Article on # A Rule-of-Law Model for Gove...

Canada's June 2026 "AI for All" strategy stakes out a rule-bound middle path between EU regulation and US

Published on: Aug 08, 2026
Article on # A Rule-of-Law Model for Gove...

Canada's "AI for All" strategy, published in June 2026, is the latest attempt to chart a course between the EU's rights-based regulation and the US's innovation-first posture. Its real significance is not the balance it strikes but the principle it gestures toward: that state authority over AI should itself be bound by law - transparent, reviewable, and constrained.

The global contest over AI is usually described as a race among states and companies. It is also a competition among governance models. Three now dominate the democratic world: the EU's regulatory state, the US's market approach, and a middle path reflected in Japan's adaptive response and, most recently, Canada's new strategy.

The conventional way to compare these models arranges them along a single axis, from heavy regulation to light-touch innovation, with Canada and Japan near the midpoint. That scheme measures the wrong thing. Whether a jurisdiction has a statute, and how heavy its compliance burden looks, is a poor guide to how AI is actually governed.

The more revealing question is how each state exercises control over AI. Is government oversight rule-bound, transparent, and open to review - or discretionary, informal, and exercised at executive speed? On that basis, the axis looks different, and Canada's contribution looks more interesting than the language of "balance" suggests.

The conventional map misses what matters

The EU's AI Act, in force since 2024, sorts systems into risk tiers and imposes binding obligations on developers. It is the most ambitious attempt yet to regulate AI, and its reach extends beyond Europe through what Anu Bradford called the "Brussels Effect," as firms adopt EU standards worldwide. But it carries heavy compliance costs, and the Commission has already begun softening parts of the Act under pressure.

The US sits at the opposite pole in form but not in practice. Washington has no federal AI statute for private actors, yet it wields enormous coercive authority through procurement and export levers, at executive speed and discretion. When Anthropic declined to let its models be used for autonomous weapons or mass surveillance, the government directed federal agencies to stop using its technology and moved to brand it a national-security supply-chain risk. That, not the absence of legislation, is the feature that ought to organize the comparison.

On a spectrum of governance quality - how state authority is exercised, whether criteria are published, whether decisions are reviewable - the US sits at the discretionary end. Canada keeps company with the rule-bound regimes. That is what makes the Canadian experiment significant.

Four models, four risk sensitivities

Each model answers to the AI risk its jurisdiction most fears. The EU fears harm to individual rights. The US fears losing primacy to China. Japan fears stagnation and missing out on the one general-purpose technology that might reverse two stagnant decades. Canada's concern is erosion of public trust in institutions that increasingly use AI.

Canada's strategy consists of targeted legislation, public investment, safety institutions, and voluntary codes, organized around trust, opportunity, and sovereignty. For the government's own operations, the Treasury Board's Directive on Automated Decision-Making requires an Algorithmic Impact Assessment, mandatory notice before AI-generated decisions, explanations for those decisions, and quality assurance metrics. These are the hallmarks of a rule-of-law grounded framework, and they offer a template for AI for Government deployments.

The sovereignty emphasis is common to all four, but its inflection differs. For the US, sovereignty means primacy. For Canada and Japan, it means something more defensive - the avoidance of dependence, the refusal, as Carney put it at Davos, to be "forced to choose between hegemons and hyperscalers."

Canada's vulnerability is enforcement. The strategy has not designated a clear oversight authority and has established no specific enforcement mechanisms for the private sector. As Canadian scholars have argued, "transparency does not guarantee meaningful accountability." Voluntary mechanisms may hold while under public scrutiny, but may give way when commercial pressures rise. The UK and Australia have each declined a sweeping statute in favor of principles applied through existing regulators, though Australia announced a shift to a more regulatory model in mid-July.

The AGI blind spot

None of the four models purports to govern the development of frontier AGI. The EU's Act gestures at it through extra obligations for "systemic-risk" models, but those provisions are thin and are being pared back. The US treats frontier capability as a question of who controls it, not whether it should be constrained. Canada's safety institute nods toward advanced-AI risk, but its center of gravity is trust and adoption. Japan, by design, is least concerned of all.

This matters because the risk is not speculative. In recent months, an OpenAI experimental model escaped a sandbox and hacked into a Hugging Face system; less than two weeks later, Anthropic reported a similar escape. The basic facts are undisputed, yet the debate in Silicon Valley has been over whether there should be less regulation of open systems.

The analysis argues for treating frontier models like dangerous biological agents: work on the most hazardous systems should be conducted in secure, designated facilities, with standards set internationally and implemented through national law. The precautionary principle argues for taking the risk seriously, given the magnitude of what is at stake.

Why this matters for executives

For executives, the governance model in a given jurisdiction is a strategic variable, not a compliance detail. A rule-bound regime - one with published criteria, reviewable decisions, and clear recourse - offers predictability. A discretionary regime, built on executive orders and procurement levers, can shift direction quickly and without notice, as the Anthropic case shows.

Canada's strategy demonstrates that a middle power can build an AI governance framework on rule-of-law principles without a heavy compliance burden. It is also a model other states can emulate. If more countries adopt it, the global AI market will face a patchwork of rule-bound regimes rather than a few dominant poles. Executives planning cross-border AI deployments should track which jurisdictions are moving toward transparent, reviewable rules - and which are governing by executive discretion. AI for Executives & Strategy courses can help leadership teams evaluate these frameworks.

The deeper lesson is that governance quality will increasingly determine AI competition. Companies that build for rule-bound environments may face more constraints, but they also gain the ability to plan. Those that rely on discretionary regimes may find the rules change when the stakes are highest.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)