US and Canadian AI rules are fragmenting apart
If your firm has clients, staff, data, or technology partnerships in the United States or Canada, the regulatory shifts currently unfolding across North America are not someone else's problem. The compliance landscape there is fragmenting rapidly, enforcement is intensifying, and the decisions being
North American AI Compliance 2025: What UK Professional Services Firms Need to Know
If your firm has clients, staff, data, or technology partnerships in the United States or Canada, the regulatory shifts currently unfolding across North America are not someone else's problem. The compliance landscape there is fragmenting rapidly, enforcement is intensifying, and the decisions being made in Ottawa, Sacramento, and Washington will shape the obligations of internationally operating businesses — including UK accountants, solicitors, HR consultancies, and marketing agencies — far sooner than many expect.
Here is what you need to understand, and what you should be doing about it now.
Canada: A Federal Pause, But Not a Regulatory Vacuum
Canada's proposed Artificial Intelligence and Data Act (AIDA), which formed part of Bill C-27, died on the order paper in January 2025 following parliamentary prorogation and sustained criticism from industry and civil society alike. Canada currently has no binding, comprehensive federal AI law. A voluntary Code of Conduct on Advanced Generative AI is acting as an interim guide, and a revised federal statute — expected in late 2025 or early 2026 — will likely incorporate lessons from the AIDA debate alongside a new data mobility right allowing individuals to request the transfer of their personal data between organisations.
The federal pause, however, does not mean inaction. Provincial legislation is already live and enforceable.
Quebec's Law 25, fully implemented by autumn 2024, requires organisations to inform individuals when automated systems use their personal information for decision-making. If your firm processes data belonging to Quebec residents — through a Canadian client engagement, a payroll system, or an HR platform — this obligation applies to you. Ontario's Bill 194, which received Royal Assent in November 2024, mandates public sector entities to disclose their AI system usage and manage associated risks. While currently targeted at the public sector, it signals the direction of travel for broader obligations.
In January 2026, the Office of the Privacy Commissioner of Canada (OPC) opened an investigation into a social media platform's generative AI tools, focusing on consent for data collection. This is a marker of where enforcement attention is heading: how organisations collect, use, and disclose personal data in the context of AI tools is now squarely in scope.
What this means for your firm: If you use AI-assisted tools — document review platforms, generative writing tools, automated HR decision systems — that process the personal data of Canadian residents, you need to audit those tools against Quebec's Law 25 requirements now, not when federal legislation eventually passes.
The United States: A Patchwork That Demands a Strategy
The United States remains without a single federal AI law, but the legislative activity is relentless. In 2024, at least 45 states proposed AI-related bills; 31 enacted laws or resolutions. For any firm operating across multiple US states, this is not a compliance puzzle — it is a compliance matrix.
The most consequential state developments are worth understanding in detail.
Colorado passed a landmark AI law requiring developers of high-risk AI systems to prevent algorithmic bias and disclose AI use. A revised version effective May 2026 introduces liability for discriminatory outcomes arising from customer use — a provision with direct implications for firms deploying AI tools that affect clients or employees.
California enacted a package of AI laws in September 2024, many taking effect from January 2026. These include the Generative AI Training Data Transparency Act, which requires public summaries of training datasets, and the AI Transparency Act, which mandates provenance data in digital content. For marketing agencies producing AI-assisted content for US clients, the provenance requirements alone warrant immediate attention.
Connecticut's "Act Concerning Online Safety," passed in May 2026, adds further obligations around AI use, reinforcing the pattern of state-level activism filling the federal void.
At the federal level, President Trump revoked the previous administration's AI executive order in January 2025, replacing it with directives aimed at developing a unified national AI policy and evaluating state laws for potential conflicts. This signals a clear federal ambition to pre-empt the state patchwork with a single national framework — but that framework does not yet exist, and the timetable is uncertain. The TAKE IT DOWN Act, passed in 2025 and targeting AI-generated deepfakes, is notable as a rare piece of bipartisan federal AI legislation, but it addresses a narrow category of harm.
What this means for your firm: If you advise US clients, use US-based AI vendors, or produce AI-assisted content for US audiences, you cannot rely on a single compliance position. You need to understand which state laws are triggered by your activities and your clients' locations.
FTC Enforcement: "AI Washing" Is in the Crosshairs
The Federal Trade Commission's "Operation AI Comply," launched in September 2024, represents the sharpest near-term enforcement risk for many professional services firms. The FTC is targeting businesses that make deceptive or unfair claims about AI capabilities — a practice it has termed "AI washing."
Critically, enforcement has extended to businesses marketing AI tools to enterprise clients. The substantiation requirements the FTC applies are the same regardless of whether the audience is a consumer or a sophisticated business buyer. If your firm, or a vendor you recommend, makes claims about what an AI tool can do, those claims must be accurate and demonstrable.
The FTC's December 2025 decision to reopen and vacate a prior consent order against Rytr LLC, an AI writing tool provider, introduces a note of nuance. The regulator appears willing to recalibrate where the alleged harm involves a more complex picture. Even so, the overall direction is clear: enforcement is active, the bar for substantiation is high, and professional services firms that rely on AI-generated outputs — or that recommend AI tools to clients — carry real exposure if those tools' claims do not hold up.
What this means for your firm: Review any AI tools you use or endorse. Examine the claims made by vendors. Ensure your own representations about AI-assisted services are accurate and supportable.
The International Dimension: Why This Is Your Problem Too
UK professional services firms have a habit of treating non-UK regulation as a distant concern until it arrives at the door. The North American AI compliance environment does not afford that luxury.
If you handle personal data from Canadian or US individuals, provincial and state-level AI disclosure obligations may already apply. If you use AI tools built on US platforms — which most firms do — the training data transparency requirements now being introduced in California will affect the tools you rely on. If you produce AI-assisted content for North American clients, provenance requirements are coming into effect. And if your firm ever seeks to expand into or serve clients in these markets, your compliance posture will be scrutinised against local standards.
The EU AI Act is already reshaping the global baseline. The North American picture is more fragmented, but it is moving in the same direction: towards mandatory disclosure, documented risk management, and meaningful accountability for AI use. Firms that build their compliance infrastructure now — rather than reactively — will be better positioned across every jurisdiction they operate in.
How Ops Intel Can Help
Navigating the intersection of multiple AI regulatory regimes — UK, EU, Canadian, and US state-level — requires more than a checklist. It requires a compliance strategy that maps your actual AI footprint, identifies your genuine exposures, and builds proportionate controls that hold up under scrutiny.
Ops Intel works with professional services firms to do exactly that. From AI use audits and vendor due diligence to staff training and board-level briefings, our compliance services are designed for businesses operating across borders in a regulatory environment that is changing by the month.
Speak to our team today. Visit opsintel.com to find out how we can help your firm stay compliant, credible, and competitive.
Work with Ops Intel
Need help navigating AI compliance?
We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.