TorontoOS — Explained Simply

v0.1, 2026-07-19 Date: 2026-07-19 ·

Status: v0.1, 2026-07-19 · RENDER. Sources: this library's internal records, this library's internal records, and this library's internal records (all dated 2026-07-17). DRAFT, pre-ratification — the charter itself says: "CHARTER (PROPOSED — operator ratifies)." No code exists yet. No city office or resident has been contacted. No data has moved. This page explains the plan. It does not change any of that.

This page explains TorontoOS in plain language. TorontoOS is a proposed shared Toronto tech platform. It covers what the plan is, why it matters, how anyone would know it is working, and what could go wrong. It uses only research already done for this program. Nothing below is a promise.

What it is

Picture three people: a city worker fixing a pothole report, the resident who filed that report through 311, and a neighbour planning a block party on the same street. They are the same kind of person, just wearing three different hats. Right now, each hat means a different login, a different city system, or no system at all. TorontoOS is a plan to give all three hats one shared, trustworthy digital home instead.

The plan imagines three connected platforms.

permits, and give the Mayor, Council, and the public a shared picture of what each department is doing. Toronto already runs dozens of these tools separately today. The plan mostly connects and opens up what already exists. It does not try to build everything from scratch.

Council to actually hear from residents. The plan's own goal is big. It wants up to a few million conversations, rolled up from thousands of small neighbourhood talks into one city-wide picture. A computer program helps sort and sum up what people say. It never invents opinions. It never casts a vote for anyone. That rule is a hard line in the plan, not a suggestion.

locally. The goal is to do this without a company like the ones behind gig-economy apps sitting in the middle and taking a cut.

The plan also draws a firm line around two things it will never touch: running elections or counting votes, and emergency dispatch for police, fire, or ambulance. Those systems stay separate, on purpose.

Six shared building blocks hold all three platforms together underneath. They are: how you prove who you are, who can see your data and on what terms, and how systems talk to each other. They also cover how big conversations get summed up honestly, how credit or value moves around, and the actual apps people touch. The plan calls this whole shared system a data commons. The plan says these six blocks would also work at other scales. They could serve a province, a country, disaster response, or a single neighbourhood. That is where the placeholder name family comes from: CityOS, ProvinceOS, CountryOS, DisasterOS, NeighborhoodOS. Only the Toronto version is actually being designed right now. The rest are named as the honest long-term shape of the idea. They are not a promise of what gets built next.

Here is one concrete example of how the conversation piece would work. About 10,000 small neighbourhood groups, informally called puroks in the plan, would spread across Toronto's 158 neighbourhoods. Each group would have roughly 300 people. Local talk inside each group would get summed up and rolled up to the city level. Every summary would still trace back to the real conversations behind it.

Nothing in this plan has been approved yet. No code exists. No city office, resident, or outside group has been contacted about it. "TorontoOS" is itself a placeholder name. The program's own charter says a better name comes later.

Why it matters

Most large government tech projects fail. That is not a fringe opinion — it is the most-cited finding in the field. Look only at U.S. federal IT projects worth $10 million or more, built between 2003 and 2012. Just 6.4% counted as a full success: on time, on budget, and doing what it was supposed to do. More than half were "challenged" — over budget, late, or falling short of what people actually needed.

Canada has its own recent, close-to-home example. The federal government's Phoenix pay system was built by a well-regarded vendor. Its job was simple and well understood: pay public servants correctly. By mid-2018, it had still caused pay problems for close to 80% of the government's 290,000 employees. Real people went unpaid, or paid wrong, for years. This was not untested, frontier technology — it was payroll.

Toronto has personally lived through a related failure, and TorontoOS names it directly. In 2017, Waterfront Toronto invited a Google-affiliated company to build a "smart city" district on a 12-acre waterfront site. The project collapsed by 2020. The reason was not that the technology failed. It was a fight over who would own the data, and who got to decide. The company's own hired privacy expert quit the project in 2018. She said its data-protection promises were not good enough. A second advisory-panel member had quit weeks earlier, citing "a lack of leadership regarding shaky public trust." A citizen campaign organized around the same worry. The company withdrew in May 2020, officially citing pandemic-era economic uncertainty. But that reason should be read alongside, not instead of, two years of eroding public trust that came first.

