A European regulation should not, on its face, bind a Canadian company with no presence in Europe. The EU’s AI Act is written to reach past that assumption, and reading its actual scope clause is the only way to know whether it reaches you.
Key takeaways
Everything in this piece describes European Union law. None of it is a Canadian statute, and none of it should be read as one — the reason it belongs in a Canadian discussion at all is that its own text reaches past the EU’s borders in a way most foreign laws do not.
Article 2 of Regulation (EU) 2024/1689 — the AI Act — sets out who the Regulation applies to, and two of its clauses matter to a company with no European office at all. It applies to “providers placing on the market or putting into service AI systems… in the Union, irrespective of whether those providers are established or located within the Union or in a third country,” and separately to “providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union” (Regulation (EU) 2024/1689, Article 2(1)(a) and (c) — European Union; consolidated text, the official version being published on EUR-Lex). Read the second clause again: a Canadian company that never opens an EU office, never sells directly into the EU, and never registers there can still fall inside the Act’s scope if its AI system’s output ends up being used in the EU — for example, through a client, a partner, or a downstream integration that feeds the output into an EU-based process. The Regulation’s own recitals make the intent explicit: the rules “should apply to providers of AI systems in a non-discriminatory manner, irrespective of whether they are established within the Union or in a third country” (recital 21), and certain systems fall within scope “even when they are not placed on the market, put into service, or used in the Union” itself, if their output is (recital 22).
The Act sorts AI uses into four fixed categories, named directly in the law rather than self-assessed case by case. “Unacceptable risk” practices are banned outright — harmful manipulation, social scoring, untargeted scraping to build facial recognition databases, and AI systems generating non-consensual intimate imagery are named specifically; these prohibitions “became effective in February 2025.” “High-risk” use cases — CV-sorting software for recruitment, credit-scoring systems, AI in the administration of justice, and safety components in critical infrastructure among them — face strict obligations including risk assessment, high-quality training data, activity logging, detailed documentation and human oversight, starting December 2, 2027. A “transparency risk” tier requires disclosure — a chatbot must make clear it is a machine, and AI-generated content (particularly deepfakes) must be identifiable — and those rules “come into effect in August 2026.” A residual “minimal or no risk” tier, covering “the vast majority of AI systems currently used in the EU,” carries no rules at all (European Commission, the AI Act — European Union). A Canadian business supplying into any of the higher tiers needs to know which one its product lands in, and needs to know well before the relevant date, not after.
Foundation-model providers face their own timeline, distinct from the four-tier system above. “The AI Act rules on GPAI became effective in August 2025,” covering transparency and copyright obligations for providers of general-purpose AI models — and for models “that may pose systemic risks,” providers must additionally assess and mitigate those risks (European Commission, the AI Act — European Union). This matters specifically for a Canadian company building or fine-tuning a foundation model, not just for one reselling a downstream product — the Commission has published a Code of Practice and a training-data transparency template to support compliance, both aimed squarely at model providers rather than end-user businesses.
None of the above makes the EU AI Act Canadian law, and none of it changes anything already covered in how Canada regulates AI without an AI act — PIPEDA, the Copyright Act and the Competition Act keep applying to a Canadian business exactly as they already do, regardless of whether the EU Act also reaches it. The two questions are independent: “what does Canadian law require of this AI system” and “does the EU AI Act also reach it because its output lands in the EU” can both be true at once, and a business that only checks one of them has only answered half the question. It is also worth being precise about what “reaches it” means here — it is a legal question about the Act’s own scope clause, not a prediction about enforcement likelihood, which is a separate and much harder question this piece does not attempt to answer.
A Toronto-based company builds an AI tool that screens job applicants, and licenses it to a mid-sized employer with hiring operations in both Canada and Germany. The Toronto company never opens a European office and never sells directly to an EU customer — its only relationship is with the Canadian parent. But the employer’s German subsidiary uses the same licensed tool to screen applicants for roles based in Germany, meaning the tool’s output — a recommendation or ranking about a specific candidate — is being used inside the EU. Under Article 2(1)(c), that is enough to bring the Toronto company’s tool within the Regulation’s scope for that use, and recruitment screening is itself one of the categories the Act names as “high-risk.” The Toronto company’s Canadian obligations under PIPEDA and Ontario’s ESA do not disappear because of this — they simply sit alongside a second, separate compliance question the company would not have if its tool’s output stayed inside Canada.
Related: how AI systems get sorted by risk and is there an AI registry in Canada — the EU’s own registration duty for high-risk systems.
No. Article 2(1)(c) of the Regulation extends it to providers established outside the EU whose AI system’s output is used inside the EU, with no EU establishment required.
Possibly not automatically — the scope clause turns on where the output is used, not only on where you sell. If a Canadian client or partner feeds your system’s output into an EU-based process, that can bring the output within scope even though you never sold into the EU directly.
No, and they are not comparable in force. The EU AI Act is an enacted, binding regulation with fixed dates already in effect for some tiers; AIDA is a bill that has not passed — see what AIDA proposed and where it stands for its actual status.
A short conversation can help work out whether Article 2’s scope clause actually reaches your specific product.