The Missing Half of Canada’s AI Strategy
Better models and Canadian data centres will not fix public-service AI if governments cannot agree on which data to trust.
Canada's AI future depends on more than better models. Trusted data infrastructure will determine whether AI can deliver secure, interoperable public services.
The nurse from my last article, the one who moved from Halifax to Calgary and had to re-prove her identity, licence, and health coverage to four separate systems, offers a useful test for an AI assistant.
AI could guide her through Alberta’s forms, retrieve information, and compare records. It could not legitimately determine which record Alberta may treat as authoritative. That question belongs to law and institutional mandate, not model capability.
In two earlier articles, I argued that Canada measures digital government against the wrong model and needs a digital public infrastructure agenda suited to a federation. The next question is more specific: what infrastructure would allow information to move lawfully between institutions without creating a single national database?
Canada needs a pan-Canadian federated data exchange through which authorised institutions can confirm facts, such as income, residency, identity, or licence status, while records remain with the institutions responsible for them.
That ecosystem requires three connected capabilities. Identity and assurance establish confidence in the people, organisations, systems, and credentials involved, proportionate to the transaction’s risk. Trusted exchange transmits verified information securely. Trusted governance determines which sources are authoritative, who may request information, for what purpose, and with what accountability and redress.
For the nurse, this does not require a mandatory national digital ID or universal identifier. Canadians already establish identity in different ways, such as presenting a driver’s licence in person, using an existing government account, or presenting a passport or professional credential. The method should match the transaction’s risk. Alberta needs sufficient assurance that the applicant is the person named in the Nova Scotia record, that the regulator is genuine, and that the credential has not been altered. Non-digital routes must remain available.
The exchange only works within a broader operating model: one that identifies authoritative sources, assigns decision rights, defines lawful purposes, sets proportionate assurance requirements, and provides correction, redress, and accountability. The Pan-Canadian Trust Framework (PCTF) can provide part of the identity and assurance foundation. The objective is not one national digital identity, one government-owned credential, or digital-only access.
An authorised service would request only the verified information required for a specific transaction. The record would remain at its source, and each request would be authenticated, logged, and auditable. The answer could move directly between institutions or be presented by the individual as a verifiable credential.
AI Is Only as Reliable as the Data Operating Model Beneath It
Canada’s new national AI strategy, AI for All, launched on 4 June 2026, emphasises adoption, commercialisation, talent, trusted partnerships, sovereign compute, and public-service transformation. These are necessary investments. They are not sufficient.
Canada does not have a shortage of government data. It has a data operating model problem.
Much of the necessary information already exists. What institutions lack is a shared operating model for determining which information is authoritative, when it may move, how its provenance is preserved, and who remains accountable for its use. Alberta should not need to ask a nurse to re-prove what Nova Scotia already knows, but it also cannot retrieve that information without agreed authority, assurance, and exchange rules.
The federal government recognises parts of this problem. Its 2023–2026 Data Strategy for the Federal Public Service treats data as a strategic asset and calls for interoperability, stewardship, and reuse. The limitation is not the strategy’s intent. It is that most data initiatives still operate within organisational, sectoral, or jurisdictional boundaries.
Health care illustrates the difference between digitisation and governed exchange. In February 2026, Ottawa introduced Bill S-5, the Connected Care for Canadians Act, which would require digital health vendors to meet common interoperability standards and prohibit data blocking. The legislation responds to a real problem: only 29 per cent of Canadian health-care providers shared patient information electronically outside their own practices.
S-5 creates an important technical floor for one sector. It does not by itself create a complete cross-jurisdictional operating model governing authority, assurance, accountability, and redress.
With clear rules, AI becomes far more valuable. It can assemble verified information, support eligibility assessments, coordinate transactions across institutions, and initiate service workflows because the operating model establishes which information can be trusted, who may use it, and for what purpose.
Alberta’s recently published Velocity White Papers point in the same direction. Their vision of AI-enabled government allows intelligent agents to work directly against governed data rather than through conventional applications, potentially transforming how governments modernise services. But governed data within one organisation is not the same as governed data across jurisdictions. When an AI agent needs information from another ministry, province, or public authority, the surrounding operating model must establish whose record is authoritative, how the person, organisation, and system have been authenticated, whether the information may lawfully be exchanged, and who remains accountable for the resulting decision. As AI lowers the technical barriers to modernisation, the harder questions, who is being authenticated, whether the exchange is lawful, and who answers for the result, matter more, not less.
