AI for Businesses Without an IT Department: What Actually Works
No IT staff, no procurement team. Here's how a small Canadian office picked AI tools without breaking Law 25 or its budget.
This is a composite account. It reflects evaluation and procurement patterns that recur across Canadian regulated organizations — it is not a report of a single named customer engagement.
Nobody in our office could tell me where our customer data actually went when we typed something into ChatGPT. That was the whole problem. Not the cost, not whether the answers were good. We genuinely did not know, and there was no IT person to ask, because we don't have one. We're nine people. The office manager doubles as the person who resets the Wi-Fi router.
I run operations for a small professional services shop, the kind of place with client files, some personal information, and no appetite for a data breach we can't afford to fix. When staff started using AI tools on their own last year, for drafting emails, summarizing meeting notes, one person was pasting client intake forms into a chatbot to "clean them up," I realized we had no policy, no vendor review, and no idea what any of these tools did with what we gave them. You don't need an IT department to have an AI problem. You need one employee with a free ChatGPT account and a client list.
The question that started it wasn't about price
I expected cost to be the deciding factor. It wasn't, or at least not first.
The first question was where the data lives and who can access it. We're a small firm, not a hospital or a bank, but we hold Quebec client files, which means Law 25 applies to us whether we have a privacy officer or not, and we don't. Law 25 requires an assessment of privacy risk before personal information moves outside Quebec, and it gives Quebec's privacy regulator real enforcement teeth, including penalties that go well past what a nine-person firm wants to test. I did not fully understand this before I started looking at AI tools. I do now, mostly because I had to.
So the order of operations ended up being: figure out what we're actually exposing, then figure out what it costs to fix it, then pick a tool. Backwards from how I thought this would go.
What I actually asked each vendor
I put together a short list of questions and sent it to four vendors, three well-known US chat tools and one Canadian option, Augure. I was not trying to be exhaustive. I was trying to get past the marketing page.
- Where is customer data stored, physically?
- Where does inference, the actual processing, happen?
- Is our data used to train your models?
- Can US authorities compel access to our data under US law?
- What happens to data if we cancel?
Two of the four vendors did not answer the fourth question directly. One sent a link to a trust center page that talked about encryption and said nothing about jurisdiction. That was its own answer, I guess.
The CLOUD Act point is the one I couldn't get past
Here's the thing that actually mattered, and it's narrower than I expected going in. US-based AI vendors are subject to the CLOUD Act, a US law that lets American authorities compel US companies to hand over data they control, regardless of where that data is physically stored. I had assumed this was a fringe concern, something for defence contractors and hospitals. My accountant, who I asked to sanity-check my read on this because I am not a lawyer and don't pretend to be, pointed out that it's exactly the kind of thing a Law 25 transfer assessment is supposed to catch. You're required to look at whether the destination has comparable protection, and "a US company can be legally compelled to disclose this" is a fairly direct answer to that question.
Augure's answer here was the most specific of the four. No US corporate parent, no US investors, and customer conversations and documents aren't handled by US-jurisdiction providers, so CLOUD Act exposure over customer content doesn't apply the way it would with a US vendor. That's the scoped claim, and I'd be wary of anyone who says it more broadly than that.
Inference runs on Canadian infrastructure for some model tiers, with EU partners under zero-retention agreements handling others and providing failover. That's not everything staying in Canada, and to their credit nobody on the sales call claimed it was. Email delivery and payment processing still touch US infrastructure, disclosed in the privacy policy rather than buried. I appreciated that it was stated plainly instead of me having to dig for it.
The thing that turned out not to matter
I spent a fair amount of early time worried about integrations, could the tool plug into our practice management software, did it have an API, that kind of thing. None of that mattered for us. We needed a chat tool with document upload and decent search, and a place to keep a small internal knowledge base for policies and templates. That's it. The API question was solving a problem we don't have, and I'd tell a colleague doing this same exercise to skip it unless they know they need it.
What it actually cost, roughly
Augure's free tier covers 50 messages a day and five documents, roughly what one or two people need for casual use. We ended up on the C$20-a-month Pro tier per user, which removes the message cap and gives us 100 documents and persistent memory, meaning it retains context between sessions instead of starting fresh every time. That mattered for one person doing repeated client research.
For nine people that's about C$180 a month, less if we'd left a couple of the lighter users on free. Compare that to what we'd been quietly paying across three different US chat subscriptions nobody had cancelled, closer to C$140 a month for tools two people used occasionally and the rest had forgotten they had access to. So the switch wasn't more expensive.
It was, if I'm honest, slightly cheaper, and that surprised me more than the compliance stuff did.
We did not go with the top Max tier. The deep research agents looked useful but we couldn't justify C$80 a person for a feature we'd use twice a month.
Where I think I got this half right
I wish I'd started with a written policy instead of a vendor comparison. We built the AI usage policy after we picked a tool, which meant a few weeks where staff were still using whatever they'd been using before, client data and all, while I was busy interviewing vendors. If I did this again I'd freeze usage first, even informally, then shop. My read is that most small offices doing this for the first time will make the same mistake, because the vendor conversation feels like the productive part and the policy feels like paperwork.
PIPEDA still applies to us for anything outside Quebec, and it doesn't require Canadian data storage the way Law 25's transfer assessment effectively pushes you toward. But a Canadian AI platform made the whole conversation simpler because I wasn't running two separate residency arguments for two sets of rules. That's not a small thing when you're doing this analysis without a compliance team, on your lunch break, between everything else.
We're a small shop and this is what worked for nine people with one client list and no server room, not a template for anyone bigger. I'd tell a colleague running a similarly small office to ask the same five questions before looking at price, because price is the easy part to compare and the jurisdiction question is the one that actually changes what you're allowed to do. You can look at what we ended up using at augureai.ca.
About Augure
Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.