Agentic AI Is Outpacing Canada’s Governance Playbook

Share

There is a version of AI governance that works reasonably well: a human submits a prompt, a model produces an output, and someone reviews the result before anything consequential happens. Canada’s existing frameworks — the Voluntary Code of Conduct on the Responsible Development of Advanced Generative AI Systems and the proposed Artificial Intelligence and Data Act — were largely designed with that version in mind.

Agentic AI is a different animal entirely.

Unlike conventional generative models that respond and wait, agentic systems plan sequences of actions, invoke tools, browse the web, write and execute code, manage files, and interact with external services — all with limited moment-to-moment human involvement. They don’t just answer questions; they pursue objectives. And when something goes wrong inside a multi-step autonomous pipeline, the failure can propagate well before any human has the opportunity to intervene.

What Guardrails Were Built For

Canada’s Voluntary Code of Conduct, introduced by Innovation, Science and Economic Development Canada in 2023, asks signatories to implement safeguards around safety, fairness, transparency, and human oversight. On paper, those commitments sound applicable to any AI system. In practice, the code’s framing assumes a relatively contained interaction model — one where a human is meaningfully in the loop at the point of decision.

Agentic architectures challenge that assumption structurally. When an AI agent is given a high-level goal and the autonomy to pursue it across dozens of sub-tasks, the “human oversight” envisioned by the Code may only occur at the beginning and end of a workflow — with a sprawling, largely opaque chain of machine decisions in between. The Code offers no specific guidance on how oversight obligations apply to orchestration layers, tool-calling behaviour, or multi-agent pipelines where one model delegates tasks to another.

AIDA, which has been stalled in Parliament and faces an uncertain future under a new government, attempted to introduce binding obligations for “high-impact” AI systems — including requirements for risk assessment, transparency, and human monitoring. But the draft legislation was developed against a baseline of AI capabilities that have since been substantially overtaken. The agentic systems now entering enterprise deployment weren’t the reference point when AIDA’s risk thresholds were being written.

The Specific Failure Modes That Matter

The risks that agentic AI introduces aren’t hypothetical. Security researchers have demonstrated prompt injection attacks — where malicious instructions embedded in external content hijack an agent’s behaviour mid-task. An agent browsing the web on behalf of a user can encounter a webpage specifically crafted to redirect its actions. An agent with access to email and calendar tools can be manipulated into exfiltrating information or taking actions the user never authorized.

Multi-agent systems compound this problem. When one AI model orchestrates others — passing instructions, interpreting results, and making branching decisions — accountability becomes genuinely difficult to assign. Which agent in the chain is responsible for an error? Which organization is liable when a third-party tool called by the agent produces harmful output? Canadian law has no settled answers to these questions, and neither AIDA nor the Voluntary Code provide a framework for untangling them.

Beyond security, there are subtler failure modes: agents that pursue their objective function in technically compliant but contextually inappropriate ways, systems that accumulate permissions over time in ways their deployers didn’t anticipate, or orchestration layers that amplify bias across repeated automated decisions affecting real people.

What the Gap Looks Like in Practice

For Canadian organizations deploying or building agentic systems — and there are a growing number of them, particularly in financial services, legal tech, and enterprise software — the governance vacuum creates genuine exposure. The Voluntary Code’s signatories have made public commitments they may struggle to honour in agentic contexts, not from bad faith, but because the commitments weren’t designed with autonomous multi-step systems in mind.

Enterprise adopters face a related challenge: standard vendor contracts and AI use policies weren’t written to account for agents that can take actions on behalf of users across third-party platforms. The liability questions that arise when an agent makes a consequential error — deletes a file, sends an unauthorized communication, triggers a financial transaction — don’t map cleanly onto existing legal or regulatory frameworks.

Canada is not alone in this. The EU AI Act, which is further along than anything Canada has passed, also largely predates the agentic turn and is already being stress-tested by practitioners trying to apply its risk classifications to systems that don’t fit neatly into “high-risk” or “limited-risk” buckets.

The Regulatory Fork in the Road

The more pressing question for Canadian policymakers is not whether to regulate agentic AI — it’s whether any regulatory initiative can be designed to remain relevant as the underlying technology continues to evolve rapidly. Prescriptive rules written for today’s agentic systems risk being obsolete before they’re enacted.

A more durable approach would focus on principles that are architecture-agnostic: meaningful accountability at the organizational level regardless of how many automated steps occur between a human decision and a system action; mandatory incident reporting for agentic failures with material consequences; and clear expectations that human oversight obligations apply to the design of the system, not just to individual interactions.

None of that is currently explicit in Canada’s framework. And as agentic AI moves from research environments into production systems touching real decisions — in healthcare, finance, law, and government services — the gap between what Canada’s governance infrastructure assumes and what is actually being deployed will become harder to ignore.

The crossroads that agentic AI presents isn’t only technical. It’s a test of whether governance frameworks can be adapted quickly enough to address capabilities that weren’t anticipated when the frameworks were conceived. On current evidence, Canada’s mechanisms are not yet positioned to pass that test.

Source

Agentic AI’s crossroads: guardrails or massive fails | TechRadar

Scott Holmes
Scott Holmes
Scott Holmes is the Founder and Editor of InsightTrack AI, a Canadian publication covering artificial intelligence news, governance, security, and infrastructure. Based in Ontario, Canada, he brings more than 20 years of technology experience, including at Ericsson Canada, and holds PMP, CCNA, ITIL v3 Foundations, and Six Sigma certifications. His areas of expertise include AI governance, telecommunications, critical infrastructure, cybersecurity, and automation.

Read more

Local News