A woman reviews documents beside an AI chat screen in a municipal council chamber.
Wellington North, a township in Ontario's County of Wellington, has approved a policy on how staff use AI, and it names Microsoft Copilot as the approved platform. The policy is a useful small case study for IT administrators. A municipality had to decide which AI tool its employees may use, which tools they may not use, and what happens to the output.

A woman reviews documents beside an AI chat screen in a municipal council chamber. What council approved​

EloraFergusToday reports that council approved the policy at a Monday afternoon meeting, which was October 5, 2026. A staff report from CAO Brooke Lambert describes it as a "practical approach." The report names Microsoft Copilot as the approved AI platform.

Lambert told council the policy starts from caution. In her words, the tool "does not replace the staff or human review." She also said the township sees AI as a valuable tool for efficiency and communications.

I haven't seen the policy text. The township's council meetings page points visitors to meeting videos and doesn't show the document. Everything below is the policy as described in the local report, not as checked against the adopted document.

What staff may do​

Staff may use Copilot, or township platforms that incorporate AI, for these tasks:

  • Drafting reports, policies and correspondence.
  • Summarizing documents and meeting materials.
  • Creating outlines.
  • Research assistance.

All information has to be independently verified. Anything produced with AI must be reviewed and edited before it is published, distributed or presented as township information.

What staff may not do​

According to the report, the policy bars AI from:

  • Making decisions on the township's behalf.
  • Replacing professional judgment.
  • Making approvals.
  • Making hiring, promotion or termination decisions.
  • Creating or modifying records in a misleading or deceptive way.

Lambert said responsibility for accuracy stays with staff. This is an assistive-use model. The AI drafts and the human is accountable for the result.

The public-tools boundary​

The policy also lets staff use publicly available generative AI tools, such as ChatGPT, for approved work tasks. The condition is that the information entered is already public.

That sets up two tiers:

  • Sanctioned platform: Copilot, the tool the township chose and presumably controls.
  • Public tools: allowed only for information that is already public.

The report doesn't say how the township defines "publicly available." It also doesn't say how staff should treat material that is sensitive but technically accessible. Those are open questions in the news account. They aren't confirmed gaps in the policy itself.

Why Copilot's edition matters​

The report doesn't say which Copilot product or licence the township means, so it would be wrong to assume particular protections. Microsoft's documentation shows the edition matters. Microsoft says that under enterprise data protection, prompts and responses aren't used to train foundation models. Its support page adds that prompts and responses in Copilot Chat are logged, and IT admins can view that logged information with Microsoft's search and audit tools.

Those protections apply to work accounts. Microsoft's FAQ says prompts and responses under enterprise data protection are logged, retained and available for audit, eDiscovery and Microsoft Purview capabilities, with specific controls varying by subscription plan. The consumer, unsigned-in version is different. One partner write-up (Bridgeall) describes it as having no enterprise data protections, with data possibly used to improve Microsoft's AI models. That is a third-party characterization, not Microsoft's wording. It still points to the practical gap between signing in with an organizational account and using the free public tool.

Microsoft also treats web searches differently. Its support page says the Bing search service operates separately from Microsoft 365 and has different data-handling practices. A policy that tells staff to verify everything fits with that.

How neighbouring municipalities compare​

The story says Wellington North is the only township in the county to approve a publicly accessible AI policy so far. Treat that as the outlet's characterization, not an independent count of every municipal document. Neighbours are at different stages:

MunicipalityStatus as reported
Centre WellingtonNo formal policy and not working on one
Guelph/EramosaDraft guidelines; clerk Amanda Knight says they are still being fine-tuned
Town of ErinNo formal policy; relies on public-sector and risk-management frameworks

Erin clerk Justin Grainger named two frameworks: UNESCO's AI and Digital Transformation Competencies for Civil Servants, and the Enhancing Digital Security and Trust Act. He described a use-case-driven, risk-managed approach. It involves evaluating proposed uses, assessing vendor and platform safeguards, and keeping staff aware and overseen.

These descriptions don't show that any municipality lacks other technology, privacy or records rules. They also don't show that Wellington North's policy is more thorough. They show only that it has an approved AI-specific policy that is publicly accessible.

What IT teams can take from this​

This is my analysis, not something from the report. The policy has four parts that any organization writing AI rules could use:

  1. Name an approved tool. That gives staff a clear answer and gives IT something to configure, license and audit.
  2. Set a data boundary for other tools. The public-information rule covers staff who reach for a familiar chatbot.
  3. Require human review before anything goes out. Hallucinated or wrong text then becomes a staff accountability issue.
  4. List decisions AI can't make. Hiring, approvals and termination are named explicitly.

The report doesn't mention several things administrators would want to know:

  • Copilot licensing.
  • Tenant configuration.
  • Sensitivity labels.
  • Logging and retention.
  • Training.
  • Rules on disclosing AI assistance.

Whether staff follow the policy will depend on how those are handled. Naming a platform doesn't enforce anything, and the policy can't be judged on those points without its text.

Bottom line​

Wellington North has put human accountability, a Microsoft-based approved tool and limits on public AI services into a written policy. It is a modest but concrete example of a small government choosing Copilot for staff use. The next thing to look for is the policy document, which would show how it is configured and enforced.

 

References

  1. Wellington North first to approve AI policy in the county EloraFergusToday.com 2026-10-08T13:30:00+00:00
  2. Data Security in Microsoft Copilot bridgeall.com
  3. Data protection when using Microsoft Copilot Chat for work or school support.microsoft.com