MarketAlbertaSheet 24

These models have consequences.

Calgary and the Alberta industrial estate.

The AI questions in this market are operational rather than consumer facing: predictive maintenance, load and price forecasting, geospatial and sensor models, field safety, and increasingly agentic automation reaching into systems that were never designed to be driven by software making its own decisions.

Where I work from

I am based in Winnipeg, Manitoba, and I serve Calgary on site and remotely, in whatever mix the engagement needs. There is no Alberta office behind that, and the arrangement is deliberate: on-site time goes where the plant, the control room or the legacy substrate has to be read in person, and the rest of the work runs from Winnipeg. The question that decides an industrial governance engagement is not the city named on the advisor’s letterhead. It is whether the person reviewing your automated decisions has stood in front of the systems making them.

§ 01The governing instruments

Alberta PIPA, and the physical consequence.

Alberta’s Personal Information Protection Act was deemed substantially similar to Part 1 of PIPEDA in 2004, and it applies instead of PIPEDA to private-sector activity occurring within the province. It has not been substantially revised since 2010, and the province ran a public consultation on modernising it between 2 February and 1 May 2026, so this is a floor that is expected to move rather than one to design against permanently.

The more distinctive governance pressure here is not privacy law. It is that a wrong automated decision in this sector has a physical consequence and a regulator’s name attached to it. A model that misjudges a pressure reading, a maintenance interval, or a shutdown threshold does not produce a customer complaint. It produces an incident, an investigation, and a question about what the system was permitted to decide on its own.

That inverts the usual governance argument. Consumer-facing AI is governed mostly because a regulator requires disclosure. Industrial AI has to be governed because the blast radius is measured in equipment and people, and the institution will be asked to show what bounded the machine long before anyone asks whether a privacy notice was adequate.

§ 02The gap

Where the gap usually is.

Authority
Nobody can state in writing what an automated system is permitted to change without a human confirming it. The capability exists; the boundary was never written down.
Legacy substrate
Decades of operational systems, historians and bespoke integrations mean the governance you can enforce is capped by the engineering you actually have.
Model ownership
Forecasting and sensor models are owned by engineering rather than risk, so they sit outside whatever model governance the enterprise runs.
Incident readiness
There is a safety incident process and an IT incident process, and no rehearsed path for an AI system that was confidently wrong.
§ 03The work

What I bring to it.

The Five-Gate Deployment Model for what an operational system must clear before it runs unattended, trust tiers and the PARA operating model for agents that touch running systems, the AI Incident Response Protocol, and the enterprise architecture depth a legacy-heavy operator actually needs first. Twenty-five years of TOGAF and DMBOK practice, multi-cloud estates, and a two hundred database modernisation programme sit behind that, because in this market the governance question is usually blocked by an integration question.

Calgary is one of my three working stations, alongside Winnipeg and Toronto.

Oil, gas and pipeline operationsElectricity and utilitiesIndustrial manufacturingEngineering and field servicesAgriculture and resource logistics
How I work here

Work is delivered through iSystematic Inc., a studio with its own team of builders, and the advisory and governance engagements are delivered by me rather than staffed to that team. Engagements run on site, remotely, or both, with no default either way: where the work happens is a property of the engagement, not a restriction I bring to it. Nothing here is legal advice; it is architecture and governance work that your counsel should review.

§ 04Questions

What Calgary clients ask.

Which privacy law applies to a private company in Alberta?

Alberta’s Personal Information Protection Act applies instead of PIPEDA for private-sector activity occurring within the province, on the basis that it was deemed substantially similar to Part 1 of PIPEDA in 2004. PIPEDA still governs personal information crossing provincial or national borders in the course of commercial activity, so most operators of any scale are dealing with both.

Is Alberta PIPA changing?

It is under active review. The province ran a public consultation on potential legislative updates between 2 February and 1 May 2026, and the Act has not undergone major revision since 2010. I would not architect a governance programme that depends on the current text staying fixed.

Is there an Alberta AI statute?

Not a dedicated one. Governance obligations for industrial AI in Alberta come from privacy law, sector safety and reliability regulation, contractual and operator duties, and the general expectation that an operator can explain what its systems were permitted to do. The absence of a named AI act is not the absence of exposure.

Our AI is operational, not customer facing. Does governance still apply?

Yes, and usually with a shorter fuse. Consumer AI failures produce complaints; operational AI failures produce incidents with physical consequences and a regulator already entitled to ask questions. The governance case here rests on blast radius rather than on disclosure rules.

Can you work with our existing operational stack?

That is normally the first half of the engagement. Governance you cannot enforce inside the systems is documentation, so the practical work often starts with what the current substrate can actually attest to, not with a policy document.

§ 05Start

Find the gap before someone else does.

The first conversation is a free thirty-minute fit call that qualifies the work in both directions. If it does not fit, you leave with a clearer read on where your governance stands and no cost. If you would rather start on your own, the Readiness Self-Assessment is twelve questions and the result is not gated behind a form.

§ 06Ask an assistantLive, no key

Ask your AI assistant instead.

This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is identify_relevant_service, list_consultation_slots and book_consultation, which map a described problem to an engagement shape, read real availability, and book a real 30 minute conversation. Booking writes to a real calendar and emails the attendee, so confirm the time with the person first.

01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp

Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.

02 · Ask

“Using Concylium, here is my situation: we have put an LLM into a regulated decision and our regulator has started asking questions. Work out which engagement shape fits and why, then show me real availability.”

It routes to a shape and shows the reasoning, so you can disagree with it. It reads live availability and can book a real conversation. It cannot agree a fee or a scope.

Fin · Calgary
Book a Fit Call →