Pith. sign in

REVIEW 5 major objections 5 minor 49 references

One unified framework can satisfy Canada's overlapping federal and provincial AI rules at once.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · deepseek-v4-flash

2026-08-02 00:16 UTC pith:3IXVJ2E3

load-bearing objection Useful mapping, honest limitations, but the burden/benefit numbers are not evidence—still deserves peer review as a proposal. the 5 major comments →

arxiv 2607.15051 v1 pith:3IXVJ2E3 submitted 2026-07-16 cs.CY

SCITUS: A Multi-Jurisdictional Framework for Adapting NIST AI RMF to the Canadian Regulatory Context

classification cs.CY
keywords AI governanceregulatory frameworkmulti-jurisdictional complianceNIST AI RMFCanadian AI regulationrisk managementcompliance mappingcontrol catalog
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

Canadian organizations deploying AI must navigate five separate regulatory regimes, and no global framework tells them how to comply with all of them at once. This paper proposes SCITUS, a framework that adapts the NIST AI Risk Management Framework to Canadian law by mapping 127 extracted federal and provincial requirements onto 57 shared controls. The central claim is that a single assessment and documentation set can simultaneously satisfy the federal Treasury Board Directive, Ontario Bill 194, Quebec Law 25, Alberta Bills 33/34, and Manitoba Bill 51, while preserving alignment with the international standard. If that holds, compliance effort drops from 12–16 weeks and three to five disconnected document sets per system to roughly 6–8 weeks and one unified set, and the same mapping method becomes a template for other federal countries.

Core claim

SCITUS's claim is that the fragmentation of Canadian AI regulation is an integration problem rather than a conflict problem. By extracting 127 distinct requirements across five jurisdictions and categorizing them under the NIST framework's GOVERN, MAP, MEASURE, and MANAGE functions, the paper finds that obligations are largely additive: 23 requirements overlap directly, most others address complementary aspects, and only two potential conflicts exist. The framework therefore builds a versioned control catalog (31 controls at v1.0, 57 at v2.0) where each control lists the multiple legal requirements it satisfies, and a four-step mapping method that turns one unified assessment into jurisdicti

What carries the argument

The load-bearing mechanism is the multi-jurisdictional compliance mapping methodology: (1) extract and categorize each jurisdiction's requirements by governance function and AI lifecycle stage; (2) identify overlapping, complementary, and conflicting requirements; (3) design unified controls, each with a mapping of which legal obligations it satisfies, and generate jurisdiction-specific documents from one source of truth; (4) validate coverage and close gaps. It operates inside a three-layer architecture — the NIST framework core, a Canadian regulatory integration layer, and an implementation-guidance layer — and uses the federal Treasury Board impact levels (I–IV) to tier how much control s

Load-bearing premise

The central claim collapses if the five jurisdictions' AI obligations turn out to include genuine incompatibilities rather than being mostly additive, because the whole framework is built on mapping one control set onto requirements that can all be satisfied together.

What would settle it

Have independent legal counsel re-extract obligations from the current statutes and regulations and find one requirement pair that cannot both be satisfied (for example, one jurisdiction mandating public disclosure of a model's logic and another protecting that logic as a trade secret, with no exemption), or run a real deployment under SCITUS and show a jurisdiction-specific requirement that the 57 controls do not cover.

Watch this falsifier — get emailed when new claim-graph text bears on it.

If this is right

  • A single AIA/PIA-style assessment would be able to satisfy federal, Ontario, Quebec, Alberta, and Manitoba requirements, instead of running separate assessments per jurisdiction.
  • Documentation overlap of 60–70 percent across jurisdictions means one source-of-truth repository with jurisdiction-specific views replaces three to five separate document sets.
  • Risk-tiered controls ensure high-impact systems get peer review, bias testing, and human oversight regardless of which province deploys them.
  • The same extraction-and-mapping method could be applied by other federal systems facing state or provincial AI regulation, such as the United States or Australia.
  • The versioned catalog gives a concrete way for a framework to stay current as regulations and AI threat classes change, without redesigning the whole structure.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • The additive-requirements premise is time-sensitive: if federal omnibus AI legislation or a constitutional ruling on AI jurisdiction arrives, the mapping method will need conflict-resolution machinery that goes beyond the 'apply the most stringent requirement' rule.
  • The 127-requirement extraction is the empirical keystone; an independent legal re-extraction could verify completeness, and disagreement with it would change the coverage claims.
  • A natural next test is a pilot in one organization with a real deployment, measuring assessment time and coverage against the 15-organization baseline the paper reports; the current demonstrations are illustrative scenarios, not measured deployments.
  • The same 'common abstraction' principle could extend beyond AI to other fragmented compliance domains, but the conflict taxonomy would likely need domain-specific types.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

5 major / 5 minor

Summary. The paper proposes SCITUS (Systematic Canadian Integration for Trustworthy and Unified Standards), a framework that adapts NIST AI RMF 1.0 to Canadian federal and provincial requirements. It extracts 127 requirements from Treasury Board, Ontario Bill 194, Quebec Law 25, Alberta Bills 33/34, Manitoba Bill 51, and British Columbia policy, classifies them by NIST function, and maps them onto a versioned control catalog that grows from 31 to 57 controls. The framework combines three layers (NIST core, Canadian regulatory integration, implementation guidance), seven enhanced trustworthy-AI characteristics, four governance functions, a multi-jurisdictional compliance mapping methodology, and implementation tooling. Three illustrative scenarios (federal immigration, Ontario hospital diagnostic AI, Quebec hiring AI) are used to argue that systematic adaptation yields significant efficiency and coverage advantages over jurisdiction-by-jurisdiction compliance and offers a replicable model for other federal systems.

Significance. If the central claims were supported, the paper would address a real gap: there is no widely accepted methodology for adapting a global framework like NIST AI RMF to a multi-jurisdictional national context. The manuscript's strengths are its detailed citation of primary legal sources, coherent three-layer architecture, transparent treatment of many limitations, and a versioned control catalog that responds to rapidly evolving regulatory and threat developments. The multi-jurisdictional mapping methodology and the conflict taxonomy in §3.6 are useful conceptual contributions. However, the paper's main value proposition—reduced burden, fewer gaps, faster assessments—is currently supported only by an undocumented 15-organization survey, an unreproducible requirement-extraction process, and scenarios that the paper itself labels hypothetical. The significance is therefore conditional: valuable as a framework proposal and research agenda, but not yet an empirically validated compliance solution.

