← Insights / Compliance

Executive Orders vs State Laws: The US AI Compliance Rift

If your firm operates in, sells into, or processes data from the United States or Canada, the AI compliance picture has shifted considerably in the past eighteen months. Neither jurisdiction has arrived at a clean, unified framework — but both are moving in ways that create real obligations and real

Compliance 9 August 2026 6 min read

US/Canada AI Compliance Update: Federal Pre-emption, State Laws, and What Professional Services Firms Need to Know (2026)

If your firm operates in, sells into, or processes data from the United States or Canada, the AI compliance picture has shifted considerably in the past eighteen months. Neither jurisdiction has arrived at a clean, unified framework — but both are moving in ways that create real obligations and real risks right now. Here is what you need to understand.

The US Federal Push: Pre-emption Without Legislation

The Trump administration has made its position clear: it wants federal authority over AI governance, and it is willing to use executive power and funding levers to assert it. Following Executive Order 14179 in January 2025, which revoked earlier AI safety directives in favour of an innovation-first posture, a December 2025 Executive Order established an AI Litigation Task Force. That body has an explicit mandate to challenge state AI laws it considers "onerous" and to evaluate whether they conflict with federal objectives — including the threat of withholding federal funding from non-compliant states.

A March 2026 National Legislative Policy Framework for Artificial Intelligence followed, setting out recommendations for unified federal legislation. A further June 2026 Executive Order addressed innovation and security for advanced AI models.

The practical problem for professional services firms is this: none of these actions constitute comprehensive federal legislation. The only AI-specific federal law currently on the books is the TAKE IT DOWN Act (2025), which addresses non-consensual deepfakes. Everything else remains a patchwork of executive orders, agency guidance, and state-level rules — and that patchwork is not going away any time soon, whatever the federal government's stated ambitions.

State Laws Remain Live Obligations

Despite federal pressure, US states continue to legislate. The compliance burden for firms operating across multiple states is real and growing.

California has introduced three significant laws effective January 2026. SB 53 requires transparency in frontier AI models. AB 2013 mandates the publication of training data summaries. SB 942 requires disclosure of AI-generated content. If your firm uses AI tools to produce client-facing content, legal documents, marketing materials, or HR communications, these disclosure obligations are directly relevant.

Colorado's position has also evolved. The original SB 24-205, which was widely watched as a model for high-risk AI regulation, was repealed and replaced by SB 189 in May 2026. The new law shifts focus from "high-risk AI" to automated decision-making technology more broadly, streamlines some developer and deployer obligations, and carries an effective date of 1 January 2027. Colorado's revised framework will be particularly relevant to HR consultancies and firms using algorithmic tools in recruitment, performance management, or client decisioning.

Illinois, New York, and Connecticut have each enacted or refined laws addressing AI in employment and consumer protection contexts. For any firm with a US workforce or US clients, these are not peripheral concerns.

The FTC's Enforcement Position

The Federal Trade Commission established a dedicated AI enforcement unit in January 2026, and its focus areas matter for professional services firms. The FTC is targeting deceptive AI claims, algorithmic bias, and — notably — the suppression of accuracy in AI outputs.

A July 2026 proposed policy statement put developers and deployers on notice that adjusting AI outputs away from factual accuracy, even to comply with state law requirements, could constitute consumer deception under Section 5 of the FTC Act. This creates a genuine tension: state law may require certain content modifications or safety interventions, while the FTC may characterise those same modifications as deceptive if they distort accuracy.

For accountancy firms, solicitors, and marketing agencies producing AI-assisted outputs for clients, the message is straightforward. Claims about your AI tools need to be accurate. The outputs those tools produce need to be what you represent them to be. The FTC's enforcement appetite is real, as demonstrated by actions against Rytr LLC and NGL Labs, and it is not limited to technology companies.

Canada: No Federal AI Law, But Obligations Exist

Canada's proposed federal AI legislation, AIDA, which formed part of Bill C-27, died in January 2025 following parliamentary prorogation. As of mid-2026, Canada has no comprehensive federal AI framework. Firms operating there should not interpret that as an absence of obligation.

AI governance in Canada currently relies on existing privacy law, human rights legislation, and consumer protection rules. The Office of the Privacy Commissioner is actively prioritising AI-related concerns, particularly around children's privacy and AI-generated deepfakes.

More immediately, amendments to PIPEDA via Bill C-15 received Royal Assent in March 2026. These introduce a data mobility right, enabling individuals to request that prescribed organisations transfer their personal information to another designated entity. For professional services firms that hold significant volumes of client data — which is to say, nearly all of them — understanding how this right will be operationalised through forthcoming regulations is a compliance priority, not an optional exercise.

At the provincial level, Alberta is expected to overhaul its Personal Information Protection Act in 2026, introducing dedicated children's privacy obligations and a penalty-based enforcement regime. Firms with operations or clients in Alberta should be tracking this closely.

What This Means for International Firms

Professional services businesses headquartered outside North America are not insulated from these developments. If your firm has US or Canadian clients, uses US-based AI platforms, processes personal data relating to US or Canadian individuals, or employs staff in those jurisdictions, you face compliance exposure.

The federal pre-emption push in the US creates particular uncertainty for international firms trying to establish consistent internal AI governance policies. You cannot yet assume that federal standards will override state requirements on any given issue. Building your compliance approach around the most demanding applicable state requirements — whilst monitoring federal developments — remains the more defensible position for now.

The absence of Canadian federal AI legislation similarly means you cannot rely on a single reference framework. Existing privacy and human rights obligations apply to AI systems today, and the data mobility amendments to PIPEDA introduce new operational requirements that need to be built into your data handling processes.

The Compliance Priorities Right Now

Across both jurisdictions, three areas demand immediate attention from professional services firms.

First, audit your AI use cases against applicable state and provincial disclosure requirements. If your firm produces AI-assisted content for clients — in any form — you need to understand where disclosure obligations apply and whether your current practices meet them.

Second, review any automated decision-making tools used in HR, client assessment, or service delivery against the evolving Colorado, Illinois, New York, and Connecticut frameworks.

Third, assess your PIPEDA compliance position in light of the data mobility amendments and prepare for the regulations that will operationalise them.

How Ops Intel Can Help

The US and Canadian AI compliance landscapes are moving quickly, and the cost of misjudging your obligations is rising. Ops Intel works with professional services firms globally to translate regulatory complexity into clear, actionable compliance programmes — tailored to your jurisdiction, your services, and your AI use cases.

If you are unsure where your firm stands, or if you need to build a defensible AI governance framework before regulatory pressure arrives, contact Ops Intel today to arrange an initial consultation.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit