This section records the EA team's interpreted position on the Government of Canada AI platform landscape as it relates to Health Canada and PHAC operations.
This is not a summary of official strategy documents. It is internal EA interpretation intended to help distinguish what exists today, what is approved, what is experimental, and what remains unresolved.
| Capability |
Current State |
Architectural Implication |
Status |
| PATH |
Pre-prototype governance control-plane concept. NOT approved to proceed as of April 2026. |
Must not be conflated with HAIL or overstated as production capability. Convergence architecture unresolved. |
Pre-prototype |
| HAIL |
Operational AI runtime deployed March 2026. Azure Databricks + Unity Catalog. Workloads: IDP, epidemiological pipelines. |
Deployment does not resolve ATO, telemetry gaps, AI-Ops ownership, or control inheritance. |
Operational |
| Copilot-Class |
Strategically important for workforce enablement, but not equivalent to enterprise AI architecture. |
Can accelerate shadow-governance patterns if user convenience outpaces control maturity. |
Active |
| GC-Wide Services |
May be useful capability sources, but do not automatically satisfy departmental requirements. |
Assessment must focus on fit to departmental controls, not simple existence of shared service. |
Conditional |
03 · April 17 Operational Signals Preserved
Provenance note: The following signals are retained from the April 17 overview revision because they materially sharpen the intelligence layer. They are not treated as formal authority statements, but as interpreted indicators that affect architectural judgment and governance urgency.
Operational Signal: HAIL Is Real, But Not Cleared
April 17 clarified a distinction that is easy to blur in executive discussion: HAIL is operational as a delivery environment, but operational deployment does not establish production defensibility.
- Deployment complete does not equal ATO readiness
- Production pathway remains governance-gated
- Runtime maturity and control maturity are not the same thing
Architectural Signal: PATH Is Directional, Not Substitute Capacity
April 17 also made explicit that PATH should not be presented as today’s fallback landing zone for HAIL or as an operational alternative already available to projects.
- PATH remains target-state control-plane framing
- It is not yet an operational runtime answer
- Overstating PATH would weaken architecture credibility
04 · PATH: Enterprise Control Plane Architecture
PATH is defined as the target-state enterprise AI control plane for governed execution, policy enforcement, and defensible scale. It is distinct from runtime environments like HAIL.
Core Principle: Platforms consume governance; they do not define it. PATH sits above data and compute layers to enforce enterprise controls rather than replace them.
What PATH Provides
- Governed AI execution patterns
- Standardized deployment procedures
- Auditability and traceability
- Secure model/data access control
- Inherited governance baseline
- Enterprise cost allocation
Current Blockers PATH Addresses
- Fragmented deployment patterns
- Missing ingress standards
- Heavy per-project negotiation
- Absent unified governance
- Weak audit trail
- Uncontrolled shadow AI
04b · HAIL/PATH Convergence Architecture (Proposed)
Status: Proposal for ARB consideration (not approved; for governance clarity only)
Core Problem: PATH and HAIL are building in parallel without a defined integration model. This creates architectural debt and forces each new project to negotiate governance boundaries individually.
Proposed Convergence Model (v0.1 - for discussion)
Integration pathway showing current fragmentation vs. target converged state
Current State (Fragmented):
Projects → HAIL Runtime (ungoverned) ↔ PATH Control Plane (not yet operational)
↓ (governance gap)
Target State (Converged):
Projects → HAIL Runtime (Foundry workspaces)
↓ (mandatory routing)
PATH Control Plane
├─ Identity/RBAC (Azure AD)
├─ Policy enforcement
├─ Cost tracking
└─ Audit logging
↓ (inherited controls)
Data Layer (Purview + RAG governance)
Convergence Dependency Chain
- ✓ HAIL deployed (March 2026)
- ⏳ Application Insights integration → Foundry telemetry closure
- ⏳ API Management ingress standard → PATH Control Plane ready
- ⏳ Azure AD/RBAC policy templates → Inherited baseline ready
- ⏳ Purview classification enforcement → Data governance operational
Timeline Risk: FY26-27 delivery exposed if ATO path for HAIL not initiated by Q2 FY26.
Decision Required: ARB approval to formalize this convergence sequence (or propose alternative).
05 · PATH Three-Plane Architecture
Control Plane
Identity & access management, API gateway enforcement, governance policy, observability, and cost management
- Azure AD for identity / RBAC
- API Management for ingress control
- Policy engine for governance rules
- Application Insights for telemetry
- Cost allocation and FinOps
Runtime Plane
Isolated project subscriptions and Foundry workspaces with mandatory gateway routing
- Project-isolated subscriptions
- Foundry workspaces for execution
- Mandatory control plane routing
- Integrated observability
- Standardized networking
Data Integration Layer
Governed RAG pipelines, Purview-enforced lineage, and data governance
- Governed RAG for retrieval
- Purview-enforced data lineage
- Classification enforcement
- Access governance
- Audit trail integration
06 · Operating Model & Onboarding
Onboarding Target: Complete in under 5 days via standardized gates and automated controls.
