veille
Issue 01, May 2026 AI Regulatory Intelligence
Regulatory Bulletin, Veille AI, Montréal

The AI regulatory moment is here. Everywhere at once.

Canada's federal AIDA bill died at prorogation in January 2025, and no successor has been tabled or dated. The EU AI Act is imposing its first hard obligations. In the US, state-level regulation is filling the federal vacuum. What follows is a structured read of where things stand, and what matters to your organization.

Canada United States European Union
From the editors

Several things are happening at once that compliance teams have never dealt with together: a provincial law (Law 25) already in enforcement mode, a European regulation that applies extraterritorially to any Canadian organization touching EU residents, and OSFI E-23 finalized and coming into force on 1 May 2027. On the federal AI front, there is no act in force: AIDA died on the order paper in January 2025 and no successor has been tabled or dated. The picture is unusually broad, even with the federal piece on hold.

This is not a moment to wait. Organizations that start their AI inventory now will have the documentation the frameworks already in force require, and the same record any future federal framework would build on. The bulletin exists to help you track this in real time, concise, opinionated, and without the noise.

In this issue
Canada, 4 items
  • Federal AI, no act in force after AIDA
  • Law 25, CAI enforcement signals
  • OSFI E-23, in force May 2027, expectations signalled
  • Bill 194, Ontario technical standards
United States, 4 items
  • Federal AI policy, post-EO landscape
  • Colorado AI Act, now in force
  • State-level proliferation
  • FTC, enforcement posture
European Union, 4 items
  • EU AI Act, high-risk deadline 2 Dec 2027 (deferred, Digital Omnibus)
  • GPAI obligations, in force
  • EU AI Office, first signals
  • UK AI, regulatory update
Lower impact, monitor Federal AI, AIDA dead

There is no federal AI act in force. AIDA died in January 2025 and no successor has been tabled, so the work that pays off is the work the frameworks already in force require.

The original Artificial Intelligence and Data Act died on the order paper in January 2025 when Parliament was prorogued. As of June 2026, no successor bill has been tabled and no session or tabling date has been confirmed. A future federal framework remains possible, but it is not scheduled and its architecture is not settled. We track the federal direction and will encode applicable obligations only if and when a bill is actually tabled, not before.

The work that pays off regardless of the federal timeline is the inventory the frameworks already in force require. Organizations that have already completed an AI inventory and risk classification under Law 25, which is in force today, hold the documentation any future federal framework would build on. The inventory is not the compliance, but it is the prerequisite to everything else, and it is justified by Law 25 and OSFI E-23 on their own.

What this means for your organization

Start the AI inventory now, for the frameworks already in force. Law 25 and OSFI E-23 already require you to know which systems you operate, what decisions they make, and what data they use. That documentation takes time to produce properly, and it is the same record any future federal framework would build on. The case for starting does not depend on a federal bill that has not been tabled.

High impact Law 25, Québec, In force

Law 25 enforcement: the CAI is signaling it is ready to act.

The Commission d'accès à l'information du Québec has been in full enforcement mode since September 2023, when Law 25's most demanding provisions, including automated decision-making transparency under Article 12.1, came into force. Two and a half years later, the CAI has opened investigations, issued guidance on impact assessments, and published detailed expectations for automated system notices.

The question is no longer whether the CAI will act, but on whom and in what sequence. The regulatory posture is consistent with what the OPC demonstrated before it: initial focus on large private-sector organizations, systematic complaints processing, and escalating penalties for organizations that fail to demonstrate good-faith compliance efforts.

Article 12.1 remains the highest-risk provision for most organizations. It requires informing individuals, before or at the time of a decision, that it is made by automated means, and disclosing the personal information used. The obligation to offer a meaningful right to human review, and to explain the principal factors behind a decision within 30 days, are frequently incomplete in practice.

What this means for your organization

If you operate automated decision-making systems touching Québec residents, Article 12.1 compliance is not optional and not later. The four obligations, inform, disclose, offer review, explain on request, need to be documented system by system, with evidence of each. A generic privacy policy does not satisfy this. An evidence dossier, built at the article level, does.

High impact OSFI E-23, Federal, Sectoral

OSFI E-23: the model risk guideline comes into force May 1, 2027, and expectations are already being set.

