Thank you very much, Mr. Chair. I'm delighted to be here.
I am a professor emeritus of political science at the University of Victoria and a fellow of the Centre for Global Studies, and I've researched and written about national and international privacy protection policy for over 40 years. I'm also an adviser to a number of civil liberties and digital rights associations, including the Centre for Digital Rights.
While I can see that there's some remarkable potential for AI—it is mind-blowing—a healthy dose of skepticism is necessary. The initial enthusiasm has now given rise, as we know, to recognition of the enormous risks to our economy, our environment, our social fabric and our civil liberties. I hope, therefore, that the committee can remain very skeptical about the business narrative that prescriptive regulation of artificial intelligence will burden companies, suppress investment and surrender capacity ground to other countries.
Regulatory certainty can reduce legal and reputational risks for companies building at scale, and safety and privacy by design requirements can drive better engineering. The real liability, in my view, is building AI systems and products that harm users, including children, without any measures to hold accountable those systems and the companies that build and deploy them.
A sovereign AI strategy is not just about the physical infrastructure. It is also about Canadian law and policy, and here I echo what Professor Geist just said. There's no point in building Canadian digital infrastructure if the information that flows over those networks is governed by the laws of other countries, such as the U.S. CLOUD Act, and the opaque corporate practices of foreign big-tech organizations.
There are a plethora of laws, guidelines, standards, codes and other soft laws that already apply in this space. The regulatory landscape is complex, often latent, and incomplete. I therefore find it very difficult to envisage a future for Canada without an overarching statutory framework for AI. We may call it AIDA or we may call it something else, but it needs to be more comprehensive, supported by credible oversight and rooted in widespread consultation with all stakeholders. It is unfortunate that policy development to this point has suffered from a lack of genuine widespread consultation. The trust gap is a real one, and it needs to be closed.
We have sufficient experience to know what effective AI governance looks like. It's worth bearing in mind that simply because we're dealing with incredibly new and complex technologies, the governance issues remain familiar. We should learn from the way we have governed and tried to regulate IT in the past, but I think there's some consensus that we need a complete prohibition on the most egregious and manipulative systems.
Mandatory risk assessments for high-risk systems, especially those that profile individuals, are necessary, as are consistent data governance regimes, transparency of algorithms, technical policy documentation and, most especially, effective redress mechanisms for individuals whose rights and interests have been denied because of automated decisions made without effective human oversight.
You will probably hear a lot of criticism at these hearings that the EU AI Act is overly prescriptive. For all its flaws in implementation, I think the legislation has attempted to get the categories and the regulatory framework about right.
Finally, be very aware of the intersection of AI governance and privacy protection policy. The Office of the Privacy Commissioner is already investigating ChatGPT for the non-consensual use of Canadians' personal data to train its large language models, Grok for the display and sharing of sexualized images, and Clearview AI for the scraping of images from the Internet to fuel the facial recognition systems shared with law enforcement.
Also bear in mind that the hallucinations that generative AI is regularly subject to can severely damage reputations. Privacy law mandates the accuracy of personal information. Chatbots like ChatGPT regularly give false information about people without offering a way to correct it.
As AI becomes embedded in our digital experiences, it is difficult to envisage a privacy case coming before the Privacy Commissioner that does not in some measure concern AI. I hope, therefore, that we will see a new Canadian privacy protection act soon that gives the Privacy Commissioner the tools and budget he needs to take on these gargantuan companies that are driving AI technology.
There was vigorous debate about Bill C-27 at this committee in the last Parliament, and I think an emerging cross-party consensus among all parties is that an effective and modernized law is urgently required. However, a new Canadian privacy law should be based on the core principle that privacy is a fundamental human right, and it should provide the OPC with a full range of investigative and enforcement tools, unencumbered, in my view, by a data protection tribunal. It should also impose heightened requirements for personal data transferred outside of Canada for processing.
Modernizing and strengthening Canadian privacy law—including, by the way, the Privacy Act, which hasn't been reformed in 40 years—will not address all the risks associated with AI deployment and development, but it is an urgent first step towards advancing Canadian digital sovereignty.
Thank you very much.