The EU delayed its high-risk AI rules, Canada has no AI law yet, and US states keep moving. Here is the one governance baseline a SaaS company can build once and map to all of them.

Navigating future AI regulations means building one AI governance baseline, an inventory, risk classification, documented controls and human review, that you can map to each law as it lands. For a SaaS company selling into the EU, Canada and the US, that is cheaper and safer than chasing every statute separately, because the rules keep moving.
Every few weeks I get a version of the same call. A founder of a 90-person HR-tech company has a German prospect whose procurement team wants to know how the product is classified under the EU AI Act. The same week, a US customer asks about Colorado and the board asks about Canada's AI law. Which first?
My answer: none of them first. Build the baseline, then map it.
The EU AI Act entered into force on 1 August 2024. Per the European Commission's AI Act page, the prohibited practices and the AI literacy provisions have applied since 2 February 2025, and the obligations for general-purpose AI (GPAI) model providers have applied since 2 August 2025.
The big change this year is the Digital Omnibus on AI. It was formally adopted as Regulation (EU) 2026/1744, dated 8 July 2026, published in the Official Journal and in force since 27 July 2026. It moves the main high-risk obligations: Annex III areas (employment, credit, education and similar) now apply from 2 December 2027, and AI in regulated products under Annex I from 2 August 2028. The Article 50 transparency duties, such as telling users they are interacting with a chatbot and labeling deepfakes, kept their 2 August 2026 date, with a short grace period to 2 December 2026 for watermarking on systems already on the market.
So there is no high-risk deadline this quarter, but transparency rules apply now if your product talks to people or generates content.
Canada still has no federal AI-specific law. The Artificial Intelligence and Data Act (AIDA) died on the order paper when Parliament was prorogued on 6 January 2025. On 15 June 2026, the federal government tabled Bill C-36, the Protecting Privacy and Consumer Data Act. It is a privacy bill, not an AI act, but it would require transparency about automated decision-making for significant decisions about individuals. As of late September 2026 it had completed first reading only, so treat its details as proposals that can change.
Provincial rules already bite. Quebec's Law 25 added section 12.1 to the private-sector privacy act: if you make a decision based exclusively on automated processing of personal information, you must tell the person, explain on request the information and principal factors used, and let them submit observations to someone who can review the decision. In Ontario, employers with 25 or more employees have had to disclose AI use to screen, assess or select applicants in publicly advertised job postings since 1 January 2026.
There is no comprehensive federal AI statute. On 11 December 2025 the President signed the executive order Ensuring a National Policy Framework for Artificial Intelligence, which created a Justice Department task force to challenge state AI laws. The order does not itself preempt state law, and the March 2026 White House legislative framework that followed is a set of non-binding recommendations to Congress.
Meanwhile the states keep legislating. Texas's TRAIGA (HB 149) took effect 1 January 2026. Colorado repealed and replaced its 2024 AI Act with SB 26-189, an automated decision-making technology law signed on 14 May 2026 and effective 1 January 2027. California's privacy regulator has finalized rules that require businesses using automated decisionmaking technology to comply from 1 January 2027.
Jurisdiction | Instrument | Status, October 2026 | What it means for a 30 to 200 person SaaS |
|---|---|---|---|
EU | AI Act prohibited practices and AI literacy | Applying since 2 Feb 2025 | Confirm you do none of the banned uses. Most B2B SaaS does not. |
EU | Article 50 transparency | Applying from 2 Aug 2026 | Disclose chatbots, label synthetic content. Act now if this is you. |
EU | High-risk (Annex III / Annex I) | Moved to 2 Dec 2027 / 2 Aug 2028 by Reg. 2026/1744 | Classify now; build evidence over the next year. No sprint required. |
Canada (federal) | Bill C-36 (privacy, incl. automated decisions) | First reading only | Watch it. Do not build to draft text. |
Quebec | Law 25, s. 12.1 | In force | Notice and human review for fully automated decisions on personal information. |
Texas | TRAIGA (HB 149) | In force since 1 Jan 2026 | Narrow private-sector duties; a defense for following a recognized AI risk framework. |
Colorado | SB 26-189 (ADMT) | Effective 1 Jan 2027 | Notices, adverse-decision explanations and human review for consequential decisions. |
California | CPPA ADMT regulations | ADMT compliance from 1 Jan 2027 | Pre-use notice, opt-out and access rights for significant decisions. |
Almost every row asks for the same four things: know where you use AI, know which uses affect people, tell those people, and keep a human able to review the outcome.
Because the laws converge on controls even when they diverge on dates. Texas makes this explicit: its affirmative defense covers a company that substantially complies with the NIST generative AI profile "or another nationally or internationally recognized risk management framework for artificial intelligence systems." That is a legislature telling you a framework is the defense.
