Ontario has had a law on the books since January 2025 that tells municipalities, school boards and children's aid societies they need to be transparent about how they use AI. It's called the Enhancing Digital Security and Trust Act, part of the province's Bill 194, and on paper it's the first Canadian law to single out AI accountability specifically for local public bodies. In practice, it doesn't require any of them to do anything yet, because the regulations that would actually switch it on haven't been written.
That gap between a law that exists and a law that bites is exactly the kind of thing a municipality can either sit out or get ahead of. Two Ontario watchdogs have already told public bodies what they expect in the meantime, and that expectation doesn't wait for a regulation to be enforceable.
What the law says, once someone finishes writing it
The Act applies to any institution covered by Ontario's Freedom of Information and Protection of Privacy Act (FIPPA) or its municipal counterpart, the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), which between them cover essentially every municipality in the province. Where it applies, it sets out four obligations: tell the public when and how AI is being used, put an accountability framework in place for that use, manage the risks that come with it, and keep a person accountable for oversight rather than letting a system run unsupervised.
The catch sits in two words: "prescribed circumstances." The Act only requires any of this when a municipality's AI use falls into circumstances the government defines by regulation, and those regulations haven't been published. The legislation also says explicitly that failing to meet these obligations doesn't invalidate any decision, policy or instrument on its own. There's no penalty clause doing any work right now. A municipality that reads Bill 194 today and concludes there's nothing urgent to do isn't wrong about the legal exposure. It's wrong about the expectation.
What's already real, regulations or not
On January 21, 2026, Ontario's Information and Privacy Commissioner (IPC) and the Ontario Human Rights Commission (OHRC) released a joint set of Principles for the Responsible Use of AI, aimed squarely at public sector organizations, including municipalities. The Principles describe what these two commissioners expect an AI system to be before they'll call it responsible: valid and reliable, safe, privacy-protective, respectful of human rights, transparent about what it's doing, and paired with a real person who's accountable for it.
"Our joint Principles with the Ontario Human Rights Commission establish the necessary guardrails for organizations to deploy AI responsibly and maintain Ontarians' trust that their access, privacy, and human rights will be respected," said IPC Commissioner Patricia Kosseim when the Principles launched.
Those Principles aren't binding law either. But they're not written in a vacuum. They build on a Responsible Use of Artificial Intelligence Directive the Ontario Public Service adopted for its own ministries back in December 2024, so they describe what the province already expects of itself. And a privacy complaint or a human rights complaint against a municipality doesn't need a finished AI regulation to proceed. FIPPA and MFIPPA complaints, and Human Rights Code complaints, already exist as live processes, and the IPC and OHRC have now told everyone, in writing, what they'll be looking for when an AI system is part of the story.
What this means outside Ontario too
Municipalities in other provinces don't fall under Bill 194, but the pattern is worth noticing regardless of where you sit. The enforceable rule almost always lands after the expectation does, not before. Ontario just made that gap unusually visible by passing a law that names the obligation and then leaving the mechanism for regulators to fill in later. Waiting for your own province's version of "prescribed circumstances" to show up before doing anything means building your first AI disclosure practice under a deadline, instead of on your own schedule.
The practical version of the Principles doesn't need a working group or a policy binder. Any resident-facing AI tool, a chatbot on the municipal website or an automated first response to a service request, should carry a plain-language note that says it's AI and how to reach a person instead. Every AI use a municipality has, or is piloting, should have one named staff member who owns it and can explain in plain terms what it does and doesn't do. And before a new use goes live, it's worth checking it against the same six themes the IPC and OHRC published: is it reliable, is it safe, does it protect privacy, does it treat people fairly, is it explainable, and does someone specific answer for it. None of that requires a regulation to exist first. It just requires deciding not to wait for one.