On June 2, 2026, the United States signed an Executive Order requiring federal pre-deployment testing of frontier AI models. Five months earlier, the European Union's harmonized AI Act standard (prEN 18286) entered formal review. In parallel, China continues to operationalize binding rules for agentic AI systems. Within a single quarter, the three regulatory blocs that shape global AI policy have all hardened their positions.
For Canadian regulated enterprises, this is not a foreign policy story. It is a procurement, compliance, and board-reporting story. A Canadian bank's AI vendors are American. Its EU clients now demand prEN 18286 conformity questions in RFPs. Its risk committee asks how the firm is positioned across jurisdictions OSFI itself does not directly regulate.
This article maps the new three-bloc landscape, explains what each bloc actually requires, and lays out what Canadian regulated firms should be doing now to operate confidently inside it.
What Just Happened in the United States
The Executive Order titled "Secure Frontier Model Development" was signed June 2, 2026, days after the same administration publicly cancelled a near-identical draft as "too burdensome." The version that signed shrank a 90-day pre-release government access window to 30 days and changed almost nothing else. The key provisions:
- A classified benchmarking process for cyber capabilities to define what counts as a "covered frontier model."
- A 30-day confidential government access window before public release of any covered model, framed as voluntary but operationally near-mandatory for any lab seeking federal business.
- Explicit language forbidding a new mandatory licensing, preclearance, or permitting regime.
- The NIST AI Safety Institute (CAISI) is the leading candidate to run the evaluations, with the NSA flagged as a potential central player. That civilian-versus-intelligence-community question is still open.
The shift matters less for its specific mechanics than for what it tells the market. Even the most deregulatory faction in US AI policy could not kill the order. The Overton window has moved. "Nothing at all" is no longer the credible US position. Cyber capability is the first trigger; biology, CBRN, and other domains are explicitly flagged as the next likely expansions. This is, in effect, the start of a federal pre-deployment review for the highest-capability AI systems.
The Three Blocs, Briefly
Each bloc now has a structural position that is distinct, operating, and ahead of where it was twelve months ago.
| Bloc | Mechanism | Status | Who it binds |
|---|---|---|---|
| European Union | EU AI Act + harmonized standards (prEN 18286 entering finalization) | Act in force; harmonized standards in late-stage drafting | Providers and deployers whose AI output is used in the EU |
| United States | Frontier Model Testing EO (Jun 2, 2026); state laws (CA AB 2013, NY, CO) filling gaps | EO signed; state patchwork active | Frontier labs targeting federal business; deployers exposed to state law |
| China | Binding agentic AI rules; mandatory algorithmic registration; security review | Operating; tightening | Any AI system serving the Chinese market |
The EU is mandate-led and certification-driven. The United States is selectively gated at the frontier and patchwork-regulated at the deployer level. China is comprehensively binding. They will not converge into a single global standard within any reasonable planning horizon. Multinational organizations must navigate all three, and the requirements do not always align.
Where Canada Sits
OSFI has not issued an AI-specific guideline. It has not had to. The existing guidance, B-13 on technology and cyber risk, E-23 on model risk management, and B-10 on third-party risk management, already covers the substance of AI governance: independent validation, board oversight, vendor due diligence, lifecycle controls. The Canadian regulator's posture is principles-based and continuous-supervision-driven rather than instrument-led.
That posture is an advantage in a three-bloc world. A Canadian regulated enterprise that operates a defensible OSFI-aligned AI governance program already has most of what each bloc requires. The work is not building three separate programs. It is mapping a single internal program to three external sets of expectations.
The friction shows up at three boundaries:
- Vendor risk. A Canadian bank's AI is overwhelmingly supplied by US foundation-model providers. When those providers come under federal pre-release testing, the bank's downstream evidence base changes. A model that has passed CAISI evaluation is a defensible vendor input. A model that has not, used in a regulated workflow, becomes a harder conversation with internal audit.
- Client expectations. EU clients will increasingly require prEN 18286 conformity evidence from their Canadian counterparties. This is the GDPR pattern repeated. Canadian firms selling AI-enabled products into Europe will see these questions appear in RFPs within twelve months.
- Board reporting. Directors carrying accountability for AI risk now have to answer three questions at once. What is our exposure under each bloc? How are we positioned if one regime tightens further? Where do we differ from a US-headquartered competitor or an EU-headquartered partner? A single regulatory tracker is no longer sufficient.
What the US EO Means for Canadian Deployers (Not Just Frontier Labs)
The EO directly binds frontier model providers. But the implications run further down the chain.
Vendor conformity becomes a procurement criterion. "Has this model been evaluated by CAISI?" will join "Is this vendor SOC 2 certified?" in vendor due diligence packs within a year. Models that participate in the 30-day federal access regime will be defensible inputs to regulated AI systems. Models that opt out, or that newer entrants do not yet qualify for, will require additional internal evidence to be used in customer-facing or model-risk-relevant workflows.
Deployment evidence will not be substituted by vendor evidence. Your foundation-model vendor passing a federal evaluation does not certify your specific deployment. Boards and second-line risk functions will want evidence that the way the model is configured, constrained, and monitored inside your environment meets your own standards. The Canadian B-10 third-party risk framework already anticipates this distinction: vendor due diligence covers what the vendor does; ongoing oversight covers what happens once the vendor's output is in your control.
State-level law fills the federal gap. Even where the federal EO is silent, US states are active. California AB 2013 mandates training-data disclosure for AI used in the state. New York and Colorado have parallel proposals. A Canadian firm with US customers needs to track this patchwork, not just the federal layer.
Five Practical Steps for the Next Two Quarters
The right posture for a Canadian regulated enterprise is not panic, and it is not waiting for OSFI to issue an AI-specific guideline. It is mapping a single defensible internal program to three external regimes deliberately.
1. Build a regulatory exposure map for each AI use case. For every AI system in your inventory, document which blocs apply, by what mechanism (extraterritorial reach, customer location, vendor jurisdiction), and what evidence each bloc expects. Most Canadian enterprises have never produced this map. The exercise alone reveals the gaps.
2. Update vendor due diligence to include CAISI participation, prEN 18286 readiness, and Chinese algorithmic registration where relevant. Add three lines to the vendor onboarding pack. The vendors that cannot answer credibly today will be the vendors that fail your audit conversation in two quarters.
3. Separate vendor evidence from deployment evidence in your model risk file. Even if your vendor passes a federal evaluation, your file needs independent evidence that your specific deployment is configured, monitored, and constrained appropriately. This separation is already implicit in OSFI E-23 and B-10. Make it explicit.
4. Brief your board on the three-bloc landscape this quarter. Directors are seeing fragments of this in the press. They have not seen a coherent map. A one-slide overview of the three blocs, the firm's exposure to each, and the program response is now a baseline expectation, not a nice-to-have.
5. Anchor your AI governance program on something that does not depend on which bloc tightens next. ISO 42001, OSFI E-23 model validation discipline, internal audit independence. The substance of governance does not change as regimes shift. The framework of evidence each regime expects does. A program anchored on substance translates into each new framework; a program built reactively to whichever regulator moved last does not.
The Bottom Line
The three-bloc world is no longer a forecast. As of June 2, 2026, it is operating. Canadian regulated enterprises sit at the intersection: supplied by US vendors, selling into EU customers, occasionally serving Chinese markets, governed at home by an OSFI that does not directly mandate any specific AI instrument.
That intersection is uncomfortable, but it is also a competitive position. A Canadian firm with a defensible OSFI-aligned program is closer to satisfying each bloc's requirements than a US firm under fresh federal pressure or an EU firm scrambling to map prEN 18286. The work is mapping, not rebuilding.
The firms that produce a clear three-bloc exposure map this quarter, brief their boards on it, and update their vendor due diligence to match will be the ones that operate confidently when the next regime tightens. The firms that wait will not.
See also:
- Trust, but Verify: AI Assurance and Certification Are Becoming the Proof Regulators Ask For
- prEN 18286: The European Harmonized Standard That Will Define EU AI Act Compliance
- The Six Accountability Layers Every Enterprise AI Agent Needs
Aeon AI Risk Management helps Canadian regulated enterprises build AI governance programs that map to OSFI, EU, US, and other regulatory regimes simultaneously. Contact us at info@airiskmanagement.ca or visit /contact.