generic image squares of blue and pink above a blue background
Submissions
Canadian Bankers Association

CBA submission on the Government of Canada’s AI Transparency Consultation

Summary Points

Article

Overview

The Canadian Bankers Association (CBA)1 welcomes the opportunity to respond to the Government of Canada’s consultation on Enhancing trust in artificial intelligence through increased transparency. The CBA shares the Government’s objective of strengthening public trust in AI.

Canada’s banks are actively adopting AI to improve efficiency and customer outcomes, strengthen fraud detection and cybersecurity, and support competitiveness. The CBA and its members support the responsible development and use of AI within mature regulatory and risk-management frameworks.

Banks already manage AI‑related risks through established legal and supervisory frameworks, including the Bank Act’s Financial Consumer Protection Framework, applicable OSFI guidance on operational, technology, third‑party and model risk, and the Personal Information Protection and Electronic Documents Act (PIPEDA). These frameworks should remain the primary means of addressing AI‑related risks in the financial sector. The CBA does not see a demonstrated need for new, standalone AI‑specific transparency requirements for banks.

If the Government determines that additional rules or guidance are warranted, they should address a clearly demonstrated material gap, operate through existing sectoral frameworks and regulators, and avoid duplicating existing obligations or creating fragmented oversight. Any such measures should be risk-based and focused on uses that could materially affect individuals or reasonably mislead them. For example, internal uses subject to human review should generally fall outside disclosure requirements. Clear disclosure may be appropriate where a customer could reasonably believe that an AI‑enabled virtual assistant is a person. Requirements should reflect the use case, level of risk, and each party’s role and control. Broad requirements for low-risk or incidental uses would create unnecessary burden and notice fatigue.

The comments below are informed by these principles and identify considerations that should guide the design of any additional measures the Government may decide to pursue. As the Government advances its approach to AI transparency, the CBA welcomes continued engagement with government and industry. These comments reflect the banking industry’s current views based on the consultation as framed. The CBA may refine them as specific policy proposals are developed.

AI‑Generated Content

Detecting and identifying AI‑generated content

  • The CBA supports risk‑based transparency for AI‑generated content where it could reasonably be mistaken for an authentic recording or representation of a person, event or communication, or otherwise materially mislead users
  • If the Government determines that further measures are necessary, they should establish a clear, risk‑based threshold to determine when content is sufficiently generated or materially modified by AI to warrant disclosure. The mere use of AI in creating or editing content should not trigger disclosure
  • That threshold should distinguish between content that is substantially generated or materially modified by AI and content where AI has played a limited or ancillary role, such as changing a background colour or generating individual elements of an advertisement. Disclosure should focus on content that could reasonably be mistaken for a real person, event or communication, or that could otherwise materially mislead users, including synthetic content used for fraud or impersonation, such as deepfakes
  • Government guidance could clarify when AI‑generated or materially modified content warrants disclosure, based on context, risk and materiality rather than the degree of AI involvement alone. No single transparency method will be appropriate in every context. Visible notices, provenance metadata and watermarking may each be appropriate depending on the content and associated risk. Guidance should also recognize that detection tools can produce false positives and that watermarking can be circumvented
  • Responsibility for transparency should be proportionate to each actor’s role, knowledge and control. Developers and providers are best placed to supply accurate technical information and appropriate provenance features. Deployers are best placed to determine whether and how disclosure is appropriate for a particular use case and customer context. No party should be expected to disclose information outside its reasonable knowledge or control
  • Existing consumer‑protection, privacy, intellectual‑property and sector‑specific frameworks, together with developing market practices and standards, should remain the starting point. For instance, for federally regulated financial institutions, prohibitions against false or misleading representations or information under the Competition Act and the Bank Act’s financial consumer protection provisions, together with the Canadian Code of Advertising Standards,2 may already address circumstances in which failing to disclose AI use could create a materially misleading impression. Further government action should be limited to clearly identified gaps and should avoid overlapping, conflicting or AI‑specific obligations
  • Any Canadian guidance should also support interoperability with relevant international approaches without importing prescriptive requirements that are unnecessary in the Canadian context

