Denis Normand
CIO Eficio

Your employees already use AI. Do you know what they Share with it?

On September 23, 2024, at an Ontario hospital, an AI transcription tool joined a virtual meeting where physicians were discussing their patients. The hospital had never approved it, and it joined without the participants’ knowledge. This is what is called shadow AI: an AI tool used without the organization’s approval.

It all started with a physician who had left the hospital more than a year earlier. However, his personal email address was still on the meeting list. He had just installed this unapproved AI tool on his device, and it found the invitation in his calendar. The tool then recorded the discussion, which involved seven patients. Finally, it automatically sent a summary and a link to the transcript to 65 recipients, 12 of whom had apparently left the hospital. The case is described in a letter from the Information and Privacy Commissioner of Ontario.

The hospital had to report the breach, write to the patients, block the tool and review its policies. When the Commissioner issued the letter, the hospital still had not obtained deletion of the data from the vendor. In short, one convenient but unapproved AI tool and one poorly closed departure were enough.

A risk small businesses face too

At a small business, this shadow AI would probably have stood out. In fact, it happened to us. A colleague had set up a similar tool, which joined one of our meetings on its own. Since there were only a few of us, we spotted it right away. On the other hand, with a list of 65 people, it is no surprise that nobody noticed at the hospital.

But the meeting is only the visible part of shadow AI. Indeed, nobody sees the tool an employee uses alone, at their desk, to summarize a contract or rephrase a reply to a client. And that holds true whatever the size of the company.

Shadow AI is already at work in your company

Half of Canadian employees say they use generative AI at work, according to a KPMG in Canada survey. Yet according to Statistics Canada, fewer than one business in five reports using it to produce goods or deliver services. Granted, the two surveys measure different things. Still, the gap suggests that a good share of this use escapes management, in the form of shadow AI.

In Quebec, the NETendances survey shows that more than half of workers are not aware of any guidance from their employer on AI. Either the organization has none, or it has not communicated it clearly.

This gap has consequences. For example, a 2024 KPMG survey found that in Canada, nearly one user in four has already entered internal company data into a public AI tool.

On the business side, Statistics Canada reports that declared adoption tripled in two years, from 6.1% to 19.2%. Very small businesses, with 1 to 4 employees, are keeping the same pace (19.9%). Yet they are the ones least likely to cite cybersecurity and privacy as barriers to using AI.

Why unapproved AI is a security issue

Once typed into a consumer tool, information follows the vendor’s rules. On May 6, 2026, Quebec’s Commission d’accès à l’information and three other privacy commissioners published the findings of their joint investigation into ChatGPT. The report notes that in the consumer version, conversations were used by default to train the models. In addition, authorized staff could review them. The Commission considers this setting contrary to Quebec law and recommends reversing it, which OpenAI disputes.

OpenAI is not an isolated case. Anthropic changed its consumer terms in the fall of 2025. Since then, conversations from individual Claude accounts can be used for training if the user agrees. In that case, Anthropic keeps them for five years. For its part, Microsoft uses conversations from consumer Copilot to train its models unless the user opts out. Google, meanwhile, reviews a subset of Gemini conversations to improve its services. Both, however, treat organizational accounts separately.

In every case, the setting belongs to the person who opened the account. The company whose data that person handles therefore has no control over it. Your employees probably do not know about these settings. You need to teach them.

The Quebec government took this risk seriously for its own staff. In March 2025, the government’s chief information officer suspended the use of generative AI assistants in the public service. The first reason given was the disclosure of data outside the public body. The Canadian Centre for Cyber Security also lists the unapproved use of AI tools among organizations’ internal risks.

Banning shadow AI is a false solution

So should you ban it? No. A ban cannot be enforced, and it amounts to burying your head in the sand. Employees who already use AI will keep doing so as shadow AI, on their personal phone or computer, out of sight. A large study by the University of Melbourne and KPMG points in the same direction. Risky behaviours, such as uploading company information to a public tool, are twice as common where generative AI is banned (67%) as where there is no policy at all (33%). This is only a correlation. Even so, it hardly makes the case for a ban.

The Quebec government understood this. Nearly nine months later, in December 2025, it replaced the suspension with a framework. This framework provides approved tools and prohibits entering confidential information into consumer versions of ChatGPT or Copilot. It also requires training before any rollout. A small or mid-sized business can adopt the same principle, scaling the effort to its size.

You can only protect what you know

That leaves the simplest blind spot of shadow AI. You can only protect what you know. A company that does not know which tools its employees use cannot assess their terms. Nor can it cut off access when an employee leaves, or reconstruct what went out after an incident. That is exactly what caught the Ontario hospital off guard.

Law 25 and shadow AI: you are accountable

In Quebec, these quiet shadow AI leaks have legal consequences. Indeed, a business must notify the Commission d’accès à l’information of any confidentiality incident that presents a risk of serious harm. According to its latest annual report, the number of notices the Commission received rose by 559% in three years. Moreover, human error and accidental disclosure weigh almost as much as cyberattacks.

