← Insights / Compliance

US/Canada AI Compliance Shifts: What UK Professional Services Need to Know in 2026

The regulatory landscape governing artificial intelligence in North America is moving quickly, and its implications extend well beyond US and Canadian borders. For UK accountants, solicitors, HR consultancies, and marketing agencies operating internationally — or working with clients who do — unders

Compliance 2 August 2026 6 min read

US/Canada AI Compliance Shifts: What UK Professional Services Need to Know in 2026

The regulatory landscape governing artificial intelligence in North America is moving quickly, and its implications extend well beyond US and Canadian borders. For UK accountants, solicitors, HR consultancies, and marketing agencies operating internationally — or working with clients who do — understanding what is happening across the Atlantic is no longer optional. Cross-border data flows, shared technology vendors, and global client relationships mean that North American AI compliance developments land on your desk whether you have a US office or not.

Here is a clear-eyed briefing on what has changed, what remains uncertain, and what your firm should be doing about it.


The US Federal Picture: Innovation First, Enforcement Continuing

The United States federal government has shifted its regulatory posture considerably since early 2025. The Biden-era Executive Order on AI Safety, which prioritised risk management and established reporting requirements for advanced AI models, was revoked by the Trump administration in January 2025. What followed was a series of executive orders taking a markedly more permissive stance — prioritising commercial innovation and reducing regulatory friction for AI developers.

Executive Order 14365, signed in December 2025, moves to establish a unified national AI policy and notably includes provisions to evaluate and potentially challenge state-level AI laws that conflict with federal priorities. A June 2026 Executive Order, Promoting Advanced Artificial Intelligence Innovation and Security, goes further still — directing AI developers to voluntarily share new models with the federal government ahead of public release and creating a framework for assessing AI-related risks at a national security level.

For international professional services firms, the practical implication is this: the US is not stepping back from AI governance — it is reorganising who governs and how. The shift is from precautionary federal oversight toward a framework that favours speed to market, while retaining firm control over security-sensitive applications.


FTC Enforcement: 'AI Washing' Remains a Real Risk

Whatever the administration's stance on innovation, the Federal Trade Commission has made clear it will continue pursuing businesses that make misleading claims about their AI capabilities. Operation AI Comply, launched in September 2024, has already produced a string of enforcement actions.

DoNotPay was settled with in January 2025 for falsely marketing itself as a "robot lawyer." Evolv was banned from making unsubstantiated claims about its AI-powered security sensors. IntelliVision faced action for misleading statements about the accuracy of its facial recognition software. More recently, in May 2026, the FTC took action against three marketing companies for deceptive claims around an AI-powered "Active Listening" tool — a case with direct relevance to marketing agencies and any firm procuring AI-driven marketing services.

There was one notable reversal: the FTC reopened and set aside a 2024 consent order against Rytr, an AI writing tool provider, concluding the original complaint lacked sufficient evidence and that the order placed an undue burden on innovation. This was an unusual move, clearly aligned with the wider administration policy direction.

The takeaway for professional services firms is straightforward. If your firm sells, markets, or procures AI-enabled services — and most do, whether knowingly or not — the claims made about those services carry legal weight. "AI washing," whether by your vendors or your own marketing team, is an enforcement target on both sides of the Atlantic.


The State-Level Patchwork: A Compliance Headache for Global Firms

While federal policy moves toward deregulation, US states are moving in the opposite direction. At least 31 states enacted AI-related laws or resolutions in 2024. Colorado introduced requirements for developers of high-risk AI systems to actively work to prevent algorithmic bias. California enacted multiple AI laws in September 2024, including the AI Transparency Act and the Defending Democracy from Deepfake Deception Act. New York and Montana followed with further legislation in 2025.

For firms with US clients or US-facing operations, this creates a genuine compliance headache. There is no single federal standard to apply. Instead, businesses must map their AI use cases against a fragmented state-level framework that varies significantly by jurisdiction. High-risk AI applications — those affecting employment decisions, credit assessments, or access to services — face the greatest exposure.

UK HR consultancies advising on AI-assisted recruitment for US-based clients, or UK accountancy firms using AI in financial assessments that touch US customers, need to understand which state laws may apply to them.


Canada: A Legislative Gap and Provincial Action

Canada's trajectory is instructive in a different way. The Artificial Intelligence and Data Act (AIDA), part of the broader Bill C-27, was widely seen as Canada's answer to comprehensive AI legislation. It was effectively killed in January 2025 when Parliament was prorogued, leaving Canada without federal AI law for the foreseeable future. A replacement framework is anticipated in 2026, but the timeline remains uncertain.

In the interim, provincial legislation is filling the gap. Québec's Law 25, with its final tranche of amendments coming into force in September 2024, now requires organisations to inform individuals when automated decision-making systems are being used to make decisions about them. This applies to any business handling the personal data of Québec residents — including international firms providing professional services to Canadian clients.

For UK solicitors, HR consultancies, and accountancy practices with Canadian client relationships, Québec's Law 25 is not a theoretical concern. If automated tools are being used to process personal data relating to Canadian individuals, disclosure obligations may already apply to your firm.


What This Means for UK and International Professional Services Firms

Several clear obligations and risks emerge from this evolving picture.

Vendor due diligence is non-negotiable. If your firm uses AI tools sourced from North American vendors — and the majority of enterprise AI products are — you need to understand the claims those vendors are making and whether their tools have been subject to regulatory scrutiny. FTC enforcement is a signal, not just a US domestic matter.

Marketing claims require legal review. The FTC's May 2026 action against marketing agencies for AI-related misrepresentation is a direct warning to the sector. If your agency markets AI-powered services, every claim needs to be substantiated and defensible.

Cross-border data flows need mapping. Where client data is processed using AI tools, and where those tools operate or store data in the US or Canada, your firm may be subject to North American regulatory requirements alongside your UK GDPR obligations.

Monitor the Canadian legislative space. When a new federal AI framework emerges in Canada — expected in 2026 — it will likely introduce risk-based requirements similar to those proposed under AIDA. Firms with Canadian operations or client bases should be preparing now rather than reacting later.


Take the Next Step With Ops Intel

The North American AI compliance landscape is not standing still, and neither is the global regulatory environment your firm operates in. Understanding these developments is one thing — translating them into practical compliance steps for your specific business is another.

Ops Intel works with professional services firms across the UK, Europe, North America, and beyond to map AI compliance obligations, assess risk exposure, and build proportionate governance frameworks that hold up under scrutiny.

If you would like a clear picture of where your firm stands — and what you need to do next — get in touch with the Ops Intel team today.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit