Governance · Municipal AI · PMI Standard
Why the City of Ottawa Needs Stronger AI Guardrails
Peter Karwacki, PMP, is a certified Project Management Professional and a member of the Project Management Institute (PMI). This commentary applies PMI’s 2026 Standard for Artificial Intelligence in Portfolio, Program, and Project Management to the City of Ottawa’s expanding use of AI. It is written in a personal capacity and is not an official PMI or City of Ottawa position.
Ottawa is no longer experimenting with artificial intelligence at the margins. Thousands of city staff already use generative tools every day. Resume screening, asset mapping, homelessness-risk models, permitting pre-checks, and police investigative tools are moving from pilot to production. Productivity is real. So is the public-trust risk. The city’s existing staff guide is a start. It is not yet a full set of guardrails.
This post argues that Ottawa should treat AI as a portfolio of public projects — not a collection of helpful apps — and should adopt the kind of principle-driven, human-in-the-loop governance set out in PMI’s 2026 AI standard. That standard was written for exactly this moment: AI is being deployed through projects faster than regulation can keep up.[1]
What Ottawa is already doing
By late 2025, more than 3,200 city employees were using Microsoft Copilot. In one 30-day window they submitted more than 114,000 prompts. Staff described the tool as a way to find information and draft communications — work that, for many office roles, is most of the job.[2]
At the same time, the city disclosed or advanced several higher-stakes uses:
- Hiring. AI-assisted resume screening for high-volume postings (including SAP Joule), where a single competition can attract hundreds of applicants.[3]
- Geospatial work. Mobile mapping and machine learning to inventory signs, poles, and other assets.[2]
- Social policy. A model, developed with Carleton University, that uses shelter and demographic data to help predict risk of chronic homelessness.[4]
- Planning and housing. An AI PreCheck pilot for low-rise residential permits, checking completeness and comparing drawings to zoning and building-code rules.[5]
- Digital twin / planning support. Scenario tools and an AI chatbot to help staff apply the new zoning bylaw.[6]
- Policing. The Ottawa Police Service has been developing a dedicated AI policy covering facial recognition, transcription, and related tools, with explicit attention to Charter rights, privacy, and bias.[7]
City Manager Wendy Stephanson told councillors the corporation was writing a broader responsible-use framework, expected in early 2026, to sit above the existing Responsible use of Generative Artificial Intelligence (GenAI) – Guide. That guide already names approved tools (Copilot Web), requires requests for non-standard tools, and sets staff principles around data security, accountability, transparency, and equity.[8]
Why guardrails matter now, not later
Municipal AI is not a lab demo. It touches who gets a job interview, who is flagged as at risk of homelessness, how fast a housing application moves, and how police generate investigative leads. PMI’s standard is blunt about the failure modes that follow when organizations skip governance:
- bias and discriminatory outcomes from training data and model design;
- hallucinations and confident-but-wrong outputs;
- privacy and consent failures when personal data is reused;
- black-box decisions that people cannot contest;
- diffused accountability (“the model did it”);
- intellectual-property and records-management exposure;
- loss of public trust when systems affect rights.
Those risks are not theoretical in Ottawa. Resume screening can encode historical hiring bias. Homelessness models use sensitive attributes (age, Indigenous identity, family status, prior service refusals). Permitting tools can quietly change who gets through the queue. Police facial recognition sits at the intersection of Charter rights and public safety. A staff guide that says “verify the output” is necessary. It is not sufficient when the output already shapes a human decision.
Ontario’s Information and Privacy Commissioner and Human Rights Commission have jointly published principles for responsible public-sector AI precisely because privacy and equality rights travel with these systems.[9] The federal public service now has its own 2025–2027 AI strategy, built around being “ready” and “responsible.”[10] Cities that wait for perfect national legislation will still be operating the tools.