OSFI's model risk management guideline E-23 applies to all federally regulated financial institutions that use models, including AI and machine learning models, to inform decisions. The guideline requires model inventory, validation frameworks, governance documentation, and ongoing performance monitoring. It comes into force on May 1, 2027, but OSFI is already signalling its expectations ahead of that date, and the expectations for AI-specific model risk have sharpened significantly.

Institutions that arrive at the in-force date without a complete model inventory, or worse, without documentation that shadow AI models have been identified and assessed, will be exposed to remediation expectations. OSFI supervisory teams are already asking about LLM usage, third-party AI subscriptions, and the governance around models that were onboarded without formal validation.

The intersection of OSFI E-23 and Law 25 is particularly acute: a credit scoring model, a claims fraud detection system, or a mortgage approval model may be simultaneously subject to OSFI model governance requirements and Law 25 Article 12.1 transparency obligations. Managing these in parallel, with a single evidence record, is the core problem Veille is built to solve.

What this means for your organization

If you are a federally regulated financial institution, the May 1, 2027 E-23 in-force date is not far off. The model inventory, the validation documentation, and the governance trail need to exist before that date, not after. The window between "we should get this organized" and "the guideline is in force" is shorter than you think.

Medium impact Bill 194, Ontario, Standards not finalized

Ontario Bill 194: the technical standards are still coming. Here is what to prepare for.

The Strengthening Cyber Security and Building Trust in the Public Sector Act received Royal Assent in November 2024. The Act requires designated public sector bodies in Ontario to establish AI accountability frameworks, conduct risk assessments before deploying AI systems, and report publicly on AI use. It came into force in stages, with the technical standards, which will define how compliance is measured, still under development as of this writing.

The current posture for private-sector organizations that supply AI systems to Ontario public bodies is to monitor the technical standards consultation and prepare for vendor documentation requirements. The Act creates obligations on the public sector client, but those obligations will flow downstream to technology providers through procurement and contracting requirements.

Note: the technical standards are not finalized, and the Bill 194 obligations encoded in Veille are drafts pending counsel review, not yet validated by a law firm.

What this means for your organization

If you sell AI-enabled products or services to Ontario government bodies, Bill 194 is about to affect your procurement conversations. The technical standards will define what documentation your clients will require from you. Track the consultation process and prepare to produce AI risk documentation on request.

Medium impact Federal AI Policy, US

After Executive Order 14110, US federal AI policy is being rewritten in real time.

President Biden's Executive Order on AI (October 2023) set an ambitious federal framework: mandatory safety evaluations for frontier models, reporting requirements for dual-use AI, and agency-specific implementation plans. The Trump administration took office in January 2025 and revoked the order, directing agencies to prioritize AI development over precautionary oversight.

In practice, this means that federal AI regulation in the US is now largely sector-specific and agency-driven. The FTC continues to apply consumer protection laws to AI-driven deception and discrimination. Banking regulators maintain their model risk and fair lending frameworks. The SEC has AI disclosure requirements for investment advisers. The absence of a unified federal framework has not produced a regulatory vacuum, it has produced a fragmented patchwork that organizations with multi-sector exposure must navigate separately.

For Canadian enterprises with US market exposure, the practical implication is that compliance with US AI requirements depends almost entirely on sector, geography, and customer type. There is no single federal checklist, but there are multiple live enforcement actions.

What this means for your organization

Canadian organizations selling into the US market need to map their AI exposure by sector and state, not by a single federal framework. The question is not "are we compliant with US AI law", it is "which of our AI systems touch which regulatory regimes, and what does each one require."

High impact Colorado AI Act, SB 205, In force

Colorado's AI Act entered into force in February. It is the most substantive state AI law in North America.

Colorado SB 205, signed in May 2024 and effective February 2026, places obligations on developers and deployers of "high-risk artificial intelligence systems", defined as systems that make, or substantially influence, consequential decisions in employment, housing, credit, education, government services, healthcare, and insurance. The definitions are broad and the thresholds are lower than many organizations initially assumed.

Deployers, organizations that use high-risk AI systems to make consequential decisions about Colorado consumers, must conduct annual risk assessments, implement risk management policies, provide notice to affected individuals, and offer a meaningful right to appeal automated decisions. The law applies regardless of where the deployer is headquartered. A Québec financial institution with Colorado retail customers is within scope if it uses automated credit decisioning.

The resemblance to Law 25's automated decision-making requirements is notable: notice before or at the time of decision, right to appeal, explanation on request. Organizations already compliant with Law 25 Article 12.1 have significant structural overlap with Colorado's requirements, though the documentation formats and specific thresholds differ.

What this means for your organization

If you serve Colorado consumers with automated decision-making systems, the Colorado AI Act is active. The compliance structure mirrors Law 25 in several key ways, organizations that have built a proper Law 25 program can extend it. Those without one face the same requirements from two directions simultaneously.

Medium impact State regulation, US, Multiple

Seventeen states have introduced AI legislation in 2025-2026. Three are close to enactment.

The state-level proliferation following Colorado is significant. Texas, Virginia, Connecticut, and Illinois have introduced bills with similar high-risk AI frameworks. Texas HB 1709, modeled closely on Colorado, passed the House in April 2026 and is before the Senate. If enacted, it would be the second state AI law and the most populous state covered. Virginia's VAIA creates similar obligations with a different enforcement mechanism, private right of action rather than attorney general enforcement.

For Canadian organizations with US exposure, the practical challenge is jurisdictional tracking. A company with operations in Colorado, Texas, and Virginia could face three distinct compliance regimes within 18 months, each with slightly different definitions, timelines, and documentation requirements. The underlying obligations are structurally similar, inventory, risk assessment, notice, appeal rights, but the specific thresholds and enforcement mechanisms vary.

What this means for your organization

Track Texas closely. If HB 1709 passes, the combined footprint of Colorado and Texas means that a significant portion of US consumer-facing AI is subject to state-level high-risk AI regulation. Build the compliance architecture for the structure, not for each individual state.

Medium impact FTC, Federal, Ongoing enforcement

The FTC is using existing consumer protection authority to enforce against AI-driven deception and discrimination.

Without a dedicated federal AI statute, the Federal Trade Commission has been enforcing against AI-related harms under Section 5 of the FTC Act (unfair or deceptive practices) and the Equal Credit Opportunity Act. Recent enforcement actions have targeted: AI-generated content presented as human-created, automated systems that produce discriminatory credit outcomes without adequate monitoring, and algorithmic pricing systems that create anticompetitive effects.

The FTC's guidance on AI makes clear that the agency views existing law as sufficient to cover most AI harms, and that organizations cannot avoid liability by claiming that a discriminatory or deceptive outcome was produced by an algorithm rather than a human decision. The "we didn't know the model was doing that" defense is not available.

What this means for your organization

If you operate AI systems that make decisions affecting US consumers, the FTC enforcement risk is live regardless of whether a federal AI statute exists. The key question is whether your model monitoring can demonstrate that you actively identified and addressed discriminatory or deceptive outputs, before the FTC did.

High impact EU AI Act, In force, Annex III

High-risk AI system obligations are the next major deadline, now 2 December 2027.

The EU AI Act entered into force on August 1, 2024. The implementation timeline is staggered: prohibited AI practices became enforceable in February 2025. General-purpose AI model obligations (GPAI) took effect in August 2025. The most substantive chapter, obligations for high-risk AI systems under Annex III, now applies 2 December 2027, deferred from 2 August 2026 by the Digital Omnibus on AI (agreement 7 May 2026, endorsed by the European Parliament 16 June 2026; formal Council adoption pending), with preparatory obligations remaining active. Note that Article 50 transparency obligations stay on the original schedule of 2 August 2026.

Annex III high-risk systems include AI used in: critical infrastructure, education, employment and workforce management, access to essential private services (credit, insurance), law enforcement, migration, and administration of justice. The obligations are substantial: conformity assessments, technical documentation, human oversight measures, accuracy and robustness standards, and registration in the EU AI system database before deployment.

The extraterritorial reach of the Act is unambiguous: any provider or deployer whose AI system's output is used within the EU is subject, regardless of where the provider is established. Canadian financial institutions, insurers, and SaaS companies serving EU-based businesses or individuals are within scope if their systems fall into Annex III categories. This is not theoretical, it is already active for several Canadian organizations.

