Sidekick Digital logo Sidekick Digital Book a Discovery Call
Home Solutions Industries Resources About Contact Book a Discovery Call
Municipal AI

Alberta's New Privacy Rules Just Kicked In. Does Your AI Use Fit Inside Them?

July 15, 2026 · Sidekick Digital

June 11, 2026 came and went for Alberta's municipalities, and most residents never noticed. That was the deadline for every public body in the province (municipalities, school boards, health authorities, universities) to have a documented Privacy Management Program in place under the Protection of Privacy Act (POPA) and the Access to Information Act (ATIA), the legislation that replaced the old Freedom of Information and Protection of Privacy Act (FOIP) a year earlier.

A month past that deadline, the Office of the Information and Privacy Commissioner (OIPC) of Alberta can now receive formal complaints against public bodies that don't have one. If your municipality built a Privacy Management Program this spring, there's a good chance it doesn't say anything about AI. That's the gap worth closing before someone else finds it for you.

What a Privacy Management Program actually has to contain

The OIPC's guidance describes a "building block" approach. At minimum, a compliant program needs a designated privacy officer accountable for compliance, written procedures for how personal information is collected, used, and disclosed, a process for responding to privacy breaches, and a security classification system for the personal information the public body holds. Public bodies handling higher-risk or more sensitive information face enhanced requirements on top of that baseline. The program itself has to be made available to the public or provided on request, so it isn't an internal document that can sit in a drawer.

None of that is AI-specific. It's the general housekeeping every public body now has to demonstrate. But buried inside POPA is a provision that is specifically about automated systems, and it's the one we see missed most often.

The AI wrinkle most municipalities are missing

Under POPA, public bodies have to notify individuals when their personal information will be input into an automated system to generate content, or to make decisions, recommendations, or predictions. That requirement applies to information collected on or after June 11, 2025, when POPA came into force. Information collected before that date can still be used in AI systems without a fresh notice.

Read that requirement against what municipalities are actually piloting right now: resident-facing chatbots that answer questions using a database of names and addresses, automated triage of permit or bylaw complaints, AI-assisted scoring of grant or licensing applications. Every one of those is an automated system generating content, a decision, or a recommendation from personal information. Every one of them needs a notice to the resident, in plain language, before it happens, not a line buried in a privacy policy nobody reads.

This is where a Privacy Management Program written before anyone thought about AI starts to show its age. A generic breach-response procedure and a designated privacy officer don't tell staff when a new AI notice is triggered, or who signs off before a pilot goes live.

The staff are already ahead of the policy

KPMG's 2026 report on responsible AI adoption in Canada's public sector found that nearly half of public servants report using AI tools in their day-to-day work (mostly to summarize information, draft or edit documents, do preliminary research, and generate ideas) while only 22% of their organizations have formally adopted AI at all. That gap is the whole problem in one number. Adoption is happening bottom-up, driven by employees looking for a faster way to get through their inbox, while governance is still waiting on a decision from the top.

"Without coordinated action, governments risk creating a shadow AI environment — one that exposes sensitive data, undermines consistency, and erodes trust," KPMG's report warns. "The greatest risk facing public sector AI today is not moving too fast, but moving without intention."

A staff member pasting a resident's complaint letter into a public chatbot to draft a reply isn't malicious. They're trying to do their job faster. But that resident's name, address, and complaint details just left the municipality's control and landed on a server with no guarantee about where the data goes or how long it's kept. And no notice was ever given, because nobody built the process to give one.

Three things to check this quarter

First, pull up your Privacy Management Program and check whether it names AI anywhere. If it doesn't, that's the first gap to close. It doesn't take a rewrite, just an addendum that says which uses require a notice and who approves a new one.

Second, ask department heads what staff are actually using, not what's officially sanctioned. The honest answer is usually a public tool like ChatGPT, Gemini, or Copilot, used for exactly the summarizing and drafting work KPMG's report describes.

Third, set one clear rule everyone can remember: nothing with a resident's name, address, account number, or case details goes into a public AI tool until there's a policy and, where POPA requires it, a notice in place. Public documents only, until then.

The deadline for having a Privacy Management Program has passed. The deadline for making sure it actually covers how your municipality is using AI hasn't, because most programs don't yet, and the OIPC hasn't started asking. That won't last.

← Back to all posts

Close the gap between your policy and your practice

Sidekick Digital helps Alberta municipalities align AI pilots with POPA obligations, from notice requirements to staff guidance.

Book a Discovery Call