---
title: "Final Report to the AI Strategy Task Force"
authors: taylor-owen
date: 2026-01-22
doi: 10.66536/ai-strategy-task-force-final-report_2026
pdf: /files/publications/ai-strategy-task-force-final-report.pdf
permalink: https://mediatechdemocracy.com/en/publications/ai-strategy-task-force-final-report_2026/
---

# **Final Report to the AI Strategy Task Force Submitted by: Taylor Owen[1](#page-0-0)**

As part of the Federal Government's AI Strategy Task Force I was asked to provide input on the theme of Safe AI & Public Trust. Given the broad nature of this topic, I have chosen to focus this report on what I believe are core imperatives of democratic governance: ensuring that AI systems and other digital technologies used by Canadians are safe, contribute to the health of our democratic society, and are governed in ways that sustain public confidence. In what follows, I recommend a series of policies to achieve these goals organized into three priority areas (Citizen Safety, Information Ecosystem Integrity, and Democratic Legitimacy), most of which could be implemented through two existing federal governance frameworks:

- An amended version of the *Online Harms Act* that includes AI platforms within its scope;
- An amended version of the *Consumer Privacy Protection Act*.

By leveraging these frameworks, the Canadian government could ground its approach to AI governance in best international practices, move swiftly to ensure that Canadians are protected from immediate harms that AI systems pose,[2](#page-0-1) and facilitate safe AI innovation and adoption.[3](#page-0-2) Given low levels of trust in AI amongst Canadians,[4](#page-0-3) legitimate concerns about its safety, and genuine uncertainty over how it will affect our economy and society, effective governance is imperative to solidifying Canadians' collective confidence in a future of Canada that is increasingly reliant on and intertwined with AI development, research, and implementation. Without this confidence, a sovereign AI innovation and adoption agenda is fraught with risk that undermines the government's investments in AI and the public's trust that it will do so responsibly.

The research centre I founded at McGill University seeks to better understand these complex systems, and to help citizens and their democratic governments maximize the benefits and minimize the harms posed by digital technologies, including AI. Through academic and policy research, years of public consultation, and close relationships with expert partners, we have built a deep empirical understanding of the impacts of the digital ecosystem on Canadians, and the policy mechanisms that advance a uniquely Canadian mix of public priorities for digital governance. This memo's perspectives grow out of that work, while also drawing from other

<span id="page-0-0"></span><sup>1</sup> Beaverbrook Chair in Media, Ethics and Communication in the Max Bell School of Public Policy, and Founding Director of the Centre for Media, Technology and Democracy, McGill University. This memo was written in collaboration with Helen A. Hayes, Associate Director, Policy, Centre for Media, Technology and Democracy.

<span id="page-0-1"></span><sup>2</sup> These harms, outlined below, include individual harms like race and gender-based stereotyping and collective harms, including the amplification of mis- and dis-information.

<span id="page-0-2"></span><sup>3</sup> Canada's G7 presidency in 2025 presents a unique opportunity to translate international commitments—such as the [G7 Leaders' Statement on AI for Prosperity](https://g7.canada.ca/en/news-and-media/news/g7-leaders-statement-on-ai-for-prosperity/)—into concrete domestic policies that meet the highest standards for safety and democratic values.

<span id="page-0-3"></span><sup>4</sup> According to KPMG's [Trust, attitudes and use of artificial intelligence: A global study 2025,](https://assets.kpmg.com/content/dam/kpmgsites/xx/pdf/2025/05/trust-attitudes-and-use-of-ai-global-report.pdf) Canada ranks among the lowest globally in perceived trustworthiness of AI systems, with only 46% of respondents expressing trust. Similarly, Telus' [Human-centric AI, perspectives on trust and the future of AI](https://downloads.ctfassets.net/fltupc9ltp8m/51TEjleIztP6dlEdLoj8qN/5f0008e1d9aede6843394e7453535f5f/TELUS_2025_AI_Report_-_EN.pdf) report finds that 70% of Canadians believe AI poses serious risks that society is not adequately prepared to address, and, notably, that only 1% of Canadians trust AI to operate independently.

expert scholars and civil society organizations; investigations into AI systems by international regulators; and statements and policy commitments made by governments around the world.

In summary, my opinion is that:

- 1. AI systems are increasingly embedded in Canadians' daily lives, shaping what we see,[5](#page-1-0) the work we do,[6](#page-1-1) the decisions we make,[7](#page-1-2) and the services we access.[8](#page-1-3) These systems mediate how citizens access information,[9](#page-1-4) engage with public institutions,[10](#page-1-5) and make decisions that shape their social and economic lives. This adoption is moving at a historically unprecedented rate.
- 2. For some, AI tools, particularly generative, conversational, and agentic systems, can enhance creativity,[11](#page-1-6) facilitate learning,[12](#page-1-7) and provide accessible forms of interaction or selfexpression.[13](#page-1-8)
- 3. For many others, AI systems pose significant risks and harms. Empirical studies have documented instances where AI chatbots, for example, fail to respond appropriately to users experiencing mental health crises,[14](#page-1-9) reinforce cognitive distortions through mirroring language,[15](#page-1-10) and cultivate a false sense of emotional reciprocity.[16](#page-1-11) Beyond individual wellbeing, AI systems have also been shown to amplify mis- and dis-information,[17](#page-1-12) enable non-consensual image generation[18](#page-1-13) and impersonation,[19](#page-1-14) perpetuate race- and gender-based stereotyping and inequalities,[20](#page-1-15) and manipulate users through data-driven optimization for engagement.[21](#page-1-16)
- 4. Public concern about AI in Canada is widespread and deeply held: only 32% of Canadians believe that the benefits of AI outweigh the risks,[22](#page-1-17) 89% worry about their privacy,[23](#page-1-18) 78% fear that AI will spread false information during elections,[24](#page-1-19) and 70% are concerned about their children accessing AI chatbots.[25](#page-1-20) In the 2025 election, polling we conducted at the

<span id="page-1-2"></span><sup>7</sup> [Levy et al. 2021;](https://www.annualreviews.org/content/journals/10.1146/annurev-lawsocsci-041221-023808) [Lang 2021;](https://heinonline.org/HOL/Page?handle=hein.journals/lexel26&div=20&g_sent=1&casa_token=JSibzbDYEKgAAAAA:J6fORqxReMFll3PAZ5lEOhQmxuAmZdka4pjAtUiBW-FDseuWrp98L5XtRoad5ygZO0XUL0o7NA&collection=journals) [Sumer 2024](https://heinonline.org/hol-cgi-bin/get_pdf.cgi?handle=hein.journals/dgtlr6§ion=9&casa_token=2HEAloTSVQ4AAAAA:2AoIj0GyTwhdyMJirMKCGA3SNNrE9QLR5BHhSrI-tOMeX3uqJZS-mYLl2vdOrYw6PNAqhOPM4A) 

<span id="page-1-0"></span><sup>5</sup> [Guess et al. 2023;](https://www.science.org/doi/abs/10.1126/science.abp9364) [Cinelli et al. 2021](https://www.pnas.org/doi/abs/10.1073/pnas.2023301118)

<span id="page-1-1"></span><sup>6</sup> [KPMG 2025.](https://assets.kpmg.com/content/dam/kpmgsites/xx/pdf/2025/05/trust-attitudes-and-use-of-ai-global-report.pdf)

<span id="page-1-3"></span><sup>8</sup> [Pham et al. 2024;](https://journals.sagepub.com/doi/full/10.1177/21582440241300007) [Ashraf et al. 2024;](https://publichealth.jmir.org/2024/1/e53086/) [Sollapur et al. 2024](https://ieeexplore.ieee.org/abstract/document/10725302?casa_token=OgS70S4I58gAAAAA:65L2DrdSC3rBVDKXkZnAoDffJfEUH4AArSHYB9XRHxK_yDFdXoH2ssm0xbao4aKYir2SUXQy2w)

<span id="page-1-4"></span><sup>9</sup> [Brown et al. 2024;](https://journals.sagepub.com/doi/full/10.1177/20563051241234691) [Edelson et al. 2025](https://dl.acm.org/doi/abs/10.1145/3757327)

<span id="page-1-5"></span><sup>10</sup> [Frangoudes et al. 2021;](https://link.springer.com/chapter/10.1007/978-3-030-77943-6_11) [Senadheera et al. 2024](https://www.tandfonline.com/doi/full/10.1080/10630732.2023.2297665#d1e290)

<span id="page-1-6"></span><sup>11</sup> [Agboola and Yassin 2025;](https://link.springer.com/chapter/10.1007/978-3-031-95901-1_4) [Chandrasekara et al. 2024](https://journals.sagepub.com/doi/full/10.1177/14780771241254637?casa_token=tN56gANFYLkAAAAA%3AdJRxlWjdKr2YokwFZ5218k_lCH0W3lJlXps0YaiXZUOkxRppvyfqJmY4hQkltIcFNnPtKf2VD_suvg)

<span id="page-1-7"></span><sup>12</sup> [Chiu and Rospigliosi 2025;](https://www.tandfonline.com/doi/full/10.1080/10494820.2025.2471199) [Aluko et al. 2025](https://www.emerald.com/ijoa/article-abstract/doi/10.1108/IJOA-07-2024-4632/1258226/Exploring-the-effectiveness-of-AI-generated)

<span id="page-1-8"></span><sup>13</sup> [Chemnad and Othman 2024;](https://www.frontiersin.org/journals/artificial-intelligence/articles/10.3389/frai.2024.1349668/full) [Penuela et al. 2024](https://dl.acm.org/doi/full/10.1145/3613904.3642211)

<span id="page-1-9"></span><sup>14</sup> [De Freitas et al. 2023;](https://myscp.onlinelibrary.wiley.com/doi/abs/10.1002/jcpy.1393) [Dergaa et al. 2024](https://www.frontiersin.org/journals/psychiatry/articles/10.3389/fpsyt.2023.1277756/full)

<span id="page-1-10"></span><sup>15</sup> [Alabad et al. 2024 ;](https://docs.google.com/document/d/16uRpD82VbqsjrhKAYl9K-3GnL9tckQ_aRLyy3NjZhDg/edit?tab=t.0) [Yankouskaya et al. 2025](https://link.springer.com/article/10.1007/s44230-025-00090-w)

<span id="page-1-11"></span><sup>16</sup> [Zhang et al. 2025;](https://dl.acm.org/doi/full/10.1145/3706598.3713429) [Laestadius et al. 2022;](https://journals.sagepub.com/doi/full/10.1177/14614448221142007?casa_token=kag45Vd9smoAAAAA%3Acq6KcidsqwR0qhULaXT4PJ8WawsTAB8rxnh0DoeIWdKPso-wNJmjzb3QHP1Y3yl-QoUfeUvoyiEPYg) [Li and Zhang 2024](https://academic.oup.com/jcmc/article/29/5/zmae015/7742812)

<span id="page-1-12"></span><sup>17</sup> [Canadian Digital Media Research Network 2025;](https://www.cdmrn.ca/ai-generated-fake-news) [Wack et al. 2025](https://academic.oup.com/pnasnexus/article/4/4/pgaf083/8097936)

<span id="page-1-13"></span><sup>18</sup> [Hawkins et al. 2025;](https://dl.acm.org/doi/full/10.1145/3715275.3732107) [Umbach et al. 2024](https://dl.acm.org/doi/full/10.1145/3613904.3642382) 

<span id="page-1-14"></span><sup>19</sup> [Tariq et al. 2022;](https://dl.acm.org/doi/abs/10.1145/3485447.3512212?casa_token=qOW3rX-rzCkAAAAA:xudkH0xiZWwIxwyfbhbUJ8lNUmn-EdWT_aR-7hYv6wQ4Cl2HwQPcT3S9VUXjaQiNj17k23CixuiQpw) [Jasserand 2024](https://ieeexplore.ieee.org/abstract/document/10786729?casa_token=QhMiV85g0owAAAAA:_b7D_1JI_iZ5mKCKRk5cbHLf74b9cEnTiSx_rlQTNY0gPY3E4cSVoifBXUwSuoQtat3gKAcJHQ)

<span id="page-1-15"></span><sup>20</sup> [Scheuerman et al. 2020;](https://dl.acm.org/doi/10.1145/3392866) [Omiye, J. A. et al. 2023](https://www.nature.com/articles/s41746-023-00939-z)

<span id="page-1-16"></span><sup>21</sup> [Du and Sen 2023;](https://journals.sagepub.com/doi/abs/10.1177/07439156231186573) [Roberts and David 2025](https://www.liebertpub.com/doi/full/10.1089/cyber.2024.0338)

<span id="page-1-17"></span><sup>22</sup> [KPMG 2025.](https://assets.kpmg.com/content/dam/kpmgsites/xx/pdf/2025/05/trust-attitudes-and-use-of-ai-global-report.pdf)

<span id="page-1-18"></span><sup>23</sup> [Office of the Privacy Commissioner of Canada, 2025.](https://www.priv.gc.ca/en/opc-actions-and-decisions/research/explore-privacy-research/2025/por_ca_2024-25/)

<span id="page-1-19"></span><sup>24</sup> [Leger 2025.](https://leger360.com/views-on-artificial-intelligence/)

<span id="page-1-20"></span><sup>25</sup> [Leger 2025.](https://leger360.com/views-on-artificial-intelligence/)

- Centre found that one in four Canadians encountered fake news sites, and that 80% of Canadians were concerned about AI-generated, misleading content.[26](#page-2-0)
- 5. These harms originate from the structural dynamics of AI systems, which are shaped by corporate and economic incentives that govern their design, deployment, and diffusion. These conditions are largely insulated from democratic oversight.
- 6. Without this oversight, Canadians' trust in AI systems will remain low. 88% of Canadians support stronger governance of AI systems,[27](#page-2-1) 85% want government oversight to ensure ethical and safe use,[28](#page-2-2) and 80% believe that there should be penalties for AI-generated disinformation.[29](#page-2-3)
- 7. If technical solutions do not make AI more trustworthy or the public does not perceive AI to be trustworthy despite those technical solutions, then trust must instead be built in the democratic infrastructure that governs AI. So, Canada's democratic institutions need to be capable of holding AI companies to account if and when they are irresponsible.
- 8. Canada is not alone in this: governments around the world[30](#page-2-4) are beginning to enact legislation that addresses the structures, design, and incentives of AI and other digital technologies. They recognise that digital sovereignty[31](#page-2-5) demands not just infrastructure, but also governance. Canada can learn from these and other best practices.
- 9. International precedent has demonstrated that effective AI governance does not necessarily require generalized AI legislation (such as the previous government's *Artificial Intelligence and Data Act*), but can at least initially be achieved through a range of existing and targeted policy mechanisms.
- 10. In Canada, there are two existing governance frameworks that could be quickly implemented by Canada's federal government to address the root causes of AI harm and promote safer systems: 1) an amended and re-introduced version of the *Online Harms Act*  that includes AI platforms within its scope; and, 2) an amended and re-introduced version of the *Consumer Privacy Protection Act.*
- 11. While these governance frameworks will require policy iteration and innovation over time and may at some point fall short and demand stand-alone AI regulation, it is imperative that the Canadian government build a foundation of AI policy capacity. Doing so will ensure the baseline democratic accountability that Canadians rightly demand, and provide the time for a next phase of public consultation and policy iteration and design.

<span id="page-2-0"></span><sup>26</sup> [The Canadian Digital Media Research Network 2025.](https://www.cdmrn.ca/publications/the-canadianinformation-ecosystem-during-the-2025-federal-election)

<span id="page-2-1"></span><sup>27</sup> [Telus 2025.](https://downloads.ctfassets.net/fltupc9ltp8m/51TEjleIztP6dlEdLoj8qN/5f0008e1d9aede6843394e7453535f5f/TELUS_2025_AI_Report_-_EN.pdf)

<span id="page-2-2"></span><sup>28</sup> [Leger 2025.](https://leger360.com/views-on-artificial-intelligence/)

<span id="page-2-3"></span><sup>29</sup> [The Canadian Digital Media Research Network 2025.](https://www.cdmrn.ca/publications/the-canadianinformation-ecosystem-during-the-2025-federal-election)

<span id="page-2-4"></span><sup>30</sup> Across Europe, the democratic global south, and at the US state-level.

<span id="page-2-5"></span><sup>31</sup> Canada's digital ecosystem and infrastructures are largely determined by foreign platforms, rules, and shareholder value. This leaves Canadian institutions and citizens vulnerable to the incentives of powerful, unpredictable, and uncontrollable foreign forces, and threatens Canada's digital sovereignty.

### **Summary of Policy Recommendations and Implementation Tactics**

|                                                                       | Citizen Safety                                                   | Info Ecosystem Integrity                                  | Democratic Legitimacy                                                                                          |
|-----------------------------------------------------------------------|------------------------------------------------------------------|-----------------------------------------------------------|----------------------------------------------------------------------------------------------------------------|
| Amended and<br>Re-introduced<br>Online Harms<br>Act                   | Digital Safety Commission<br>(1.1)32<br>Systemic Risk Governance | Monitoring and Data<br>Sharing (2.2)35                    | Recourse Mechanisms<br>(3.2)36                                                                                 |
|                                                                       | (1.2)33<br>Age-Appropriate Design<br>(1.3)34                     |                                                           |                                                                                                                |
| Amended and<br>Re-introduced<br>Consumer<br>Privacy<br>Protection Act |                                                                  | AI Identification and<br>Provenance Disclosure<br>(2.1)37 | Data Portability,<br>Interoperability, and<br>Right to Deletion (3.1)38<br>User Empowerment<br>Support (3.2)39 |
| Other<br>Measures                                                     |                                                                  | Reliable Information<br>Production (2.3)40                | Mandated Consultation<br>Mechanisms (3.3)41                                                                    |

<span id="page-3-0"></span><sup>32</sup> The Digital Safety Commission would have authority to: 1.1.1) regulate data access; 1.1.2) conduct algorithmic audits; and, 1.13) enforce compliance by issuing orders, penalties, and corrective action plans.

<span id="page-3-1"></span><sup>33</sup> This would include three duties to: 1.2.1) act responsibly; 1.2.2) protect children; and, 1.2.3) make certain content inaccessible. It should also minimize users' exposure to other forms of harmful content, including fraud and scam content.

<span id="page-3-2"></span><sup>34</sup> This requires heightened safety and design standards, overseen by the Digital Safety Commission, including: 1.3.1) child-impact assessments; 1.3.2) default high-privacy settings; and 1.3.3) crisis-response protocols for conversational systems.

<span id="page-3-3"></span><sup>35</sup> At a minimum, this includes: 2.2.1) mandated data inventories of AI system inputs and outputs; 2.2.2) secure researcher access frameworks for data on social media and consumer chatbot use and algorithmic design, facilitated by an independent monitoring or observatory body; and, 2.2.3) confidentiality-safe data enclaves for public-interest research.

<span id="page-3-4"></span><sup>36</sup> This would involve 3.2.1) establishing a statutory AI and Digital Safety Ombudsperson within the Digital Safety Commission.

<span id="page-3-5"></span><sup>37</sup> This should include: 2.2.1) visible labelling; 2.2.2) provenance metadata and digital watermarking; and, 2.2.3) source transparency requirements.

<span id="page-3-6"></span><sup>38</sup> This should include: 3.1.1) interoperable data standards; 3.1.2) user-initiated data mobility rights; 3.1.3) public disclosure of interoperability specifications, and, 3.1.4) mandated right to deletion for users.

<span id="page-3-7"></span><sup>39</sup> This include: 3.2.2) mandatory human review of consequential automated decisions; and, 3.2.3) public reporting obligations.

<span id="page-3-8"></span><sup>40</sup> The government could: 2.3.1) consider adapting existing journalistic support mechanism to, and develop new programs for, a broader range of journalistic content creators and reliable content generations forms; 2.3.2) support new sovereign, decentralized infrastructure for public interest media; and, 2.3.3) actively engage in domestic and international efforts to transition the journalism sector to a new AI-driven mediated information ecosystem.

<span id="page-3-9"></span><sup>41</sup> This could include: 3.3.1) standing citizens' assemblies or deliberative panels; 3.3.2) structured partnerships between civil society organizations and academic researchers; and 3.3.3) mandated and regularly held advisory councils.

### **Democratic Priority 1: Citizen Safety**

One of the most fundamental obligations of a democratic government is to ensure the safety and security of its citizens.[42](#page-4-0) As new AI technologies enter the Canadian market,[43](#page-4-1) this responsibility extends to ensuring that they do not expose individuals or communities to preventable harms. On this measure, Canada has fallen short. While the decision to delay comprehensive AI legislation may reflect a desire for measured policy development, the absence of enforceable safety obligations has left Canadians under protected in a rapidly evolving digital marketplace.[44](#page-4-2) The core challenge is not merely technological, but structural: AI systems are being designed, deployed, and monetized by private actors who bear little legal responsibility for the risks their systems create. Addressing this requires moving beyond voluntary ethics frameworks and industry self-regulation toward binding legal mechanisms that assign clear accountability and remedies. In order to protect Canadians from AI harms, the government should consider:

**1.1 Independent Regulatory Authority.** The asymmetry between global technology firms and national governments (both in technical capacity and access to information) makes independent regulatory authority not a procedural detail but a democratic necessity. Canada should create a single, empowered institution responsible for coordinating national digital governance (i.e., social media and consumer-facing AI) through new online harms legislation. This Digital Safety Commission[45](#page-4-3) would have authority to: 1.1.1) mandate data access;[46](#page-4-4) 1.1.2) conduct algorithmic audits;[47](#page-4-5) and 1.1.3) enforce compliance by issuing orders, penalties, and corrective action plans.[48](#page-4-6)

**1.2 Systemic Risk Governance.** The Digital Safety Commission, as proposed in Part 1 of the *Online Harms Act*, should adopt a systems-level duty of care for AI systems (once scoped in), which 1.2.1) obliges providers to assess and mitigate systemic risks before and after deployment (*duty to act responsibly)*; [49](#page-4-7) 1.2.2) requires heightened protections for minors (*duty to protect* 

<span id="page-4-0"></span><sup>42</sup> [Anderljung et al. 2023;](https://arxiv.org/pdf/2307.03718) [Coeckelbergh 2024](https://link.springer.com/article/10.1007/s43681-024-00492-9)

<span id="page-4-1"></span><sup>43</sup> [Benchetrit 2025;](https://www.cbc.ca/news/business/open-ai-canada-data-centres-digital-sovereignty-9.6935195) [Steven 2025](https://www.cbc.ca/news/politics/ai-canada-regulations-innovators-researchers-9.6935017)

<span id="page-4-2"></span><sup>44</sup> [Competition Bureau 2025;](https://competition-bureau.canada.ca/en/how-we-foster-competition/education-and-outreach/publications/canadian-digital-regulators-forum-synthetic-media-digital-landscape#sec02) [Du and Sen 2023](https://journals.sagepub.com/doi/abs/10.1177/07439156231186573)

<span id="page-4-3"></span><sup>45</sup> In addition to the establishment of a Digital Safety Commission, it is also important for the Government of Canada to have a central digital governance coordinating capacity in order to overcome the soloing of digital polices between departments. In addition, it is critical that the Digital Safety Commission, the Office of the Privacy Commissioner of Canada and the Competition Bureau be empowered to share data and collaborate.

