Quebec Law 25 and AI: Meeting the 'Equivalent Protection' Bar Before It Costs C$25M
Quebec Law 25 makes most cloud AI usage a compliance problem before the first prompt is sent, and the mechanism is its cross-border rule: personal information may not be communicated outside Quebec unless an assessment establishes it will receive "adequate protection" in light of the destination's legal regime. A US-based AI provider cannot easily clear that bar — whatever its contract says, it remains compellable under the US CLOUD Act (18 USC 2713), which reaches data in a US provider's custody even on Canadian soil. The stakes are the highest in Canadian privacy law: penal fines up to C$25 million or 4% of worldwide turnover, administrative penalties up to C$10 million or 2%, and a private right of action. The clean answer is architectural: an on-premise model keeps personal information inside Quebec and inside the organization, so the cross-border provisions never engage at all.
What does Law 25 actually require when AI processes personal information?
Law 25 — Quebec's 2021 modernization of its private-sector privacy act, phased in through September 2024 — is not an AI statute, but four of its obligations land directly on AI deployments:
- Cross-border assessment. Before communicating personal information outside Quebec, the organization must assess whether it will receive protection equivalent to Quebec's regime, considering the destination jurisdiction's law. Every prompt containing personal information sent to an out-of-province AI endpoint is such a communication.
- Privacy impact assessments. Any project involving the collection, use, or communication of personal information — an AI rollout squarely qualifies — requires a PIA proportionate to sensitivity.
- Automated-decision transparency. Decisions based exclusively on automated processing require notice to the individual and, on request, an explanation of the principal factors — which presumes you can actually interrogate the system that decided.
- Consent, minimization, and destruction. Purposes must be specific; retention must end when purposes are fulfilled. A vendor's indefinite prompt-log retention is your compliance problem.
Why do cloud AI tools fail the equivalent-protection analysis?
Because the analysis is about law, not geography. A US provider offering a Montreal region still answers to US legal process: the CLOUD Act obliges providers subject to US jurisdiction to disclose data in their possession, custody, or control "regardless of whether" it is stored inside or outside the United States. That creates the exact scenario the assessment exists to catch — disclosure to a foreign authority without consent, without Quebec-recognized legal authority, and potentially without the organization ever being told. Our companion analysis, why "hosted in Canada" isn't enough, walks through the statute; the one-line version is that region selection changes latency, not jurisdiction.
The assessment must also weigh vendor practice: retention of prompts, abuse-monitoring access, subcontractors, training use. Each is a factor an organization must evaluate, document, monitor, and re-evaluate at every contract change — permanent compliance overhead for every AI vendor in the stack.
How do the deployment options compare under Law 25?
| Law 25 obligation | Cloud AI (US provider) | Cloud AI (Canadian region, US provider) | On-premise open-weight deployment |
|---|---|---|---|
| Cross-border assessment | Required; hard to conclude favourably | Still required — provider is the transfer | Not triggered; data never leaves |
| CLOUD Act exposure | Yes | Yes | None — no provider to compel |
| Retention/destruction control | Vendor policy | Vendor policy | Fully yours |
| Automated-decision explainability | Black-box API | Black-box API | Model, version, and logs in-house |
| Ongoing vendor monitoring | Continuous | Continuous | None — no vendor in the data path |
| Exposure ceiling | C$25M / 4% penal | C$25M / 4% penal | Standard internal-safeguard duties |
Who is most exposed?
Any Quebec organization whose AI prompts carry personal information — which in practice means nearly all of them. Three sectors carry compounding duties:
- Financial services. Quebec credit unions, insurers, and federally regulated institutions layer Law 25 on top of OSFI's Guideline E-23 model-risk expectations (effective May 1, 2027) — a combination that rewards pinned, documented, self-hosted models. See our financial services practice.
- Legal. Client files are both personal information and privileged material; after US v. Heppner (SDNY, February 2026) held consumer-AI chats unprivileged, the analysis in our lawyers-and-ChatGPT guide applies with Law 25 penalties stacked on top.
- Health and insurance. Sensitive-category information raises the PIA bar and the reputational cost of a misstep.
The workforce reality raises the floor further: security-industry surveys consistently find roughly 27% of employees admit pasting confidential data into public AI tools. Under Law 25, every one of those pastes containing personal information is an unassessed cross-border communication. Bans do not stop it; a sanctioned, better tool does.
What does the compliant-by-architecture alternative look like?
Run the model where the data lives. Open-weight models — GLM-5.2 (744B MoE, 40B active, MIT license, 1M-token context), DeepSeek, Qwen3-VL for documents — deploy on hardware the organization owns, on premises or in a Quebec or Canadian colocation rack, with SSO, role-based access, audit logging, and pinned versions. The Law 25 consequences are structural:
- No communication outside Quebec — the cross-border assessment never triggers, because nothing egresses.
- Retention and destruction under your control — prompt logs live on your systems, on your schedule.
- Explainable automated processing — you can name the model version, inspect the logs, and reproduce the behavior behind any decision.
- The PIA gets shorter — the residual risks are internal-safeguard questions you already govern, not a foreign vendor's legal exposure.
For organizations that want the architecture without running the operations, managed sovereign hosting on dedicated in-country hardware preserves the same property: residency and control stay with you; only physical operations are delegated.
Law 25 was written to make organizations accountable for where personal information goes. The strongest possible answer to "where does it go?" — the one that ends the assessment, the monitoring, and the exposure to a C$25-million fine — is nowhere.
Questions we get
Frequently asked questions
Does Quebec Law 25 apply to using AI tools like ChatGPT at work?
Yes, whenever prompts or training data contain personal information about identifiable individuals — customers, patients, employees, claimants. Sending that information to a cloud AI provider is a communication of personal information to a third party, and if the provider or its infrastructure sits outside Quebec, the cross-border assessment requirement applies before a single prompt is sent.
What is the 'equivalent protection' requirement in Law 25?
Before communicating personal information outside Quebec, an organization must conduct a privacy assessment establishing that the information will receive protection equivalent to Quebec's regime, considering the destination's legal framework. A US AI provider subject to the CLOUD Act (18 USC 2713) — under which US authorities can compel disclosure without Quebec-recognized authority — makes that conclusion difficult to defend.
What are the penalties under Law 25?
Administrative monetary penalties from the Commission d'accès à l'information reach C$10 million or 2% of worldwide turnover, and penal provisions reach C$25 million or 4% of worldwide turnover, whichever is greater. Law 25 also creates a private right of action for punitive damages.
Does Law 25 restrict automated decision-making with AI?
Yes. When an organization makes a decision based exclusively on automated processing of personal information, it must inform the person, and on request explain the principal factors and allow observations. That requires access to and control over the model's inputs and behavior — straightforward with a self-hosted model, difficult with a third-party black box.
Take the 40 Claude skills and the briefing with you
The Vault 2026 skills pack (calendar audits, hiring scorecards, calibration, continuity plans) plus the sovereignty briefing: model releases, deployment economics and regulatory shifts for regulated firms. One click to unsubscribe.
Ready to move from reading to running?
We design, build, fine-tune, host, and maintain sovereign AI deployments end to end.
Book a sovereignty assessment How deployment works