“Shadow AI” is what happens when staff start using AI tools the business never chose, reviewed, or agreed to be responsible for — a free account, a browser extension, a personal subscription put to work on a company task. The tools themselves are often perfectly capable. The problem is that nobody with the authority to say yes or no ever got asked, and Canadian privacy law does not care whether a tool was approved before it decides who answers for what went into it.
Key takeaways
The distinction is not about capability — a free consumer AI account can be just as good at the task as an enterprise one. What is missing is everything the business would normally put in place around a vendor: a contract that says what happens to the data, a data-processing agreement, a security review, and someone inside the business who is responsible for having checked those things. None of that exists for a tool an employee picked on their own to get a task done faster. The business is exposed to whatever that tool does with the data it receives, without having had any say in what that is.
Canada’s Centre for Cyber Security names this as one of the concrete risks of generative AI use, under a heading it calls “Privacy of data”: “Users may unknowingly provide sensitive corporate data or personally identifiable information (PII) in their AI queries and prompts.” The word “unknowingly” is doing real work in that sentence — the risk is not usually a staff member deliberately leaking something. It is someone pasting a customer file into a chat window to get a faster summary, without stopping to ask where that data goes next, how long it is kept, or whether it might be used to train the tool for other users. A tool the business never reviewed is a tool the business has no way to answer any of those questions about.
This is where shadow AI stops being a productivity question and becomes a compliance one. PIPEDA’s Schedule 1, clause 4.1.3, states the rule without carving out an exception for tools nobody signed off on: “An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.” An unapproved AI account is, for this purpose, a third party the information has been transferred to. The business is still responsible for it, and clause 4.1.1 keeps that responsibility pinned to a specific designated individual inside the organization, not to whichever employee happened to paste the data in. Nobody approving the transfer does not mean nobody is accountable for it — it means the accountable person finds out about the exposure after it has already happened, which is the wrong order for the accountability this article covers to actually work.
The Office of the Privacy Commissioner’s own generative-AI principles distinguish between organizations that develop AI systems and organizations that use them, noting that an organization “might shift between or play multiple roles at once” — and every one of the nine principles that follow, including Accountability and Safeguards, is written on the assumption that the organization using a tool actually knows it is being used. A tool operating entirely outside that visibility cannot be governed by a policy that was never applied to it, which is exactly the gap shadow AI opens.
A blanket ban rarely works, because it does not remove the reason staff reached for an unapproved tool in the first place — usually that the approved option is slower, missing, or nobody knew one existed. The more durable fix is the same discipline any new tool touching business or customer data should get, stated in a policy employees actually see rather than left as an assumption. Ontario’s general employment-privacy principles — not written with AI in mind, but directly transferable — make this same point about any new system that touches employee or business data: “review any new monitoring tool or HR software for what data it collects before you roll it out, not after”, and put the resulting practice into a written policy employees actually receive. The AI-specific version of that discipline is a short approved-tools list staff can actually find, reviewed before it is needed rather than after an incident forces the review.
A worked example
A staff member cannot get a fast answer from the business’s approved research tool, so they open a free AI account on their own laptop and paste in a client’s file to get a faster summary. Nothing about their intent was careless. But the business now has customer personal information sitting inside a vendor it never reviewed, has no contract with, and did not know was involved — and under PIPEDA, that exposure belongs to the business the moment it happened, not from whenever the business finds out about it.
No — the difference is not the tool’s capability, it is the absence of everything a business normally puts around a vendor: a contract, a data-processing agreement, and a person accountable for having reviewed them. An unapproved tool has none of that in place before data reaches it.
No. PIPEDA’s Schedule 1 makes an organization responsible for personal information in its custody “including information that has been transferred to a third party for processing,” with no exception for a transfer nobody at the business approved. Accountability for the organization’s compliance still rests with its designated individual under clause 4.1.1.
Ask, rather than assume. Canada’s Cyber Centre frames the core risk as staff “unknowingly” putting sensitive data into an AI tool’s prompts — which means the fastest way to find the gap is a plain conversation about what tools people are already using, followed by a short, genuinely usable approved-tools policy rather than a ban nobody will actually follow.
Yes. What matters for PIPEDA is where the data ended up and who has a contract with the vendor, not whose credit card paid for the account. A personal subscription used on a company file is, from an accountability standpoint, indistinguishable from any other unreviewed third party the information was transferred to.
Related: who is accountable when AI decides, and keeping a human in the loop without slowing everything down.
A short call covers how to build an approved-tools list people will actually follow.