Executive Summary
North America now regulates artificial intelligence through two very different experiments running side by side. Canada, after its proposed Artificial Intelligence and Data Act died with the prorogation of Parliament in January 2025, is governing AI through privacy law, procurement rules, sector guidance, and heavy public investment while it designs a National AI Strategy. The United States has no comprehensive federal AI statute either, but it does have a deregulatory federal executive agenda colliding with the most active state legislatures in the world: more than 2,000 state AI bills are in play, laws in Texas, California, Illinois, and Utah took effect in 2026, and a federal executive order is openly working to preempt them. For organizations, the practical conclusion is the same on both sides of the border. Binding obligations already exist, they are fragmented, and they are converging on a common set of expectations: transparency, risk assessment, human oversight, and accountability. This article maps the landscape and makes the case that governance is a strategic capability, not a compliance chore.
Canada: Regulating Through Everything Except an AI Act
Canada entered 2026 without an AI statute, but not without AI regulation. The Artificial Intelligence and Data Act, introduced in 2022 as part of Bill C-27, would have created a risk-based regime for high-impact systems with penalties reaching 25 million dollars or 5 percent of global revenue. It died on the order paper in January 2025 and has not been reintroduced. The current government has signalled that it will regulate AI through privacy legislation, policy, and investment rather than an omnibus act, and the Minister of Artificial Intelligence and Digital Innovation, Evan Solomon, has indicated that any future law will be a new design rather than a revival of the old one. What binds Canadian organizations today is a layered framework. Federal and provincial privacy laws, PIPEDA along with the Alberta and British Columbia acts and Quebec's Law 25, govern personal information used in AI systems, with Law 25 adding explicit transparency rights around automated decisions. Sector regulators add their own requirements, most concretely OSFI's Guideline E-23 on model risk management for federally regulated financial institutions. Human rights law applies to discriminatory outcomes regardless of whether an algorithm produced them. For the public sector, the Treasury Board's Directive on Automated Decision-Making requires algorithmic impact assessments, transparency, testing, and proportionate human oversight, and it is increasingly influential as a de facto standard because government procurement flows through it. A federal Voluntary Code of Conduct for generative AI rounds out the soft-law layer. Direction of travel is visible. The February 2026 summary of national AI strategy consultations points toward future rules on safety evaluation, adversarial testing, human oversight, traceability across the model lifecycle, and clearer allocation of liability across the AI supply chain. The 2026 Spring Economic Update set out six pillars for the forthcoming National AI Strategy. A Digital Sovereignty Framework released in November 2025 signals rising expectations about who controls Canadian data and infrastructure, reinforced by the two billion dollar Sovereign AI Compute Strategy and the January 2026 invitation for Canadian-controlled data centre projects of 100 megawatts or more. Ottawa is building the capacity first and writing the rulebook second.
The United States: A Deregulatory Centre and Activist States
The American picture inverts the Canadian one. At the federal level, a January 2025 executive order set a deregulatory direction, followed by an AI Action Plan in July 2025 that prioritized speed, infrastructure, and open-weight development. There is still no comprehensive federal AI statute; the main enacted federal law with AI relevance is the TAKE IT DOWN Act targeting non-consensual intimate imagery, enforced since May 2026. Executive orders in June 2026 added AI-enabled cyber defence work and benchmarking processes for frontier models, and procurement memoranda shape how agencies buy and use AI. The states have filled the vacuum. As of mid-2026, Texas's Responsible Artificial Intelligence Governance Act is the broadest comprehensive law in force, effective January 1, 2026, notable for intent-based liability and for granting a safe harbour to organizations that substantially comply with the NIST AI Risk Management Framework. California's Transparency in Frontier AI Act requires large frontier developers to publish risk frameworks and report critical safety incidents, alongside a training data disclosure law. Illinois made AI-driven employment discrimination a civil rights violation. Utah imposes disclosure duties, and New York City's bias audit rule for hiring tools has applied since 2023. Colorado, which passed the first comprehensive high-risk AI law in 2024, repealed and replaced it in May 2026 with a narrower automated decision-making statute taking effect in January 2027, centred on pre-use notice, explanations within 30 days of adverse outcomes, and meaningful human review. Over all of this hangs the preemption fight. A December 2025 executive order directed the Attorney General to establish a litigation task force to challenge state AI laws deemed inconsistent with federal policy and instructed the Commerce Department to identify onerous state regimes, while carving out child safety, data centre infrastructure, and state procurement from preemption. Congressional bills introduced in early 2026 would create a single federal framework that displaces state law. As of mid-2026 no preemption has been enacted, courts have not resolved the constitutional questions, and businesses must plan for the patchwork they have rather than the uniformity they might one day get.
What the Rules Actually Ask For
Strip away the jurisdictional differences and the same obligations recur across North America and beyond:
- Privacy and data governance. Lawful basis for the personal information that trains and feeds AI systems, minimization, and residency awareness, with Quebec, California, and the EU setting the practical high-water marks for multi-jurisdiction operators.
- Transparency and disclosure. Telling people when AI is used in consequential decisions, what data it relies on, and, increasingly, publishing risk frameworks for the most capable models.
- Bias and discrimination controls. Testing for disparate outcomes in employment, credit, housing, insurance, and services, the area where existing human rights and civil rights law already bites hardest.
- Risk assessment and human oversight. Documented impact assessments before deployment and meaningful human review of adverse outcomes, the common thread from Canada's federal directive to Colorado's replacement statute to the EU AI Act.
- Safety and incident reporting. Evaluation, adversarial testing, and reporting of serious incidents, currently aimed at frontier developers but signalled in Canada's consultations as a broader future expectation.
