CONTINUOUS AI COMPLIANCE

Your audit, ready in days
not months.

Fifteen Canadian and EU frameworks now govern how you use AI. Law 25 and the AMF guideline come first. Veille maps every obligation to the systems you actually run and builds the proof as it goes. When a regulator asks for it, it is already there.

The founding cohort is open now, capped at 12 organizations. Founding members pay a flat $9.6K a year for two years, any size.

Compliance dashboard

Every AI system.
One record, always current.

Law 25 ADM Audit
OSFI E-23 Model Guard
Immutable WORM Vault
Agent Live Status
EU AI Act Compliance
SHA-256 Hashed Proof
app.veille.space / dashboard
Veille AI, compliance dashboard (Overview)
Why now

Regulation created this market. The calendar is public.

Five dated milestones land across four years. A federal privacy bill may join them. Each one makes continuous AI compliance mandatory for one more segment of the Canadian economy. The next falls on 1 May 2027.

Sept 2023 Law 25 in force Automated-decision rules bind Québec's private sector.
Nov 2024 Bill 194 assented AI accountability for Ontario public bodies.
June 2026 Federal privacy reform C-36 governs automated decisions. It does not create an AI regime. AIDA died in 2025.
2 Aug 2026 EU AI Act, transparency milestone Article 50 transparency obligations have applied since 2 Aug 2026. High-risk (Annex III) obligations deferred to 2 December 2027 by the Digital Omnibus on AI.
Aug 2026 You are here Founding cohort opens, capped at 12 organizations.
May 2027 AMF and OSFI E-23 Québec's AMF AI guideline has been published since April 2026. The federal OSFI E-23 rules take effect the same day. What has to be ready on 1 May 2027 gets decided now.
The asset: a rule library that compounds
15
Regulatory frameworks encoded today.
01
Federal AI direction tracked, AIDA died Jan 2025; encoded on tabling.
3h
Automated regulatory-watch cadence, every three hours.
FR / EN
Native bilingual output for every artifact.

The rule library is continuously updated. Every obligation is tracked as it changes, leaving no gap between what the regulation says and what Veille enforces. Every amendment makes the library deeper and harder to replicate: rebuilding it from scratch means months of combined legal and engineering work, and the gap widens with each regulatory cycle. The library is not a feature. It is the asset.

Who it's for

Built for the teams the incumbents skip.

Not the Big Six banks with a compliance floor of dozens. Veille is built for two kinds of team the incumbents overlook: Canadian financial institutions, starting with Québec's multi-regulator squeeze, and fast-moving companies, fintechs, scale-ups, and AI-heavy product teams, running more AI systems than their compliance function can track. Neither can absorb a Big-4 mandate or a five-figure enterprise licence just to prove it.

Provincial

AMF

Autorité des marchés financiers. Its AI guideline (LD IA) takes effect May 1, 2027, and it is the sole prudential regulator of Québec caisses, insurers, and dealers.

Privacy

CAI

Commission d'accès à l'information. Law 25 governs automated decisions and personal data, in force since September 2023, with penalties up to $25M or 4% of worldwide revenue.

Federal

OSFI

For the institutions also federally regulated, model-risk guideline E-23 applies May 1, 2027. One system covers the overlap, instead of three tools and a consultant.

Most compliance tools speak one regulator's language. A Québec financial institution answers to all three at once; a fintech or an AI-heavy scale-up answers to Loi 25 the moment its models touch people, and to the EU AI Act if it ships to Europe. Veille encodes all of it in one library, in French and English, and prices by institution size with unlimited AI systems, so running dozens of models never costs more than running three.

Caisses and credit unions
Mid-market insurers
OCRI / CIRO dealers and portfolio managers
Fintechs
AI-heavy scale-ups
SaaS and product teams
Product

Three operations. One system.

Veille is not a checklist platform. It runs against your AI infrastructure in real time: discovery, monitoring, evidence. All continuous.

The platform

From obligation to deliverable. Automatically.

Four engines take each AI system from regulatory exposure to regulator-ready evidence, without your team writing a single document from scratch.

01, Generate

Document generation engine

Veille drafts the compliance documentation each framework demands: privacy impact assessments, model risk records, transparency notices, mapped to every obligation across Law 25, PIPEDA, BC PIPA, AB PIPA, PHIPA, AMF Québec, OSFI E-23, OSFI B-13, CSA/CIRO, the EU AI Act, the TBS Directive, Bill 149, Bill 194, the ISED Code and Canadian human rights law.