Would a client file pasted into a consumer tool count as an unauthorized disclosure? When the question comes up for real, how will you answer it? What information went out, when, to whom, for how many people, and what is left of it?

Yet undeclared AI use leaves no trail to answer with. Meanwhile, the law requires you to assess the risk and notify affected individuals when it is serious. What you do not know can hurt you.

What you can do to manage shadow AI

Putting a framework around shadow AI takes less effort than you might think. In fact, five measures are enough to get started.

1. Take inventory of shadow AI

Ask your teams which AI tools they use, for which tasks and with which account. Ask without looking for someone to blame, because you want an honest answer.

2. Provide an approved tool

If you do not choose the tool, your employees will, with their personal account: that is how shadow AI takes hold. The difference is concrete. By default, the business offerings from OpenAI and Anthropic are not used for training, unlike individual accounts.

3. Say what never goes into a tool

A short list that everyone remembers, adapted to your context and to what is sensitive in your business.

4. Write a one-page usage rule

Which tools, for which purposes, with which data, and whom to call when in doubt.

5. Train, briefly

One hour to explain the rule, show the approved tool, walk through account settings and share real cases is worth more than a policy nobody has read. Training also goes hand in hand with better results. According to BDC, among Canadian small businesses that use AI, 86% of those that train their staff are satisfied with the return on their investment. By contrast, that is the case for only 53% of those that do not. Admittedly, the study cannot attribute this gap to training alone, but the link is still telling.

Where to start

The whole Ontario case comes down to a poorly closed departure and a tool nobody had approved. In your company, the first question to ask is therefore simple. Which AI tools touch your data? Which data? With which accounts? Ask it this week.

Managing shadow AI protects your data. Getting value from AI, however, takes one more step. Eficio’s AI 360 program helps you choose the use cases worth pursuing and test them on a small scale. It also helps you build the governance that lets you move faster without losing control of your data. Book an exploratory meeting !

Transparency: I wrote this article with the help of AI for research, structure and language review.

Sources

  • Information and Privacy Commissioner of Ontario. Letter to health information custodian, Reported Breach HR24-00691 (https://www.ipc.on.ca/en/media/5995/download), October 27, 2025.
  • KPMG in Canada. “Canadian employees call for clear and transparent AI policies as adoption grows”, news release, November 27, 2025, and “Generative AI use surges in workplaces, posing risks to employers”, news release, November 28, 2024.
  • Statistics Canada. Vicky Do, Shivani Sood and Chris Johnston, Analysis on artificial intelligence use by businesses in Canada, second quarter of 2026 (https://www150.statcan.gc.ca/n1/pub/11-621-m/11-621-m2026010-eng.htm), Analysis in Brief, June 11, 2026.
  • Académie de la transformation numérique, Université Laval. “Intelligence artificielle générative”, NETendances 2025, March 2026.
  • Office of the Privacy Commissioner of Canada, Commission d’accès à l’information du Québec, and the commissioners of British Columbia and Alberta. PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC (https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2026/pipeda-2026-002/), May 6, 2026.
  • “Updates to Consumer Terms and Privacy Policy” (https://www.anthropic.com/news/updates-to-our-consumer-terms), August 28, 2025.
  • “Privacy FAQ for Microsoft Copilot” and “Microsoft Copilot privacy controls”, help pages accessed September 23, 2026.
  • “Gemini Apps Privacy Hub”, help page, and “Generative AI in Google Workspace Privacy Hub”, updated August 14, 2026.
  • Quebec Government Chief Information Officer. Directive IA-RI-2025-001-OP, suspension of the use of generative AI virtual assistants, March 13, 2025, repealed by IA-RI-2025-003-OP of December 5, 2025.
  • Canadian Centre for Cyber Security. Frontier artificial intelligence (ITSAP.10.050) (https://www.cyber.gc.ca/en/guidance/frontier-artificial-intelligence-itsap10050), May 2026.
  • Nicole Gillespie, Steven Lockey, Tiarnach Ward, Alexandria Macdade and Gerard Hassed. Trust, attitudes and use of artificial intelligence: A global study 2025, University of Melbourne and KPMG, 2025.
  • Commission d’accès à l’information du Québec. Rapport annuel d’activités et de gestion 2024-2025, 2025.
  • Act respecting the protection of personal information in the private sector, CQLR, chapter P-39.1, sections 3.5 to 3.8.
  • Mathieu Galliot, The Digital Transformation of SMEs in the Age of Artificial Intelligence (https://www.bdc.ca/en/about/analysis-research/digital-transformation-of-smes-in-the-age-of-artificial-intelligence), June 2026.
  •  

Inscrivez-vous à l’infolettre Eficio et soyez le premier à recevoir notre actualité !