Almost certainly not, unless it already names the specific purpose and the fact that a third-party tool is involved — a generic service-provider clause rarely clears that bar on its own.
Short answer
Probably not, even if it already mentions third-party service providers in general terms. PIPEDA's Openness principle asks whether a policy specifically and understandably describes what's actually happening with personal information — and Canada's generative-AI-specific guidance asks for that at the level of the AI system's actual lifecycle, not a generic reference to unnamed technology. A policy written before an AI feature was added usually names the wrong things, or names them too vaguely, to genuinely cover it.
PIPEDA Schedule 1, clause 4.8 requires an organization to “make readily available to individuals specific information about its policies and practices relating to the management of personal information,” in a form that is “generally understandable.” Clause 4.2 requires purposes to be “identified by the organization at or before the time the information is collected.” A policy doesn't need to say “artificial intelligence” to satisfy this — but it does need to describe, specifically enough for a reader to actually understand, what's being done with their information and by what means.
Canada's joint generative-AI principles apply that standard directly to AI: organizations should “inform individuals what, how, when, and why personal information is collected, used or disclosed throughout any stage of the generative AI system's lifecycle (including development, training and operation) for which the party is responsible.” A policy that only ever said “we may use technology to help provide our services” was written for a much lower bar than this.
Run your existing policy against three questions rather than rewriting it on instinct. First, does it disclose that a third-party service provider or processor handles personal information at all — most legacy policies do, at least generically. Second, does it name AI or an automated tool specifically, or use a purpose description broad enough to genuinely cover what's actually happening (“to provide and improve customer support” only covers AI-assisted support if that's a fair reading of what a customer would expect from it). Third, does it disclose the lifecycle stage that matters for your use — for example, that an AI tool drafts responses to enquiries, versus a vague reference to unspecified “technology.” If only the first box is checked, the policy discloses that a third party is involved but not what that third party is actually doing with the information at the level of specificity the Openness principle calls for.
This companion piece covers how to actually draft that update once the gap is confirmed. Treadstone Law’s privacy-policy checklist for Ontario businesses covers the rest of what a compliant policy needs to include beyond the AI-specific piece, and the related consent question covers what happens when the gap turns out to be a consent problem rather than a disclosure problem.
See how AI fits into a compliant growth and marketing engine.