Law 25 Artificial Intelligence Rules: How Quebec Regulates AI
Law 25 artificial intelligence rules don't name AI directly, but automated decision-making, consent, and transfer rules apply. Here's what changes.
Quebec's Law 25 artificial intelligence framework doesn't mention "artificial intelligence" anywhere in its text. That's the first thing to understand, and the source of most confusion. What the law does regulate, automated decision-making, profiling, consent for personal information processing, and cross-border data transfers, covers nearly every practical AI deployment a Quebec organization is likely to run. If your law firm, clinic, or SMB is feeding client data into an AI tool, Law 25 already applies. The question isn't whether the law reaches your use case. It's whether your AI vendor's architecture lets you comply, which is exactly where many general-purpose AI tools fall short. For a broader look at which platforms clear that bar, see our review of AI tools that comply with Quebec's Law 25.
Section 12.1 and Law 25 automated decision-making: the provision that actually governs AI
Section 12.1, the core Law 25 automated decision-making clause, has been in force since September 2023. It requires that any organization using personal information to render a decision "based exclusively on an automated processing of such information" must inform the individual of that fact and, on request, explain the factors and parameters that led to the decision. Individuals also have the right to submit observations, and to have a member of the organization's staff review the decision. Transparency alone doesn't satisfy the section; the organization has to provide a route to contest the outcome.
This applies whether you're using AI to triage insurance claims, screen job applicants, or flag contract clauses for review. A law firm using AI to auto-reject NDA terms without human review sits squarely inside Section 12.1's scope.
Law 25's Section 12.1 doesn't ban automated decision-making. It bans automated decision-making without transparency, and it puts the burden of explanation on the organization, not the individual.
The practical requirement is straightforward: you need to be able to say, in plain language, what data went into a decision, how it was weighted, and how someone can push back on it. Black-box AI tools that can't produce this explanation create compliance exposure the first time a client files an access request under Section 12.1. Our post on AI governance platforms and Law 25 Quebec compliance covers what a defensible explanation workflow looks like in practice.
Consent still governs the training and inference pipeline
Separately from Section 12.1, Law 25 tightened consent requirements across the board. Sections 8 and 9 require that consent be requested in clear, specific language, separate from any other information provided to the person. These requirements predate the AI-specific provisions but apply directly to them.
If personal information is going into a prompt, a knowledge base, or a fine-tuning dataset, you need a lawful basis for that processing. A general engagement letter signed years ago is not that basis anymore.
- Consent must be granular, not bundled into a general privacy policy (Sections 8-9)
- Sensitive personal information (health, biometric, financial) requires explicit, not implied, consent
- Minors under 14 require parental consent under Section 4.1, with heightened protections for information collected from them
- Consent withdrawal must be as easy as consent given
This is where a lot of "just paste it into a chatbot" workflows quietly break down. The convenience of a general-purpose AI tool doesn't remove the consent obligation underneath it. It just makes the obligation easier to ignore until a CAI complaint or audit surfaces it.
Cross-border transfers: where Quebec organizations most often get Law 25 artificial intelligence compliance wrong
Section 17 requires a privacy impact assessment before transferring personal information outside Quebec, including to a service provider, including for processing by an AI model. The assessment must evaluate whether the information will receive protection equivalent to what Law 25 provides.
Jurisdiction becomes the whole conversation here. A US-headquartered AI vendor is subject to the US CLOUD Act, meaning US authorities can in principle compel data disclosure regardless of where servers physically sit. The CAI hasn't published a bright-line rule declaring US vendors automatically non-compliant, but that legal exposure is a material fact any Section 17 assessment has to document and weigh, particularly for privileged or sensitive files.
If your AI vendor has a US corporate parent, your Section 17 transfer assessment has to reckon with CLOUD Act exposure, a legal reality no amount of "our servers are in Canada" marketing language resolves on its own.
This is the gap a Canadian AI platform is designed to close. Augure operates with no US corporate parent, which removes the CLOUD Act question from the Section 17 transfer assessment, not because data never leaves Quebec, but because the entity handling it isn't subject to a foreign government's compelled-disclosure statute. Augure's model inference runs on Canadian infrastructure and vetted partners under contractual data retention limits, and the operating company sits under Canadian jurisdiction. Organizations should still document this analysis themselves rather than take any vendor's claims at face value; the Office of the Privacy Commissioner of Canada publishes guidance on cross-border data transfer assessments worth reviewing alongside CAI materials.
