Last updated on June 19th, 2026 at 10:47 pm
While similar legislation is being proposed in the US, and the UK
It’s remarkable coordination, even if it’s not intentional. At almost the same time Canada, the US and the UK are tabling a series of bills that will restrict speech online report to increase safety online, make privacy weaker, and in the Canadian instance, strengthen anti-crime measures. The sum total is a decrease in freedom and an enormous expansion of federal powers. The fact that this is coordinated, at least by timing, across the world should be noticeable to everyone. But the larger issue (and one that has gone largely unexplored) is the fact these bills will likely do little too limit incidents like the spate of visible violence (largely to property) that has recently occurred in Toronto and appears to have been foreign cutout work for hire; and will impact Canadian sovereignty, both from an AI and a data perspective. There are implications in these bills that affect what information and data is exposed to our partners, our allies and the world at large.
In just over three months, the Carney government has tabled an interlocking set of digital bills that would change how Canadians speak, what they can access, what an artificial intelligence system is permitted to say, and who holds the records of their digital lives. The legislation is being sold as a response to genuine emergencies: a wave of shootings across the Greater Toronto Area, attacks on synagogues and Jewish schools, gunfire at the U.S. consulate, the killing of a police officer, and a broader sense that the online world has outrun the law. The emergencies are real. Some of the concerns the bills address are legitimate. But the timeline is alarming, and the architecture being assembled has consequences.
The most pointed of those consequences is not the one dominating the debate. The civil-liberties alarm, surveillance, censorship, digital ID, is warranted and widely voiced. But underneath it sits a sovereignty problem that runs in two directions at once. These bills would build powers that reach inward, at Canadians, while simultaneously eroding Canada’s standing outward, weakening the country’s data relationship with its most important partners and manufacturing precedent that hostile and friendly states alike can use. A country trying to assert control over its digital life may end up with less of it.
The bills, summarily
Three pieces of legislation carry the position, with two more in support. Bill C-22, the Lawful Access Act, is the most advanced and the most consequential. It would authorize regulations requiring core service providers to retain categories of metadata, including transmission data, for up to one year. Metadata is not the content of messages. It’s the record of who contacted whom, when, for how long, and from where, which is in many ways more revealing than content because it maps a life. The bill also empowers the Public Safety Minister to issue orders compelling providers to build interception capability, with limits on what those providers may disclose. The opposition has been extraordinary. Signal has said it would withdraw from Canada rather than comply. Windscribe, the Toronto-headquartered VPN provider, has said it would relocate its headquarters out of the country, and NordVPN has signalled it would consider the same. Apple and Meta have raised public concerns about the bill’s effect on encryption and cybersecurity. The Citizen Lab at the University of Toronto and the Canadian Civil Liberties Association called for the metadata-retention and ministerial-order provisions to be withdrawn from the bill entirely, recommendations I have made as well, describing a section that offers the government maximum flexibility, minimal restrictions, and minimal judicial scrutiny. C-22 passed second reading and is now the bill most likely to reach a House vote before the summer recess.
Bill C-34, the Safe Social Media Act, would bar anyone under sixteen from social media unless platforms implement sufficient safeguards, and it carries broad public support, with polling showing roughly three in four Canadians in favour of the age restriction. The difficulty is operational. To reliably keep people under sixteen off a platform, the platform has to establish the age of everyone, which in practice points toward government ID or biometric face scans submitted to third-party verification services by adults and children alike. C-34 also creates the Digital Safety Commission and gives it sweeping authority to set rules, decide which platforms must comply, grant or deny exemptions, and levy penalties reaching into the millions of dollars and a percentage of global revenue. It defines seven categories of harmful content, and the detail that should stop every reader is this: the bill devotes extensive language to defining terrorism and violent extremism, including acts said to undermine social stability, while leaving the most elastic category, hatred, undefined. The bill also reaches past platforms and into the outputs of AI systems, requiring AI companies to “reduce exposure to harmful content” under that same regulatory umbrella while leaving largely undefined what that means.