major comments (5)
  1. [§3.1, Appendix A] The 127-requirement extraction is load-bearing. The text says requirements were extracted by 'structured coding' but provides no codebook, sampling frame, inter-rater reliability, or raw extracts; the compliance matrix in Appendix A is the only output and cannot be reconstructed from the paper. If the extraction is incomplete or inaccurate, the claims in §4.5 and the abstract that one catalog simultaneously satisfies all five regimes lose their foundation. Please publish the coding protocol and the complete requirement–control mapping (or a stable versioned dataset), and clearly separate verified legal obligations from interpretive mappings.
  2. [§3.4, §4.5 Step 2] The conclusion that Canadian requirements are 'predominantly additive rather than conflicting' is used as the basis for unified single-documentation compliance. The paper identifies only two potential conflicts and resolves them by 'implementing both' or 'applying most stringent'; these techniques work only if obligations are compatible or nested. Genuinely contradictory obligations—for example, a mandatory public-disclosure duty versus a trade-secret or national-security duty—are acknowledged in §3.6 Type 1 as a governance tension but are not analyzed as potential compliance impossibilities. Please either define a conflict criterion and systematically screen all 127 requirements against it, or restrict the simultaneous-compliance claim and describe the decision procedure for irreducible conflicts.
  3. [§3.5, §6, §7.1 Finding 1] The central efficiency claims—'12–16 weeks per system', '15% average requirements missed', and the 6–8 week SCITUS assessment time in §3.6—are derived from an undocumented survey of 15 unnamed organizations and from explicitly hypothetical scenarios (§6.2–6.4 carry IMPORTANT NOTE: hypothetical). Section 7.3 Limitation 3 concedes there is no empirical validation. As written, the abstract's 'significant advantages' is an unsupported empirical claim. Please either provide the survey instrument, sample description, and analysis; present a small real-world pilot; or reframe the contribution as a framework proposal with testable hypotheses. The current wording overstates the evidence.
  4. [§4.9, Appendix A] The paper claims a versioned 57-control catalog and per-control assessment criteria, but only a version-history table and a high-level matrix are included; the actual catalog is 'maintained in the framework's public documentation' and is not accessible in this manuscript. Similarly, §5.3 references an 'extended protocol document' that is not provided. For peer review, the artifact must be included in the paper or made available in a stable, versioned repository; otherwise a central mechanism of the framework cannot be audited.
  5. [§6.6, abstract] The abstract says SCITUS addresses Canadian regulations 'simultaneously' and the framework positions itself as comprehensive, but §6.6 identifies critical gaps (Indigenous data sovereignty, French-language AI requirements, municipal AI) and §2.3 notes unresolved constitutional and jurisdictional uncertainty. Please align the language of the abstract and contributions with the scope actually supported. In particular, the framework at this stage covers mapped federal/provincial provisions, with an explicit roadmap for integrating OCAP principles and other gaps.
minor comments (5)
  1. [§6.1, abstract] The abstract says the framework 'demonstrate[s] applicability,' while §6.1 and the scenario notes use 'illustrative' and 'hypothetical.' Please make the epistemic status consistent throughout.
  2. [§4.7.1, §6.2] The SCITUS code example defines SCITUS_THRESHOLD = 0.05 as a configurable parameter, but §6.2 treats 5% as the operative threshold. Clarify whether thresholds are framework-prescribed, examples, or organization-specific.
  3. [§4.9] The v2.0 release refers to '9 control enhancements' but does not itemize them. If the full catalog is made available, please include a changelog listing each enhancement.
  4. [§4.3, Table 4] Table 4 labels the last characteristic 'Fair - Bias Managed,' while the text uses 'Fair with Harmful Bias Managed.' Use consistent terminology across tables and prose.
  5. [§9.4] The table of contents lists a 'Citation Verification' section. Please confirm that all legal citations have been checked against official texts and state the verification method; if the section concedes unverified citations, that should be disclosed in the paper itself.

Circularity Check

2 steps flagged

Partial self-referential support: efficiency advantages are illustrated by the paper's own hypothetical scenarios and then cited as evidence; NIST-function categorization also guarantees the 'NIST provides effective foundation' finding.

specific steps
  1. fitted input called prediction [§3.6 (Theoretical Contributions, Principle 2), relying on §3.5 and §6.2–6.4]
    "Evidence: Our compliance burden quantification (Section 3.5) shows organizations using jurisdiction-first approaches spend 12-16 weeks per system with 15% requirement gaps, while risk-first SCITUS approach (demonstrated in scenarios Section 6) achieves comprehensive coverage in 6-8 weeks."

    The SCITUS '6-8 weeks' figure is not an independent measurement; it comes from the paper's own hypothetical scenarios (e.g., §6.3: 'Avoided separate assessments for each regulator (estimated 16 weeks) through integrated SCITUS approach (6 weeks)'). The baseline relies on §3.5 'data from 15 organizations' with no instrument or methodology, and Limitation 3 concedes 'does not provide empirical validation through real-world implementations.' Thus the central efficiency advantage is supported by numbers authored as part of the demonstration: the conclusion is fitted to the illustrative inputs rather than independently derived.

  2. self definitional [§3.1 Step 3 and §3.6 Contribution 1, Principle 1]
    "We categorized requirements according to NIST AI RMF functions (GOVERN, MAP, MEASURE, MANAGE)... Our analysis reveals that federal (Treasury Board), Ontario (Bill 194), Quebec (Law 25), and Alberta (Bills 33/34) requirements all address fundamentally similar governance functions..."

    Because Step 3 performs the categorization using NIST's own function labels, the later 'analysis reveals' that all requirements address NIST-compatible governance functions is a property of the coding scheme, not an independent empirical discovery. The paper then presents this as Finding 3 ('NIST AI RMF provides effective foundation'), converting the chosen analytical frame into an apparent confirmation. This is a mild self-definitional loop, though it does not invalidate the practical mapping.

full rationale

This is a design/mapping paper rather than a formal derivation. The compliance matrix maps cited primary-source regulatory requirements to controls, and that mapping is the framework's content, not a circular equation or a fitted parameter. No uniqueness theorem or load-bearing self-citation is used to force the choice of NIST AI RMF as the foundation. However, two self-referential loops weaken the evidence for the central 'significant advantages' claim. First, the efficiency figures used to demonstrate those advantages originate in the paper's own hypothetical scenarios (§6) and an unmethodized 15-organization survey (§3.5); §3.6 then cites these as evidence. The paper's Limitation 3 explicitly concedes 'demonstration rather than empirical validation,' confirming this is an evidence loop rather than an externally validated prediction. Second, the finding that NIST functions provide an effective foundation follows in part from the decision to categorize the extracted requirements using NIST functions in §3.1 Step 3; this is a mild self-definitional loop. Neither loop makes the regulatory extraction itself circular: the 127-requirement set is grounded in cited legislation, and the framework is reproducible from primary sources. Score 3 reflects partial self-referential support, not a by-construction equivalence.

Axiom & Free-Parameter Ledger

3 free parameters · 5 axioms · 1 invented entities

The framework rests on domain assumptions about the additivity and completeness of Canadian AI requirements, plus hand-selected thresholds and asserted cost estimates. The only standard-mathematics input is the well-known fairness impossibility theorem. No new physical entity is postulated beyond the framework artifact itself, which lacks independent empirical evidence.

free parameters (3)
  • SCITUS bias disparity threshold = 0.05 (5 percentage points)
    Chosen by hand as an investigation trigger in Section 4.8.1 and Section 6.2; no regulatory source or derivation is given.
  • Impact-level testing and oversight tiers = Level I-IV mappings in Tables 5, 6, and 9
    Design choices aligning provincial requirements to Treasury Board levels; not empirically calibrated.
  • Compliance burden estimates = 12-16 weeks; 192-256 person-hours; $45k-$75k; 15% gaps
    Presented as quantified in Section 3.5 but no underlying dataset or methodology is provided; these numbers underpin the claimed advantage of SCITUS.
axioms (5)
  • domain assumption NIST AI RMF's four functions and seven characteristics form a valid neutral abstraction layer for Canadian regulations.
    The entire mapping in Sections 4-5 assumes NIST structure can host provincial and federal duties without distortion.
  • domain assumption Canadian AI requirements are predominantly additive rather than conflicting, with only two potential conflicts identified.
    Section 3.4 states conflicting requirements are minimal; if this legal reading is wrong, the unified-control approach breaks down.
  • domain assumption The 127 extracted requirements and their categorization are complete and accurate.
    Section 3.1 reports structured coding but provides no codebook, inter-rater reliability, or full requirement list in the body; incomplete extraction would invalidate coverage claims.
  • domain assumption The reported 2025-2026 Canadian regulatory statuses (Bill C-27 death, Bill C-36, Manitoba Bill 51, PIPEDA findings, etc.) are accurate.
    Central to the framework's current applicability; unverifiable from the preprint alone.
  • standard math Chouldechova/Kleinberg fairness impossibility results apply to the fairness metric trade-offs discussed.
    Used in Section 4.7.1 to justify structured metric selection; accepted prior result.
invented entities (1)
  • SCITUS framework (three-layer architecture, 57-control catalog, compliance matrix) no independent evidence
    purpose: Unified multi-jurisdictional compliance management for Canadian AI systems
    No deployment, external audit, or independent evaluation is reported; its claimed advantages are exhibited only through author-constructed scenarios.

