Colleagues work with an AI assistant and review documents in a Quebec office.
Granby, a city of Quebec's Eastern Townships, is already using AI for some administrative work. It says it has access to Microsoft Copilot, and it is writing a formal AI policy with a research consortium. Many IT teams are in the same position: the licences are in place, the tools are switched on, and the rulebook is still being drafted. Granby's account is a small but useful case study in that gap.

Colleagues work with an AI assistant and review documents in a Quebec office. What Granby says it is doing​

The reporting comes from The Pulse, which put written questions to the city. According to that outlet, Granby is already using AI for some administrative work and has access to Microsoft Copilot while it works with the university-led consortium IVADO on a formal AI policy. The city described the IVADO partnership as a way to explore and introduce AI in a controlled manner, through specialized legal advice, training and strategic guidance.

Some terms of the arrangement, again as reported from the city's answers:

  • The city says the collaboration agreement carries no professional fees or other charges payable to IVADO.
  • Granby contributes resources in kind, including staff time and participation in producing project reports.
  • The city says the work could eventually yield knowledge or tools useful to other municipalities. That is subject to rules on confidentiality, personal information and intellectual property.

These terms come from the city's own statements to The Pulse. I found no separate Granby or IVADO announcement confirming them.

The tools: Copilot and Decisions​

Granby says it has Copilot access through its existing Microsoft licences, and that it also uses a product called Decisions to prepare meeting summaries.

The reporting leaves several details open:

  • It does not say which Copilot product or licence tier the city has.
  • It does not say who has access or how the tool is configured.
  • It does not say whether Copilot is approved for particular classes of information.

I won't guess at any of these. The reporting also records no incident or security problem.

For context, Microsoft's documentation says that for Microsoft 365 Copilot, prompts, responses and data accessed through Microsoft Graph aren't used to train foundation LLMs. The same documentation says Microsoft offers third-party models such as Anthropic and OpenAI models in Copilot, and admins can decide whether to use them. That is a general product statement, not a description of Granby's tenant. Settings like these are what a municipal AI policy normally has to pin down.

Low-risk uses first​

For now, the city says it is looking at relatively low-risk uses, such as summaries, first drafts, meeting summaries and reducing some repetitive administrative tasks. Possible uses that touch services delivered directly to residents have not yet been determined.

The city's stated rule is that the tools support employees' work and their results must be verified before use. Each project is to be assessed before launch by its purpose, the data involved and the risks.

Safeguards: people, training and rules​

Granby describes these measures:

  • An AI committee. It coordinates assessments, recommends controls and monitors risks, working with the official responsible for protecting personal information.
  • Training. Employees have received internal instructions and an information session on personal information and AI risks.
  • A data rule. Internal rules bar employees from entering personal, confidential or sensitive information into generative-AI tools.
  • Accuracy warnings. Staff are cautioned about wrong answers, bias and hallucinations.
  • Accountability. The city says the employee remains responsible for the content they use. Anything AI-produced must be checked before use or communication.
  • Technical controls, still to come. The city says further controls are being prepared to better prevent unauthorized information from reaching AI tools.

This last item matters most to administrators. A "don't paste sensitive data" rule depends on people following it. Technical controls, such as data-loss-prevention policies, sensitivity labels and restrictions on which AI services staff can reach, are what make the rule enforceable. That is my general industry observation, not something Granby said. The city gave no detail on what its controls will be, when they will arrive, or whether they are live today.

The Quebec privacy-law angle​

Granby cited section 63.5 of Quebec's access-to-information law. It said privacy impact assessments, known in Quebec as évaluations des facteurs relatifs à la vie privée (EFVP), will be completed where required.

The Government of Quebec's guidance shows the trigger is narrower than "any AI use." Under section 63.5, the assessment is required for a project to acquire, develop or overhaul an information system or electronic service involving personal information. Video surveillance or biometrics projects are also covered. (This guidance is in French, and the rendering is mine.)

Other points from Quebec's guidance:

  • The duty is limited to those project types. It excludes system updates, though applying the requirements is recommended when an update significantly affects privacy.
  • The assessment must begin at the start of the project and be kept current as it evolves.
  • Its depth must be proportionate to the sensitivity, purpose, quantity, distribution and format of the information.
  • The public body must consult its access-to-information and privacy committee from the outset.

Separate provisions require EFVPs in other situations. These include certain collaborative collections of personal information, certain disclosures without consent, and certain processing or communication outside Quebec.

Practically, this means a staff member using a chatbot to polish a non-sensitive memo is probably not a formal EFVP event. A project that builds or buys a system handling residents' data, such as a citizen-facing chatbot, is the kind of thing the law targets. Granby's plan to assess every proposed use is a stricter governance habit than the statute demands. I'm not a lawyer, and the final classification of any given project is for the city and its privacy officer.

Who IVADO is, and what it has published for cities​

IVADO's own site describes it as an interdisciplinary consortium for AI research, training and knowledge mobilization. The Pulse adds that it is led by the Université de Montréal. I could not confirm that last point independently.

IVADO has also published guidance aimed at municipalities. In October 2025 it launched, with Nord Ouvert, a bilingual guide for municipalities. The stated recommendations include:

  • picking projects that benefit the community;
  • adopting transparent governance with accountability and public registers;
  • involving residents in design and evaluation;
  • anticipating risks around bias, data security and environmental impact.

That guide is a useful yardstick for any city's policy. The reporting does not say Granby is using it, planning public consultations or publishing an AI register, so none of that should be assumed.

Other policies in the region​

According to The Pulse's earlier coverage, Bromont adopted a policy on responsible AI use covering privacy, cybersecurity, approved uses and human oversight. The Pulse also reported that AI cannot by itself make decisions with legal, administrative, financial, disciplinary or rights-related consequences. It further reported that the Eastern Townships School Board is developing an AI framework built on four principles. These are People First, Enhance Don't Replace, Use AI Responsibly, and Learn and Grow Together. I haven't verified either independently.

What IT admins can take from this​

Granby's approach follows a pattern that is becoming common for public bodies:

  1. Start with low-risk, internal drafting and summarizing.
  2. Put a human-verification rule in front of everything.
  3. Ban sensitive data from generative tools.
  4. Form a cross-functional committee that includes privacy.
  5. Assess each project before launch.
  6. Add technical enforcement, ideally alongside the policy rather than after it.

The open question is step six. Granby says the controls are coming, and the policy is still unfinished while Copilot is already available. Until the final policy appears, it is unclear how closely the tool's configuration matches what employees are told. Useful follow-ups would be the finished policy, an approved-tool list, and how the sensitive-data ban is enforced technically.

The takeaway is modest but practical. A municipality with standard Microsoft licensing is treating AI as a governance project, with law, training and oversight, rather than just another feature that arrived in the productivity suite.

 

References

  1. Granby develops AI safeguards with IVADO as city uses AI tools The Pulse of the Eastern Townships 2026-10-09T16:35:15+00:00
  2. Évaluation des facteurs relatifs à la vie privée | Gouvernement du Québec quebec.ca
  3. Protection de la vie privée lors d’un projet d’acquisition, de développement ou de refonte d’un système d’information ou d’une prestation électronique de services | Gouvernement du Québec quebec.ca