Norton Rose Fulbright Canada LLP

09/16/2026 | Press release | Archived content

AI governance for corporate boards

As discussed in our 2026 Technology Summit webinar, the exponential growth of artificial intelligence (AI) technologies across industries has made AI governance a central issue for boards and management teams. As AI adoption continues to accelerate, investors, regulators, and other stakeholders are increasingly inquiring about recommended governance structures to manage AI-related risks and opportunities.

As Canada advances its National Artificial Intelligence Strategy: AI for All, boards and management teams should proactively identify, assess, and manage AI-related risks. This legal update highlights key considerations for effective AI oversight and offers practical prompts to help organizations strengthen their AI governance frameworks.

National Artificial Intelligence Strategy: AI for All

On June 4, 2026, the federal government unveiled Canada's National Artificial Intelligence Strategy: AI for All - an ambitious blueprint designed to accelerate AI adoption across the economy. The strategy targets substantial economic impact, projecting up to C$200 billion in GDP gains driven by enhanced productivity and the creation of as many as 250,000 jobs by 2031.

Canada's AI for All strategy is centred around six pillars:

  1. Protecting Canadians and safeguarding our democracy: Build trust in AI through stronger privacy protections, enhanced oversight, and safeguards against AI-related harms.
  2. Empowering Canadians: Expand AI literacy and access by equipping Canadians with the skills and training needed to participate in an AI-driven economy.
  3. Powering AI adoption for shared prosperity: Support businesses in adopting AI technologies to enhance productivity, innovation, and competitiveness.
  4. Building the Canadian sovereign AI foundation: Strengthen Canada's sovereign AI infrastructure by expanding national compute capacity and digital connectivity.
  5. Scaling Canadian champions: Support the growth and global competitiveness of Canadian AI companies by improving access to capital and scaling opportunities.
  6. Building trusted partnerships and global alliances: Strengthen Canada's AI ecosystem through strategic international partnerships, investment attraction, and expanded global market opportunities.

Despite this forward-looking national agenda, Canada has yet to enact a comprehensive federal regulatory framework governing AI. The Artificial Intelligence and Data Act was introduced through Bill C-27 in 2022, but the bill died when Parliament was prorogued in January 2025. It was intended to create a national AI governance framework. Without a dedicated federal AI statute in place, AI in Canada remains subject to a patchwork of existing legal regimes.

AI governance risk and rising investor expectations

As AI becomes increasingly integrated into core business operations, the growth opportunities it presents are inseparable from a widening web of legal, operational, and reputational risk. Investor expectations are shifting in lockstep, raising the stakes for organizations that fail to demonstrate rigorous oversight. For boards and management teams, AI governance is now a critical aspect of enterprise risk management, not just a technology issue or an issue for technology companies only.

Regardless of sector, AI is increasingly being integrated in all aspects of a business life cycle - from recruitment and training to marketing, sales and delivering goods and services, and a myriad of administrative support functions in between. While boards may appropriately delegate day-to-day operational risk management to the management teams closest to the business, ultimate accountability for enterprise risk management rests with the board.

While comprehensive federal AI legislation has yet to materialize, investors in public companies are increasingly pressing boards to disclose how they approach AI. Investors want clarity on key risks, opportunities, and guardrails. For example, during the 2025 and 2026 proxy seasons, the Mouvement d'éducation et de défense des actionnaires (MÉDAC) submitted more than nine AI-related shareholder proposals at several major Canadian financial institutions. Those proposals generally sought greater transparency around using AI in decision-making and risk assessment.

The Shareholder Association for Research and Education took a similar step, submitting a proposal to Shopify in 2026, calling on its board to adopt a policy on responsible AI use aligned with internationally recognized standards and respect for human rights. None of these proposals passed. They nonetheless reflect mounting shareholder interest in AI governance and signal that scrutiny of AI-related disclosure and oversight will only increase.

What boards need to know about AI governance

Governance structures will vary by organization depending on size, sector, and the extent of AI integration. To provide effective oversight, boards must first understand how AI is being used within the company (both currently and as planned), how it affects strategy and operations, and how their broader industry is adopting it. Key board considerations include:

  1. Understanding AI risks generally to meet oversight responsibilities.
  2. Ensuring management identifies the company's AI uses, systems, and associated risks.
  3. As part of its overall risk oversight responsibilities, setting the company's AI risk appetite (within the company's general risk framework) and confirming appropriate policies, processes, and structures (including escalation protocols) are in place.
  4. Overseeing ongoing AI risk assessment and monitoring through regular reporting from management.
  5. Ensuring documentation and controls exist to support transparency, compliance, and auditability.

