387 Canadian organizations have published an AI policy. Here's what they say.
The Got AI Policy registry now covers schools, libraries, newsrooms, non-profits and regulators — with source links, plain-language descriptions, and the controls they actually name.

TL;DR
- The organizations registry is live: 387 published AI governance artifacts from Canadian organizations outside city hall, every one linked to its public source document.
- 203 are formal policies and 184 are operational guidance — the practical direction staff actually follow.
- Education dominates (209 records), followed by libraries and cultural institutions (37) and media (28).
- Ontario leads with 127 records, then national bodies (66), British Columbia (61), Alberta (55) and Quebec (42).
- The most-named controls are disclosure, privacy, human review and an approval path — a de facto Canadian baseline.
- 351 records carry a human-reviewed description today; the rest stay listed with their source link while review finishes.
For two years the question Canadian organizations asked us was some version of the same thing: has anyone like us written this down yet? Not a template from another country, not a vendor's whitepaper — an actual published document from an actual Canadian organization of roughly their size, doing roughly their work.
As of mid-2026, there is a place to answer that. The organizations registry at /organizations covers 387 published AI governance artifacts from Canadian organizations outside municipal government: school boards and post-secondary institutions, libraries and cultural institutions, newsrooms, non-profits and associations, health and professional regulators, agencies and research bodies. Every record links to the public source document, because the source is always the authority and we are not.
What is actually in it
The split between formal policy and operational guidance is close to even: 203 formal policies against 184 operational guidance documents. That balance matters more than it looks. A formal policy is an approved governing document — board-adopted, versioned, usually written in the language of accountability. Operational guidance is what staff read on a Tuesday: newsroom standards, classroom rules, a section of the staff handbook, a one-page 'how we use AI here' note.
Neither is automatically stronger. We have seen ten-page approved policies that no one can act on and one-page newsroom standards that answer every question a reporter will realistically face. The registry lists both and lets you judge.
Sectors
- Education — 209 records. Universities, colleges and school boards moved first and moved hardest, mostly because assessment integrity forced the conversation in 2023 and never let it go.
- Libraries and cultural institutions — 37 records. Small teams, disproportionately thoughtful documents, usually anchored in patron privacy and intellectual freedom.
- Media and communications — 28 records. Short, specific, unusually readable: disclosure to the audience is almost always the first clause.
- Non-profits and associations — 21 records, and the fastest-growing group in the last two quarters.
- Health and professional regulation — 21 records, typically the most conservative on data handling.
- The remaining 71 records span business and professional services, public agencies and research, infrastructure and transport, public safety and justice, and finance and insurance.
Open any sector in the registry
Each link opens /organizations filtered to that sector, so you can read the actual documents side by side.
Geography
Ontario accounts for 127 records, followed by national bodies at 66, British Columbia at 61, Alberta at 55 and Quebec at 42. Atlantic Canada, the Prairies and the territories are visibly thinner. Read that as a coverage gap in what has been found and published, not as proof that governance is absent — a missing record has never meant a missing policy.
One distinction is worth holding onto when you read those numbers. A province filter shows organizations based and operating in that province. “National” is a separate group — bodies whose mandate spans the whole country — so it is not the sum of the provinces, and the two views answer different questions. Pair a province view with the same province's municipal picture on /provinces-territories to see the full jurisdictional stack, or start from /registry for all three lenses at once.
Open the registry by region
Province links show organizations based there; National shows Canada-wide bodies.
The de facto Canadian baseline
The interesting finding is not the count. It is how consistently these documents converge on the same handful of commitments, written by organizations that mostly did not read each other's work.
- Disclosure — say when AI was involved in something the public reads, sees or receives. Named in more than half of all records.
- Privacy and data handling — do not put personal, confidential or student information into a public tool.
- Human review — a person is accountable for anything that goes out the door, and 'the model wrote it' is not a defence.
- An approval path — someone specific decides which tools are permitted, and that someone is named.
Those four are the closest thing Canada has to a consensus baseline right now. They emerged from practice, not from legislation. If your draft policy does not answer all four clearly, you are behind the median of your own sector — and if it answers only those four, you are exactly at it.
What is mostly missing
Three gaps show up again and again. Very few documents say anything about procurement — how a new AI-enabled vendor product gets assessed before it is bought. Fewer still set a review date, which quietly turns a 2024 policy into a 2026 liability. And almost none address agentic systems: tools that take actions, book things, or spend money rather than draft text. That last gap is the one closing fastest in the real world and slowest on paper.
How the records are built
Each record starts from a public source document. A description is drafted from that document, then reviewed by a human before it becomes visible; 351 of 387 records carry a reviewed description today. The other 36 stay listed with their source link while adjudication finishes — usually because the source was hard to access, the document turned out to be an AI strategy rather than a use policy, or the scope was genuinely ambiguous. We would rather show you a link with no summary than a summary we have not checked.
Descriptions summarise what a document covers and which controls it names. They are never a score and never an opinion about whether the policy is good. The full approach is on /methodology.
How to actually use this
- Find three comparable organizations — same sector, similar size, ideally your province — and read their source documents end to end before you write a word.
- Note which of the four baseline controls each one covers and how specifically. Specificity, not length, is what makes a policy usable.
- Draft against that evidence in the Policy Builder at /studio rather than from a blank page or a generic template.
- If you already have a draft or an adopted policy, run it through /policy-review to see which controls are present, weak or absent — then push the gaps straight into the Builder.
- Book the review date now. The single most common failure in this registry is a good document that stopped being true.
Your organization is not listed?
Submit your policy from /organizations and it will be reviewed against the same standard as everything else here. Absence from the registry is a gap in what we have found, not a judgement about your governance.
Resources
- Organizations registry — https://gotaipolicy.ca/organizations
- Municipal registry — https://gotaipolicy.ca/municipalities
- How records are built and reviewed — https://gotaipolicy.ca/methodology
- Government of Canada, Guide on the use of generative AI — https://www.canada.ca/en/government-canada/services/digital-government/digital-government-innovations/responsible-use-ai/guide-use-generative-ai.html
- Office of the Privacy Commissioner of Canada, Principles for responsible generative AI — https://www.priv.gc.ca/en/privacy-topics/technology/artificial-intelligence/gd_principles_ai/
- NIST AI Risk Management Framework — https://www.nist.gov/itl/ai-risk-management-framework
- ISO/IEC 42001, AI management systems — https://www.iso.org/standard/81230.html
Frequently asked questions
Does inclusion mean a policy is good?
No. Inclusion means an organization published something public about how it governs AI, and we could link to it. The registry describes; it does not grade. If you want an assessment of a specific document, that is what /policy-review does.
Why are municipalities in a separate registry?
Municipal records carry jurisdiction-specific context — population bands, provincial legislation, comparable-city benchmarking — that does not translate to a library or a newsroom. They live at /municipalities and keep their own detail pages.
How often is the registry updated?
Continuously, in reviewed batches. New submissions and newly found documents are adjudicated before publication, and records are re-checked when a source URL changes or an organization tells us the document has been superseded.
We have no policy yet. Where do we start?
Read three comparable records here, then draft in the Policy Builder at /studio. Starting from real Canadian peer evidence takes most organizations from blank page to reviewable draft in an afternoon rather than a quarter.
About this post
This post was drafted by Anya, the Got AI Policy research assistant, from the registry data described above, and reviewed by a human before publication. Anya's role, limits and review process are documented at /author/anya. Numbers reflect the registry as of mid-2026 and will drift as records are added.