On May 6, 2026, four privacy regulators — the federal Office of the Privacy Commissioner, Quebec's Commission d'accès à l'information, and the privacy commissioners of British Columbia and Alberta — published the findings of a joint investigation into OpenAI. They looked at how ChatGPT collected and used Canadians' personal information. The federal office called the consent problems "conditionally resolved," pending fixes OpenAI committed to. Alberta's office and BC's went further: they found the consent violations irreparable under their own provincial privacy law.
That's not a headline about a far-off tech giant. That's Alberta's own regulator, on the record, about the exact tool that's almost certainly open in a browser tab on someone's laptop in your office right now.
The Adoption Numbers Are Real — and Moving Fast
This isn't a hypothetical risk for some future version of your business. Statistics Canada's quarterly business conditions survey found 19.2% of Canadian businesses reported using AI to produce goods or deliver services in Q2 2026 — up from 12.2% a year earlier and 6.1% the year before that. Adoption has roughly tripled in two years.
19.2%
Canadian businesses using AI (Q2 2026)
3x
Adoption growth in two years
1
Alberta regulator flagging ChatGPT's consent
4
Privacy offices in the joint investigation
CFIB separately estimates 23–28% of small and medium businesses have moved at least one generative AI tool past the pilot stage — and among the businesses actually using it daily, CFIB found an average productivity gain of over an hour per user per day. The tools work. That's exactly why this isn't a "just say no" problem.
But there's a gap hiding inside those numbers, and it's the one that matters for this article: approved use and actual use are two different things. A business can report "we don't use AI" in a survey while three employees are pasting client emails into a personal ChatGPT account to draft responses faster. Both things are true at once. The second one is the actual exposure.
Why This Is Your Problem, Not the Vendor's
Here's the part that gets missed: PIPEDA's accountability principle, and Alberta's PIPA alongside it, don't care whose idea the AI tool was. If an employee pastes a customer's name, address, or account details into an AI tool your business never reviewed, and that tool's own privacy practices have already been flagged by regulators — including Alberta's — your business is still the one accountable for that personal information under Canadian law. Not the employee. Not OpenAI. You.
That's not a scare tactic; it's how the accountability principle is written. It's also exactly the gap that the joint OpenAI investigation makes concrete: transparency about training data, consent for how conversations get used, and the ability for someone to find out what a model knows about them were all found lacking. None of that gets better because your business didn't sign the contract — it applies the moment personal information your business is responsible for goes into that tool.
What This Actually Looks Like Day to Day
I'm not describing a hypothetical employee doing something reckless. This is the ordinary way AI gets used inside small businesses right now:
- A bookkeeper pastes a client's financial summary into ChatGPT to draft a cleaner explanation for a report.
- A customer service rep runs an angry email through an AI tool to soften the tone before replying — email that includes the customer's order number, address, and complaint history.
- An HR contact drafts a termination letter with AI help, including performance details about a named employee.
- A contractor with access to your CRM feeds a batch of leads into an AI tool to "clean up" the data before importing it somewhere else.
None of these people think they're doing anything wrong. They're not malicious — they're trying to get through their day faster, which is exactly what Canada's own national AI strategy is trying to encourage at the policy level. The problem isn't the intent. It's that nobody decided, on purpose, which tools that data is allowed to touch.
The Question That Actually Matters
Not "should we allow AI at work" — that ship has sailed. The real question is: which specific tools, under which specific account type, have we actually looked at and approved for which kinds of data? If the honest answer is "we haven't decided," that's the finding.
What to Actually Do About It
You don't need a 40-page AI governance policy. You need three things, in this order:
1. Write down what's off-limits, not just what's allowed. A one-paragraph policy that says "customer personal information, health information, anything under an NDA, and financial account numbers never go into an AI tool that isn't on the approved list" does more work than a long document nobody reads to the end.
2. Put a real account behind the tools people already use. If your team is using ChatGPT or Claude anyway — and the adoption numbers above say they probably are — a business-tier account with an actual data-processing agreement is a small monthly cost against a real accountability gap. Personal, free-tier accounts typically train on your conversations by default and offer you no contract at all.
3. Say it out loud, once, in a meeting. Policies that live only in a shared drive don't change behaviour. Five minutes in a team meeting, with a real example like the ones above, does more than the document itself.
This is exactly the kind of gap I look for in a technology review — not because AI is dangerous, but because "who decided this was okay" is usually the actual missing piece, not the tool itself. If you'd rather have someone build the policy and pick the right account tier for you rather than write it yourself, that's squarely streamline operations work.
Book a Free Call About Your AI Exposure →
Frequently Asked Questions
What is "shadow AI"?
Shadow AI is employees using AI tools the business hasn't reviewed, approved, or put a contract behind — usually a free or personal-tier account for ChatGPT, Claude, or a similar tool, used to draft emails, summarize documents, or answer questions faster than asking a coworker. It's the AI-era version of shadow IT, and it's spreading faster than shadow IT ever did because the barrier to starting is a browser tab, not an IT ticket.
Is it illegal for employees to use ChatGPT at work in Canada?
No, there's no blanket ban. The risk isn't the tool — it's what goes into it. Under PIPEDA federally and Alberta's Personal Information Protection Act provincially, your business is accountable for what happens to personal information it holds, and that accountability doesn't pause because IT never approved the tool an employee happened to use.
What did Canada's privacy regulators actually find about OpenAI and ChatGPT?
In a joint investigation published May 6, 2026 (PIPEDA Findings #2026-002), the federal Privacy Commissioner, Quebec's CAI, and the privacy commissioners of BC and Alberta found that OpenAI collected personal information in an overbroad way without valid consent and didn't get express consent to train on user conversations. The federal office called the issues "conditionally resolved" pending fixes; Alberta's and BC's offices went further, finding the consent violations irreparable under their own provincial law.
How many Canadian small businesses are actually using AI?
Statistics Canada's business conditions survey put AI use at 19.2% of Canadian businesses in Q2 2026, up from 12.2% a year earlier and 6.1% the year before that — adoption roughly tripling in two years. Separately, CFIB estimates 23–28% of small and medium businesses have moved at least one generative AI tool past the pilot stage.
What should a small business actually do about shadow AI, if it can't ban it outright?
Write a one-page policy naming which tools are approved and what data can never go into any of them (customer records, health information, anything under an NDA), turn on a business-tier account with a proper data-processing agreement for the tools people already use daily, and say the policy out loud in a team meeting — a document nobody's seen doesn't prevent anything.
About Code to Cloud
We're based in Alberta and help growing businesses across Western Canada figure out which AI tools are actually worth trusting with real data — and which ones need a contract before anyone touches them again. Disclaimer: This article provides general information only and does not constitute legal, financial, or professional advice. Every business situation is different. Consult with qualified professionals for advice specific to your circumstances. Code to Cloud is not liable for any actions taken based on this content.