- Intellectual property. Unsettled copyright litigation over training data on both sides of the border, making provenance records and vendor indemnities a live procurement issue.
- Procurement. Government buying rules that function as de facto standards, from the Treasury Board directive in Canada to federal agency memoranda in the United States, which cascade into the private vendors who sell to them.
Why Governance Is a Strategic Capability, Not a Compliance Cost
The strongest argument for treating governance strategically comes from performance data, not legal risk. PwC's 2026 Global CEO Survey of 4,454 chief executives found that leaders whose organizations had established strong AI foundations, including responsible AI frameworks, were three times more likely to report financial returns from AI, and the 12 percent of companies achieving both revenue and cost gains were distinguished by exactly this discipline. McKinsey's 2026 AI Trust Maturity Survey of roughly 500 organizations found only about 30 percent reaching upper maturity in strategy, governance, and controls for increasingly autonomous systems, which means governance capability is still a differentiator rather than table stakes. The mechanism is simple. Good governance makes approvals predictable, which makes deployment faster, not slower. It creates the system inventory, risk tiering, and monitoring that agentic AI will demand as software begins taking actions rather than drafting text. It satisfies the procurement questionnaires of enterprise and government customers, turning compliance into market access. And it is portable: an organization aligned to the NIST AI Risk Management Framework or ISO/IEC 42001 can map most of its obligations in Texas, Colorado, Canada, and the EU onto work it has already done, including an explicit legal safe harbour in Texas. In a fragmented landscape, the framework is the constant.
Separating Fact, Opinion, and Prediction
What the evidence shows. The laws described above are enacted text with dates and duties; the AIDA vacuum in Canada, the state law patchwork, and the live but unenacted federal preemption push are all matters of record as of mid-2026. So are the performance correlations: PwC's foundations finding and McKinsey's maturity data are measured survey results, though correlation with returns is not proof of causation. What experts believe. Genuine disagreement runs through this field. Preemption advocates argue a single national standard would cut compliance costs and protect innovation; critics respond that the current federal framework offers no enforceable protections to replace what states provide. In Canada, some see the wait for a new AI law as prudent sequencing behind investment, others as a governance gap that leaves harms to be litigated under laws never designed for AI. Both positions are held by credible people. What remains a forecast. Whether and when Canada tables AI legislation, whether US courts uphold or strike down preemption efforts, whether Congress passes a federal framework, and whether the EU's enforcement timeline shifts are all open questions. Prudent planning assumes continued fragmentation for at least the next two to three years and builds on the frameworks that survive any of those outcomes.
Practical Recommendations
- Build an AI system inventory now. You cannot govern what you have not catalogued. Record every AI system in use, including embedded vendor features and employee shadow tools, with owner, purpose, data, and decision impact.
- Adopt one framework and map everything to it. Align to the NIST AI Risk Management Framework or ISO/IEC 42001, then treat jurisdictional requirements as mappings rather than separate programs. Texas already rewards this approach with a statutory safe harbour.
- Tier by risk and gate the high end. Classify systems by their impact on people's rights, money, health, and safety. Require impact assessments, bias testing, and named human oversight before high-tier systems ship, mirroring where every North American regime is heading.
- Fix procurement clauses. Push transparency, testing evidence, incident notification, and indemnity obligations into vendor contracts, because most organizations deploy far more AI than they build.
- Prepare explanations and appeals. Colorado's 2027 rules, Quebec's Law 25, and Canada's federal directive all converge on the same consumer-facing duties: tell people, explain adverse outcomes, and offer human review. Building that plumbing once serves every market.
- Assign board-level ownership. Put AI risk on a named executive and a standing board agenda with quarterly reporting, the same treatment cyber risk earned a decade ago and for the same reasons.
Key Takeaways
- There is no waiting for clarity. Binding obligations already exist in both countries through privacy, human rights, sector, and state law, even without comprehensive AI statutes.
- Fragmentation is the planning assumption. A live US preemption fight and a Canadian strategy still in design mean rules will keep shifting; frameworks, not statutes, are the stable foundation.
- The obligations rhyme everywhere. Transparency, risk assessment, bias controls, and human oversight recur across every regime, so one well-built program travels.
- Governance correlates with returns. The organizations reporting real AI value are disproportionately the ones with responsible AI foundations in place.
- Procurement is the quiet regulator. Government and enterprise buying requirements will reach most organizations before legislation does.
Where QA Enterprises Can Help
AI governance is one of QA Enterprises' core practices. We help organizations build system inventories, align to the NIST AI Risk Management Framework and ISO/IEC 42001, run impact and bias assessments, draft vendor and procurement language, and stand up the oversight routines that regulators, customers, and boards now expect, sized for small and midsize organizations rather than only enterprises. If you want a clear picture of your obligations across Canada and the United States and a governance program that speeds adoption instead of stalling it, book a 30-minute consultation with our team or write to info@qa-enterprises.com. Sources referenced: Government of Canada, ISED and Treasury Board Secretariat publications (2024 to 2026); Osler, McCarthy Tetrault, MLT Aikins, and Chambers practice commentary on Canadian AI regulation (2025 to 2026); the Texas Responsible Artificial Intelligence Governance Act, California SB 53 and AB 2013, Illinois HB 3773, Colorado SB 26-189, and NYC Local Law 144; US executive orders and the July 2025 AI Action Plan; King & Spalding and Baker Botts analyses of the December 2025 preemption executive order; NIST AI Risk Management Framework; ISO/IEC 42001; PwC 2026 Global CEO Survey; McKinsey 2026 AI Trust Maturity Survey.
Musap "Moose" Abdelhag writes on technology, entrepreneurship, and community impact. This article is part of the QA Enterprises Insights Series on artificial intelligence and the future of business.