What PMI means by “guardrails”
PMI does not use the marketing word “guardrails” as a slogan. It supplies eight principles and five performance domains that function as guardrails for any organization running AI as work. The standard is technology-agnostic, human-centred, and written for portfolio, program, and project managers — which is how a city actually delivers AI: as initiatives with sponsors, budgets, vendors, risks, and close-out.[11]
The eight principles, applied to a city
| PMI principle | What it requires | Ottawa example if it is missing |
|---|---|---|
| Strategic value | Every AI initiative must map to a public outcome, not a vendor demo. | Copilot usage volume is reported; resident-facing value is not. |
| Risk | Treat AI-specific threats (bias, drift, hallucination, over-automation) and keep a human in the loop. | Resume ranking or homelessness scoring without documented override rules. |
| Governance and compliance | Clear owners, escalation paths, audits, and alignment with MFIPPA, human-rights law, and procurement. | A staff guide without an inventory of systems or an impact-assessment gate. |
| People and culture | Literacy, change management, and no “shadow AI.” | 114,000 prompts with uneven training and no public skills plan. |
| Ethics and professional responsibility | Fairness, transparency, explainability, and an ethics oversight body. | No published municipal ethics committee for AI comparable to PMI’s model. |
| Stakeholder engagement | Residents, unions, equity offices, and affected clients are in the loop before deployment. | Homelessness model consultations promised; public register still thin. |
| Optimization and innovation | Iterate, measure, retire tools that fail. | Pilots that persist because they are already “in the stack.” |
| Data quality | Lineage, representativeness, purpose limitation, and integrity. | Shelter and HR data reused for prediction without a published data card. |
Source: author’s synthesis of PMI, The Standard for Artificial Intelligence in Portfolio, Program, and Project Management (2026), Principles section.[12]
Human-in-the-loop is the non-negotiable control
PMI treats human-in-the-loop (HITL) as both a safety control and a source of value. Machines can generate options at scale. They cannot carry legal accountability, read political context, or weigh competing public values. The standard expects defined intervention triggers, escalation protocols, trained reviewers, and feedback loops — not a vague instruction to “use your judgment.” For a city, that means:
- no automated hiring rejection without a documented human decision;
- no homelessness-risk score used as a service gate without caseworker review;
- no permit “fail” that cannot be explained with a cited bylaw clause;
- no police lead generated by a model that investigators cannot audit.
An ethics oversight committee, not just a PDF
Section 7 of the PMI standard is unusually practical for a municipal reader. It calls for a multidisciplinary AI ethics oversight committee — legal, privacy, equity, operations, PPPM, and community representation — with authority to set boundaries, review vendors, demand audits, and stop a deployment. That is different from asking every employee to be their own ethics officer after they have already pasted text into Copilot.
The same section lists the ethical failure modes cities actually hit: bias and misinformation, discriminatory decision-making, unclear accountability, opacity, weak data security, hallucinations, consent failures, untraceable data sources, and intellectual-property exposure. Ottawa’s GenAI guide already flags several of these. PMI’s contribution is to put them inside a project life cycle with named owners.
Comparative chart: Ottawa versus peer cities
Most large cities are in the same awkward middle: lots of projects, thinner public governance. A minority published standalone strategies years ago. Ottawa is closer to Toronto (staff guidance plus a building policy) than to Amsterdam or Barcelona (public principles plus registers and rights language).
| City | Public AI strategy / policy | Staff GenAI guide | Algorithm register / AIA | Independent or multi-stakeholder ethics body | High-stakes use cases in play |
|---|---|---|---|---|---|
| Ottawa | Corporate framework announced for early 2026; not a long-standing public strategy | Yes (2025 GenAI Guide; Copilot approved) | Not published as a resident-facing inventory | Not published city-wide | Hiring, Copilot at scale, mapping, homelessness model, permitting AI, police AI policy |
| Toronto | In-house AI policy work in 2025; Digital Infrastructure Strategic Framework as foundation | Yes (June 2025 GenAI guidance) | Working toward municipal algorithmic impact assessment | Police board AI policy since 2022; city-wide ethics body still evolving | Service AI plus Toronto Police Service AI governance |
| New York City | AI Strategy (2021) and Action Plan (2023); steering committee | Yes, plus staff training actions | Local Law 144 (AEDT) and public reporting culture | City AI Steering Committee / OTI lead | Hiring tools, service bots, agency systems |
| Amsterdam | Intelligence Agenda; 2024 Vision on AI (human value, education, equal access) | Yes | Pioneer of public algorithm register | Strong civic / rights framing | Municipal algorithms with public documentation |
| Barcelona | 2021 ethical algorithms-and-data strategy; 2026 investment package to deepen it | Yes | Rights-centred model; external advisory council on AI and digital rights | Yes | Recommendation systems constrained; digital-rights brand |
| Montréal | Early Montréal Declaration for responsible AI (principles, not a binding ops manual) | Varies by institution | Research-heavy ecosystem (Mila) | Declaration as civic reference | Research and civic principles more visible than ops playbooks |
Comparative judgments are based on publicly described instruments, not on unpublished internal controls.[13][14][15]
Ottawa’s current guide versus a PMI-style control set
| Control | Ottawa GenAI Guide (2025) | PMI AI Standard (2026) expectation |
|---|---|---|
| Approved tools | Copilot Web; exceptions via technology request | Tool selection criteria: alignment, integration, scale, learning curve, cost-benefit, data control |
| Human responsibility | Employee must verify outputs | Defined HITL triggers, roles, escalation, and audit of the HITL process itself |
| Equity / bias | Staff told not to amplify bias | Fairness testing, diverse teams, periodic bias reassessment, documented remediation |
| Privacy | Do not put non-compliant data into tools | Data-quality principle plus legal considerations (consent, MFIPPA-class rules, vendor clauses) |
| Transparency to the public | Internal education document | Stakeholder engagement domain; explainability; contestability of decisions that affect rights |
| Oversight body | Not specified in the staff guide | AI ethics oversight committee with cross-functional membership and stop-the-line authority |
| Life cycle | Use-time guidance | Initiation → data prep → model/tooling → deploy → monitor → optimize → decommission, tailored into PPPM phases |
| Business case | Implied productivity | ROI, risk, ethics, regulatory fit, and long-term sustainability before scale-up |
The honest reading is that Ottawa did the first-mile work well: pick a sanctioned tool, tell staff not to paste secrets, remind them they own the output. The second mile — the one that protects residents when AI is used on them, not just by staff — is where PMI’s performance domains matter: managing stakeholder expectations, defining scope, designing for quality and reliability, executing strategic goals, and managing AI-specific risk.
