Skip to content
../services/ai

AI MODULE 06

AI governance

Your employees already use AI. The question is under which rules.

We put in place the framework that is missing: what may go through an AI tool and what may not, who is allowed to do what, how decisions are traced, and what you answer a client who asks whether their file was handled by a machine. All aligned with Quebec’s Law 25 and with what insurers and large clients are starting to demand.

Who it is for

  • Leadership discovering that half the staff paste data into ChatGPT
  • Organisations subject to privacy law that must document their processing
  • Companies whose client or insurer is asking for a written AI policy
  • Teams accumulating AI tools with no idea which ones are approved

What you live with today

  • Nobody knows what data has already been copied into a consumer tool
  • Each department picked its own tool, with no IT or legal input
  • You have nothing to show when a client asks how AI is governed
  • Your internal policies predate generative AI entirely

What it gets you

Written

Defensible framework

A policy your employees understand and that you can show a client, an auditor or an insurer.

Inventoried

Real usage

The list of what is actually running in the company, including tools installed without going through IT.

Law 25

Alignment

Processing register, impact assessments and disclosure notices written for the Quebec context.

What is included

  • An inventory of the AI tools genuinely in use, department by department
  • Classification of your data: what may leave, what never leaves
  • An acceptable-use policy written in plain language, not legal jargon
  • The processing register and impact assessments required by Law 25
  • An approval procedure before any new tool is adopted
  • A training session per department and reminder posters of the rules

How it runs

01

A no-blame stocktake

2 weeks

We record what is used today. The goal is to get the truth, so the exercise is explicitly non-punitive.

02

Data classification

2 weeks

We establish with you what is public, internal, confidential or personal under Law 25, and what each category allows.

03

Writing the framework

2 to 3 weeks

Policy, register, approval procedure and disclosure notices. Short, readable documents — not a binder nobody will open.

04

Rollout and training

3 to 4 weeks

Team-by-team presentation, answers to concrete cases and setting up the periodic review of the framework.

Indicative timelines for an SMB. A multi-site group or a regulated sector requires more consultation time.

The questions you are asking

Should we simply ban ChatGPT?

Outright bans rarely work: they push usage into the shadows, where you can no longer see it. We prefer defining what is permitted with which data, and offering an internal alternative for sensitive cases.

Are we really covered by Law 25?

If you do business in Quebec and hold personal information — clients, employees, suppliers — then yes, whatever your size. The transparency obligations around automated decisions target AI usage directly.

We have no legal department. Is that a problem?

No. We produce documents that are usable as they are, and flag the points worth validating with a lawyer. We do not give legal advice, and we say so plainly when a question calls for it.

How long does this framework stay valid?

The substance holds for years, but the list of approved tools moves fast. We plan for at least an annual review, and more often if you adopt new tools.

Governing AI now costs less than repairing it later.

We start with an honest stocktake of what is already in use, then write the framework that goes with it.

The other AI modules