Magnifying glass over code. Photo by Kristina Alexanderson (internetstiftelsen), CC-BY-SA https://www.lawfaremedia.org/article/new-ai-transparency-rules-have-a-trade-secrets-problem

Magnifying glass over code. Photo by Kristina Alexanderson (internetstiftelsen), CC-BY-SA https://www.lawfaremedia.org/article/new-ai-transparency-rules-have-a-trade-secrets-problem

News

An AI Transparency Act for Canada: My Submission to the Government’s AI Transparency Consultation

The government’s consultation on AI transparency closed yesterday. My submission builds on appearances before the House of Commons Industry committee, the Senate Transport and Communications committee, and the Senate Social Affairs committee, and recommends an AI Transparency Act built on three pillars: mandatory public disclosure of AI corporate safety and escalation policies, an issue I raised in the aftermath of Tumbler Ridge, transparency on the works included in AI training data, and annual transparency reports on government and law enforcement demands for user data. It addresses each of the discussion paper’s five areas, including why Bill C-36 (the government’s privacy reform bill) is unlikely to facilitate better transparency in automated decision-making before at least 2030 and why Bill C-34’s synthetic content labelling obligation does not fully address the issue of identifying such content that can mislead. The full submission is posted below.

Submission to the Government of Canada Consultation on Advancing AI Transparency

September 2026

I am a law professor at the University of Ottawa where I hold the Canada Research Chair in Internet and E-commerce Law. I submit these comments in a personal capacity, representing only my own views.

Introduction

In recent months, public and government pressure has escalated to establish AI regulatory frameworks. In appearances on AI policy before the House of Commons Standing Committee on Industry, Science and Technology, the Standing Senate Committee on Transport and Communications, and the Standing Senate Committee on Social Affairs, Science and Technology over the past year, I emphasized that the goal must be well-considered frameworks that balance facilitating innovation with safeguards against potential risks and harms. I believe greater transparency should be the starting point for any regulatory framework, and that the lack of AI transparency is linked to diminished public trust. Transparency is the most practical and broadly supported foundation for AI regulation, covering disclosure of where AI is used, which works are included in training data, and instances of government and law enforcement demands for user information.

The government’s decision to consult on AI transparency is therefore welcome. The government’s AI for All strategy disappointingly contained only limited commitments to transparency, notably a promise to work on the issue over time through watermarking and a voluntary Canada Trusted AI Certification program. Those commitments did little to compel companies to disclose which works they used to train their models, which is the type of information that would let users and creators make informed choices.

This consultation is the opportunity to fill that gap. My central recommendation is that the government introduce and pass an AI Transparency Act built on three pillars. First, make AI corporate policies on user safety publicly accessible, including standards for escalating beyond flagging content or banning users. Second, mandate transparency on which works are included in the training data for large language models so creators have access to the information they need to exercise choice and, if they wish, seek content removals on an opt-out basis. Third, require companies to publish annual transparency reports on government and law enforcement demands targeting users or content. This approach addresses real concerns without undermining privacy or locking in rules that may not fit a fast-moving technology.

1. The Need for AI Transparency Legislation

Each section of the discussion paper concludes by asking whether the government should pursue regulatory measures, guidance and codes of conduct, standards, research and development, literacy initiatives, or procurement requirements. I believe ample evidence shows that voluntary codes alone are insufficient. Canada has had a Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems in place since September 2023 (the “Code”). The Code recommends that developers establish reliable methods to detect AI content, maintain public incident databases, and publish information on AI system capabilities. Yet today detailed disclosure of training datasets remains rare and the discussion paper itself acknowledges “limited visibility into serious AI incidents and how AI companies respond,” and that transparency practices “remain inconsistent across the industry.”

To be clear, standards, literacy funding and procurement conditions can all contribute to AI policy objectives. However, the core disclosure obligations should be statutory. Those rules should apply to the largest AI developers and deployers in the Canadian market, backed by a designated regulator with the authority to verify disclosures and impose administrative monetary penalties for non-compliance.

2. Information about AI systems

Greater transparency on AI systems is long overdue, covering at least three categories of information subject to mandatory public disclosure. First, corporate safety and escalation policies. As I noted in the aftermath of the Tumbler Ridge tragedy, it should not take a meeting with company executives for the Minister, or anyone else, to know about a company’s policies on banning user accounts or reporting conduct to the police. Companies should be required to fully disclose their user-safety policies, including the standards used to escalate matters beyond flagging content or banning users from the platform. Disclosures should also include age-related restrictions. Further, companies that fail to live up to their published policies should face liability for that failure.

Second, training data. The paper treats input transparency as a distinct issue and notes that creators and rights holders want to know whether their works were used in training. I believe that transparency is the logical next step in addressing this issue. While some support copyright reform to address the use of works in large language models, such reforms are premature, as many copyright cases are still working their way through the courts and shaping legal guidance and market deals. Legislating too quickly could lock in rules that do not match the legal and market realities. Further, regulating licensing or imposing new restrictions on fair dealing would render Canada a more difficult and costly country for AI, risking less Canada in the training data and less Canada in the outputs.