Bill C-36, the Protecting Privacy and Consumer Data Act, is the one whose true significance has been least discussed, and it is the hinge of the sovereignty argument. The bill recognizes privacy as a fundamental right and strengthens consent, deletion, and children’s protections, which the Privacy Commissioner has welcomed. But it does something structural that outweighs any of those substantive reforms. It repeals the private-sector half of Canada’s existing privacy law and transfers the entire private-sector privacy file, complaints, investigations, audits, codes of practice, and penalties, away from the independent Privacy Commissioner of Canada and into the same Cabinet-appointed Digital Safety Commission created by C-34. The Privacy Commissioner is an Agent of Parliament, confirmed by both chambers and reporting directly to Parliament. Under C-36 that independent officer is removed from private-sector oversight and replaced, in that role, by a body the government appoints. Major law firms and the International Association of Privacy Professionals confirm the mechanism: this is the creation of a single digital super-regulator with content, data, and privacy authority concentrated in one appointed commission.
Two further bills round out the framework. Bill C-8 would grant secret-order powers over telecoms, banks, and energy companies under a cybersecurity banner. Bill S-209 seeds an age-verification requirement for adult content that C-34’s architecture would extend across the wider internet.
The first sovereignty problem: Canada becomes the precedent
Canada is not building this in isolation, and its choices do not stay within its borders. The government’s central justification for C-22 is that Canada is the only Five Eyes country without a modern lawful-access framework. Set aside that the claim is shakier than it sounds, the United States has no federal mandatory metadata-retention law, and the EU’s highest court has twice struck down blanket retention as incompatible with fundamental rights. The deeper issue is what passage would do to the alliance.
The Five Eyes intelligence partnership runs on the logic of precedent. Each member’s surveillance law becomes the argument for the next member’s. Analysts tracking C-22 have been explicit: if Canada mandates retention and interception capability, the argument in Washington becomes that the closest allies already require this and American companies already comply in those markets, so why not at home. The chairs of two U.S. congressional committees have already written to the Public Safety Minister, and their concern cuts the other way, warning that the bill threatens cross-border data flows and U.S. interests. Canada would not merely be surveilling its own citizens. It would be manufacturing the template that erodes privacy protections across the alliance, including in jurisdictions with far less restraint. Sovereignty, in this frame, is not only what a country does to its own people. It is what its example licenses everyone else to do. And the licensing is no longer theoretical.
The same trade is running in Washington, the same week
The precedent argument stopped being hypothetical this month, because the United States is now assembling its own version of the bargain, and the symmetry with Ottawa is hard to miss.
Two moves in Washington need to be read together. The first is an executive order President Trump signed in December 2025, updated on March, titled Ensuring a National Policy Framework for Artificial Intelligence, after Congress declined to insert AI preemption language into the annual defense bill. When the legislative route stalled, the administration turned to executive power. The order declares it federal policy to sustain American AI dominance through a minimally burdensome national framework, and it builds machinery to enforce that policy against the states. It establishes a Justice Department litigation task force whose sole job is to challenge state AI laws in federal court. It threatens to make states with laws the administration deems onerous ineligible for certain federal broadband funds. It directs the Federal Trade Commission to treat state-mandated bias mitigation as a deceptive trade practice. It names Colorado’s AI law as a problem to be solved.
The second move is the legislative deal Axios reported in June. The White House and Senator Marsha Blackburn launched simultaneous legislation to block state AI regulation for a period of years in exchange for passing three federal bills: the Kids Online Safety Act, the NO FAKES Act, and a national age-verification mandate. The deal is not finished, the White House has not endorsed final text, and Congress has rejected preemption twice already, including a Senate vote of ninety-nine to one to strip an AI moratorium from an earlier bill. It may fail again.
