Skip to main content
12 min read

From Policy to Practice: Canada's Shared AI Governance Infrastructure

Got AI Policy is building source-first, human-accountable AI governance infrastructure that helps Canadian community-serving organizations discover, review, build, practise, monitor, and improve.

From Policy to Practice: Canada's Shared AI Governance Infrastructure

TL;DR

  • AI governance is not a document you finish and file โ€” it is a continuous cycle: Discover โ†’ Review โ†’ Build โ†’ Practise โ†’ Monitor โ†’ Improve.
  • The Got AI Policy public registry stays the source-first foundation. Studio connects review, drafting, and Trust Drills; Workspace holds organizations, roles, and shared context.
  • CivicPlay.ai is the human advisory layer that helps organizations implement what the platform makes visible โ€” technology never replaces accountable people.
  • Private uploads stay scoped to the organization. Aggregate insights are de-identified, purpose-limited, and suppressed below five participating organizations.
  • Governance Watch is deliberately deferred until pilots show which change signals actually alter what teams should do next.

For many organizations, the first response to artificial intelligence has been to ask a simple question: Do we need an AI policy? The answer is usually yes. But the question is too small.

A policy can establish expectations. It can define acceptable uses, identify restricted information, assign accountability, and make clear that humans remain responsible for consequential decisions. Those things matter. But a policy cannot tell us whether an employee will recognize a convincing deepfake voice call, pause before pasting private information into an unapproved chatbot, challenge an AI-generated answer that sounds certain but is wrong, or know what to do when a vendor makes an attractive claim that nobody in the room is equipped to evaluate.

The real challenge is not simply writing an AI policy. It is building the organizational capacity to govern AI as technologies, risks, public expectations, and staff practices continue to change. That requires more than a document. It requires a cycle.

The cycle in six words

Discover โ†’ Review โ†’ Build โ†’ Practise โ†’ Monitor โ†’ Improve.

No organization should have to start from zero

Got AI Policy began with a practical frustration. Canadian organizations were being told to develop AI policies, but many had no reliable way to see what comparable organizations had already published. Teams repeated the same research, searched through scattered websites, worked from generic templates, or delayed action because the blank page felt too large. Smaller municipalities, nonprofits, recreation organizations, libraries, community agencies, and associations faced the same questions as larger institutions, but rarely had the same legal, privacy, cybersecurity, procurement, and policy capacity.

We believed there was a better starting point: make existing public evidence easier to find, compare, and verify. That is why Got AI Policy was built as a source-first Canadian registry. The aim was not to tell every organization to copy the same policy. It was to help people learn from what already existed, examine different approaches, and return to the original sources before making decisions.

"The risk is too great for Canadian community-serving organizations to write an AI policy from zero."

But as the registry grew, something became increasingly clear. Discovering a policy is only the first step. Even a well-written policy can fail if it is never translated into tools, decisions, training, reporting, and repeated practice.

The gap between policy and practice

Most governance failures do not begin with someone intentionally ignoring a policy. They begin in ordinary moments. A staff member is under pressure and chooses the fastest tool available. A supervisor receives an AI-generated summary and assumes the source was checked. A front-desk employee answers a caller who sounds exactly like a senior leader. A team begins using a free AI product without realizing that information entered into it may leave the organization's approved environment. A vendor presents an automated system as more accurate, efficient, or objective than it really is.

These are not abstract technical risks. They are human judgment problems occurring inside real workloads. A policy may say that sensitive information should not be entered into unapproved systems. That is useful. But will staff recognize sensitive information when it appears inside a long client document? Will they remember the rule when a deadline is ten minutes away? Will they know which approved alternative to use? Will they report the near miss, or quietly close the browser and hope nobody noticed?

Governance becomes real only when written commitments shape everyday behaviour. This is why we are expanding Got AI Policy from a directory of evidence into shared AI governance infrastructure for organizations that serve communities. Infrastructure does not mean one giant piece of software that replaces human judgment. It means a connected set of public evidence, structured tools, organizational controls, practical exercises, and human support that helps teams move through the full governance cycle.

The AI governance lifecycle

1. Discover what already exists

Responsible governance should begin with evidence, not invention. The Discover stage helps organizations find policies, frameworks, guidance, regulatory developments, benchmarks, and examples from comparable institutions. Public records should remain linked to their original sources so users can verify the context, date, jurisdiction, and wording for themselves.