146 obligations mapped to 18 document types
02, Review

Legal review workspace

Your counsel reviews every AI-drafted document in a focused three-panel workspace: queue, document, decision. Confidence scores and flagged gaps surfaced inline. Approve, nuance, or return in one click.

Lawyers review 3× faster
03, Monitor

Regulatory intelligence

When a regulator moves, Veille synthesizes what changed and maps the impact to each of your AI systems: which obligations shift, which actions to take, in plain language, French and English.

Per-system impact mapping
04, Prove

Compliance reports

One click produces a board- and regulator-ready report: posture score, validated documents, open gaps, active watch, sealed in a tamper-evident WORM vault with a verifiable SHA-256 hash chain.

Deliverable-ready
Regulatory coverage

The library is current. Always.

From Law 25 privacy impact assessments to OSFI E-23 model risk management and EU AI Act high-risk classification: every framework encoded obligation by obligation. When legislation changes, the rule library updates, no gap between what the law says and what Veille enforces.

Québec

Law 25

Automated decision-making, transparency obligations, and the right to human review. Binding on private-sector organizations since September 2023.

European Union

EU AI Act

High-risk classification and transparency requirements; the high-risk Annex III obligations are deferred to December 2027. Applies extraterritorially to Canadian organizations.

Sectoral, Finance

OSFI E-23

Model risk management guideline for federally regulated financial institutions. Applies to all AI and machine learning models in production.

Ontario, Employment

Bill 149

Working for Workers Four Act, ESA s. 8.4. Publicly advertised job postings must disclose the use of AI to screen, assess or select applicants.

Ontario, Public sector

Bill 194

AI accountability frameworks and risk management for Ontario public bodies. Technical standards regulations pending.

Federal

TBS Directive

Directive on Automated Decision-Making for the federal public service. Algorithmic Impact Assessment, transparency, bias testing, peer review and recourse.

Québec, Finance

AMF Québec

Autorité des marchés financiers guideline on AI use for Québec financial institutions (caisses, insurers, dealers). The provincial regulator, distinct from federal OSFI. Effective May 1, 2027.

Federal

PIPEDA

The federal private-sector privacy law. Consent, accountability, and safeguards for personal information used in automated systems outside Québec's Law 25 scope.

British Columbia

BC PIPA

British Columbia's Personal Information Protection Act. Provincial privacy obligations for personal information handled by AI systems in B.C.

Alberta

AB PIPA

Alberta's Personal Information Protection Act. Provincial privacy obligations for personal information handled by AI systems in Alberta.

Ontario, Health

PHIPA

Ontario's Personal Health Information Protection Act. Rules for personal health information used in automated and AI-assisted decisions.

Canada, Securities

CSA / CIRO

Canadian Securities Administrators and CIRO expectations for AI in securities. Governance, oversight, and controls for dealers and portfolio managers.

Sectoral, Finance

OSFI B-13

Technology and cyber risk management guideline for federally regulated financial institutions, covering the systems that run AI and machine learning models.

Federal, Voluntary

ISED Code

The federal voluntary code of conduct on advanced generative AI systems. Transparency, safety, and accountability commitments for generative models.

Canada, Rights

Human Rights AI

Federal and provincial human rights law as it applies to AI. Non-discrimination duties where automated decisions affect people.

Federal

Federal AI watch

AIDA (Bill C-27) died at prorogation in January 2025. Ottawa is moving toward privacy-law reform plus a tribunal, not a standalone AI act. Veille tracks the federal direction and encodes it when a bill is tabled.

Every obligation is anchored to the official source text; independent Canadian counsel review is being formalized.

We are building Veille AI because we watched organizations spend more than $200,000 on a single annual compliance sprint, then spend the following twelve months hoping nothing had changed. It always does. Compliance is not a project. It is an operating condition.

Veille AI, Montréal, 2026
Serge Anthony Maa, Co-Founder & CEO Stefan Wakata, Co-Founder & CTO

Compliance isn't an annual audit. It's a living posture.
Prove it the day they ask.

A consultant's report is out of date the day after it's signed. Veille keeps your proof live and current, so the day a regulator, an auditor, or your board asks, you're ready, not scrambling. Start with a 90-day Inventory Sprint.

Request a demo Read the bulletin Response within one business day Founding rate $9.6K/yr flat, 2 years, any size
or stay informed