One technology, several regulatory models.
The question is no longer whether artificial intelligence will be governed. The question is how organizations can keep pace as different jurisdictions pursue different approaches. Europe has enacted a comprehensive risk-based law. The United States relies on executive policy, existing regulators and increasingly active states. Canada is continuing to shape its approach after AIDA did not become law. Standards bodies, meanwhile, are defining practical management systems that organizations can apply across borders.
Despite these differences, the direction of travel is remarkably consistent. Leaders are increasingly expected to know where AI is used, understand the purpose and risk of each system, assign accountable ownership, manage data and third parties, test and monitor outcomes, retain evidence and provide meaningful human oversight.
Canada: AIDA shaped the debate, but it is not law
Canada introduced the Artificial Intelligence and Data Act (AIDA) as part of Bill C-27 in 2022. The proposal focused on high-impact AI systems and concepts such as accountability, risk mitigation, monitoring, record keeping and transparency. Bill C-27 did not become law, so organizations should not describe AIDA as a current Canadian compliance requirement.
That does not mean Canada has stepped away from responsible AI. Existing privacy, human-rights, consumer-protection and sector-specific obligations continue to apply. Federal departments also operate under the Directive on Automated Decision-Making, and Canada’s 2026 national AI strategy places continued emphasis on safety, trust, privacy modernization and responsible adoption. For business leaders, AIDA remains useful as a policy signal – but future readiness must be distinguished from current legal compliance.
European Union: the AI Act is the global reference point
The EU AI Act is the world’s first comprehensive AI law. It uses a risk-based model, prohibiting certain practices and imposing stronger obligations on high-risk systems, general-purpose AI models and selected transparency use cases. Its requirements have been entering into application in stages since 2025, with broader obligations continuing through 2026 and 2027.
The Act matters well beyond Europe. Organizations may be affected if they place AI systems or models on the EU market, deploy them in the EU, or produce outputs used there. The practical starting point is exposure mapping: identify relevant systems, determine the organization’s role, classify risk and establish the documentation, testing, oversight and monitoring required for each use case.
United States: no single AI Act, but no regulatory vacuum
The United States has not adopted one comprehensive federal AI statute equivalent to the EU AI Act. Its model is decentralized. Federal policy currently emphasizes innovation, infrastructure, competitiveness and national security, while agencies continue to apply existing consumer-protection, employment, civil-rights, privacy, competition and sector laws to AI-enabled activities.
State activity is becoming increasingly important. Colorado, for example, enacted a revised Automated Decision-Making Technology Act in 2026 addressing consequential automated decisions and algorithmic discrimination. Other states are developing rules covering automated decisions, disclosures, deepfakes, privacy and frontier models. For organizations operating in the U.S., the absence of a single federal law does not mean the absence of obligations; it means exposure must be assessed across federal law, sector regulators and the states in which the organization operates.
ISO/IEC 42001 and NIST AI RMF: turning principles into operating practice
ISO/IEC 42001 and the NIST AI Risk Management Framework are not laws, but they are among the most useful tools for operationalizing responsible AI. ISO/IEC 42001 is a certifiable AI management-system standard covering leadership, policy, risk management, data governance, lifecycle controls, monitoring and continual improvement.
NIST AI RMF is a voluntary, outcome-oriented framework organized around four functions: Govern, Map, Measure and Manage. It provides a practical common language for business, technology, risk, legal and compliance teams. Used together, ISO and NIST can provide the repeatable operating model beneath jurisdiction-specific obligations.
Other markets and international instruments to watch
Market / instrument |
Approach |
Why it matters |
United Kingdom |
Sector-led, pro-innovation regulation through existing regulators. |
Organizations should monitor sector-specific expectations rather than wait for one omnibus AI law. |
China |
Binding rules covering recommendation algorithms, synthetic content and generative AI services. |
AI governance may need to address content, data, security, registration and local operating requirements. |
Council of Europe Convention |
The first legally binding international treaty focused on AI, human rights, democracy and the rule of law. |
It signals growing international convergence around rights, accountability, transparency and risk-based governance. |
What business leaders should do now
1. Build an AI inventory Record use cases, owners, vendors, models, data, affected users, geography and business purpose. |
2. Classify risk and exposure Assess impact, affected people, jurisdictions, sector requirements and the organization’s role as developer, provider or deployer. |
3. Assign accountable ownership Define executive, business, technology, data, risk, legal and compliance responsibilities. |
4. Establish lifecycle controls Set requirements for approval, data, testing, security, human oversight, monitoring, incidents and retirement. |
5. Create defensible evidence Maintain impact assessments, risk decisions, test results, model and vendor documentation, approvals and monitoring records. |
6. Prepare people and partners Provide AI literacy and extend governance expectations to vendors, platforms and other third parties. |
Executive perspective
Do not build a separate governance program for every new law or framework. Build one right-sized enterprise capability with common ownership, risk classification, lifecycle controls, evidence and monitoring – then map it to applicable requirements. Done well, governance is not a brake on innovation. It is what makes AI adoption repeatable, defensible and scalable.
Key takeaways
- Canada’s AIDA is not enacted law, but its concepts remain useful indicators of likely Canadian policy direction.
- The EU AI Act is binding and can apply to organizations outside Europe based on how systems and outputs enter the EU market.
- The U.S. is a federal-and-state patchwork: existing laws, sector enforcement and state AI rules all matter.
- ISO/IEC 42001 and NIST AI RMF provide practical foundations for a single, cross-jurisdictional governance model.
- The objective is not more policy. It is clear accountability and reliable controls that allow the organization to make faster, better AI decisions.
Official sources and further reading
- Parliament of Canada – Bill C-27 / AIDA legislative record
- Government of Canada – AIDA companion document
- Government of Canada – National Artificial Intelligence Strategy: AI for All
- European Commission – EU AI Act regulatory framework and timeline
- White House – America’s AI Action Plan
- Colorado Attorney General – Automated Decision-Making Technology Act
- NIST – Artificial Intelligence Risk Management Framework
- ISO – ISO/IEC 42001 AI management systems
- UK Government – AI regulation: a pro-innovation approach
- Council of Europe – Framework Convention on Artificial Intelligence