Treadstone Associates
Ask an Expert · 5 min read

Can my employer read my AI prompts?

A prompt typed into a company-provided AI assistant is closer to a work email than a private conversation — and Ontario has a specific, if narrow, rule about disclosing that kind of monitoring.

Treadstone Associates · Updated 2026

Short answer

Generally, yes, on an employer-owned or company-provided AI tool used for work. Ontario employers with 25 or more employees must maintain a written policy disclosing whether and how they electronically monitor staff, including through “a software program created specifically for this purpose” — but the ESA rule is a disclosure duty, not a limit on what can be read.

The rule that actually covers this

Since 2022, Ontario employers that count 25 or more employees on January 1 of a given year must have a written electronic-monitoring policy in place by March 1 of that year. The guidance sets out three separate things the policy has to cover: how the employer may electronically monitor employees, the circumstances in which it may do so, and the purposes the resulting information may be used for. It gives online chats through a purpose-built software program as its own worked example — the same shape as an internal AI assistant — and it applies even where the monitoring runs through “the employee's own personal computer that is used for work purposes.”

What the rule deliberately does not do

The guidance is direct about the limit: these requirements “do not establish a right for employees not to be electronically monitored by their employer” and “do not create any new privacy rights for employees.” The employer's obligation is to be transparent about monitoring that happens — not to limit how much of it happens, or what it's used for, beyond stating the purpose in the policy.

What backs this up where the ESA doesn't reach

For most provincially regulated Ontario employers, PIPEDA doesn't govern purely internal employee records the way it governs customer data — that gap is real. Employees generally have a reduced, not zero, expectation of privacy on employer-owned systems, and a written policy that is actually communicated matters a great deal here. Where the AI tool is a third-party vendor rather than something built in-house, PIPEDA's vendor-accountability rule does reattach — see how it applies once the data actually leaves the building.

Related questions

See also: what happens once that prompt data leaves the employer's own systems, where a monitoring or AI-use policy should actually be written down, why the calculus shifts for a sensitive HR conversation.

Where this leads

Deciding what a workplace AI policy actually says once a tool is in daily use is operations work — ai-operations covers it.