Bill C-36. What has changed, and what is changing.

There is no doubt that we are living in a new world. The scale and ubiquitousness of AI has accelerated the pace of innovation, underscoring the need for clear frameworks that optimize potential and minimize risk. In June, the Canadian government released AI for All, a comprehensive strategy that will provide the guiding principles for regulation and investment in Canada. Bill C-36, Protecting Privacy and Consumer Data Act, provides one of the legislative mechanisms to guide Canadian organizations. inq recently hosted policy makers and key industry leaders to discuss how organizations can prepare for future success.
What has changed
The most significant change may actually be in how our current federal government works. The government is focused on execution and outcomes, rather than process. They received significant feedback on Bill C-27 (the predecessor to Bill C-36), and some of that feedback appears to be reflected in Bill C-36. There is also a strong emphasis on ensuring that regulation is not unnecessarily burdensome.
These, coupled with the fact that Canada is under a majority government federally, could mean that C-36 will make its way through the chambers much quicker than previous attempts.
What is changing
Bill C-36 introduces a number of changes, some quite operational. Our law firm, INQ Law LLP, has previously written about Bill C-36 and what it means for applicable organizations (click here). For example, privacy impact assessments may be considered at a broader program level, rather than for each individual use case, to avoid creating an overly burdensome process. Broadly speaking, Canadian organizations should not lose sight of the fact that we are building on a strong regulatory baseline of adequacy.
The current focus of Bill C-36 is less on standalone AI legislation and more on privacy reform, including consolidating enforcement under a unified commission (Digital Safety and Data Protection Commission) and changing the existing structure of enforcement of privacy law. The National Institute on Standards and Technology (NIST) AI Risk Management Framework and the ISO/IEC 42001 (AI Management Standard) and similar frameworks also came up as potential reference points for AI governance and controls.
Will there be any law governing AI?
Beyond elements of AI law in other federal bills and the recent public consultation on AI transparency that closed on September 23, 2026, there is a growing global consensus that cooperation and implementation need a consistent effort across jurisdictions. On September 21, 2026, twenty countries (including Canada) and the EU endorsed A Call for Control of Frontier AI Models. Signatories agreed to support the following guiding principles in AI governance and oversight:
Companies to develop transparent safety protocols, including mandatory pre-deployment testing and independent evaluation, with qualified evaluators granted sufficient access to assess risks.
Governments and regional organisations to further develop and coordinate common standards, strengthen transparency, including shared reporting of serious safety incidents, and ensure that countries across all regions have access to scientific capacity, expertise and trusted evaluation.
UN member states to build on existing international mechanisms and explore creating an international institution, able to set standards, enable verification, and convene states when capability thresholds are crossed.
With an open invitation for other countries to add their endorsement, it appears that Canada will be moving in lockstep with other jurisdictions to ensure we are building a regulatory environment that works for all.






