That gap is the story. The County has put in place a governance model that requires human review, risk assessment, an AI-system registry, procurement-stage consultation, and senior executive approval. Its public update, however, describes outcomes at a high level rather than giving residents or other municipalities enough detail to assess whether a particular AI deployment is appropriately constrained.
For Windows and Microsoft 365 administrators, the County’s approach is a useful reminder that “we use Copilot” is not a deployment plan. A defensible AI rollout needs a precise inventory of products, identities, connectors, data permissions, user groups, permitted tasks, review requirements, and measurable results. Prince Edward County appears to have built much of the approval machinery. The September workshop and promised implementation-and-evaluation framework will determine whether that machinery produces evidence rather than simply policy paperwork.
The County has moved from policy writing to operational inventory
Prince Edward County adopted its Municipal Artificial Intelligence Use Policy in 2025 and later created an AI Governance Committee to oversee AI across departments. The committee’s published terms of reference require it to maintain an inventory of current and proposed AI systems, assess new deployments for privacy, fairness, transparency, security and legal risks, and assign risk tiers that guide approval.
Those requirements make the County’s reported software audit significant. According to The Picton Gazette, staff reviewed AI-enabled applications across municipal operations and determined that the tools in use comply with the new policy. The list reportedly includes Microsoft Copilot, Adobe products, and software supporting planning, scheduling, website management, data analysis, security, report editing, and summarization.
The distinction County staff made is important: software may contain AI functions without employees actively using them. That is an easy fact for organizations to lose when conducting an audit. Microsoft 365 tenants, Adobe subscriptions, web platforms, customer-service systems, endpoint security products, and line-of-business applications increasingly enable AI features through defaults, add-ons, or vendor-side upgrades. An inventory based only on purchase orders or named “AI projects” will miss those embedded capabilities.
Prince Edward County’s policy structure recognizes this by treating AI as something that must be reviewed at procurement and project-scoping stages, rather than solely after an employee starts using a chatbot. Its governance committee is also supposed to document the purpose, risk level, and relevant compliance rules for each registered system. For an enterprise IT department, that is the baseline needed to answer a question that auditors and privacy officers increasingly ask: what AI is operating in our environment, and on what authority?
“Human in the loop” needs a named person and a defined decision
County staff told The Picton Gazette that all AI-generated content must be reviewed by an employee before it is used, describing this as a “human-in-the-loop” requirement. The County’s policy similarly frames AI as a support for human decision-makers and says residents must retain access to human assistance.
That is a sound principle, but it is only useful when an organization defines the decision that the human is actually making. Editing a draft report for grammar, summarizing a long meeting package, and producing a suggested response to a public inquiry each call for different levels of review. So do automated classifications, recommendations, eligibility assessments, security alerts, and data-analysis outputs.
A reviewer who is merely expected to click “accept” after receiving a polished Copilot response is not meaningful oversight. The review must include access to the relevant source material, enough time and expertise to challenge the result, and a clear line of accountability if the output is wrong. The County’s policy says AI decisions should be understandable and documented with their logic and data sources; that standard will be harder to meet for complex vendor tools than for simple text assistance.
The practical test is whether a staff member can identify what was generated, verify the factual basis, correct it, reject it, and explain why. Municipal records, reports to council, public-facing web copy, accessibility materials, and correspondence may all be retained or disclosed under freedom-of-information rules. AI assistance does not remove the need for ordinary records management, privacy review, and quality control.
For Microsoft environments, this is also where product boundaries matter. A Copilot tool with access only to a user’s active document is not the same governance problem as an assistant grounded in SharePoint, Teams, Exchange, OneDrive, external connectors, or a line-of-business database. The County’s update does not specify which of those access patterns, if any, it has approved.
The agentic pilot raises the approval bar
The County is testing agentic AI with a small group of employees, The Picton Gazette reports. The paper describes the technology as capable of completing more complex tasks with limited human direction, while Senior Manager of Infrastructure Technology and Transformation David Boyle said the pilot had demonstrated value as an efficiency tool and was not eliminating County jobs.
The phrase “agentic AI” can obscure the operational difference from ordinary generative AI. A system that produces a draft or answer remains relatively contained if an employee chooses what to do next. An agent that retrieves information across systems, sequences steps, sends messages, changes records, triggers workflows, or acts under delegated access creates a new class of risk: errors can propagate before a human sees the result.
Prince Edward County’s existing governance terms appear designed for that escalation. They require all AI project proposals to be reviewed and approved before deployment, while the Chief Administrative Officer has final approval and veto power over committee decisions. The committee must also evaluate accessibility, fairness, security, legal compliance, and performance—not just whether staff like the tool.
What remains undisclosed is whether the pilot agents can take actions, or whether they only generate recommendations for employees to carry out. The County has not publicly named the vendor, the departmental use cases, the data handled, the pilot’s risk tier, the number of participants, success measures, or the rollback controls if a test fails. Those omissions do not establish a governance failure; they define the questions the forthcoming framework needs to answer.
A credible evaluation framework should require more than anecdotes about time saved. It should document task boundaries, tool permissions, datasets and systems accessed, expected and prohibited actions, escalation paths, human approval points, error rates, security findings, accessibility testing, and the decision on whether the pilot may expand. It should also identify who owns the agent’s output when the underlying model or vendor behavior changes.
The public registry question is still unresolved
The County’s AI committee is explicitly tasked with maintaining an AI System Registry and preparing reports on AI projects, benefits realized, risks managed, and recommended policy changes. It also has a public-transparency mandate. The March 2026 inaugural committee agenda said that public disclosures should include a system’s purpose, risk level, oversight arrangements, and changes to human contact options, while balancing security, sensitive data, and proprietary concerns.
That is more substantive than the generic AI principles many organizations have issued. But an internal registry is not automatically a public registry. The County’s published committee terms do not say that every entry, every risk assessment, or every evaluation result will be released.
The annual update reported by The Picton Gazette is therefore an initial transparency step, not a complete public accounting. Readers can learn that Copilot and other AI-capable applications have been reviewed, but not what data classifications they are allowed to process, whether prompts or outputs are retained, how staff are trained, or whether departments must disclose AI assistance in particular public-facing documents.
Those details are especially relevant where municipal staff handle resident information, planning files, financial data, records subject to retention rules, and materials that may later be requested by the public. The County’s policy promises privacy, security, explainability, accessibility, environmental responsibility, and fairness. Its next public report should show how those commitments were tested in individual deployments.
September’s workshop needs to produce enforceable controls
The County plans a September workshop for staff and members of the AI Governance Committee as it develops an Artificial Intelligence Implementation and Evaluation Framework. That is the point at which broad principles should turn into operating controls.
The County should publish, at minimum, a plain-language register of approved AI systems and use cases; a statement of whether tools can access personal or confidential data; documented human approval requirements; training completion requirements; and aggregate measurements of errors, incidents, benefits, and projects rejected or restricted. Systems that affect residents directly should receive deeper disclosures than low-risk internal writing assistance.
The County’s framework should also distinguish between AI features that assist individual employees and tools that act across systems or make recommendations that shape public services. Treating both categories as one generic “AI use” would flatten the very risk differences its committee was created to manage.
Prince Edward County has already made a useful choice: it is attempting to inventory and govern AI before treating it as routine office software. The harder work starts now. Its agentic pilot and September framework will show whether the County can translate human oversight from a policy phrase into accountable controls over the tools staff actually use.