Business IT projects · Across Québec Request a quoteFrançais

AI governance and oversight

AI governance is the set of rules, roles and controls that frame how a business uses artificial intelligence: which tools are allowed, for which tasks, with which data and under what oversight.

Updated on

For an SMB, an AI governance project can start with a simple question: which AI tools are our employees already using? It then leads to an AI usage policy, a risk assessment and measures to meet Law 25 when AI processes personal information.

Short answer

You describe your AI governance need once: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote. The scope of the mandate is set with you based on your tools, your data and your obligations.

What a mandate can cover

  • An inventory of the AI tools used in the business, including AI features built into software you already have
  • An AI usage policy: allowed tools, permitted uses, content that may be generated and oversight processes
  • A risk assessment: sensitive data entered in prompts, inaccurate or biased outputs, more convincing phishing
  • A privacy impact assessment (PIA) when an AI project involves personal information
  • Staff guidelines and training on using generative AI tools
  • A review of AI vendors and contracts: data origin, security practices, retention of prompts
  • Ongoing monitoring: periodic review of the policy and the inventory as tools change

Frequently asked questions

Do we need a policy for ChatGPT at work?

We recommend one as soon as your employees use generative AI tools. The Canadian Centre for Cyber Security says your organization should establish a plan that identifies policies on how AI should be used and the content that is allowed to be generated, and advises avoiding providing personally identifiable information or sensitive corporate data as part of queries or prompts. A short policy can set out the allowed tools, the data never to enter, review of outputs before use and who to ask when in doubt.

AI and Law 25: which obligations apply?

Québec's Act respecting the protection of personal information in the private sector, as amended by Law 25, applies to personal information a business collects, holds, uses or communicates, whatever the medium (s. 1). Three sections are especially worth reviewing in an AI project: section 12.1 on decisions based exclusively on automated processing, section 8.1 on technology that allows a person to be identified, located or profiled, and section 3.3 on privacy impact assessments.

What does section 12.1 say about automated decisions?

A business that uses personal information to render a decision based exclusively on automated processing must inform the person concerned no later than when it informs the person of the decision. At the person's request, it must also disclose the personal information used, the reasons and the principal factors and parameters that led to the decision, and the person's right to have that information corrected. The person must be given the opportunity to submit observations to a staff member who is in a position to review the decision (s. 12.1).

Is a privacy impact assessment needed for an AI project?

Section 3.3 requires a privacy impact assessment for any project to acquire, develop or overhaul an information system or electronic service delivery system involving the collection, use, communication, keeping or destruction of personal information. An AI tool that fits this description is covered. The person in charge of the protection of personal information must be consulted from the outset, and the assessment is proportionate to the sensitivity of the information, its purposes, its quantity and distribution, and its medium.

What risks does generative AI pose for an SMB?

The Canadian Centre for Cyber Security lists, among others, misinformation, more targeted phishing, the privacy of data entered in prompts, malicious or buggy code, poisoned datasets, biased content and loss of intellectual property. It also notes that outputs can be incorrect, might not make sense, might not take certain factors into account and can be biased.

What should we ask an AI tool vendor?

The Canadian Centre for Cyber Security suggests asking whether the datasets were acquired externally or developed internally and how they were validated, ensuring the vendor has robust security practices in data collection, storage and transfer, and determining whether the tool lets users delete their prompt history. If the vendor handles personal information for you, section 18.3 requires a written mandate or contract that specifies the protection measures, and section 17 requires a privacy impact assessment before entrusting that information to an organization outside Québec.

Specific services

AI governance

Usage policy, tool inventory and Law 25

Request a quote