Skip to main content

Beyond the Chaos: Practical Application of AI Governance

IAPP Cross-Canada KnowledgeNet Event

On January 28, 2026, privacy professionals in 10 cities across Canada came together to explore the topic of AI governance. The session was intended to foster conversation with a view to helping organizations consider how best to reap the benefits of AI without compounding the risks.

Participants heard from Privacy Commissioners in Newfoundland and Labrador and British Columbia, along with a panel of experts who conveyed the importance and practical realities of AI governance today. Attendees in each city then probed into specific aspects of AI governance to further uncover the challenges and best practices for organizations to follow. This report serves as a summary of the conversations from the day.

Key takeaways
 
  • Enable adoption with pragmatic foundations: AI governance should drive responsible innovation, leveraging existing privacy, data, and risk programs as a starting point.
  • Maturing but uneven landscape: Many organizations are at varying stages of AI governance maturity, requiring clearer accountability, executive oversight, and cross-functional alignment.
  • Operationalize governance end-to-end: Success depends on continuous, risk-focused assessments and monitoring, supported by strong intake mechanisms, cross-team collaboration, inventories, training, and consideration of global regulatory and data constraints.

 

AI governance is no longer a theoretical exercise. As organizations explore and deploy AI, the question is not whether governance is needed, but how to make it practical, proportionate, and sustainable.

At the IAPP Cross-Canada KnowledgeNet event, participants discussed the need to move beyond uncertainty and take concrete steps. Many organizations are still determining where to begin, but a common message emerged: start somewhere, learn from the process, and adapt as technology, regulation, and organizational needs evolve.

Poll results from over one hundred respondents reinforced this reality. Many organizations reported being in the early or foundational stages of AI governance. Respondents also identified regulation, ethics, trust, and privacy concerns as key barriers to responsible AI adoption. These findings point to a clear need for governance models that are not only compliant, but also usable and trusted.

The report identifies six pillars of effective AI governance:

  1. Determine an AI governance framework
    Organizations should adopt a risk-based, principle-driven framework that fits their size, maturity, industry, and AI use cases. Existing resources such as NIST, ISO, government guidance, and emerging international models can help shape a defensible approach.
  2. Establish roles and responsibilities
    AI governance depends on clear ownership. Privacy, legal, compliance, technology, business, and executive stakeholders all have a role to play. Responsibilities should be documented, communicated, and reviewed regularly.
  3. Implement the right assessment tools and processes
    Governance should include practical tools such as AI inventories, intake forms, privacy impact assessments, algorithmic impact assessments, security reviews, vendor assessments, and human-in-the-loop controls.
  4. Align AI governance with existing privacy programs
    Privacy programs already provide valuable foundations, including accountability, transparency, data minimization, consent, access, appeal rights, and risk assessment practices. AI governance should build on these structures rather than operate separately.
  5. Invest in change management, training, and education
    Responsible AI adoption requires a common language, clear guidance, and tailored training. Employees need to understand not only how AI can be used, but also the risks, escalation paths, and responsibilities attached to that use.
  6. Use metrics and monitoring to track performance
    Metrics should go beyond adoption and financial value. Effective monitoring includes risk, compliance, ethical outcomes, incident tracking, vendor oversight, and regular reporting to leadership.

The discussions also highlighted broader considerations, including data sovereignty, cross-border data flows, vendor power imbalances, transparency, and international regulatory alignment. These issues reinforce the need for flexible governance programs that can evolve over time.

AI governance does not need to begin with a perfect program. It begins with practical steps: understand how AI is being used, assign accountability, build on existing privacy and risk practices, assess impacts, educate employees, and monitor outcomes.

Download the full report in English to explore the event insights, poll results, and practical guidance for building AI governance that supports innovation while protecting trust.

Did you find this useful?

Thanks for your feedback