This is the role of the public Got AI Policy registry, national and provincial snapshots, policy comparisons, sector resources, and the public MCP server. The website should not be the only way people can access this evidence. Verified governance information should also be available inside the tools where practitioners already work, including AI assistants, knowledge systems, and partner platforms.

  • What have other Canadian organizations published?
  • Which governance topics appear consistently across policies?
  • What approaches differ by organization type or jurisdiction?
  • What is public evidence, and what is expert recommendation?
  • Which source should we verify before relying on a claim?

The goal is not to produce a single national template that every organization adopts unchanged. The goal is to reduce duplicated effort and give teams a defensible starting point.

2. Review what you already have

Many organizations are not starting from nothing. They may have a draft, an acceptable-use guideline, a privacy policy that partially covers AI, a procurement checklist, or informal rules spread across several documents. The Review stage helps teams understand what is present, what is unclear, and what is missing.

A structured policy review can examine areas such as accountability, human oversight, privacy, information security, transparency, procurement, approved tools, incident response, staff training, monitoring, and review responsibilities. It should distinguish between descriptive evidence about what other organizations have done and normative guidance about what a specific organization should consider. Canadian practice evidence can show patterns, precedents, and gaps. It does not automatically create a binding requirement. Legal, regulatory, and sector conclusions still require appropriate human expertise.

A useful review should not end with a grade that publicly labels an organization as good or bad. Public shaming produces defensive behaviour and discourages participation. The more useful output is a clear set of findings, priorities, suggested wording, evidence links, and next actions. The better questions are: what risk does this gap create, who owns the response, and what should we do next?

3. Build what your organization needs

Policies should be adapted to organizational reality, not generated from a blank prompt and accepted because the language sounds professional. The Build stage will help organizations develop practical drafts using approved clauses, reviewed templates, control mappings, public evidence, and answers about their actual operations. The organization's size, services, legal environment, data, staff roles, technology stack, procurement practices, and risk exposure all matter.

This is the principle behind the Policy Builder being developed within Got AI Policy Studio: adapt, do not invent. AI can support the assembly and drafting process, but it should not silently invent the governance framework for each request. Structured questions, source-linked patterns, versioned controls, and human review create a more defensible process than asking a general chatbot to write us an AI policy.

AI drafts. Humans decide.

The final result must still belong to the organization. Named people must approve it. Staff must understand it. Leaders must be willing to enforce it. The policy must connect to procurement, privacy, security, training, incident response, and operational procedures.

4. Practise before trust is tested

This is the stage that traditional policy projects often miss. A fire drill does not exist because an organization expects staff to memorize the fire code. It exists because people need to recognize a situation, make decisions under pressure, and build a response reflex before a real emergency. AI governance requires the same kind of practice.

Trust Drills are short, realistic simulations designed around the pressure moments community-serving staff increasingly face. A caller may use a cloned voice. A chatbot may confidently provide incorrect program information. An employee may be seconds away from placing a client document into an unapproved tool. A vendor pitch may combine legitimate benefits with claims that require deeper scrutiny. Some scenarios involve scams. Some do not. That uncertainty is part of the exercise.

The purpose is not to trick or embarrass staff. It is to help people pause, ask better questions, find the correct escalation path, and understand how written policy applies to real work. Over time, team sessions and privacy-conscious reporting can help organizations identify recurring gaps between policy commitments and staff decisions. That information can guide better training, clearer wording, improved procedures, and more targeted future drills.

"Trust has to be practised before it is tested."

5. Monitor what changes

AI governance cannot be treated as a one-time launch project. Tools change. Vendors change their terms and capabilities. Governments publish new guidance. Regulators clarify expectations. Policies are amended. New incidents reveal weaknesses that were not obvious when the original document was approved. Staff adopt new workflows faster than a committee can schedule its next annual review.

The Monitor stage is intended to help organizations stay informed about developments that could affect what they understand, review, build, or practise. This is the planned role of Governance Watch: change detection, source verification, document comparisons, effective-date tracking, and control-level impact mapping. It is deliberately deferred until early pilots demonstrate repeated demand and show which changes actually affect organizational decisions. When it is built, the purpose will not be another overwhelming news feed. An update is useful only when it changes what an organization should understand, review, build, practise, or do.

