Extraterritorial scope
Does it apply to Canadian organizations?
Yes, if your AI system produces outputs used within the European Union, or if your system affects individuals in the EU, the Act applies regardless of where you are established.
In scope for most Canadian enterprises:
- SaaS platforms with European customers
- HR systems screening EU-resident candidates
- Financial institutions with European subsidiaries or counterparties
- Insurance and credit companies serving European residents
- AI outputs used by EU-based business partners in regulated processes
Risk classification
Four tiers, obligations differ significantly.
- Employment and recruitment (CV screening, promotion decisions)
- Access to essential services (credit, insurance)
- Education (admissions, assessment)
- Critical infrastructure management
Annex III
High-risk categories relevant to Canadian organizations.
| Reference | Category | Canadian relevance |
|---|---|---|
| §4 | Employment & workers management | CV screening, shortlisting, promotion decisions affecting EU-resident individuals |
| §5 | Access to essential private services | Credit scoring, insurance risk assessment, eligibility for financial products for EU residents |
| §3 | Education & vocational training | Admissions, assessment, learning outcome evaluation for EU-based students |
| §1 | Biometric categorisation | Biometric identification, emotion recognition in professional contexts |
Compliance timeline
Key dates as of July 2026.
High-risk (Annex III) obligations apply 2 December 2027, deferred from 2 August 2026 by the Digital Omnibus on AI (agreement 7 May 2026, endorsed by the European Parliament 16 June 2026; formal Council adoption pending). Preparatory obligations (documentation, registration) remain active. Article 50 transparency obligations stay on the original schedule (2 August 2026).
Penalties
Fines calibrated to the severity of the violation.
How Veille helps
EU AI Act coverage in Veille AI.
Veille identifies whether each registered system falls within a high-risk Annex III category, what documentation is required, and what gaps exist. When changes are detected, such as the Annex III deadline revision, all affected systems are re-evaluated within 4 hours.
Veille's EU AI Act coverage focuses on Annex III high-risk obligations and general-purpose AI transparency requirements. Conformity assessment processes (which require a notified body for some systems) are outside Veille's scope, the platform provides the documentation and gap analysis that feeds into that process.