TorontoOS treats that history as a reason: settle governance before building any technology, not after. But the program's own research is careful here. It says this Toronto case is one cautionary example, not the whole story. Big government tech projects fail in more than one way. The plan studies several of them, not just this one.

There is also a real reason to think Toronto could do this well. The Toronto-Waterloo region genuinely ranks among the top handful of tech-talent markets in North America. Independent rankings put it at #3 or #4 — and the fact that industry sources even disagree on the exact rank is itself a sign not to treat it as a fixed fact. The region added more tech jobs than any other Canadian market in recent years: 42,900 of them, between 2021 and 2024. But the same research is honest about a real gap. Canadian venture-capital investment is roughly 20 to 40 times smaller than the U.S. market. Research reviewed for this program says that gap is mostly structural, not just poor coordination — better teamwork alone would not close it. Canadian startups that get bought out have typically raised only about a third as much money first — $12.8 million, on average — as similar companies internationally ($37 million). That is a sign many are sold because they ran out of money, not because they are winning. None of this means the idea is not worth trying. The program's own research says plainly: TorontoOS does not need to beat Silicon Valley to be worth building. It only needs to work for Toronto.

How would we know it's working

TorontoOS does not try to build everything at once. One of its own founding rules names the problem directly: huge, all-at-once government tech projects — sometimes called "big-bang" projects — fail at a bad rate. So the plan goes small and phased instead. It moves one proven piece at a time. Each piece is designed so it can be shown to have failed, instead of quietly limping along forever. The plan lays out four stages:

Toronto-Waterloo already. Find out which city systems already exist. Test whether the "Toronto could out-build Silicon Valley" claim holds up — in its strongest honest form, not a boosted one.

local coordination and small-group decisions, built on free, open-source tools other city governments already use (Barcelona and Madrid both run versions of this). It would come with a small digital-ID feature — the plan calls this a verifiable credential — that proves only one thing: that you live in the pilot neighbourhood. It would be built together with Toronto's own civic-tech community and a university program, in one or two neighbourhoods already known for an active mutual-aid group. Parkdale and Davenport are named as likely candidates.

private company, and not just City IT — would actually own the data and the technology. It would be tested first by taking over just one contained, non-critical city system.

packaging the idea for other cities. This is named honestly as a long-term goal, not a near-term plan.

The plan also says, in advance, what would count as the small pilot failing. It does this instead of deciding after the fact. Say people in the pilot neighbourhood do not take part more than they already do through a plain Facebook group or WhatsApp thread. That counts as real evidence the idea does not work as designed. Say the extra step of setting up a digital-ID wallet itself becomes the reason people do not bother. That counts too. Neither outcome gets explained away.

Before anything ever touches a real city system, a resident's real identity, or real money, the plan requires more than one person's decision to proceed. It requires a second, independent sign-off, a legal review, and a named partner already on board.

The plan has also already killed one of its own early ideas, after checking it against the evidence. An early idea proposed building kits to turn ordinary vehicles into fully self-driving vehicles. The evidence review found this is not realistic with today's technology — not outside of vehicles built from scratch for the purpose. So the program's own tracking record formally marked that idea dead, instead of letting it quietly linger.

What could go wrong

It could repeat one of Toronto's own worst civic-tech failures. A platform holding this much of a city's data and daily life carries a real risk. It could drift toward the same failure Sidewalk Toronto already showed this city: an owner with too much say over citizens' data, and not enough real accountability to the people it serves. The plan's answer is an independent, chartered group — the plan calls this a public-interest steward — not a private company, and not just City IT. This group would own the data and the technology from day one. Real community power would be built in, not just an advisory board with no power. Whether that group actually gets created, and in what legal form, is one of the questions the plan itself calls "the single hardest problem." It admits this is not solved yet.