AI Interaction

Empowering individuals to know when they are interacting with an AI system

  • In the financial sector, existing privacy, consumer‑protection and sector‑specific requirements already address many circumstances in which an AI interaction could mislead or materially affect a user. These frameworks should remain the starting point, with clear disclosure used where the risk‑based threshold is met. However, disclosure should not be required where it would compromise fraud prevention, anti‑money‑laundering monitoring, cybersecurity controls or a lawful investigation
  • Disclosures should be risk‑based and focused on direct interactions where the use of AI is not reasonably apparent and could materially affect a person’s expectations or decisions. Low‑risk interactions that would not reasonably affect the user should not require disclosure. Where disclosure is warranted, it should be brief, clear and proportionate to the context, with access to additional information where appropriate. The form and timing of a disclosure should reflect the context and avoid lengthy or repetitive notices
  • Disclosure that a person is interacting with AI should be distinguished from explaining how an AI system generated an output or why a recommendation or decision was made. Any government measures should define their scope clearly and avoid conflating interaction disclosure with automated‑decision explainability
  • Any further government guidance should be limited to clearly identified gaps and coordinated with applicable automated‑decision transparency requirements to avoid duplicative disclosures, notice fatigue and AI-specific obligations
  • Responsibility should reflect each actor’s role, knowledge and control. Deployers are generally best placed to determine whether and how an interaction disclosure should be provided. Developers and providers should supply the information reasonably needed to support that disclosure

Information about AI Systems

Improving the availability of consistent and understandable information about AI systems, including their development, capabilities and limitations

  • In the financial sector, existing privacy, prudential, consumer‑protection, model‑risk, third‑party‑risk and cybersecurity frameworks already govern how institutions obtain, assess and use information about AI systems. These frameworks should remain the foundation for any further guidance. Additional government action should address clearly identified information gaps and support interoperable industry standards without creating new AI‑specific oversight or duplicative obligations
  • Against that backdrop, information needs vary according to the user, use case and level of risk. For individuals, useful information generally relates to the system’s purpose, material capabilities and limitations, and any information needed to make an informed choice. Businesses assessing third‑party AI systems may require more detailed technical, operational and risk information
  • For third‑party AI systems, relevant information may include intended uses, performance and limitations, data provenance and governance, data location, security safeguards, testing and monitoring, material changes to the system or its capabilities, and material dependencies on upstream models or providers. Information requests should be proportionate to the risk and limited to what is reasonably needed for due diligence, risk management and compliance
  • Dependence on a small number of critical providers can reduce visibility into third‑party systems and increase concentration risk. Consistent baseline supplier documentation, developed through industry standards and existing third‑party risk‑management practices, could improve access to relevant information without requiring broad disclosure of proprietary models, architecture or training data
  • Responsibility should reflect which party possesses or controls the relevant information. Upstream providers are best placed to supply model-level information and identify material dependencies on foundation models or other providers. Deployers are best placed to explain how a system is implemented and used. Expectations should recognize circumstances in which a deployer cannot obtain proprietary upstream information despite reasonable due diligence and contractual efforts
  • In the financial sector, existing privacy, prudential, consumer‑protection, model‑risk, third‑party‑risk and cybersecurity frameworks should remain the starting point. Any further government action should focus on clearly identified gaps, proportionate guidance and support for interoperable industry standards, while avoiding new AI-specific oversight or duplicative obligations

AI Incidents

Enabling the tracking of serious incidents related to AI systems

  • Any reporting obligation for material incidents involving AI should operate through applicable existing regulatory or supervisory frameworks. A separate AI‑specific reporting regime would create duplication and fragmentation
  • Reporting should be subject to a clear and sufficiently high materiality threshold so that routine malfunctions and other events that do not cause, or create a substantial likelihood of, material harm do not trigger a reporting obligation. The materiality assessment should consider the severity and scale of harm, significant effects on individuals’ rights, material financial or operational impacts, and whether the AI system caused or materially contributed to the incident
  • Reports should be made through applicable existing regulatory or supervisory channels. Where more than one authority has an interest, a clearly identified lead recipient should coordinate information‑sharing among the relevant authorities so that an incident reported under an applicable regime does not have to be reported again to multiple government bodies, subject to applicable confidentiality and legal restrictions. Existing supervisory coordination mechanisms should also be used to identify and communicate potential systemic issues across institutions and jurisdictions
  • Any reporting guidance should clearly state when an incident becomes reportable, the minimum information required in an initial report, and how subsequent updates should be handled. Initial reports should be limited to information reasonably available at the time, with proportionate updates as material facts become known
  • If further reporting requirements are introduced, they should protect confidential information and should not require disclosure or waiver of information protected by solicitor‑client or litigation privilege
  • Existing third‑party risk‑management arrangements and contracts should support timely incident notification from AI providers to financial institutions, enabling institutions to meet their applicable reporting obligations. Providers should be responsible for information within their knowledge or control, including material incidents involving upstream models. Deployers should not be expected to report proprietary information they cannot reasonably obtain

