US and Canada AI Compliance 2024–2026: What UK Professional Services Need to Know
The North American AI regulatory landscape is shifting quickly, and not always in predictable directions. For professional services businesses outside the United States and Canada — whether you are a solicitors' firm in London, an HR consultancy in Singapore, or an accounting practice in the UAE — t
US and Canada AI Compliance 2024–2026: What Professional Services Firms Need to Know
The North American AI regulatory landscape is shifting quickly, and not always in predictable directions. For professional services businesses outside the United States and Canada — whether you are a solicitors' firm in London, an HR consultancy in Singapore, or an accounting practice in the UAE — these developments are not distant noise. They are live compliance risks if you serve North American clients, deploy AI tools built by North American providers, or operate across borders.
Here is a clear-eyed account of where things stand and what it means for your business.
The United States: Federal Signals and a State-Level Maze
The US federal posture on AI has shifted meaningfully under the Trump administration. The Federal Trade Commission published a proposed policy statement on AI accuracy on 1 July 2026, issued pursuant to Executive Order 14365 of December 2025. Its focus is narrow but significant: politically motivated steering or suppression of AI outputs, and the requirement for clear, conspicuous disclosures to consumers about the objectives an AI system is serving.
Critically, the FTC is using this initiative to assert a unified federal approach — one that may preempt conflicting state AI laws. That ambition alone is worth watching. If federal preemption holds, it could simplify the compliance picture for international businesses operating in the US. But that outcome is not guaranteed, and in the meantime, the patchwork remains firmly in place.
The FTC's December 2025 decision to reopen and set aside its 2024 consent order against Rytr LLC — an AI writing tool provider — adds a further layer of complexity. On the surface, it suggests the FTC is stepping back from enforcement actions based on speculative downstream harm. In practice, it signals a recalibration rather than a retreat. The FTC has made clear it will continue to pursue cases where deception or consumer harm is demonstrable. For professional services firms using AI-generated content in client-facing work, the line between acceptable use and enforceable deception deserves careful attention.
State-Level Regulation: Quantity Is Not Clarity
The scale of US state-level AI activity is genuinely extraordinary. In 2024, 635 AI-related bills were introduced across 45 states, with 99 enacted. By 2025, that figure had risen to 1,208 bills introduced across all 50 states, with 145 enacted. As of March 2026, 1,561 bills had already been introduced across 45 states.
The subject matter varies considerably. States are legislating across high-risk AI systems, algorithmic discrimination, deepfakes, biometric data, and privacy — often with inconsistent definitions and conflicting requirements. Colorado's 2024 AI law targeting high-risk systems was replaced by SB 189, which pushed major requirements back to June 2026 following constitutional challenges. California's AI Transparency Act, effective January 2026, mandates disclosure and detection tools for AI-generated or altered content from certain providers.
For international firms with US operations or US clients, the practical implication is this: you cannot treat "US compliance" as a single exercise. You need jurisdiction-by-jurisdiction analysis, particularly if your services touch California, Colorado, or other states with active enforcement environments.
NIST: The Voluntary Framework That Is Becoming the Benchmark
The National Institute of Standards and Technology's AI Risk Management Framework (AI RMF) 2.0, published in February 2024, was updated in July 2024 with the Generative AI Profile (NIST AI 600-1), which addresses risks specific to generative AI and supply chain vulnerabilities. A concept note for a Trustworthy AI in Critical Infrastructure Profile followed in April 2026.
The AI RMF is technically voluntary. It is increasingly not optional in practice. Federal agencies including the FTC, SEC, CFPB, FDA, and EEOC are referencing it in enforcement guidance. If your business is providing professional services to regulated US entities — financial institutions, healthcare providers, publicly listed companies — your clients may already be expected to demonstrate AI RMF alignment. That expectation will flow downstream to you.
Canada: A Regulatory Reset and a New Direction
Canada's federal AI story in this period is largely one of absence followed by ambition. The Artificial Intelligence and Data Act (AIDA), introduced as part of Bill C-27 and Canada's first attempt at comprehensive federal AI legislation, died on the order paper in January 2025 when Parliament was prorogued. Canada entered 2026 without overarching federal AI regulation.
That gap is now being addressed, at least in intent. Prime Minister Mark Carney launched a new national AI strategy, "AI for All," in June 2026. The strategy commits to new legislation, investment, and programmes designed to support responsible AI adoption across Canadian businesses. The details of any resulting legislation remain to be seen, but the direction is clear: Canada intends to build a coherent federal framework, and it will do so with economic competitiveness as well as risk management in mind.
For firms with Canadian clients or operations, this is a moment to build governance structures that can flex as legislation takes shape — rather than retrofitting compliance onto established practices once the law is settled.
What This Means for International Professional Services Firms
The North American picture carries direct implications for firms operating globally, in several ways.
Client-facing AI use is under scrutiny. Whether you are producing AI-assisted legal documents, financial reports, HR assessments, or marketing content for US or Canadian clients, disclosure obligations are tightening. California's AI Transparency Act is already in force. More requirements are coming.
Your AI supply chain matters. If the tools you use are built by North American providers — which, for most firms, they are — the compliance posture of those providers affects your own exposure. NIST AI 600-1's focus on supply chain vulnerabilities is a prompt to ask harder questions of your vendors.
NIST alignment is becoming a commercial expectation. Even outside the US, demonstrating that your AI governance approach maps to recognised frameworks is increasingly a client requirement and a differentiator in competitive pitches.
Canada's regulatory gap is temporary. AIDA's failure does not mean Canada lacks enforcement appetite. Provincial privacy laws remain active, and new federal legislation is coming. Building governance now is more efficient than building it under deadline.
Act Before the Deadlines, Not After Them
The North American AI compliance environment is characterised by speed, fragmentation, and ongoing uncertainty. That combination is uncomfortable for businesses that prefer to wait for clarity before acting. Waiting is itself a risk posture — and not a low-risk one.
Ops Intel works with professional services businesses globally to map their AI compliance obligations across jurisdictions, assess their current governance arrangements, and build frameworks that hold up as regulation evolves.
If you operate in or with North American markets, now is the right time to understand your exposure. Contact Ops Intel to arrange a compliance assessment and find out where your gaps are before a regulator does.
Work with Ops Intel
Need help navigating AI compliance?
We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.