What this means for law firms specifically
Law firms carry an added layer: solicitor-client privilege. Feeding client files into a general-purpose AI tool for research or drafting assistance raises the question of whether that transfer weakens privilege, particularly if the vendor's terms of service permit use of inputs for model training.
The Barreau du Québec and law society guidance across Canadian jurisdictions increasingly treat AI tool selection as a due diligence question, not just a convenience decision. A firm that can't answer where a document goes and who can access it hasn't done the diligence Law 25 and professional conduct rules both expect.
Privilege doesn't survive a vague terms-of-service clause. If you can't articulate exactly who has access to a client document once it enters an AI tool, you can't confidently tell your client privilege is intact.
Augure Legal was built around this problem: contract review, NDA triage, and clause extraction with Law 25 (Sections 8, 9, 12.1, and 17) and PIPEDA compliance checks built into the workflow, running on infrastructure that doesn't introduce a foreign jurisdiction into the privilege analysis. For solo practitioners, that's a C$149/month decision that removes a recurring compliance question from every engagement. If you're building an internal breach response plan alongside this, our guide to AI data breach notification requirements in Canada covers the reporting timelines Law 25 and PIPEDA both impose.
PIPEDA and CPCSC: the layers above Law 25
Law 25 doesn't operate alone. Federally regulated Quebec organizations, and any business with data flows outside the province, also answer to PIPEDA, the federal Personal Information Protection and Electronic Documents Act. PIPEDA is built around ten fair information principles, and two matter most for AI deployments: Principle 4.3, which governs consent, and Principle 4.9, which governs an individual's right to access their own personal information held by an organization. The Office of the Privacy Commissioner of Canada enforces PIPEDA and can investigate complaints, audit compliance, and refer matters to Federal Court.
Quebec's private-sector regime is generally considered substantially similar to PIPEDA, which exempts most intra-Quebec commercial activity from PIPEDA's direct application. But overlap isn't identity. A compliance program built for Law 25 doesn't automatically satisfy PIPEDA the moment data crosses a provincial or national border, which is increasingly the default for cloud-hosted AI tools.
The Canadian Program for Cyber Security Certification (CPCSC) adds a further layer for organizations in defence supply chains or handling controlled goods. CPCSC sets cybersecurity maturity requirements that contractors and subcontractors must meet to bid on certain federal defence contracts, and it increasingly intersects with AI procurement decisions where vendor infrastructure and data handling practices come under scrutiny. Our detailed breakdown of CPCSC requirements for AI tooling walks through what that means for vendor vetting in practice.
- Law 25: Quebec private sector, automated decision-making (s. 12.1), consent (ss. 8-9), cross-border transfer assessments (s. 17), penal provisions up to C$25 million or 4% of worldwide turnover under Section 102
- PIPEDA: federal baseline, ten fair information principles including consent (4.3) and access (4.9), applies alongside Law 25 for interprovincial and international data flows
- CPCSC: supply chain and controlled-goods contexts, growing relevance for AI vendor vetting in defence-adjacent industries
An AI platform built with all three frameworks in mind, rather than retrofitted after a US privacy standard, saves a compliance team from stitching together three separate assessments for one tool. That's the architectural premise behind Augure: Law 25, PIPEDA, and CPCSC considerations built into the platform rather than bolted on. If you're documenting any of this for an internal audit trail, our piece on PIA documentation as a collaboration tool is a useful companion for turning these assessments into something a team can actually maintain.
The practical Quebec AI compliance checklist
Before deploying any AI tool with personal information in Quebec, a compliance-minded team should be able to answer:
- Can we explain, in plain language, any automated decision the AI contributes to, and can the affected person submit observations, per Section 12.1?
- Do we have specific, granular consent for the personal information involved under Sections 8-9, not a blanket policy?
- Have we completed a Section 17 transfer assessment, including CLOUD Act exposure if the vendor has a US parent?
- Can we produce a privacy impact assessment on request from the Commission d'accès à l'information?
- Does the vendor's data retention policy match what we've represented to clients?
- If the organization has federal or interprovincial data flows, have we separately confirmed PIPEDA's consent and access principles are met?
An honest "we're not sure" on any of these points isn't a legal-advice gap. It's an infrastructure gap, and the fix isn't a longer privacy policy. It's choosing tools where the answers are already yes by design.
Augure was built for exactly this checklist: a Canadian AI platform with no US corporate parent, documented data retention terms, and Law 25, PIPEDA, and CPCSC considerations built into the architecture rather than added after the fact. If your organization is working through what Law 25 artificial intelligence rules mean for AI adoption, augureai.ca is a reasonable place to start that conversation, or to end it by removing the question from your next vendor review.
About Augure
Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.