Canada Has Started, but It Has Not Finished
The Canadian Digital Exchange Platform (CDXP) is a meaningful federal foundation, but not yet a jointly governed exchange layer that provinces, territories, Indigenous governments, municipalities, and authorised private-sector participants can join and trust.
The PCTF has been under development since 2014 through the Joint Councils, working with the Digital ID and Authentication Council of Canada. Its Public Sector Profile addresses trust in identities, credentials, organisations, infrastructure, privacy, and transactions. It provides an important basis for deciding who and what can be trusted, and at what assurance level.
Canada has pieces of all three capabilities; it lacks an operating model that integrates them into a coherent digital trust ecosystem.
Technology is only half the challenge. Governments must also establish lawful authority to exchange information.
Parliament is considering Bill C-36, the Protecting Privacy and Consumer Data Act, introduced on 15 June 2026, while the federal Privacy Act remains under separate review. Provinces and territories operate under their own privacy, health, tax, education, and professional-licensing statutes. Many of these laws restrict when information may leave a department, sector, or jurisdiction.
Secure networks and shared APIs cannot create authority that does not exist in law. Some pathways will require new agreements, regulations, or legislation, and that work needs to begin before the infrastructure is complete.
Privacy and lawful authority belong in the design from the outset, through purpose limitation, correction, redress, accountability, and consent where appropriate.
What a Canadian X-Road Equivalent Would Require
The underlying principle is straightforward. X-Road allows information to move directly between an authorised requester and the institution holding the record, without pooling the information in a central database.
A Canadian version would require more than compatible software: operational connections, service-specific permissions, legal agreements, shared assurance standards, and enforceable accountability. The trust ecosystem around the technology matters more than the technology itself.
Estonia and Finland jointly steward X-Road through the Nordic Institute for Interoperability Solutions (NIIS), with Iceland later joining. Québec has also established a relationship with the institute.
Canada does not need a single exchange controlled from Ottawa. It needs compatible federal, provincial, territorial, Indigenous, municipal, and sectoral environments, alongside trusted private-sector identity and credential services. Private participants should operate under open, publicly governed trust standards and assurance requirements rather than set the rules themselves.
Alberta’s emerging approach to digital trust points the same way. It calibrates assurance to the risk of the service and permits different evidence and methods, rather than assuming that government must own a single digital identity for every person.
Institution-to-institution exchange is one route. User-controlled wallets are another when individuals should review and present credentials themselves. The approaches should complement each other, and non-digital alternatives remain essential.
This is not solely a Nordic idea. The European Union’s Once-Only Technical System went live across member states on 12 December 2023. It allows public authorities to retrieve official documents from authentic sources in other member states at an individual’s request.
If 27 sovereign states can build cross-border exchange without a central database, institutional complexity is not a sufficient excuse for Canadian inaction.
The Exchange Must Preserve Authority and Rights
A trusted exchange requires three controls: the authoritative record remains with its source and every exchange is logged; each request is limited to the minimum information necessary; and people can see what was requested, correct errors, challenge decisions, and seek redress.
These protections matter even more when AI is involved. Authority to exchange information for service delivery is not authority to train a model. Each purpose needs its own legal basis and accountability.
Authority over data is distributed across Canada, and First Nations, Inuit, and Métis governments hold distinct rights and governance authority.
Indigenous data governance provides the clearest example. The First Nations principles of OCAP® (Ownership, Control, Access, and Possession) establish that First Nations governments and data systems, not a national platform, determine whether, how, and on what terms their information is shared. A federated, ask-on-demand architecture is more compatible with this principle than central data pooling because records can remain under the possession and control of the governing community unless it authorises a specific exchange. In some cases, that may require an Indigenous-controlled exchange environment. In others, the appropriate decision may be not to share the information at all.
For every exchange, four questions should govern: who has authority over the information, who may use it, for what purpose, and who benefits while bearing the risk?
Begin with One High-Value Pathway
Health care demonstrates the need for interoperability, but it is not the easiest place to prove the broader operating model. Bill S-5 addresses technical standards, not the full question of cross-jurisdictional authority. Benefits and labour mobility are better starting points.
