AI & Automation

AI Governance & Policy

One page, actually read.

AI governance is the small set of decisions that determine how an organization uses AI: which tools are approved, what information may be entered into them, who owns the rules, which uses need a person to check the output, and where the data is processed. happier IT writes and implements this for Canadian organizations of roughly 15 to 200 people, usually as one page rather than a programme.

Who it's for

AI adoption in a small business happens in an afternoon.

Somebody creates an account, pastes in a document, and it becomes part of how they work. No approval, no malice, no visibility.

Staff are already using tools nobody approved. Free accounts on personal logins, work documents pasted in. This is the normal state of things in an organization that has not published a list, and it is not a discipline problem.

A client contract now asks what you do with their data. Whether client information is entered into AI systems, and where those systems process it. The question is appearing in supplier questionnaires and it needs an answer you can stand behind.

You want to say yes, safely. Blocking every AI site rarely works and mostly moves the activity onto phones. Approving one good tool that is genuinely good enough removes the reason to go elsewhere.

Someone asked whether AI is regulated in Canada. It is a fair question with a clearer answer than most people expect, and it is below.

What Canadian law actually says

There is no comprehensive federal AI statute in force. The Artificial Intelligence and Data Act, part of Bill C-27, died when Parliament was prorogued on 5 January 2025.

What applies is everything that already applied: federal and provincial privacy law, your contracts, sector regulators, and human rights and consumer protection law. AI did not create an exemption from any of it.

What's included

The seven decisions, and the documents that record them.

This is deliberately short. A twelve-page policy nobody reads governs nothing, and staff have to be able to use it while working.

  • An approved-tool list

    Which AI services staff may use for work, evaluated individually rather than as a category: administrative controls, identity and access management, data-handling terms, retention options. Plus a rule that a new tool receiving company or customer information needs approval first.

  • Concrete data rules, with examples

    "Do not enter sensitive information" governs nothing. Real categories with real examples from your business: what may go in, what must never, and where the line sits for client names, pricing, contracts, payroll and health information.

  • A named owner

    One person or a small group responsible for keeping the list current, reviewing new requests, and knowing when to bring in privacy, legal or HR advice. Without an owner, an AI policy becomes a document nobody maintains within a quarter.

  • Access managed like any other system

    Company-managed accounts rather than personal ones, multi-factor authentication, a second check, usually a prompt on a phone, before a login is accepted, least privilege, and removal when somebody changes role or leaves. See <a href="/cybersecurity/identity-access-management/">identity and access management</a>.

  • Approved use cases, not just approved tools

    Approving a product does not approve every use of it. A short list of low-risk workflows staff can start with today, and a defined set of higher-impact uses, employment decisions, automated customer commitments, sensitive personal information, that need a conversation first.

  • Where human review is required

    Which output must be checked by a person before it is sent, published, entered into a system, or used to make a decision. Canada’s privacy commissioners are explicit that accountability for decisions rests with the organization, not with an automated system.

  • A data residency answer per tool

    Data residency means where your information is stored and processed. It differs per product and per tier and it is not a general property of "the cloud", so we answer it tool by tool, in writing, including where the honest answer is that processing may happen outside Canada.

  • Model governance in plain terms

    Which model version a tool uses, who may change it, what happens when a vendor deprecates one, and how you would know if outputs changed. For anything you have built, that means a recorded evaluation and a re-test after every model change, see <a href="/ai/custom-development/">custom AI development</a>.

How it works

Find out what is already happening, then write it down.

Starting from what staff already do produces a policy people follow. Starting from a template produces one they route around.

  1. Find the shadow AI

    Which services are already in use, on which accounts, with what data. Not to discipline anyone, to understand what people actually needed. It is the most honest requirements document you will get, and it usually points straight at the tool worth approving.

  2. Make the seven decisions

    One workshop with the people who can actually decide: approved tools, data categories, owner, access rules, approved uses, review requirements, and the residency position. An afternoon, not a project.

  3. Publish it, brief people, review it

    One page circulated, a short session per team about what it means for their actual tasks, and a scheduled review because tools change. A policy written once and never revisited stops matching reality within about six months.

What it costs

A short fixed-price engagement, then it is yours.

This is not a subscription. It is a piece of work with a document at the end, and a review date.

The technical controls, company-managed accounts, multi-factor authentication, sensitivity labels in Microsoft Purview, and data loss prevention rules that can block specific content from leaving, sit inside managed IT

Where an obligation is genuinely legal, a regulated sector, a contract with a specific data-location clause, an employment decision, you need a lawyer, not an IT provider. We will say so and stay in the room to answer the technical half.

What a policy cannot do

It cannot stop a determined person pasting a contract into a personal account on their phone. Nothing can.

What reduces that to almost nothing is giving people an approved tool that is genuinely good enough for the job. Policy handles the edges. A decent approved tool handles the middle.

