Canada public-company observatory

Who controls enterprise AI in Canada?

Track what Canadian public companies disclose about control of AI data, models, compute, and suppliers. Every published classification is labeled as reviewed or automated screening and linked to official-source evidence.

Full TSX and TSXV listed-company coverage, paired with an official-source evidence layer built from issuer-hosted PDFs and filed SEC annual reports with traceable excerpts.

"AI risk management" includes governance, privacy, cybersecurity, controls, oversight, vendor risk, responsible-use language, and disclosure-lens themes tied to AI.

Universe mapped: 3,700 entities | Official-source evidence: 1,483 records
As of 2026-07-29
Next scheduled refresh: 2026-08-05
← Back to dashboard
← Back to dashboard

Compare

Two issuers, side by side

← Back to lenses

Executive signal

AI exposure is visible. Internal control evidence is scarce.

Filings discuss sovereignty, compute, local models, and vendors in very different contexts. The important distinction is whether a company describes its own deployment, a customer offering, an investment, a risk, a plan, or explicit non-use.

The chart separates those postures so product marketing and risk boilerplate are not mistaken for internal operating architecture.

Automated screening is evidence discovery, not human verification. Only reviewed internal-deployment evidence supports a company-use claim.

Control evidence by disclosure posture
Issuer counts by posture in screened or reviewed AI-linked evidence. Internal deployment is not presented as confirmed company use unless manually reviewed.

The AI Governance Gap

Mentioning AI is not the same as governing it.

The observatory scores every issuer filing on two independent axes: AI mentions (do they talk about AI?) and AI governance (do they disclose how they govern it?). The gap between the two is the first measurable Canadian baseline. Numbers refresh weekly; the chart below is live.

Paired bars per issuer: slate = AI mention vocabulary, gold = explicit AI governance vocabulary. Full term lists in the methodology.

AI mentions vs governance disclosure per issuer
Top issuers: AI mentions (slate) vs explicit AI governance disclosure (gold), 2024-2026. The gap is the story.

Disclosure lenses

Control evidence across data, models, compute, and suppliers

Disclosure lenses are evidence signals, not proof of actual internal architecture.
Filing layer Official-source report corpus

Public evidence rows are generated from issuers' SEDAR+ continuous-disclosure filings (accessed via TMX Money), filed SEC filings, and issuer-hosted reports - each with traceable excerpts and source links.

Refresh cadence Weekly scheduled rebuild

TSX universe refresh, issuer PDF ingestion, SEC annual filing refresh, validation, and static bundle rebuild.

Evidence boundary Public research edition

The site publishes compact screened or reviewed evidence. Full source text, unreviewed candidates, and analyst operations remain private.

Listed entities tracked 3,700 Current TSX plus TSXV listed-company universe from the official directory
Official-source evidence records 1,699 Current signal records across SEDAR+, SEC, and issuer-hosted sources; legacy TMX history is being migrated to document-level accounting
AI mentions captured 7,615 Total explicit AI, generative AI, machine learning, and related mentions across the signal corpus
AI risk mentions 25,540 Mentions tied to AI governance, privacy, cybersecurity, controls, oversight, vendor risk, and responsible-use language

Coverage progression

Official-source corpus by year

Official-source documents Explicit AI-signal documents

Coverage model

How to read this dataset

Universe first

The dashboard starts with all currently listed TSX and TSXV entities before adding document-level evidence.

Corpus second

The evidence layer shows which companies already have parsed official-source documents in the current dataset.

Signals third

Filings are ranked only when they contain explicit AI language rather than generic technology boilerplate.

Coverage boundary

The listed-company universe is broad, while the verified-document layer expands through issuer PDFs, filed SEC annual reports, investor-relations resolution, and queued SEDAR+ sources.

Signal corpus

Ranked official-source reports with explicit AI terms

1,483 evidence records
Company / filing Exchange Year Signals Evidence Source

Exchange footprint

Listed universe vs matched filing coverage

Highest-signal companies

Companies surfacing the most AI language

532 companies

Listed company universe

All TSX and TSXV entities currently loaded

3,700 entities
Company Exchange Symbol Bucket Variants

Methodology

How to interpret the observatory

This observatory separates the full TSX/TSXV directory from the narrower official-source evidence layer. Candidate language is found deterministically, classified by disclosure posture, and published only as reviewed evidence or clearly labeled automated screening with a compact excerpt and source link.

1. Universe layer

The full TSX and TSXV listed-company directory is enumerated from the official TMX listing data, giving the broad-market denominator.

2. Filing layer

Official-source evidence comes from SEDAR+ continuous-disclosure filings identified through the current POC source, SEC filings, and issuer-hosted reports. Future weekly runs check filing metadata across the universe and download only new or previously failed documents.

3. Two-tier signal scoring

Deterministic dictionaries find high-recall candidate language. A structured context layer then classifies subject, polarity, temporality, jurisdiction, and posture: internal deployment, customer product/service, investment exposure, risk disclosure, planned/exploratory use, denied/non-use, or unclear. Candidate evidence remains private. Automated screening never supports a company-use claim; only manually reviewed internal-deployment evidence can do so. The AI mentions/governance gap remains a secondary baseline. Field-level definitions are in the data dictionary.

4. Refresh & reproducibility

The public research edition rebuilds weekly with an explicit "as of" date. Each public evidence row carries one compact excerpt and an exact source link. Complete evidence ledgers and analyst operations remain private/professional.

Limitations & coverage boundary

  • Universe vs evidence layer. The listed directory spans TSX/TSXV entities, while evidence coverage depends on successful filing metadata retrieval and text extraction. Failures are reported separately from clean scans.
  • Filing data source. SEDAR+ is not scraped directly (its terms prohibit automated access); issuers' SEDAR+ continuous-disclosure filings are accessed through TMX Money, the exchange's own public market-data service. SEC EDGAR provides an independent lane for the cross-listed minority.
  • Funds vs operating companies. ETFs, index funds, and split-corps that mention AI in an investment mandate are segmented out of the company headline - they are not operating companies governing their own AI use - and reported separately.
  • Historical migration. Existing TMX history contains legacy issuer-year aggregates. New filings use document-level provenance; a deliberate historical migration is required before older records have equivalent accounting.
  • Screening, not semantic certainty. Dictionaries and structured posture rules improve context but remain automated screening until manually reviewed. The seed accuracy set is not publication-grade until every lens meets its sample threshold.
  • Disclosure lenses are not architecture proof. Newly refreshed lens matches are scored from extracted filing text, then compacted to short public excerpts. Broad lens matches show topic disclosure; AI-linked matches show disclosed language near AI terms in official filings. Neither proves that a company runs AI on-prem, hosts local models, or uses a specific vendor architecture.
  • Disclosure ≠ adoption. A company may use AI without disclosing it, or disclose aspirationally. The observatory measures what is written in official documents.

Professional pilot

Canada AI Control Intelligence Pilot

Turn public disclosure signals into a decision-ready benchmark for one company and a selected peer group. The pilot is built for corporate secretaries, CROs, CISOs, general counsel, investor-relations leaders, internal audit, strategy teams, and board-risk stakeholders.

Scope One company plus up to 20 peers

A focused watchlist selected around sector, market, or board relevance.

Timeline Two-week fixed scope

Delivered manually before recurring software or subscription infrastructure is built.

Evidence Complete evidence ledger

Reviewed context, posture classification, exact sources, peer comparison, and filing-change watchlist.

Decision output Board-ready findings brief

Executive interpretation, priority gaps, and a 60-minute readout with Aeon.

Request a 20-minute pilot fit call Founding-pilot scope: two weeks, one company plus up to 20 peers. The fixed fee is confirmed during the fit call.

Cite & reuse

Cite this observatory

The public research edition contains Aeon's compact derived classifications and source-backed evidence. Full evidence ledgers, monitoring, exports, and analysis are part of the professional pilot.

Recommended citation

Aeon AI Risk Management. Canada AI Disclosure & Governance Observatory. Zenodo. https://doi.org/10.5281/zenodo.20802285 (accessed 2026).

DOI: 10.5281/zenodo.20802285 · current release: 2026-07-29 · rebuilt weekly

FAQ

Frequently asked questions

Key findings as of July 2026. Figures rebuild weekly; the dashboard above always shows the current release.

How many Canadian public companies disclose AI governance?

As of July 2026, of the 515 TSX- and TSXV-listed companies that mention AI in their official filings, 58 (11%) disclose explicit AI governance language - named AI governance programs, AI risk or impact assessments, AI lifecycle controls, or AI-anchored model-risk oversight. The other 89% mention AI without disclosing how they govern it. Coverage spans the full TSX and TSXV universe (3,700 listed entities) via SEDAR+ continuous-disclosure filings, not just the SEC-filing subset.

What is Canada's "AI governance gap"?

It is the difference between the companies that mention AI and the smaller set that disclose how they govern it. As of July 2026 the gap is 89%: nearly nine in ten AI-mentioning TSX/TSXV companies disclose no explicit AI governance language. Across the full listed universe, mentioning AI is now common while explicit governance disclosure stays rare - only about one in nine of AI-mentioning companies discloses how it governs AI.

Which Canadian companies disclose the most about AI governance?

As of July 2026, the companies with the most AI governance disclosure are TELUS, BCE, RBC, CIBC, Docebo, and Thomson Reuters - led by telecoms and banks rather than technology companies.

What sources and method does the Observatory use?

It enumerates the full TSX/TSXV listed universe (~3,700 issuers) and scores official-source documents on two independent axes: whether an issuer mentions AI, and whether it discloses how it governs AI. Coverage spans the full universe via issuers' SEDAR+ continuous-disclosure filings (MD&A, annual information forms, financial statements, information circulars) sourced through TMX Money, plus SEC filings (Form 40-F, 6-K, 20-F via EDGAR) for cross-listed issuers and issuer-hosted reports. Every signal links to its source, and the dataset rebuilds weekly. The Observatory does not scrape SEDAR+ directly (its terms prohibit automated access); SEDAR+ filing data is accessed through TMX Money, the exchange's own public market-data service.

What are the disclosure lenses?

Disclosure lenses locate AI-linked language for privacy, data sovereignty, compute sovereignty, open-weight or local models, third-party AI vendors, and AI cyber or abuse risk. Each match is then classified as internal deployment, customer product/service, investment exposure, risk disclosure, planned/exploratory use, denied/non-use, or unclear. Screened evidence is automated and does not prove company use.

Is the data free, and how do I cite it?

Yes. The dashboard, report, public research CSV/JSON, and Aeon's original public annotations and aggregates are available with attribution, subject to source rights. The professional tier adds full evidence ledgers, monitoring, exports, and analysis.

Who maintains the Observatory?

It is built and maintained by Aeon AI Risk Management, a global AI implementation, Private AI, cybersecurity, and governance practice with AIGP, CISA, CRISC, and FRM credentials.

Source frame

TSX listed company directory Issuer-hosted annual report and meeting materials SEDAR+ SEC EDGAR full-index master files

Contact

Questions, corrections, or source additions

If you spot a document issue or want to suggest an additional public-company source, contact info@airiskmanagement.ca.

Aeon network

Need monitored, audit-ready disclosure evidence?

Use the public Observatory as market evidence, then ask Aeon for complete evidence ledgers, peer comparisons, monitoring, and a board-ready control brief.

Request disclosure brief