But read the executive order and the deal side by side and the strategy resolves into focus. The executive order carves child safety out of preemption deliberately, exempting state laws on child protection while targeting the rest, and it instructs the administration to work with Congress to pass federal legislation that preempts the remainder while ensuring children are protected and censorship is prevented. The deal is that legislation. The two halves are one architecture: strip the states of general authority to regulate artificial intelligence through executive action and litigation, and route child-safety-framed content power through new federal law. Deregulate the industry at the state level. Centralize speech and content authority at the federal level. Use the protection of children as the vehicle that carries the second half past the objections it would otherwise face. The Kids Online Safety Act would give enforcement power over content deemed harmful to minors to the Federal Trade Commission, which is the American equivalent of handing that authority to Canada’s new Digital Safety Commission.
States hold real, operative authority to regulate AI right now. They have used it heavily, with more than a thousand AI bills introduced across the states in a single year and well over a hundred enacted, from Colorado’s risk law to New York’s frontier-model safety act. That authority exists by default, because Washington has not occupied the field, rather than because it has been entrenched, which is exactly what makes it vulnerable. A government does not build a litigation task force and a funding-leverage regime to attack a power that does not exist. The elaborate machinery is itself the proof that the authority is real, and the point of the machinery is to revoke it.
In Canada, one government fuses child protection, privacy, content rules, and AI-output regulation into a single appointed commission, concentrating the powers in one body. In the United States, the administration splits the same elements deliberately, hollowing out AI accountability at the state level by executive force while federalizing child-safety-framed speech control through Congress. The structural methods are opposite. The destination is identical: speech-adjudication power concentrated at the national level, meaningful AI accountability weakened, and the protection of children serving as the politically unassailable wrapper in both capitals. This is what the precedent cascade looks like when it is happening rather than being predicted. Two allied governments, in the same season, reaching for the same wrapper to build the same kind of authority.
And the same handful of AI companies sit in the middle of it. A multinational model developer would be supervised by a content-and-data commission in Ottawa and actively deregulated by executive order in Washington, with Canadian and American user data crossing a border where the two regimes now point in opposite directions. One country builds the power to dictate what a model may say. The other dismantles the power of its own states to impose any obligations on how a model is built. The company operates in both, the data flows through both, and no one is coordinating the seam. The result is not a coherent North American approach to artificial intelligence, but two incompatible regimes converging on the same control over speech while diverging on everything else, with the people whose data moves between them protected by neither.
The second sovereignty problem: Canada may sever its own data’s standing in Europe
This consequence distinguishes C-36 from “ordinary” privacy reform, and it is the one most likely to inflict concrete, measurable harm. The European Union grants Canada an adequacy finding, a determination that Canadian privacy protection is strong enough to let data move from the EU to Canada without additional legal barriers.
The finding rests on conditions, and the central condition under the GDPR is that a jurisdiction maintain an independent supervisory authority for data protection, an independence requirement rooted in the EU Charter itself. The EU, the United Kingdom, and Australia all structure their regimes the same way, keeping data-protection oversight in an independent body and assigning online-content and platform-safety questions to a separate one. The UK splits the Information Commissioner’s Office from Ofcom. Australia splits its Information Commissioner from its eSafety Commissioner, and the two signed a coordination agreement to handle the overlap.
Canada, with C-36, would move in the opposite direction, dissolving the independence that the model is built to protect and folding private-sector privacy into a Cabinet-appointed content-and-data commission. The question this raises is not rhetorical, and privacy authorities are already asking it: does this jeopardize Canada’s EU adequacy status? If it does, Canadian data loses its frictionless legal channel to Europe, and every Canadian business that handles European data faces new barriers and costs. The irony is total. In the name of asserting domestic control over the digital economy, Canada may surrender the international standing that lets its data move freely to the bloc that takes data sovereignty most seriously in the world. The government frames the new commission as the institutional foundation of a trustworthy digital economy. The structure of that commission may cost Canada its trusted status abroad.
The third sovereignty problem: who else can reach this
None of these bills hand a foreign government a direct line into Canadian data. There is no clause sharing the retained metadata with allied agencies by default, no provision granting the FBI a login. Anyone claiming otherwise is reaching past the text. But the architecture creates several real channels even without a direct one.
