← Back to Insights
Compliance

How Law 25 applies to artificial intelligence in Quebec

Law 25 doesn't mention AI by name, but automated decision-making, consent, and cross-border transfer rules apply directly. Here's what changes.

By Augure·
a computer chip in the shape of a human head

Quebec's Law 25 doesn't mention "artificial intelligence" anywhere in its text. That's the first thing to understand, and the source of most confusion. What it does regulate — automated decision-making, profiling, consent for personal information processing, and cross-border data transfers — covers nearly every practical AI deployment a Quebec organization is likely to run. If your law firm, clinic, or SMB is feeding client data into an AI tool, Law 25 already applies. The question isn't whether the law reaches your use case. It's whether your AI vendor's architecture lets you comply, which is exactly where most US-built AI alternatives fall short.


Section 12.1: the automated decision-making provision that actually governs AI

Section 12.1, in force since September 2023, is the operative clause. It requires that any organization using personal information to render a decision "based exclusively on an automated processing of such information" must inform the individual of that fact — and, on request, explain the factors and parameters that led to the decision.

This applies whether you're using AI to triage insurance claims, screen job applicants, or flag contract clauses for review. A law firm using AI to auto-reject NDA terms without human review is squarely inside Section 12.1's scope.

Law 25's Section 12.1 doesn't ban automated decision-making. It bans automated decision-making without transparency, and it puts the burden of explanation on the organization, not the individual.

The practical requirement: you need to be able to say, in plain language, what data went into a decision and how it was weighted. Black-box AI tools that can't produce this explanation create direct compliance exposure under the CAI's enforcement powers — not hypothetically, but the first time a client files an access request under Section 12.1.


Consent still governs the training and inference pipeline

Separately from Section 12.1, Law 25 tightened consent requirements across the board. Sections 8 and 9 require that consent be requested in clear, specific language, separate from any other information provided to the person — requirements that predate the AI provisions but apply directly to them.

If personal information is going into a prompt, a knowledge base, or a fine-tuning dataset, you need a lawful basis for that processing. "The client signed a general engagement letter in 2019" is not that basis anymore.

  • Consent must be granular — not bundled into a general privacy policy (Sections 8–9)
  • Sensitive personal information (health, biometric, financial) requires explicit, not implied, consent
  • Minors' data has heightened protections under Section 4.1
  • Consent withdrawal must be as easy as consent given

This is where a lot of "just paste it into ChatGPT" workflows quietly break down. The convenience of a general-purpose AI tool doesn't remove the consent obligation underneath it — it just makes the obligation easier to ignore until a CAI complaint or audit surfaces it.


Cross-border transfers: the part most Quebec organizations get wrong

Section 17 requires a privacy impact assessment before transferring personal information outside Quebec — including to a service provider, including for processing by an AI model. The assessment must evaluate whether the information will receive protection equivalent to what Law 25 provides.

This is where jurisdiction becomes the whole conversation. A US-headquartered AI vendor is subject to the US CLOUD Act, meaning US authorities can compel data disclosure regardless of where the servers physically sit. That's a material fact your Section 17 assessment has to account for — and for many regulated files, it's disqualifying.

If your AI vendor has a US corporate parent, your Section 17 transfer assessment has to reckon with CLOUD Act exposure — a legal reality no amount of "our servers are in Canada" marketing language resolves.

This is precisely the gap a genuinely Canadian AI platform is built to close. Augure operates with no US corporate parent and no US investors, which removes the CLOUD Act question from the Section 17 transfer assessment entirely — not because data never leaves Quebec, but because the entity handling it isn't subject to a foreign government's compelled-disclosure statute. Inference for Augure's models runs on infrastructure in the EU under zero data retention terms, and the operating company itself sits squarely under Canadian jurisdiction.


What this means for law firms specifically

Law firms carry an added layer: solicitor-client privilege. Feeding client files into a general-purpose AI tool for research or drafting assistance raises the question of whether that transfer waives privilege, particularly if the vendor's terms of service permit use of inputs for model training.

The Barreau du Québec and Law Society guidance across Canadian jurisdictions increasingly treats AI tool selection as a due diligence question, not just a convenience decision. A firm that can't answer "where does this document go and who can access it" hasn't done the diligence Law 25 and professional conduct rules both expect.

Privilege doesn't survive a vague terms-of-service clause. If you can't articulate exactly who has access to a client document once it enters an AI tool, you can't confidently tell your client privilege is intact.

This is the specific problem Augure Legal was built to solve — contract review, NDA triage, and clause extraction with Law 25 (Sections 8, 9, 12.1, and 17) and PIPEDA compliance checks built into the workflow, running on infrastructure that doesn't introduce a foreign jurisdiction into the privilege analysis. For solo practitioners, that's a C$149/month decision that removes a recurring compliance question from every engagement.


PIPEDA and CPCSC: the layers above Law 25

Law 25 doesn't operate alone. Federally regulated Quebec organizations and any business with data flows outside the province also answer to PIPEDA's ten fair information principles, particularly Principle 4.3 (consent) and 4.9 (individual access). Quebec's private-sector regime is generally considered "substantially similar" to PIPEDA, but overlap isn't identity — a compliance program built for one doesn't automatically satisfy the other.

The Canadian Program for Cyber Security Certification (CPCSC) adds a further layer for organizations in defence supply chains or handling controlled goods, with its own requirements around data handling and vendor assessment that increasingly intersect with AI procurement decisions.

  • Law 25 — Quebec private sector, automated decision-making (s. 12.1), consent (ss. 8–9), cross-border transfer assessments (s. 17), penalties up to C$25M or 4% of worldwide turnover (s. 91)
  • PIPEDA — federal baseline, Principles 4.3 (consent) and 4.9 (access), applies alongside Law 25 for interprovincial and international data flows
  • CPCSC — supply chain and controlled-goods contexts, growing relevance for AI vendor vetting

An AI platform built with all three in mind, rather than retrofitted after a US privacy framework, saves a compliance team from stitching together three separate assessments for one tool. That's the architectural bet behind Augure — Law 25, PIPEDA, and CPCSC considerations built into the platform rather than bolted on.


The practical compliance checklist

Before deploying any AI tool with personal information in Quebec, a compliance-minded team should be able to answer:

  • Can we explain, in plain language, any automated decision the AI contributes to, per Section 12.1?
  • Do we have specific, granular consent for the personal information involved under Sections 8–9 — not a blanket policy?
  • Have we completed a Section 17 transfer assessment, including CLOUD Act exposure if the vendor has a US parent?
  • Can we produce a privacy impact assessment on request from the Commission d'accès à l'information?
  • Does the vendor's data retention policy match what we've represented to clients?

If any answer is "we're not sure," that's not a legal-advice gap — it's an infrastructure gap. The fix isn't a longer privacy policy. It's choosing tools where the answers are already yes by design.


Augure was built for exactly this checklist: a sovereign Canadian AI platform with no US corporate parent, zero data retention, and Law 25, PIPEDA, and CPCSC considerations built into the architecture rather than added after the fact. If your organization is navigating what Law 25 means for AI adoption, augureai.ca is a reasonable place to start the conversation — or to end it, quietly, by removing it from your next vendor review entirely.

A

About Augure

Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.

Ready to try sovereign AI?

Start free. No credit card required.

Get Started