Production Gates Required: Security clearance, privacy review, data science validation, EA approval, responsible AI committee sign-off.
Inherited Control Baseline (Minimum Required)
Every HAIL project onboarded through PATH must inherit these controls
| Control |
Implementation |
Owner |
| Identity & Access |
Azure AD with MFA; RBAC per Foundry workspace |
Team Lead + ARB |
| Data Classification |
Input/output data tagged with Purview classification |
Data Owner |
| Audit Logging |
All model calls logged to Application Insights; 90-day retention |
PHAC Audit |
| Cost Attribution |
Billable to project cost center; monthly reviews |
FinOps |
| Model Version Control |
Frozen model versions; traceability to training data/approval |
Data Science |
| Incident Escalation |
Governance incident triggers ARB notification |
EA / ARB |
Timeline Impact: Days 1-2 (Security/Privacy review + classification audit) → Days 3-4 (Technical onboarding) → Day 5 (EA/RAI approval + control inheritance activation). Complex projects (Protected B, new model classes) may exceed 5 days; escalate to ARB.
07 · Primary Architectural Themes
Control Plane vs Runtime
Most important distinction: environments that run AI workloads vs. governance fabric that makes them defensible.
- Runtime enables workloads
- Control plane governs workloads
- Both required for enterprise readiness
- Deployment ≠ governance completeness
Fragmentation Risk (P1 ARB)
PATH and HAIL building simultaneously without defined convergence architecture — P1 ARB escalation.
- Parallel development without integration
- Independent experimentation streams
- Weakly aligned governance narratives
- Duplication and unresolved ownership
GREP-ExP as Live Architectural Evidence
The April 17 overview correctly elevated GREP-ExP beyond project status and into architecture significance.
- Shows agentic AI in a governed PHAC context
- Demonstrates disagreement-driven workflow logic with HITL adjudication
- Provides a grounded L3/L4 capability reference for EA work
Governance Friction as Design Reality
April 17 surfaced that working-level constraints are not noise; they shape whether target-state architecture can become operational reality.
- DTB WFA slows governance documentation progress
- Cloud support drag affects delivery continuity
- Architecture must account for operating-capacity constraints
08 · Shadow AI Governance Exposure (Quantified Assessment)
CANChat (Internal Government Service)
Workforce enablement tool with scope creep and data handling exposure
- Scope: HC/PHAC internal productivity tool
- Estimated Users: ~40-60 active users (est. based on Slack adoption patterns)
- Governance Status: Deployed without formal ARB review; usage patterns not audited
- Critical Gap: Unknown classification levels of prompts; no data residency enforcement
- Risk: Scope creep — unclear boundary between approved use cases and experimental workloads
- Mitigation Path: Propose CANChat governance workstream with data classification audit
Copilot (M365 Integration)
Productivity suite integration with Protected B data residency risk
- Scope: Microsoft 365 (Word, Excel, Teams) AI assistant
- Estimated Users: ~200+ (all M365 users eligible; adoption growing)
- Governance Status: Pilot phase; no per-user audit trail; T+1 rollout planned
- Critical Gap: ATO gap unresolved; M365 Copilot not formally authorized for Protected B
- Regulatory Risk: Protected B data processed by US-based LLM (sovereignty/jurisdiction unclear; data residency not HC-controlled)
- Mitigation Path: Formal ATO required before rollout; data classification audit; consider data masking for Protected B
RADIA (Deprecated)
Legacy tool with persistent references blocking clean migration
- Scope: Legacy Analytics and Decision Intelligence Architecture (deprecated 2025)
- Current Exposure: Tool deprecated but references persist in documentation and Foundry workspaces
- Governance Status: No sunset migration plan; teams may still rely on cached outputs
- Impact Scope: Unknown; requires audit of Foundry artifacts and process documentation
- Mitigation Path: Deprecation audit — identify teams still using RADIA outputs; provide Databricks migration path
Governance Exposure Patterns (Summary)
Shadow AI creates invisible control gaps that compound over time
- Workloads deployed without ATO/ARB review (CANChat, Copilot pilots)
- Deprecated tools still referenced as current (RADIA)
- Classification boundaries crossed (Protected B data in US-based LLMs)
- Audit traceability absent (no per-user model call logging)
- Data residency assumptions misaligned with regulatory requirements
09 · Enterprise Implications for HC / PHAC
ARB Focus Areas
ARB value highest where it clarifies enterprise boundaries and readiness
- What is enterprise vs. project-specific
- What is approved vs. experimental
- What is production-ready vs. not defensible
- What dependencies block scale
Data Governance as AI Control
AI readiness depends on whether data can be governed, classified, traced, and justified
- Classification consistency
- Lineage and traceability
- Protection and access governance
- Defensibility for AI use cases
Purview-PATH Integration Roadmap
Operational pathway for automated data governance in HAIL workloads
- Classification Enforcement: Purview classification tags → Policy engine (PATH) → Foundry access control. All model inputs must have classification tags; outputs tagged automatically.
