
The question we get most often in the public sector is whether a given technology is allowed. It is the wrong question. Under the frameworks now governing the use of artificial intelligence in Quebec, the same model, from the same vendor, inside the same secure environment, can be perfectly compliant in the morning and require months of approval in the afternoon. What changes between the two is not the technology. It is the category your tool falls into.
Two ways to do exactly the same thing
Take a team that writes administrative documents all day long. It already has an office suite with a built-in AI assistant, paid for, deployed and approved by the organization. Two paths open up.
The first: each person opens the assistant in their own session, pastes their text and asks it to structure, rephrase, clarify. The second: you configure one assistant once and for all, with the right instructions and the right reference documents, and you make it available to the team. Same tool, same vendor, same environment. The second is visibly cleaner and more repeatable.
And the second is precisely the one that triggers an approval regime.
The threshold is configuration, not sharing
The frameworks in force draw a line between the secure conversational assistant, meaning the tool used as is by one person in their own session, and the specialized system, meaning an assistant that has been configured for a given service. The first is allowed outright. The second calls for an impact assessment and a review committee.
The word that matters is configured. Plenty of teams assume the tipping point is sharing, or volume, or how sensitive the data is. It is not. Simply saving an assistant with its instructions is enough, even if it stays private, even if only one person uses it, even if it never sees a single piece of personal information.
Almost everyone learns this after building.
The option that looks simplest is the most regulated
When the options go on the table in front of a management team, there are three of them.
- The kit alone. No saved agent. The person loads a set of instructions and reference documents into their own session. Compliant today, with no prior process.
- The de-identified agent. A configured assistant, fed only with extracts stripped of direct identifiers. Compliant, but an impact assessment has to be produced and the committee has to be cleared.
- The agent that receives the full file. The most comfortable for the person using it, the heaviest on the regulatory side: personal information inside a specialized system, so an approval to obtain and consent at every single use.
Almost every team instinctively ranks the third option as the simplest. It is, for the person using it: you paste the whole file and there is nothing to prepare. That is exactly what makes it the most regulated. The preparation work you think you are avoiding is precisely what keeps the project inside the permissive category.
Put differently: the second option requires an analysis to produce, the third requires a decision to obtain. Those are not the same delay, and the second one is not yours to control.
What we delivered instead
On a recent mandate at the complaints and quality of service commissioner's office of Santé Québec Capitale-Nationale, the client wanted a configured agent. We recommended not building it.
Instead, a writing kit: one tested set of instructions and four reference documents the person loads into their own session. The official templates and the standard paragraphs live in the documents, not in the instructions. And no identifier ever enters the tool: name, address and file number are merged in afterwards in the word processor, outside the AI.
Same gain for the team, usable the following week, no approval gate to clear.
Why this delays nothing
The objection that follows is fair: are we not just postponing the real project?
No, because the kit is the configuration. The day the impact assessment and the committee are done, that set of instructions and those documents become the official agent, near enough as they stand. Nothing is thrown away. We simply separated what needs authorization from what does not, and delivered the second part right away.
There is a useful side effect. Putting the templates in documents rather than in the instructions means a change to a letter template is handled by replacing one file. No consultant to call back. It is counterintuitive to build it that way when you are the vendor, and it is the argument that reassured the client most.
What to take away
Before choosing an AI tool in a regulated environment, one question comes before all the others: what category does this put us in? Not which model, not which vendor, not which hosting. The category.
This holds well beyond health care. Quebec's Law 25 works on the same logic: your obligations are not triggered by the tools, they are triggered by what you do with the information and how you structure the processing. A project that asks the question up front ships in weeks. A project that discovers it at the end waits months.
The good news is that there is almost always a way to deliver the gain right away without triggering the approval gate. You just have to have looked for it before you start building.
Working in a regulated environment and wondering what category your project falls into? Book a 30-minute exploratory call.


