Treadstone Associates
Article · 6 min read

Can staff be disciplined for using AI?

Yes — but “using AI” is not, on its own, a distinct legal category. Discipline for breaking a written AI policy runs through the same two Canadian standards, and the same evidentiary bar, that already govern every other workplace rule.

Treadstone Associates · Updated 2026

Key takeaways

  • • No Ontario or federal statute creates a separate offence for “misusing AI” at work — discipline for breaching a written AI policy is judged under the same just-cause and progressive-discipline principles as any other rule.
  • • Common-law cause and the Employment Standards Act’s own carve-out from termination and severance pay are two different, differently worded tests. Meeting one does not automatically meet the other.
  • • A newly introduced AI policy is a term of employment like any other — courts read a one-sided, after-the-fact change to a fundamental term with real skepticism.
  • • What usually makes “unauthorized AI use” serious enough to act on is what left the building inside the prompt, not the tool itself.

There is no statute that names “AI misuse” as a disciplinary category

Search Ontario and federal employment law for a rule against employees using AI and you will not find one. The only place a Canadian statute defines artificial intelligence for a workplace purpose at all is Ontario’s Employment Standards Act, 2000, and it defines the term for one narrow job: the duty to disclose AI use inside a publicly advertised job posting. (Ontario, Requirements related to publicly advertised job postings) The Act’s own definition is: “a machine-based system that, for explicit or implicit objectives, infers from the input it receives in order to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments.” (same page) Even that definition comes with a built-in disclaimer — the guide adds that “whether a particular system falls within the scope of the definition of ‘artificial intelligence’ under the ESA will depend on the specific facts of each case.” A definition written for one disclosure duty, and hedged even there, is not a general-purpose legal test an employer can borrow for a discipline decision.

Two standards, and they are not interchangeable

What actually decides whether discipline holds up is the same architecture that decides every other Ontario dismissal case, and it has two distinct layers. At common law, the test is proportionality: (Treadstone Law, Just Cause Termination in Ontario) treadstonelaw’s own explainer puts it as “the court asks whether the misconduct, viewed in context, was so serious that it struck at the heart of the employment relationship” — looking at the nature of what was done, the employee’s role and record, and the surrounding circumstances, not whether the conduct fits a label. Poor performance and one bad judgment call, on their own, almost never clear that bar.

Separately, the ESA sets its own, differently worded carve-out before an employer can withhold statutory notice and severance pay. Per treadstonelaw’s summary, “the regulation exempts only an employee guilty of wilful misconduct, disobedience or wilful neglect of duty that is not trivial and has not been condoned”, where “‘wilful’ means deliberate — intentional or persistent conduct, not carelessness, incompetence or an error of judgment.” The practical trap for employers: it is entirely possible to establish common-law cause and still owe the ESA minimums, because the conduct was serious but not deliberate. (Treadstone Law)

Mapped onto an AI policy: an employee who pastes a client file into a personal AI account once, in good faith, having never seen the policy or been warned, is very unlikely to clear either bar on that fact pattern alone. An employee who does the same thing after signing an acknowledged policy and receiving a documented warning for the identical conduct is a much closer fit for “wilful” — deliberate, repeated, and not condoned.

Whether the policy itself will hold up matters as much as the breach

A discipline case built on breaching “the AI policy” is only as strong as that policy’s own enforceability. Employment contracts commonly include language letting an employer “change any term ‘at its sole discretion’ without the employee’s agreement”, and, per treadstonelaw’s review of Ontario contract drafting, “courts have generally treated this kind of broad, one-sided language with skepticism, particularly where it purports to reach fundamental terms like compensation or job duties” — a genuinely fundamental change “usually still requires the employee’s agreement (often supported by fresh consideration) to be enforceable.” (Treadstone Law, Unenforceable Employment Contract Clauses in Ontario) A brand-new AI-use policy, rolled out mid-employment with no notice, sign-off or consideration, risks exactly this problem if it reaches into how someone is actually allowed to do their job. Building a defensible discipline record also means the same paper trail any performance case needs: a standard communicated clearly, a documented warning, and a genuine chance to comply before the next step.

The real exposure is usually the data, not the tool

What makes unauthorized AI use worth disciplining in the first place is rarely the software itself — it is what an employee handed it. Canada’s Cyber Centre names this directly among generative AI’s core risks: “users may unknowingly provide sensitive corporate data or personally identifiable information (PII) in their AI queries and prompts.” (Canadian Centre for Cyber Security, ITSAP.00.041) That risk lands squarely on the employer, not the AI vendor. PIPEDA’s Schedule 1 is explicit that “an organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing”, and must “use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.” (PIPEDA, Schedule 1, clause 4.1.3) An employee who routes customer data through an unapproved consumer AI account has not just broken an internal rule — they have created a live accountability problem the employer cannot hand off to that tool.

What a defensible process actually looks like

Put the two standards together and a workable sequence emerges. First, the policy has to exist in writing, be actually communicated (not buried in a handbook nobody opened), and say plainly what is and is not permitted with which tools and which data. Second, a first breach with no aggravating facts calls for a documented warning, not a termination letter — exactly the “standard communicated clearly” and “clear warnings” treadstonelaw’s own guidance on performance-based cause describes. (Treadstone Law) Third, if the same employee repeats the conduct after that warning, the case for “wilful…and not condoned” strengthens considerably, because condonation — an employer that knew and carried on as normal — is itself a defence that disappears once a clear warning is on file. Employers who skip straight to termination on an isolated, unwarned incident are the ones who end up owing both ESA minimums and, often, common-law notice on top.

Common questions

Does using ChatGPT against policy automatically count as “just cause”?

No. Common-law cause requires misconduct serious enough to “strike at the heart of the employment relationship” — a one-off, good-faith use of an unapproved tool rarely meets that bar on its own, and even where it does, the ESA’s separate wilful-misconduct test may still leave statutory notice and severance owing.

Can an employer discipline for a first, good-faith mistake?

It can, but progressive discipline — a clear standard, a documented warning, and a real chance to comply — is the safer and more defensible route than jumping straight to termination on a first, unwarned incident.

Does Ontario’s AI job-posting disclosure rule affect internal discipline?

No, they are unrelated. The ESA’s AI disclosure duty governs what an employer must state in a job posting, not what it may do about an employee’s conduct after they are hired — see Ontario’s AI disclosure rule for job ads.

Related: Ontario’s AI disclosure rule for job ads, what a workplace AI policy should cover, and operating AI responsibly day to day.

Not sure your AI policy would hold up?

A short call is enough to see whether your acceptable-use policy is actually enforceable, and where the real data risk sits.