Applicants for income-tested programmes routinely resubmit information public institutions already hold, including identity, income, residency, and family composition. A federated exchange could verify those facts at their source or issue credentials for applicants to review and present.
The Canada Revenue Agency is one natural candidate to anchor the income-verification component of such a pathway, holding the authoritative income record for most Canadians and administering benefits for the federal government and most provinces and territories. But the pathway matters more than the institution: Employment and Social Development Canada and provincial benefit administrators hold complementary authoritative records, and the first exchange could begin with any of them. This pathway need not wait for comprehensive legislative reform. Some initial exchanges may be possible under existing consent-based disclosure authorities and intergovernmental agreements, including machinery similar to that which has carried tax collection agreements for decades. That would allow Canada to test parts of the model while the remaining legal work proceeds. Legislation can formalise and scale arrangements once they have been demonstrated in practice.
OECD research on fraud in social-benefit programmes indicates that verification at the registration stage, before a false identity or income claim enters the system, is the highest-leverage point for preventing both fraud and administrative error. Matching records after the fact is more resource-intensive and often occurs only after money has already been paid or an individual has been wrongly denied support.
Labour mobility is a natural second pathway because it tests the same capabilities across different legal authorities.
Alberta could ask Nova Scotia to confirm that the nurse’s licence is valid and in good standing, or Nova Scotia could issue her a verifiable credential. Either route replaces repeated submissions with a trusted assertion from the authoritative source.
Canada should select a pathway within a year, establish the governing agreements and technical connections within three, and have at least one cross-jurisdictional service operating at production scale within five. One pathway governed by common trust, legal, and accountability rules will teach more than a dozen announcements.
Govern and Measure It as Shared Infrastructure
The practical case for participation is substantial. A shared operating model can reduce repeated proof, manual verification, processing delays, and correction costs for every service connected to it. It can also lower the marginal cost of adding the next programme or jurisdiction because identity-and-assurance standards, exchange mechanisms, and accountability rules do not have to be rebuilt each time. The same foundations give AI access to verified information with known provenance, defined lawful purposes, correction mechanisms, and clearly assigned institutional accountability.
The incentive problem is that connection costs are immediate and concentrated, while many benefits are distributed across departments, governments, and future users. A province that pays to connect an authoritative source may not capture the full return. Shared funding, reusable infrastructure, reciprocal access, and transparent measures of burden reduced and time saved will therefore be necessary to make participation rational for each jurisdiction, not merely desirable for the federation as a whole.
No single government should own this ecosystem. Canada’s Joint Councils model offers a better starting point: a multilateral forum in which federal, provincial, territorial, Indigenous, and other participating governments can jointly steward common trust standards while retaining authority over their own records and services. The convening function should be neutral and collaborative, not controlled by Ottawa or any other single participant.
Whatever institutional arrangement is chosen, it must maintain common standards, recognise participants, oversee shared technical services, resolve disputes, and leave accountability with the institution responsible for the authoritative record. The coordinating body may change, but those functions must endure. Canada Health Infoway demonstrates that an arms-length, jointly governed body can operate across the federation: for more than two decades, it has co-invested with every province and territory in shared digital health foundations without a dedicated statute. Its record also carries a harder lesson. Co-investment without binding adoption commitments produces projects rather than connection, which is why participation and use, not construction, should be conditions of shared funding.
Germany’s experience implementing the Online Access Act demonstrates how difficult this coordination can be. Technical platforms do not eliminate fragmented authority, competing incentives, or uneven institutional capacity.
Progress should be measured through transactions rather than announcements: participants and services in production, requests eliminated, processing times reduced, errors corrected, and evidence that people can move between jurisdictions without repeatedly proving the same facts.
Activity without better services is not progress.
The Missing Infrastructure Beneath AI
Until Canada can confirm who someone is, move that confirmation between institutions lawfully, and say clearly who is accountable for the result, the nurse moving from Halifax to Calgary will continue proving information governments already possess.
AI may help her complete forms and identify inconsistent records, but it will not fix the operating model beneath them. AI turns governed information exchange from a digital-government improvement into a foundational operating requirement for the public sector.
That, rather than better chatbots, is the missing institutional half of Canada’s public-service AI strategy.
Sovereign compute determines how much AI Canada can run. A digital trust ecosystem built on identity and assurance, trusted exchange, and trusted governance determines whether that AI can complete the public services Canadians rely on.
