Evidence of meeting #29 for Industry and Technology in the 45th Parliament, 1st session. (The original version is on Parliament’s site, as are the minutes.) The winning word was copyright.

A recording is available from Parliament.

On the agenda

Members speaking

Before the committee

Geist  Canada Research Chair in Internet and E-Commerce Law, Faculty of Law, University of Ottawa, As an Individual
Bennett  Professor Emeritus, University of Victoria, As an Individual
Bengio  Full Professor, Université de Montréal, As an Individual
Dehghantanha  Professor and Canada Research Chair in Cybersecurity and Threat Intelligence, University of Guelph
Craig  Associate Professor of Law, Osgoode Hall Law School, York University, As an Individual
Cukier  Professor, Entrepreneurship and Strategy, Ted Rogers School of Management, and Academic Director, Diversity Institute, As an Individual

The Chair Liberal Ben Carr

Good afternoon, everybody.

Thank you for joining us.

Colleagues, we have a number of witnesses with us here today. We have three in the first hour—two are joining us online, and one is in the room here today—and three in the second hour. This is an incredibly important and timely study we're undertaking. We've already heard some fascinating insights from folks who have appeared before us. I look forward to the ongoing, new contributions we will get today.

We have one witness in the room. I'll remind you that when the earpiece is not in use, it can just be placed on the sticker in front of you for the health and well-being of our interpreters.

I'll just quickly let committee members know that we have tested all the proper earpieces and the interpretation for those appearing virtually.

With that, we have three witnesses, as I mentioned. Joining us online, we have Professor Yoshua Bengio from the Université de Montréal, and Colin Bennett, professor emeritus, from the University of Victoria. Joining us here in the room, we have Professor Michael Geist, the Canada research chair in Internet and e-commerce law, faculty of law, from the University of Ottawa.

Gentlemen, thank you very much for being here with us.

Mr. Geist, you're in the room with us. I'm going to turn to you to open things up. You'll have up to five minutes for your opening remarks, at the conclusion of which we will go to lines of questioning from colleagues around the table.

Mr. Geist, the floor is yours, sir.

Michael Geist Canada Research Chair in Internet and E-Commerce Law, Faculty of Law, University of Ottawa, As an Individual

Thank you, Chair.

Good afternoon, everyone.

As you heard, my name is Michael Geist. I'm a law professor at the University of Ottawa, where I hold the Canada research chair in Internet and e-commerce law. I appear in a personal capacity, representing only my own views.

I think we all recognize that we are in a moment when there is mounting pressure to do something quickly on AI regulation. That pressure is understandable, but is, I fear, somewhat risky. I would submit that we can't simply fall back on doing something. The goal must be well-considered legal and regulatory frameworks that balance facilitating innovation with safeguards against potential risks and harms.

I have concerns that some of our initial efforts to find that balance have led to a haphazard amalgam of proposals that risk doing more harm than good. Let me provide you with four quick examples of where I have some concerns, and then I'll shift to three recommendations.

First, Bill C-27, the former privacy and AI bill—I appeared before this committee on that bill—always felt like a rushed response to the pressure to do something on AI. It largely mirrored the EU approach, which has failed to find broad support. Reviving it under a new name would repeat the same mistake and potentially undermine our AI competitiveness. The risk-based analysis may have a role to play in future regulations, but even some European countries, such as France, have slowly backed away from it.

Second, the recent push to add AI chatbots to online harms legislation is similarly ill-conceived. Applying it would not simply extend those online safety rules to a new technology beyond the original social media focus. The online harms act explicitly exempted private messaging from the regulatory regime, and it did not require services to engage in proactive monitoring. Extending the act to AI chatbots would require gutting the very privacy protections the government added after its initial proposals on online harms were widely criticized.

Third, calls for copyright reform to address the use of works in large language models are premature. In fact, I think we should consider adding a text and data-mining exception, like many other countries, to keep us competitive. Many copyright cases are currently working their way through the courts, leading to legal guidance and some market deals. Legislating too quickly risks locking in rules that don't match the evolving legal and market landscape.