The first is intelligence sharing. A year of retained metadata on every Canadian is a far richer pool than exists today, and the intelligence product derived from what Canadian agencies collect or access can flow to allied services through the Five Eyes arrangements that already operate with limited public visibility. The data does not become foreign-accessible. Its value feeds outward through channels that predate these bills, now with vastly more to draw on.
The second is the vulnerability that mandated capability creates, and it is the heart of what the technology companies are actually arguing. Signal’s objection is not that Canada will share its users’ data. It is that compelled changes to a provider’s systems weaken privacy protections for everyone and create exploitable weaknesses for hackers and foreign intelligence actors. A door built for Canadian law enforcement is still a door, and doors get picked. A retained-metadata store built to satisfy a Canadian regulation is a target for every hostile service and criminal group that wants it. You do not grant access by building the capability. You build the thing that access exploits.
The third is the channel that connects directly to the longer pattern of Canadian digital dependence. Much of the infrastructure underneath these bills runs on U.S.-headquartered providers, and U.S. authorities already possess, through the CLOUD Act, a legal mechanism to compel those companies to produce data regardless of where it is physically stored. These bills do not change that exposure directly. What they change is the volume and sensitivity of what sits on the exposed infrastructure. More retained Canadian data, concentrated on systems a foreign legal regime can already reach, is a larger surface for a reach that already exists. The bills do not open the door to Washington. They enlarge what is sitting on the other side of a door Washington already has.
Put the three together and the formulation is apparent. These bills do not hand foreign governments a key, but they do build the doors, enlarge the troves, and concentrate them on infrastructure a foreign legal regime can already reach, while jeopardizing the one international arrangement that protects Canadian data’s standing abroad.
The threat the bills were sold to stop, and cannot
Let’s return to the violence revelations, because the gap between the justification and the legislation is the final piece. The GTA shootings are real and the structure behind them is now partly documented. Toronto police have linked two firearms to at least twenty-eight shooting incidents, with young people recruited through encrypted messaging apps and paid only after they film the attack. Police say the networks extend beyond Toronto and that more than one operation is recruiting. On the question of who is paying, the Canadian agencies running the investigation have been silent, even as U.S. prosecutors have named an alleged foreign-directed orchestrator in a criminal complaint based on a single witness.
Strip that threat to its mechanics and it is an amplification system. The violence is the input. The output is distributed video, and distribution at scale is governed by recommender algorithms, the same machine-learning systems that decide what circulates on every major platform. The filming requirement is not incidental. A filmed bullet hole, optimized for circulation, frightens a country. The orchestrator is not buying a shooting. The orchestrator is buying reach, and reach is an algorithmic product manufactured downstream by systems built to maximize engagement and indifferent to what they are amplifying. The recruitment side is converging on the same technology, the targeting of expendable, financially desperate young people being a pattern-matching problem at scale. This is the physical-world version of the foreign-influence dynamics that have been visible in the information layer for years, the same deniability architecture of offshore orchestration, local cut-outs, and algorithmic distribution, now load-bearing on firearms.
Now measure the bills against that. C-22’s metadata power reaches the executors, Canadian users on encrypted apps, who are already being caught, which is what this week’s arrests were. It does nothing to an orchestrator operating from outside Canadian jurisdiction through a state-protected channel a production order cannot reach. C-34’s content regime reaches the public tail of the amplification layer, the videos visible after the fact, not the encrypted recruitment and not the orchestrator. And C-34 engages artificial intelligence at exactly the wrong end. It would put a government commission in judgment of what a chatbot may say to a Canadian while leaving wholly untouched the recommender system that turns a filmed shooting into a nationwide terror product. It regulates the AI that answers a question and ignores the AI that distributes the attack. The money confirms the design. The payments reportedly move partly through cryptocurrency, which is traceable on public ledgers using ordinary analysis, no frontier AI required, but the trace dies at the cross-border off-ramp, with an endpoint no Canadian order can touch. The crypto is not the clever part. It is one more layer built to keep the orchestrator beyond domestic reach.
