A Bill That Moved Fast
Bill C-22, the Lawful Access Act, 2026, was tabled in the House of Commons on April 24, 2026. Fewer than two months later, on June 18, 2026, it passed third reading — after the government used a procedural motion, introduced June 15 and passed June 17, to compress the Standing Committee on Public Safety and National Security's clause-by-clause review and limit further amendments and debate (LEGISinfo). The bill received first reading in the Senate the same day; senators are not expected to take it up until they return on September 21, 2026.
Contrast that pace with the fate of Canada's last attempt at comprehensive AI legislation. The Artificial Intelligence and Data Act (AIDA), bundled into the omnibus Bill C-27, died on the order paper in January 2025 when Justin Trudeau prorogued Parliament amid his resignation announcement (IAPP). Eighteen months later, no replacement has been tabled. Ottawa still governs generative AI systems only through a 2023 voluntary code of conduct — guidance, not law.
The Encryption Fight Parliament Didn't Finish
Bill C-22 is a genuine expansion of state power: it creates new subscriber-data disclosure orders, expands technical-assistance obligations on "electronic service providers," and — the provision drawing the most sustained criticism — touches what companies must do when law enforcement or intelligence agencies demand access to encrypted communications. The Electronic Frontier Foundation called it a "dangerous surveillance bill" precisely because of how it moved: "With no serious debate, including on proposed amendments," the House pushed it through in its final days before summer recess (EFF).
That criticism has real backing. Privacy Commissioner Philippe Dufresne testified before the same committee and filed a formal statement on May 26, 2026 acknowledging that C-22 "improves on its predecessor, Bill C-2," while pressing for amendments where it still falls short. His central recommendation: tighten the definition of "systemic vulnerability" to explicitly cover "any action that would render systemic methods of authentication or encryption less effective," and bar regulations that would force a provider to introduce — or block a provider from patching — such a vulnerability, aligning Canada with Australia's comparable access law (Privacy Commissioner of Canada).
"Regulations and orders must not have the effect of requiring an electronic service provider to introduce — or of preventing an electronic service provider from rectifying — a systemic vulnerability."
The government's underlying case deserves a fair hearing before dismissal. Encrypted platforms genuinely complicate investigations into child exploitation, organized crime, and terrorism financing, and Canadian police agencies have argued for years — not without basis — that their legal toolkit hasn't kept pace with how criminals communicate now. A lawful-access regime with real judicial oversight isn't inherently illegitimate; several liberal democracies, including Australia, have built comparable frameworks. The problem with C-22 isn't its goal. It's that the amendment stage where encryption-specific safeguards get hashed out — the Commissioner's proposed fix among them — was the exact stage Parliament chose to compress.
Where That Leaves AI
Set against C-22's velocity, AIDA's death looks less like bad luck and more like a structural pattern. A lawful-access bill has an institutional owner — the Minister of Public Safety, backed by RCMP and CSIS operational demands — that can rewrite and refile it fast whenever the legislative calendar allows. A comprehensive AI statute has no equivalent champion: it requires reconciling industry competitiveness concerns, civil-society safety demands, provincial jurisdiction over most day-to-day AI applications, and a public that mostly hasn't settled on what it wants regulated. That coalition takes years to assemble and evaporates the moment Parliament prorogues.
Ottawa isn't idle on AI in the abstract — a February 2026 government consultation summary previewed possible future rules on safety evaluation, adversarial red-teaming, human-oversight mechanisms, and liability allocation across the AI supply chain. But "previewed" is the operative word. Nothing has been tabled, and nothing looks close.
What Proportionate Reform Would Actually Require
None of this means Canada should have rushed AIDA back the way it rushed C-22. AIDA's own drafting was criticized for vague "high-impact system" definitions left to future regulation — a due-process problem in its own right. The lesson isn't "legislate AI as fast as lawful access." It's that the same discipline should apply to both files: specific obligations defined in statute rather than deferred to regulators, and amendments tested in committee rather than waved through under time allocation.
On C-22 specifically, the Senate's fall sitting is the last realistic venue to fix what the Commons compressed. The Privacy Commissioner's systemic-vulnerability language is a narrow, technically precise amendment — not a wrecking-ball objection to lawful access as a concept — and senators should adopt it before the bill becomes law. On AI, the government should stop treating a "framework sometime in 2026" as a placeholder and actually table something, however narrower than AIDA's original scope, that gives industry a concrete target to design toward instead of a voluntary code with no enforcement teeth.