On January 28, 2026, privacy professionals in 10 cities across Canada came together to explore the topic of AI governance. The session was intended to foster conversation with a view to helping organizations consider how best to reap the benefits of AI without compounding the risks.
Participants heard from Privacy Commissioners in Newfoundland and Labrador and British Columbia, along with a panel of experts who conveyed the importance and practical realities of AI governance today. Attendees in each city then probed into specific aspects of AI governance to further uncover the challenges and best practices for organizations to follow. This report serves as a summary of the conversations from the day.
AI governance is no longer a theoretical exercise. As organizations explore and deploy AI, the question is not whether governance is needed, but how to make it practical, proportionate, and sustainable.
At the IAPP Cross-Canada KnowledgeNet event, participants discussed the need to move beyond uncertainty and take concrete steps. Many organizations are still determining where to begin, but a common message emerged: start somewhere, learn from the process, and adapt as technology, regulation, and organizational needs evolve.
Poll results from over one hundred respondents reinforced this reality. Many organizations reported being in the early or foundational stages of AI governance. Respondents also identified regulation, ethics, trust, and privacy concerns as key barriers to responsible AI adoption. These findings point to a clear need for governance models that are not only compliant, but also usable and trusted.
The report identifies six pillars of effective AI governance:
The discussions also highlighted broader considerations, including data sovereignty, cross-border data flows, vendor power imbalances, transparency, and international regulatory alignment. These issues reinforce the need for flexible governance programs that can evolve over time.