Yes — but “using AI” is not, on its own, a distinct legal category. Discipline for breaking a written AI policy runs through the same two Canadian standards, and the same evidentiary bar, that already govern every other workplace rule.
Key takeaways
Search Ontario and federal employment law for a rule against employees using AI and you will not find one. The only place a Canadian statute defines artificial intelligence for a workplace purpose at all is Ontario’s Employment Standards Act, 2000, and it defines the term for one narrow job: the duty to disclose AI use inside a publicly advertised job posting. (Ontario, Requirements related to publicly advertised job postings) The Act’s own definition is: “a machine-based system that, for explicit or implicit objectives, infers from the input it receives in order to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments.” (same page) Even that definition comes with a built-in disclaimer — the guide adds that “whether a particular system falls within the scope of the definition of ‘artificial intelligence’ under the ESA will depend on the specific facts of each case.” A definition written for one disclosure duty, and hedged even there, is not a general-purpose legal test an employer can borrow for a discipline decision.
What actually decides whether discipline holds up is the same architecture that decides every other Ontario dismissal case, and it has two distinct layers. At common law, the test is proportionality: (Treadstone Law, Just Cause Termination in Ontario) treadstonelaw’s own explainer puts it as “the court asks whether the misconduct, viewed in context, was so serious that it struck at the heart of the employment relationship” — looking at the nature of what was done, the employee’s role and record, and the surrounding circumstances, not whether the conduct fits a label. Poor performance and one bad judgment call, on their own, almost never clear that bar.
Separately, the ESA sets its own, differently worded carve-out before an employer can withhold statutory notice and severance pay. Per treadstonelaw’s summary, “the regulation exempts only an employee guilty of wilful misconduct, disobedience or wilful neglect of duty that is not trivial and has not been condoned”, where “‘wilful’ means deliberate — intentional or persistent conduct, not carelessness, incompetence or an error of judgment.” The practical trap for employers: it is entirely possible to establish common-law cause and still owe the ESA minimums, because the conduct was serious but not deliberate. (Treadstone Law)
Mapped onto an AI policy: an employee who pastes a client file into a personal AI account once, in good faith, having never seen the policy or been warned, is very unlikely to clear either bar on that fact pattern alone. An employee who does the same thing after signing an acknowledged policy and receiving a documented warning for the identical conduct is a much closer fit for “wilful” — deliberate, repeated, and not condoned.
A discipline case built on breaching “the AI policy” is only as strong as that policy’s own enforceability. Employment contracts commonly include language letting an employer “change any term ‘at its sole discretion’ without the employee’s agreement”, and, per treadstonelaw’s review of Ontario contract drafting, “courts have generally treated this kind of broad, one-sided language with skepticism, particularly where it purports to reach fundamental terms like compensation or job duties” — a genuinely fundamental change “usually still requires the employee’s agreement (often supported by fresh consideration) to be enforceable.” (Treadstone Law, Unenforceable Employment Contract Clauses in Ontario) A brand-new AI-use policy, rolled out mid-employment with no notice, sign-off or consideration, risks exactly this problem if it reaches into how someone is actually allowed to do their job. Building a defensible discipline record also means the same paper trail any performance case needs: a standard communicated clearly, a documented warning, and a genuine chance to comply before the next step.
What makes unauthorized AI use worth disciplining in the first place is rarely the software itself — it is what an employee handed it. Canada’s Cyber Centre names this directly among generative AI’s core risks: “users may unknowingly provide sensitive corporate data or personally identifiable information (PII) in their AI queries and prompts.” (Canadian Centre for Cyber Security, ITSAP.00.041) That risk lands squarely on the employer, not the AI vendor. PIPEDA’s Schedule 1 is explicit that “an organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing”, and must “use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.” (PIPEDA, Schedule 1, clause 4.1.3) An employee who routes customer data through an unapproved consumer AI account has not just broken an internal rule — they have created a live accountability problem the employer cannot hand off to that tool.
Put the two standards together and a workable sequence emerges. First, the policy has to exist in writing, be actually communicated (not buried in a handbook nobody opened), and say plainly what is and is not permitted with which tools and which data. Second, a first breach with no aggravating facts calls for a documented warning, not a termination letter — exactly the “standard communicated clearly” and “clear warnings” treadstonelaw’s own guidance on performance-based cause describes. (Treadstone Law) Third, if the same employee repeats the conduct after that warning, the case for “wilful…and not condoned” strengthens considerably, because condonation — an employer that knew and carried on as normal — is itself a defence that disappears once a clear warning is on file. Employers who skip straight to termination on an isolated, unwarned incident are the ones who end up owing both ESA minimums and, often, common-law notice on top.
No. Common-law cause requires misconduct serious enough to “strike at the heart of the employment relationship” — a one-off, good-faith use of an unapproved tool rarely meets that bar on its own, and even where it does, the ESA’s separate wilful-misconduct test may still leave statutory notice and severance owing.
It can, but progressive discipline — a clear standard, a documented warning, and a real chance to comply — is the safer and more defensible route than jumping straight to termination on a first, unwarned incident.
No, they are unrelated. The ESA’s AI disclosure duty governs what an employer must state in a job posting, not what it may do about an employee’s conduct after they are hired — see Ontario’s AI disclosure rule for job ads.
Related: Ontario’s AI disclosure rule for job ads, what a workplace AI policy should cover, and operating AI responsibly day to day.
A short call is enough to see whether your acceptable-use policy is actually enforceable, and where the real data risk sits.