The threat is engineered to defeat exactly the kind of domestic legislation Canada is passing in response to it. That is not a flaw the bills can be amended around but the design of the threat, and it raises the question the framing is built to suppress. If these powers cannot stop the thing being used to justify them, what are they for?
Whether any of this even works
There is a body of evidence on this now, because Canada is not the first to try. Australia introduced an under-sixteen social media ban in December 2025, and its own online-safety regulator reports that a large majority of under-sixteens continue to reach the banned platforms, bypassing the restriction with false credentials, the same workaround that existed before. The blunt-instrument critique is not hindsight. Experts warned in an open letter before passage that the approach was too blunt to address the risks effectively, and that large-scale identity verification could backfire. The United Kingdom’s experience with age verification under its Online Safety Act tells the circumvention story plainly: VPN usage more than doubled when the requirement took effect, before receding significantly in the months after. The surge proves the behavior. Faced with an identity gate, large numbers of people route around it, and the routing-around carries its own consequence. A population pushed toward VPNs by C-34’s age verification is a population that C-22’s metadata regime then has reason to surveil. Each bill helps create the condition the next one polices.
The European Union, for its part, considered a mandatory message-scanning regime and its own Parliament rejected it, with the EU’s legal service concluding that indiscriminate scanning of private communications is incompatible with fundamental rights. The jurisdictions Canada most resembles have looked at pieces of what Canada is now assembling and either struck them down, split them apart, or watched them fail to deliver.
What can still be done
It is highly unlikely these bills will be defeated. The Carney government holds a majority, which is the reason two previous attempts at this legislation failed under a minority and this attempt probably will not. False comfort serves no one. But the worst version is not inevitable, and the leverage is specific. It sits in four places.
The first is severance at committee. The bills draw their rhetorical power from bundling, genuine child-protection measures fused to sweeping speech, surveillance, and AI provisions, so that any objection to the second can be cast as indifference to the first. That bundle is the weapon, and unbundling it is the single most achievable intervention. Separating the protection of children from the policing of adult discourse forces each to stand on its own, which is exactly what the framing is designed to prevent.
The second is C-36’s transfer of privacy authority, which is both the most consequential provision and, because of the EU adequacy exposure, the one with a concrete external check the government cannot fully control. Pressure to preserve an independent data-protection authority is not only a civil-liberties argument. It is an argument about keeping Canadian data legally welcome in Europe, and that gives it force in rooms where rights talk alone does not land.
The third is the Charter. C-22’s metadata regime runs directly into Supreme Court precedent holding that metadata linking activity to identity is private information, and C-34’s undefined hatred standard paired with content removal is close to a purpose-built expression problem. The credible prospect of constitutional challenge is itself a constraint on how broadly the final text is drawn and how aggressively any commission dares to act.
The fourth is the external pincer, the one most visible from a sovereignty vantage point. The same foreign-hosted, externally-exposed, adequacy-threatening architecture that makes these bills a sovereignty risk also makes them externally fragile. U.S. legislators are already objecting, EU adequacy hangs in the balance, and the global technology companies are prepared to exit rather than comply. The vulnerability and the leverage are the same structural fact. A regime built on dependence can be pressured through that dependence.
For Canadians who want to engage the process directly, organizations including OpenMedia are running campaigns with tools to contact lawmakers during the window that remains.
None of this stops the violence that opened the case for the bills. That is the point worth ending on. The shootings will keep being answered by the arrest of the disposable, while the architecture that produces them stays offshore, automated, and amplified beyond the reach of any Canadian law. What the legislation will leave behind is permanent domestic power over speech, over data, and over artificial intelligence, acquired under the cover of a threat it cannot touch, justified by an attribution the country’s own investigators will not confirm, running on infrastructure a foreign government can already reach, and structured in a way that may cost Canada the international standing its data depends on. The alarm is warranted. The powers point inward at citizens and outward at sovereignty, and the thing everyone is frightened of can still walk straight through the gap between them.

