Fifteen Canadian and EU frameworks now govern how you use AI. Law 25 and the AMF guideline come first. Veille maps every obligation to the systems you actually run and builds the proof as it goes. When a regulator asks for it, it is already there.
Compliance dashboard
Five dated milestones land across four years. A federal privacy bill may join them. Each one makes continuous AI compliance mandatory for one more segment of the Canadian economy. The next falls on 1 May 2027.
The rule library is continuously updated. Every obligation is tracked as it changes, leaving no gap between what the regulation says and what Veille enforces. Every amendment makes the library deeper and harder to replicate: rebuilding it from scratch means months of combined legal and engineering work, and the gap widens with each regulatory cycle. The library is not a feature. It is the asset.
Not the Big Six banks with a compliance floor of dozens. Veille is built for two kinds of team the incumbents overlook: Canadian financial institutions, starting with Québec's multi-regulator squeeze, and fast-moving companies, fintechs, scale-ups, and AI-heavy product teams, running more AI systems than their compliance function can track. Neither can absorb a Big-4 mandate or a five-figure enterprise licence just to prove it.
Autorité des marchés financiers. Its AI guideline (LD IA) takes effect May 1, 2027, and it is the sole prudential regulator of Québec caisses, insurers, and dealers.
Commission d'accès à l'information. Law 25 governs automated decisions and personal data, in force since September 2023, with penalties up to $25M or 4% of worldwide revenue.
For the institutions also federally regulated, model-risk guideline E-23 applies May 1, 2027. One system covers the overlap, instead of three tools and a consultant.
Most compliance tools speak one regulator's language. A Québec financial institution answers to all three at once; a fintech or an AI-heavy scale-up answers to Loi 25 the moment its models touch people, and to the EU AI Act if it ships to Europe. Veille encodes all of it in one library, in French and English, and prices by institution size with unlimited AI systems, so running dozens of models never costs more than running three.
Veille is not a checklist platform. It runs against your AI infrastructure in real time: discovery, monitoring, evidence. All continuous.
Four engines take each AI system from regulatory exposure to regulator-ready evidence, without your team writing a single document from scratch.
Veille drafts the compliance documentation each framework demands: privacy impact assessments, model risk records, transparency notices, mapped to every obligation across Law 25, PIPEDA, BC PIPA, AB PIPA, PHIPA, AMF Québec, OSFI E-23, OSFI B-13, CSA/CIRO, the EU AI Act, the TBS Directive, Bill 149, Bill 194, the ISED Code and Canadian human rights law.
146 obligations mapped to 18 document typesYour counsel reviews every AI-drafted document in a focused three-panel workspace: queue, document, decision. Confidence scores and flagged gaps surfaced inline. Approve, nuance, or return in one click.
Lawyers review 3× fasterWhen a regulator moves, Veille synthesizes what changed and maps the impact to each of your AI systems: which obligations shift, which actions to take, in plain language, French and English.
Per-system impact mappingOne click produces a board- and regulator-ready report: posture score, validated documents, open gaps, active watch, sealed in a tamper-evident WORM vault with a verifiable SHA-256 hash chain.
Deliverable-readyFrom Law 25 privacy impact assessments to OSFI E-23 model risk management and EU AI Act high-risk classification: every framework encoded obligation by obligation. When legislation changes, the rule library updates, no gap between what the law says and what Veille enforces.
Automated decision-making, transparency obligations, and the right to human review. Binding on private-sector organizations since September 2023.
High-risk classification and transparency requirements; the high-risk Annex III obligations are deferred to December 2027. Applies extraterritorially to Canadian organizations.
Model risk management guideline for federally regulated financial institutions. Applies to all AI and machine learning models in production.
Working for Workers Four Act, ESA s. 8.4. Publicly advertised job postings must disclose the use of AI to screen, assess or select applicants.
AI accountability frameworks and risk management for Ontario public bodies. Technical standards regulations pending.
Directive on Automated Decision-Making for the federal public service. Algorithmic Impact Assessment, transparency, bias testing, peer review and recourse.
Autorité des marchés financiers guideline on AI use for Québec financial institutions (caisses, insurers, dealers). The provincial regulator, distinct from federal OSFI. Effective May 1, 2027.
The federal private-sector privacy law. Consent, accountability, and safeguards for personal information used in automated systems outside Québec's Law 25 scope.
British Columbia's Personal Information Protection Act. Provincial privacy obligations for personal information handled by AI systems in B.C.
Alberta's Personal Information Protection Act. Provincial privacy obligations for personal information handled by AI systems in Alberta.
Ontario's Personal Health Information Protection Act. Rules for personal health information used in automated and AI-assisted decisions.
Canadian Securities Administrators and CIRO expectations for AI in securities. Governance, oversight, and controls for dealers and portfolio managers.
Technology and cyber risk management guideline for federally regulated financial institutions, covering the systems that run AI and machine learning models.
The federal voluntary code of conduct on advanced generative AI systems. Transparency, safety, and accountability commitments for generative models.
Federal and provincial human rights law as it applies to AI. Non-discrimination duties where automated decisions affect people.
AIDA (Bill C-27) died at prorogation in January 2025. Ottawa is moving toward privacy-law reform plus a tribunal, not a standalone AI act. Veille tracks the federal direction and encodes it when a bill is tabled.
Every obligation is anchored to the official source text; independent Canadian counsel review is being formalized.
We are building Veille AI because we watched organizations spend more than $200,000 on a single annual compliance sprint, then spend the following twelve months hoping nothing had changed. It always does. Compliance is not a project. It is an operating condition.
A consultant's report is out of date the day after it's signed. Veille keeps your proof live and current, so the day a regulator, an auditor, or your board asks, you're ready, not scrambling. Start with a 90-day Inventory Sprint.
A free monthly digest, open to anyone: what changed in Canadian AI regulation, decoded. (Mapping it to your own systems is the platform, not the bulletin.)