Somewhere in your business, probably this week, someone did something reasonable.
They had a long document to summarise, or an awkward email to write, or a spreadsheet they could not make sense of. They opened a browser tab, pasted the thing in, and got a good answer in nine seconds. It saved them half an hour. They did not tell you, because there was nothing to tell. They were not doing anything wrong, as far as they knew. They were just getting on with the job.
If that document had a client’s name in it, or a patient’s, or an employee’s, then your business has just transferred personal information to a third party that you have no contract with, no agreement from, and no visibility into. Nobody was reckless. Nobody was warned. And in most Canadian businesses, nobody would ever find out.
That is shadow AI, and it is the most common AI deployment in the country. Nobody scoped it, nobody approved it, and it is already running.
The size of it
The numbers here are worth being careful with, because this topic attracts vendor surveys with no method behind them. Here are the ones that hold up.
KPMG in Canada surveyed 2,239 Canadian employees in the autumn of 2025 and found that 51% now use generative AI at work, up from 22% two years earlier. In the same survey, only 29% said their employer had a comprehensive AI policy, and 40% did not know what AI controls existed at their workplace at all.
The larger international study, run by the University of Melbourne with KPMG across 47 countries and 48,340 respondents, found that 48% of employees admit using AI in ways that contravene company policy.
And on what actually goes in: an earlier KPMG Canada wave found that 24% of Canadian generative AI users had entered proprietary employer information into public AI platforms, and 19% had entered private company financial data.
Put those together for a fifteen-person office. Roughly half your staff are using these tools. Most of them have no policy to follow. A quarter of the users have already put company information into one. You do not need a vendor’s fear-marketing to find that uncomfortable, and you cannot manage it, because you cannot see it.
What the twenty-dollar seat actually does
Here is the part that matters most and that almost nobody has read, because it lives in a support article rather than on the pricing page. The difference between the consumer tier and the business tier is not the model. It is usually the same model. The difference is the default, the retention clock, and who is contractually on the hook.
OpenAI states in its own documentation that when you use its services for individuals, it may use your content to train its models. Training is on by default and the opt-out is a setting the user has to go and find. For business and enterprise products, the position is inverted: OpenAI does not train on business inputs or outputs by default.
Google is the most direct of the lot, and the sentence in its consumer Gemini privacy documentation deserves to be read slowly, because it is Google telling your employee not to do the thing your employee is doing: “Please don’t enter confidential information that you wouldn’t want a reviewer to see or Google to use to improve our services.” Note reviewer. On the consumer tier with activity history on, human beings review a subset of conversations, and a conversation a reviewer has seen can be retained for up to three years, and is not removed when the user deletes their history.
Anthropic changed its consumer terms in August 2025 so that consumer chats may be used for training where the setting is enabled, with retention running to five years if training is allowed and thirty days if it is not. Commercial and enterprise terms are explicitly excluded. Worth noting because anyone working from 2024 knowledge will get this backwards.
Microsoft has two products with almost the same name, which is its own trap. Microsoft 365 Copilot, signed in with a work account, does not use your prompts or your organisation’s data to train foundation models. Consumer Copilot, signed in with a personal account, is a different product with different terms and a user-facing opt-out.
So the honest summary: on the consumer tiers the default leans toward training, the retention is measured in years rather than days, and the terms of service were accepted personally by your employee, on their own account, on behalf of a business that never saw them. On the business tiers the default is contractual non-training, the data sits under an agreement your business signed, and there is an administrator who can see what is happening.
That is what twenty dollars a month does and does not buy.
The Canadian exposure, stated plainly
You do not need a leak for this to be a problem, which is the part people miss.
Canadian privacy law works on accountability. An organisation remains responsible for personal information it transfers to a third party for processing, and is expected to use contractual means to ensure a comparable level of protection. Note what that sentence requires: a contract, a purpose limitation, and transparency with the person whose information it is. A staff member pasting a client file into a free chatbot has none of those. The obligation was breached at the moment of the paste, not at the moment of a breach.
Canada’s privacy commissioners, federal and provincial together, published joint principles for generative AI that speak directly to this. Two lines are aimed at organisations using these tools: use anonymised or de-identified information in prompts where reasonably possible, and where personal information must go into a prompt, only do so where authorised. That word, authorised, is doing the work. Somebody has to have decided. In most businesses nobody has.
If you are in a regulated profession the bar is higher again. The Law Society of BC’s guidance tells lawyers they must understand how a tool collects, stores and uses data before entering client information into it, that privilege could be at risk, and that informed client consent may be required before uploading confidential material to a platform that retains it. The College of Physicians and Surgeons of BC issued equivalent interim guidance for physicians. If you run a clinic, a law office, or a notary practice, your regulator has already told you the answer.
Two more things worth knowing. Canada’s privacy commissioners, including British Columbia’s, jointly investigated OpenAI and in May 2026 found its training practices offside Canadian privacy law on collection, consent and transparency. That finding is about how the model was trained, not about your employee’s paste, and the two should not be blurred. But it does establish that Canadian regulators are looking at this squarely.
And on the question of who wears it when an AI gets something wrong, a BC tribunal has already answered. In Moffatt v Air Canada, decided in February 2024, Air Canada argued that its chatbot was responsible for its own statements. The tribunal rejected that outright and held the airline liable. You own what your AI says, and you own what your staff put into it.
I should be straight about one thing, because the scare version of this article would not be. I could find no case of a Canadian regulator fining a business specifically because an employee pasted data into a chatbot. The enforcement has not arrived. The obligation exists anyway, and accountability does not wait for a breach to become real.
Why banning it does not work
The instinct is to send a company-wide email forbidding it. That reliably fails, and the reason is more interesting than the failure.
Slack’s Workforce Index surveyed over 17,000 desk workers and asked why people hide their AI use. Nearly half said they would be uncomfortable telling their manager they had used AI for a common task. The reasons were that it feels like cheating, that they would be seen as less competent, and that they would be seen as lazy. Company policy came last, cited by only about a fifth.
Read that carefully. Your staff are not hiding this from you because of the rules. They are hiding it because they think it makes them look bad. A ban adds a fourth reason to hide and takes away the last of your visibility. You do not get less shadow AI. You get the same amount, quieter.
The other reason bans fail is that the tools genuinely work. You are not asking someone to give up a toy. You are asking them to go back to spending half an hour on something that now takes nine seconds, for a reason you have not explained, in exchange for nothing.
What actually works
Three things, none of which require a policy department.
Sanction something specific, and pay for it. Not a category, a named tool with a business agreement behind it. This is the whole game. Staff use the free tier because there is nothing else, and the moment there is an approved option that works as well, most of the problem evaporates on its own. A business seat costs roughly what the personal one does and moves the contractual position from your employee accepted terms on your behalf to your business signed an agreement.
Write one page on what may never go in. For a fifteen-person firm two categories is plenty. Client, patient and employee personal information, financial records and anything under privilege: never, in any tool. Everything else: fine, use your judgment. That single page does more than a twenty-page framework, because people will actually read it and remember it. It should name the sanctioned tool, name what is off limits, say who to ask when it is unclear, and say what to do when someone gets it wrong.
Make the reporting non-punitive, and mean it. If the consequence of admitting a mistake is discipline, you will find out about the next one from a client. The point of the policy is visibility, and visibility is bought with safety.
Notice that none of this is technical, and none of it takes a quarter. It is a purchase, a page, and a conversation.
The uncomfortable good news
Shadow AI is genuinely a risk, and it is genuinely evidence of something useful: your staff have already found the tasks where this technology helps. They did the pilot for you. For free. Without a steering committee.
That information is worth having. The person quietly using a chatbot to summarise intake forms has just told you which workflow is ripe, and whether that job is worth building properly is arithmetic you can run this afternoon. The right response to discovering shadow AI is not only to close the exposure. It is to ask what people are using it for, and then to build the sanctioned version of the two or three things that come up most.
You already have an AI policy. It is whatever each of your staff privately decided was fine. They made that decision without the terms of service, without knowing what the consumer tier retains, and without knowing your regulator has an opinion. They were not being careless. Nobody gave them anything else to go on.
Giving them something to go on takes an afternoon. It is, by a distance, the cheapest AI work your business will ever do.