- Data Lineage Tracking: HAIL workload → Purview lineage metadata → audit trail. Query: "Show all Protected B data touched by epidemiological pipelines" = automatic lineage graph.
- Incident Response: Governance incident (e.g., unclassified data fed to model) → Purview alert → ARB escalation
- Current State: Purview metadata catalog exists (partial coverage); classification standard in draft (Protected A/B/C incomplete); no automated enforcement yet
- Implementation Timeline: Target Q3 FY26 (dependent on Purview metadata completeness and PATH readiness)
10 · Open Questions & Governance Gaps
| Question |
Why It Matters |
Owner |
Status |
| HAIL / PATH Convergence |
Building simultaneously without convergence model. P1 ARB item. |
ARB / OCDO / CIO |
Escalated |
| Fabric vs. Databricks |
Fabric position explicitly unresolved; HAIL confirmed on Databricks + UC. |
ARB / CIO |
Open |
| Application Insights Gap |
Foundry telemetry insufficient for audit without App Insights. Active EA flag. |
ARB / Security / Audit |
Open |
| AI-Ops Ownership |
No defined ownership, support tier, or cost model. Blocks sustainability. |
CDO / CIO / DTB |
Open |
| Inherited Control Baseline |
Scale requires minimum controls rather than repeated project negotiation. |
ARB / Security / CDO |
Open |
| Production ATO Path for HAIL |
Operational runtime without an initiated ATO path leaves FY26-27 delivery exposed to governance stall. |
CDO / CIO / ARB |
Open |
| Working-Level Capacity Drag |
Documentation and cloud support slowdowns can delay architecture socialization and implementation readiness. |
DTB Delivery / CDO |
Open |
12 · FY26 Governance Milestones & ARB Decision Points
Critical Path Timeline: Risk exposure increases with each delayed milestone. Monthly ARB steering reviews recommended June-September 2026.
| Date |
Milestone |
Decision Required |
Risk if Missed |
| Q1 (Apr-Jun) |
HAIL/PATH convergence model approved by ARB |
Proceed with convergence sequence or propose alternative |
Parallel development continues; duplication & rework |
| Q2 (Jul-Sep) |
Production ATO path for HAIL initiated |
Formal ATO workstream started with Security/Privacy |
FY26-27 delivery stalled; workloads remain ungoverned |
| Q2 (Jul-Sep) |
CANChat governance audit completed |
Scope definition & data classification baseline |
CANChat usage accelerates uncontrolled |
| Q3 (Oct-Dec) |
Copilot ATO completed; M365 rollout approved |
Data residency/jurisdiction posture confirmed |
Protected B data exposed to US-based LLM |
| Q3 (Oct-Dec) |
Inherited control baseline tested (2-3 pilot projects) |
Verify 5-day onboarding achievable |
Scaling blocked; per-project negotiation persists |
| Q4 (Jan-Mar) |
Purview-PATH integration operational |
Automated classification enforcement live |
Manual data governance continues; governance debt compounds |
Escalation Path: If any Q1/Q2 milestone missed, governance debt compounds. Recommend ARB steering committee monthly reviews June-September 2026.
13 · Local Inference Capability: Privacy-First Intelligence Analysis
Operational Signal: New intelligence analysis capability deployed April 2026. Supports privacy-compliant document analysis without external API dependencies.
What Changed:
The intelligence page editor now includes browser-based LLM analysis using Transformers.js (Hugging Face). Imported documents (text, markdown, images) are analyzed locally in the browser—zero external API calls. Uses DistilBERT for relevance assessment and DistilBART for key insights extraction.
Technical Architecture:
User imports document
↓
LocalLLMAnalyzer loads models (first run: ~300MB to browser cache)
↓
Transformers.js inference runs in-browser via WebAssembly
↓
Analysis output: Relevance, Key Insights, Incorporation Approach
↓
User approves → content integrated into intelligence page
Privacy & Compliance Implication:
- No data leaves the browser: All analysis runs locally; nothing transmitted to Anthropic, Hugging Face, or external analytics.
