THE PROBLEM — Data, privacy, and Toronto's own AI
1 · The problem
Toronto's own data and AI practices sit in a layer few residents ever see directly: municipal data handling is governed by MFIPPA, the city's vendor contracts increasingly embed algorithmic decision-making, and the city adopted its own corporate AI assessment framework in 2025 to govern what it buys and deploys. Two decisions sit above the city and shape what it can do: a federal privacy-modernization bill (covering children's data and surveillance-based pricing) is before Parliament now, and Canada has no national digital ID, which pushes the identity question down onto whichever province, city, or vendor signs the next procurement contract. This is also the governance layer under two other rows in this register — the AI-and-work file (§3) and the policing-surveillance file (§5, see THE PROBLEM — Policing and surveillance in Toronto) — since the same board-pre-approval rule that governs facial recognition for police also sits inside the city's broader AI framework. Toronto's own lever here is real and underused: procurement terms. Every contract the city signs for a new system is a chance to set the rules that govern it, or to inherit whatever a vendor's default happens to be — across four budget cycles this council term. Full framing and receipts: register entry; scheduling context: DECISIONS BEFORE 2030 — the full inventory (Phase C, one of this library's own project records) §1 (AI), §2 (surveillance), §3 (data).
2 · What we're asking — the question hierarchy
The primary question: Who actually controls the data Toronto collects and the algorithms it buys, and can the city build — or govern — digital systems that serve residents rather than watch them?
What the city already runs — the inventory nobody has published
- Before anything gets replaced or rebuilt, what does the City of Toronto and the wider GTA actually run today — 311, permits, property tax, transit, the core finance and HR systems, the open-data portal — which systems are aging or locked in, which contracts and renewal dates constrain the timeline, and which vendors hold the keys? (torontoos T13)
- What is the complete, current inventory of live AI systems the city runs today under its 2025 assessment framework? (the register's own named gap, and the single missing document that would make every other question in this file answerable)
Where the line sits — what a system may decide
- What does "AI done the right way" actually mean as an operational rule rather than a slogan — a system may cluster, translate, summarize, and surface, but never decide, vote, or manufacture consensus, with every AI-generated output labelled as such? (torontoos T21 · agora A24)
- How does a "humanistic AI" standard become testable and auditable rather than asserted — human-in-command, augmenting rather than replacing, transparent, contestable, demonstrably reducing drudgery rather than dignity — a checklist Toronto could publish and be held to? (torontoos T48)
- How do we keep the AI itself from becoming a new centralized power — since a model that clusters and surfaces information is a model that shapes what everyone sees — through transparent, auditable, contestable, ideally open-source-and-community-governed design? Who watches the model, and how does a resident challenge what it decided? (agora A25)
Sidewalk Toronto's lesson — identity and structural sovereignty
- How is a citizen-owned, privacy-preserving identity layer designed so it answers Sidewalk Toronto rather than repeats it — a person controlling their own identity rather than a platform-owned profile that becomes the key to everything? (torontoos T8)
- Can sovereignty be built into the architecture itself — personal data stores, local-first computing, end-to-end encryption — so a platform structurally cannot extract or surveil even if a future operator, vendor, or government wanted it to, or is that aspiration dressed as engineering? (torontoos T9)
- What is the short, testable checklist a Torontonian who remembers Quayside can actually check any new city system against — does the citizen own their data structurally, is the governance public and accountable, is there no private master, is it transparent, reversible, and forkable? (torontoos T60)
- What does the existing evidence base actually say — Barcelona's Decidim and DECODE data-sovereignty work, Estonia's X-Road, the platform-cooperative movement, and the failures worth learning from (Sidewalk itself, Aadhaar's exclusion harms, the wider government-IT graveyard)? (torontoos T64)
Data commons, consent, and the transparency line
- Who decides what municipal data becomes a shared public commons versus stays private, how is consent made granular and revocable, and what legal container — a public data trust, a civic data cooperative — keeps a data commons from becoming the honeypot Sidewalk's critics feared? (torontoos T11)
- How far can the city make its own operations radically transparent — real-time KPIs, spending, service levels — while still protecting what's legitimately private, and who draws that line? (torontoos T27)
- Could a city ever give itself the power of a total-integration data platform — seeing its own systems whole — without the surveillance, the black box, and the private ownership that make that kind of platform powerful in the first place? Is a public version that refuses surveillance by design an acceptable trade even if it ends up a weaker tool? (automata AU87 · automata AU88)
Procurement, vendor lock-in, and who governs the platform
- What is the honest rule for deciding whether to replace, integrate with, or leave alone an existing city system — since "rebuild everything" is how government IT megaprojects fail — and what does the evidence from successful and failed public-sector modernizations actually say the rule should be? (torontoos T14)
- How does any new city platform avoid becoming the next vendor lock-in it was built to escape — through open standards, open data formats, and a forkable, exportable design that lets a department or another city walk away with its data intact? (torontoos T15)
- Who actually governs, and who owns, any city-built digital platform — a public-benefit body, a civic data trust, a municipally-owned cooperative — structured to resist capture by a private buyout, a future council, or provincial override? (torontoos T58)
- Is exit designed into every layer of a city system — identity, data, services, governance — so public ownership is demonstrable by actually walking away, not just declared in a policy document? (torontoos T65)
- Whoever holds the pen on a city's surveillance, valuation, and decision-making systems holds real power — which of those systems is Toronto actually positioned to redesign for its own people, and what ownership and governance form makes a system serve residents rather than whichever funder or vendor built it? (automata AU84 · automata AU85)
Jurisdiction — what the city can actually decide alone
- Since municipal, provincial, and federal powers are genuinely different, and privacy, procurement, and accessibility law all bind hard, what can a Toronto-built system actually do on its own authority, and where must it defer to the province or Ottawa? (torontoos T57)
- Running the Sidewalk-Toronto checklist (T60) backward: where does Toronto's own practice sit today, for the systems it already runs — not the ones still being designed?
- Which vendor contracts already in force today embed algorithmic decision-making, and were any of them assessed under the city's 2025 AI framework, or does the framework only apply going forward?
Who governs technology best in the world — and everything already recommended
- The cities that actually govern their algorithms — Amsterdam and Helsinki's public AI registers, New York's algorithmic accountability law, Barcelona's data-commons experiments, the EU AI Act's municipal practice — what EXACTLY does each require, what has it caught, and which piece does Toronto adopt first?
- Collect ALL of it: everything already recommended to Toronto on data and technology governance — the entire Sidewalk-era review literature, the city's own digital-infrastructure and AI-framework consultations, Auditor General IT audits, civil-society submissions — what was recommended, adopted, and left on the shelf?
- Who are the best minds and organizations on public-sector AI and data governance anywhere — whose standards do we import — and who in Toronto's own civic-tech and academic community is already world-class and unused?
3 · What we already have — the evidence shelf
| Topic | Backgrounder | Leaf | Brief | Card |
|---|---|---|---|---|
| Data privacy & municipal information governance | link | not published | link | link |
| Digital equity & connectivity | link | not published | link | link |
| AI & public-good adoption | link | not published | link | link |
| AI & Toronto's sovereignty opportunity | link | not published | link | link |
Deep surface: WORKLOG — Toronto "Surveillance Pricing" Council Item (shadow report project)
— an active, in-progress research project (not yet corpus-graduated; several claims still marked
[UNVERIFIED-COMMODITY] in its own files) tracking Toronto Council's unanimous July 31, 2026 vote
(item 2026.EX33.33) directing staff to report back Q1 2027 on regulating algorithmic "surveillance
pricing." It is the live, real-world test case of this file's own jurisdiction cluster: it finds the
City of Toronto Act gives a real but narrow hook (consumer protection, business licensing), that
enforcement against out-of-jurisdiction platforms is genuinely contested, and that Manitoba's Bill 49
is currently the only in-force Canadian law on point — all directly relevant to how far Toronto's own
procurement and bylaw levers actually reach. This project is explicitly named against this register row
in DECISIONS BEFORE 2030 — the full inventory (Phase C, one of this library's own project records) §3.
4 · What's unexplored
The register's own named gap: inventory of live city AI systems — no such document exists anywhere
in the corpus today (harvest CSV, problem-register F2+H4, gap-cell).
Everything §2's "Raised this review" names has no dedicated evidence shelf yet: there is no published inventory of live city AI systems under the 2025 framework (NEW-1); nobody has run the Sidewalk-Toronto checklist (T60) against systems already in production rather than systems still being designed (NEW-2); and there is no public accounting of which existing vendor contracts already embed algorithmic decision-making or whether they were ever assessed under the 2025 framework at all (NEW-3).
Source tags like (homes HM12) mark questions carried from the project's own question banks (QUESTION_HARVEST.csv); untagged questions were raised in the 2026-08-11 rewrite.