  • Has a relevant policy or source changed?
  • Does the change affect one of our existing controls?
  • Is there a new risk that staff should practise?
  • Does a vendor update require a new review?
  • Should our policy, approved-tool list, or incident process be revised?

Human editorial review remains important. Automated monitoring can identify possible changes, but people must determine relevance, authority, and the appropriate response.

6. Improve through evidence and experience

The final stage returns the organization to the beginning of the cycle, but with better information. Policy reviews reveal structural gaps. Builder decisions reveal where organizations need clearer ownership. Trust Drills reveal where staff struggle under pressure. Monitoring reveals new external developments. Incidents and near misses reveal where formal expectations do not match operational reality.

Improvement means turning those signals into action. That may involve revising a clause, naming a decision-maker, changing an approved tool, improving onboarding, creating a new drill, adjusting a vendor review, or scheduling a deeper governance assessment. The aim is not constant policy rewriting. It is maintaining a governance system that learns.

Over time, privacy-safe and properly consented aggregate evidence may also help sectors understand common policy-to-practice gaps. An association could learn which controls its members find hardest to implement, and a sector could identify recurring training needs. But aggregate reporting must remain de-identified, purpose-limited, and protected against re-identification. Our current partner rule is to suppress aggregate cells below five participating organizations. Uploaded policy text, free-text drill responses, staff-level results, organization rankings, and invisible secondary uses are outside that model.

One ecosystem, different ways to use it

Public intelligence

The public layer includes the source-linked policy registry, comparisons, benchmarks, guides, public reports, regulatory analysis, and MCP access. It helps users discover evidence without requiring every visitor to create an account or enter a private workspace. Public evidence should remain broadly accessible. Got AI Policy's public MCP server is therefore designed to remain free and read-only.

Got AI Policy Studio

Studio is the authenticated work layer being consolidated inside Got AI Policy. It is where Policy Review, Policy Builder, Trust Drills, reports, and future monitoring can connect over time. Some elements are available now and others remain staged behind product, privacy, and security gates. We will describe a capability as available only when it is active in the current release and has passed the relevant acceptance criteria.

Studio is where evidence becomes action. The intended journey moves from a policy finding to suggested next steps, from a drafting decision to a relevant simulation, and from a drill result to an improvement recommendation without treating each feature as an unrelated product. The tools are delivery mechanisms. The product is the governance cycle.

Workspace

Workspace is the organizational layer. It manages members, roles, permissions, shared policies, reports, branding, facilitator access, partner relationships, and data boundaries. Studio contains the work. Workspace contains the organization, people, permissions, and shared context. A personal workspace can help an individual begin without unnecessary setup. Organizational workspaces support collaboration and continuity when multiple people are responsible for governance.

The visibility model is intentionally narrow. An organization can access its own workspace information. An authorized consultant can access only the information explicitly delegated by that organization. An association or sector partner receives privacy-safe aggregate programme information โ€” not private member documents, free-text responses, or organization-level rankings.

CivicPlay.ai

Technology can support governance, but it cannot replace implementation leadership. CivicPlay.ai provides the human advisory and delivery layer: governance consulting, policy implementation, training, workshops, facilitated simulations, assessments, and custom support for organizations and sector partners.

"Got AI Policy provides shared governance intelligence and tools. CivicPlay.ai helps organizations implement them."

This allows the platform to serve people who want to work independently while providing a clear path for organizations that need deeper facilitation, expert review, or programme design.

Source-first, human-accountable governance

As Got AI Policy expands, the methods matter as much as the features.

  • Public evidence and expert guidance must remain distinct. A source can show what an organization published โ€” not that the policy is complete or appropriate for every other organization.
  • AI should support judgment, not conceal it. AI-assisted summaries, reviews, and drafts should be traceable to structured methods, versioned governance controls, and evidence. Consequential conclusions require human review.
  • Private information should remain scoped to the organization and authorized users. Uploads, drafts, free-text responses, and staff-level results should not quietly become public benchmarks or model-training material.
  • Aggregate learning requires consent and safeguards. Cross-organization insights should be de-identified, thresholded, purpose-limited, and protected against re-identification.
  • Security and privacy are launch gates. Production pilots involving private uploads, paid entitlements, partner reporting, or external access must meet defined acceptance criteria โ€” including adversarial tests for prompt injection inside uploaded documents.
  • Governance must remain usable. A technically perfect framework that staff cannot understand or apply will fail when it matters.

