AI Governance in Financial Services: The Deadline Is Already Set
The Artificial Intelligence and Data Act died with Bill C-27 when Parliament was prorogued in January 2025, and it has not been reintroduced. In June 2026 the federal government launched a national AI strategy, AI for All, which is a strategy and not a statute.
Plenty of Canadian financial institutions read that sequence as breathing room. It is the opposite. While the legislation stalled, the supervisors moved, and one of them has already set a date: OSFI Guideline E-23 on model risk management takes effect on 1 May 2027.
TL;DR
- No AI statute, and obligations anyway. They arrive as supervisory expectations, not legislation, and they carry fixed dates.
- Your AI is already a model. E-23 defines a model to include AI and machine learning methods, so this is not a new discipline. It is your existing model inventory, missing entries.
- 1 May 2027 is the date. Published 11 September 2025, with an 18-month transition that is now most of the way gone.
- Securities registrants have a separate track in CSA Staff Notice 11-348, and a firm can sit under both.
- The lifecycle has five stages and the one firms skip is decommission, which is also where stale models quietly keep making decisions.
- The hard part is the inventory, not the policy. Most institutions can write the policy in a fortnight and cannot list what it applies to.
Start by counting, not by drafting
The instinct when a governance deadline appears is to write a policy. It is the wrong first move, and it is wrong for a boring reason: a policy applies to a population, and almost nobody can name the population.
Ask a Canadian financial institution for a complete list of the AI systems it runs and you will usually get the ones procured as AI. Missing from that list, reliably: models inside vendor platforms bought for something else, scoring logic a team built in a spreadsheet, a fraud rule set that was upgraded to machine learning three years ago and never re-classified, and whatever a business unit is quietly running through a general-purpose assistant.
E-23 closes that gap by definition rather than by enumeration. It defines a model as “An application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI/ML methods, which processes input data to generate results.” The phrase to sit with is including AI/ML methods. AI is not a new category beside your models. It is inside the category you already govern.
So your AI is already a model. That reframe does more than tidy the language. It tells you which function owns this, which committee it reports to, which documentation standard applies, and which inventory has the hole in it. An institution with mature model risk management does not need to build a parallel AI governance function. It needs to find the entries that were never registered.
What E-23 actually asks for
Guideline E-23 was published on 11 September 2025 and takes effect on 1 May 2027, following an 18-month transition. It applies to banks, foreign bank branches, life insurance and fraternal companies, property and casualty companies, and trust and loan companies.
It asks for an enterprise-wide, risk-based governance framework covering each stage of a model’s life, with policies and procedures attached to each. Proportionality is built in, which matters more than it sounds: the expectation scales with the risk a model carries, so a pricing model and an internal document classifier are not held to one standard. That is the provision that makes the guideline workable, and it is also the provision firms most often fail to use, because applying it requires having rated the models, which requires the inventory again.
The lifecycle runs in five stages.
Decommission deserves the attention it rarely gets. A model that was retired in intent but not in production keeps producing results, keeps feeding downstream systems, and keeps being defensible right up until somebody asks when it was last reviewed. Every other stage has a natural trigger. This one only happens if someone owns it.
Worth keeping
- Do the inventory before the policy. The policy is easy and it is useless without a population.
- Proportionality is available and requires risk-rating, so rating the inventory is what unlocks it.
- Give decommission an owner. It is the only lifecycle stage with no natural trigger.
The other track, for anyone registered in securities
Institutions often sit under more than one supervisor, and the securities track is written differently.
CSA Staff Notice and Consultation 11-348, published 5 December 2024, sets out how existing securities law applies to AI systems in capital markets. It is staff guidance rather than a rule, and it opens from a principle worth quoting because it is frequently misread in both directions: “Securities laws are generally technology-neutral and apply regardless of the technology being used to carry out a given activity. However, applying technology-neutral laws does not mean that all technology can be treated in the same way.”
Technology-neutral does not mean nothing changes. It means the obligation does not change while the work required to meet it does.
The notice ties explainability directly to record keeping, saying AI systems used by registrants “should provide an appropriate degree of explainability so that registered firms are able to meet applicable record keeping requirements”, and it flags that lower-explainability systems may challenge transparency, accountability, record keeping and auditability. It also draws the line that decides most vendor conversations: support activities such as data processing and report generation can be outsourced, and registerable activity cannot.
The use-case side of that notice, including where staff say AI cannot substitute for a registered individual, is covered in AI use cases in investment management.
Two frameworks the regulators actually produced
Canadian supervisors have not only written expectations. They have run a multi-year industry forum and published what came out of it, which is useful because it shows the direction of travel rather than only the current line.
The first Financial Industry Forum on Artificial Intelligence produced the EDGE principles: Explainability, Data, Governance and Ethics.
The second, run as four workshops between May and November 2025 and published on 23 March 2026 by OSFI with the Global Risk Institute, produced AGILE:
Stay ahead of AI-driven risks by understanding how the technologies reshape the risk landscape.
Make best practice regular practice, with strong controls and data-integrity standards.
Adopt an AI growth mindset that treats AI as a driver of competitiveness.
Build AI skills at every level of the organization, including employees and management.
Fortify system-wide defences through improved third-party oversight.
The workshops covered security and cybersecurity, financial crime, financial stability, and financial well-being and consumer protection. Read the letter that surprises you. For most institutions that is Innovation, because it is unusual to see a supervisor-convened forum treat under-adoption as a risk worth naming alongside the others.
What supervisors already know about adoption
In a joint risk report published on 24 September 2024, OSFI and the Financial Consumer Agency of Canada reported that roughly 30% of financial institutions used AI in 2019 and roughly 50% did in 2023, and that 70% were expected to be using it by 2026. Seventy-five percent of the institutions that responded to their questionnaire planned to invest in AI over the following three years.
