Quebec Law 25 and AI Voice Agents: The 12-Question Compliance Test (and 1-Week Fix Plan for 2026) | Agent IA Vocal
    Back to blog
    compliance7 min readMay 5, 2026

    Quebec Law 25 and AI Voice Agents: The 12-Question Compliance Test (and 1-Week Fix Plan for 2026)

    Quebec Law 25 and AI voice agents: the 12-question compliance test, a real Laval clinic case study, and a 1-week fix plan to avoid a CAI fine in 2026.

    MA

    Masdouk Adelakoun

    Cofondateur & CTO

    Quebec Law 25 and AI Voice Agents: The 12-Question Compliance Test (and 1-Week Fix Plan for 2026)

    On May 1, 2026, La Presse ran a headline plenty of Quebec SMB owners would have preferred to skip: "Your use of AI at work might be illegal." The article focused on workplace AI, but it also rattled another group entirely — the hundreds of Quebec SMBs that have plugged an AI voice agent into their phone line over the past 18 months without ever cracking open the text of Law 25.

    The bad news: if your AI voice agent answers calls in Quebec, the Commission d'accès à l'information (CAI) considers that you're processing personal information through automated decision-making. The maximum administrative penalty under Article 91 of Law 25 is $25 million CAD or 4% of worldwide revenue — whichever is higher.

    The good news: compliance is not a six-month project. For most SMBs, it's a system prompt update, two or three operational tweaks, and one email to your lawyer. About a week of focused work.

    Here is the 12-question test we run on every AI voice agent we deploy at TECHMA, ever since the CAI announced its 2026 audit wave.

    The 3 Articles of Law 25 That Bite a Voice Agent

    Before the test, you need to know what applies. Three articles do most of the heavy lifting:

    Article 12.1 — Automated decisions. If your agent makes any decision about a caller (route to human or not, offer an appointment or not, qualify the request), that's a decision based exclusively on automated processing. You must inform the caller, explain the logic, and disclose the consequences. Not a generic notice. The actual logic.

    Article 14 — Informed consent. Consent for AI processing must be "manifestly informed and explicit." The classic trap: "this call may be recorded for quality purposes." That phrase is worthless once an AI is in the loop. The CAI wants the caller to understand that an AI is processing their data and how.

    Article 17 — Cross-border transfers. If your AI voice agent runs on ElevenLabs, OpenAI, or Microsoft Azure US servers, you have cross-border data transfer. You must inform the caller and obtain consent — period. Most SMBs we audit miss this one.

    The 12-Question Test

    Take 10 minutes. Tally your score. At the end, we tell you the threshold above which you should be reaching for the phone.

    1. At the start of every call, does your agent explicitly say it's an artificial intelligence? Not "virtual assistant" or "24/7 receptionist." The words "artificial intelligence" or "AI agent" must be in there. The CAI has been clear since 2025: functional transparency beats generic disclosure.

    2. Does the agent announce that the call is recorded AND processed by an AI? Both. Many scripts mention recording but not the AI processing. Article 12.1.

    3. Can the caller, at any moment, ask to speak to a human? And does the agent obey without friction? The CAI considers being trapped in an AI loop a failure of revocable consent.

    4. Do you have a disclosure script in both FR and EN? If the caller switches to English, consent switches with them. An SMB we audited in March had a flawless FR script and an EN script that didn't mention AI at all. Immediate risk.

    5. Do you keep call history? For how long? And where? Article 3 requires a retention policy. "Indefinitely" isn't a policy.

    6. Are recordings stored in Canada? If not, mandatory cross-border disclosure under Article 17. Most integrators use US infrastructure by default. Audit it now.

    7. Have you completed a Privacy Impact Assessment (PIA)? Article 3.3. For an AI voice agent, that's roughly 8 to 12 pages. The CAI can request it on 48 hours' notice.

    8. Does your agent process health, financial, or children's data? If yes, the explicit consent threshold goes up a notch. For clinics and law firms, this is non-negotiable.

    9. Have you appointed a privacy officer? Article 3.1. For an SMB, that can be the president or the GM. But the name must be public and reachable.

    10. Have you documented the decision logic of your agent? When to route to a human, when to offer an appointment, when to end the call. If you can't explain it in plain French, you can't disclose it to callers.

    11. Can you delete a caller's data on request? And how fast? The right to erasure (Article 28.1) is being enforced. 30 days is the standard.

    12. Do you have an incident response plan for a voice data breach? Article 3.5. What's known as a "privacy incident" triggers a mandatory CAI notification within 72 hours.

    Score: 0 to 4 yeses: red zone, unplug or fix fast. 5 to 8: yellow zone, fix in 30 days. 9 to 12: green zone, an annual audit is enough.

    Real Case: An Audiologist Practice in Laval

    In February 2026, we got a call to bring a clinic into compliance. They had been running an AI voice agent for 14 months: appointment booking, new patient qualification, post-trial follow-up. Excellent ROI numbers. Law 25 score: 3 out of 12.

    The gaps? The agent introduced itself as "Maria, your assistant." No mention of AI. Recordings lived on ElevenLabs (US) with no cross-border disclosure. No PIA. No appointed officer. And the clinic was collecting health information.

    Compliance fix in 6 days. Rewrote the opening script (8 seconds added, conversion rate identical). Migrated recordings to a Canadian infrastructure. PIA drafted by a partner lawyer ($1,800). Designated the owner-doctor as the privacy officer. Set retention to 90 days. Final score: 11 out of 12.

    Total compliance cost: $4,100. Compare that to the minimum $15,000 fines per violation the CAI can impose, even on a small practice.

    The 1-Week Compliance Plan

    Day 1 — Audit. Run the 12-question test. Note the 3 highest-risk gaps (red zone first).

    Day 2 — Opening script. Rewrite the introduction block. Here is our 18-second EN template: "Hello, you are speaking with [name], the artificial intelligence agent for [company]. This call is recorded and processed by an AI for [purposes]. Your information may be stored on servers in the United States. You can ask to speak to a human or stop this call at any moment. Are you OK to continue?" Mirror it in FR.

    Day 3 — Infrastructure and retention. Check where your recordings live. If possible, switch to a Canadian option (ElevenLabs has been offering CA deployment since February 2026). Set a retention period: 30, 60, or 90 days depending on your industry.

    Day 4 — PIA. Draft (or have drafted) the Privacy Impact Assessment. For a standard SMB, that's 4 to 8 hours of work with a lawyer or a compliance consultant.

    Day 5 — Officer and policy. Appoint the officer. Publish the updated privacy policy on your website. Add a "How We Use AI" section.

    Day 6 — Tests. Run the usual 7 operational tests on top of the 12 compliance questions. Document results.

    Day 7 — Documentation. File everything in a compliance binder: scripts, PIA, policy, consent log, incident plan. If the CAI knocks, you open the binder in two minutes.

    What Actually Changed in 2026

    Three concrete things:

    First, in January the CAI published its 2026 audit priorities. AI voice agents and chatbots are explicitly named. This is no longer theoretical.

    Second, the May 1 La Presse article moved the topic from legal departments to SMB management tables. Boards are starting to ask questions of their executive teams.

    Third, the penalties. The administrative range runs from $15,000 to $25,000,000. For an SMB, the real risk isn't the maximum fine — it's the publication order under Article 90. The CAI can force you to publicly disclose your violation. For a practice that depends on trust, that's more damaging than the cheque.

    The Honest Trade-off: Compliance vs. ROI

    People often ask whether Law 25 compliance kills the ROI of an AI voice agent. Short answer: no, but it adds 8 to 15 seconds to the start of every call. On 90-second calls, that's about 10%.

    What we've seen across 30 SMB compliance fixes: conversion rates barely move. Callers actually appreciate the transparency. A few hang up — but those were callers unlikely to convert anyway. Net ROI drops 5 to 8% on average. That's the price of sleeping at night.

    The mistake some SMBs make: hide the AI to keep the conversation feeling "natural." Short term, it works. Medium term, that's exactly what the CAI is hunting. And if a caller files a complaint, you pay both the fine and the bad press.

    Now What?

    If you have an AI voice agent live in Quebec, run the 12-question test this week. Not next month. This week.

    If your score lands in red or yellow, we can help close the gaps. The TECHMA team rewrites the scripts, migrates the infrastructure, drafts the PIA with our partner lawyer, and configures your retention policy. You, you keep your agent running through the transition.

    Law 25 wasn't written to kill AI voice. It was written so people can no longer hide behind it. For Quebec SMBs that do things properly, that's actually excellent news: your competitors taking shortcuts will get caught first.

    Share