Home » Resources
AI governance is shaped by binding laws, government directives, regulatory guidance and voluntary frameworks.
What applies depends on where an organization operates, how an AI system is used, who it affects and the organization’s role in developing, providing or deploying it.
Effective governance connects these requirements to the AI systems they affect, the people responsible for them, the controls that address them and the evidence that demonstrates compliance.
Canada does not currently have a single economy-wide AI law, but AI is not unregulated.
Existing privacy, human-rights and sector-specific requirements may apply. Covered federal institutions must also consider the Directive on Automated Decision-Making and its Algorithmic Impact Assessment, while federally regulated financial institutions are preparing for OSFI’s updated model-risk expectations.
The proposed AIDA legislation did not become law, but Canada’s approach to AI accountability, safety and transparency continues to evolve.
The EU AI Act establishes a risk-based framework for AI and assigns different responsibilities to providers, deployers and other participants in the AI value chain.
Its requirements can apply to organizations outside the European Union when AI systems, services or outputs are placed on the EU market or used within the EU.
Readiness begins with a complete AI inventory, role and risk classification, appropriate controls, ongoing monitoring and evidence.
NIST AI RMF provides a flexible structure for governing, mapping, measuring and managing AI risk.
ISO/IEC 42001 provides a management-system approach for establishing, operating and continually improving AI governance across an organization.
Together, they help organizations connect principles and policies to accountability, risk assessment, controls, monitoring and evidence.
Connected Lifecycle
Models are retrained. Data changes. Vendors release updates. Prompts, tools and integrations evolve. AI systems are adopted for new purposes and can affect different people over time.
These changes can alter a system’s performance, risk classification and applicable requirements.
Dynamic AI governance keeps oversight aligned as AI systems, models, data, vendors and uses change through continuous monitoring and trigger-based reassessment.
FairFuture Insights