It could fail the way most big government tech projects fail. The plan's own rule is to move small and phased, never all at once, specifically to avoid the failure pattern above. But a standing note attached to the charter itself also says the plan should be "more aggressive" than that cautious default. Part of the bet is that people will only really use this if it is genuinely fun to use, not just careful. As of this writing, that tension is not resolved. It is flagged as something to work out at a future planning session, not settled yet.

It could exclude exactly the people it is supposed to help. A comparable digital-ID system in India was built to make government services easier to reach. It also caused real, documented harm. In one Indian state, 88% of 144,000 cancelled food-ration cards belonged to genuine, eligible people. They were wrongly cut off by a system built to catch fraud. Independent trackers have also linked some hunger-related deaths elsewhere in India to this kind of failure. The exact death count comes from advocacy tracking, not one peer-reviewed study. But the pattern of wrongful exclusion itself is confirmed separately by academic research. A different digital-ID company, Worldcoin, has had its fingerprint- and eye-scanning technology banned or paused in five countries, over privacy and consent worries. None of this proves digital ID always causes harm — other countries have used similar systems well. What decides the outcome is whether the safeguards are strong, not the technology itself. TorontoOS's plan tries to design against this directly. There is no single, centrally-held biometric identity. There is a required non-digital option for anyone without a smartphone or digital skills. And no city service can ever require the digital-ID system as the only way in.

The "millions of conversations" idea could end up amplifying the loudest voices, not everyone's. Research on similar tools elsewhere finds a pattern. The people who join online civic talks tend to look like the people who already show up to any low-key civic process. They are not a full cross-section of a city. Without real, funded outreach to quieter neighbours, a big digital platform does not automatically produce a fair result on its own. That is the plan's own evidence review talking, not a guess.

A publicly-owned platform is not automatically safe from becoming another extractive company. Even the plan's own research admits this: a public-interest group under funding pressure could still drift toward charging more, or loosening its own data rules, if nobody actively keeps watch. Removing the profit motive helps. It does not guarantee anything on its own.

The technology choices carry their own known failure patterns. The plan considered, and mostly rejected, building this on blockchain-style technology. The evidence is blunt about why. In 2025, fewer than 2% of the people holding voting tokens in most blockchain-governed groups actually voted. In one real case, a single wallet holding just 4% of the tokens was able to block a $1 million funding decision on its own. The plan instead defaults to more ordinary, standards-based technology for proving who you are. It reaches for blockchain-style tools only where a specific property actually requires one.

A lot of the hardest questions are legal, and none of them are answered yet. Ten separate legal questions are flagged as unresolved. One example: who is liable if someone's digital ID is stolen and used fraudulently. Another: would the platform have to go through a competitive city bidding process. A third: which of three different privacy laws would apply to which piece of data. None of these have real answers yet. They are named as open questions for actual lawyers, not settled here.

And underneath everything: nothing here has been approved. TorontoOS is still a proposal. Its own charter is marked "PROPOSED," waiting on the operator to ratify it. No resident, city office, or outside group has been contacted. Three big decisions are still waiting on that sign-off. One is whether to ratify the charter at all. Another is whether to green-light the first small pilot. A third is how to settle two structural questions about ownership and technology.

Receipts

Everything above comes from three documents. All three are still marked DRAFT or PROPOSED. None are formally approved yet:

founding rules, the phased stages, and the questions still waiting on the operator's sign-off.

concept: the six shared building blocks, the three staged models with their honest for-and-against arguments, and ten legal questions flagged for real counsel review.

claim stress-tested against real data, the Sidewalk Toronto case study, and research on digital-ID systems, blockchain-style governance, and government-tech track records elsewhere in the world.

Every number and claim in this explainer traces back to one of those three files. If a figure above does not have a citable source in those files, it is not in this explainer either.

There is no app to try and no pilot to join yet. TorontoOS has not been ratified. No resident or group has been contacted about it. The one honest action available right now is to watch for the first small pilot actually getting a green light, and real outreach starting to Toronto's civic-tech community or a university partner for the first neighbourhood app. That is the concrete first step the plan names. It has not happened yet.