AI for Canadian accounting firms: CPA Canada's position, PIPEDA, and what's actually allowed
Canada has no dedicated AI law, so Canadian accounting firms using AI answer to PIPEDA, provincial privacy statutes like Quebec's Law 25, and their provincial CPA code of conduct. This guide explains what the regulators and CPA bodies actually say, and lays out a practical, compliant adoption path.
Trent McLaren · 22 July 2026 · 9 min read
In this article
- What CPA Canada actually says about AI
- PIPEDA: the law that actually governs client data in AI tools
- The provincial layer: Quebec's Law 25 and the others
- So what is actually allowed?
- A practical adoption path for a Canadian firm
- Frequently asked questions
- Does CPA Canada prohibit any specific AI tools?
- Do I need client consent every time I use AI on their file?
- Does it matter that most AI tools store data in the United States?
- Should I wait for Canada's next AI law before adopting?
- Can a sole practitioner realistically meet all these obligations?
Part of our AI in accounting coverage. See the full AI for accounting firms guide →
Can a Canadian firm use AI on client work? Yes, almost certainly. The rules that govern it already exist; they just were not written with AI in mind.
Canada has no dedicated AI law. The Artificial Intelligence and Data Act, which would have been the country's first, died on the order paper when Parliament was prorogued in January 2025, and the government has confirmed it will not return in its old form. So as at July 2026, a Canadian firm using AI answers to three things: PIPEDA (the federal privacy law from 2000), provincial privacy statutes where they apply, and your provincial CPA body's code of professional conduct.
None of those bans AI. All of them constrain how you use it. This is general information, not legal advice; talk to a privacy lawyer if your situation is unusual.
What CPA Canada actually says about AI
Search for "CPA Canada AI guidance" expecting a rulebook and you will be disappointed. There is no standalone standard naming which tools you may use or what you may put into them.
What exists instead is guidance and advocacy. CPA Canada has published a series of AI publications with the AICPA, run ethics courses on managing AI risk, and in its 2025 pre-budget submission called on the federal government to build a framework for independent assurance over AI systems and to strengthen AI literacy. That last part matters: the national body sees CPAs as the people who will audit and govern AI, not the people who should fear it.
The provincial bodies have been more direct. CPA Ontario has published regulatory guidance on accountabilities for CPAs in the age of AI and on the responsible use of AI in professional practice. The consistent message: the CPA Code of Professional Conduct remains the lens through which you evaluate any AI tool. Competence, due care, confidentiality, and integrity did not get an AI exemption, and every AI-generated output must be reviewed, verified, and fully understood before you use it, including checking for hallucinated content.
Translated into practice, the profession's position is three sentences long. You may use AI. You are fully accountable for what it produces, exactly as if a junior had drafted it. And your confidentiality obligations follow client data into whatever tool you put it in. That last sentence is where PIPEDA comes in.
PIPEDA: the law that actually governs client data in AI tools
The Personal Information Protection and Electronic Documents Act applies to personal information handled in commercial activity, which describes nearly everything an accounting firm does. Client names, SINs, salaries, home addresses, payroll records: all personal information. Paste any of it into an AI tool and PIPEDA applies to that act.
PIPEDA is built on ten fair information principles. Four of them do most of the work in an AI context:
- Consent. Clients gave you their information for accounting services. Using an AI tool to deliver those services is generally consistent with that purpose, much like using practice management software such as FYI or Kloud Connect. Letting a tool train its models on client data is a different purpose entirely, and one no client consented to.
- Limiting use, disclosure and retention. Information can only be used for the purposes it was collected for. A consumer AI tool that retains prompts indefinitely and uses them for training takes you offside almost by definition.
- Safeguards. You must protect personal information with security appropriate to its sensitivity, and tax and payroll data is sensitive. A free-tier chatbot with no contractual protections is not an appropriate safeguard. An enterprise agreement with encryption, access controls, and no-training commitments can be.
- Accountability. The one firms miss. Information transferred to a third party for processing remains your responsibility, so "the AI vendor leaked it" is not a defence. You are expected to use contractual means to ensure comparable protection, which means reading the data processing terms before you buy, not after.
The regulators have applied all of this to generative AI specifically. In December 2023, the federal Privacy Commissioner and every provincial and territorial privacy regulator jointly published principles for responsible, trustworthy and privacy-protective generative AI. For organizations that use (rather than build) these tools, the guidance is concrete: only use tools that respect privacy law in how they were trained, use anonymized or de-identified information in prompts where feasible, only enter personal information into a prompt when authorized to, and validate accuracy before relying on outputs for decisions that affect people.
That checklist lines up with what we found when we dug into whether AI is safe for client data: the risk lives in the tier of tool and the discipline of the person prompting, not in the technology itself.
The provincial layer: Quebec's Law 25 and the others
PIPEDA is the default, but Alberta, British Columbia and Quebec have their own private-sector privacy laws that apply instead of PIPEDA for most matters within those provinces. Alberta's and BC's PIPAs run on similar principles, so if your PIPEDA hygiene is good, you are most of the way there.
