Basenews
Published on 22 September 2026 par David Beauchemin, Ph. D.
Your employees are already using ChatGPT, Claude, or Copilot. Probably for months now. Driven by excitement and the urgency to test these new AI tools to achieve quick wins, things were sometimes done backwards. Nobody has decided yet whether it is permitted, structured, or risky. This is the reality for most Quebec SMEs receiving AI consulting for SMEs: the tool arrives before the policy.
This guide serves as a framework for business leaders and digital managers looking to structure AI adoption within their organization.
Here you will find the roles to define, key obligations to know, a four-phase roadmap, and the questions your managers will ask you.
Since the full entry into force of the Act modernizing legislative provisions as regards the protection of personal information, Quebec SMEs have concrete obligations. As soon as an AI tool collects, processes, or analyzes personal data (including your employees' data), the law applies. This includes meeting transcription tools, writing assistants configured with customer data, and HR performance analysis models.
Lacking a usage policy is not a gray area. It is a documented vulnerability during an audit or incident and exposes the organization to new cybersecurity risks and vulnerabilities.
Large enterprises and institutional buyers are adding AI governance clauses to their vendor contracts. It isn't universal yet, but it is coming. Having a documented framework before being asked puts you in a position of strength during RFPs.
Often, what we observe is that SMEs that adopted AI tools without structure report a recurring phenomenon: every employee works individually with personal or public licenses (which poses a major data security risk) and different tools, resulting in a loss of internal knowledge and stalling skill sharing. Data doesn't flow between platforms and expected gains fail to materialize. A manufacturing SME supported by Baseline had seven active AI tools across the organization prior to our engagement. Nobody knew which ones exchanged data. Unraveling that situation took two weeks, but it was necessary before any structured deployment.
To effectively govern AI, an SME relies on clear executive sponsorship and three key operational roles.
Essential to the success of the process, the executive sponsor provides political and strategic support for governance. Whether general management or a dedicated committee, their role is to grant the necessary legitimacy to decisions, allocate required resources, and decide on strategic directions. They bridge company vision, operational execution by the Privacy Officer, and grassroots awareness led by the adoption champion.
This role is mandatory under Law 25. In an SME, it is often held by the CEO or Administrative Director. Their AI responsibility: ensuring deployed tools comply with confidentiality obligations, personal data is not transmitted to third-party vendors without contractual safeguards, and employees understand what is collected.
This role does not require a full-time commitment, but rather a quarterly review of active tools and a clear onboarding process for new software acquisitions.
This is the person who understands the existing toolset and can evaluate new requests. In an SME of 20 to 100 employees, this role is often held by the IT Manager or Operations Director. Their function: evaluating the technical compatibility of new tools, managing access, and overseeing integrations.
The most common friction point in SMEs is that this person lacks time. This is precisely why external support absorbs the initial workload and then transfers responsibilities with documented processes.
This is not a formal position. Many organizations already have AI enthusiasts and optimists: identifying one of these convinced users and giving them a clear mandate greatly facilitates adoption by example. Ignoring this role is the main reason AI deployments stall after the pilot phase.
AI governance and Law 25 compliance intersect at several specific points.
This progression is drawn from real engagements. Timelines are indicative for an SME with 15 to 75 employees starting without a governance structure in place.
Inventory currently used AI tools, who uses them, and what data they process. Identify immediate compliance gaps. This phase often reveals surprises: tools used by employees without management's knowledge, active subscriptions on unapproved platforms, customer data entered into public models.
At the end of Phase 1, you have a list ranked by risk level. Not a complete strategy—a list.
Draft the acceptable use policy. Formally assign the three governance roles. Renegotiate or document agreements with priority vendors. Train managers on Law 25 basics applied to AI.
This phase is administrative, not technological. It may not feel flashy, but it conditions everything that follows.
Select a single high-potential, low-risk use case. Deploy the tool with your adoption champion. Measure results against a specific metric: processing time, error rate, volume handled. A professional services SME supported by Baseline reduced time spent on data reconciliation between its CRM and invoicing system by 40% during this pilot phase. This figure justified the investment for subsequent phases.
Extend validated tools to other teams. Integrate AI tool reviews into existing processes (annual reviews, new employee onboarding). Verify annual compliance against regulatory developments.
AI governance has no end date.
Several programs support Quebec SMEs in adopting AI. Eligibility criteria and funding amounts vary by fiscal year and sector.
An external advisor can help identify eligible programs and prepare applications. The time spent assembling a grant application is often recovered as soon as the first funding installment is received.
Not necessarily, but likely exposed. The risk depends heavily on the license type used (free personal account vs. enterprise license with confidentiality guarantees). If personal data was entered into a public or free model, document what was shared. Then check the platform's terms of service. Lacking a usage policy makes it difficult to demonstrate during an incident that reasonable measures were taken.
The investment varies depending on your starting point and the scope of the framework needed. External support for the initial framing phases represents a modest financial commitment, with execution phases depending on deployed tools. Based on your profile, several grant programs can cover a significant portion of incurred costs.
For drafting the usage policy and PIA of a standard project, an AI governance consultant is sufficient in most cases. However, legal counsel remains a valuable asset for in-depth legal advice. Indeed, legal intervention is strongly recommended if you process sensitive data (health, finance, biometric data) or serve as a vendor to a regulated entity.
This is the most common situation. The practical solution: external support that handles the diagnosis and drafting phase, documents processes, and trains the designated lead once the structure is in place. The goal is to absorb the initial workload while laying the foundations.
Yes. A SaaS tool that processes customer or employee personal data is subject to the same obligations. Verify where data is hosted, whether the vendor uses your data to train its models, and whether a data processing agreement is in place.
Waiting for an explicit request or new laws exposes you to higher costs and unnecessary stress. Anticipating allows you to ensure compliance, better frame AI usage, and guarantee transparency. It also legitimizes tool usage across the organization, resolving scattered employee practices while positioning you as a trusted partner during RFPs.
Generic templates exist, but a useful policy must reflect your actual tools, data types, and industry sector. Generic templates are a starting point, not a complete policy. Adapt it to your organization's real context.
Structuring AI governance in a Quebec SME does not require complex infrastructure. It requires executive sponsorship, three defined operational roles, and a documented usage policy. These frameworks protect your organization and accelerate deployments.
Your employees have already started without you. The question is no longer whether to structure, but how.