The two frameworks I use as the baseline are the NIST AI Risk Management Framework, voluntary and released in January 2023, and ISO/IEC 42001, the certifiable AI management system standard published in December 2023. NIST defines good AI risk management; ISO 42001 gives you the management system that proves you do it consistently. Our ISO 42001 readiness checklist covers the clauses.
Approach | What gets pitched | My view for a 30 to 200 person SaaS |
|---|---|---|
One compliance project per law | "EU AI Act readiness", then "Colorado readiness" | Expensive duplication. The controls overlap, and you redo the work every time a date moves. |
Buy an AI compliance platform first | Dashboards scoring you against every regulation | A tool cannot classify your use cases or own decisions. Buy it after the baseline, if at all. |
Certify to ISO 42001 immediately | "Certification is the only proof buyers accept" | Only if a customer or contract asks. Otherwise implement the controls and certify when demand appears. |
One baseline, mapped to each regime | Rarely pitched because it sells fewer projects | The approach I recommend. Build once, maintain one evidence set, add a short mapping per jurisdiction. |
Across our assessments, companies that answer AI questionnaires quickly have the same seven things in place.
An AI use inventory covering your product features, internal tools and vendor AI, including the shadow AI your staff adopted on their own.
A risk classification for each use, recording whether it informs decisions about people (hiring, credit, access to services) and which regimes it touches.
An AI policy and acceptable use rules that name an accountable owner.
Transparency patterns: a standard chatbot disclosure, a content-labeling approach, and an adverse-decision explanation template.
A human review path for any automated decision that affects an individual.
Vendor and model due diligence, collecting the documentation your AI providers publish and tracking what data flows to them.
Evidence and logging, so you can show what the system did, who approved it and when.
If you already run a security program aligned to ISO 27001 or SOC 2, much of this plugs into your existing governance, risk and compliance structure. Quebec, California and Colorado regulate the decision, not just the model, so check your data security and privacy controls too.
This is the sequence I run with founders, assuming one internal owner working with a fractional security leader.
Days 1 to 30: see it. Build the AI inventory, classify each use, and flag anything that makes or shapes decisions about individuals. Fix Article 50 gaps first if your product has a chatbot or generates content for EU users, because that date has passed.
Days 31 to 60: govern it. Approve the AI policy, assign owners, write the transparency and adverse-decision templates, and set up the human review path. Start collecting vendor model documentation.
Days 61 to 90: prove it. Turn on logging, run one internal review against NIST AI RMF and ISO 42001 clauses, and produce a one-page mapping showing which controls satisfy the EU, Quebec, Colorado and California rules that apply to you.
After day 90 it is maintenance: re-classify when the roadmap adds AI, update the mapping when a law changes. Our AI governance playbook packages the templates for this sequence.
No EU high-risk conformity sprint. Annex III obligations apply from 2 December 2027. Classify now and build evidence steadily. Anyone selling panic about a 2026 high-risk deadline is selling against the published regulation.
No ISO 42001 certification without demand. If no customer, investor or regulator is asking, implement the controls and hold off on the audit fee.
No build to Bill C-36 draft text. It is at first reading. Track it; do not redesign product flows around clauses that may change.
No product changes for the US preemption fight. The executive order creates no duties for a private SaaS company.
No governance program at all if AI is not in your product or your decisions. If staff only use a chatbot to draft emails, you have an acceptable use problem, covered by a policy and a short training session.
It will not make you compliant by itself. You still apply it to each jurisdiction's specifics, such as Colorado's 30-day window for explaining adverse decisions.
It will not stop a determined attacker either. Prompt injection, data poisoning and agent misuse need technical safeguards and guardrails on top of policy.
It can. The Act reaches non-EU providers and deployers when their systems are placed on the EU market or their outputs are used in the EU.
Yes. Regulation (EU) 2026/1744, in force since 27 July 2026, moved Annex III high-risk obligations to 2 December 2027 and Annex I product-embedded AI to 2 August 2028. Prohibited practices, GPAI obligations and most transparency duties were not delayed.
No. AIDA died in January 2025. Bill C-36, tabled in June 2026, is a privacy bill with automated decision-making transparency rules, and it has not passed. Quebec's Law 25 already regulates fully automated decisions.
Start with the inventory; every later decision depends on it. If you want a second set of eyes, our AI governance services and ISO 42001 readiness offering are built for exactly this baseline, and our Virtual CISO services start with the Crawling tier from $2,000 a month for teams that need fractional leadership to own it. Book a free consultation and bring your AI questionnaire; we will tell you honestly which parts matter now and which can wait.
Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.