<span id="page-4-4"></span><sup>46</sup> This can be accomplished by applying sections 73-77 of Bill C-63, which provides mechanisms for a Commission to grant access to inventories and electronic data of the operators of social media services.

<span id="page-4-5"></span><sup>47</sup> The EU's [Digital Services Act](https://commission.europa.eu/strategy-and-policy/priorities-2019-2024/europe-fit-digital-age/digital-services-act_en) Article 37 requires very large online platforms to contract an independent auditor to assess compliance. In Canada, this function could be filled by a designated Commission, rather than left to independent auditors, such as the proposed Digital Safety Commission in Bill C-63.

<span id="page-4-6"></span><sup>48</sup> These powers are assigned to the Digital Safety Commission in Bill C-63.

<span id="page-4-7"></span><sup>49</sup> This can be accomplished by adapting Bill C-63, Section 54: operators "must implement measures that are adequate to mitigate the risk that users of the regulated service will be exposed to harmful content on the service." The EU's AI Act [Article 51](https://artificialintelligenceact.eu/article/51/) further provides definitions and obligations for operators of general-purpose AI models that entail systemic risk.

*children*);[50](#page-5-0) and, 1.2.3) mandates categorical removal of certain categories of content and updating of models,[51](#page-5-1) including child sexual abuse material and non-consensual intimate images (*duty to make certain content inaccessible).[52](#page-5-2)* Beyond this, systemic risk governance should also minimize users' exposure to other forms of harmful content, including fraud and scam content.[53](#page-5-3)

**1.3 Age-Appropriate Design.** Democratic societies have distinct obligations to protect children and youth in digital environments.[54](#page-5-4) Beyond content-based governance mechanisms, this requires heightened safety and design standards, overseen by the Digital Safety Commission, including: 1.3.1) child-impact assessments;[55](#page-5-5) 1.3.2) default high-privacy settings;[56](#page-5-6) and, 1.3.3) crisis-response protocols for conversational systems.[57](#page-5-7)

## **Democratic Priority 2: Information Ecosystem Integrity**

Democratic societies demand access to reliable information. AI is reshaping our information ecosystem in two ways: it is used to determine our personalised feeds of content,[58](#page-5-8) and is increasingly creating content itself.[59](#page-5-9) In the near future, the majority of what we see online may

<span id="page-5-0"></span><sup>50</sup> This can be accomplished by adapting Bill C-63, Section 65: "an operator must integrate into a regulated service that it operates any design features respecting the protection of children, such as age-appropriate design, that are provided by regulations." The EU's AI Act also obligates operators to identify and address unique vulnerabilities of minors on digital platforms. [California Senate Bill 243](https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243) additionally requires special protections for minors using chatbot platforms. The UK's [Online Safety Act](https://www.gov.uk/government/collections/online-safety-act) includes specific provisions for child safety, such as requiring platforms to use effective age assurance to prevent children from accessing harmful content.

<span id="page-5-1"></span><sup>51</sup> Examples of this include: the EU's [Digital Services Act](https://commission.europa.eu/strategy-and-policy/priorities-2019-2024/europe-fit-digital-age/digital-services-act_en) requirement for platforms to remove or disable access to illegal content and [easily enable users to flag](https://www.reuters.com/sustainability/boards-policy-regulation/eu-preliminarily-finds-meta-tiktok-breach-transparency-obligations-2025-10-24/) such content; the UK's [Online Safety Act](https://www.gov.uk/government/collections/online-safety-act) requirement that platforms remove [illegal content,](https://www.ofcom.org.uk/siteassets/resources/documents/online-safety/information-for-industry/illegal-harms/overview-of-illegal-harms.pdf?v=390985) including fraud, incitement of violence, and content that promotes suicide[. Luccioni et al.,](https://arxiv.org/abs/2111.04424)  [2022.](https://arxiv.org/abs/2111.04424)

<span id="page-5-2"></span><sup>52</sup> This can be accomplished by adapting Bill C-63, Sections 67-71, which obligates operators of regulated service to remove content that "sexually victimizes a child or revictimizes a survivor or intimate content communicated without consent" within 24 hours of identification.

<span id="page-5-3"></span><sup>53</sup> This can be accomplished by adapting Bill C-63, Section 54: operators "must implement measures that are adequate to mitigate the risk that users of the regulated service will be exposed to harmful content on the service" and by adding online scams and fraud as a category of harm.

<span id="page-5-4"></span><sup>54</sup> The [UN Committee on the Rights of the Child's General Comment No. 25](https://www.ohchr.org/en/documents/general-comments-and-recommendations/general-comment-no-25-2021-childrens-rights-relation) clarifies that Canada's obligation to protect children's rights applies in the digital world, which explicitly encompasses AI technologies; This further contributes to the global consensus that children's rights must be protected in the age of AI, as reflected in th[e UN](https://5rightsfoundation.com/resource/governing-ai-for-humanity/)  High-[Level Advisory Body on AI's 'Governing AI for Humanity'](https://5rightsfoundation.com/resource/governing-ai-for-humanity/), [UN General Assembly resolution 78/187 on the](https://docs.un.org/A/RES/78/187)  [Rights of the child in the digital environment,](https://docs.un.org/A/RES/78/187) and [UNICEF's Policy guidance on AI for children](https://www.unicef.org/innocenti/reports/policy-guidance-ai-children).

<span id="page-5-5"></span><sup>55</sup> These assessments should be designed around the "best interests of the child". See [UNCRC General comment No.](https://www.ohchr.org/en/documents/general-comments-and-recommendations/general-comment-no-25-2021-childrens-rights-relation)  [25, paras. 23 and 38,](https://www.ohchr.org/en/documents/general-comments-and-recommendations/general-comment-no-25-2021-childrens-rights-relation) the Canadia[n Department of Justice, Child Rights Impact Assessment tool and e-learning](https://www.justice.gc.ca/eng/csj-sjc/cria-erde/index.html)  [course,](https://www.justice.gc.ca/eng/csj-sjc/cria-erde/index.html) and [UNICEF, Assessing child rights impacts in relation to the digital environment.](https://www.unicef.org/childrightsandbusiness/workstreams/responsible-technology/D-CRIA)

<span id="page-5-6"></span><sup>56</sup> This aligns with the Resolution of the Federal, Provincial and Territorial Privacy Commissioners and Ombuds with Responsibility for Privacy Oversight "[Putting best interests of young people at the forefront of privacy and](https://www.priv.gc.ca/en/about-the-opc/what-we-do/provincial-and-territorial-collaboration/joint-resolutions-with-provinces-and-territories/res_231005_01/)  [access to personal information](https://www.priv.gc.ca/en/about-the-opc/what-we-do/provincial-and-territorial-collaboration/joint-resolutions-with-provinces-and-territories/res_231005_01/)"; the [Roundtable of G7 Data Protection and Privacy Authorities Statement on AI and](https://www.priv.gc.ca/en/opc-news/speeches-and-statements/2024/s-d_g7_20241011_child-ai/)  [Children;](https://www.priv.gc.ca/en/opc-news/speeches-and-statements/2024/s-d_g7_20241011_child-ai/) and the [Sweep Report 2024: Deceptive Design Patterns.](https://www.priv.gc.ca/en/about-the-opc/what-we-do/international-collaboration/international-privacy-networks/international-privacy-sweep/2024_sweep/opc-sweep-report-2024/)

<span id="page-5-7"></span><sup>57</sup> Examples of this include[s California Senate Bill 243](https://legiscan.com/CA/text/SB243/id/3273344), which obligates conversational AI platforms to maintain "a protocol for preventing the production of suicidal ideation, suicide, or self-harm content to the user" and issue crisis service provider referral notifications when needed.

<span id="page-5-8"></span><sup>58</sup> [Brown et al. 2024;](https://journals.sagepub.com/doi/full/10.1177/20563051241234691) [Edelson et al. 2025](https://dl.acm.org/doi/abs/10.1145/3757327)

<span id="page-5-9"></span><sup>59</sup> [Wei and Tyson 2024;](https://dl.acm.org/doi/abs/10.1145/3664647.3680631?casa_token=UL-FbvyC4RQAAAAA:DFWuyLskSvB3eSWTqestzodCTE58Rd93Yn6eVIr75yvGzHbp0TO0JVBYPan-f9bpiQ2XUheAoEkIlQ) [DiResta and Goldstein 2024](https://arxiv.org/abs/2403.12838)

be both selected and created by AI.[60](#page-6-0) This raises acute challenges for democratic societies, particularly regarding electoral integrity. AI systems can now produce and circulate synthetic political content,[61](#page-6-1) impersonations,[62](#page-6-2) and deepfakes at unprecedented speed. Ensuring the transparency of these systems and the reliability of content they prioritize and generate must be a priority for democratic societies. In order to ensure information ecosystem integrity, the government should consider:

- **2.1. AI Identification and Provenance Disclosure**. Citizens should have the right to know when they are interacting with or consuming content produced by an AI system. This requires a multi-layered identification regime that mandates clear disclosure in both human and machinereadable formats. At a minimum, a re-introduced and amended *Consumer Privacy Protection Act*  should include: 2.1.1) visible labelling;[63](#page-6-3) 2.1.2) provenance metadata and digital watermarking;[64](#page-6-4) and, 2.1.3) source transparency requirements, including training data.[65](#page-6-5)
- **2.2 Monitoring and Data Sharing with Researchers and Civil Society.** Addressing the power asymmetry between private platforms and the public, and ensuring that researchers, journalists, and civil society organizations can study the effects of AI systems, requires statutory mechanisms given to the Digital Safety Commission for data access, transparency, and independent oversight. At a minimum, this includes: 2.2.1) mandated data inventories of AI system inputs and outputs;[66](#page-6-6) 2.2.2) secure researcher access frameworks for data on social media and consumer chatbot use and algorithmic design, facilitated by an independent monitoring or observatory body;[67](#page-6-7) and 2.2.3) confidentiality-safe data enclaves for public-interest research.[68](#page-6-8)

<span id="page-6-0"></span><sup>60</sup> [Kreps and Kriner 2023;](https://muse.jhu.edu/article/907693) [Birrer 2024](https://journals.sagepub.com/doi/full/10.1177/14614448241253138)

<span id="page-6-1"></span><sup>61</sup> Examples in Canada include the [Kirkland Lake Bot Incident](https://www.cdmrn.ca/kirkland-lake-bot-campaign) and th[e emergence of AI-generated ads](https://www.cdmrn.ca/ai-generated-fake-news) masquerading as legitimate news sources during the 2025 Federal Election.

<span id="page-6-2"></span><sup>62</sup> [Leong et al. 2024;](https://ieeexplore.ieee.org/abstract/document/10674334) [Lyngaas 2025](https://www.cnn.com/2025/07/12/politics/fake-ai-calls-us-officials)

<span id="page-6-4"></span><span id="page-6-3"></span><sup>63</sup> California's [Senate Bill 243](https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243) requires that conversational AI systems issue periodic, in-context notifications to remind users that they are interacting with an automated agent, with heightened requirements for mental health and companion chatbots; [South Korea's Artificial Intelligence \(AI\) Basic Act](https://www.trade.gov/market-intelligence/south-korea-artificial-intelligence-ai-basic-act) requires labelling or generative AI content. <sup>64</sup> The EU's [AI Act](https://artificialintelligenceact.eu/) (article 50) establishes mandatory disclosure when users interact with an AI system and requires providers of generative AI to implement technical measures such as watermarking or metadata tagging that signal synthetic content.

<span id="page-6-5"></span><sup>65</sup> This can be achieved through the Consumer Privacy Protection Act or through the transparency provision of the Online Harms Act should AI systems be brought into scope. Other examples of legislation with AI transparency provisions include Australia's [Data Availability and Transparency Act](https://www.legislation.gov.au/C2022A00011/latest/text), the EU's [AI Act](https://artificialintelligenceact.eu/), and Japan's [Act on](https://www.japaneselawtranslation.go.jp/ja/laws/view/4532/en)  [Improving and Fairness of Digital Platforms.](https://www.japaneselawtranslation.go.jp/ja/laws/view/4532/en) 

<span id="page-6-6"></span><sup>66</sup> The EU's [AI Act \(a](https://artificialintelligenceact.eu/article/10/)rticle 10) mandates developers of high-risk systems must maintain detailed records and evaluations of training and testing datasets.

<span id="page-6-7"></span><sup>67</sup> This can be achieved through Sections 73-74 of Bill C-63, which outlines access to electronic data by accredited researchers.

<span id="page-6-8"></span><sup>68</sup> This can be achieved by amending Part 1, Sections 73-74 of Bill C-63 or introducing a stand-alone Act to allow persons engaged in public interest research to request access to inventories of electronic data that are included in digital safety plans. Other examples of legislation with similar provisions include that EU AI Act's [Article 57,](https://artificialintelligenceact.eu/article/57/) which establishes "AI regulatory sandboxes" for controlled testing of AI and the EU's Digital Services Act [Article 40](https://www.eu-digital-services-act.com/Digital_Services_Act_Article_40.html) which obligates very large online platforms to provide vetted researchers with access to platform data for systemicrisk research under secure conditions.

**2.3 Support for Reliable Information Production**. As AI-generated content saturates digital spaces,[69](#page-7-0) supply-side measures are essential to preserve and promote the production of reliable, evidence-based information in an increasingly AI mediated and created information ecosystem. Policies in this domain are less developed, however, the government could: 2.3.1) consider adapting existing journalistic support mechanism to, and develop new programs for, a broader range of journalistic content creators and reliable content generations forms;[70](#page-7-1) 2.3.2) support new sovereign, decentralized infrastructure for public interest media; and, 2.3.3) actively engage in domestic and international efforts to transition the journalism sector to a new AI-driven mediated information ecosystem.[71](#page-7-2)

### **Democratic Priority 3: Democratic Legitimacy**

In a democratic society, citizens must have meaningful agency in determining the development and governance of the AI infrastructure that shapes their lives. Rebuilding democratic legitimacy in the age of AI therefore requires more than public consultation; it demands institutional pathways that are built for meaningful participation, agency and autonomy, and accountability. This includes mechanisms through which citizens can contest automated decisions,[72](#page-7-3) assert control over their data,[73](#page-7-4) and contribute to the governance of AI itself.[74](#page-7-5) In order to ensure the democratic legitimacy of AI systems, the government should consider:

**3.1 Data Portability, Interoperability, and Right to Deletion**. Empowering citizens also means restoring their control over their personal data. In our current information economy, data mobility is not simply a matter of convenience, but is a structural determinant of citizens' autonomy.[75](#page-7-6) Together, portability and interoperability provide the technical and legal architecture through which citizens can reclaim agency over their data[76](#page-7-7) and reduce the concentration of informational power.[77](#page-7-8) To do so, amendments to the *Consumer Privacy* 

<span id="page-7-0"></span><sup>69</sup> [Birrer 2024;](https://journals.sagepub.com/doi/full/10.1177/14614448241253138) [Chen et al. 2025](https://dl.acm.org/doi/full/10.1145/3720553.3746675)

<span id="page-7-1"></span><sup>70</sup> Such as the [Local Journalism Initiative,](https://www.canada.ca/en/canadian-heritage/services/funding/local-journalism-initiative.html) th[e Online News Act](https://www.canada.ca/en/canadian-heritage/services/online-news.html) and the [Media Fund.](https://cmf-fmc.ca/)

<span id="page-7-2"></span><sup>71</sup> Examples include[:](https://ifpim.org/how-we-work) [International Fund for Public Interest Media,](https://ifpim.org/how-we-work) [Media Forward Fund,](https://allianzfoundation.org/media-forward-fund/) [Public Media Bridge Fund.](https://publicmedia.co/bridge-fund/)

<span id="page-7-3"></span><sup>72</sup> The EU's General Data Protection Regulation [Article 22](https://gdpr-info.eu/art-22-gdpr/) grants individuals the right "not to be subject to a decision based solely on automated processing", and allows them to request human review and contest decisions. The EU's AI Act [Article 86](https://artificialintelligenceact.eu/article/86/) further allows individuals affected by AI systems to lodge complaints with national authorities and receive information about how decisions were made.

<span id="page-7-4"></span><sup>73</sup> This can be accomplished by applying sections 62, 63, and 72 of Bill C-27, which requires organizations to disclose the use of individual data in automated decision systems, provide explanations of decisions with "significant impact" on individuals, and "disclose the personal information that it has collected from the individual to an organization designated by the individual" upon request.

<span id="page-7-5"></span><sup>74</sup> Examples of this include regular citizen assemblies on AI policy and the creation of public transparency registers to allow civil society to monitor incidents and risks.

<span id="page-7-6"></span><sup>75</sup> The EU's Digital Markets Act [Article 6\(64\)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv:OJ.L_.2022.265.01.0001.01.ENG#006.007) explains that a "lack of interoperability allows gatekeepers that provide number-independent interpersonal communications services to benefit from strong network effects, which contributes to the weakening of contestability."

<span id="page-7-7"></span><sup>76</sup> [Walker and Milne 2024;](https://www.emerald.com/jrim/article-abstract/18/5/815/1237824/AI-driven-technology-and-privacy-the-value-of?redirectedFrom=fulltext) [Crabtree and Mortier 2016](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2874312)

<span id="page-7-8"></span><sup>77</sup> [Mantelero 2012;](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2048236) [Rahman 2018;](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3220737) [Zuboff 2015](https://journals.sagepub.com/doi/abs/10.1057/jit.2015.5)

*Protection Act* should include: 3.1.1) interoperable data standards;[78](#page-8-0) 3.1.2) user-initiated data mobility rights including social graph data;[79](#page-8-1) 3.1.3) public disclosure of interoperability specifications,[80](#page-8-2) and, 1.1.4) a mandated right to deletion for users.[81](#page-8-3)

- **3.2 Recourse Mechanisms and User Empowerment Support.** Citizens must have clear and accessible avenues for redress when AI systems cause or exacerbate individual and collective harms. Establishing recourse mechanisms ensures procedural fairness by enabling users to challenge automated decisions, demand explanation, and seek remedies. The amended and reintroduced *Online Harms Act* should include: 3.2.1) a statutory AI and Digital Safety Ombudsperson[82](#page-8-4) within the Digital Safety Commission, who is empowered to receive complaints, investigate harms, and provide users with informational resources, including literacy materials. The amended Consumer Privacy Protection Act should include: 3.2.2) mandatory human review of consequential automated decisions;[83](#page-8-5) and, 3.2.3) public reporting obligations.[84](#page-8-6)
- **3.3 Mandated Consultation Mechanisms.** This will institutionalize democratic input into the design and oversight of AI policy. This could include: 3.3.1) standing citizens' assemblies or deliberative panels, composed of demographically representative participants;[85](#page-8-7) 3.3.2) structured partnerships between civil society organizations and academic researchers to promote cogovernance and value-chain governance;[86](#page-8-8) and 3.3.3) mandated and regularly held advisory councils, such as with youth and Indigenous stakeholders.[87](#page-8-9)

<span id="page-8-0"></span><sup>78</sup> The EU Digital Markets Act [Article 6](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv:OJ.L_.2022.265.01.0001.01.ENG#006.007) mandates that gatekeeper operating systems provide "effective interoperability for third party services," and in all cases, "the gatekeeper and the requesting provider should ensure that interoperability does not undermine a high level of security and data protection in line with their obligations." <sup>79</sup> This can be accomplished by applying and expanding section 72 of the CPPA in Bill C-27, which grants individuals the right to request an organization to disclose their data to another organization.

<span id="page-8-2"></span><span id="page-8-1"></span><sup>80</sup> An example of this includes the EU's Digital Markets Act [Article 7,](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv:OJ.L_.2022.265.01.0001.01.ENG#006.007) which requires companies to allow "reasonable requests for interoperability" by providing technical interfaces and relevant information required to interoperate.

<span id="page-8-3"></span><sup>81</sup> The "right to erasure" originates in the EU's General Data Protection Regulation [Article 17.](https://gdpr-info.eu/art-17-gdpr/) This grants data subjects the right to request the prompt deletion of personal data held about them by a business organization. <sup>82</sup> This can be accomplished by applying and expanding the rights and duties afforded to the Digital Safety Ombudsperson proposed in Bill C-63, Sections 10-12.

<span id="page-8-5"></span><span id="page-8-4"></span><sup>83</sup> An example of this includes the EU's AI Act [Article 14,](https://artificialintelligenceact.eu/article/14/) which requires that high-risk AI systems be designed and developed in such a way that "they can be effectively overseen by natural persons,"

<span id="page-8-6"></span><sup>84</sup> This can be accomplished by applying and expanding section 62 of Bill C-27, which requires organizations to publicly disclose their data collection policies and account how automated decision systems are used for significant impact decisions, and section 62 of the Online Harms Act in Bill C-63, which requires operators to publish a digital safety plan online.

<span id="page-8-7"></span><sup>85</sup> Examples of these assemblies include Taiwan's standing [Alignment Assemblies,](https://www.thersa.org/rsa-journal/democracy-in-the-age-of-ai/) The Centre for Media, Technology and Democracy's [Youth Assembly on Digital Rights and Safety](https://digitalassembly.ca/), and Germany's [Artificial Intelligence](https://idpf.uni-wuppertal.de/en/projekte/artificial-intelligence-and-citizens-councils/)  [and Citizens Councils.](https://idpf.uni-wuppertal.de/en/projekte/artificial-intelligence-and-citizens-councils/)

<span id="page-8-8"></span><sup>86</sup> The United States has relied primarily on soft law and voluntary frameworks for AI governance, including NIST's [AI Risk Management Framework \(2023\)](https://www.nist.gov/itl/ai-risk-management-framework) and the [White House's Blueprint for an AI Bill of Rights \(2022\)](https://bidenwhitehouse.archives.gov/ostp/ai-bill-of-rights/), both which promote co-governance through extensive multi-stakeholder consultation.

<span id="page-8-9"></span><sup>87</sup> Examples of these councils include the [IPC's Youth Advisory Council](https://www.ipc.on.ca/en/about-us/ipcs-youth-advisory-council)[, The Digital Youth Advisory Committee,](https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/digital-youth-advisory-committee.html) the [OECD's Youthwise](https://www.oecd.org/en/about/programmes/youthwise.html), and th[e Global Indigenous Data Alliance.](https://www.gida-global.org/)