Why machine-learning training shapes this regulator’s AI calls


About 25,000 queries a year arrive at the regulator that licenses professional engineers in Ontario. A person answers every one.

“I can confirm that it is all humans who respond to all 25,000 of those queries,” says Arun Dixit, vice president of digital transformation and corporate operations at Professional Engineers Ontario (PEO).

Dixit spent six years in a machine-learning PhD program. The AI he allows in the building schedules meetings and puts together agendas.

The reason, he says, is trust.

Dixit measures almost every technology decision at PEO against one thing, whether it protects the trust the regulator lives on, and is a finalist for CanadianCIO of the Year in the not-for-profit category, hosted by the CIO Association of Canada.

“Every single thing that we do is based on that foundation of trust,” says Dixit.

Training as a process engineer taught him to map how work moves through an organization, where information flows, where approvals sit, and where a step survives because a system requires it while adding no value. 

He carried that into a PhD in machine learning, using data collected at hospital emergency-department triage to improve care for patients with complex needs. He joined PEO in 2023 while still in the program, and left the PhD in 2024, six years in, describing it as a choice to concentrate on his strengths.

The research left him with a habit he brings to work at PEO, which is pulling ideas from industries that look nothing like his own.

“The ability to look for intersections between things that may not on the surface seem to have a match,” says Dixit.

In his research, he looked at a patient with complex care needs as an anomaly, the way a bank or a cyber team looks at fraud, to see which of their detection techniques might carry over.

AI books the meetings while people do the rest

Dixit knows what the technology can do, which is why he is deliberate about where it goes.

The organization runs on about 150 staff. Dixit describes them as a microcosm of complex users, spanning the full range of comfort with technology. 

He moves slowly on purpose, keeping people in the loop and holding AI out of decision-making. Hallucinations, the confident wrong answers generative AI produces, are one reason he keeps it away from that work.

He also tells the board before any AI goes live.

“We as staff have the obligation to duly advise our board and the public of where we’re using AI,” says Dixit.

He guards trust so carefully because of how high he’s set the bar.

“That’s not the best engineering regulator, that’s the best regulator full stop,” says Dixit.

Getting there, he says, means building around rules that can survive whatever technology comes next. The tools can change faster than what’s mapped out in a five-year plan, so Dixit has anchored PEO’s 2026 to 2030 strategy on controls that outlast any single technology.

New AI brings cyber risks he hasn’t seen yet, but some of the defences he relies on are old ones. One is multi-factor authentication, a second proof of identity beyond a password. Another is a phone call to confirm any unusual request to move money.

He’d heard a line a few days before we spoke that stuck with him.

“The AI works for humans. Humans don’t work for the AI,” says Dixit.

Arun Dixit, vice president of digital transformation and corporate operations at Professional Engineers Ontario (PEO) — Photo courtesy of Arun Dixit
Arun Dixit, vice president of digital transformation and corporate operations at Professional Engineers Ontario (PEO) — Photo courtesy of Arun Dixit

The deadlines PEO doesn’t get to set

Dixit built the business relationships that let him slow AI down. The same ones let him move fast when a deadline he can’t control arrives.

Ontario’s as-of-right framework, in effect since January 2026, requires regulators like PEO to process applications from engineers already licensed in another province on timelines the government sets. 

Qualified applicants are deemed certified to work in Ontario for up to six months while they complete full registration.

Dixit says his teams are processing applications well inside the required timelines even as application numbers rose, and he credits the relationships his technology group built with the rest of the business. 

When a change is coming, the technology people are in the room before the requirements are even set.

“That’s when we need to have everybody in the room together to start to figure out what a solution could look like,” says Dixit.

He builds that readiness deliberately, through engaging staff early, including them in testing and vendor selection, and demystifying what the technology team does.

The cyber bill for a crisis that never comes

Trust also has to be defended, and security spending has an awkward problem. When it works, nothing happens.

PEO ran its first external penetration test in 2025, hiring outside specialists to attack its systems the way a criminal would. External penetration tests are designed to turn up weaknesses. Dixit says PEO compared favourably with similar organizations.

“Compared to peer groups of a similar industry and organization size, we did quite favourably on that,” says Dixit.

He attributes that to earlier investment, to prioritization, and to his team clearing known weaknesses before the test.

Making the case for that spending is its own problem.

“You kind of have to prove the negative,” says Dixit.

He is arguing for money against an event he is working to make sure no one ever sees.

“You never want to be in the situation where you’re having to deal with one live,” says Dixit.

To build the case, he works out what PEO spends on security for each staff member and each licence holder, then checks that against what comparable organizations spend. He also points to threats reported elsewhere and to figures like the average cost of paying off a ransomware attack, where criminals lock an organization’s systems until it pays.

He runs the same approach inside the building, treating security as everyone’s job. During cybersecurity month, every staff member takes part.

“Everybody has a role to play in cyber,” says Dixit.

For all the systems and tests, Dixit gives credit to others. He describes his own contribution as direction from a distance, worth little on its own.

“If that doesn’t persist down to every member on the team, all the contributors on the team, what I say won’t matter,” says Dixit.

Final shots

  • Dixit has drawn a hard line at decision-making, and everything AI touches at PEO sits on the administrative side of it.
  • How long a regulator can keep its customer service entirely human is the question his approach leaves open.
  • The case for cyber spending never closes for Dixit, because it pays off only by preventing events no one will ever see.

This article is part of a series profiling the finalists for the 2026 CanadianCIO of the Year Awards, not-for-profit sector category, presented by the CIO Association of Canada. The winner will be announced Oct. 1 in Toronto. Digital Journal is the national media partner for the CIO Association of Canada.



Why machine-learning training shapes this regulator’s AI calls

#machinelearning #training #shapes #regulators #calls

Leave a Reply

Your email address will not be published. Required fields are marked *