What this means for your organization

This is not a comfortable deadline for a cold start, even at 2 December 2027. A conformity assessment for a high-risk AI system, including technical documentation, a fundamental rights impact assessment, and a human oversight design, takes several months to complete properly. Organizations that start now stay within a viable timeline. Those who wait will be compressing a European compliance sprint on top of the work Law 25 and OSFI E-23 already require.

Medium impact EU AI Act, GPAI, Art. 53-55

GPAI model obligations are in force. The Code of Practice was finalized in February 2026.

General-purpose AI model providers, primarily frontier model developers, have been subject to EU AI Act obligations since August 2025. The Code of Practice developed by the AI Office, which operationalizes these obligations, was finalized in February 2026 after an extensive consultation involving more than 1,000 participants. Providers of GPAI models used in EU-facing applications are expected to maintain technical documentation, implement copyright policies, and conduct adversarial testing at defined intervals.

For most Canadian enterprises, the GPAI chapter matters primarily because the third-party AI services they deploy, from major US LLM providers, are subject to these obligations. This creates a chain of accountability: providers must produce documentation that their enterprise customers can rely on for their own conformity assessments. Tracking which of your third-party AI tools are EU AI Act compliant is now a procurement due diligence requirement.

What this means for your organization

If you use third-party AI services in EU-facing applications, your vendor's EU AI Act compliance status is now your problem. Ask your AI vendors for their GPAI documentation. If they cannot produce it, document that you asked, and assess the risk of continuing to use them for high-risk applications.

Medium impact EU AI Office, Enforcement body

The EU AI Office is operational, staffed, and issuing its first signals to the market.

The European AI Office was established in March 2024 as the central enforcement body for GPAI models and the coordination hub for national market surveillance authorities. It has published guidance on the GPAI obligations, initiated model evaluations under the safety framework, and issued informal communication to the market on what it considers compliant and non-compliant conduct. Its enforcement posture is becoming clearer with each published document.

National market surveillance authorities, the equivalent of data protection authorities for AI Act enforcement, are in various stages of readiness across EU member states. Germany's BNetzA, France's CNIL (acting in dual capacity), and the Netherlands' ACM have published their initial frameworks. The first formal enforcement actions are expected in the second half of 2026, targeting the most visible non-compliance cases in high-risk categories.

What this means for your organization

The enforcement machinery is running. The first cases will likely be chosen for visibility, organizations with large EU user bases, significant AI use, and publicly visible gaps in transparency. Being visibly non-compliant with transparency requirements is a higher risk than being imperfectly compliant with documentation requirements.

Lower impact, monitor UK AI, Post-Brexit, Sector-specific

The UK is maintaining its sector-specific approach to AI regulation, distinct from the EU AI Act.

The UK government has explicitly chosen not to adopt a horizontal AI Act equivalent, at least for now. Its approach relies on existing sector regulators, the FCA for financial services, the CMA for competition, the ICO for data protection, each applying their own AI guidance within their remit. The government's AI Action Plan (January 2026) reaffirmed this position, prioritizing "pro-innovation" regulation over precautionary horizontal legislation.

In practice, this means that UK-facing AI compliance is sector-specific, regulator-specific, and evolving faster than any single statute. The FCA's guidance on AI in financial services is substantive. The ICO's work on automated decision-making under UK GDPR is closely watched. For Canadian organizations with UK operations, the compliance posture is closer to "multiple regulatory relationships" than "one law."

Post-Brexit, the UK and EU frameworks are diverging, but organizations serving both markets need to maintain parallel documentation, and cannot assume that EU AI Act conformity satisfies UK regulatory expectations, or vice versa.

What this means for your organization

UK exposure is real but sector-specific. The priority is identifying which UK regulators have jurisdiction over your AI-enabled products and what their current guidance requires. The FCA and ICO guidance are the highest-priority reads for most financial services and data-intensive organizations.

Veille tracks this, so your team doesn't have to.

Every framework in this bulletin is encoded in the Veille rule library, obligation by obligation, and kept current as regulation changes.

Request a demo ›