Making AI Safe to Scale: A Framework for Responsible AI Adoption

Adapted from a presentation made at the Ontario East Municipal Conference (OEMC), September 2026.

Not long ago, AI in most organizations meant a handful of people trying something new — testing a tool, seeing what it could do, treating it as a side experiment. In a few short years, there's been a dramatic shift from one-off experimentation to a push for whole-of-organization adoption.

What we're seeing is that AI adoption rarely happens in one neat, predictable way. There are varying levels of comfort, interest, and reluctance across individuals and teams — which makes sense. AI brings real opportunities for innovation and efficiency, but if it isn't brought in thoughtfully, those opportunities can just as quickly turn into threats.

However far along any one organization is, the direction is clear: AI isn't going away. Vendors are building it into the tools already in use. Staff are finding and adopting tools on their own, with or without formal approval. New capabilities keep arriving faster than most organizations can formally evaluate them.

The question I see in front of us now is: How do we take advantage of new technology while protecting accountability and the people we serve?

For me, the answer starts with trust. Every organization runs on it — the confidence that clients, members, donors, employees, or the public have that you'll handle what's entrusted to you responsibly. Increasingly, what's entrusted to you is information: how you collect it, use it, and act on it.

Interlocking puzzle pieces demonstrating how privacy, accountability, governance and resilience work together to strengthen trust

That trust takes time to build (and maintain) — and AI, because it runs on information, is one of the clearest tests of it right now.

Trust isn't the product of a single policy or decision. It's built over time, through a handful of interconnected practices working together: privacy, accountability, governance, and resilience. Individually, each matters. Together, they form a working framework for adopting AI responsibly, with trust at the center of the decision rather than an afterthought to it.

Privacy: what information is AI touching?

A practical place to start is by really understanding how information is moving through your organization. One of AI's biggest advantages is its ability to gather and work with large amounts of information at once — it opens up new ways for data to flow through an organization. The challenge is that AI moves so much faster than we do. Without the right guardrails in place, this can show up as collecting more information than is necessary, different systems unknowingly sharing personal information, or decisions being generated about people without their knowledge or consent.

When considering a new AI tool or use case, ask:

  • What information is being collected? What are we comfortable/not comfortable with?

  • What can the tool access?

  • What new information does it generate?

  • Where does that output end up?

Practical step: Start a shared documentation practice with your team. You can use a shared document, a spreadsheet or form, whatever's easiest to use and access, and use it to answer these four questions when evaluating a new AI tool or use case.

As we work through accountability, governance, and resilience below, add to this practice to eventually create a central knowledge bank to refer back to when making AI decisions.

Accountability: who remains responsible?

A common assumption is that when AI is involved, responsibility shifts to the tool or the vendor. It doesn't. AI can gather information, analyze it, and generate a recommendation — but the accountability for what happens next stays with the people using it. That matters even more once AI starts influencing decisions or communicating on an organization's behalf.

Nobody thinks much about accountability when things are going well. The real test is what happens when something goes wrong:

  • Who reviews the output for accuracy?

  • Who approves the final version?

  • Who owns the result?

  • Who can explain it if it's challenged?

When there's no clear answer to those questions, the gap doesn't stay internal — it surfaces publicly, and it's the kind of gap that erodes trust quickly.

Practical step: Ensure a human-in-the-loop policy is in place for all AI-supported work. This keeps people with the right skills and experience at the center of review, approval, and ownership of outputs, even as AI takes on more of the groundwork. Note who that person is in your AI documentation practice.

Governance: how do we make decisions as AI evolves?

This is where things can get complicated. Most governance structures were built for a slower pace of change — a world where new situations came up occasionally and there was time to deliberate. AI doesn't move at that pace. New use cases and capabilities show up faster than most approval processes were designed to handle, which creates real tension between oversight and the practical need to make decisions.

The way through isn't to slow AI down or to skip governance. The mechanism doesn't need to be a formal committee for every decision. At a more formal level, leadership sets the boundaries — what counts as low-risk, what needs a second look, and who has authority to approve what. Within that framework, most day-to-day decisions can be made operationally: whoever owns the tool or process works through a short set of questions before saying yes, and writes down the answer. Anything that falls outside those boundaries — sensitive information, external communication, decisions about people — gets escalated. That's what keeps decisions consistent without slowing everything down. When someone wants to use AI in a new way, three questions do most of the work:

  • Who decides?

  • What risks does this introduce?

  • How does the decision get documented?

Practical step: The documentation practice you've started is doing the work here. Add the answers to these questions to ensure governance considerations are included. Over time, it builds toward the central knowledge bank that doesn't live in any one person's head, and it makes each new decision a little easier than the last.

Resilience: what happens when things don't go as planned?

If we've learned anything over the past few years, it's that change is the new normal. With AI, change can happen in several ways — the technology itself changes, vendors change, processes change, and sometimes something simply goes wrong.

Resilient organizations assume problems will occur, and they prepare for them. With AI:

  • What's in place if an output turns out to be wrong?

  • What's in place if the tool changes or becomes unavailable?

  • What's in place if this decision is questioned publicly?

Practical step: Start a habit of short "what if" discussions as part of a regular team meeting, working through one scenario at a time, finding the gaps before an incident happens and noting the solutions in your documentation.

Bringing It Together

By now, you've got the start of a documentation practice that ties it all together — a single place to point to when someone asks how an AI decision got made.

Technology will keep changing. New tools and vendors will emerge. New use cases will present themselves, probably faster than expected. You won't have all the answers before you start implementing, but you can create the conditions for responsible adoption by thinking intentionally about privacy, accountability, governance, and resilience.

That's ultimately where trust comes from — not because an organization simply asks people to trust it, but because it can show that it has taken the time to ask the right questions, make informed decisions, and put appropriate safeguards in place.

Next
Next

Feeling the strain? How to reset your organization without starting over