A commission built for scale, not soft letters
Bill C-34 is not subtle. Introduced as the Safe Social Media Act, it would enact a Digital Safety Act and stand up a Digital Safety Commission of Canada. Treat the bill as proposed law until it receives royal assent and comes into force. Track status on Parliament’s LEGISinfo / parl.ca. The policy goal is familiar — reduce online harm, especially to children — but the machinery is new. This is not PIPEDA-style recommendation-and-hope. The proposal contemplates monitoring, audits, compliance orders, content inaccessibility orders, and administrative monetary penalties of up to the greater of $10 million or 3% of gross global revenue. Criminal-style fine tracks go higher still on indictment.
I have sat through enough “online harms is coming” briefings over the past few years to be careful with hype. Still, the combination of scope and enforcement is different from earlier drafts that died on the Order Paper. Social media operators, AI chatbot services, and other online services sit inside the same statutory architecture. Chatbots are not an afterthought. They are a defined category with duties around harmful content, crisis intervention, and behaviours the statute treats as risky when a system simulates a relationship.
Why this matters if you are not a “platform”
Many organizations will claim they are out of scope until regulations define user thresholds and which services are “regulated.” That is fair as a legal posture. It is a poor operational posture. If you ship conversational AI, host user-generated content, or run services that allow interaction at scale with people in Canada, you should assume the Commission will eventually care how you design, log, and govern those systems.
From a governance seat, three things stand out.
First, super-regulator dynamics. Audits plus orders plus percentage-of-revenue AMPs change the internal conversation. Legal can no longer treat digital safety as a communications function. Product, security, trust & safety, and privacy have to share one control map.
Second, chatbot specificity. Treating AI chat as a regulated service class is more ambitious than most jurisdictions have gone. If you fine-tune models for companionship, coaching, or open-ended support, crisis-response and anti-dependency measures will not be optional brand values. They will be compliance artefacts.
Third, institutional stack risk. C-34 does not live alone. Privacy reform proposals and safety duties are arriving in the same political window after Bill C-27 died on prorogation. Boards should ask who owns the interface between privacy minimization and safety-driven retention, logging, and age controls.
Privacy law does not leave the building
Digital safety duties will stack on top of existing privacy obligations, not replace them. Commercial services still answer to PIPEDA and the OPC. Quebec-facing products still answer to Law 25 and the CAI. Age checks, report handling, and long safety logs are personal-information processing activities. If safety teams invent retention “for the Commission” without a privacy review, you will trade one regulatory problem for another.
What I would do this quarter
I would not wait for royal assent to start a light impact assessment:
- Inventory services that could look like social media, chatbots, or interactive online services under the bill’s concepts.
- Map existing trust & safety and privacy controls against child protection, harmful content handling, transparency (digital safety plans), and record retention for compliance proof.
- Stress-test AMP exposure language for the board: $10M vs 3% global revenue is a different conversation for a multinational than a domestic scale-up.
- Identify where product roadmaps already conflict with “safety by design” duties — especially features that increase engagement of minors or emotional dependence on AI.
- Draft a RACI that names one executive owner for digital safety and a privacy counterpart with veto on over-collection.
This bill still has to move through Parliament, and regulations will do a lot of the hard definitional work — user thresholds, which services are designated, and how “adequate” measures will be judged. That is not a reason to ignore it. It is a reason to build optionality now: modular age gates, clear content-report workflows, chatbot escalation paths, and evidence that leadership can produce under audit.
I would also assign a single executive owner. Split ownership between “legal watches the bill” and “product ships anyway” is how organizations wake up non-compliant. The Commission model rewards people who can produce a digital safety plan that matches the product that actually runs in production.
Evidence the Commission will want
Whether or not every clause survives committee, the evidence pattern is familiar from other regulators with teeth:
- A living inventory of in-scope services and features
- Documented risk assessments for child and intimate-image harms
- Timestamps from report to action
- Training records for moderators and model operators
- Vendor terms for outsourced moderation and age assurance
- Decision logs when safety and privacy conflict
If you cannot produce those in weeks, you cannot produce them under order.
Actionable takeaway
Treat Bill C-34 as a proposed design constraint on Canadian digital products, not only a social media story. Confirm status on parl.ca before you brief the board as if it were already law. If a Digital Safety Commission can audit, order, and fine at global-revenue scale, the winners will be organizations that can show — with records — how safety, privacy, and product decisions fit together before the first information request arrives. Start the inventory now, while scoping is still a planning exercise rather than a response to an order. Keep privacy primary sources — OPC / PIPEDA and, where relevant, CAI — in the same binder so safety expansion does not become unlawful over-collection by another name.