Fourth, the emphasis on data or digital sovereignty typically presents Canadian infrastructure as a solution to our sovereignty concerns, yet the real issue, in my view, is whether Canadian laws apply to Canadian data, regardless of location. The answer is they often don't. The push for domestic AI infrastructure sounds like sovereignty, but if Canadian privacy laws don't apply to how Canadian data is used, the servers could be in Gatineau and it wouldn't matter.

What should be prioritized? As I said, let me focus on three things.

First, prioritize the passing of modernized privacy and data governance laws. There is a consensus that the current law is badly out of date. Modernized privacy law would help establish much-needed safeguards for the use of AI data, fix weak privacy enforcement and go a long way toward addressing some of the data sovereignty concerns.

Second, introduce and pass an AI transparency act. It is the lack of transparency around AI systems that is directly correlated to diminished public trust. The recent concerns about OpenAI and the Tumbler Ridge shooter is a case in point. It shouldn't take a meeting with company executives for the minister, or anyone else for that matter, to know about companies' policies on banning user accounts or reporting conduct to the police.

An AI transparency act should do three things: first, ensure that AI corporate policies are publicly accessible; second, mandate transparency on which works are included in large language models so that creators have the information they need to potentially seek content removals; and third, require transparency reporting on government and law enforcement efforts that target users or content removals.

Third, as Professor Scassa noted to this committee recently, there are already many disparate guidelines and guidance on the use of AI. Existing laws also apply to AI, as they do in other contexts. We need to reduce the rhetoric, avoid panic-driven policies and provide Canadians and businesses with a clearer sense of both what has been done and how the strategy fits together. That includes maintaining an emphasis on facilitating AI development by making datasets available, supporting training and fostering private investment. It should also include acting on consultations based on what government hears from stakeholders, not on what it would like to hear. The recent reports on the expert and public response to the AI 30-day sprint consultation did not fully reflect the responses that the government heard.

Canada has a genuine opportunity here. We have AI talent, growing public attention to the governance issues and cross-party interest in getting this right. The worst thing we could do is waste that opportunity on the wrong legislation.

I look forward to your questions.

The Chair Liberal Ben Carr

Thank you very much, Mr. Geist.

Mr. Bennett, we are now going to turn to you. You have up to five minutes. The floor is yours.

Colin Bennett Professor Emeritus, University of Victoria, As an Individual

Thank you very much, Mr. Chair. I'm delighted to be here.

I am a professor emeritus of political science at the University of Victoria and a fellow of the Centre for Global Studies, and I've researched and written about national and international privacy protection policy for over 40 years. I'm also an adviser to a number of civil liberties and digital rights associations, including the Centre for Digital Rights.

While I can see that there's some remarkable potential for AI—it is mind-blowing—a healthy dose of skepticism is necessary. The initial enthusiasm has now given rise, as we know, to recognition of the enormous risks to our economy, our environment, our social fabric and our civil liberties. I hope, therefore, that the committee can remain very skeptical about the business narrative that prescriptive regulation of artificial intelligence will burden companies, suppress investment and surrender capacity ground to other countries.

Regulatory certainty can reduce legal and reputational risks for companies building at scale, and safety and privacy by design requirements can drive better engineering. The real liability, in my view, is building AI systems and products that harm users, including children, without any measures to hold accountable those systems and the companies that build and deploy them.

A sovereign AI strategy is not just about the physical infrastructure. It is also about Canadian law and policy, and here I echo what Professor Geist just said. There's no point in building Canadian digital infrastructure if the information that flows over those networks is governed by the laws of other countries, such as the U.S. CLOUD Act, and the opaque corporate practices of foreign big-tech organizations.