A practical guardrail package for Ottawa
If the city’s 2026 framework is still being socialized, it should include the following, mapped to PMI practice rather than invented from scratch.
- Publish an AI system inventory. Name the systems, owners, data sources, decision type (assistive vs. consequential), and whether a human can override. Amsterdam’s register is the benchmark; Toronto is moving toward impact assessment. Ottawa should not be less transparent than its peers while running more operational pilots.
- Classify use by harm, not by vendor. Copilot drafting a memo is not the same class as ranking job applicants or scoring homelessness risk. High-impact classes require privacy impact assessments, human-rights review, and a public plain-language notice.
- Stand up an ethics oversight committee with real authority. Include privacy, legal, People and Culture, Community and Social Services, Planning, ITS, labour, and community representation. Give it the power to pause a pilot. PMI’s committee model exists so ethics is not a sidebar comment in a steering deck.
- Hard-code HITL for consequential decisions. Write the intervention triggers. Train the reviewers. Audit whether humans actually review, or just click “accept.”
- Treat vendors as part of the control system. Contractual clauses on data residency, training-data use, audit rights, explainability, and liability — the legal chapter of the PMI standard is there for a reason.
- Measure more than prompt counts. PMI asks for leading and lagging indicators: accuracy, override rates, complaint rates, disparate impact, downtime, and whether the tool still matches the original business case. 114,000 prompts is activity. It is not value and it is not safety.
- Engage the people the models describe. Shelter users, job applicants, builders, and communities over-represented in administrative data should see the purpose, limits, and redress path before scale-up. The homelessness project’s planned consultations should be the rule, not a one-off.
- Plan decommissioning. Models drift. Vendors change terms. A city that cannot turn a system off does not control it.
Why a project-management standard is the right instrument
City AI work is already organized as projects and programs. That is PMI’s home territory. A rights charter without delivery mechanics becomes a poster. A delivery plan without ethics becomes a procurement. The 2026 standard is useful because it forces both into the same operating system: principles, performance domains, life-cycle tailoring, and legal/ethical close-out.
It also matches how Ottawa actually works. Portfolio language helps Council prioritize which AI bets deserve scarce attention. Program language helps ITS, HR, Planning, and Community and Social Services stop running parallel pilots that share data and risk. Project language gives a manager a checklist that survives a staff rotation.
None of this requires Ottawa to wait for a federal AI Act with municipal teeth. The tools are already in the building. The public already has a reasonable question: when the city uses a model to sort people or speed a legal decision, who is accountable, how do we see it, and how do we contest it?
That is what guardrails are for.
References
- Project Management Institute. “PMI Publishes World’s First Global Standard for AI in Project Work.” Press release, 2026. pmi.org.
- White-Crummey, Arthur. “City working on AI projects to speed up hiring, mapping and office work.” CBC News, 2 December 2025. cbc.ca.
- Dodd, Anna. “City of Ottawa is making use of AI tools like Microsoft Copilot, SAP Joule.” CompassNews, 4 December 2025. compassnews.ca.
- Karadeglija, Anja. “Ottawa becomes the latest city to turn to AI to help it predict chronic homelessness.” The Globe and Mail, 4 August 2024. theglobeandmail.com.