AI Agents

Advancing ways to better track the activity and interactions of AI agents

  • In the financial sector, existing privacy, consumer‑protection, contractual, payment‑security, prudential and third‑party‑risk frameworks should remain the foundation for addressing AI agents. Given that agent technologies and industry standards are still developing, prescriptive rules governing agent behaviour or liability would be premature. Government action should focus on clearly identified gaps and interoperability rather than a new AI‑specific regulatory regime
  • Within that framework, banks should be able to identify when they are dealing with an AI agent acting on behalf of a customer, counterparty or third-party provider, particularly where the agent can access information, communicate instructions or initiate actions
  • Disclosure should be risk- and context‑based. The nature and extent of disclosure should reflect the agent’s level of autonomy and authority. It is most important where an agent interacts with customers, other organizations or public‑facing systems, or can take consequential actions on another person’s behalf. Purely internal or administrative uses generally should not require the same level of disclosure
  • Authentication and authorization mechanisms should allow institutions to verify whom an agent represents, the activities it is permitted to perform and whether those permissions remain valid. Industry‑led, interoperable standards could support consistent verification across institutions and platforms
  • Responsibility should reflect each actor’s role and control. The party deploying an agent is generally best placed to disclose its use and maintain proportionate records of material actions, instructions and authorizations. Developers and providers are best placed to supply information about the agent’s capabilities, limitations and safeguards
  • Businesses may need information about an agent’s operational boundaries, permissions, capabilities and limitations, human‑oversight and escalation mechanisms, complaint‑handling processes and contractual allocation of responsibility. The nature and level of information should be proportionate to the use case and associated risk

Broader considerations

  • AI transparency is most important where the use of AI could materially affect individuals or where the absence of disclosure could reasonably mislead them. Broad disclosure requirements for low-risk or incidental uses would create unnecessary burden and contribute to notice fatigue
  • Banks already manage risks associated with AI and other technologies through established, sector-specific regulatory requirements and internal frameworks, including model risk management, third-party oversight, and technology and cyber risk controls. These frameworks are adaptable and should remain the foundation for AI transparency. New AI-specific regulatory oversight for federally regulated financial institutions is not necessary and would risk duplication and fragmentation. Any further government action should address clearly identified. Further government action should be limited to clearly identified gaps
  • Any measures should be principles-based, technology-neutral and risk-tiered, with expectations calibrated to the use case, the role of AI, the degree of human oversight and the materiality of potential impacts. This approach can adapt as technologies, uses and standards evolve3
  • Measures affecting small and medium-sized enterprises should reflect their role, use case, level of risk and capacity. Organization size should not exempt a high-risk use, but fixed requirements should not impose the same compliance burden regardless of an organization’s role or the risks involved
  • Canadian policy should support coherence across federal, provincial, territorial and relevant international frameworks, particularly given the global operations of financial institutions. Approaches in other jurisdictions should inform Canadian policy without being imported wholesale, taking account of implementation experience, evolving standards and the Canadian regulatory context. Where requirements achieve substantially similar outcomes, Canada should support appropriate recognition of equivalent compliance, reporting and documentation measures across jurisdictions to reduce unnecessary duplication
  • Any guidance or measures should clearly distinguish voluntary practices from legal obligations, recognize existing requirements and processes applicable to regulated entities where they achieve equivalent outcomes, and avoid inconsistent, overlapping or duplicative compliance requirements, particularly across federal and provincial regimes

Conclusion

Canada can strengthen public trust in AI while supporting responsible innovation by building on existing legal, regulatory and supervisory frameworks. The CBA welcomes continued engagement as the Government develops its approach.


1 The Canadian Bankers Association (CBA) is the voice of more than 60 domestic and foreign banks operating in Canada with over 280,000 employees that help drive Canada’s economic growth and prosperity. The CBA advocates for public policies that contribute to a sound, thriving banking system to ensure Canadians can succeed in their financial goals.
2 See Competition Act, RSC 1985, c C-34, s 74.01(1)(a); Bank Act, SC 1991, c 46, s 627.03; Ad Standards, Canadian Code of Advertising Standards, cls 1(a)–(b).
3 Comparable regulator-led approaches include the UK’s framework, under which existing regulators apply common cross-sectoral AI principles within their respective remits, supported by a central coordination function, and Australia’s approach, which builds on existing, largely technology-neutral laws and sector regulators, supported by an AI Safety Institute. See UK Department for Science, Innovation and Technology, Implementing the UK’s AI Regulatory Principles: Initial Guidance for Regulators (February 2024) at 4–6; Australian Government, Department of Industry, Science and Resources, National AI Plan.


Related Articles