A trade secret’s entire legal protection depends on the information staying secret — so the moment know-how is typed into a tool whose data-handling terms nobody checked, the question isn’t whether a contract was breached, it’s whether the information still qualifies as a trade secret at all.
Key takeaways
The Cyber Centre’s guidance on generative AI names this as its own distinct risk, separate from a privacy breach: “Loss of intellectual property. Generative AI tools may enable sophisticated threat actors to steal corporate data more easily, quickly and in larger quantities. Loss of intellectual property (for example, proprietary business information and copyrighted data) can devastate your organization’s reputation, revenue, and future growth.” (cyber.gc.ca) The distinction matters: a PIPEDA-style breach is about exposing information about a person; this is about an informational asset itself — a formula, a client list, a process — losing the secrecy its value depended on, the moment it leaves the organization’s control through a prompt rather than through a hack.
Treadstone Law’s explainer on confidentiality-clause remedies states the underlying doctrine plainly: “Ontario law also protects trade secrets through the equitable doctrine of breach of confidence independently of any contractual clause. This means even without a written confidentiality agreement, deliberate misuse of genuinely confidential information shared in confidence may be actionable.” (treadstonelaw.ca) That doctrine does not require a signed NDA at all — but it still requires the information to have actually been treated as confidential, which becomes a harder argument to make once the material has been submitted to a third-party AI tool whose retention practices were never reviewed by anyone at the organization.
Beyond that civil doctrine, Parliament made deliberate trade-secret theft a distinct criminal offence. Criminal Code section 391 states that “everyone commits an offence who, by deceit, falsehood or other fraudulent means, knowingly obtains a trade secret or communicates or makes available a trade secret,” punishable on indictment by up to fourteen years’ imprisonment, and the same section supplies the statutory test for what the doctrine above is actually protecting: information that “is not generally known in the trade or business that uses or may use that information,” “has economic value from not being generally known,” and “is the subject of efforts that are reasonable under the circumstances to maintain its secrecy.” (laws-lois.justice.gc.ca, Criminal Code s.391) That third branch of the test is exactly what weakens every time the same information is pasted into an AI tool whose retention practice was never checked.
The same Treadstone Law page describes an injunction as the priority remedy, because “confidential information once disclosed may spread further”; courts can grant interim injunctions applying “the same three-part test” used elsewhere in Ontario civil litigation: “a serious issue, irreparable harm, and a favourable balance of convenience.” Damages are available too, but “must be proven” — courts compensate “losses that flow directly from the unauthorized disclosure,” and “where monetary loss is hard to quantify, courts may consider a ‘reasonable royalty’ or negotiated-price measure of what the parties would have agreed to for a legitimate use of the information.” Applied to an AI leak: if a competitor’s product visibly incorporates a formula that was pasted into a public AI tool, the business still has to show that specific disclosure caused that specific outcome — often the harder half of the claim once the information passed through a third-party service the business does not control.
Treadstone Law’s own advice is to “move quickly: preserve evidence, document the disclosure, and consult a litigation lawyer about emergency relief before the information spreads further” — advice that matters more here given the Cyber Centre’s own framing of scale, that AI tools can let threat actors “steal corporate data more easily, quickly and in larger quantities.” It is worth being precise about what copyright does not do in this scenario: the Copyright Act gives “the author of a work” first ownership of copyright in it, and states that “no assignment or grant is valid unless it is in writing signed by the owner.” (laws-lois.justice.gc.ca) That means a business’s copyright in its own submitted document does not transfer to an AI vendor merely because the material was uploaded — a vendor’s terms of service are not, on their own, a signed written assignment. But that is a narrower and different question from whether the trade secret survived: copyright protects the specific wording of a document, not the underlying formula or process it describes, so a business can keep its copyright intact and still have lost the trade secret the document was written to protect.
A manufacturer’s process engineer pastes an internal formulation sheet into an AI tool to get help rewriting it as a clearer procedure document, without checking whether the tool’s terms permit using submitted content to improve its model. Months later, a competitor’s product specification looks suspiciously similar. Under the breach-of-confidence doctrine, the manufacturer does not need a signed NDA with the AI vendor to have a claim in principle — but it still needs to show the information was genuinely treated as confidential up to that point, and connecting that specific prompt to that specific competitor’s product is the harder evidentiary step the doctrine still requires. The manufacturer’s copyright in the original formulation document, meanwhile, was never at risk in the first place — the AI vendor’s terms could not have taken it without a signed assignment — which is exactly why copyright was never going to be the tool that protected the formula itself.
Related: the contractual side of the same underlying problem, why no single rule governs this scenario yet, how the Copyright Act’s silence on AI plays out elsewhere
Not to have a claim in principle — Ontario’s equitable breach-of-confidence doctrine can apply even without one. But a written agreement makes the confidentiality of the information, and the vendor’s obligations regarding it, far easier to prove than relying on the doctrine alone.
Not automatically, but it becomes a harder argument. The doctrine requires that the information was genuinely treated as confidential, and submitting it to a service whose retention practices were never reviewed weakens that argument even if no visible leak has occurred yet.
No. Copyright protects the specific wording or expression of a document, not the underlying idea, formula or process it describes — that protection comes from trade secret law, not copyright, which is why losing secrecy is the real risk here, not losing copyright.
Not under the breach-of-confidence doctrine, which turns on whether the information was shared in circumstances importing an obligation of confidence, not on the format it was shared in — an AI prompt, a written document and a spoken conversation can all qualify if the underlying information was genuinely treated as confidential.
A clear policy on what can and can’t go into a prompt is an operations decision, not a legal afterthought.