Before Canada Scales Health AI Infrastructure, It Must Govern What Health Data Becomes

Published On: September 2026Categories: 2026 Editorial Series, Canada's New AI Strategy, Editorials

Author(s):

Cindy Hansen

headshot CH – Cindy Hansen
Disclaimer: The French version of this text has been auto-translated and has not been approved by the author.

The Trust Gap

Trust is not built by slogans. Clinicians earn it one encounter at a time. It is one of the unseen foundations health care depends on; decades of research confirm the therapeutic alliance as one of the most consistent predictors of treatment outcomes — in medicine as much as in mental health care. Patients share intimate information with the assumption that it will be used for care, within a defined relationship, and with clear limits on disclosure.

AI for All is now the federal government’s chosen language for anchoring a national AI strategy. It promises leadership through trust: protecting Canadians, safeguarding sovereignty, and building trusted partnerships. The ambition is right. But the strategy draws on trust rooted in clinical relationships it has not yet learned to protect at scale. Health data is where that gap will show up first: it is already intimate, distributed, and increasingly shaped by AI.

The challenge is that public trust in AI is already thin. A global trust study by KPMG–University of Melbourne placed Canada 42nd out of 47 countries for trust in AI systems. In a free democracy, that skepticism is not failure; it is feedback. Canadians are not withholding trust; they are asking what would make it warranted. 

Health care offers a possible answer. People may distrust AI in the abstract while still granting trust daily in clinical settings. Every day, people disclose highly sensitive information because they believe it will be used to help them. The governance challenge is to protect that trust when ordinary health records are linked and turned into AI-enriched representations of a person’s life. After that point, what follows disclosure becomes far less clear.

 

The Governance Gap

That is why health care is not merely one application of AI governance. It is the stress test for whether Canada’s trust agenda can survive contact with real lives.

The problem is not disclosure alone; it is what disclosure becomes after linkage. Link a clinical record to a pharmacy history, specialist notes, wearable data, and an AI-generated summary, and it stops behaving like a dataset. It starts behaving like a life story. It can be queried, compared, and reused in ways no one specified when the original consent was given. New tools are emerging to address part of this. Self-sovereign identity, where individuals hold digital credentials and decide who receives what, is a genuine advance. But it governs the moment of sharing. It does not govern what happens after information accumulates, links, and becomes more than the sum of its parts.

This is not a future problem. It is ordinary life for many Canadians: a family doctor, a managed condition, prescriptions, lab results, a benefits plan, perhaps a wearable device. Current frameworks still tend to classify risk by identifiability: can a person be named or re-identified? That question matters, but it is no longer sufficient. A single clinical note, lab result, or prescription can be governed as information. But when those fragments are linked over time, enriched by AI, and made searchable across systems, they begin to function as something else: a representation of the person. At that point, the governance problem is not only whether the data identifies someone. It is whether a version of that person has been assembled and made available for uses they may never have anticipated. No current category is built to address that data construct. If Canada wants trusted health AI, it needs a practical way to recognize when health data has become a representation of a person.

 

A Practical Path Forward

The answer is not to slow innovation. It is to define that construct clearly enough to govern it. Canada should distinguish between discrete structured data, a single clinical file, and a linked representation of a person built from unstructured and AI-derived content over time. Once a record becomes that third kind of object, it deserves the review a research subject would receive — not because a name is attached, but because a life is being drawn on.

This can start with tools Canadians already know. Provincial health portals that show lab results and appointments could also show how linked records are used beyond direct care and give people meaningful opt-out choices. As self-sovereign identity matures, those choices can travel with the person. One layer is available today. The other is where the infrastructure is heading. Both depend on naming the object first.

Canada should not wait for a scandal to define the rules. Extractive data regimes often end the same way: backlash, litigation, and hurried regulation written after trust has already been damaged. A clear category adopted now is not a constraint on innovation. It is the condition for sustaining it. It would meet a gap repeatedly identified in the UN’s Global Dialogue on AI Governance: the need for shared vocabulary and interoperable governance.

If AI for All is to mean what it says, governance must move before the infrastructure hardens. It must travel as far as the data does — to the point where a dataset becomes a person’s life story — and return authority to the person who is owed a say. Get this right, and Canada can lead on a foundation that holds. Leave the gap unnamed, and the country will scale health AI on borrowed trust. That trust is unlikely to last.

More on the Author(s)

Cindy Hansen

Holistic Research Canada, BC

Chief Science Officer