Over the past year, the same question kept reaching me from psychologists: "are we even allowed to use this?" What they wanted was simple — to know what their college of psychologists says about AI in clinical documentation, and whether provincial AI guidance even exists yet. So I went and read what Canadian regulators actually publish, and talked with the clinicians who have to live inside those rules. Here is the short version I wish I could have handed them: no Canadian psychology college has banned AI documentation tools, and none has published a full rulebook. The clearest signals so far come from Ontario and Alberta, and from Ontario's privacy commissioner.
I'm not a clinician and I'm not a lawyer, so treat this as a map, not advice — the plain summary one psychologist told me she wished existed when her practice partner asked whether they were even allowed to try these tools. This is where things genuinely stand, as of mid-2026, from what the regulators have put in writing and what the psychologists reading those rules told me they took from them.
Do any Canadian colleges have explicit AI guidance yet?
A few do. Most don't. That gap is worth saying plainly, because the internet is full of confident summaries of rules that were never written.
Ontario. The College of Psychologists and Behaviour Analysts of Ontario put out new Standards of Professional Conduct that took effect July 1, 2024. They address AI directly but lightly: registrants are free to responsibly use technological advances — including computer-assisted scoring and interpretation and non-human artificial intelligence — but technology "may not be used instead of registrants' own professional knowledge." The psychologists I spoke with read that the same way I did: judgment stays with the human.
Alberta. The College of Alberta Psychologists went further. Its Use of Technology practice guideline (September 1, 2024) is the most specific document I've found from any Canadian psychology regulator. It cautions that "psychologists should not rely solely on AI-generated text generators to help produce reports or letters," warns against feeding client-identifying information into a tool before you understand whether it trains a model on that data, and advises informed consent when using emerging technology whose evidence base is still thin.
British Columbia. In 2024 the College of Psychologists of BC folded into the new College of Health and Care Professionals of BC, and psychology-specific practice standards for that body are still being developed. So there is no explicit BC psychology AI standard yet — the baseline is the general Health Professions Act plus provincial privacy law.
Nationally. The Canadian Psychological Association — an association, not a licensing regulator — published an Artificial Intelligence and Psychology briefing paper in 2024. Its refrain is human oversight: interpretability and a person in the loop remain essential to ethical use.
Beyond these, many provincial colleges simply haven't issued AI-specific guidance. More than one clinician has told me they went looking for their college's "AI policy" and found nothing — so if someone tells you your college has a detailed one, it's fair to ask them to link it.
What is the privacy baseline underneath all of this?
Even where a college is silent, privacy law is not. PIPEDA is the federal private-sector baseline. In Ontario, PHIPA governs health-information custodians — the legal term for a clinician who holds client records. British Columbia and Alberta each have their own PIPA. The psychologists I talked to were quick to point out that these apply to their client files whether or not their college has spoken about AI, and they are the floor any documentation tool has to clear.

Where client data physically lives, and who can touch it, is a privacy-law question before it's a college question.
What did Ontario's privacy commissioner actually say?
This is the most concrete thing to happen in the space, and the document clinicians kept forwarding to me. On January 28, 2026, Ontario's Information and Privacy Commissioner released AI Scribes: Key Considerations for the Health Sector. Legal analysts have called it an emerging regulatory baseline — a signal of what regulators will increasingly expect, even outside Ontario.
A few points from it kept coming up in my conversations:
- PHIPA does not go away. A custodian's "obligations under PHIPA continue to apply when they collect, use, and disclose personal health information using an AI system." The tool is not the accountable party — the clinician is.
- Humans in the loop. The guidance calls for "adequately trained humans in the loop to oversee quality and performance," because errors in a clinical note "can reduce quality of care."
- Minimize what you keep. It urges custodians to question whether they need to retain full transcripts at all, and to limit what personal health information ever reaches a vendor.
- Contract hard. Where a system is procured, negotiate strong contractual safeguards: limits on the vendor's use of information, data-retention and destruction obligations, and breach-notification commitments.
- Consent is real. Clients who withhold or withdraw consent must receive the same standard of care.
The IPC and the Ontario Human Rights Commission also published joint principles for AI: it should be valid and reliable, safe, privacy-protective, human-rights affirming, and transparent and accountable. None of that is a psychology standard, but the clinicians I spoke with said it reads like the criteria they'd want anyway.
Why does every source point back to "keep the clinician as the author"?
Because they all converge on it. Ontario says technology can't stand in for professional knowledge. Alberta says don't lean on a generator to produce the report. The privacy commissioner says keep a trained human overseeing the output. The through-line the psychologists drew for me isn't "avoid these tools" — it's "the tool drafts, the human decides."
That maps cleanly onto what they tell me makes a report hold up in the first place. The reasoning has to be theirs, traceable, and signed by them. It's the same argument they walked me through in what makes a psychological report defensible — the person who signs owns the conclusion, full stop.

The posture every Canadian source lands on: the tool assembles a first draft, and the clinician reviews, edits, and signs.
What did clinicians tell me they check before adopting a tool?
When I asked psychologists what they actually look at, the same short list came back — and it lines up with the guidance above:
- Where the data lives. Canadian-hosted, Canadian-owned, with data at rest in Canada is a genuine advantage under PIPEDA and PHIPA — and, they told me, a real differentiator from US tools. Canadian privacy law is the bar that actually applies to them, so a US compliance frame doesn't settle the question.
- What the vendor can do with the data. Whether it trains a model on their files, how long anything is retained, and how a breach would be handled — the exact things Alberta's college and Ontario's IPC tell them to ask.
- Consent and documentation they can show. Employer and college policies can block adoption; one assessor told me her employer simply wouldn't permit AI, full stop. The clinicians who'd cleared that hurdle had their consent language and security facts ready before the question came.
- Clinician control by design. A first draft they review, edit, and sign — never a finished document that bypasses their judgment. As more than one put it to me, the thinking is the work, and the thinking is why report writing takes the hours it does — so the thinking has to stay theirs.
That last principle is exactly what we build toward at Soma: a Canadian-hosted first draft you review and sign, never a decision made for you.
I'm grateful to the psychologists who've walked me through these rules, and to the regulators putting real thought into them. The landscape will keep moving — but the place the clinicians I talked to feel safe standing is already clear, and it hasn't changed once: they stay the author.
— Ian
