Privacy regulators in Canada have concluded that OpenAI broke national and provincial privacy law while training the early models behind ChatGPT, a finding that lands among the first of its kind from a Western government against a frontier AI lab.
The joint investigation, published on 6 May 2026, was led by federal Privacy Commissioner Philippe Dufresne with his counterparts in Alberta, British Columbia, and Québec. Together the four offices examined how OpenAI collected personal information to build GPT-3.5 and GPT-4: scraped web pages, licensed third-party datasets, and the conversations users had with ChatGPT itself.
The headline finding is that OpenAI ingested, in the regulators' words, "vast amounts of personal information," including details about health conditions, political views, and information about children, and did so without obtaining valid consent. The commissioners also found that OpenAI did not give individuals a workable way to see what had been collected about them, or to correct or delete it after the fact.
What the watchdogs concluded
The full report sets out four broad failings. OpenAI overcollected personal information relative to any defensible training purpose. It relied on a legal theory of implicit consent that the regulators rejected for material this sensitive. It did not offer a meaningful access and correction mechanism. And it released ChatGPT to the public despite knowing several of these privacy risks had not been resolved.
Coverage by CBC News notes that Dufresne framed the investigation as a test of whether existing Canadian privacy law can hold its own against generative AI. His conclusion, in effect, is that it can.
OpenAI's response and the conditional resolution
OpenAI has agreed to a set of corrective steps over the coming months. The company will deploy filtering tools to detect and mask personal information such as names and phone numbers before training data is consumed. It will improve user-facing notices and the data export process, strengthen access, correction and deletion mechanisms, and adopt a formal retention policy for personal data. Quarterly progress reports will go to the Canadian commissioners.
The federal office regards the matter as conditionally resolved. Québec's Commission d'accès à l'information has marked it conditionally resolved on most points but unresolved on the question of valid consent. Alberta and British Columbia have left their findings open under provincial PIPA requirements, as an analysis by Canadian law firm MLT Aikins summarises.
Why this ruling matters beyond Canada
The decision does not, by itself, require OpenAI to retrain or delete the affected models. What it does is establish a formal regulatory record. Other jurisdictions can now cite it, and litigators can lean on it.
For the wider AI industry, the implication is harder to wave away. Training corpora built from the open internet, long treated as a kind of legal grey zone, have now been found in at least one major jurisdiction to have been assembled in violation of existing law. That does not make the practice illegal everywhere overnight. It does make the legal exposure visible in a way it was not a month ago.
Further reporting on the ruling appeared in Dataconomy and BetaKit.
Sources
- i. betakit.com
- ii. www.cbc.ca
- iii. dataconomy.com
- iv. www.mltaikins.com
- v. itif.org
Commentarii · 0