Local AI Guy Book a 15 minute call
Data

Data · ai use policy for employees canada

Your staff are already using AI. You just have not written the rule yet.

Statistics Canada found 32.0% of AI-using businesses trained staff. The rest have people improvising with client data and no written rule. Fix that first.

Lasse Pettersen

Statistics Canada found that 44.4% of Canadian businesses using AI had made changes to training or staffing because of it, and 32.0% had provided AI-related training to existing employees. Read the second figure the other way round. Roughly two thirds of the businesses that are actively using AI have not trained anybody.

And that is only the businesses that know they are using it. Overall business AI use reached 19.2% in the second quarter of 2026, up from 6.1% two years earlier. Adoption tripled. Almost nobody wrote a rule first.

The gap between those numbers is the same thing in every business I have looked at: capable people, sensible intentions, no boundary, and nobody who thinks it is their job to draw one.

What is actually happening in the building

Not sabotage. Ordinary work, done faster, by people trying to help.

  • A resume pasted into a chatbot to be summarised before an interview.
  • A customer complaint pasted in to draft a reply that sounds calmer than the first attempt.
  • A spreadsheet of client contacts pasted in to be reformatted or deduplicated.
  • A contract pasted in with “what am I agreeing to here”.
  • A photograph of a handwritten intake form, uploaded to be transcribed.

Every one of those is somebody doing their job well by their own standards. Every one is also a disclosure of personal information belonging to a third party, made by your organisation, under terms nobody in the building has read.

Why this is your problem rather than theirs

The Personal Information Protection and Electronic Documents Act governs how an organisation collects, uses and discloses personal information in the course of commercial activity. Putting a customer’s details into a third-party service is a disclosure. The obligation sits with the organisation.

In May 2026 the Office of the Privacy Commissioner of Canada found that OpenAI’s initial training of ChatGPT did not comply with Canadian privacy law, and the surrounding guidance treats prompts, retrieval corpora and outputs as personal information handling like any other processing. Complaints under PIPEDA rose 109% year over year to 3,044.

An employee who has never been told not to do something is not the person who failed. That reasoning is set out at length in what PIPEDA means for your AI tools.

There is also a narrower Ontario duty already in force. Since January 1, 2026, an employer with 25 or more employees must state in publicly advertised job postings whether AI is used to screen, assess or select applicants, under the Employment Standards Act and Ontario Regulation 476/24. Most employers over that threshold use an applicant tracking system that ranks or filters candidates, frequently by a default nobody chose. That one is covered in the Ontario AI job posting rule.

The conversation to have this week

One hour. No consequences attached, stated explicitly at the start and meant.

Ask: which AI tools are you using for work, what have you put into them, and what has it saved you? Write the answers down without reacting to any of them.

Three things come out of that hour, reliably:

The list is longer than you expected. Owners typically name two tools. Staff typically name five or six, including at least one browser extension nobody had considered.

Somebody has found something genuinely valuable. In most businesses one person has quietly worked out an approach that would save the whole team hours, and has not mentioned it because they were not sure it was allowed.

One thing in the list will worry you. That item is the reason to have had the conversation, and finding it costs an hour.

Do not start with network logs. A quiet audit produces a shorter list and a worse relationship, because people stop volunteering information once they learn they were being checked, and volunteered information is the only kind that arrives in time to be useful.

The policy, in six sections

Two pages. Anything longer is not read, and an unread policy is worse than none because it creates the appearance of a control that does not exist.

  1. Approved tools, by name. Actual products and actual tiers, not categories. Business or enterprise tiers where available, chosen specifically because the terms on training and retention differ from consumer tiers.
  2. What may never be entered into a general chatbot. Customer and candidate personal information, anything under a confidentiality agreement, credentials, unreleased commercial terms. Write it as a list, not as a principle.
  3. Which outputs need a human check. Anything leaving the building, anything affecting a person, anything containing a number that has to be right. Name who checks.
  4. Disclosure. When a customer, a candidate or a regulator has to be told, including the job posting duty.
  5. What happens when somebody breaks it. Written as a process rather than as a threat. If the only stated consequence is discipline, you have guaranteed that the next mistake is concealed.
  6. The date you decided. Because once you have looked at this properly, “nobody realised” is no longer available, and the dated record is what turns an incident into a breach of a known rule instead of an unexplainable failure.

The training half day that goes with it

Two to three hours, for the people who touch the work rather than for the management team.

Not an awareness session. Everybody brings a real task from their own week and does it, with the policy open, so the rule is learned against the job rather than against a slide.

The usual outcome is not enthusiasm. It is two discoveries. Somebody finds that the task they were about to automate should not be, usually because of what is in the data. And somebody else finds that a task nobody had thought about takes four hours a week and could take ten minutes. That second person is where most of my workflow automation work starts, and the ranking method is in which jobs to automate first.

The objection worth answering

The most common response to all of this, from owners who have thought about it, is that a policy will slow people down and the whole point was to go faster.

In practice the reverse happens, for a reason that becomes obvious once the hour-long conversation has happened. Most staff using these tools quietly are doing it because they are unsure whether it is permitted. Being unsure means they also do not ask for help with it, do not share the approach that works with anybody else, and cannot be corrected when they are doing something risky. The productive use stays trapped inside one person and the risky use goes unmentioned.

A written rule ends both. It converts a hidden behaviour into a managed one, and it converts the person who quietly worked something out into the person who shows everybody else. That second effect is usually worth more than the risk reduction, which is not the argument the compliance framing would predict.

Why this comes before any build

It is the cheapest engagement I sell. AI policy and staff training is $1,500 to $4,000 including the half day, against $2,500 to $12,000 for a build.

It is also the one with the highest chance of preventing something. A build that goes wrong costs you the build. An uncontrolled disclosure of a client’s personal information costs you the client, and possibly a complaint you have to answer with no record of any rule having existed.

The order is not a preference. A business that automates a process while its staff are independently pasting the same data into an unapproved tool has not reduced its exposure. It has added a system on top of it.

If you do one thing

Have the hour. Ask what people are using. Do not react. That single conversation is the highest-value privacy activity available to any Ontario business that has not had it yet, and it costs nothing but the hour.

Questions on this

How do I find out which AI tools my staff are using?

Ask them, once, with an explicit statement that nobody is in trouble for what they say in that conversation. The answer is always broader than the owner expects. Auditing network logs first produces a smaller list and a worse relationship, because people stop telling you things after they discover you were checking.

What should an AI use policy say?

Which tools are approved by name, what may never be entered into a general chatbot, which outputs need a human check before they leave the building, when disclosure is required, what happens when the rule is broken, and the date the decision was made. Six sections. It fits on two pages and anything longer will not be read.

Is a template policy good enough?

As a starting structure, yes. As a finished document, no, because the value is in the specific list of approved tools and the specific list of what may never be pasted in. A template cannot know that your intake sheet contains health information or that your quoting file has a customer's pricing under an agreement.

Will a policy stop people using AI?

The opposite, in practice. Most staff using these tools quietly are doing it because they are unsure whether it is permitted, which means they also do not ask for help, do not share what works, and cannot be corrected. A written rule converts a hidden behaviour into a managed one.

Local AI Guy

Before you spend anything

Tell me how many people work there, what the busiest hour of the week looks like, and which task everybody complains about. That is usually enough to say on a first call whether an assessment is worth your $999 or whether you have one obvious problem that needs one obvious fix.

Reply within one business day · Mon to Fri, 9am to 5pm Eastern

Book a 15 minute call Call (705) 555-0182