Governance · Municipal AI · PMI Standard
Why the City of Ottawa Needs Stronger AI Guardrails
Peter Karwacki, PMP, is a certified Project Management Professional and a member of the Project Management Institute (PMI). This commentary applies PMI’s 2026 Standard for Artificial Intelligence in Portfolio, Program, and Project Management to the City of Ottawa’s expanding use of AI. It is written in a personal capacity and is not an official PMI or City of Ottawa position.
Ottawa is no longer experimenting with artificial intelligence at the margins. Thousands of city staff already use generative tools every day. Resume screening, asset mapping, homelessness-risk models, permitting pre-checks, and police investigative tools are moving from pilot to production. Productivity is real. So is the public-trust risk. The city’s existing staff guide is a start. It is not yet a full set of guardrails.
This post argues that Ottawa should treat AI as a portfolio of public projects — not a collection of helpful apps — and should adopt the kind of principle-driven, human-in-the-loop governance set out in PMI’s 2026 AI standard. That standard was written for exactly this moment: AI is being deployed through projects faster than regulation can keep up.[1]
What Ottawa is already doing
By late 2025, more than 3,200 city employees were using Microsoft Copilot. In one 30-day window they submitted more than 114,000 prompts. Staff described the tool as a way to find information and draft communications — work that, for many office roles, is most of the job.[2]
At the same time, the city disclosed or advanced several higher-stakes uses:
- Hiring. AI-assisted resume screening for high-volume postings (including SAP Joule), where a single competition can attract hundreds of applicants.[3]
- Geospatial work. Mobile mapping and machine learning to inventory signs, poles, and other assets.[2]
- Social policy. A model, developed with Carleton University, that uses shelter and demographic data to help predict risk of chronic homelessness.[4]
- Planning and housing. An AI PreCheck pilot for low-rise residential permits, checking completeness and comparing drawings to zoning and building-code rules.[5]
- Digital twin / planning support. Scenario tools and an AI chatbot to help staff apply the new zoning bylaw.[6]
- Policing. The Ottawa Police Service has been developing a dedicated AI policy covering facial recognition, transcription, and related tools, with explicit attention to Charter rights, privacy, and bias.[7]
City Manager Wendy Stephanson told councillors the corporation was writing a broader responsible-use framework, expected in early 2026, to sit above the existing Responsible use of Generative Artificial Intelligence (GenAI) – Guide. That guide already names approved tools (Copilot Web), requires requests for non-standard tools, and sets staff principles around data security, accountability, transparency, and equity.[8]
Why guardrails matter now, not later
Municipal AI is not a lab demo. It touches who gets a job interview, who is flagged as at risk of homelessness, how fast a housing application moves, and how police generate investigative leads. PMI’s standard is blunt about the failure modes that follow when organizations skip governance:
- bias and discriminatory outcomes from training data and model design;
- hallucinations and confident-but-wrong outputs;
- privacy and consent failures when personal data is reused;
- black-box decisions that people cannot contest;
- diffused accountability (“the model did it”);
- intellectual-property and records-management exposure;
- loss of public trust when systems affect rights.
Those risks are not theoretical in Ottawa. Resume screening can encode historical hiring bias. Homelessness models use sensitive attributes (age, Indigenous identity, family status, prior service refusals). Permitting tools can quietly change who gets through the queue. Police facial recognition sits at the intersection of Charter rights and public safety. A staff guide that says “verify the output” is necessary. It is not sufficient when the output already shapes a human decision.
Ontario’s Information and Privacy Commissioner and Human Rights Commission have jointly published principles for responsible public-sector AI precisely because privacy and equality rights travel with these systems.[9] The federal public service now has its own 2025–2027 AI strategy, built around being “ready” and “responsible.”[10] Cities that wait for perfect national legislation will still be operating the tools.
What PMI means by “guardrails”
PMI does not use the marketing word “guardrails” as a slogan. It supplies eight principles and five performance domains that function as guardrails for any organization running AI as work. The standard is technology-agnostic, human-centred, and written for portfolio, program, and project managers — which is how a city actually delivers AI: as initiatives with sponsors, budgets, vendors, risks, and close-out.[11]
The eight principles, applied to a city
| PMI principle | What it requires | Ottawa example if it is missing |
|---|---|---|
| Strategic value | Every AI initiative must map to a public outcome, not a vendor demo. | Copilot usage volume is reported; resident-facing value is not. |
| Risk | Treat AI-specific threats (bias, drift, hallucination, over-automation) and keep a human in the loop. | Resume ranking or homelessness scoring without documented override rules. |
| Governance and compliance | Clear owners, escalation paths, audits, and alignment with MFIPPA, human-rights law, and procurement. | A staff guide without an inventory of systems or an impact-assessment gate. |
| People and culture | Literacy, change management, and no “shadow AI.” | 114,000 prompts with uneven training and no public skills plan. |
| Ethics and professional responsibility | Fairness, transparency, explainability, and an ethics oversight body. | No published municipal ethics committee for AI comparable to PMI’s model. |
| Stakeholder engagement | Residents, unions, equity offices, and affected clients are in the loop before deployment. | Homelessness model consultations promised; public register still thin. |
| Optimization and innovation | Iterate, measure, retire tools that fail. | Pilots that persist because they are already “in the stack.” |
| Data quality | Lineage, representativeness, purpose limitation, and integrity. | Shelter and HR data reused for prediction without a published data card. |
Source: author’s synthesis of PMI, The Standard for Artificial Intelligence in Portfolio, Program, and Project Management (2026), Principles section.[12]
Human-in-the-loop is the non-negotiable control
PMI treats human-in-the-loop (HITL) as both a safety control and a source of value. Machines can generate options at scale. They cannot carry legal accountability, read political context, or weigh competing public values. The standard expects defined intervention triggers, escalation protocols, trained reviewers, and feedback loops — not a vague instruction to “use your judgment.” For a city, that means:
- no automated hiring rejection without a documented human decision;
- no homelessness-risk score used as a service gate without caseworker review;
- no permit “fail” that cannot be explained with a cited bylaw clause;
- no police lead generated by a model that investigators cannot audit.
An ethics oversight committee, not just a PDF
Section 7 of the PMI standard is unusually practical for a municipal reader. It calls for a multidisciplinary AI ethics oversight committee — legal, privacy, equity, operations, PPPM, and community representation — with authority to set boundaries, review vendors, demand audits, and stop a deployment. That is different from asking every employee to be their own ethics officer after they have already pasted text into Copilot.
The same section lists the ethical failure modes cities actually hit: bias and misinformation, discriminatory decision-making, unclear accountability, opacity, weak data security, hallucinations, consent failures, untraceable data sources, and intellectual-property exposure. Ottawa’s GenAI guide already flags several of these. PMI’s contribution is to put them inside a project life cycle with named owners.
Comparative chart: Ottawa versus peer cities
Most large cities are in the same awkward middle: lots of projects, thinner public governance. A minority published standalone strategies years ago. Ottawa is closer to Toronto (staff guidance plus a building policy) than to Amsterdam or Barcelona (public principles plus registers and rights language).
| City | Public AI strategy / policy | Staff GenAI guide | Algorithm register / AIA | Independent or multi-stakeholder ethics body | High-stakes use cases in play |
|---|---|---|---|---|---|
| Ottawa | Corporate framework announced for early 2026; not a long-standing public strategy | Yes (2025 GenAI Guide; Copilot approved) | Not published as a resident-facing inventory | Not published city-wide | Hiring, Copilot at scale, mapping, homelessness model, permitting AI, police AI policy |
| Toronto | In-house AI policy work in 2025; Digital Infrastructure Strategic Framework as foundation | Yes (June 2025 GenAI guidance) | Working toward municipal algorithmic impact assessment | Police board AI policy since 2022; city-wide ethics body still evolving | Service AI plus Toronto Police Service AI governance |
| New York City | AI Strategy (2021) and Action Plan (2023); steering committee | Yes, plus staff training actions | Local Law 144 (AEDT) and public reporting culture | City AI Steering Committee / OTI lead | Hiring tools, service bots, agency systems |
| Amsterdam | Intelligence Agenda; 2024 Vision on AI (human value, education, equal access) | Yes | Pioneer of public algorithm register | Strong civic / rights framing | Municipal algorithms with public documentation |
| Barcelona | 2021 ethical algorithms-and-data strategy; 2026 investment package to deepen it | Yes | Rights-centred model; external advisory council on AI and digital rights | Yes | Recommendation systems constrained; digital-rights brand |
| Montréal | Early Montréal Declaration for responsible AI (principles, not a binding ops manual) | Varies by institution | Research-heavy ecosystem (Mila) | Declaration as civic reference | Research and civic principles more visible than ops playbooks |
Comparative judgments are based on publicly described instruments, not on unpublished internal controls.[13][14][15]
Ottawa’s current guide versus a PMI-style control set
| Control | Ottawa GenAI Guide (2025) | PMI AI Standard (2026) expectation |
|---|---|---|
| Approved tools | Copilot Web; exceptions via technology request | Tool selection criteria: alignment, integration, scale, learning curve, cost-benefit, data control |
| Human responsibility | Employee must verify outputs | Defined HITL triggers, roles, escalation, and audit of the HITL process itself |
| Equity / bias | Staff told not to amplify bias | Fairness testing, diverse teams, periodic bias reassessment, documented remediation |
| Privacy | Do not put non-compliant data into tools | Data-quality principle plus legal considerations (consent, MFIPPA-class rules, vendor clauses) |
| Transparency to the public | Internal education document | Stakeholder engagement domain; explainability; contestability of decisions that affect rights |
| Oversight body | Not specified in the staff guide | AI ethics oversight committee with cross-functional membership and stop-the-line authority |
| Life cycle | Use-time guidance | Initiation → data prep → model/tooling → deploy → monitor → optimize → decommission, tailored into PPPM phases |
| Business case | Implied productivity | ROI, risk, ethics, regulatory fit, and long-term sustainability before scale-up |
The honest reading is that Ottawa did the first-mile work well: pick a sanctioned tool, tell staff not to paste secrets, remind them they own the output. The second mile — the one that protects residents when AI is used on them, not just by staff — is where PMI’s performance domains matter: managing stakeholder expectations, defining scope, designing for quality and reliability, executing strategic goals, and managing AI-specific risk.