- No retention risk: No cloud vendor data retention concerns.
- Compliant with PIPEDA / Protected B: Can analyze sensitive government content without external transmission.
- Fully offline-capable: After initial model download, works without internet connection.
Architectural Significance:
This signals a shift toward local-first intelligence workflows for government. Instead of sending governance content to external LLMs, models are pulled to the client once, analysis happens locally, and only approved content flows to version control. Data residency = user's machine.
Why it matters:
- Removes barrier for Protected B / sensitive governance analysis.
- Enables privacy-compliant document review at source without vendor vetting.
- Reduces operational friction for EA intelligence updates (no API key management).
- Model cache persists—subsequent analyses are instant.
Trade-offs:
| Benefit / Constraint |
Implication |
| ✅ Zero external API dependency |
No vendor lock-in or compliance review needed. |
| ⚠️ First use requires model download (~300MB) |
5-10 min initial load; cached for instant subsequent use. |
| ⚠️ Inference slower than cloud API |
Local CPU/GPU vs. dedicated servers; acceptable for intelligence workflow (not real-time). |
| ℹ️ Browser memory usage: ~500MB-1GB |
Requires modern browser; clear models after use if memory-constrained. |
Operational Impact for EA Intelligence:
- Intelligence officers can import governance documents without API vendor compliance review.
- Faster iteration on intelligence drafts (no API key management, no rate limits).
- Can operate in air-gapped environments after initial model cache.
- Supports workflow: Import → Analyze locally → Review → Publish to GitHub.
Architectural Implications:
- Local model inference is viable alternative to cloud LLM for enterprise document analysis.
- Opens path for on-device RAG (Retrieval-Augmented Generation) of governance policies.
- Precedent: local models can handle enterprise confidentiality concerns without architecture review.
- Aligns with HAIL/PATH convergence (04b): reduces dependency on external cloud services for governance workflows.
Next Steps:
- Compliance validation: Engage privacy team to formally approve local analysis approach for Protected B workflows.
- Expand model coverage: Evaluate larger models (LLaMA, Mistral) if compute available, for deeper analysis.
- Document caching strategy: Ensure model cache behavior is audited and predictable.
- Off-device scenarios: If intelligence work moves to shared terminals, validate data isolation.
Recommendation: Local inference removes key barrier to privacy-first intelligence operations. Formal compliance approval unlocks Protected B governance analysis workflows without vendor dependencies.
14 · Document Update Log
2026-04-21
Consolidated Intelligence (v1.3 - Local Inference Capability): Added Section 13: Local Inference Capability (Transformers.js / Hugging Face). Intelligence page editor now supports privacy-compliant document analysis without external API calls. Deployed browser-based LLM inference (DistilBERT + DistilBART) for imported content assessment. Zero data transmission to external vendors; compliant with Protected B / PIPEDA workflows. Recommendation: formal compliance validation for Protected B intelligence analysis.
2026-04-20
Consolidated Intelligence (v1.2 - Draft for ARB Review): Added HAIL/PATH convergence model (v0.1) for governance clarity; explicitly noted as proposal pending ARB decision. Quantified shadow AI vectors: CANChat (~40-60 users, data handling unclear), Copilot (~200+ users, Protected B ATO gap critical), RADIA (deprecated but references persist). Defined inherited control baseline for HAIL onboarding (6 controls: identity, classification, audit, cost, versioning, escalation). Extended data governance with Purview-PATH integration roadmap (target Q3 FY26). Added FY26 governance milestones and escalation risk timeline; highlighted Q1-Q2 ARB decision points as critical path.
2026-04-19
Consolidated Intelligence (v1.1): Preserved selected April 17 overview signals inside the intelligence layer rather than the dashboard layer. Added provenance note, operational interpretation that HAIL deployment does not equal production clearance, explicit caution that PATH is not current substitute capacity, GREP-ExP reframed as live architectural evidence, and working-level delivery friction captured as a governance-relevant operating constraint.
2026-04-19
Consolidated Intelligence (v1.0): Merged platform landscape analysis with PATH architecture documentation. Added: three-plane system detail (Control, Runtime, Data Integration), operating model with 5-day onboarding target, enterprise positioning vs. HAIL, strategic maturity assessment. Consolidated shadow AI vectors (CANChat scope creep, Copilot ATO gap, RADIA deprecated references) and fragmentation named as P1 ARB item with specific PATH/HAIL convergence framing.
2026-04-17
Initial Intelligence Page: Established interpretation boundary, positioned PATH as target-state control-plane direction, positioned HAIL as runtime-significant but not equivalent to full governance resolution, and identified fragmentation and operating model clarity as main architectural concerns.