Canada's AI Transparency Register Is Hiding in Plain Sight
A government that lists 409 AI systems — but systematically erases the human judgment, uncertainty, and institutional friction required to run them — hasn't achieved transparency. It's automated the appearance of it.
~6 min read · University of Toronto / FAccT '26 · 2026-04-21 · Alignment
TL;DR Researchers analyzed Canada's first federal AI Register — 409 systems across 42 departments — using a public-sector governance framework. They found the register privileges technical descriptions and efficiency justifications while obscuring human discretion, training requirements, and uncertainty. The result: a document that looks like accountability but functions more like a compliance trophy.
When Canada published its first government-wide AI Register in November 2025, it felt like a milestone. Over 400 AI systems, spread across more than 40 federal departments, finally made public. Immigration tools. Fraud detectors. Security screeners. All cataloged in one place.
But a catalog is not accountability. And a list of tools, stripped of the human judgment and institutional context required to wield them responsibly, may actually make oversight harder — by giving the impression that it's already been done.
That's the core argument of this paper from researchers at the University of Toronto, who analyzed the complete Canadian federal AI Register using a structured framework for public-sector algorithmic governance. What they found is a document that tells you a great deal about what government AI is, and almost nothing about how it works in practice.
💡 The Core Idea AI registers are not neutral mirrors. They are acts of institutional design — and the choices of what to include, what to omit, and how to categorize systems actively shape what can be questioned, contested, or reformed. The authors call these structured gaps "bureaucratic silences."
What the Register Actually Contains
The dataset covers 409 systems. The authors categorized them using ADMAPS (Algorithmic Decision-Making Adapted for the Public Sector), a framework built around three dimensions: the nature of algorithmic decision-making itself, the bureaucratic processes surrounding it, and the role of human discretion.
A few numbers set the stage immediately. About 86% of systems are designed for internal government use — not for direct public interaction, but for employees managing caseloads, processing documents, or flagging risks. Just 21.4% involve personal information, while 24.4% don't specify their data practices at all. Systems are roughly split between in-house development (43.3%) and external vendors (38.1%), with open-source accounting for only 6.1%. Of external vendors, Microsoft dominates with 46 systems — a level of concentration the authors flag as a direct contradiction to Canada's stated goal of "AI sovereignty."
Three Silences That Matter
Uncertainty, systematically erased. The register contains systems that openly acknowledge they're experimental — using language like "pilot," "exploring," or "intended to establish infrastructure." Fine. But a large number of operational systems present themselves as stable and reliable while performing tasks — identity verification, anomaly detection, document classification — that are inherently prone to error and contextual ambiguity. The CBSA's Electronic SIN Automation system, for instance, uses a vague phrase like "when certain criteria are met" to wave away the complexities of document authentication under varying image quality and emerging fraud vectors. When a system projects false confidence, the uncertainty doesn't disappear — it gets silently transferred to the human officer who has to resolve the edge cases that confident classifications produce.
Training and administration, treated as self-evident. Many systems in the register involve layered, multi-step workflows: probabilistic output interpretation, threshold configuration, human-in-the-loop review, AI-generated content validation. Yet training requirements are "rarely articulated." The register assumes workers will know how to calibrate their professional judgment against model outputs, recognize failure modes, and decide when to override — without saying anything about how that knowledge is developed or maintained. In high-stakes contexts like medical adjudication or immigration screening, that's not a minor omission.
Human discretion, nominally preserved but practically constrained. The register consistently notes that "final decisions remain with human officers." But this formal statement does a lot of work. Prescriptive systems that highlight "essential details," route cases, or flag "pre-determined areas of concern" don't eliminate discretion — they reshape it. When a border agent sees a ranked list of security flags, their practical latitude narrows even if their formal authority doesn't. The register, by foregrounding the technical capability and omitting the operational dynamics, obscures this redistribution entirely.
The Ontology Problem
The authors introduce a term worth keeping: ontological design. An AI register doesn't just describe what exists — it defines what counts as governable. A system that appears on the register can be scrutinized. One that doesn't, can't.
Here the authors invoke IRCC's Chinook system, which has been documented in academic and journalistic sources as playing a role in processing temporary resident visas and permit applications. Chinook does not appear as a named system in the register. Whether this is intentional exclusion, different naming, or classification ambiguity is unclear — but the consequence is the same. A materially impactful form of algorithmic mediation remains outside the formal accountability structure.
The register also shapes what kind of AI is visible. NLP, large language models, and generative AI dominate the capability descriptions. Older predictive and scoring systems — the kind that quietly shape immigration decisions, benefit calculations, and enforcement priorities — tend to be described in more muted terms, with their uncertainty and operational complexity understated.
⚠️ Watch out for
- Only 4% of 303 automated government tools had publicly available Algorithmic Impact Assessments, despite formal requirements to complete and publish them — the register doesn't close this gap
- Concentrated vendor reliance (notably on a single foreign provider for dozens of systems) creates governance dependencies the register doesn't address
- Systems described as stable may be concealing high classification uncertainty, leaving frontline workers without guidance on when to distrust outputs
Why "Visibility Without Contestability" Is Worse Than Nothing
There's a specific harm in performative transparency that goes beyond mere incompleteness. When a government publishes an AI register, civil society actors, journalists, and affected individuals may reasonably conclude that oversight is happening. The register becomes a settlement — a way of saying "we've addressed this" — rather than an opening for deeper scrutiny.
The authors put it plainly: "When registers function as endpoints rather than entry points for scrutiny, they may stabilize public trust at the surface level." In domains like immigration, social services, and border enforcement, where algorithmic systems directly shape access to rights and services, that surface-level stabilization can erode genuine trust over time.
Canada isn't unique here. Similar registers have launched or are being designed in Amsterdam, Helsinki, and across EU member states under the Digital Services Act. The silences identified in Canada's register — around uncertainty, training, discretion, and vendor dependency — should be treated as structural properties of register-driven transparency regimes generally, not as a peculiarly Canadian failure.
What a Better Register Would Look Like
The paper's implicit prescription: registers should be designed as entry points for accountability, not endpoints. That means specifying how workers are trained to interpret and override system outputs, documenting how uncertainty is communicated at the point of decision, naming vendors and their data governance obligations explicitly, and — critically — building in contestation mechanisms so affected individuals can understand and challenge decisions made with algorithmic support.
A transparency artifact that tells you what AI systems exist, but not how they fail, who decides when to trust them, or what happens when they're wrong, isn't a governance instrument. It's a catalog. Catalogs don't hold anyone accountable.
Source: Bureaucratic Silences: What the Canadian AI Register Reveals, Omits, and Obscures Authors: Dipto Das, Christelle Tessono, Syed Ishtiaque Ahmed, Shion Guha Published: 2026-04-21 PDF: https://arxiv.org/pdf/2604.15514