Skip to main content

Year 1 of an AI Governance Program at a Medium-Sized Local Public Health Unit

·9 mins

AI governance has to work within the organization that actually exists. Wellington-Dufferin-Guelph Public Health (WDGPH) is a medium-sized local public health unit in Ontario, with approximately 200 staff serving about 350,000 people. Most of our staff work in public health nursing, inspection, health promotion, and other program areas.

We began formalizing governance while staff were already experimenting with AI and several projects were moving into production. Our first year focused on making governance workable in this environment: setting strategic direction before adding rules, extending processes the organization already trusted, and using an established framework while keeping our own values and obligations at the centre.

This article is adapted from a presentation delivered on July 21st in Montreal at the 2026 AI4PH Summer Institute.

Create strategy before rules #

WDGPH had already committed to innovation and sustainability through its organizational strategic plan. Before creating new governance rules and processes, we needed to translate those broad commitments into a specific direction for AI.

We reviewed several AI maturity models and took an honest look at where we were. At the beginning of this work, we were doing a lot of experimentation, had developed some implementation capacity, and were moving a few AI projects into production. Our goal was to move closer to a point where we had looked more comprehensively at public health functions and how they could be redesigned with AI.

To work on getting there together, we developed four strategic priorities for low to medium-risk AI work between 2025 to 2028.

PriorityDirection
Strong foundationsStrengthen data governance, establish AI governance, and develop staff capacity to provide oversight and promote quality in AI systems.
Targeted automationPrioritize repetitive tasks so staff can focus on higher-value work such as planning, quality improvement, client communication, and scaling services during periods of high demand.
Maximize the value of data assetsUse AI to transform unstructured information into structured data and extract data from legacy systems. Centralize data in secure, governed infrastructure that supports access controls, lineage, quality monitoring, and responsible reuse.
Capability and alignmentAdvance responsible innovation through learning and partnerships, and share practices that promote consistency and quality across public health units.

Strong foundations means putting the governance, infrastructure, and staff capacity in place before AI becomes deeply embedded in day-to-day work. For us, this includes strengthening data governance, establishing clear processes for reviewing and documenting AI uses, and ensuring that staff in key oversight roles have enough knowledge to assess privacy, security, accuracy, reliability, and impact. It also means building technical environments where sensitive data can be handled appropriately and where AI systems can be monitored and improved over time. The goal is ensure that the organization has enough distributed knowledge and accountability to use AI responsibly and maintain quality as adoption grows.

Targeted automation means being intentional about opportunities that allow staff to shift time to higher-value work and improve the capacity of the health unit overall. It does not mean inserting generative AI into every workflow.

Maximizing the value of data assets includes working with information contained in audio, images, and documents, as well as getting data out of legacy systems and into modern, centralized data infrastructure. This priority built directly on earlier data-governance work in which we had already mapped many of our organizational data assets.

The final priority reflects the reality that local public health units have limited technical capacity when working alone. We want to collaborate with public health peers and academic partners, share what we learn, and improve quality across the public health system rather than only within our own organization, and that’s part of the reason this website, phiz.ca, exists.

This AI strategy gave us enough direction to begin making governance decisions against an agreed set of priorities.

Extend what already works #

The next step was to identify supportive elements that already existed inside the organization. We looked at three areas: how we educate and engage staff, which committees and assessment processes could take on AI-related work, and where new expectations should be documented.

Education and staff engagement #

In the first year, we held three all-staff town halls on AI. These ranged from introducing responsible AI, to showing examples of AI in practice, to openly challenging staff to identify new opportunities in their work.

We also grew an internal AI community of interest to more than 30% of all staff. We use it to share AI articles that have public health relevance, and learning opportunities.

Many staff individually pursued further AI education including short courses hosted through the AI4PH training platform.

Committees and assessment processes #

The largest structural change was expanding our existing Data Governance Committee into a Data and AI Governance Committee. We chose this rather than creating a separate AI governance committee. The existing committee already had cross-functional representation and responsibility for data-policy decisions. AI governance became a second implementation stream with a co-chair arrangement.

We also began including progress on the AI portfolio in regular executive and Board of Health briefings (for instance, in our December 2025 Board of Health Report - Data & AI Governance).

Other existing committees and assessment processes continue to handle the parts of responsible AI that already fall within their mandates. These include:

  • research ethics review;
  • code review for accuracy, reliability, and maintainability;
  • privacy impact assessments;
  • IT threat risk assessments; and
  • quality and impact assessment.

A new AI application can flow through a privacy impact assessment in much the same way as another application. The process may need new questions, and the staff involved need enough knowledge to recognize AI-specific issues, but the underlying privacy function is not new.

Some gaps did require new work. In particular, we developed impact-measurement tools and resources specifically for AI initiatives. The aim is to assess more than whether a tool functions technically. We also need to look at its use, quality, intended benefits, possible harms, and equity impacts.

Policies and guidance #

Where appropriate, we codified expectations in agency documentation. Two early examples were an updated acceptable AI use and access policy and a guidance document on balancing environmental responsibility with AI use.

We have shared these documents with several peer public health units. They will need regular updates as the technology changes and as we learn from implementation. We have tried to keep durable organizational expectations in policy while leaving more changeable operational details in guidance and assessment tools.

Use established frameworks, but remain critical #

There are already resources available to support a reasonably comprehensive approach to AI governance. We did not need to invent a framework ourselves.

After reviewing alternatives, we selected the U.S. National Institute of Standards and Technology AI Risk Management Framework (NIST AI RMF). It is vendor-neutral, voluntary, and designed to be usable across organizations and types of AI systems.1 We chose a staged implementation rather than attempting to implement every part at once.

We began implementing the AI RMF in phases and later learned that NIST was revising it.2 Some of the proposed changes appear to reflect political direction rather than developments in AI. In particular, the July 2025 U.S. AI Action Plan directed NIST to remove references to misinformation, diversity, equity and inclusion, and climate change.3

One reason version 1.0 has been practical for us is that it explicitly covers widely recognized areas of concern and sensitivity. Removing those references makes the related risks easier to overlook.

At the same time, no framework can supply an organization with its values. Organizations have to decide what constitutes harm, which risks matter in their context, and what obligations they have to the people affected by their use of AI.

WDGPH’s existing strategic plan is already explicit about our organizational values: accountable, adaptable, collaborative, compassionate, equitable, innovative, and trustworthy.4 Those values align closely with many of the responsible AI frameworks we reviewed. We did not feel that we needed to write a separate set of AI values. Equity remains an organizational value whether or not a future NIST framework names it.

Mapping our first year to the NIST AI RMF #

The NIST AI RMF is organized around Govern, Map, Measure, and Manage. These functions gave us a useful way to check the work completed during the first year and identify what was missing.

FunctionFirst-year activity at WDGPH
GovernDevelop an AI registry, update documentation, prepare public disclosure, and communicate regularly with staff, executives, and the Board of Health.
MapSurvey staff to understand current use, capability, concerns, and support needs. Identify intended benefits, data sensitivity, and the risk associated with decisions or outputs.
MeasureDevelop an Impact Assessment Plan with baseline and pre/post measures covering activity, quality, benefits, harms, and equity impacts.
ManageDetermine where AI can run based on data sensitivity and scale human oversight and other controls to the consequences of the output.

We developed an internal AI registry that records the type of technology and how it is deployed. We later expanded it to include expected benefits, risks, data sensitivity, and the potential impact of system decisions or outputs. This made the registry more useful than a simple inventory of tools.

We also ran an all-staff survey to understand how staff were using AI in their day-to-day work, their current knowledge, their concerns, and the supports they felt would be useful. The findings helped populate the registry and gave the Data and AI Governance Committee information to use when planning education and other supports.

Our Impact Assessment Plan was created to evaluate AI initiatives against their stated goals. Depending on the project, this can include baseline and follow-up measures related to activity, output quality, time, benefits, harms, and equity. We are still early in applying this consistently across projects.

We also began applying proportionate controls. Where an AI system can run depends partly on the sensitivity of the data it uses. The amount of human review and validation depends partly on the consequences of its output. A low-risk drafting tool and a system that influences a decision about an individual should not follow the same path.

This work informed a major year-two investment: expanding local AI inference capacity so that sensitive data can be used in AI workflows without leaving our network for an external inference provider.

Where we are after year one #

This is still an early account. We can point to the structures we created, the staff we reached, the projects entered in the registry, and the assessment tools we developed. We cannot yet claim that the program has reduced AI-related harms, that intended benefits have been achieved across the portfolio, or that every governance process is proportionate.

The next stage is to apply these processes consistently, evaluate whether they are useful, and adjust them when they create unnecessary work or fail to identify important risks. We also need better evidence from individual AI projects about whether they improve quality, capacity, access, or other intended outcomes.

For a similar public health organization, my advice from the first year is to set an AI strategy before writing a large set of rules, look closely at the internal processes that already work, and use established frameworks to structure the work. Remain critical of those frameworks, particularly as they change, and keep organizational values and obligations in front of the program.


  1. National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0). 2023. https://doi.org/10.6028/NIST.AI.100-1 ↩︎

  2. National Institute of Standards and Technology. AI Risk Management Framework. https://www.nist.gov/itl/ai-risk-management-framework ↩︎

  3. The White House. America’s AI Action Plan. July 2025. https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf ↩︎

  4. Wellington-Dufferin-Guelph Public Health. Strategic Plan 2024-2028. https://wdgpublichealth.ca/about-us/strategic-plan ↩︎