Thank you, Chair.
Good afternoon, everyone.
As you heard, my name is Michael Geist. I'm a law professor at the University of Ottawa, where I hold the Canada research chair in Internet and e-commerce law. I appear in a personal capacity, representing only my own views.
I think we all recognize that we are in a moment when there is mounting pressure to do something quickly on AI regulation. That pressure is understandable, but is, I fear, somewhat risky. I would submit that we can't simply fall back on doing something. The goal must be well-considered legal and regulatory frameworks that balance facilitating innovation with safeguards against potential risks and harms.
I have concerns that some of our initial efforts to find that balance have led to a haphazard amalgam of proposals that risk doing more harm than good. Let me provide you with four quick examples of where I have some concerns, and then I'll shift to three recommendations.
First, Bill C-27, the former privacy and AI bill—I appeared before this committee on that bill—always felt like a rushed response to the pressure to do something on AI. It largely mirrored the EU approach, which has failed to find broad support. Reviving it under a new name would repeat the same mistake and potentially undermine our AI competitiveness. The risk-based analysis may have a role to play in future regulations, but even some European countries, such as France, have slowly backed away from it.
Second, the recent push to add AI chatbots to online harms legislation is similarly ill-conceived. Applying it would not simply extend those online safety rules to a new technology beyond the original social media focus. The online harms act explicitly exempted private messaging from the regulatory regime, and it did not require services to engage in proactive monitoring. Extending the act to AI chatbots would require gutting the very privacy protections the government added after its initial proposals on online harms were widely criticized.
Third, calls for copyright reform to address the use of works in large language models are premature. In fact, I think we should consider adding a text and data-mining exception, like many other countries, to keep us competitive. Many copyright cases are currently working their way through the courts, leading to legal guidance and some market deals. Legislating too quickly risks locking in rules that don't match the evolving legal and market landscape.
Fourth, the emphasis on data or digital sovereignty typically presents Canadian infrastructure as a solution to our sovereignty concerns, yet the real issue, in my view, is whether Canadian laws apply to Canadian data, regardless of location. The answer is they often don't. The push for domestic AI infrastructure sounds like sovereignty, but if Canadian privacy laws don't apply to how Canadian data is used, the servers could be in Gatineau and it wouldn't matter.
What should be prioritized? As I said, let me focus on three things.
First, prioritize the passing of modernized privacy and data governance laws. There is a consensus that the current law is badly out of date. Modernized privacy law would help establish much-needed safeguards for the use of AI data, fix weak privacy enforcement and go a long way toward addressing some of the data sovereignty concerns.
Second, introduce and pass an AI transparency act. It is the lack of transparency around AI systems that is directly correlated to diminished public trust. The recent concerns about OpenAI and the Tumbler Ridge shooter is a case in point. It shouldn't take a meeting with company executives for the minister, or anyone else for that matter, to know about companies' policies on banning user accounts or reporting conduct to the police.
An AI transparency act should do three things: first, ensure that AI corporate policies are publicly accessible; second, mandate transparency on which works are included in large language models so that creators have the information they need to potentially seek content removals; and third, require transparency reporting on government and law enforcement efforts that target users or content removals.
Third, as Professor Scassa noted to this committee recently, there are already many disparate guidelines and guidance on the use of AI. Existing laws also apply to AI, as they do in other contexts. We need to reduce the rhetoric, avoid panic-driven policies and provide Canadians and businesses with a clearer sense of both what has been done and how the strategy fits together. That includes maintaining an emphasis on facilitating AI development by making datasets available, supporting training and fostering private investment. It should also include acting on consultations based on what government hears from stakeholders, not on what it would like to hear. The recent reports on the expert and public response to the AI 30-day sprint consultation did not fully reflect the responses that the government heard.
Canada has a genuine opportunity here. We have AI talent, growing public attention to the governance issues and cross-party interest in getting this right. The worst thing we could do is waste that opportunity on the wrong legislation.
I look forward to your questions.
