Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

Do You Actually Need EU AI Act?

Most Canadian companies do not need EU AI Act compliance work yet, and some never will. You need it only if you develop or deploy an AI system that touches the EU market and that system falls into a regulated risk category, most commonly "high-risk" under Annex III. If you are not selling, deploying, or making an AI system available to users in the EU, the Act does not apply to you no matter how advanced your model is.

What the EU AI Act Actually Regulates

The EU AI Act is not a blanket AI law. It sorts AI systems into four risk tiers: unacceptable risk (banned outright), high-risk (heavily regulated), limited risk (transparency obligations only), and minimal risk (no obligations). The overwhelming majority of software marketed as "AI-powered", chatbots, recommendation engines, internal copilots, sits in the limited or minimal tiers. The heavy compliance lift, conformity assessments, technical documentation, human oversight design, risk management systems, applies almost entirely to high-risk use cases: things like AI used in hiring decisions, credit scoring, biometric identification, medical devices, critical infrastructure, and law enforcement tools.

If your product recommends playlists or drafts marketing copy, you are not in scope for the high-risk obligations. If your product screens job applicants, sets loan terms, or influences access to essential services, you likely are, and that is true whether your company is in Toronto, Waterloo, or Berlin, as long as EU users are affected.

Who Genuinely Needs to Act Now

There is a real population of companies that should be moving on this today:

  • SaaS vendors selling AI-driven hiring, lending, insurance underwriting, or education-scoring tools into the EU market
  • Companies building or embedding biometric identification or emotion-recognition features anywhere near EU users
  • Medtech and health-tech firms whose AI components qualify as regulated medical devices under existing EU frameworks, which pulls them automatically into the high-risk tier
  • Fintech and insurtech companies expanding from Canada into EU markets where their models touch creditworthiness or claims decisions

For these teams, the deadlines are not theoretical. Prohibited-practice rules are already in force, and the high-risk system obligations, including conformity assessments and quality management systems, phase in on a rolling timeline through 2026 and into 2027 depending on the system category. Waiting until a prospect's procurement team asks for evidence is the expensive way to find out you needed a program eight months ago.

Who Is Over-Buying EU AI Act Compliance

We see a lot of Canadian SaaS founders reaching for EU AI Act readiness the same way they reached for SOC 2 a few years ago, as a generic trust signal, before checking whether it applies. If your AI features are internal tooling, general-purpose chat assistance, content generation, or analytics dashboards with no EU high-risk use case attached, a full EU AI Act program is the wrong spend. You would be building conformity assessment documentation for a regulation that does not touch your product.

The honest test is simple: does your AI system make or materially influence a decision about a person's access to employment, credit, education, essential services, or safety, and does that system reach EU users? If the answer is no on either count, your money is better spent on the compliance frameworks your actual buyers are asking for, SOC 2, ISO 27001, or a security questionnaire response process, rather than a regulation you are not subject to.

How the EU AI Act Interacts With Canadian Obligations

Canadian companies already juggle PIPEDA and, for anyone touching Quebec residents, the stricter automated-decision-making disclosure rules under Quebec's Law 25. Those obligations exist regardless of the EU AI Act and often cover similar ground: transparency about automated decisions, the right to an explanation, and human review rights. If you are already building governance for Law 25 automated decision-making, you have a head start on EU AI Act high-risk documentation, the risk assessment logic, human oversight design, and audit trail requirements overlap substantially. This is one reason a scoped gap assessment is worth doing even for companies that are not yet EU-bound: it tells you what you already have from domestic compliance work versus what is genuinely EU-specific.

What a Scoped Assessment Actually Looks Like

Before committing to a full readiness program, the right first step is a scoping exercise: mapping every AI system your company builds or deploys against the Act's risk categories, confirming which of those systems actually reach EU users, and flagging any that touch prohibited practices outright. For most companies this takes days, not months, and it produces a clear answer instead of a guess. Our EU AI Act readiness engagement starts exactly there, with scoping before spend, so you are not paying for high-risk conformity work on a system that never needed it.

Where a real high-risk obligation does exist, the work that follows is structured and time-boxed: a risk management system, technical documentation aligned to the Annex IV requirements, human oversight controls built into the product, and a conformity assessment path appropriate to the system category. None of that is optional once you are in scope, but none of it should be started until scope is confirmed.

Building AI Governance Once, Not Per Regulation

The companies that handle this well do not treat the EU AI Act as an isolated project. They fold it into a broader AI governance posture that also satisfies buyer expectations around responsible AI use, whether that shows up in a SOC 2 questionnaire, an ISO 42001 conversation, or a Law 25 disclosure requirement. If you are already assessing your AI governance maturity for other reasons, it is worth reviewing our ISO 42001 readiness work alongside any EU AI Act scoping, since the underlying risk management practices reinforce each other rather than duplicate effort.

The Bottom Line for Canadian Tech Companies

Traztech works with Canadian SaaS and fintech companies in Toronto, Waterloo, Ottawa, Vancouver, Calgary, and Montreal that are scaling into US and EU markets and need a straight answer on what actually applies to them, not a sales pitch dressed up as regulatory urgency. If your AI product touches hiring, lending, insurance, health, or biometric data and any part of your user base is in the EU, it is worth getting a real scoping conversation on the calendar before a customer's legal team forces the timeline. If it does not, we will tell you that too, and point you toward the compliance work that will actually move deals forward.

Not sure which category you fall into? Contact traztech for a straightforward scoping conversation, no pressure to buy a program you do not need.

Not ready for a call? Same.

Get the playbook, not a sales pitch

If this was useful, Jacob sends a few short, practical notes on locking down your startup without a big security team. No fluff, unsubscribe in one click. Just reply if you want to talk; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Need help with any of this?

We help startups build secure, scalable infrastructure. Book a free strategy call and let's talk about your stack.

Book a free consultation