← Back to Insights
Regulated Industries

Exam integrity in the AI era: How Canadian schools are responding

A compliance lead's account of evaluating detection tools and Canadian AI platforms for a school board's exam integrity policy.

By Augure·
a sign in front of a building in the snow

This is a composite account. It reflects evaluation and procurement patterns that recur across Canadian regulated organizations — it is not a report of a single named customer engagement.

The detection software was the easy part to reject. What actually slowed our committee down for three weeks was a question nobody had put on the agenda: if a teacher uses an AI tool to help draft a rubric or reword an exam question, whose data is that, and where does it go?

I sit on a policy working group for a mid-size school board — not a huge urban district, not a one-school operation, somewhere in between, with enough schools that "just tell teachers to use their judgment" stopped being an adequate answer around the time ChatGPT reached a few hundred thousand Canadian students. We were asked, roughly a year ago, to write something coherent about AI and exam integrity. What we produced looked almost nothing like the draft we started with, and the reason is mostly this: student-facing detection turned out to be the wrong problem, and staff-facing tool use turned out to be the real one.

The detection tools didn't hold up

We piloted two AI-detection products across a handful of high school English and social studies classes. Both gave us false positive rates that our vice-principals were not comfortable defending in a hearing — one vendor's own documentation put their false positive rate at under 1%, but on tens of thousands of submissions district-wide, "under 1%" still means real students getting flagged. We had at least two cases, that I know of, where a student's own writing style triggered a flag, and staff had no confident way to rebut it beyond "the software said so." My read was that we'd be substituting one integrity problem for a due-process problem, and that trade didn't sit right with anyone in the room, including our board's legal counsel.

So we dropped detection as the primary mechanism. That decision surprised some parents on our consultation committee, who expected us to buy a tool and move on. I think it also surprised me a little, because I'd walked in assuming the policy would be built around catching AI use, and it ended up being built around disclosure — students state what tools they used and how, similar to a citation, with escalating conversations rather than escalating accusations for a first instance.

What actually mattered was the staff side

Once detection was off the table for students, the working group's attention shifted to something we hadn't planned to spend much time on: what tools teachers themselves were using to build assessments, and where that content lived afterward.

This is where it got uncomfortable. A number of teachers, entirely reasonably, had been pasting draft exam questions, IEP notes, and in a couple of cases actual student work samples into free consumer AI chatbots to get feedback or rewording help. None of that was malicious. Almost none of it was authorized either. Our privacy office got involved at that point, because student records in Canada sit under provincial education privacy law layered on top of PIPEDA considerations for anything that touches a third-party vendor, and a free consumer chatbot's terms of service are not written with a Canadian school board's obligations in mind.

That's when we started actually evaluating platforms, and that's when the Canadian AI question stopped being abstract for me. We weren't looking for a homework detector anymore. We were looking for something staff could use for legitimate, day-to-day tasks — drafting rubrics, summarizing a policy document, checking a French-language school communication — without student or staff data ending up on a server we couldn't account for.

What we actually asked vendors

The working group put together a short list of questions and sent it to four vendors, including two of the large US chatbot providers and two Canadian AI platforms, one of which was Augure.

  • Where is customer data stored, physically, and is it ever used to train the underlying models?
  • Does inference happen inside Canada, and if not, where, and under what agreement?
  • Is the vendor's parent company or majority ownership based in the United States?
  • What is the actual pathway, if any, for a foreign government to compel access to our data?
  • What does it cost per seat, and does pricing scale sensibly for a district with a few hundred staff accounts versus a few thousand?

The CLOUD Act question is the one our legal counsel would not move on. Two of the four vendors gave answers that amounted to "our data centres are in Canada," which is true and also not the same as saying the company isn't a US entity subject to US compulsion regardless of where servers sit. Augure's answer was more specific than I expected: customer conversations and documents are stored in Canada, inference for certain model tiers runs on Canadian infrastructure, with EU partners handling other tiers and serving as failover, and because no part of that pipeline touches a US-jurisdiction provider, US authorities don't have a CLOUD Act pathway to the customer content itself. They were upfront that payment processing and email delivery still touch US systems, which is a narrower and more honest answer than "everything stays in Canada," and honestly more useful for our own compliance memo because it told us exactly what to disclose rather than what to assume.

Where Law 25 came in, and where it didn't

We're an Ontario board, so Law 25 — Quebec's private sector privacy law — isn't directly binding on us. But our privacy officer used it as a reference point anyway, because a couple of the platforms we looked at, Augure included, had built their architecture around Law 25's stricter transfer-disclosure requirements, and that turned out to be a reasonable proxy for "has this company actually thought hard about Canadian privacy obligations" versus "has this company just added a Canada region to an existing US product."

Law 25 requires organizations to conduct a privacy impact assessment before transferring personal information outside Quebec, and to disclose the nature of any such transfer.

We're not a Quebec institution and that specific obligation doesn't apply to us. But the underlying discipline — knowing which flows exist and being able to name them — is what we ended up wanting from any vendor regardless of jurisdiction. Augure's privacy policy laid out the EU inference flow and the US processing for payment and email plainly enough that we could just copy the shape of it into our own memo; that's a decent filter for whether a company has actually engineered for Canadian regulation or is describing US infrastructure with reassuring language layered on top.

What ended up not mattering

One thing I expected to be a dealbreaker and wasn't: model quality for creative writing tasks. We spent an early meeting worried about whether a Canadian AI platform's models could match a large US chatbot on nuanced feedback for student essays. For the staff use case we actually approved — rubric drafting, policy summarization, internal memo writing — the difference was negligible. Augure's free tier caps at 50 messages a day, which was fine for individual teacher use; the C$20/month Pro tier removed the cap for department heads who wanted it for regular planning work. We didn't need the C$80 tier's deep research agents for anything in this policy cycle, though I could see a curriculum team wanting it later.

We also spent time debating bilingual capability that, in hindsight, was somewhat moot for our board specifically, since we're an English-language district. For a board in Quebec or a bilingual district elsewhere in the country that question would matter a great deal more, and I'd flag that as the kind of thing that looks generic in a vendor comparison sheet until it's your actual student population.

Where we landed, roughly

The final policy treats AI disclosure the way we'd treat citation of any source, keeps detection tools out of the student discipline process entirely — a decision I still think is right, though I'm not fully certain it will hold up once a harder case comes along — and gives staff an approved Canadian AI tool for internal use instead of leaving them to find their own workaround. We were not sure, going in, that "give teachers a sanctioned tool" would reduce shadow use of consumer chatbots, and I still don't have hard numbers on whether it has. That's the piece of this I'd want to revisit in a year.

If you're doing a version of this review for your own institution, the vendor questions above are close to the actual list we used, and augureai.ca has the pricing and product detail we were checking against.

A

About Augure

Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.

Ready to try sovereign AI?

Start free. No credit card required.

Get Started