← Back to Insights
Canadian AI

AI Readiness Assessments in Vancouver: What the Checklist Actually Missed

A Vancouver compliance lead walks through the AI readiness assessment process — the questions asked, what Canadian AI options changed, what didn't matter.

By Augure·
a view of a city with mountains in the background

The part that stopped us wasn't the privacy policy. It was the sub-processor list.

We'd been asked to run an AI readiness assessment for a mid-size professional services firm here in Vancouver — the kind of exercise where someone senior says "we need to know what we're allowed to use before people start using it anyway," which, if I'm honest, they already had. Staff were pasting client correspondence into whatever chatbot was free that week. The assessment was supposed to catch up to that reality, not get ahead of it.

I expected the hard part to be technical — model accuracy, hallucination rates, that kind of thing. It wasn't. The hard part was figuring out, tool by tool, where the data actually went once it left someone's browser.

What we were actually trying to answer

The brief, stripped of corporate language, came down to one question: can staff use generative AI on client and employee personal information without creating exposure under PIPEDA, and — because this firm has a Quebec office — under Law 25 as well. Everything else fed into that.

We built the intake around a short list of questions we sent to every vendor under consideration, including the ones already in informal use around the office:

  • Where is customer data stored at rest, and where does inference actually run?
  • Is any customer content used to train models, and is that opt-out or structural?
  • Who are the sub-processors, and does any of them sit under US jurisdiction?
  • What happens to data on account deletion, and how is that verified rather than just claimed?
  • Is there a data processing agreement that names Canada specifically, or does it default to a US template with a Canada rider bolted on?

That last one mattered more than I expected going in. A lot of vendors will tell you, verbally, that data residency isn't a problem. Far fewer will put "stored in Canada" into the contract itself.

The CLOUD Act point our counsel wouldn't move on

Here's where the assessment stopped being a spreadsheet exercise and became a legal one. Our outside counsel flagged that a US-incorporated AI vendor — even one offering a "Canadian data residency" toggle — can still be compelled to produce customer content under the US CLOUD Act, because the obligation attaches to the company, not the server location. That's the plain operation of the statute, and it's the point counsel wouldn't compromise on for anything touching client files with solicitor-client privilege implications.

That single constraint did more to narrow our shortlist than every feature comparison combined. It's also, I'll admit, the point that took longest to get everyone comfortable with, because "the server is in Toronto" sounds like it should end the conversation, and it doesn't, if the company behind the server has a US parent.

This is where looking at Canadian AI platforms specifically started to make more sense than trying to configure a US tool around the problem. A company incorporated and operating under Canadian jurisdiction, with no US parent, doesn't have that compulsion pathway attached to its customer content in the first place. We were careful, and our counsel was careful, not to write that up as immunity from all foreign legal process — it's a narrower, scoped claim than that, and it's still the one that mattered.

Where Augure fit into the shortlist

We evaluated four tools in the end. Two were the large US incumbents everyone already knew. One was a smaller Canadian document-review product. The fourth was Augure.

The concrete thing that stood out with Augure was the pricing structure lining up with how the firm actually planned to roll this out — a free tier capped at 50 messages a day for the partners who wanted to poke at it before committing budget, and a C$20/month Pro tier with no message limits and persistent memory for the associates doing real drafting work. For the document-heavy litigation team, the C$80/month Max tier's 100-document knowledge base cap was a real limitation we flagged; a firm with a deep document management system already in place is going to bump into that ceiling fast, and we said so in the recommendation memo rather than glossing over it.

On the sub-processor question, Augure's answer was that customer data is stored in Canada and inference runs on Canadian infrastructure, with vetted EU partners handling certain model tiers and failover under zero-retention agreements — never routed to US providers for inference or customer content. That's a more specific answer than we got from either US incumbent, whose answers amounted to "data residency options are available on enterprise plans," which is a different thing, and in one case didn't extend to the model actually doing the inference, only the storage layer.

The thing that didn't matter

We spent a genuinely embarrassing number of hours comparing SOC 2 Type II attestations across vendors, building a little matrix, colour-coding it. In the end it didn't move the decision at all. Every serious vendor we looked at had one, or had a credible date for getting one, and the firm's own security reviewer said afterward that the attestation was table stakes rather than a differentiator — it told her a vendor had a functioning security program, not whether that program's jurisdiction created a legal problem for privileged client data. I'd cut that whole exercise from the checklist next time and put the hours into the sub-processor and DPA review instead.

What the finance team pushed back on

Not everything came from legal. Finance asked, reasonably, whether the cost difference between the free tiers everyone was already using informally and a paid Canadian AI platform was worth it in avoided risk versus hard dollars. I don't think we answered that perfectly — my honest read is that we made a qualitative case, backed by counsel's exposure analysis, rather than a hard ROI number, because quantifying "avoided regulatory exposure" is close to impossible to do with a straight face. If someone pushed me on the exact dollar figure we saved, I couldn't give them one.

Under Law 25, the transfer question doesn't disappear

One thing I'd flag for anyone running this in a Quebec-touching organization: choosing a Canadian AI platform doesn't automatically close the section 17 analysis. Law 25 requires an assessment of any transfer of personal information outside Quebec, and that includes transfers to other Canadian provinces or to the EU tier some platforms use for certain workloads or failover. We asked Augure directly which flows exist, and got a straight answer — EU inference for specific model tiers and during failover, plus limited US processing for payment card handling and email delivery, all documented in their privacy policy rather than left implicit. That disclosure is what actually helps the section 17 writeup, because you're not guessing at what to assess.

What I'd change

If I ran this again, I'd bring procurement into the room in week one, not week four, because the pricing conversation ended up trailing behind the technical review and cost us real calendar time. I'd also push back harder, earlier, on the instinct to build a comparison matrix with twenty rows when six of them never influenced anything. Roughly half our effort went somewhere that didn't change the outcome. That's probably normal for this kind of review. I'm still not entirely sure it's avoidable.

For the firm, the shortlist that survived was narrow, and it leaned toward Canadian AI tools for anything touching client data, with the US tools kept on for lower-stakes internal work under a written policy rather than an outright ban. If you're doing a version of this assessment yourself, augureai.ca has the pricing and privacy documentation laid out in enough detail to start your own sub-processor questions from somewhere other than zero.

A

About Augure

Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.

Ready to try sovereign AI?

Start free. No credit card required.

Get Started