While AI is expected to play a role in all companies regardless of sector, companies that develop, deploy, market, or sell AI systems (i.e., developers as opposed to users only) face a heightened standard of accountability. Their control over system design and data means flaws can cascade across every user of their AI products, amplifying liability exposure. These companies should consider nominating a director with AI and emerging technology expertise to their boards, establishing processes for gathering external feedback on AI system impacts, documenting AI-related risks, evaluating applicable AI disclosure requirements (particularly for public companies), and forming a dedicated risk management committee to oversee AI activities.

Companies that are primarily users of AI face a different but equally important set of considerations. They should regularly monitor third-party AI risks and benefits, engage external experts where in-house expertise is limited, and establish clear protocols for incident reporting with documented tracking and recovery processes. Organizations should also define proficiency requirements for AI operators and ensure policies, training programs and relevant certifications are maintained.

Whether as developers or users of AI, companies should periodically assess their AI systems for inherent biases and take appropriate steps to remediate any issues identified. Equally important, employees should receive ongoing training on AI use, associated risks, and best practices to ensure responsible adoption at every level of the organization.

One question that often comes up is whether to use AI tools to record and/or produce draft minutes of board or committee meetings. While the convenience offered may be compelling, recording board or committee meetings with AI tools is not recommended as doing so may deter directors from speaking freely, undermining the candor essential to effective governance.

As AI technologies continue to reshape industries and investor expectations evolve, boards and management teams are taking, and are being encouraged to take, deliberate steps to ensure their organizations are prepared to manage AI-related risks while capturing its significant opportunities. For a deeper discussion of the issues outlined in this update and customized advice for your board, management team, and organization, we encourage you to view our 2026 Technology Summit webinar and to reach out to our team.

AI governance: Where to start

To support your organization's approach to AI governance, we have included a few prompts below covering board matters, technology matters, and employment matters. These questions are designed to help boards and management teams identify key areas of focus and take concrete steps toward strengthening their AI oversight frameworks. For further guidance, please reach out to our team to discuss how we can support your organization's AI governance priorities.

A. Board Matters
  1. Does the board possess the necessary AI expertise and, where needed, is that expertise being supplemented through external advisors and targeted education sessions?
  2. Has the board refrained from using AI tools to record board meetings in order to preserve open and candid discussion among directors?
  3. Has the board formally assigned responsibility for AI oversight to the board or a designated committee, and is this responsibility clearly reflected in its mandate or charter?
  4. Has the board reviewed its disclosure policies and, where appropriate, amended them to address AI-related disclosures?
B. Technology Matters
  1. Has the board ensured appropriate measures are in place to safeguard data, monitor privacy risks, and require suitable vendor due diligence?
  2. Has the board assessed whether the organization's AI systems may produce biased outcomes, and has management implemented appropriate measures to identify, mitigate, and remediate such biases?
  3. When deploying or overseeing agentic AI systems, has the board ensured that:
    1. Emergency shutdown mechanisms or override controls are established and tested.
    2. Processes are in place to monitor for consistent, reliable, and expected behaviour patterns.
    3. Clear operational boundaries, authorities, and limitations have been defined for the AI's activities and decision-making?
C. Employment Matters
  1. Has the board ensured the organization has developed and implemented policies governing the use of AI, including key considerations for its adoption, deployment, and integration across the company, and implementation of safeguards to protect against potential bias?
  2. Has the board ensured the organization complies with employment standards relating to the use of AI, such as Ontario's Working for Workers Four Act?
  3. Has the board considered intellectual property implications related to AI, including ownership and assignment of AI-generated outputs, protection of the company's intellectual property, and potential exposure to third-party infringement claims?
  4. Has the board ensured employees receive ongoing training on the appropriate use and risks of AI, as well as best practices?

The authors wish to thank Shayanti Roy for her help in preparing this legal update.

Norton Rose Fulbright Canada LLP published this content on September 16, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 22, 2026 at 12:24 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]