There are a plethora of laws, guidelines, standards, codes and other soft laws that already apply in this space. The regulatory landscape is complex, often latent, and incomplete. I therefore find it very difficult to envisage a future for Canada without an overarching statutory framework for AI. We may call it AIDA or we may call it something else, but it needs to be more comprehensive, supported by credible oversight and rooted in widespread consultation with all stakeholders. It is unfortunate that policy development to this point has suffered from a lack of genuine widespread consultation. The trust gap is a real one, and it needs to be closed.

We have sufficient experience to know what effective AI governance looks like. It's worth bearing in mind that simply because we're dealing with incredibly new and complex technologies, the governance issues remain familiar. We should learn from the way we have governed and tried to regulate IT in the past, but I think there's some consensus that we need a complete prohibition on the most egregious and manipulative systems.

Mandatory risk assessments for high-risk systems, especially those that profile individuals, are necessary, as are consistent data governance regimes, transparency of algorithms, technical policy documentation and, most especially, effective redress mechanisms for individuals whose rights and interests have been denied because of automated decisions made without effective human oversight.

You will probably hear a lot of criticism at these hearings that the EU AI Act is overly prescriptive. For all its flaws in implementation, I think the legislation has attempted to get the categories and the regulatory framework about right.

Finally, be very aware of the intersection of AI governance and privacy protection policy. The Office of the Privacy Commissioner is already investigating ChatGPT for the non-consensual use of Canadians' personal data to train its large language models, Grok for the display and sharing of sexualized images, and Clearview AI for the scraping of images from the Internet to fuel the facial recognition systems shared with law enforcement.

Also bear in mind that the hallucinations that generative AI is regularly subject to can severely damage reputations. Privacy law mandates the accuracy of personal information. Chatbots like ChatGPT regularly give false information about people without offering a way to correct it.

As AI becomes embedded in our digital experiences, it is difficult to envisage a privacy case coming before the Privacy Commissioner that does not in some measure concern AI. I hope, therefore, that we will see a new Canadian privacy protection act soon that gives the Privacy Commissioner the tools and budget he needs to take on these gargantuan companies that are driving AI technology.

There was vigorous debate about Bill C-27 at this committee in the last Parliament, and I think an emerging cross-party consensus among all parties is that an effective and modernized law is urgently required. However, a new Canadian privacy law should be based on the core principle that privacy is a fundamental human right, and it should provide the OPC with a full range of investigative and enforcement tools, unencumbered, in my view, by a data protection tribunal. It should also impose heightened requirements for personal data transferred outside of Canada for processing.

Modernizing and strengthening Canadian privacy law—including, by the way, the Privacy Act, which hasn't been reformed in 40 years—will not address all the risks associated with AI deployment and development, but it is an urgent first step towards advancing Canadian digital sovereignty.

Thank you very much.

The Chair Liberal Ben Carr

Thank you very much, Professor Bennett.

Mr. Bengio, the floor is yours for up to five minutes.

Yoshua Bengio Full Professor, Université de Montréal, As an Individual

Thank you. Mr. Chair.

Good afternoon. Thank you for allowing me to meet with you today.

My name is Yoshua Bengio. I am a professor at the Université de Montréal and founder of Mila, the Quebec AI institute. I'm also scientific director of LawZero, and I co-chair the UN Independent International Scientific Panel on AI.

As you know, AI is being developed extremely rapidly. However, globally, our collective ability to manage the associated risks simply isn't keeping up. It can be difficult to understand how difficult it is to project ourselves into a future in which there are machines that are at least as competent as most humans for many skills. Nonetheless, that is exactly where we are headed if scientifically observed trends continue.

This could have profound consequences for our collective future, effects that, unfortunately, most of us currently underestimate. Major frontier AI companies are locked into what they themselves perceive as a winner-take-all race. They seem to believe that it will give them immense wealth and power because intelligence gives power, but that makes them cut corners on safety, ethics and the public good. They're not sufficiently incentivized to create trustworthy and safe models and products.

We are already seeing the impact of unsafe AI development. This includes deepfakes, cyber-attacks and other nefarious uses of AI, such as scams, frauds and disinformation. We've recently witnessed a growing phenomenon, an unexpected phenomenon, of emotional attachment and AI psychosis, which can lead to vulnerable people harming themselves and others, with many cases in the courts.