Two cautions on those numbers, because both matter. The 2026 figure is a forecast made in 2024, and this article is being read in 2026, so it describes an expectation rather than an observation. And the survey is of institutions that responded.
The same report named the most common uses as operational efficiency, customer engagement, document creation and fraud detection, and the top risks as data privacy and security, model risk, legal risk and business risk.
That combination is the whole governance problem in one line. The common uses are mundane and the named risks are structural, which means the exposure builds through ordinary work rather than through a flagship project anyone is watching.
Worth keeping
- Supervisors have been measuring adoption since before the guidance landed. They are not starting from zero when they ask.
- The most common uses are unremarkable, which is exactly why the inventory is incomplete.
- Model risk sits in the top four named risks, and E-23 is the instrument aimed at it.
Seven mistakes that cost the most
- Waiting for the legislation. Why it fails: AIDA died in January 2025 and the obligations arrived from supervisors instead, with a date attached. Better: work to E-23 and the guidance that applies to your registrations, and treat any future statute as an addition.
- Building an AI governance function beside model risk management. Why it fails: E-23's definition of a model already includes AI and machine learning methods, so a parallel function duplicates the committee, the documentation and the argument. Better: extend the discipline you have.
- Writing the policy first. Why it fails: a policy without a complete inventory governs the systems you remembered. Better: inventory, risk-rate, then write to what you found.
- Counting only the things procured as AI. Why it fails: the largest category is usually AI arriving inside platforms bought for another purpose. Better: ask what the system decides, not what the vendor calls it.
- Ignoring proportionality. Why it fails: holding every model to the highest standard exhausts the team and slows the low-risk work that would have built capability. Better: rate the inventory and apply effort where the risk sits.
- Treating explainability as a technical preference. Why it fails: in the securities track it is tied to record-keeping obligations, so a system you cannot reconstruct is a compliance exposure rather than an engineering inconvenience. Better: make it a selection criterion before purchase.
- Assuming the vendor carries the risk. Why it fails: oversight of third parties is named explicitly in both tracks, and in the securities notice the registrant remains accountable for outsourced functions. Better: write down what you verified and how often you re-verify.
What this article does not claim
It does not tell you that any product, platform or vendor is compliant with E-23. Nothing can have a compliance record against a guideline that takes effect on 1 May 2027, and a claim otherwise should be treated as marketing.
It does not summarise privacy, human rights or consumer protection obligations, all of which bite on AI systems and none of which are covered here. It does not cover the rules of the Canadian Investment Regulatory Organization, which apply to its members in addition to those made by securities regulators.
And it is not legal advice. It is a description of what has been published, with dates, so that a plan can be built against something firmer than a general sense that regulation is coming.
Check current status before relying on any of it. Regulatory material is the one class of claim that expires on a schedule.
Glossary
- Model
- Under E-23, an application of theoretical, empirical, judgmental assumptions or statistical techniques, including AI and machine learning methods, which processes input data to generate results.
- Model risk management
- The discipline of governing models across their life, covering design, independent review, deployment, monitoring and retirement.
- FRFI
- Federally regulated financial institution. The population E-23 applies to, including banks, foreign bank branches, life and fraternal insurers, property and casualty insurers, and trust and loan companies.
- Proportionality
- Scaling governance effort to the risk a model carries, rather than applying one standard to every model.
- Model drift
- Degradation in a model's performance over time as live conditions diverge from the conditions it was built on.
- Explainability
- The ability of a person to understand and explain how a system produced a given output, including which factors were used and their weight.
- Decommission
- Deliberate retirement of a model from production, including its downstream dependencies. The lifecycle stage with no natural trigger.
- Staff notice
- Published guidance from regulatory staff on how existing law applies. It is not a rule, and it signals the approach a review is likely to take.
Questions boards are asking
Is there an AI law in Canada that applies to us?
There is no federal AI statute in force. AIDA died with Bill C-27 at prorogation in January 2025 and has not been reintroduced, and the June 2026 AI for All announcement is a national strategy rather than legislation. The obligations that bind financial institutions today come from supervisors and from existing law, including privacy law.
When do we have to be ready for E-23?
1 May 2027. It was published on 11 September 2025 with an 18-month transition, so the runway is already substantially consumed.
Does E-23 apply to us?
It applies to federally regulated financial institutions: banks, foreign bank branches, life insurance and fraternal companies, property and casualty companies, and trust and loan companies. Provincially regulated institutions and securities registrants have their own supervisors, and many organizations sit under more than one.
Do generative AI assistants count as models?
Ask whether the system processes input data to generate results that inform a decision. The definition in E-23 is written around function rather than product category, and it names AI and machine learning methods explicitly. Where a tool is used to produce output that feeds a decision, the safe assumption is that it belongs in the inventory.
Where should we start with six months of runway?
The inventory, then a risk rating, then the gaps that rating exposes. Policy drafting is fast once the population is known, and slow to fix if it was written against the wrong one.
Do we need a separate AI governance committee?
Usually not. If model risk management already has a governance route, extending it is faster than standing up a parallel structure, and it avoids two bodies disagreeing about the same system.
What do supervisors expect on third-party AI?
Oversight that does not stop at the contract. Ecosystem resiliency in the AGILE framework is specifically about third-party oversight, and in the securities track a registrant remains responsible and accountable for outsourced functions and is expected to supervise on an ongoing basis.
The work that actually starts this
Every institution reading this can write an AI policy. Very few can hand a supervisor a complete, risk-rated list of the systems that policy would govern, and that list is what the 2027 date is really asking for.
Start there. It is unglamorous, it takes weeks rather than days, and it is the only part of this that cannot be compressed later.