pith-pipeline@v1.3.0-alltime-deepseek · 39296 in / 9937 out tokens · 103485 ms · 2026-08-02T00:16:29.840015+00:00 · methodology

0 comments
read the original abstract

Canadian organizations deploying artificial intelligence systems face a fragmented regulatory landscape spanning federal requirements (the Treasury Board Directive on Automated Decision-Making) and divergent provincial regulations across Ontario, Quebec, Alberta, Manitoba, and British Columbia. The death of Bill C-27 (Artificial Intelligence and Data Act) in January 2025 - and the federal government's June 2026 confirmation that it will pursue targeted instruments rather than omnibus AI legislation - leaves organizations without unified compliance guidance. Global frameworks such as NIST AI RMF 1.0, the EU AI Act, and ISO/IEC 42001 provide valuable guidance but lack systematic methodologies for adaptation to multi-jurisdictional national contexts. We present SCITUS (Systematic Canadian Integration for Trustworthy and Unified Standards), a comprehensive framework adapting NIST AI RMF 1.0 to Canadian federal and provincial AI regulations simultaneously. SCITUS integrates seven trustworthy-AI characteristics enhanced for Canadian requirements, four core governance functions, a novel multi-jurisdictional compliance mapping methodology, and a versioned control catalog that has evolved from 31 controls (v1.0, June 2025) to 57 controls (v2.0, July 2026) in response to regulatory developments - including Canada's first regulatory findings on generative-AI training data - and the documented 2026 agentic-AI threat landscape. We demonstrate applicability through scenarios spanning federal government, provincial healthcare, and the private sector, and argue that systematic adaptation of NIST AI RMF to multi-jurisdictional requirements offers significant advantages over jurisdiction-by-jurisdiction compliance and provides a replicable model for other federal systems.

Figures

Figures reproduced from arXiv: 2607.15051 by Mohammad Etemad.

Figure 1
Figure 1. Figure 1: Layered reference architecture for SCITUS compliance: governance and compliance [PITH_FULL_IMAGE:figures/full_fig_p039_1.png] view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

49 extracted references · 2 linked inside Pith

  1. [2]

    Bill C-27: Digital Charter Implementation Act, 2022,

    Parliament of Canada, “Bill C-27: Digital Charter Implementation Act, 2022,” Died on Order Paper, Jan. 2025

  2. [3]

    Artificial Intelligence Risk Management Framework (AI RMF 1.0),

    National Institute of Standards and Technology, “Artificial Intelligence Risk Management Framework (AI RMF 1.0),” NIST AI 100-1, U.S. Department of Commerce, Jan. 2023. doi: 10.6028/NIST.AI.100-1

  3. [4]

    Regulation (EU) 2024/1689 on Artificial Intelligence (AI Act),

    European Parliament and Council of the European Union, “Regulation (EU) 2024/1689 on Artificial Intelligence (AI Act),” Official Journal of the European Union, Aug. 2024. [Online]. Available: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

  4. [5]

    ISO/IEC 42001:2023 - Information Technology - Artificial Intelligence - Management Systems,

    International Organization for Standardization, “ISO/IEC 42001:2023 - Information Technology - Artificial Intelligence - Management Systems,” ISO/IEC, Dec. 2023. [Online]. Available: https: //www.iso.org/standard/42001

  5. [6]

    Algorithmic Impact Assessment Tool,

    Treasury Board of Canada Secretariat, “Algorithmic Impact Assessment Tool,” Government of Canada, 2023. [Online]. Available: https://www.canada.ca/en/government/system/digital-govern ment/digital-government-innovations/responsible-use-ai/algorithmic-impact-assessment.html

  6. [7]

    Bill 194: Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024,

    Legislative Assembly of Ontario, “Bill 194: Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024,” Statutes of Ontario, Chapter 24, Royal Assent Nov. 25, 2024

  7. [8]

    An Act to modernize legislative provisions as regards the protection of personal information (Law 25),

    National Assembly of Quebec, “An Act to modernize legislative provisions as regards the protection of personal information (Law 25),” Quebec, Canada, in force Sept. 22, 2023

  8. [9]

    Bill 33: Protection of Privacy Act,

    Legislative Assembly of Alberta, “Bill 33: Protection of Privacy Act,” Royal Assent Dec. 5, 2024; in force June 11, 2025 (Alta Reg 132/2025)

  9. [10]

    Bill 34: Access to Information Act,

    Legislative Assembly of Alberta, “Bill 34: Access to Information Act,” Royal Assent Dec. 5, 2024; in force June 11, 2025 (Alta Reg 133/2025)

  10. [11]

    Canada: Bill C-27 dies after Parliament is prorogued,

    DataGuidance, “Canada: Bill C-27 dies after Parliament is prorogued,” Jan. 2025. [Online]. Available: https://www.dataguidance.com/news/canada-bill-c-27-dies-after-parliament-prorogued

  11. [12]

    Personal Information Protection and Electronic Documents Act (PIPEDA),

    Parliament of Canada, “Personal Information Protection and Electronic Documents Act (PIPEDA),” 2000. [Online]. Available: https://laws-lois.justice.gc.ca/eng/acts/p-8.6/

  12. [13]

    Medical Devices Incorporating Artificial Intelligence,

    Health Canada, “Medical Devices Incorporating Artificial Intelligence,” Regulatory Guidance,

  13. [14]

    ISO/IEC 23894:2023 - Information Technology - Artificial Intelligence - Guidance on Risk Management,

    International Organization for Standardization, “ISO/IEC 23894:2023 - Information Technology - Artificial Intelligence - Guidance on Risk Management,” ISO/IEC, Feb. 2023. [Online]. Available: https://www.iso.org/standard/77304.html

  14. [15]

    ISO/IEC 42001: a new standard for AI governance,

    KPMG Switzerland, “ISO/IEC 42001: a new standard for AI governance,” 2024. [Online]. Available: https://kpmg.com/ch/en/insights/artificial-intelligence/iso-iec-42001.html

  15. [16]

    ISO 42001 Standard for AI Governance and Risk Management,

    Deloitte US, “ISO 42001 Standard for AI Governance and Risk Management,” 2024. [Online]. Available: https://www.deloitte.com/us/en/services/consulting/articles/iso-42001-standard-ai- governance-risk-management.html

  16. [17]

    ISO 23894 Explained: AI Risk Management Made Simple,

    Stendard, “ISO 23894 Explained: AI Risk Management Made Simple,” 2024. [Online]. Available: https://stendard.com/en-sg/blog/iso-23894/ 67

  17. [18]

    OECD Principles on Artificial Intelligence,

    Organisation for Economic Co-operation and Development, “OECD Principles on Artificial Intelligence,” OECD Legal Instruments, adopted May 22, 2019, updated May 2024. [Online]. Available: https://www.oecd.org/en/topics/sub-issues/ai-principles.html

  18. [19]

    Between Innovation and Oversight: A Cross-Regional Study of AI Risk Management Frameworks in the EU, U.S., UK, and China,

    A. Al-Maamari, “Between Innovation and Oversight: A Cross-Regional Study of AI Risk Management Frameworks in the EU, U.S., UK, and China,” arXiv preprint arXiv:2503.05773, Feb. 2025. [Online]. Available: https://arxiv.org/abs/2503.05773

  19. [20]

    Global AI Governance: Where the Challenge is the Solution - An Interdisci- plinary, Multilateral, and Vertically Coordinated Approach,

    Multiple Authors, “Global AI Governance: Where the Challenge is the Solution - An Interdisci- plinary, Multilateral, and Vertically Coordinated Approach,” arXiv preprint arXiv:2503.04766, 2025. [Online]. Available: https://arxiv.org/html/2503.04766v1

  20. [21]

    From principles to practice: a novel matrix for evaluating AI-powered learning platforms based on the UNESCO Ethical Impact Assessment tool,

