AI Platform for Building Custom Chatbots and Agents
Inform
What it collects
- Data files from SharePoint, Dataverse, Azure Search, the internet, and user-uploaded files selected by the chatbot or agent builder as the knowledge base. No personal information is involved per the register.
- User queries and interaction inputs typed into chatbots and agents built on the platform. The register states no personal information is involved.
- Run by
- Global Affairs Canada (GAC)
- Where
- No fixed location
- Kept
- Not stated by the Helpful Places.
- Shared with
- Accountable organization
- Your copy
- You cannot see the data it holds about you. What you can do
What it is for
Copilot Studio is a platform used by Government of Canada employees at Global Affairs Canada to build, manage, and deploy their own AI-powered chatbots and agents using internal data sources. Users connect knowledge bases — such as files from SharePoint, Dataverse, or the internet — to create conversational tools that can be deployed on SharePoint, Microsoft Teams, or as standalone apps. The system does not involve personal information, and users are informed when they are interacting with AI.
What it collects and what happens to it
Data taken in
- Data files from SharePoint, Dataverse, Azure Search, the internet, and user-uploaded files selected by the chatbot or agent builder as the knowledge base. No personal information is involved per the register.
- User queries and interaction inputs typed into chatbots and agents built on the platform. The register states no personal information is involved.
Processing
- Large language models underlying the Microsoft Copilot Studio platform, used to power the chatbots and agents that read, interpret, and respond in natural language based on configured knowledge bases.
- Retrieval from connected data sources — SharePoint, Dataverse, Azure Search, internet, and uploaded files — to ground agent and chatbot responses in relevant content.
What it does
- Copilot Studio enables users to build agents that plan and carry out multi-step tasks, call tools, and compose workflows on behalf of GC employees. Humans initiate and review actions; the agents execute steps within user-defined parameters.
- Chatbots built on Copilot Studio understand and retrieve meaning from connected knowledge bases — matching user questions to relevant content from SharePoint, Dataverse, Azure Search, or uploaded files.
- The chatbots and agents produce new conversational text responses grounded in selected knowledge bases and data sources.
Outputs
- AI-generated conversational text responses delivered to GC employees through SharePoint, Microsoft Teams, or standalone and integrated apps.
Run by
- Global Affairs Canada is the federal department deploying Copilot Studio to enable GC employees to build and use AI-powered chatbots and agents.
Government of Canada AI Register — Copilot Studio (2526-GAC-AMC-015)
Built by
- The register lists the Government of Canada as the developer; the underlying platform is Microsoft Copilot Studio, a low-code AI development environment provided by Microsoft.
Government of Canada AI Register — Copilot Studio (2526-GAC-AMC-015)
Kept for
Not stated by the Helpful Places.
Shared with
- Outputs from the deployed chatbots and agents are available to GC employees within Global Affairs Canada using the respective SharePoint, Teams, or app deployment. The register indicates no personal information is collected or retained.
- Members of the public do not have access to the chatbots and agents built on this platform. The system is restricted to GC employees at Global Affairs Canada.
Stored
Not stated by the Helpful Places.
How to read the colours
Can it identify you?
- Anonymized data
- Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
- Pseudonymous data
- Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
- Identifiable data
- The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.
Who completes the loop?
- Human decides
- This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
- Human executes
- This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
- Autonomous
- This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.
Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.
- AI registerGovernment of Canada Algorithmic Impact Assessment Register — Copilot Studio (2526-GAC-AMC-015)Global Affairs Canada, Government of Canada AI Register entry 2526-GAC-AMC-015.
- AI registerGovernment of Canada AI Register — Copilot Studio (2526-GAC-AMC-015)
- AI registerGovernment of Canada AI Register — Copilot Studio (2526-GAC-AMC-015)
- Register entryPublished by the Helpful Places. Reference 1cbe71cb. This disclosure was drafted with AI assistance.Schema: ai@2026-05-06-beta
What you can do
Ask about this system
Questions go to the Helpful Places, not the vendor.
Your rights
- Right to Be Informed of AI UseGC employees are informed when they are interacting with an AI system. The register confirms that AI use is disclosed to users.
- Right to Algorithmic TransparencyThe system is listed on the Government of Canada's public AI register, providing transparency about how Copilot Studio works, what data sources are used, and who is accountable. Contact Global Affairs Canada for further information.
Risks and safeguards
- Societal & cultural harmAI-generated responses may contain inaccuracies, misinformation, or culturally inappropriate content depending on the knowledge bases selected by individual builders.Safeguard: The platform is restricted to GC employees; users are informed of AI use; the citizen-led development model means builders are responsible for the quality and appropriateness of their own knowledge bases and agent configurations.