Most AI training programs teach prompting. The gap that actually gets Canadian businesses into trouble is narrower and less exciting: what not to paste in, when to stop trusting the output, and who has to sign off before it goes out the door.
Key takeaways
The Canadian Centre for Cyber Security’s guidance on generative AI names eight concrete risk categories, and they map directly onto a training curriculum better than any generic “AI literacy” course: misinformation and disinformation, phishing, privacy of data, malicious code, buggy code, poisoned datasets, biased content, and loss of intellectual property. (Canadian Centre for Cyber Security, ITSAP.00.041) The one that shows up in the most workplaces first is data handling: “users may unknowingly provide sensitive corporate data or personally identifiable information (PII) in their AI queries and prompts.” Phishing is the second most immediately relevant — the Centre warns that “threat actors can craft targeted spear-phishing attacks more frequently, automatically, and with a higher level of sophistication” using the same generative tools staff are being trained to use for legitimate work, which is a reason to train people to recognize AI-polished phishing, not just to avoid producing it.
The single most transferable habit any AI training should build is treating output as a draft, never a finished answer. The Cyber Centre is blunt about why: outputs “can be incorrect”, “might not make sense”, “might not take certain factors into account”, and “can be biased”. Its own instruction to users is exactly the habit to train: “you should always be aware of and validate your sources to verify whether the content being presented is accurate.” (same guidance) That is a checkable behaviour — did the employee confirm a client name, a figure, a citation, a policy detail against a real source before sending it — not a vague attitude, and it is the one piece of training that applies to literally every use case a business will find for the tool.
Under PIPEDA, an organization’s accountability for personal information is not satisfied by writing a policy and hoping staff read it. Schedule 1 says organizations “shall implement policies and practices to give effect to the principles”, and spells out what that actually includes: “training staff and communicating to staff information about the organization’s policies and practices” is listed alongside procedures to protect information and a complaints process, as one of the required elements. (PIPEDA, Schedule 1, clause 4.1.4(c)) Feeding customer or employee personal information into an AI tool without staff understanding the organization’s own rules for doing so is exactly the gap that clause exists to close — it turns “we have a policy” into something an organization can actually demonstrate it did.
Statistics Canada’s most recent survey of AI-using businesses found that 44.4% made changes to training or staffing practices as a result of adopting AI — 32.0% provided AI-related training for existing employees, and 21.6% trained existing executives specifically. (StatCan, AI use by businesses in Canada, Q2 2026) The pattern scales with size and seriousness of adoption: among AI-using businesses with 100 or more employees, 68.1% trained existing employees and 51.7% trained existing executives, versus 24.0% and 15.6% respectively among the smallest AI-using businesses (1–4 employees). Among larger adopters, 30.2% also brought in external consultants or vendors to help, more than double the smallest firms’ 10.7%. The honest reading is not that every Canadian business trains staff on AI — StatCan’s own separate survey found two-thirds of Canadian businesses have no plans to adopt AI at all — but among businesses that do adopt it seriously, training is close to standard practice, not an afterthought.
Someone configuring a chatbot or voice assistant that customers will talk to needs a training track the rest of the staff do not. Canada’s Voluntary Code of Conduct on generative AI puts one obligation on whoever manages such a system in plain terms: “ensure that systems that could be mistaken for humans are clearly and prominently identified as AI systems.” (ISED, Voluntary Code of Conduct) It is voluntary and binds only the 46 organizations that signed it, but it is the closest thing Canadian federal policy has to a disclosure norm for AI that talks to the public, and it is a training item, not just a copywriting one — the person configuring the greeting message needs to know the norm exists before they can honour it. The same code recommends a developer “employ adversarial testing (i.e., red-teaming) to identify vulnerabilities” before a system ships, which is itself a trainable skill: someone on the team should be taught to actively try to break the tool’s guardrails before a customer does it by accident.
Put together, the sources above point to a training session that is short, specific, and testable rather than a broad “AI literacy” seminar: what categories of data may never be pasted into a public AI tool, and which internal tool is approved instead; how to validate an output before it reaches a client, a filing, or a public-facing message; who signs off on AI-assisted work before it goes out; and, for anyone building a customer-facing bot, the disclosure norm above. A new hire who can answer those four questions correctly has had the training that actually reduces risk. A new hire who can write an elegant prompt but does not know what data they are allowed to put in one has not.
What not to paste into a prompt — client names, unreleased figures, personal information, anything covered by a confidentiality obligation. Canada’s Cyber Centre names this as the leading generative-AI risk, and it is the fastest way training pays for itself.
Not by a standalone AI statute. But PIPEDA’s accountability principle lists staff training as part of what an organization must do to give effect to its privacy obligations, which reaches AI use the moment personal information is involved.
StatCan’s data shows training scales with adoption seriousness rather than being universal — smaller AI-using businesses train at a lower rate than larger ones, but the risks the Cyber Centre names do not shrink with headcount.
Related: what a workplace AI policy should cover, can staff be disciplined for using AI, and building AI adoption into a wider plan.
A short call is enough to map the two or three risks specific to your workflow before you write a training deck.