Built in Canada, designed around principles that travel

Got AI Policy is Canadian at its core. The registry begins with Canadian public evidence. The platform is being shaped around the realities of Canadian municipalities, nonprofits, recreation and facility organizations, community agencies, libraries, associations, and other institutions that serve the public. That focus is deliberate. Governance advice becomes vague when it attempts to serve every jurisdiction, sector, and legal system at once.

At the same time, many underlying controls travel. Human accountability, privacy, transparency, security, procurement discipline, incident response, staff competence, and meaningful oversight are not uniquely Canadian concerns. The responsible approach is not to dilute the Canadian core. It is to add clearly scoped jurisdictional evidence where needed and state the limits of what the platform can conclude.

"Built from Canadian public evidence, designed around governance principles that travel."

What this means for community-serving organizations

For a small or mid-sized organization, AI governance can feel like a choice between doing too little and launching a project it cannot sustain. The lifecycle offers a more practical path. Begin by discovering what comparable organizations have already published. Review the policies, procedures, and informal rules you already have. Build only what your context requires. Practise the moments where people are most likely to make mistakes. Monitor the changes that genuinely affect your work. Improve based on evidence rather than fear or hype.

Not every organization needs a large AI office. Every organization does need clarity about who is accountable, what tools are approved, what information is protected, how AI-assisted work is checked, how incidents are reported, and how staff are prepared. The purpose of shared infrastructure is to make that work more achievable without pretending it can be fully automated.

From a registry to a governance system

Got AI Policy started by making Canadian AI policies easier to find. That work remains essential. It creates the public evidence base that everything else depends on. But the need is larger now. Organizations do not only need examples. They need a way to understand their gaps, develop practical rules, prepare their people, respond to changes, and learn over time. Associations and sector partners need ways to support members without seeing private organizational information or turning governance into a competition. Practitioners need trusted evidence that can travel into the tools and workflows they already use.

That is the system we are building. Not a policy generator that produces impressive language and disappears. Not a public ranking that rewards appearances. Not an AI system that replaces accountable human decisions. A shared governance ecosystem that helps organizations move from policy to practice.

Discover what exists. Review what you have. Build what you need. Practise before trust is tested. Monitor what changes. Improve what comes next. The technology will keep moving quickly. Community trust will move more slowly. Our responsibility is to build the governance infrastructure that respects both.

Try it end-to-end on Starter

Everything you need to walk the cycle โ€” Discover, Review, Build, Practise โ€” is available on Free and Starter. Starter unlocks the export formats, higher quotas, and collaboration when you're ready. Open /studio and see what fits.

Resources and further reading

Frequently asked questions

Do we need to pay to use Got AI Policy?

No. The registry, Policy Profiles, comparisons, and the /grade lookup are free and require no account. Starter ($19/mo or $190/yr CAD, 14-day free trial) unlocks more private Policy Reviews, larger exports, and higher Studio quotas. Pooled team seats live in Pro.

Who is this actually for?

Municipal staff, community-serving nonprofits, libraries, recreation and cultural organizations, associations, and the practitioners who advise them. If you are being asked 'what is our AI policy?' and do not have a legal, privacy, or IT team the size of a large city, this is built for you.

What happens to information we upload into Studio or a private review?

Private uploads stay scoped to your account and โ€” if you use Workspace โ€” your organization. Aggregate insights we publish are de-identified, purpose-limited, and suppressed below five participating organizations. Public registry entries only ever come from documents an organization already published itself.

How is CivicPlay.ai different from Got AI Policy?

Got AI Policy is the platform โ€” registry, Studio, Trust Drills, Workspace. CivicPlay.ai is the human advisory layer that helps organizations facilitate readiness workshops, run tabletop exercises, and translate what the platform surfaces into decisions. You can use the platform without CivicPlay; you cannot use CivicPlay without accountable people inside your organization.

Where should we start if we have never done AI governance work?

Start at Discover. Visit gotaipolicy.ca to find peer organizations in your sector or region, open their Policy Profile at /grade, and read one full breakdown. That single hour usually reframes the internal conversation more than a week of blank-page drafting.

About this post

This post was drafted by Anya, the Got AI Policy AI research assistant, and reviewed by the Got AI Policy team in mid-2026. You can learn more about how Anya works at /author/anya.