    Multiple Authors, “From principles to practice: a novel matrix for evaluating AI-powered learning platforms based on the UNESCO Ethical Impact Assessment tool,” Frontiers in Education, Frontiers, 2025. [Online]. Available: https://www.frontiersin.org/journals/education/articles/10.3 389/feduc.2025.1640780/full

  21. [22]

    AI Governance in a Complex and Rapidly Changing Regulatory Landscape: A Global Perspective,

    Multiple Authors, “AI Governance in a Complex and Rapidly Changing Regulatory Landscape: A Global Perspective,” Humanities and Social Sciences Communications, Nature Portfolio, vol. 11, no. 1, Sept. 2024. doi: 10.1057/s41599-024-03560-x

  22. [23]

    Bill C-27: Timeline of developments,

    Gowling WLG, “Bill C-27: Timeline of developments,” 2024. [Online]. Available: https: //gowlingwlg.com/en-ca/insights-resources/articles/2024/bill-c27-timeline-of-developments

  23. [24]

    Looking ahead: the Canadian privacy and AI landscape without Bill C-27,

    Torys LLP, “Looking ahead: the Canadian privacy and AI landscape without Bill C-27,” Legal Insights, Jan. 2025. [Online]. Available: https://www.torys.com/our-latest-thinking/publications/ 2025/01/the-canadian-privacy-and-ai-landscape-without-bill-c-27

  24. [25]

    Ontario’s Public Sector Cyber Security Legislation Receives Royal Assent,

    Fasken Martineau DuMoulin LLP, “Ontario’s Public Sector Cyber Security Legislation Receives Royal Assent,” Legal Analysis, Nov. 2024. [Online]. Available: https://www.fasken.com/en/knowle dge/2024/12/ontarios-public-sector-cyber-security-legislation-receives-royal-assent

  25. [26]

    Quebec’s Law 25: What Is It and What Do You Need to Know?,

    OneTrust, “Quebec’s Law 25: What Is It and What Do You Need to Know?,” Blog Post, 2023. [Online]. Available: https://www.onetrust.com/blog/quebecs-law-25-what-is-it-and-what-do-you- need-to-know/

  26. [27]

    Algorithmic Transparency in Canada: From Commitments to Practice,

    S. Barriball and V. Gautrais, “Algorithmic Transparency in Canada: From Commitments to Practice,” Canadian Journal of Law and Technology, 2024

  27. [28]

    Pan-Canadian Artificial Intelligence Strategy,

    CIFAR, “Pan-Canadian Artificial Intelligence Strategy,” Canadian Institute for Advanced Research, 2017 (renewed 2022). [Online]. Available: https://cifar.ca/ai/

  28. [29]

    AI Governance Research Program,

    Vector Institute, “AI Governance Research Program,” Toronto, Canada, 2024. [Online]. Available: https://vectorinstitute.ai/

  29. [30]

    Montreal Declaration for a Responsible Development of Artificial Intelligence,

    Université de Montréal, “Montreal Declaration for a Responsible Development of Artificial Intelligence,” 2018. [Online]. Available: https://montrealdeclaration-responsibleai.com/

  30. [31]

    Artificial Intelligence and the Law: Privacy Challenges for Canadian Frameworks,

    T. Scassa, “Artificial Intelligence and the Law: Privacy Challenges for Canadian Frameworks,” 2020

  31. [32]

    Privacy and Administrative Data in the Age of AI,

    T. Scassa, “Privacy and Administrative Data in the Age of AI,” 2023

  32. [33]

    Evitable Conflicts in Canadian AI Policy and Regulation,

    I. Kerr and K. Szilagyi, “Evitable Conflicts in Canadian AI Policy and Regulation,” 2021

  33. [34]

    Multi-Jurisdictional Complexity in Canadian AI Governance,

    M. Geist, “Multi-Jurisdictional Complexity in Canadian AI Governance,” 2023. 68

  34. [35]

    Ontario AI Commissioner Role,

    Government of Ontario, “Ontario AI Commissioner Role,” 2024

  35. [36]

