Do we have an AI policy? Show the receipts
Municipal AI governance fails under pressure. Got AI Policy is a Canadian, evidence-first registry built so organizations can show their work.
TL;DR
- The hard question isn't 'do we have principles?' โ it's 'can you show the policy, the source, and the review date?'
- Most Canadian municipalities have fragments: press releases, dead links, vendor clauses โ rarely a reviewable trail.
- Got AI Policy is a public, source-first registry of municipal AI governance artifacts: policy, status, review date, evidence link.
- AI assists (summaries, comparisons, candidate documents) but the source link is always the authority. AI drafts, humans decide.
- 'Procurement-grade' means defensible under council, privacy, FOIP, and journalist scrutiny โ not flashy.
At some point, the question lands. It might come from council. From a CAO. From procurement, privacy, legal, or communications. Sometimes from a journalist on a tight deadline. Sometimes from a resident after an AI or privacy incident, when the story is already moving faster than the facts.
The question is simple: do we have an AI policy? And if the answer is yes โ where is it, and what is in it?
That is where many organizations discover the real problem. Not a lack of principles. Not a lack of frameworks. Not a lack of discussion. A lack of retraceable evidence.
Someone starts searching inboxes. Someone opens an old SharePoint folder. Someone vaguely remembers a draft. Someone references a vendor clause that never became operational policy. The evidence exists in fragments, if it exists at all.
That gap is what led us to build Got AI Policy โ a Canadian, evidence-first registry of municipal AI governance artifacts designed to answer one increasingly important question: can your organization show its AI governance work?
The problem is not theory. It is pressure.
Municipal AI governance rarely fails in workshops or strategy sessions. It fails under pressure.
- A vendor proposes an AI-enabled feature and wants a fast answer.
- Council asks whether staff are using AI tools internally.
- A resident files a FOIP request.
- A privacy concern surfaces.
- A journalist asks whether governance exists before publishing a story.
That is when governance becomes real โ not when principles are written, but when evidence is needed. And when you go looking across Canada, you find a familiar pattern: press releases, dead links, generic statements, vendor marketing, references to 'ongoing work.' What you rarely find is a consistent, reviewable trail another person can inspect and verify.
"Governance is not a vibe. It is an audit trail you can stand behind."
What Got AI Policy actually is
Got AI Policy is a public, evidence-first registry of AI governance artifacts across Canadian municipalities and related public-serving organizations. The goal is simple: help organizations move from 'we think we have something' to 'here is the source, the status, the review date, and the evidence.'
The platform records public AI policies, directives, council references, governance artifacts, review status, source links, and evidence trails โ all built around one design constraint: receipts over rhetoric. If a municipality is listed as having a policy, there should be evidence another person can review themselves.
Why we built this
This project grew out of years of practical AI governance work through CivicPlay.ai alongside municipalities, nonprofits, recreation organizations, and community-serving teams across Canada. Again and again, the same operational problem appeared: teams were not trying to invent governance from scratch. They were trying to move quickly, reduce risk, benchmark peers, answer leadership questions, support procurement decisions, document responsible use, and survive scrutiny.
But the evidence was scattered. And when the timeline becomes urgent, scattered evidence becomes organizational risk. That is the gap this platform is designed to reduce.
What it is โ and what it is not
It is
- A public registry of Canadian municipal AI governance evidence.
- A practical workflow for policy discovery, verification, monitoring, and comparison.
- A way to benchmark peer organizations using Canadian precedents.
- A system designed around traceable source links and reviewable evidence.
- A shared reference point for municipalities, consultants, procurement teams, and governance practitioners.
It is not
- Legal, procurement, or privacy advice.
- A replacement for internal review or human judgment.
- A 'magic AI policy generator.'
- A guarantee of compliance or organizational readiness.
The source links are the authority. Everything else should be treated as supporting interpretation.
Why this matters now
AI adoption inside municipalities is already happening โ often quietly. Staff are experimenting with tools for drafting communications, summarizing documents, generating reports, brainstorming policies, supporting procurement workflows, and analyzing information faster.
The issue is not whether AI is being used. The issue is whether organizations have governance, oversight, documentation, review processes, and clear accountability. Public trust does not disappear gradually. It disappears quickly when organizations cannot explain their decisions.
