veille Built for, AI / SaaS (EU-exposed)
Vertical

You build the AI. You own the compliance.

Every software company deploying AI in Canada faces Law 25 obligations. Every company with EU users faces the AI Act. Every company selling to Ontario public-sector clients faces Bill 194. These aren't future problems, they're current obligations. Veille maps each one to each system, continuously.

Primary frameworkLaw 25, EU AI Act, Bill 194
Applies toAny AI feature, model, or automated decision
CoverageContinuous monitoring, bilingual evidence

Regulatory framework

Three frameworks that apply to every AI product touching Canada or Europe.

Québec, Privacy Law 25, Automated decisions and privacy impact assessments (QC)
Québec's Law 25 applies to any organization collecting, using, or disclosing personal information about Québec residents, including every SaaS product with Québec users. Art. 12.1 requires a transparency notice before any automated decision that significantly affects a person. Art. 3.3 and 17 require a Privacy Impact Assessment (PIA) before deploying any technology that collects personal information. For software companies shipping AI features, this means a documented assessment before every new model goes to production, not after. Both articles have been in force since September 2023. The CAI has begun enforcement reviews.
EU, High-risk EU AI Act, High-risk and general-purpose AI systems
The EU AI Act applies extraterritorially: if your AI system is used by people in the EU, regardless of where your company is incorporated, you may be in scope. Annex III lists high-risk categories including hiring tools, credit scoring, education, and critical infrastructure. Title VIII introduces new obligations for General Purpose AI (GPAI) models above certain capability thresholds, including model cards, adversarial testing, and copyright compliance documentation. Article 50 transparency obligations apply 2 August 2026. High-risk (Annex III) provisions apply 2 December 2027, deferred from 2 August 2026 by the Digital Omnibus on AI. For Canadian AI companies with any EU distribution, this is not a future problem.
Tier 2, Monitored Bill 194, AI accountability for Ontario public-sector contracts
Ontario's Bill 194 requires public bodies, and vendors supplying them, to conduct an algorithmic impact assessment before deploying AI in administrative decisions. For technology companies with Ontario public-sector clients, this creates a documentation obligation that mirrors the EU AI Act's conformity assessment process. Veille encodes the 3 active Bill 194 obligations and monitors the bill's implementation regulations as they are tabled.

Use cases

AI systems Veille monitors for technology companies.

System Primary frameworks Key obligations
Recommendation engine Law 25EU AI Act Art. 12.1 transparency, PIA, GPAI model card if above threshold
Hiring / screening AI Law 25EU AI Act Annex III High-risk classification, Conformity assessment, Human oversight documentation
Customer support chatbot Law 25EU AI Act Disclosure of AI interaction, PIA, GPAI transparency obligations
Content moderation model Law 25EU AI Act Automated decision transparency, Appeal pathway, Model documentation
SaaS analytics with AI Law 25Bill 194 PIA before deployment, Client data processing documentation, Government contract scope
Predictive API sold to enterprises Law 25EU AI Act Downstream obligation mapping, Provider vs. deployer classification, GPAI registration

Pain points

What we hear from engineering and legal teams at tech companies.

01
No one knows which models are in production
Engineering ships fast. ML experiments become production systems overnight. By the time legal asks "what AI do we have?", the answer requires weeks of discovery. Veille runs that discovery continuously, not as a project, as a process.
02
PIAs are treated as a legal formality, not a product gate
Law 25 Art. 3.3 and 17 require a PIA before deployment, not after. Most teams complete them retroactively, months after the feature shipped. The CAI considers a retroactive PIA inadequate when the processing was live before assessment. Veille makes the PIA part of the build process, not the audit.
03
EU exposure is underestimated
Canadian companies assume the AI Act doesn't apply to them. It does, if any user or customer is in the EU. For SaaS products, this is almost always true. The extraterritorial scope is identical to GDPR: where the users are, not where the company is.
04
Compliance documentation can't keep pace with the release cadence
A team releasing weekly can't write a PIA for each release manually. Veille's agent drafts the compliance documents triggered by each deployment, bilingual, article-mapped, human-gated before they count.

Act now

Law 25 has been in force since 2023. EU AI Act transparency obligations apply 2 August 2026; high-risk (Annex III) 2 December 2027.

A 30-minute call is enough to map which of your systems are in scope, which obligations apply, and where the gaps are. No deck. No sales process.

Book a 30-minute call