The EU AI Act for Canadian software vendors: what actually applies to you
When the EU AI Act section of a buyer's questionnaire lands in Toronto, Montréal or Vancouver, two reflexes kick in: point at PIPEDA and adequacy, or point at AIDA. Neither answers the question. Scope under Regulation (EU) 2024/1689 is decided by the Regulation's own text, and it crosses the Atlantic exactly the way the GDPR does.
Does the EU AI Act reach you?
Two clauses of Article 2(1) decide it for a Canadian vendor:
- The market trigger — Art. 2(1)(a). Providers placing AI systems on the market or putting them into service in the Union are in scope irrespective of whether they are established in the Union or in a third country. One paying customer in Ireland or Germany puts a Toronto vendor in scope as provider; Canadian incorporation changes nothing.
- The output trigger — Art. 2(1)(c). Third-country providers and deployers are in scope where the output produced by the AI system is used in the Union. Selling only to Canadian and US enterprises does not keep you out if their European subsidiaries consume your AI's reports, scores or content.
If neither trigger applies, you are genuinely out of scope — and entitled to say so. Our Article 50 checker runs the test question by question; the full non-EU vendor guide covers both triggers in depth.
What you owe if it does
Being in scope does not mean the whole Regulation lands on you. For most B2B SaaS — limited-risk systems outside Annex III — the obligations are the Article 50 transparency duties, applicable since 2 August 2026. The Digital Omnibus did not postpone them.
- 50(1) — if your product includes AI that interacts directly with people (chatbots, voice agents), users must be told they are dealing with a machine.
- 50(2) — synthetic audio, image, video or text your product generates must be marked machine-readable as artificially generated; systems already on the market have until 2 December 2026.
Mind the rebranding rule: a deployer becomes the provider when it markets a system under its own brand or substantially modifies it. If your SaaS wraps GPT, Claude or any third-party model under your own name, you — not your model supplier — are the provider for Article 50 purposes.
High-risk obligations attach only if your use case sits in Annex III, and after the Omnibus they apply from 2 December 2027. Article 50 fines can reach €15,000,000 or 3% of worldwide turnover, whichever is higher (Art. 99(4)(g)); SMEs pay the lower of the two (Art. 99(6)).
What Canadian law adds (and what it doesn't)
Canada holds one genuine advantage in a European deal: a partial EU adequacy decision (Commission Decision 2002/2/EC, carried forward under the GDPR and reaffirmed in the Commission's January 2024 review of the pre-GDPR adequacy decisions) covering commercial organisations subject to PIPEDA. When a buyer's privacy reviewer examines EU-to-Canada personal-data flows, adequacy is a cleaner answer than the Standard Contractual Clauses most third-country vendors rely on.
But adequacy is a GDPR Chapter V transfer mechanism: it says nothing about the AI Act and exempts you from none of Article 50.
On the AI side, the federal picture is thinner than many questionnaire answers assume. The proposed Artificial Intelligence and Data Act (AIDA), part of Bill C-27, died when Parliament was prorogued in early 2025. As at this guide's legal base date, we cite no Canadian federal AI statute in force — verify any successor's status before referencing it to a buyer. There is no domestic "equivalence" argument to make; the trigger that matters remains the European Article 2(1).
The questionnaire reality
Direct enforcement against a vendor with no EU establishment is not the near-term risk. The questionnaire is: your enterprise customers are in scope, so AI-CAIQ and SIG 2026 questionnaires — and AI sections in RFPs — now ask Canadian vendors to state their EU AI Act position, and the buyer's legal team reads the answer.
The classic Canadian mistake: answering the AI Act section with PIPEDA compliance and adequacy status — a different law, and reviewers flag it immediately. The answer that survives scopes honestly under Art. 2(1), classifies the system, names the Article 50 duties with dates, and states measures and gaps. Just received one? Start with what to do when you receive a security questionnaire and our worked answer to "Are you EU AI Act compliant?".
Mini-FAQ
Does Canada's EU adequacy status exempt us from the EU AI Act?
No. Adequacy is partial — commercial organisations subject to PIPEDA — and covers GDPR transfers, not AI Act scope. Article 2(1) applies irrespective of where the provider is established.
Can we cite AIDA as our AI compliance framework in a questionnaire?
Be careful. AIDA died with the 2025 prorogation; as at this guide's last update we cite no Canadian federal AI statute in force. Verify the current state before citing anything to a buyer.
We only sell to Canadian and US customers — are we outside the EU AI Act?
Not necessarily. Under Art. 2(1)(c), output used in the Union is enough. If your customers' EU teams consume your AI's output, you can be in scope with no EU contract at all.
- Regulation (EU) 2024/1689, Official Journal — Art. 2(1)(a), 2(1)(c), Art. 50, Art. 99, Art. 113 (ELI: data.europa.eu/eli/reg/2024/1689/oj)
- Digital Omnibus — Parliament 16 June 2026; Council 29 June 2026 (consilium.europa.eu)
- Commission Decision 2002/2/EC — adequacy of PIPEDA for commercial organisations (GDPR Chapter V); reaffirmed by the Commission's adequacy review report of 15 January 2024 (COM(2024) 7)