Quebec is the exception worth planning around. Law 25, fully in force in stages through September 2023, is the closest thing Canada has to Europe's GDPR, and it touches AI use directly:
- Privacy impact assessments before data leaves Quebec. If personal information about Quebec residents will be communicated outside the province, you must first assess whether it will receive adequate protection. Most AI tools process data on US servers, so if you serve Quebec clients that assessment is not optional paperwork.
- Automated decision disclosure. If a decision about an individual is made exclusively by automated processing, you must tell them, and they can ask for human review. Drafting and analysis reviewed by a human does not trigger this; fully automated client-facing workflows would.
- Real penalties. Fines for the most serious offences can reach $25 million or 4 percent of worldwide turnover, and Quebec's regulator has enforcement powers PIPEDA's federal commissioner can only recommend.
The practical read for a firm with Quebec clients: prefer vendors offering Canadian or contractually protected data residency, document where client data flows, and keep a human in the loop on anything that decides an outcome for a person.
So what is actually allowed?
Here is where the three layers leave a Canadian firm:
- Allowed with basic discipline: business or enterprise tiers of mainstream AI tools (training disabled, proper terms) for drafting, research, summarization, working paper support, and analysis, with a human reviewing every output. This covers most of the prompts accountants actually use day to day.
- Allowed with extra care: identifiable client data in AI tools. You need the right tier of tool, no-training terms, and comfort that the use fits the purpose the client gave you the data for. De-identify where you feasibly can; the regulators' joint guidance says exactly that.
- Not defensible: client data in free consumer chatbots that train on inputs, fully automated decisions about individuals with no disclosure or human review, and unverified AI output in anything you sign. None of these needs a new law to be a problem; PIPEDA and your CPA code already cover them.
A practical adoption path for a Canadian firm
Five steps, in order. A firm of any size can do this inside a month.
- Pick one business-grade tool and read its data terms. Confirm in writing: no training on your data, encryption at rest and in transit, deletion on request, and where the data is processed. Our comparison of the major AI platforms for accounting firms covers how the big three stack up on exactly these questions.
- Write the one-page AI policy. Name the approved tools, the banned ones, what data can go in, and who reviews outputs. We have a template you can adapt this week. Under PIPEDA's accountability principle, having a documented policy is half your defence.
- Update your engagement letter. One plain-language clause disclosing that the firm uses AI tools under confidentiality safeguards as part of service delivery. This shores up the consent question before anyone asks it; the clause wording, and when Canadian firms need more than a clause, is in our guide to client consent for AI.
- Start where the data risk is lowest. Internal drafting, research, and meeting documentation are the classic entry points. Purpose-built tools help: Vinyl, an AI meeting assistant built for accounting firms, handles client conversations under proper data terms rather than through a consumer chatbot (Vinyl is a commercial partner of The Firm).
- Review everything, and log that you did. The single obligation every regulator and every CPA body agrees on: the human signs, the human is accountable. Build review into the workflow, not around it.
The firms getting this right are not waiting for a federal AI act. They are treating PIPEDA and their provincial code as the operating manual they already are. For the bigger picture on tools and workflows, start with our full guide to AI for accounting firms.
Frequently asked questions
Does CPA Canada prohibit any specific AI tools?
No. Neither CPA Canada nor the provincial bodies publish a banned-tools list. The obligation is framed the other way: whatever tool you choose must meet your confidentiality and due care obligations under your provincial code. A free chatbot that trains on inputs fails that test; the same vendor's enterprise tier with no-training terms may pass it.
Do I need client consent every time I use AI on their file?
Not per use. PIPEDA consent attaches to purposes, not tools, so using AI to deliver the services the client engaged you for generally sits within existing consent, the same way outsourced processing does. The clean practice is a standing disclosure in your engagement letter plus internal rules about which data goes into which tool.
Does it matter that most AI tools store data in the United States?
PIPEDA does not prohibit cross-border processing, but it holds you accountable for protection wherever the data goes, so contractual safeguards are essential. Quebec's Law 25 goes further and requires a privacy impact assessment before Quebec residents' information leaves the province, so ask vendors about Canadian data residency and document your assessment.
Should I wait for Canada's next AI law before adopting?
No. A successor to the failed AIDA is expected but has no firm timeline as at July 2026, and any future law will almost certainly demand the same fundamentals (governance, transparency, human oversight) that PIPEDA and the CPA codes already require. Building those habits now is preparation, not wasted effort.
Can a sole practitioner realistically meet all these obligations?
Yes, with less friction than a 50-partner firm. The core stack is a paid business-tier AI subscription with training disabled, a one-page policy, an engagement letter clause, and a habit of reviewing outputs. That is an afternoon of setup and a few hundred dollars a year. The obligations scale with the sensitivity of the data, not with headcount.
AIComplianceCanada