Why us for this

The Canadian picture, stated accurately.

Canada has no comprehensive federal AI statute in force. AIDA died with Bill C-27 at prorogation on 5 January 2025. What exists instead is a set of clear expectations. Canada’s federal, provincial and territorial privacy commissioners published joint principles for responsible, trustworthy and privacy-protective generative AI on 7 December 2023, covering legal authority and consent, appropriate purposes, necessity and proportionality, openness, accountability, individual access, limiting collection and use, accuracy, and safeguards.

Those expectations have teeth. In findings published on 6 May 2026, the federal privacy commissioner together with the Quebec, British Columbia and Alberta authorities concluded that OpenAI’s collection of personal information from publicly accessible websites to train its models was overbroad and inappropriate under Canadian privacy law. The practical lesson for a Canadian business is that "it was publicly available" is not a defence, and neither is "everyone uses it".

On residency specifically, the honest position is per tool. Microsoft states that Copilot is covered by its Advanced Data Residency and Multi-Geo offerings, and also that customers outside the EU may have queries processed in the US, EU or other regions. For anything built on Azure AI Foundry, Regional deployments keep inference inside a chosen geography, Data Zone deployments are confined to the US or EU, and Global deployments may process anywhere. Whether happier IT hosts anything in a Canadian data centre for you: Vancouver and Quebec.

Go deeper

Questions

What people ask before they sign anything.

Do we need an AI policy?

Yes, and one page is enough. It needs to say which tools are approved, what information must never be entered into any of them, who approves a new tool, which uses need a person to check the output, and that the human sending the work is accountable for it. Writing it takes an afternoon once the decisions are made. The reason to do it now rather than later is that once several teams have adopted different tools, getting visibility back is much harder than setting the rule was.

Is there a law in Canada about business use of AI?

No comprehensive federal AI statute is in force. The Artificial Intelligence and Data Act, part of Bill C-27, died when Parliament was prorogued on 5 January 2025. What applies is everything that already applied: federal privacy law, provincial private-sector privacy legislation in Alberta, British Columbia and Quebec, sector regulators, your own contracts, and human rights and consumer protection law. Canada’s privacy commissioners have also published joint principles for generative AI, which set out what regulators expect even without AI-specific legislation.

Is it safe for staff to use ChatGPT at work?

It depends on the account tier and what is being entered, which is why the answer has to be per tool rather than per category. Consumer and business tiers differ materially in retention, administrative control and whether content can be used to improve a vendor’s models, a business-tier product is not automatically safe either, and each configuration still has to be evaluated. The realistic risk is a well-meaning person pasting a client contract into a free personal account. The fix is approving a managed account that is good enough, then writing down what may go into it.

Where is our data processed when we use AI tools?

It varies by product, tier and deployment choice, and it should be answered in writing per tool. Microsoft states that Microsoft 365 Copilot is covered by its Advanced Data Residency and Multi-Geo offerings, while also stating that customers outside the EU may have queries processed in the US, EU or other regions. For anything built on Azure AI Foundry, a Regional deployment keeps inference inside your chosen geography, a Data Zone deployment is confined to the US or EU, and a Global deployment may process anywhere. If you have a contract promising data stays in Canada, that difference is the whole conversation.

How do we stop staff pasting client information into AI tools?

Mostly by giving them an approved tool that is good enough, which removes the reason to go elsewhere. Beyond that: a one-page policy with real examples rather than "do not enter sensitive information", company-managed accounts instead of personal ones, and technical controls where the data genuinely warrants them, sensitivity labels and data loss prevention rules can block specific content from leaving. Blocking every AI website rarely works and usually moves the activity onto personal phones, where you can see none of it.

What is shadow AI?

Shadow AI is staff using AI tools the organization has not approved or does not know about, usually free accounts on personal logins. It is the AI-shaped version of shadow IT and it is not a discipline problem, it happens because the tools are useful and nobody published a list. It matters because company information ends up somewhere with terms nobody has read, and because when the person leaves, so does the visibility of what they put there.

Who is responsible if an AI tool gets something wrong?

Your organization. Canada’s privacy commissioners put it plainly in their joint principles: accountability for decisions rests with the organization, not with any automated system. Practically, that means deciding in advance which outputs a person must check before they are sent to a customer, entered into a system, published, or used to make a decision. Automation removes work. It does not remove responsibility for the underlying business process.

What is model governance?

Model governance is knowing which model version each of your AI tools uses, who may change it, and how you would notice if the outputs changed. It matters because vendors update and retire models on their own schedule, and an answer that was reliable last quarter can quietly shift. For anything custom-built, it means keeping a recorded evaluation set and re-scoring it after every model change, see custom AI development. For bought products it mostly means reading the release notes and knowing who is responsible for doing so.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.