← Insights / Compliance

Canada's PIPEDA and Quebec Law 25 still bind AI work

The North American AI compliance landscape has shifted considerably in the past eighteen months. Canada has stepped back from binding federal AI legislation. The United States has responded not with a single federal framework but with a torrent of state-level laws. For professional services firms op

Compliance 16 August 2026 6 min read

Canada Abandons AIDA, US States Race Ahead: What Professional Services Firms Need to Know

The North American AI compliance landscape has shifted considerably in the past eighteen months. Canada has stepped back from binding federal AI legislation. The United States has responded not with a single federal framework but with a torrent of state-level laws. For professional services firms operating internationally — accountants, solicitors, HR consultancies, and marketing agencies with clients or operations in North America — the implications are immediate and practical.

Here is what has changed, and what you need to do about it.

Canada's AIDA Is Dead. That Does Not Mean Anything Goes.

Canada's proposed Artificial Intelligence and Data Act (AIDA), part of Bill C-27, died on the order paper in January 2025 when Parliament was prorogued. The government has since confirmed it will not be revived. In June 2026, Canada launched its "AI for All" National Artificial Intelligence Strategy — a five-year investment and policy package that sets direction but introduces no new binding compliance obligations.

The temptation is to read this as a green light. It is not.

Existing Canadian law still applies to AI systems, and it has teeth. The Personal Information Protection and Electronic Documents Act (PIPEDA) governs how organisations collect, use, and disclose personal information, and the Office of the Privacy Commissioner (OPC) is actively enforcing it in AI contexts. In May 2026, a joint OPC investigation found that OpenAI had violated Canadian privacy law by collecting publicly available data for model training without adequate consent. The OPC's conclusion — that OpenAI's practices were "overbroad" — signals clearly that consent and proportionality requirements apply to AI training data, not just finished products.

Quebec's Law 25, fully effective since September 2023, adds a further layer for firms with Quebec operations or clients. It includes specific provisions on automated decision-making, requiring organisations to inform individuals when a decision affecting them is made solely through automated means and to explain the principal factors influencing that decision.

The practical upshot: the absence of AIDA removes the pressure of a single federal deadline, but it does not remove compliance obligations. Firms processing personal data in Canada — or using AI tools that do — must still assess consent frameworks, data minimisation practices, and automated decision-making disclosures under existing law.

The US Is Not One Jurisdiction. Treat It Accordingly.

The United States has no federal AI law of general application. What it has instead is a rapidly expanding patchwork of state legislation that now demands serious operational attention.

In 2025, every US state introduced AI-related bills. One hundred and forty-five were enacted into law. The pace accelerated further into 2026. The scope varies significantly by state, but several themes recur: high-risk AI systems, discrimination in automated decision-making, disclosure requirements, and data privacy.

A few specific laws warrant attention from firms advising or serving US clients:

Colorado SB 26-189 repealed and replaced the state's earlier 2024 AI law. It now requires businesses to inform individuals when AI is used in consequential decision-making contexts, including employment. HR consultancies advising clients on recruitment technology, performance management tools, or workforce analytics need to understand whether those tools trigger disclosure obligations in Colorado.

California's AI Transparency Act (SB 942), effective August 2026, requires disclosure tools for AI-generated content. Marketing agencies producing or placing AI-generated advertising in California must ensure content is appropriately labelled and that detection tools are available. This is not a theoretical future obligation — it is in force now.

California's Transparency in Frontier AI Act (SB 53), effective January 2026, targets large frontier AI models and their developers. If your firm uses, recommends, or integrates such models, understanding this framework is part of responsible advisory practice.

The TAKE IT DOWN Act, passed federally in 2025 and effective May 2026, criminalises the non-consensual publication of AI-generated intimate images. This has implications for any firm advising on digital content, social media strategy, or online reputation management.

President Trump's December 2025 Executive Order sought to establish a unified national AI policy and signalled federal intent to challenge conflicting state laws. That tension between federal and state authority is unlikely to resolve quickly. In the meantime, compliance obligations remain at the state level.

FTC Enforcement Is Accelerating. Undisclosed AI Content Is a Priority.

For professional services firms and their clients involved in marketing, advertising, or consumer-facing communications in the United States, the Federal Trade Commission's posture deserves particular attention.

In January 2026, the FTC established a dedicated AI enforcement unit. Its stated priorities include deceptive AI-generated content, algorithmic bias, and privacy violations under existing consumer protection law. The FTC has been explicit: undisclosed AI-generated advertising is a priority enforcement area. Each non-compliant piece of content can attract a fine of up to $53,088 in 2026.

The FTC is also pursuing "AI-washing" — misleading claims about AI capabilities made by companies to investors, clients, or the public. In March 2026, Air AI settled a case for $18 million. Accountancy firms and legal advisers involved in due diligence, investment advice, or commercial transactions involving AI-enabled businesses should factor AI-washing risk into their assessments.

What This Means for International Professional Services Firms

The fragmentation of the North American regulatory environment does not reduce your obligations — it multiplies them. A UK-based accounting firm with Canadian clients, a Dubai-headquartered HR consultancy placing candidates with US employers, or a Singapore law firm advising on cross-border M&A involving North American AI assets: all of these scenarios now carry specific, jurisdiction-level compliance considerations that require active management.

Several immediate actions are worth prioritising:

Audit your AI tool stack. Identify every AI system your firm uses — document processing, client communications, research tools, marketing automation — and determine whether any of them process personal data of Canadian or US residents. Apply existing privacy frameworks accordingly.

Review client-facing AI outputs. If your firm produces or oversees AI-generated content for US clients, ensure disclosure obligations under California SB 942 and FTC guidance are being met. Build this into your standard content governance process.

Assess automated decision-making. If your firm or your clients use AI in HR, credit, insurance, or legal decision-making affecting individuals in Colorado, California, or other regulated states, disclosure and explanation requirements may already apply.

Update due diligence frameworks. Transactions involving AI-enabled businesses in Canada or the US require specific review of privacy compliance, AI claims substantiation, and exposure to state-level regulatory liability.

Stay current. With 145 US state AI laws enacted in a single year, and Canadian enforcement of existing privacy law intensifying, the compliance picture will continue to evolve. Standing still is itself a risk.


Navigating a regulatory environment this fragmented — across jurisdictions, legal traditions, and enforcement priorities — requires more than a once-a-year policy review. It requires structured, ongoing compliance intelligence.

Ops Intel works with professional services firms globally to translate complex AI regulation into clear, actionable compliance programmes. Whether you need a gap assessment, a jurisdiction-specific compliance framework, or ongoing regulatory monitoring, our team can help you stay ahead of obligations rather than react to them.

Get in touch with Ops Intel to discuss your AI compliance position.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit