Once it’s typed in, getting it back out isn’t guaranteed.
Short answer
It depends entirely on the product and its settings, but the safe assumption is yes by default. Canada’s Cyber Centre warns plainly that people using generative AI tools “unknowingly provide sensitive corporate data or personally identifiable information (PII) in their AI queries and prompts” — and once information has been sent to a third-party service, you are relying on that service’s own retention practices to control what happens to it next.
Canada’s joint privacy principles for generative AI split this into two roles: “developers and providers” who “determine how a generative AI system operates, how it is initially trained and tested, and how it can be used”, and organisations “using” the tool for their own purposes. Whichever role applies to the product you’re using, PIPEDA doesn’t let responsibility disappear once information leaves your screen — the accountable party is whoever collected it from you, not the AI system it ended up inside.
PIPEDA’s definition of personal information is broader than most people assume, as an existing-law explainer on the topic notes — it covers a name, address or account activity, and can extend to anything that can realistically be tied back to a specific person. If what you typed fits that definition and it leaks, PIPEDA’s breach-reporting duty turns on whether there is “a real risk of significant harm”, which the Act itself defines to include “bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft… and damage to or loss of property”. That duty comes with a paper trail requirement too: “an organization must maintain a record of every breach of security safeguards for 24 months after the day on which the organization determines that the breach has occurred”, whether or not that breach ever crosses the threshold that triggers notification. What else that record has to contain is covered here.
Don’t type anything into a general-purpose AI tool that you wouldn’t be comfortable sending to an outside vendor by email, because that is functionally what you’re doing. See can I stop a tool training on my data and can an accountant use AI on client files for the two situations where this comes up most often.
Controlling what actually reaches a live AI tool, day to day, is an operations problem more than a one-time policy.