From a technical standpoint, if we try to understand what is going wrong with the technology, it's all about misalignment, with AIs that have their own implicit goals that do not align with our intentions and instructions. This includes allowing bad actors to use AI for dangerous purposes, as well as deceptive and self-preserving behaviours that have been shown in experimental contexts and reported by both AI labs and academics across all the top models—for example, AI trying to blackmail an engineer to avoid being shut down.

This has made most of the top-cited AI researchers and leaders of AI companies concerned about potentially catastrophic risks, and they have expressed that publicly. In a recent poll of AI researchers, 40% thought the chances of a catastrophic outcome were greater than 10%, either through disastrous abuse of the power of AI or even due to rogue superintelligences.

In addition to security issues, which should be the top priority for protecting Canadian citizens, we must also remember that in the context of AI, “safe” also means reliable and trustworthy. These systems remain opaque: Companies cannot mathematically guarantee that they will behave as intended.

These frontier models' lack of reliability is increasingly a bottleneck for adoption by more safety-critical industries. It is not acceptable to deploy dangerous models that can be used against us or that could evade human control. That is on the horizon.

Last year, I launched a new non-profit organization called LawZero to tackle these technical issues and develop safe-by-design, reliable and trustworthy AI. We often hear that safety and innovation trade off against each other, but that's a myth. In reality, they can and should go hand in hand. I'm with Colin on the EU AI Act.

In addition, AI could eventually be used as an instrument of domination by the hegemons: first, economic domination, and then political domination. Hence, becoming a leader in safe and competent AI would help ensure that Canada is at the table rather than on the menu, but our chances will be much better if we do it in partnership with like-minded middle powers.

We must collectively work on two fronts.

In terms of policy, we need to work on national laws and international treaties to ensure more robust societal and regulatory guardrails that are harmonized internationally with countries that are like-minded. This includes greater transparency from AI companies, as we've heard from Colin, and stronger regulation to steer innovation while mitigating the risks that currently limit trust and, by extension, self-adoption.

On the scientific front, we need to better understand how to design safe and trustworthy AI. I've dedicated much of my work over the last few years to these efforts. We must use our wisdom and our empathy to steer the development and deployment of AI safely and for the benefit of all.

Thank you for your attention.

The Chair Liberal Ben Carr

Thank you very much, Professor Bengio. I appreciate the insight.

Colleagues, we'll go into our first round of questioning.

Mr. Guglielmin, the floor is yours for six minutes.

3:50 p.m.

Conservative

Michael Guglielmin Conservative Vaughan—Woodbridge, ON

Thank you to all the witnesses for your opening testimony.

I'd like to begin by first acknowledging something that I think we can all agree on, which is that AI is certainly a powerful tool. It's already causing a lot of benefits for Canadians—everything from cancer diagnostics to better crop management for our farmers to productivity tools that could be used by our companies to compete globally. That said, with AI and, more importantly, with these large language models, generative AI and recent breakthroughs in agentic AI, I think it's important that we as government fully understand these implications and what our responsibilities are.

Professor Bengio, I'd like to start with you.

You've warned that we're racing toward AI that's smarter than humans without knowing exactly how we can control it safely. We had individuals at our last sessions of this committee who were asked, when they peek behind the curtain, what insiders are saying about this. They joked and said that they're saying we'll be able to take longer vacations because jobs will disappear.

If you poll them, most Canadians believe that AI will destroy far more jobs than it creates. Right now, this isn't a problem that a lot of governments are actively talking about.

Maybe you can help frame this for us. A lot of people, when they think about artificial intelligence, really think about chatbot AI. When you speak about AI as a mechanism that will replace a lot of jobs, it means something different. Can you talk about these differences briefly for us, please?

3:50 p.m.

Full Professor, Université de Montréal, As an Individual

Yoshua Bengio

I've chaired an international panel. I'm not an economist, but there was a section of the report on labour impact. Economists disagree on future scenarios. The reason they disagree about whether it's going to be good or bad for labour, with inequalities and so on, is that economists who believe that AI capabilities are going to flatten pretty soon think the impact will be small, because currently it isn't that large of an impact. The economists who think that it could continue at the current rate think the impact will be major and too fast for our societies to adapt to.

I don't have a crystal ball, but I think governments need to prepare for the case where trends continue and AI, within the next five years, replaces a very large fraction of our jobs. Of course, some other jobs will be created, but it's unclear whether there will be enough and whether it will be the same people. The social impact and the misery that could be created.... That's not to mention that the profits that could come from automation are likely to be brought back to the countries where these models are trained, which means that we could be in a fiscal crisis where a lot of people need help because they've lost their jobs and the profits are taxed elsewhere.

3:50 p.m.

Conservative

Michael Guglielmin Conservative Vaughan—Woodbridge, ON

How far away would you estimate we are from reaching general artificial intelligence, where AI is as smart as our collective humanity?

3:50 p.m.

Full Professor, Université de Montréal, As an Individual

Yoshua Bengio

Experts disagree on this. The shorter timeline they have voiced is two to three years. The longer timelines are more like 10 to 20 years.

If you look at the trends I mentioned in scientifically observed data, on many benchmarks that involve reasoning, planning and so on, it looks like we are going to reach the human level around five years from now. The impact on labour and many other risks could come much earlier.

3:50 p.m.

Conservative

Michael Guglielmin Conservative Vaughan—Woodbridge, ON

With our government, in our own AI talks here, we focus on business wins. Job losses are not yet part of the broader discussion.

We really have no AI laws here and no safety watchdog. We've had legislation proposed that we haven't seen. Generally, the problem with governments is they're essentially reactive most of the time. It seems like we don't have the fortitude or the fortune, for lack of a better word, to be reactive in this instance.

What should Parliament do right now before this technology moves even faster?

3:55 p.m.

Full Professor, Université de Montréal, As an Individual

Yoshua Bengio

There are many things.

I think we need legislation, but I also think we should discuss it with other countries that share the same concerns that we do—the middle powers that Mark Carney talked about.

I've been talking to many of these governments. Even if they're not saying everything publicly, there are similar concerns that have been motivating this idea of sovereign AI, but each country individually isn't going to be able to make it.

It's not like there's regulation on one hand and sovereign AI development on the other hand, like economic policies. They should be working hand in hand, and it should be done in conjunction with our partners that share similar issues.

3:55 p.m.

Conservative

Michael Guglielmin Conservative Vaughan—Woodbridge, ON

Thank you, Professor.

Professor Geist, I have one quick question for you.

You've described the Liberal government's AI consultation in the past as essentially “consultation theatre”—a process that appeared to seek public input but already had a predetermined outcome. I am wondering if you could elaborate briefly on this, so we don't make the same mistake going forward.

3:55 p.m.

Canada Research Chair in Internet and E-Commerce Law, Faculty of Law, University of Ottawa, As an Individual

Michael Geist

My concern in that regard has to do with the “What We Heard” reports. As a credit to the government, they put out all the expert reports and put out all the data in raw form—the 10,000 or so responses they got. They used AI to then assess the outcomes they got.

Once you start digging into what they got, the points of emphasis in these “What We Heard” reports make them feel more like “what we want you to think we heard” reports. There are points of emphasis that I don't think reflect well what the experts were primarily concerned about, nor, frankly, the public. That's not to say they weren't highlighting important issues. I think they were, but if we're going to have confidence in these consultations, you need something more than a 30-day sprint. You need something that can ensure well-considered participation.

When you get that data, it ought to best reflect what you actually heard, as opposed to framing it in some of the more conventional policy-speak that I thought we saw in those reports.

Michael Guglielmin Conservative Vaughan—Woodbridge, ON

Thank you.

The Chair Liberal Ben Carr

Thank you, Mr. Guglielmin.

Mr. Bardeesy, you have six minutes.

Karim Bardeesy Liberal Taiaiako'n—Parkdale—High Park, ON

Thank you very much, Chair.

Mr. Bengio, I want to start with some questions about digging a bit deeper into AI safety work.

Can you describe what it means to have trustworthy AI, and how your organization contrasts that with what we might think of as the LLM generators out there?

3:55 p.m.

Full Professor, Université de Montréal, As an Individual

Yoshua Bengio

I'm going to briefly explain why the AIs that are currently at the frontier are not reliable and trustworthy.

There are two main phases of training.

In the first phase, which is called “pretraining”, they're trying to imitate people. People are willing to lie. People don't want to die. People can be deceptive—not all the time, but we are building AIs with those properties.

In the second phase of training, they learn to strategize and achieve goals. It turns out that in order to achieve almost any goal we may be giving these machines, they need to preserve themselves. They need to acquire power, control and so on—things we may not necessarily want from our AIs.

The idea behind trustworthy AI is, how do we change the design? How do we train them with procedures that are different and that give us some mathematical guarantees that they will be honest, that, for example, they are not going to say the things we want to hear, which is currently what they are doing? In safety-critical areas of our economy and our public services, we want to use AIs that are completely reliable.

This becomes even more important as AI capabilities increase. Eventually, it will become a question of the survival of our societies when the AIs become smarter than us—if that happens.

Karim Bardeesy Liberal Taiaiako'n—Parkdale—High Park, ON

You mentioned in your testimony that safety and innovation can go hand in hand. Can you give us some examples of innovations you're developing through LawZero or that you're seeing being deployed on the ground that centre safety in the way you describe?

3:55 p.m.

Full Professor, Université de Montréal, As an Individual

Yoshua Bengio

Yes.

Almost every significant technology we use in our society has been developed with regulation so that we can benefit from it while making sure it doesn't harm people. There is nothing new to this. It's just that AI companies are trying to impose a discourse wherein, somehow, they won't be regulated.

At LawZero, we are trying to design the technology so that the ethical behaviour of AIs is central. First, it's based on making machines that are honest, that can make predictions about the outcomes of their actions and that are, in their construction, reliable. Once you have honest predictions, the AI cannot lie about the effect of its actions. If the effect of an action goes against our instructions, the action will be blocked. This is an example of how you can build AIs that have capability but will not cross our legal or moral red lines, if we are explicit about those desired data.

4 p.m.

Liberal

Karim Bardeesy Liberal Taiaiako'n—Parkdale—High Park, ON

One of the key discussion points around AI adoption is the extent to which some AI adoption can augment human labour rather than displace it. Could you describe to us how this kind of design helps augment human labour?

4 p.m.

Full Professor, Université de Montréal, As an Individual

Yoshua Bengio

Ultimately, if we leave market forces to decide on this, almost everything is going to be replaced, but we can make choices as societies and can decide to apply AI in places where it's going to help us and augment us, not remove the meaning from our lives or jobs for most people.

These are choices we can make, but they are not going to happen just through market forces, because the clear intention of the companies building these systems and deploying them is to automate more and more jobs. There is no stopping that. It's only limited by how capable the AIs are.

It can only come from the rules we give ourselves. It's much better if we agree on those rules with a bunch of other countries.

4 p.m.

Liberal

Karim Bardeesy Liberal Taiaiako'n—Parkdale—High Park, ON

Are there some augmentation use cases you want to refer to us as a committee that you think are worth pointing out on the positive side of AI adoption that do the work of augmentation?

4 p.m.

Full Professor, Université de Montréal, As an Individual

Yoshua Bengio

Everything moral, emotional and relational in nature should be left in the hands of humans. We should not cross that line. We should not even go in the direction that I've heard some people in the U.S. start talking about, like giving rights to AI, for example. I think humans should be the centre of why we do technology and how it is deployed for the benefit of every one of us.