Skip to content
This is NOT an official site of the Government of Canada. Click here for the official AI registry.

AI-Assisted Code Generation for Government Developers

Education & Learning

What it collects

Operational data
Anonymized data
  • Source code from PSC's internal code repository is provided as context to GitHub Copilot at runtime. This is operational/administrative data describing how software systems are built, not personal information about individuals.
Run by
Public Service Commission of Canada (PSC)
Where
No fixed location
Kept
Retained Not specified in the register entry
Shared with
Accountable organization, Vendor

What it is for

GitHub Copilot is a Microsoft AI tool integrated into the coding environments used by developers and data specialists at the Public Service Commission of Canada. It helps them write software faster by generating code suggestions, reviewing code quality, and providing guidance during application development. As of mid-2025, it has been deployed to a limited number of staff on a pilot basis to evaluate its value relative to its cost. No personal information about members of the public is processed by this system.

What it collects and what happens to it

Data taken in

Operational data
Anonymized data
  • Source code from PSC's internal code repository is provided as context to GitHub Copilot at runtime. This is operational/administrative data describing how software systems are built, not personal information about individuals.

Processing

Language Models
  • GitHub Copilot is built on large language models (LLMs) trained on code and natural language. It predicts and completes code tokens based on the developer's input and surrounding context.

What it does

Creating (Generative AI)
Human decides
  • GitHub Copilot generates new code — boilerplate, completions, and suggestions — in response to developer prompts within the IDE. Developers review and decide whether to accept, modify, or discard each suggestion.
Understanding (Semantic AI)
Human decides
  • GitHub Copilot understands the context of existing code in the repository and the developer's current file to ground its suggestions. It retrieves relevant patterns and intents from the codebase to inform completions.

Outputs

Generated content
Anonymized data
  • GitHub Copilot produces generated code suggestions, boilerplate code, code-quality reviews, and miscellaneous development guidance. This content did not exist before the system ran and is created in response to developer prompts.

Run by

Public Service Commission of Canada (PSC)
  • The Public Service Commission of Canada is the federal institution that has deployed GitHub Copilot to its developers and data specialists on a pilot basis to accelerate application development.

Government of Canada AI Register — GitHub Copilot (2526-PSC-CFP-003)

Built by

Microsoft
  • Microsoft is the vendor that supplies GitHub Copilot as a licensed offering. The system is developed and maintained by Microsoft and integrates into developer IDEs.

Government of Canada AI Register — GitHub Copilot (2526-PSC-CFP-003)

Kept for

Retained Not specified in the register entry
  • The register does not specify retention periods for code inputs or generated outputs. Retention terms are likely governed by PSC's standard data management policies and the Microsoft licensing agreement.
  • Duration: Not specified in the register entry

Shared with

Available to the accountable organization
  • Code suggestions and outputs generated by GitHub Copilot are available to the PSC developers who use the tool within their IDE sessions. The accountable organization (PSC) has access to usage and licensing data through its Microsoft agreement.
Available to vendor
  • As the supplier of GitHub Copilot, Microsoft may have access to telemetry, usage patterns, and prompts submitted through the tool, subject to the terms of the licensing agreement between PSC and Microsoft.

Stored

Stored on 3rd Party Cloud
  • GitHub Copilot is a cloud-hosted Microsoft service. Code context submitted to the model and any generated outputs are processed on Microsoft's cloud infrastructure. Specific storage jurisdiction details are not provided in the register entry.
  • Duration: Not specified in the register entry
How to read the colours

Can it identify you?

Anonymized data
Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
Pseudonymous data
Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
Identifiable data
The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.

Who completes the loop?

Human decides
This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
Human executes
This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
Autonomous
This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.

Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.

What you can do

Ask about this system

Questions go to the Helpful Places, not the vendor.

Your rights

  • Right to Be Informed of AI UsePSC has disclosed that AI is in use in this system (AI use disclosed to users: Y). GC employee developers using the IDE are informed that GitHub Copilot AI is active and generating suggestions within their workflow.
  • Right to Algorithmic TransparencyInformation about how GitHub Copilot works is publicly available through Microsoft's product documentation. PSC's registration of the system in the Government of Canada AI Register provides additional transparency about its deployment context and purpose.

Risks and safeguards

  • Reputational harmGitHub Copilot may generate incorrect, insecure, or low-quality code that, if deployed without review, could undermine the quality and reliability of PSC's software systems and damage institutional credibility.Safeguard: Licenses are currently limited to a small pilot group; developers are expected to review all suggestions before accepting them; the pilot is designed to measure impact against costs before broader rollout.
  • Societal & cultural harmReliance on AI-generated code suggestions may erode developers' own skills over time or create unhealthy dependency on a proprietary vendor tool for critical government software infrastructure.Safeguard: The current limited pilot allows the PSC to assess these effects before committing to broad adoption; human review remains required for all outputs.