks and identity theft.Footnote 82 Shopping agents can be tricked by malicious actors to act against the shopper's best interests, potentially buying products that are too expensive or not what the user desires. While robust governance practices, such as ensuring that there is a human in the loop to review key decisions or actions, can help to mitigate failures, AI governance practices have not kept up with the technology's rollout. Recognizing the risks involved with their use, in particular that AI agents can malfunction and behave in unexpected ways, some businesses have taken the position that users are responsible when agents do not behave as the user directs them to.Footnote 83 These circumstances heighten the need for clearer user-facing transparency and accountability when it comes to this new technology.

Market responses

Existing practices for understanding software system behaviour are being adapted to enable deployers of AI agents to better understand how these agentic AI systems function by collecting and monitoring AI-specific telemetry data, such as information about what tools an AI agent invokes, when, and how it makes decisions or takes a specific action.

A growing market of specialized software-as-a-service (SaaS) providers has also emerged to help organizations manage the risks associated with deploying AI agents. Often marketed as "agent platforms" or agent observability solutions, these products aim to enable organizations to monitor agent behaviour, log actions taken by agents, track tool usage, review decision pathways, and implement guardrails around what agents can do. Examples of dedicated AI observability and governance platforms that offer these capabilities include Maxim AI, Langsmith, and Comet as well as agent development frameworks that increasingly incorporate monitoring and governance features, including OpenAI Agents SDK, LangGraph, and Microsoft AutoGen.Footnote 84

Alongside commercial offerings, industry efforts are also underway to establish common standards for agent observability. For example, the open-source OpenTelemetry project is developing semantic conventions for AI systems that would standardize the collection and exchange of telemetry data, including information about model invocations, tool usage, agent decisions, and multi-agent interactions.Footnote 85 Some developers of agentic AI systems, such as Anthropic for Claude Cowork, are already enabling organizations to monitor system activities through OpenTelemetry.Footnote 86

A further development is the emergence of independent, third-party verification services that test and attest to an agent's behaviour against published security and risk standards before deployment, and monitor it thereafter.Footnote 87 Tying attestations to common public standards allows agents from different vendors to be compared on consistent terms — an early, market-led parallel to the conformity assessment approaches seen in other sectors.

Regulatory environment

In the absence of regulatory frameworks in Canada that specifically govern the use of agentic AI systems, existing consumer protection frameworks, which require businesses to provide products that are reasonably safe and perform as advertised, and civil liability frameworks, which allow individuals or companies to be held liable for failures to meet a duty of care resulting in foreseeable harm, continue to operate in cases where system malfunctions occur. In the context of AI, courts may apply these frameworks to examine whether developers or deployers acted responsibly. While the deployment of agentic AI systems represents unique malfunction risks, emerging Canadian case law concerning non-agentic malfunctions suggests that deployers can be held liable for resulting harms.Footnote 88

While regulatory efforts specifically governing agentic AI systems have been limited, several jurisdictions have taken steps to address risks associated with their deployment. These include legislative initiatives that contemplate product liability in the context of the increased opacity involved with AI systems, including AI agents, and deployment guidance to organizations. For example, in 2024, the EU enacted an updated directive on liability for defective products, which expanded the definition of a product to apply to software such as AI systems, including those with agentic AI.Footnote 89 According to this directive, products are presumed defective unless evidence to the contrary is produced by the provider of the product. It also introduced an obligation on defendants to disclose relevant evidence at the request of a claimant. In the context of agentic AI systems, this could create incentives for developers and deployers to implement measures to ensure that actions taken by agents are clearly documented.

Singapore's recently released Model AI Governance Framework for Agentic AI (MGF) also outlines risks associated with agentic AI and provides guidance to organizations on how to deploy agents responsibly, recommending technical and non-technical measures to mitigate risks.Footnote 90

Discussion

While the market deployment of agentic AI remains nascent, initiatives supporting greater visibility into how agentic AI systems are being used could help identify the magnitude and likelihood of potential risks they pose. At the same time, the technology, its uses, and the supporting standards are all evolving quickly, and approaches to transparency in this area remain at an early stage.

Better understanding of how AI agents are deployed and how they interact within broader ecosystems may become more important as they begin to operate at scale in open or high-stakes environments. Possible measures to support that goal could include disclosure measures on when and how agentic AI is used; the types of actions the deployed agentic AI systems are empowered to take; how human oversight is maintained; and transparency on the chain of custody when AI agents interact with one another.

Industry work on approaches such as maintaining detailed activity logs and developing identity credentials that platforms and service providers can verify when an agent interacts with them is ongoing, but these approaches are not yet mature. Whether and when government action would add value beyond emerging market and standards activity remains an open question.

The Government is interested in receiving stakeholder feedback on the following questions:

  • Are you concerned about the use of AI agents? In what contexts is it most important to know when an AI agent is in use? Why?
  • Who should be responsible for disclosing the use of AI agents? What kinds of information should they be recording regarding the activities of AI agents, and what kinds of disclosures should they be making, and to whom?
  • What kinds of information do businesses need in order to confidently and safely use AI agents? Do businesses currently have access to the information that they need about AI agents?
  • Are existing technical solutions, market practices, and legal frameworks sufficient to support transparency around agentic AI systems? If not, where do gaps remain and what actions (e.g., regulatory measures, guidance and codes of conduct, standards and technical solutions, research and development, literacy initiatives, procurement requirements) do you think the Government should take?

Conclusion

Through this consultation, the Government is seeking to understand where transparency about AI systems and AI-generated content matters most to Canadians, where existing practices and frameworks are sufficient, and where further action may be warranted. The Government is looking for feedback on the approaches presented in this document. This includes feedback on the range of policy instruments available, such as voluntary codes, industry standards, and legislation, and how these instruments could be implemented and interact with one another.

The Government also recognizes that there may be other elements beyond those identified in this document where greater transparency could promote responsible AI adoption and innovation and welcomes input in these areas. It encourages interested parties to share their perspectives on how Government action in these areas could protect Canadians from AI risks, as well as how potential measures could be implemented in practice.

In particular, the Government welcomes views on the following cross-cutting questions:

  • Given the areas discussed here, when is AI transparency most important, and are there any areas where action would be premature? Are there other areas that should be considered for action to enhance AI transparency?
  • How should any measures account for the circumstances of small and medium-sized enterprises?
  • How should Canada ensure coherence between any federal measures and provincial, territorial, and international frameworks? What approaches in other jurisdictions could best inform a Canadian consideration of this issue?
  • How can Canada design measures to best account for the ongoing evolution in AI technologies and their use?