Skip to main content

AI governance

Independent · we do not remediate what we assess

Three questions. Most organisations get sold one answer.

Almost everything written about AI risk answers all three at once, usually in a brochure. Separating them is the first useful thing anyone can do for you, because an organisation that knows which question it is asking can buy the right thing — and can tell when it is being sold the wrong one.

  1. How do we use AI safely? Rolling out Copilot, Gemini or Claude without exposing what should not be exposed. This is a permissions, classification and retention problem, and it is mostly not an AI problem at all.
  2. How do we defend against attackers using AI? A synthetic voice on a payment call, phishing that no longer reads like phishing. This is a verification problem, and the answers are older and duller than the threat.
  3. How do we stop our own AI being turned against us? Assistants and agents that read untrusted content and then act on it. This is an architecture and least-privilege problem, and it is the least settled of the three.

One: using AI safely

The first incident in a Copilot rollout is almost never an attack. Somebody asks what the salary bands are, and gets a correct answer from a file they were never meant to read but were always technically entitled to.

Copilot does not break your permissions. It respects them perfectly, and that is the problem. Years of “Everyone except external users” links, broken inheritance, ownerless sites and files shared once and forgotten have been safe largely because nobody could find them. An assistant that honours those same permissions makes every one of them findable in plain English, by anyone who already had access.

The work, therefore, happens before you switch it on, and almost none of it is AI work. It is permissions, ownership, labelling and retention — the housekeeping that was already overdue and never had a deadline attached to it. Microsoft publishes the method itself; the gap is not information, it is a structured way through it.

Free

Before you switch on Copilot

Twelve questions on whether the groundwork is done. Five minutes, nothing leaves your browser, no form at the end.

  • Permissions, ownership, labelling, retention and the agent questions nobody has asked yet.
  • You get the gaps back in the order we would fix them, not a score out of ten.
  • Honest about its own limits: it cannot see your tenant, and it says so.

Free

Take the readiness check

No email address · nothing recorded

AI use and oversight runbook

The operating module: who may use what, on which data, with which approvals, and what happens when it goes wrong.

  • Written for an owner or operations lead, not a data scientist.
  • English and French Canadian, PDF and Word.
  • Part of the three-module set if you want the incident and operations runbooks too.

CAD $165

Buy the AI oversight runbook — $165

Secure checkout by Stripe · emailed within one working day

If the readiness check comes back uncomfortable, the AI rollout governance pack is the structured version of the same thing — thirty-two controls in four phases, an AI system and agent register, decision gates, and the Quebec Law 25 assessment. CAD $595.

Two: defending against attackers using AI

Here is the unpopular version, which we think is the true one. AI has not changed what actually costs Canadian businesses money. It is still payment fraud and it is still ransomware. What AI changed is the cost of a convincing pretext — the phishing email that finally reads properly, the voice on the telephone that is unmistakably the finance director asking you to change a supplier’s bank details.

The defences are correspondingly unglamorous, and they pre-date all of this: verification by callback on a number you already hold rather than one in the email, out-of-band approval for payment changes, identity proofing at the helpdesk before anyone resets anything, and phishing-resistant multi-factor authentication. Very few people sell that, because there is no product in it. There is, however, a document in it, and an exercise.

Free

The ransomware tabletop

Ninety minutes, a printed deck, no system touched. The complete exercise, published in full.

  • Eight timed injects, six role cards, six complications for when the room is finding it too easy.
  • Produces a one-page evidence record — the thing an insurer or auditor is actually asking for.
  • Three more scenarios, including an AI tool leaking a client list, are available as a paid pack.

Free

The tabletop exercises

Published in full · nothing held back

The insurance application companion

Where this gets expensive is not the attack. It is discovering at claim time that an answer on the form was wrong.

  • Fifteen questions every Canadian cyber-insurance application asks, and the trap in each.
  • A workbook that records the evidence behind every answer — which is what protects you.
  • We are not brokers and take no commission from any insurer.