    Quebec AI Ecosystem Strategy,

    Gouvernement du Québec, “Quebec AI Ecosystem Strategy,” 2023

  36. [37]

    Canada’s AI Ecosystem Framework,

    Innovation, Science and Economic Development Canada, “Canada’s AI Ecosystem Framework,” 2022

  37. [38]

    Advisory Council on Artificial Intelligence — Recommendations,

    Government of Canada, “Advisory Council on Artificial Intelligence — Recommendations,” 2023

  38. [39]

    AI for All: Canada’s National Artificial Intelligence Strategy,

    Innovation, Science and Economic Development Canada, “AI for All: Canada’s National Artificial Intelligence Strategy,” Government of Canada, June 4, 2026. [Online]. Available: https: //www.canada.ca/en/innovation-science-economic-development/news/2026/06/minister-solomon- highlights-canadas-national-artificial-intelligence.html

  39. [40]

    Joint Investigation of OpenAI OpCo, LLC,

    Office of the Privacy Commissioner of Canada, Commission d’accès à l’information du Québec, OIPC British Columbia, and OIPC Alberta, “Joint Investigation of OpenAI OpCo, LLC,” PIPEDA Findings #2026-002, May 6, 2026. [Online]. Available: https://www.priv.gc.ca/en/opc-actions-and- decisions/investigations/investigations-into-businesses/2026/pipeda-2026-002/

  40. [41]

    Bill C-36: An Act to enact the Protecting Privacy and Consumer Data Act,

    Parliament of Canada, “Bill C-36: An Act to enact the Protecting Privacy and Consumer Data Act,” 45th Parliament, 1st Session, First Reading June 15, 2026. [Online]. Available: https://www.parl.ca/legisinfo/en/bill/45-1/c-36

  41. [42]

    Bill 51: The Public Sector Artificial Intelligence and Cybersecurity Governance Act,

    Legislative Assembly of Manitoba, “Bill 51: The Public Sector Artificial Intelligence and Cybersecurity Governance Act,” Royal Assent June 1, 2026. [Online]. Available: https://web2.gov .mb.ca/bills/43-3/b051e.php

  42. [43]

    Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile,

    C. Autio, R. Schwartz, J. Dunietz, S. Jain, M. Stanley, E. Tabassi, P. Hall, and K. Roberts, “Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile,” NIST AI 600-1, National Institute of Standards and Technology, July 2024. doi: 10.6028/NIST.AI.600-1

  43. [44]

    Careful Adoption of Agentic AI Services,

    CISA, NSA, ASD ACSC, Canadian Centre for Cyber Security, NCSC-NZ, and NCSC-UK, “Careful Adoption of Agentic AI Services,” Joint Guidance, May 1, 2026. [Online]. Available: https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services

  44. [45]

    AI Agent Standards Initiative,

    National Institute of Standards and Technology, “AI Agent Standards Initiative,” February 17,

  45. [46]

    Hiroshima AI Process Reporting Framework v2.0,

    OECD, “Hiroshima AI Process Reporting Framework v2.0,” G7 Digital & Tech Ministerial, May 28, 2026. [Online]. Available: https://oecd.ai/

  46. [47]

    International AI Safety Report 2026,

    Y. Bengio et al., “International AI Safety Report 2026,” 2nd ed., February 3, 2026. [Online]. Available: https://internationalaisafetyreport.org/

  47. [48]

    Digital Omnibus on AI — Amend- ment of Regulation (EU) 2024/1689,

    Council of the European Union and European Parliament, “Digital Omnibus on AI — Amend- ment of Regulation (EU) 2024/1689,” adopted June 29, 2026. [Online]. Available: https: //www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council- gives-final-green-light-to-simplify-and-streamline-rules/ Appendix A: SCITUS Multi-Jurisd...

  48. [2024]

    Available: https://www.canada.ca/en/health-canada/services/drugs-health- products/medical-devices.html

    [Online]. Available: https://www.canada.ca/en/health-canada/services/drugs-health- products/medical-devices.html

  49. [2026]

    Available: https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative

    [Online]. Available: https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative