OffrePro OffrePro.
FR
← All news
Artificial intelligence

Where a Québec SMB should start with generative AI

A Québec SMB should start with generative AI on a single repetitive, high-volume, low-risk task, keep a human validation step wherever the output matters, and document where the data goes before comparing tools at all. Adoption is already here: 52% of Québec internet users had used a generative AI tool by October 2025, up from 33% a year earlier, according to the NETendances 2025 survey by Université Laval's Académie de la transformation numérique, published on March 19, 2026. Drafting a first version of a document, summarizing meeting notes or triaging a request queue are sound starting points: mistakes cost little there, and the effect on time spent shows up by recording that time before and after the tool arrives.

The tool has usually entered the organization before anyone decided to buy one. Among Québec residents who use generative AI, 84% use ChatGPT and 48% use nothing else, per the same survey, fielded October 17-31, 2025 with 993 internet users aged 18 and over. Among those same users, the share using it at least weekly rose from 38% in 2024 to 54% in 2025. A management team that still believes it is deciding whether to adopt generative AI is in fact deciding how to govern usage that already exists, often on personal accounts. The first useful move is not a purchase order: it is asking the team which tasks already pass through a consumer tool.

The most common trap is buying a tool before naming the problem. An SMB that adopts generative AI because it feels obliged to usually ends up with underused software and a skeptical team. Naming the repetitive task to be lightened, before comparing options, changes the nature of the decision: it stops being a tool choice and becomes a process choice. The selection test then becomes checkable. Does the task recur at least weekly? Is its output read by a person before it reaches a third party? Is a mistake recoverable without contractual consequences? Three straight yes answers identify a good first project.

The principle worth keeping on every sensitive task is human validation: the system proposes, a person validates, then the system executes. That sequence is not a comfort brake; it is what stops a model hallucination or a context error from reaching a client unreviewed. It has a direct design consequence: a tool with no stopping point between generation and delivery cannot be trusted with a binding document. Models also fail quietly, when a provider is unavailable or a quota is exceeded. A careful service then falls back to deterministic template content rather than improvising, which keeps the output predictable even when the provider does not answer.

The data question comes before the tool question, and Québec's Law 25 frames it as a duty to inform. Section 8 of the Act respecting the protection of personal information in the private sector requires a business collecting personal information from the person concerned to inform them, at the time of collection, of the purposes of the collection, the means used, their rights of access and rectification, and their right to withdraw consent to the communication or use of the information collected. The Commission d'accès à l'information further notes that a privacy impact assessment must precede any communication of personal information outside Québec, a requirement in force since September 2023. Where a context note pasted into a tool hosted elsewhere ends up belongs on the map of processing activities drawn before deployment, with legal advice as needed.

The duty to inform covers technologies, not just files. Since September 2023, a business collecting personal information from the person concerned by means of technology that includes functions allowing that person to be identified, located or profiled must say so beforehand, and the Commission d'accès à l'information states that such technologies cannot be turned on by default: it falls to the person concerned to activate them if they wish. The same Commission page puts administrative monetary penalties at up to 2% of worldwide turnover or CAD 10 million. How those provisions apply to any given deployment is a matter of legal analysis, with legal advice as needed.

A generative AI vendor sorts on what it will describe technically, and that gets settled before the demo. Which fields exactly are sent to the model, and which stay inside the application? Where is the model provider hosted, and is there a failover mechanism that could route the same request somewhere else, in another jurisdiction? How long does the vendor keep prompts and responses, and is that retention contractual or merely stated on a web page? An honest answer always separates what the software guarantees technically from what the vendor promises commercially. A vague answer about failover is a signal in itself: that is exactly where jurisdiction changes without notice. The same questions, widened to hosting, subprocessors and termination, are taken up in the questions to ask a software vendor before handing over data.

Here is what those answers look like on a real case. In OffrePro, every call to the model passes through a single outbound point, where the identifiers stored on client records — contact name, company name, email addresses, phone numbers — are replaced with typed placeholders before any network call, then restored locally. The masking covers identifiers and stops there: the substance of the mandate goes out as written, and the privacy policy sets out the exact perimeter. On the second question, the model provider is a deployment setting, and an automatic failover can route the same request outside Québec. On the third, how long the provider keeps prompts is governed by the contract signed with that provider: the code sends no non-retention flag. The software's own AI audit log is purged after 90 days by default.

Measuring before and after the tool arrives is the step most often skipped, and the only one that shows whether it actually helped. Time spent on a task, the number of round trips needed to finish it, and the correction rate on a first draft are simple markers to record for two weeks before starting, then compare a month later. Without that baseline, the conversation falls back on impressions. The same demand for precision applies to the documents themselves: what deserves standardizing and what must stay bespoke is covered in automating business documents without losing your voice, and the expected anatomy of an offer in what a winning business proposal must contain.

A similar challenge in your organization? Get in touch