CAD $95

Read about the companion

Guide and workbook · PDF and Excel

Three: your own AI being turned against you

This is the newest of the three and the least settled, by us and by everybody. Plenty of organisations have decided who may use AI. Almost none have decided who may publish an agent — something that acts rather than answers, holds standing access to data, and takes steps on its own.

The questions are ordinary governance ones wearing unfamiliar clothes. Whose identity does it act under. What may it reach. Who owns it. What happens when the person who built it leaves. How is it switched off. An agent with no owner and no leaver process is the shared administrator account again, and it will end the same way.

The single most useful rule we have found

An agent acting without human approval should have at most two of these three things.

Access to private data. Exposure to untrusted content. The ability to communicate externally. Any two are manageable. All three is where the incidents come from — because an agent that can read your files, be influenced by something written by an outsider, and then send a message, can be instructed by that outsider to do so. This is not our rule; it originates with Meta and reaches us through OWASP’s work on agentic security, which finds prompt injection running through most agentic failures. We repeat it because it fits on one page and a non-technical owner can apply it.

The AI rollout governance pack covers the agent questions at governance level — the register, the publishing decision and the leaver process. A deeper pack on agent lifecycle and design review is in preparation. If that would be useful now rather than later, tell us: what you say you need shapes what we build next, and we would rather hear it before writing than after.

What actually governs AI in Canada

There is no Canadian AI Act. AIDA died with Bill C-27, and a great deal of published guidance — including guidance you may have been sent by a supplier — still implies otherwise. What binds you is PIPEDA’s purpose limitation, Quebec’s Law 25 automated-decision regime, the Treasury Board Directive if you sell to government, and your own contracts, which are the instrument most likely to catch you first.

Two bills were tabled in June 2026 and neither is law yet. One of them catches AI chatbots, carries penalties of up to 5% of global revenue, and has a scope threshold that has not been set — which means nobody can honestly tell a small organisation it is exempt.

We have set all of this out in full, free, with every claim linked to its primary source, in what actually governs AI in Canada. The first document most organisations are missing is an AI acceptable use policy, and ours is free to take and adapt.

Three things we will not do

These are commitments rather than marketing, and you are entitled to hold us to them.

  1. We will not remediate what we assess. We will not write your gap analysis and then clean up your SharePoint permissions. That work belongs to you or your IT provider, and it is the reason our assessment of it is worth anything.
  2. We will not quote a threat statistic we cannot trace to a primary source. Search for evidence on AI-enabled fraud and you will find enormous numbers repeated across dozens of sites, citing each other, several published by firms selling detection tools. We cite the Canadian Anti-Fraud Centre and the FBI’s complaint centre, or we say we do not know.
  3. We will tell you when a supplier describes an obligation that does not exist. Including when doing so costs us the sale. There is no Canadian AI Act, most AI “compliance” offers imply there is, and somebody should be saying so out loud.
Dr Jane Mayhew

Practical tip

Dr Jane Mayhew

Before deploying an AI tool, write the sentence you would say to the person it makes a decision about. If you cannot write that sentence, you are not ready to deploy it.

International data protection law · the people who do the work

Start with the free things

Everything on this page that costs nothing is complete — not a sample, not a teaser, and not behind an email address. The readiness check will tell you in five minutes whether your organisation is ready for the tool it has probably already bought. If the answer is uncomfortable, that is the useful outcome.

Take the readiness checkTell us what you need

Current at 29 August 2026. Legislative status and product features in this area change quickly; every page here carries a date, and we would rather you checked the primary sources than trusted us. English, with French Canadian available on enquiry.

Standards we assess against

ISO/IEC 27001:2022 · ISO/IEC 27701:2025 · ISO 9001:2015 · ISO/IEC 42001:2023 · ISO/IEC 23894:2023 (guidance) · ISO/IEC 42005:2025 (guidance)

Français : La première heure — rédigé en français, pas une traduction automatique.

Canada Cyber-Safe is an independent assessment practice. We are not a certification body and we do not issue certificates.