I've written about two of Canada's three digital policy bills this summer. Bill C-22, the Lawful Access Act, passed the House in June and is in the Senate. It compels electronic service providers to build interception capability and retain metadata. Its definition of "electronic service provider" is broad enough to capture a community organization running a Nextcloud instance. That was the surveillance argument for owning your stack.
Bill C-36, the Protecting Privacy and Consumer Data Act, tabled June 15, replaces PIPEDA. It frames privacy as a fundamental right, adds real penalties, and requires cross-border transfer assessments. That was the compliance argument for owning your stack.
Bill C-34, the Safe Social Media Act, is the third bill. It was introduced June 10, five days before C-36. It has received less attention on this site because it looked like a content moderation bill — online harms, child safety, platform regulation. Those matter, but they're not the sovereignty story.
The sovereignty story is in the identity layer.
What Bill C-34 Actually Builds¶
Bill C-34 enacts the Digital Safety Act and creates the Digital Safety Commission of Canada. The Commission has three to five members, appointed by Cabinet, with the power to make rules, investigate, adjudicate, enforce, and advocate. That's five functions in one body. The Commission decides which platforms are regulated, what age verification methods are acceptable, what content moderation standards apply, and how AI chatbot services must behave. Penalties reach $10 million or 3% of global revenue for administrative violations, and $20 million or 5% for criminal offences.
The bill sets a minimum age of 16 for social media accounts. To enforce that, platforms must verify the age of every user. Not just minors — everyone. You cannot determine who is under 16 without determining who is over 16. The Australian experience confirms this: their under-16 ban, which inspired the Canadian approach, resulted in platforms deploying facial age estimation, behavioural inference, and government ID checks across the entire user base. Australia's own progress report found more than two-thirds of under-16 teens continued using social media anyway.
The government's briefing note for Heritage Minister Steven Guilbeault, dated June 11, 2026 — one day after the bill was tabled — sets out the messaging strategy. The talking points call the bill "an essential step forward" and describe child safety as "a collective responsibility." The note lists Google and Meta as supporters. Google said it was "committed to working with the federal government." Meta said it wanted "safe, positive online experiences for young people." The government read those as endorsements and built its communications around them.
Google and Meta run on harvesting personal data. A law that routes identity verification through their platforms is not a constraint on their business model. It extends it.
The Age Verification Trap¶
Age verification is the infrastructure, not the safeguard. The bill says the Commission will decide which methods are acceptable and will oversee the destruction of data collected during verification. The destruction requirement exists because the system collects identity data from adults in the first place. The safeguard is a promise to delete what shouldn't have been collected at all.
The methods under consideration are the same ones Australia uses: facial age estimation (AI that guesses your age from a photo), behavioural inference (AI that guesses your age from how you act), and government ID submission. The Discord breach last fall leaked roughly 70,000 government-issued IDs through a third-party verification service. That's the model. The risk is not theoretical — it's demonstrated.
Michael Geist, Canada Research Chair in Internet and E-commerce Law, argues the ban is unconstitutional. His analysis is direct: the ban on its face infringes Section 2(b) of the Charter, which protects freedom of expression including the right to seek, receive, and impart information. A law that conditions access to social media on proof of identity limits expression for everyone, not just minors. The real question is whether the infringement can be justified under Section 1, and Geist's argument is that it cannot — because the safeguards the bill points to as proportionality measures won't exist when the ban takes effect.
The government says it needs 12 to 18 months to establish the Commission. The ban starts when the Commission launches. The age verification standards, the privacy protections, the exemption mechanism — all of these are created by the Commission after it exists. Developing the standards takes at least another year. A platform seeking an exemption faces a review process that takes another year after that. The safeguards will not be operational until years after the ban takes effect.
Geist's prediction: if the bill passes, the ban faces an immediate court challenge, and a court will rule it violates the Charter because the safeguards that would make it proportionate don't exist yet.
He's not alone. The Canadian Civil Liberties Association warned about risks to freedom of expression and privacy. The Justice Centre for Constitutional Freedoms launched a national campaign against the bill. Emmett Macfarlane, a political science professor at the University of Waterloo, argues the ban is "nowhere near minimally impairing." Robert Diab reaches a similar conclusion.
And France's Constitutional Council struck down a similar ban on social media for under-15s, ruling it infringed on freedom of expression. That precedent travels.
The 50 Blank Cheques¶
The most structural problem with Bill C-34 is not any single provision. It's that more than 50 important policy decisions are left to the Commission or to Cabinet, after the bill passes. These include:
- Which social media platforms are covered
- What age verification methods are acceptable
- How the censorship rules are interpreted
- What constitutes "adequate" safety measures
- Which AI chatbot services are regulated
- What the content moderation standards look like
- How exemptions work
- What the penalties look like in practice
Parliament is being asked to approve a legal architecture without knowing what it will look like. The bill creates the framework. The Commission fills it in. That's not delegation — it's a blank cheque.
The Commission's structure compounds the problem. It combines rule-making, investigation, adjudication, enforcement, and advocacy in one body. The same organization that advocates for a policy, writes the rule, investigates the violation, judges the case, and sets the penalty. In administrative law, this is called a lack of procedural separation. In practice, it means the Commission's decisions are shaped by its own advocacy, reviewed by its own investigators, and enforced by its own adjudicators.
The AI Chatbot Provision¶
Bill C-34 extends its reach into AI chatbot services. Operators must monitor conversations for suicidal ideation, self-harm, or intent to cause serious harm. When those signals are detected, the operator must interrupt the chat and may report it to crisis services or police.
This is a mandate to scan private conversations. The bill doesn't say the scanning is optional. It doesn't say it only applies to flagged accounts. It says operators must monitor. When Canadians know their chats may be scanned or handed to authorities, the chilling effect is structural. People avoid sensitive topics. The standard for what triggers a report is undefined. The penalty for missing a signal is severe. The incentive is to over-report.
For community infrastructure operators running Matrix homeservers with AI integrations, this provision is directly relevant. If your community runs a chatbot service that could be designated as a regulated service by Cabinet order, the monitoring obligation applies. The bill's scope is defined by regulation — not by statute. That means the scope can expand without Parliamentary vote.
The Triad as Architecture¶
David Fraser, Canada's leading privacy lawyer, framed the three bills together in an August 24 post. His reading is structural:
- Bill C-22 is about how law enforcement and national security agencies obtain information, and what technical capabilities companies must build to facilitate that access.
- Bill C-36 is about what organizations can do with personal information, and how they are regulated.
- Bill C-34 is about what online platforms are required to do — content moderation, age verification, AI chatbot monitoring.
Three bills. Three domains: surveillance, data governance, content and identity control. But Fraser's key insight is that they're not separate. They're pieces of the same architecture. Bill C-34 creates a new Digital Safety Commission. Bill C-36 expands that Commission into the Digital Safety and Data Protection Commission and gives it private-sector privacy enforcement. The same body that polices online content also polices privacy compliance. The same Cabinet appointees who decide what speech is harmful also decide what data practices are acceptable.
This is the architecture: C-22 builds the collection capability. C-36 governs the data. C-34 verifies identity and monitors communication. Each bill is defensible in isolation. Together, they form a integrated digital control framework where one Commission has authority over what you can say, what data can be collected about you, and whether you can access the platforms where you say it.
What This Means for Community Infrastructure¶
The Bill C-22 argument was: the government can compel access to your data, so own the infrastructure to control what's compellable.
The Bill C-36 argument was: the government will require you to document how you protect data, so own the infrastructure to make compliance verifiable.
The Bill C-34 argument is: the government is building an identity verification layer across the internet, so own the infrastructure to stay outside it.
Bill C-34's scope is defined by regulation. Cabinet decides which services are "regulated social media services" and which AI chatbot services are covered. The bill says it targets services that are "sufficiently risky to children" — a standard that is not defined in the legislation and will be set by the Commission. A community Matrix homeserver with 30 users could theoretically be designated. A fire hall's internal communication platform could be designated. The definition is whatever the Commission says it is.
In practice, the Commission is unlikely to target a 30-user community server. The enforcement priorities will be platforms with large user bases. But the legal exposure exists, and the cost of defending against a Commission inquiry — even an unsuccessful one — is more than most community organizations can absorb.
The deeper concern is not enforcement. It's normalization. Bill C-34 normalizes identity verification as a condition of online expression. It normalizes content monitoring by platform operators. It normalizes a super-regulator with combined functions and undefined scope. Each normalization makes the next expansion easier. The bill that regulates Meta today provides the framework for regulating your community server tomorrow — not because the Commission will, but because the legal architecture permits it.
For communities building sovereign infrastructure, the response is the same as with C-22 and C-36. Own the stack. Run your own Matrix server, your own Nextcloud, your own Keycloak. A community platform that doesn't collect government IDs, doesn't deploy facial age estimation, and doesn't scan private conversations is not just compliant by default — it's architecturally outside the bill's reach. The Commission can regulate services that verify age. It cannot compel a service that doesn't verify age to start verifying age, unless it designates that service as a regulated social media service. And the community that owns its stack can choose what it becomes.
The pattern across all three bills is consistent. The government is building a digital policy architecture that assumes platform-mediated interaction, corporate data processing, and state-accessible infrastructure. Community-owned infrastructure doesn't fit the model. That's not a bug in the legislation — it's the point. Infrastructure you own is infrastructure you control. Infrastructure you rent is infrastructure someone else controls, and the government regulates the someone else.
The Bottom Line¶
Bill C-34 is not a child safety bill. Child safety is the justification. The substance is an identity verification infrastructure, a content regulation framework, and a super-regulator with powers that Parliament hasn't defined. The government's own messaging strategy treats it as a political product: the briefing note coaches the minister on how to sell it, names the corporate supporters, and cites the polling numbers.
The three bills together form a pattern that's now visible across two summers of Canadian legislation. The surveillance bill builds the pipes. The privacy bill governs the water. The safety bill checks who's drinking. The community that owns its own well is outside the system entirely. That's not a loophole — it's a design choice the government didn't intend, and one that communities should exploit while they still can.
Sources: Parliament of Canada, LEGISinfo Bill C-34, Michael Geist — Why the Government's Plan for a Social Media Ban in Bill C-34 Is Unconstitutional, David Fraser — Privacy, Online Harms and Lawful Access: Keep an Eye on Parliament This Fall, Reclaim The Net — Canada's Safe Social Media Act Requires ID Checks, Justice Centre for Constitutional Freedoms — Safe Social Media Act is a Trojan Horse, Osler — Bill C-34 At a Glance, Michael Geist — The Data on Australia's Social Media Ban