The headlines make AI regulation sound like a wall of new law bearing down on every business. For most Canadian small businesses, the reality is calmer: very little of it binds you today, and the parts that might are narrow. But "calmer" is not "ignore it," because the direction is clear and a few habits now will save a scramble later. Here is an honest map of what actually applies, and what to do about it. This is general guidance, not legal advice.
The EU AI Act: probably not you, but check one thing
The EU AI Act reaches organisations anywhere if they put an AI system on the EU market or their AI output reaches people in the EU. For a Canadian business serving Canadian customers with internal AI use, it does not apply. The one piece worth checking, as we covered when its main deadline landed, is transparency: if you run a public AI chatbot or push AI-generated content to EU audiences, you may owe disclosure. Most SMBs still will not, but it is a two-minute check, not an assumption.
US state laws: relevant only if you operate there
Several US states have passed AI rules, and more are coming, aimed mainly at AI used in consequential decisions (hiring, credit, housing, insurance). If you have no US operations or customers, these are background noise. If you do sell into specific states or use AI to make decisions about Americans, it is worth a targeted look, because the patchwork is genuinely complex.
Canada: not in force yet, but coming
Canada's own AI rules, once bundled into a larger bill, are expected to return as standalone legislation, built on the same ideas of transparency, accountability, and not using AI to harm or unfairly decide about people. Nothing binds you today, but our national direction is set, and existing privacy law (PIPEDA, Law 25) already applies whenever AI touches personal data.
What to do regardless of the rules
The reassuring part is that the same short list makes you ready for all of it: know where your business uses AI, be transparent when AI meaningfully affects a customer or a decision about a person, keep humans accountable for outcomes, and protect the personal data AI touches. That is a light AI governance program, and it is the right response to a shifting landscape: proportionate, not fearful, and useful no matter which rule arrives next.