AI Productivity Assistant for Government Employees
Employment & Work
What it collects
- Employee prompts, queries, and task instructions entered into the Copilot Chat interface. Restricted to non-protected, non-classified information per departmental policy.
- Non-sensitive departmental documents, spreadsheets, emails, and other Microsoft 365 content that employees submit for summarization, drafting assistance, or data analysis.
- Run by
- Veterans Affairs Canada (VAC)
- Where
- No fixed location
- Kept
- Not stated by the Helpful Places.
- Shared with
- Vendor, Accountable organization
What it is for
M365 Copilot Chat is an AI-powered productivity tool provided to all Veterans Affairs Canada employees. It helps staff summarize content, draft documents, analyze data, and automate routine tasks. The system is intended for use with non-sensitive information only and is not approved for protected or classified data. Employees are not currently informed when they encounter AI-generated outputs within this tool.
What it collects and what happens to it
Data taken in
- Employee prompts, queries, and task instructions entered into the Copilot Chat interface. Restricted to non-protected, non-classified information per departmental policy.
- Non-sensitive departmental documents, spreadsheets, emails, and other Microsoft 365 content that employees submit for summarization, drafting assistance, or data analysis.
Processing
- Microsoft's large language model (GPT-4 class) integrated within the Microsoft 365 suite, used to generate text, summarize content, draft documents, and analyze data in response to employee prompts.
What it does
- Generates text, document drafts, and data summaries in response to employee prompts. Employees review and decide whether to use, edit, or discard the AI-generated output.
- Analyzes and summarizes data and documents on demand, surfacing insights for employees who then decide how to act on them.
Outputs
- AI-generated text including document drafts, summaries, analyses, and task automation outputs produced for VAC employees. Content is based on non-sensitive departmental inputs.
Run by
- Federal government department that deploys M365 Copilot Chat to all departmental employees as a productivity tool for non-sensitive work.
Built by
- Technology vendor that builds and supplies the M365 Copilot Chat AI system, including the underlying large language model and Microsoft 365 integration.
Kept for
Not stated by the Helpful Places.
Shared with
- Microsoft, as the vendor, processes employee prompts and inputs through its cloud infrastructure to generate responses. Departmental policy restricts inputs to non-protected information, but Microsoft's data processing terms govern what the vendor retains or uses.
- Veterans Affairs Canada has access to usage logs and outputs within its Microsoft 365 tenant as the deploying organization, subject to Microsoft's enterprise data governance terms.
Stored
Not stated by the Helpful Places.
How to read the colours
Can it identify you?
- Anonymized data
- Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
- Pseudonymous data
- Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
- Identifiable data
- The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.
Who completes the loop?
- Human decides
- This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
- Human executes
- This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
- Autonomous
- This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.
Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.
- AI registerGovernment of Canada AI and Algorithmic Systems Register — M365 Copilot Chat (2526-VAC-ACC-003)Veterans Affairs Canada, AI Register ID 2526-VAC-ACC-003, accessed 2026-05-08.
- AI registerGovernment of Canada AI Register — M365 Copilot Chat
- AI registerGovernment of Canada AI Register — M365 Copilot Chat
- Register entryPublished by the Helpful Places. Reference a9086372. This disclosure was drafted with AI assistance.Schema: ai@2026-05-06-beta
What you can do
Ask about this system
Questions go to the Helpful Places, not the vendor.
Your rights
- Right to Be Informed of AI UseThe register states that AI use is NOT currently disclosed to users. Employees interacting with M365 Copilot Chat outputs may not be informed that they are generated by an AI system. This is a transparency gap identified in the official register.
- Right to Algorithmic TransparencyEmployees may seek information about how Copilot Chat works through Veterans Affairs Canada's departmental ATIP (Access to Information and Privacy) office or Microsoft's published model documentation. The register does not specify a formal transparency mechanism for this system.
Risks and safeguards
- Psychological harmRisk of over-reliance on AI-generated content leading to uncritical acceptance of inaccurate drafts or summaries (automation bias).Safeguard: the system is advisory only — employees decide whether to use, edit, or discard outputs. The register notes AI use is not disclosed to employees, which may increase over-reliance risk. Recommendation: implement clear AI output labelling.
- Civil liberties harmRisk that sensitive or protected employee or client information is inadvertently entered into the system despite policy restrictions, potentially exposing it to Microsoft's cloud infrastructure.Safeguard: departmental policy explicitly prohibits use with protected or classified information. Technical controls and employee training are expected but not described in the register.