- Archistar. “City of Ottawa Launches AI PreCheck Pilot to Accelerate Permitting.” 1 June 2026. archistar.ai.
- What Works Cities. “Ottawa, Canada.” whatworkscities.bloomberg.org.
- “AI is coming to the Ottawa police. Here’s how they’ll use the new tech.” Ottawa Citizen, 29 March 2026. ottawacitizen.com.
- City of Ottawa. Responsible use of Generative Artificial Intelligence (GenAI) – Guide. 2025. PDF via AMCTO.
- Ontario Human Rights Commission and Information and Privacy Commissioner of Ontario. Principles for the Responsible Use of Artificial Intelligence. ohrc.on.ca.
- Government of Canada. AI Strategy for the Federal Public Service 2025–2027. canada.ca.
- Walch, Kathleen. “The New AI Standard: A Shared Foundation for Responsible Adoption.” PMI Blog, 14 July 2026. pmi.org/blog.
- Project Management Institute. The Standard for Artificial Intelligence in Portfolio, Program, and Project Management. PMI, 2026. ISBN 978-1-62825-891-2. Principles, performance domains, human-in-the-loop guidance, and ethics oversight summarized from the published standard.
- Vidal D’oleo, Alexandra. “Case studies of urban AI governance frameworks.” CIDOB, 2024. cidob.org.
- The GovLab. “AI Localism in Action: Six Local Approaches to Governing AI.” blog.thegovlab.org.
- City of Toronto. Guidance for the Responsible Use of Generative Artificial Intelligence, 18 June 2025. toronto.ca PDF.
Ottawa's AI Use Isn't Coming. It's Already Here.
The city is already using AI to screen job applicants. The rules for that still don't exist.
Over 3,200 City of Ottawa employees now have access to Microsoft Copilot. Between them, they've logged more than 114,000 prompts. Staff are using it to draft documents, map city infrastructure, and — this is the one that should get your attention — screen job applications.
None of that is a rumour or a worry about the future. City officials laid it out themselves at the Finance and Corporate Services Committee's budget briefing this past December. What they didn't have yet, by their own account, was the governance framework meant to sit alongside all of it. It was still being written.
That gap matters most in hiring. An AI system helping decide who gets an interview is a decision about someone's livelihood. If nobody at City Hall can tell you clearly who's accountable when that system gets it wrong, or what a human is actually required to check before a rejection goes out, the city isn't managing that risk. It's hoping one doesn't happen.
In June, the Project Management Institute — the professional body behind the PMP designation I hold — published the first ANSI-approved standard for how organizations should actually run AI-driven work, not just talk about doing it responsibly. It's built to outlast any one tool, because it's organized around eight guiding principles instead of a list of today's software.
The StandardThe eight guardrails
Principle two is the one that belongs on every councillor's desk. Keep a human in the loop — not "someone probably checks this," but a defined point where a person has to sign off, and a named role accountable if they don't.
Ottawa doesn't need to adopt a private institute's standard word for word, and PMI isn't the only body saying this. On January 21, 2026, Ontario's own Information and Privacy Commissioner and the Ontario Human Rights Commission jointly published six principles for responsible public-sector AI use: valid and reliable, safe, privacy-protecting, human-rights affirming, transparent, and accountable. Between a national professional standard and the province's own regulators, Ottawa already has more than enough of a template sitting in front of it. What's missing is the will to publish one.
How far behind is Ottawa?
Lay the substance of those frameworks next to what Ottawa has actually published, and the gap isn't subtle:
| Provision | PMI Standard | Ontario IPC–OHRC | City of Ottawa |
|---|---|---|---|
| Published governance framework | ✓ | ✓ | — |
| Human-in-the-loop requirement | ✓ | ✓ | — |
| Named accountable role | ✓ | ✓ | — |
| Independent audit provision | ✓ | ~ | — |
✓ explicit requirement ~ implied, not a standalone requirement — not publicly documented as of this writing
Three things council could actually do
- Publish where AI is currently used in decisions that affect residents — hiring, permitting, enforcement, 311 triage — instead of leaving it in a committee slide deck.
- Require a documented human sign-off before an AI-assisted decision like a resume rejection becomes final, with a named accountable role attached to it.
- Publish an annual audit confirming that sign-off is actually happening — not a one-time policy memo. I've made this same ask about the Police Services Board's database access. The pattern doesn't change: a policy nobody checks isn't a policy. It's a press release.
This is the same argument I've been making about AI in city operations since I started this campaign. The question was never whether AI would be used at City Hall. It already is. The question is whether anyone can tell you, honestly, how.

No comments:
Post a Comment