PHAROS
Practice analysis

Law 25 and AI governance in Canada: obligations, automated decisions, and what organizations miss

Quebec's Law 25 imposes concrete obligations on systems that process personal information and make automated decisions. Here is what that means for teams deploying or governing AI systems in Canada.

Martin Lepage, PhD · PHAROS AI Governance · June 30, 2026 · 12 min read
Cet article est aussi disponible en français : Loi 25 et intelligence artificielle →

What Law 25 changes for AI systems

Quebec's Act to modernize legislative provisions as regards the protection of personal information — universally referred to as Law 25 — came into force in phases between 2022 and 2023. It amends the Act respecting the protection of personal information in the private sector (LPRPSP) and imposes new obligations that directly affect organizations operating AI systems.

Law 25 is not an AI law. But its requirements on transparency, risk assessment, and automated decision-making create real operational obligations for any system that processes personal information in the course of its functions — which covers the large majority of AI systems deployed in Quebec.

Starting point

If an AI system processes personal information to make or prepare a decision about a person, Law 25 applies. This is not a question of sector or organization size — it is a question of processing.

Law 25 obligations that apply to AI: an overview

Law 25 introduces several obligations with direct impact on AI systems. They fall into four operational blocks.

Obligation Trigger Status
Automated decision transparency Decision made exclusively by automated means affecting a person Required
Right to human review Automated decision affecting access, employment, or substantive rights Required
Privacy Impact Assessment (PIA) New system or substantial modification processing personal information Required
Current privacy policy publication Processing of personal information — no exception Required
Explicit consent and stated purposes Collection or secondary use of personal information Required
Privacy officer designation All organizations within scope Required
Cross-border transfer assessment Data processed outside Quebec (e.g., foreign cloud provider) Conditional

Automated decision systems: what Law 25 requires exactly

Section 12.1 of the amended act is the provision that creates the most operational obligations for AI teams. It applies when a decision is made exclusively by automated means using personal information and affects the exercise of a person's right.

Obligation 1 — Inform the person

The organization must inform the person concerned that the decision is made by automated means. This information must be provided before or at the time the decision is communicated. It cannot be buried in terms of service or in a twenty-page privacy policy.

In practice: if an AI system generates a credit decision, a hiring decision, a service access decision, or a risk score that determines an outcome, the person must know that an algorithm — not a human — decided.

Obligation 2 — Disclose the personal information used

The organization must also be able to inform the person of the personal information used to make the decision and the principal factors that influenced it. This is not a requirement for full algorithmic explainability, but it goes beyond a simple acknowledgment.

Common friction point

Many organizations use commercial models provided by third parties without being able to identify the principal decision factors. Law 25 does not accept "the vendor won't tell us" as a sufficient answer. Accountability stays with the organization that makes the decision.

Obligation 3 — Allow human review

The person has the right to request that a decision be reviewed by a human being. This right must be real and operational: it is not sufficient to state that a review is possible if the process does not exist, or if a human does nothing more than mechanically validate the system's output.

The concrete governance question is: who is accountable for this review, at what point, with what authority to change the decision, and what documentary record is produced?

Privacy Impact Assessments (PIA) for AI systems

The PIA is the obligation that generates the most operational work for teams deploying new AI systems. It is required before a system goes live when it collects, uses, or communicates personal information for new or substantially modified purposes.

For AI systems, this means concretely:

What a PIA is not

A PIA is not a generic compliance document filled out once. It is a risk assessment specific to the system, the processing, and the use context. A copy-pasted template with no real analysis of the actual system does not satisfy the obligation.

Law 25 and the EU AI Act: convergence for Canadian organizations

Canadian organizations doing business with European companies or using systems developed in Europe face dual regulatory pressure: Law 25 on one side, the EU AI Act on the other.

Both regimes share several central concerns:

The primary difference is scope: the EU AI Act classifies systems by risk level and imposes proportionate obligations. Law 25 applies whenever personal information is processed, without risk classification — but with less extensive requirements on system design and testing.

For Canadian organizations, the convergence creates an opportunity: controls built to satisfy the EU AI Act (data documentation, decision registers, human oversight) are generally sufficient to cover Law 25 requirements on the same systems. Build once, cover both.

What organizations miss most often

In practice, four gaps recur in AI governance reviews conducted under Law 25.

Gap 1 — The "automated decision" threshold is undefined

Many organizations do not know precisely which systems trigger the obligations of section 12.1. Is a recommendation engine that ranks job applications an automated decision? A credit risk scoring tool used by an advisor who makes the final call? The line is not always clear, and failing to define it creates undocumented exposure.

Gap 2 — Human review is not operational

The obligation to offer human review exists on paper but not in process. No one has named accountability, timelines are undefined, and no documentary record is produced. In a regulatory review or audit, this gap is the hardest to defend.

Gap 3 — The PIA is generic or absent

The assessment was done once, for the original system, without being updated when modifications occurred. Or it was completed with a generic template with no specific analysis of the system's actual data flows.

Gap 4 — The privacy officer has no real authority

Law 25 requires a designated privacy officer. In many organizations, the role is named but has no mandate, no resources, and no decisions to make. Nominal accountability without real authority does not satisfy the spirit of the obligation.

A deterministic governance approach to Law 25

Compliance with Law 25 is not built with general statements about commitment to privacy protection. It is built by naming precise thresholds, explicit decision rights, and reconstructible evidence paths.

For each AI system within Law 25's scope, this means documenting:

This work is not symbolic compliance. It is the construction of a record that any external reviewer — the Commission d'accès à l'information, an institutional buyer, a partner conducting due diligence — can follow and reconstruct.

PHAROS principle

An AI governance system that cannot be reconstructed by an outside observer is not a governance system — it is a statement of intent. Law 25 rewards the first and exposes the second.

Is your organization ready for a Law 25 review on its AI systems?

PHAROS structures AI governance reviews that translate Law 25 obligations into verifiable operational controls — explicit thresholds, named decision rights, and reconstructible documentation for the CAI, your buyers, or your auditors.