The AI questions in this market are operational rather than consumer facing: predictive maintenance, load and price forecasting, geospatial and sensor models, field safety, and increasingly agentic automation reaching into systems that were never designed to be driven by software making its own decisions.
Alberta’s Personal Information Protection Act was deemed substantially similar to Part 1 of PIPEDA in 2004, and it applies instead of PIPEDA to private-sector activity occurring within the province. It has not been substantially revised since 2010, and the province ran a public consultation on modernising it between 2 February and 1 May 2026, so this is a floor that is expected to move rather than one to design against permanently.
The more distinctive governance pressure here is not privacy law. It is that a wrong automated decision in this sector has a physical consequence and a regulator’s name attached to it. A model that misjudges a pressure reading, a maintenance interval, or a shutdown threshold does not produce a customer complaint. It produces an incident, an investigation, and a question about what the system was permitted to decide on its own.
That inverts the usual governance argument. Consumer-facing AI is governed mostly because a regulator requires disclosure. Industrial AI has to be governed because the blast radius is measured in equipment and people, and the institution will be asked to show what bounded the machine long before anyone asks whether a privacy notice was adequate.
The Five-Gate Deployment Model for what an operational system must clear before it runs unattended, trust tiers and the PARA operating model for agents that touch running systems, the AI Incident Response Protocol, and the enterprise architecture depth a legacy-heavy operator actually needs first. Twenty-five years of TOGAF and DMBOK practice, multi-cloud estates, and a two hundred database modernisation programme sit behind that, because in this market the governance question is usually blocked by an integration question.
Calgary is one of my three working stations, so on-site time here does not carry a travel premium.
I am an independent consultant and architect, not a firm with branch offices. You work with me directly rather than with a bench of juniors, engagements are delivered remotely by default, and on-site time is used where it earns its cost. Nothing here is legal advice; it is architecture and governance work that your counsel should review.
Alberta’s Personal Information Protection Act applies instead of PIPEDA for private-sector activity occurring within the province, on the basis that it was deemed substantially similar to Part 1 of PIPEDA in 2004. PIPEDA still governs personal information crossing provincial or national borders in the course of commercial activity, so most operators of any scale are dealing with both.
It is under active review. The province ran a public consultation on potential legislative updates between 2 February and 1 May 2026, and the Act has not undergone major revision since 2010. I would not architect a governance programme that depends on the current text staying fixed.
Not a dedicated one. Governance obligations for industrial AI in Alberta come from privacy law, sector safety and reliability regulation, contractual and operator duties, and the general expectation that an operator can explain what its systems were permitted to do. The absence of a named AI act is not the absence of exposure.
Yes, and usually with a shorter fuse. Consumer AI failures produce complaints; operational AI failures produce incidents with physical consequences and a regulator already entitled to ask questions. The governance case here rests on blast radius rather than on disclosure rules.
That is normally the first half of the engagement. Governance you cannot enforce inside the systems is documentation, so the practical work often starts with what the current substrate can actually attest to, not with a policy document.
The first conversation is a free thirty-minute fit call that qualifies the work in both directions. If it does not fit, you leave with a clearer read on where your governance stands and no cost. If you would rather start on your own, the Readiness Self-Assessment is twelve questions and the result is not gated behind a form.