Ask a business owner in British Columbia what the AI rules are and you will usually get one of two answers, both wrong in opposite directions. Either the rules are so onerous that using AI on customer information is asking for trouble, or there are no rules at all, so anything goes until somebody says otherwise.
The accurate answer is more specific and more useful than either. Canada has no artificial intelligence statute. British Columbia has no artificial intelligence statute. What exists instead is privacy law that already applied to everything your business does with personal information, which now has to be read as covering a set of tools it was written long before anyone imagined. In May 2026 four privacy commissioners, including this province’s, published a joint finding that made clear how they intend to read it.
This piece sets out what is actually in force, what is proposed, and what a business with five to fifty staff should do about it. Everything below was verified on 18 August 2026, and the proposed items in particular will move.
One thing to state plainly before going further. Entoura.Studio is an AI development studio, not a law firm, and nothing here is legal advice or creates a solicitor-client relationship. This is a plain-language summary of publicly available law as it stood on 18 August 2026, written so you know which questions to ask. For your own circumstances, ask a lawyer qualified in your jurisdiction, and check currency before acting, because two of the items below are still moving.
What is in force
BC’s Personal Information Protection Act. For most private-sector organisations operating in British Columbia, PIPA is the governing statute rather than the federal PIPEDA. It has been in force since 2004 and it contains nothing about artificial intelligence, which is precisely the point: its requirements apply to AI because they apply to personal information regardless of what technology touches it.
The obligations that bite hardest in an AI context are the ordinary ones. Collect personal information only for purposes a reasonable person would consider appropriate. Get meaningful consent, which means the person understood what they were agreeing to. Use the information only for the purpose you named. Protect it with reasonable security. Keep it only as long as you actually need it.
Read that list next to what typically happens when a business starts using AI and the exposure becomes obvious. A staff member pastes a client file into a chat tool to get a summary. At minimum that is a use of the information, and it has to stay consistent with the purpose the information was collected for. Depending on the tool’s terms it is also a disclosure to a third party. The federal commissioner treats a transfer to a service provider purely for processing as a use rather than a disclosure, which is why the tier you are on and the agreement behind it decide the answer. A consent form saying the business “may use technology to improve service” carries neither.
PIPEDA. The federal act still governs personal information in commercial activity that crosses provincial or national borders, and it applies to federally regulated businesses. Most BC companies land under PIPA for their own operations and encounter PIPEDA at the edges.
The May 2026 enforcement signal. On 6 May 2026 the Office of the Privacy Commissioner of Canada, together with Quebec’s Commission d’accès à l’information and the BC and Alberta commissioners, published joint findings on OpenAI. They concluded the scraping used to build the models was overbroad and inappropriate, and identified failures on transparency, accuracy, access and deletion, and retention.
That finding is about a model developer rather than a business using AI, so it creates no direct obligation for a lodge in Courtenay. What it establishes is posture. Four regulators, one of them yours, have now said in public that existing privacy law reaches generative AI and that they intend to apply it.
Quebec’s Law 25. In force since 2022 and 2023, and it applies by activity rather than by where a company is headquartered. Two provisions matter here. The first requires informing a person when a decision about them is made exclusively by automated processing, and giving them the chance to make representations. The second requires a privacy impact assessment before transferring personal information outside Quebec. A BC business handling personal information about Quebec residents is inside this, which is a fact that surprises people.
Ontario’s hiring disclosure. Since 1 January 2026, Ontario’s Employment Standards Act has required publicly advertised job postings to disclose when artificial intelligence is used to screen, assess or select applicants. It applies to employers with 25 or more employees on the day the job is posted, and it reaches employment governed by Ontario’s ESA rather than every advertisement visible in Ontario. British Columbia has no equivalent. A BC business hiring for BC work sits outside it; a BC business with an Ontario operation should check.
The EU AI Act, for a narrow set of businesses. Its transparency obligations became applicable on 2 August 2026: disclose that a person is dealing with an AI system, mark synthetic content in a machine-readable way, and label deepfakes. The obligations for high-risk uses were pushed back to December 2027 and beyond by the Digital Omnibus agreed on 6 May 2026. The part that catches Canadian companies out is reach: the Act applies where the output of an AI system is used in the EU, which is a different test from selling to European customers. Most BC businesses are outside it. A business that builds or operates an AI system whose output lands in Europe should look properly.
Everything else that always applied. Human rights law prohibits discriminatory outcomes regardless of whether a machine produced them. Consumer protection law applies to what your system tells a customer. Professional regulation applies to the professional record. Your own client contracts frequently contain confidentiality and data-handling terms that are stricter than any statute, and in practice those are the constraint that binds first.
What is proposed and has not happened
AIDA is dead. The Artificial Intelligence and Data Act was part of Bill C-27, which died when Parliament was prorogued in January 2025. It has not been revived, and Canada has no comprehensive AI legislation in prospect. Anyone still planning around AIDA obligations is planning around a bill that does not exist.
AI for All. Launched 4 June 2026, this is the federal government’s national AI strategy: adoption support for small and medium businesses, funding for the Canadian AI Safety Institute, and a trusted AI certification program. It is policy and money, not rules. The part worth watching is the adoption funding, since it is aimed squarely at businesses the size of most of ours.
Bill C-36. Tabled at first reading on 15 June 2026, the Protecting Privacy and Consumer Data Act is the third federal attempt at privacy reform and would replace PIPEDA. It carries mandatory privacy management programs, rules for service providers and cross-border transfers, privacy impact assessments before moving data outside Canada, protections for children’s data, transparency requirements for automated decision systems, and administrative monetary penalties reaching $10 million or 3% of global revenue.
None of that is in force. It is at the earliest stage of the parliamentary process and two previous attempts died before reaching it. Reorganising your business around C-36 today would be premature. Noting that Canadian AI obligations are arriving through privacy law rather than AI law is the durable insight, and it tells you where to look.
What to actually do
The gap between the legal position and a sensible operating position is where most of the value sits, and the work is smaller than the length of this article suggests.
Write down what you are actually using. This is the first step and the one almost nobody has done. A short list: which AI tools are in use anywhere in the business, who uses them, what kind of information goes into each one, and whether the business or an individual controls the account. The number is usually higher than the owner expects, because the tools people quietly adopt on their own do not announce themselves. That inventory is the foundation for every other decision here, and it takes an afternoon.
Decide what may never leave. One clear rule, understood by everyone, does more work than a long policy nobody reads. Client files, health information, financial records, anything under a confidentiality clause: name the categories that may not be pasted into a tool the business does not control, and name the approved place to do that work instead. A rule without a sanctioned alternative gets ignored, so the alternative has to exist.
Know where the data goes. For each significant tool, whether the information leaves Canada, whether it is retained, and whether it is used for training. Consent, purpose and retention decide most of this, and they are quieter than residency. Consumer tiers and business tiers differ substantially here, and the terms change. Where the processing physically happens is a design decision with legal consequences, and it is worth understanding what actually determines where your AI runs before choosing.
Set a retention period and honour it. Keeping information indefinitely because storage is cheap sits badly against PIPA, and it is the kind of thing that turns a small incident into a large one. Under C-36 it would become a documented obligation. What a workable schedule looks like, including the legal hold that has to be built alongside the deletion, is a piece in itself.
Keep a person on decisions about people. No BC statute requires it. Quebec’s does in its circumstances, Ontario’s does for hiring disclosure, C-36 would add transparency requirements, and human rights law has always applied to the outcome. Beyond compliance, this is simply how you avoid a system quietly making a decision about someone that nobody can explain afterwards.
Write down the decision. For anything consequential, a short record of what tool, what data, what basis, and who decided. Under C-36’s proposed privacy management program requirement this becomes formal. Today it is the difference between answering a regulator’s question in an hour and answering it in a month.
The part worth carrying out the door
The absence of an AI statute in Canada is not permission. It means the questions a regulator will ask are the ones they have always asked. What personal information did you collect, for what purpose, with what consent, protected how, kept how long, and disclosed to whom. A new tool in the middle of the process changes none of those questions.
The BC-specific position as of today is straightforward. PIPA applies and always did. Quebec’s rules can reach you through your customers rather than your address. Ontario’s hiring rule can reach you through a job posting. The EU’s rules probably do not reach you. Federal privacy reform is coming through Bill C-36 and has not arrived.
The businesses that will find this easy are the ones that can produce a list of what they use and a sentence about why each one is acceptable. That list is a Tuesday afternoon of work and it is the entire difference between a manageable position and a guess.