The thesis
Most organizations do not need to invent AI governance from zero. They need examples, comparables, reviewable evidence, operational workflows, and defensible starting points. Most practitioners innovate by remixing, not by starting from scratch โ that is how governance work actually moves forward under real constraints.
Registry + AI + Community
A shared Canadian evidence base where municipalities can learn from one another, compare governance approaches, identify gaps, improve policies faster, and reduce duplicated effort. No municipality should have to rebuild governance from zero every time the question resurfaces.
What you can do on the platform
- Search municipalities and inspect source links.
- Compare jurisdictions and benchmark peers.
- Review policy documents and track governance status.
- Export findings and monitor changes over time.
Each municipality is assigned a public-facing status based on available evidence: has policy (published), in progress, no policy found, or unknown / not yet reviewed. Importantly, 'no policy found' does not mean no internal work exists โ it means no sufficiently verifiable public evidence was identified at the time of review.
Why 'source-first' matters
AI summaries can help. Comparisons can help. Structured reviews can help. But the source link remains the authority. That is intentional, because governance systems become dangerous when commentary becomes mistaken for evidence.
"AI drafts. Humans decide."
What 'procurement-grade' actually means
Procurement-grade does not mean flashy. It means defensible. When questions become sharp, organizations need source links, statuses, review dates, traceable evidence, and documented reasoning. That is what survives council scrutiny, procurement review, privacy concerns, public controversy, and access-to-information requests. Good intentions are not enough. Organizations need to be able to show their work.
Building this in public
Governance work attracts scrutiny quickly โ procurement, legal, privacy, methodology questions. But building publicly became part of the point. Trust at scale is built through repeated, inspectable touchpoints, not polished announcements. So the platform includes methodology documentation, governance disclosures, AI-use disclosures, changelogs, verification workflows, and correction mechanisms. Trust should be inspectable too.
Anya and transparent AI use
On the platform, 'Anya' is the name used for certain AI-assisted features and updates. The name comes from the Igbo word connected to seeing or observation, reflecting both our Nigerian-Canadian background and the role the system plays in surfacing governance evidence.
Anya is not a replacement for human review. AI is used to surface candidate documents, summarize public artifacts, identify patterns, and support structured comparisons โ but outputs remain AI-assisted, reviewable, potentially imperfect, and secondary to source evidence. The registry remains source-first by design.
Who this is for
Got AI Policy is built for people inside organizations trying to do responsible work under real-world constraints: municipal staff, procurement teams, privacy professionals, legal reviewers, governance leads, consultants, auditors, and association leaders. Especially the people being asked difficult questions with limited time and limited leverage. The real prize is not innovation theatre. It is being able to answer difficult questions with calm confidence.
The larger goal
The next phase of AI governance will not be decided by who makes the boldest promises. It will be decided by who can show evidence, explain decisions, maintain trust, survive scrutiny, and document responsible practice. That is what this project is trying to support. Not hype. Not fear. Operational trust.
Receipts over rhetoric.
Frequently asked questions
Who actually needs an AI policy?
Any organization where staff, contractors, or vendors are using AI tools that touch client data, public communications, financial decisions, or hiring. In practice, that is almost every community-serving organization in mid-2026 โ the question is not whether to have a policy, but how minimal a first version you can defensibly publish.
What is the smallest useful AI policy?
A one-page acceptable-use note: what tools are approved, what categories of data cannot be entered into them, who to ask when unsure, and who is accountable. That is enough to start; you iterate from there once staff hit real edge cases.
Do we need to start from a blank page?
No โ that is the whole point of the registry. Browse /tracker for organizations similar to yours, open Policy Profiles at /grade to see what coverage blocks they addressed, and adapt what fits. Copying wording verbatim is fine; the underlying accountability is yours to own.
Who inside our organization should sign off on it?
Whoever signs off on your privacy, procurement, or acceptable-use policies today. In most municipalities that is Council or a CAO; in nonprofits it is the Executive Director with board awareness. AI does not create a new accountability structure โ it plugs into the one you already have.
How long does it take to draft one?
A short acceptable-use policy can be drafted in an afternoon using peer templates. A full framework with governance, procurement, risk classification, and human-oversight sections typically takes 6โ12 weeks including internal consultation. Policy Studio and Starter are built to compress the drafting side of that timeline.