A practical guardrail package for Ottawa
If the city’s 2026 framework is still being socialized, it should include the following, mapped to PMI practice rather than invented from scratch.
- Publish an AI system inventory. Name the systems, owners, data sources, decision type (assistive vs. consequential), and whether a human can override. Amsterdam’s register is the benchmark; Toronto is moving toward impact assessment. Ottawa should not be less transparent than its peers while running more operational pilots.
- Classify use by harm, not by vendor. Copilot drafting a memo is not the same class as ranking job applicants or scoring homelessness risk. High-impact classes require privacy impact assessments, human-rights review, and a public plain-language notice.
- Stand up an ethics oversight committee with real authority. Include privacy, legal, People and Culture, Community and Social Services, Planning, ITS, labour, and community representation. Give it the power to pause a pilot. PMI’s committee model exists so ethics is not a sidebar comment in a steering deck.
- Hard-code HITL for consequential decisions. Write the intervention triggers. Train the reviewers. Audit whether humans actually review, or just click “accept.”
- Treat vendors as part of the control system. Contractual clauses on data residency, training-data use, audit rights, explainability, and liability — the legal chapter of the PMI standard is there for a reason.
- Measure more than prompt counts. PMI asks for leading and lagging indicators: accuracy, override rates, complaint rates, disparate impact, downtime, and whether the tool still matches the original business case. 114,000 prompts is activity. It is not value and it is not safety.
- Engage the people the models describe. Shelter users, job applicants, builders, and communities over-represented in administrative data should see the purpose, limits, and redress path before scale-up. The homelessness project’s planned consultations should be the rule, not a one-off.
- Plan decommissioning. Models drift. Vendors change terms. A city that cannot turn a system off does not control it.
Why a project-management standard is the right instrument
City AI work is already organized as projects and programs. That is PMI’s home territory. A rights charter without delivery mechanics becomes a poster. A delivery plan without ethics becomes a procurement. The 2026 standard is useful because it forces both into the same operating system: principles, performance domains, life-cycle tailoring, and legal/ethical close-out.
It also matches how Ottawa actually works. Portfolio language helps Council prioritize which AI bets deserve scarce attention. Program language helps ITS, HR, Planning, and Community and Social Services stop running parallel pilots that share data and risk. Project language gives a manager a checklist that survives a staff rotation.
None of this requires Ottawa to wait for a federal AI Act with municipal teeth. The tools are already in the building. The public already has a reasonable question: when the city uses a model to sort people or speed a legal decision, who is accountable, how do we see it, and how do we contest it?
That is what guardrails are for.
References
- Project Management Institute. “PMI Publishes World’s First Global Standard for AI in Project Work.” Press release, 2026. pmi.org.
- White-Crummey, Arthur. “City working on AI projects to speed up hiring, mapping and office work.” CBC News, 2 December 2025. cbc.ca.
- Dodd, Anna. “City of Ottawa is making use of AI tools like Microsoft Copilot, SAP Joule.” CompassNews, 4 December 2025. compassnews.ca.
- Karadeglija, Anja. “Ottawa becomes the latest city to turn to AI to help it predict chronic homelessness.” The Globe and Mail, 4 August 2024. theglobeandmail.com.
- Archistar. “City of Ottawa Launches AI PreCheck Pilot to Accelerate Permitting.” 1 June 2026. archistar.ai.
- What Works Cities. “Ottawa, Canada.” whatworkscities.bloomberg.org.
- “AI is coming to the Ottawa police. Here’s how they’ll use the new tech.” Ottawa Citizen, 29 March 2026. ottawacitizen.com.
- City of Ottawa. Responsible use of Generative Artificial Intelligence (GenAI) – Guide. 2025. PDF via AMCTO.
- Ontario Human Rights Commission and Information and Privacy Commissioner of Ontario. Principles for the Responsible Use of Artificial Intelligence. ohrc.on.ca.
- Government of Canada. AI Strategy for the Federal Public Service 2025–2027. canada.ca.
- Walch, Kathleen. “The New AI Standard: A Shared Foundation for Responsible Adoption.” PMI Blog, 14 July 2026. pmi.org/blog.
- Project Management Institute. The Standard for Artificial Intelligence in Portfolio, Program, and Project Management. PMI, 2026. ISBN 978-1-62825-891-2. Principles, performance domains, human-in-the-loop guidance, and ethics oversight summarized from the published standard.
- Vidal D’oleo, Alexandra. “Case studies of urban AI governance frameworks.” CIDOB, 2024. cidob.org.
- The GovLab. “AI Localism in Action: Six Local Approaches to Governing AI.” blog.thegovlab.org.
- City of Toronto. Guidance for the Responsible Use of Generative Artificial Intelligence, 18 June 2025. toronto.ca PDF.

No comments:
Post a Comment