Transparency provides a more effective alternative. The EU AI Act requires providers of general-purpose models to publish a sufficiently detailed summary of training content, including the major datasets, the principal domains crawled, and the categories of data used. California’s AB 2013 requires generative AI developers to post documentation of their training datasets, including sources, whether the data includes copyrighted content, licensed material or personal information, and the collection period. Canada could emulate these legislative models. This kind of disclosure is also essential for any viable opt-out system, since a creator cannot request exclusion from training data without first knowing whether their work is included.

Third, capabilities, limitations and safety frameworks. California’s Transparency in Frontier Artificial Intelligence Act requires frontier developers to publish transparency reports and to describe how they assess and manage risk. Canada should require the same publication from large developers offering systems in the Canadian market, aligned with the California and EU formats.

3. AI interaction

Signatories to the Code already commit to ensuring that systems that could be mistaken for humans are clearly and prominently identified as AI systems. Subject to the EU AI Act’s exception where the AI nature of the interaction is obvious from the circumstances, that commitment should become a legal obligation for every commercial and public sector deployer of conversational AI in Canada. The government’s own case study (a dealership chatbot that negotiated a vehicle buyback under a human name without revealing that it was an AI system), illustrates how voluntary commitments have not reached the deployers where the risk of deception is greatest. This obligation would align with rules already enacted elsewhere, including in the EU, South Korea, and several U.S. states.

The paper also points to Bill C-36 to enhance transparency in automated decision-making. The challenge with relying on the bill is that it faces an uncertain path to enactment, leaves key issues to future regulations, and removes the Privacy Commissioner from private-sector enforcement in favour of a new commission that will take years to come to fruition. Indeed, the new regime is unlikely to be fully operational before 2030 at the earliest. The risks associated with AI, such as automated decision-making in hiring, require a timelier response. A transparency statute could require disclosure for consequential automated decisions, with notices stating that AI materially influenced the decision, identifying the principal factors considered, and explaining how to obtain human review.

4. AI-generated content

AI-generated content needs more transparency, but the government should not adopt a general obligation to label all AI-involved content. In fact, even the EU AI Act exempts ordinary editing, artistic and satirical works, and text that has undergone human editorial review. Instead, the focus should be on realistic synthetic audio, image and video content that misrepresents real people, places or events. For this category of content that can mislead users, requiring large generative AI providers to embed machine-readable provenance information and make detection tools freely available builds on the Code’s standards. Since Bill C-34’s proposed labelling obligation addresses only the distribution point and only for regulated social media services, a developer-side obligation is the necessary complement.

5. AI incidents

I support a serious incident reporting obligation for AI developers. Reports should be filed confidentially with a designated regulator, with aggregated public reporting annually and earlier public advisories or notices to affected people where there is significant risk of harm. Protection for good-faith reporting should attach to the act of reporting, but not to the conduct reported.

Reporting should not be limited to technical malfunctions, since a system can produce discriminatory outcomes or expose sensitive inferred information while functioning as its developer intended. The EU AI Act’s definition covers an incident or malfunction that leads to death or serious harm, serious disruption of critical infrastructure, or breaches of fundamental rights protections. Canada should adopt a similar threshold.

User speech or inputs should not constitute a reportable incident, and the regime should create no general duty to monitor users. Given that Internet intermediaries find themselves at the centre of virtually everything people write, whether text messages, e-mails, articles stored on cloud-based services, or exchanges with chatbots, an incident regime that captured user activity would presumably apply to virtually all written expression.

6. AI agents

AI agents are still in early development, so prescriptive rules would be premature. The transparency obligations described above should nonetheless apply to agentic systems from the outset. The fundamental principle should be that a consumer dealing with an agent should know it is an agent. Companies deploying agents should publish what those agents are authorized to do and how they maintain human oversight. Safety policies should address how agent errors are handled and remedied, and existing consumer protection and civil liability rules should also apply to agents.

7. Transparency Issues Missing from the Consultation

The discussion paper treats transparency primarily as the flow of information from companies to users and from companies to government. Yet it says nothing about the demands that governments and law enforcement make of AI companies for user data and content. This is the third pillar of my proposed AI Transparency Act. AI providers now hold conversational records that are among the most sensitive data Canadians generate. Governments and police will likely seek access to them, as they do with other intermediaries. Canadians cannot assess the safety-privacy balance in AI systems without knowing how often those systems are the subject of government demands. Companies should be required to publish annual transparency reports with aggregated figures on government and law enforcement demands, including company-initiated referrals to police, much like telecommunications providers and major Internet platforms have done for years.

Moreover, the consultation fails to grapple with the government’s own use of AI. A transparency statute should bind federal institutions as well as companies. The Government of Canada AI Register describes itself as a minimum viable product, assembled from algorithmic impact assessments, access-to-information responses, parliamentary returns, and other existing sources. The government should be required to maintain a complete and current register of its own systems, including the vendor, model and purpose, the population affected, the impact assessment, and any incidents, with responsibility for updating it and for justifying any exemption.

Conclusion

The Canadian government will never outspend the market on AI. Supporting AI development must primarily involve creating the legal and regulatory frameworks that facilitate investment, trust, and adoption. Transparency is an essential part of those frameworks, ideally developed through an AI Transparency Act that makes disclosure of safety policies, training data, and government demands a legal requirement.

Leave a Reply

Your email address will not be published.

*

*