Europe’s AI Act stopped being a bill on August 2. It started being enforced.
Under the Act, the EU’s AI Office and national regulators can now demand technical documentation from companies that build AI models, run their own evaluations of a system, order corrective measures, and issue fines. The transparency rules switched on the same day. A chatbot has to disclose that it’s a chatbot. A deepfake needs a label. Anything machine generated or altered has to carry a marker that software can detect. Ignore any of it and the fine runs to €15 million or 3% of a company’s worldwide turnover, whichever number is larger.
A Deadline That Actually Landed
Plenty of tech regulation gets announced and then drifts for years before anyone feels it. This one didn’t drift. Brussels set a date, and on that date the enforcement machinery actually turned on: audits, evaluations, corrective orders, fines attached to real numbers instead of a warning letter. Companies building AI systems that touch European users now answer to an office that can request the paperwork and act on what it finds.
That’s a meaningful shift from where most AI governance has sat for the past two years, which is somewhere between a white paper and a promise. The EU picked a lane and enforced it.
Canada’s Empty Chair
Canada has no AI statute in force. None. The Artificial Intelligence and Data Act, the piece of legislation meant to fill this exact gap, died along with Bill C-27 when Parliament prorogued in January 2025, and nobody has reintroduced it since. What Canadian AI companies have instead is a voluntary code of conduct and a stack of privacy laws written to solve a different problem, back when the biggest worry was a company selling an email list, not a model making decisions that affect someone’s life.
A voluntary code works exactly as well as the word suggests. Nobody gets fined for ignoring one. It’s a good faith gesture, and good faith isn’t what showed up in Brussels on August 2.
Why a Calgary Company Answers to Brussels Anyway
Here’s where it stops being abstract. Say a software company based in Calgary sells an AI product with customers across Europe. The EU AI Act reaches that company regardless of where its office sits, because the Act’s jurisdiction follows the outputs, not the address on the lease. If the system’s decisions affect someone living in the EU, that Calgary company sits inside the Act’s reach, answering to rules drafted in Brussels and enforced by an office it has never met, simply because Ottawa never wrote a domestic equivalent for that company to answer to instead.
That isn’t a hypothetical for some future date. That’s the actual position every Canadian AI exporter with European customers is sitting in right now, whether anyone in Ottawa has registered it or not.
What Alberta Already Has
Alberta isn’t starting from zero on this file, even without a federal AI law to lean on. The province has a privacy act in force and a data centre policy framework with real conditions written into it: no public dollars into private data centre builds, grid protection ahead of new load, tight water use controls, a computing equipment levy structured so a return lands here instead of only in a shareholder letter somewhere else. None of that is an AI statute. It’s still a framework with teeth, built by a government that decided to write its own rules rather than wait for someone else to.
The country hasn’t made that same call yet. The AI economy sitting inside Canada’s borders keeps getting bigger every quarter that passes without a domestic rulebook, and companies building here keep defaulting to whichever real regulator happens to be nearest, which at the moment is Brussels.
Should Ottawa write its own AI law, or keep letting Europe set the rules for Canadian companies by default?




