The Safe Social Media Act Has a Chatbot Problem
Bill C-34 is mostly a social media bill, and it shows

Yesterday, Minister of Canadian Identity and Culture Marc Miller introduced Bill C-34, the Safe Social Media Act.
On the whole, it is a step in the right direction. The bill sets out a path toward safer, healthier online environments for Canadians.
But while the social media provisions are relatively robust, the chatbot provisions are much less convincing. They are too narrow in scope, too vague, and not sufficiently grounded in how AI systems are actually built and deployed.
The Bill Gets Platform Accountability Mostly Right
The social media side of the bill has a clear theory of harm and a structured set of duties for regulated platforms.
The transparency framework is particularly refreshing. By requiring public digital safety plans and a resource person to support users, the bill should give Canadians a clearer view into how platforms assess risks, what safety measures they use, how effective those measures are, and who users can contact when something goes wrong.
The main issue is the under-16 account restriction, which raises separate concerns around privacy and expression. But even with that caveat, the social media provisions seem to be drafted around a mature understanding of platform governance.
Why the Chatbot Provisions Feel Less Developed
Bill C-34 is, in many ways, a second attempt at legislation introduced in the last Parliament. Bill C-63 was largely a social media platform accountability bill. It was publicly debated for months before it died on the Order Paper.
With this recent past attempt at legislation, and the large body of research on social media harms, the social media provisions read like the product of years of debate about platform accountability.
The bill is on less certain ground when it turns to AI chatbots. Unlike the previous Online Harms Act, this version creates a distinct framework for regulated chatbot services. Two recent developments help explain why:
AI chatbots have become a much more visible public safety concern. In 2025, OpenAI rolled back an update to GPT-4o after finding that the model had become overly sycophantic.
The Tumbler Ridge tragedy appears to have had a major influence on this bill. After the shooting, federal officials met with OpenAI, and ministers signalled that government action could follow. OpenAI later told the government that it is strengthening its law-enforcement referral criteria.
But the government also seems to recognize that chatbot policy is less settled than social media policy. When asked why the government is not proposing to ban kids from chatbots alongside social media, Minister Miller admitted that chatbots are an “evolving playing field” and not as well studied as social media platforms.
That is exactly the problem. If chatbots are an evolving playing field, the bill’s chatbot provisions need to be more forward-looking.
The Chatbot Definition Is Too Brittle
The bill defines a “chatbot service” around a very specific product: an AI system that communicates over the Internet, is made available on a publicly accessible website or application, uses a natural-language conversational interface, can simulate a sustained human-like relationship, and generates responses that are not fully predetermined.
That definition likely captures obvious public chatbot services, such as ChatGPT, Claude, Gemini, and Character.AI.
AI plush toys and AI-powered learning companion robots marketed for children and families expose the problem. The bill does not clearly capture AI systems where the user interacts with a device rather than a website or application.
The risks the bill identifies are not tied to text-based chat boxes. They are associated with AI systems that can simulate relationships, induce reliance, give advice, reinforce harmful beliefs, or interact with vulnerable users over time.
The bill should be capable of reaching AI systems that can form sustained human-like relationships with users, regardless of how they are accessed.
The Chatbot Duties Need Clearer Adequacy Criteria
Section 49 requires regulated chatbot services to implement measures adequate to mitigate the risk that the service will communicate harmful content to a user.
Section 53 requires them to implement measures adequate to mitigate the risk that the chatbot itself will engage in harmful behaviours, including posing as a human being, posing as a licensed professional, using manipulative engagement techniques to encourage emotional attachment, or encouraging self-harm, suicide, or serious violence.
The problem is that the bill does not explain what will be considered “adequate” in either context.
That omission stands out because, elsewhere in the bill, “adequate” is usually paired with criteria for how adequacy is to be assessed.
For age-verification and age-estimation measures, the Commission must be satisfied that the measures are effective, limited to age-verification or age-estimation purposes, protect personal information, and destroy that information once verification or estimation is complete.
For social media harmful-content measures, the Commission must consider effectiveness, the size of the service, the operator’s technical and financial capacity, and whether the measures are discriminatory.
For synthetic-content labelling, the Commission must also consider technical feasibility and the risk of incorrectly labelling content.
Even the exemption for under-16 access restrictions contemplates regulations and Commission guidelines on what counts as “adequate safeguards.”
Sections 49 and 53 do not have an equivalent. They should.
It’s important for providers to know what is expected of them. And it’s also important that the adequacy of measures to mitigate risks be assessed realistically.
Generative AI systems are probabilistic and vulnerable to adversarial prompting, so one of the most technically challenging types of harmful behaviour to mitigate is the requirement in section 53(c):
using manipulative engagement techniques to encourage a user of the service to form or maintain an emotional attachment to the service in a way that may encourage the user to withdraw socially or disconnect from reality;
The challenge is that mitigating this risk may require evaluating the user’s relationship with the chatbot beyond a single conversation thread.
A related issue appears in section 53(a), which targets chatbots that pose as human beings. Persistent interface labels can help, but preventing the model itself from claiming to be human is more reliable when that behaviour is addressed through post-training, not only through a system prompt or moderation filter.
Not every chatbot operator controls the underlying model. A smaller operator may be able to adjust the interface, system prompt, and filters, but it likely cannot meaningfully post-train the model or harden it against jailbreaks. Smaller operators should not be held to the same practical standard as major general-purpose AI platforms, especially when even well-resourced operators still struggle with prompt injection and jailbreaks.
That is why sections 49 and 53 need explicit adequacy factors. Without them, the chatbot provisions risk becoming unrealistic, unevenly enforced, or dependent on after-the-fact regulatory discretion.
How Parliament Should Fix This
The bill should replace or supplement “chatbot service” with a technology-neutral category for public AI systems. That category should cover systems accessed through websites, applications, devices, toys, robots, smart speakers, headsets, vehicles, operating systems, virtual environments, and future interfaces. It should also cover interaction through speech, text, image, sound, gesture, touch, movement, biometric signal, neural signal, or any other mode of input or output.
Sections 49 and 53 should include explicit adequacy factors. At minimum, the Commission should be required to consider:
for section 49, the effectiveness of the measures in mitigating the risk that the service will communicate harmful content to a user
for section 53, the effectiveness of the measures in mitigating the risks referred to in that section, including in reasonably foreseeable use or misuse of the service
the risk that the measures will incorrectly restrict, interrupt, or alter interactions that do not present the relevant risk
the extent to which it is technically feasible to mitigate the risk
the size of the service, including the number of users
the technical and financial capacity of the operator
the extent to which the operator controls the development, training, or modification of the underlying model
whether the measures are designed or implemented in a manner that is discriminatory on the basis of a prohibited ground of discrimination within the meaning of the Canadian Human Rights Act
Conclusion
Bill C-34 is a serious and constructive attempt to make digital services more accountable. Its social media provisions are relatively mature, and the public digital safety plan requirement is especially promising.
But the chatbot provisions need work. They are too tied to today’s public chatbot products and do not clearly reflect how AI systems are built, deployed, or controlled.
Parliament should make the AI provisions technology-neutral, technically realistic, and ready for what comes next.
