Treadstone Associates
Article · Liability

Can I be sued for negligence over AI use?

Not for using AI. For work that fell below the standard of care and caused a loss — which is what you could always be sued for. The tool is evidence about conduct, not a separate wrong.

Treadstone Associates · Updated 2026

Key takeaways

  • • There is no Canadian cause of action for ‘using AI’. A claim still runs on standard of care, causation, damages and limitation.
  • • The standard of care is set by what a reasonable practitioner in your position would have done — Treadstone Law explains how Ontario courts decide it.
  • • Causation is where most claims are won or lost, and an unverified output that a client would have rejected on sight is a clean causal story for a plaintiff.
  • • In tax work the exposure is not only civil. Section 163.2 of the Income Tax Act penalises culpable conduct, defined to include indifference as to whether the Act is complied with.

The short answer

Yes, in the sense that you have always been suable: a client who says your work fell below the standard of a reasonable practitioner and cost them money can bring a claim, and it makes no difference whether the faulty paragraph was typed by you, by an articling student or by a model. Canadian law has not created a distinct AI tort, and there is no reason to expect one, because the existing framework already handles ‘you used a tool badly’.

What is genuinely different is the evidence. AI-assisted work leaves an unusually legible trail of what was checked and what was not, and it changes what a plaintiff can allege at the pleading stage.

The four questions a claim turns on

The useful observation is that AI moves the argument onto the second question and keeps it there. A plaintiff does not have to establish that a language model is unreliable in general; they only have to establish that a reasonable practitioner would have opened the source document before relying on the summary of it.

Where the standard of care is actually being written

Standards of care are informed by what the profession does and what its bodies say. Two Canadian sources are already doing that work in accounting. The AASB's summary of its Technology Quality Management roundtable records the practices firms describe using today: human involvement at critical points, centralised certification of firm-level tools, rigorous validation of inputs and outputs for engagement-level tools, risk-based testing, limits on how tools may be used in engagement files, and mandatory training before staff use them. CPAB's technology in the audit page records that the use of technology is an inspection focus, including the quality management practices around approving and maintaining automated tools at both firm and engagement level.

You do not have to be a CPAB-inspected firm for that to matter to you. Once a professional body has described what careful firms do, a plaintiff's expert has a benchmark, and ‘we had no policy’ stops being neutral.

Three exposures that are specific rather than general

Tax positions. Section 163.2 of the Income Tax Act imposes a penalty on a person who makes, participates in, assents to or acquiesces in the making of a false statement that could be used by another person for a purpose of the Act, where the person knows it is false or would reasonably be expected to know but for circumstances amounting to culpable conduct — defined in subsection 163.2(1) to include conduct showing indifference as to whether the Act is complied with. Subsection 163.2(5) sets the penalty at the greater of $1,000 and a further calculated amount. This is a personal exposure that no engagement letter limits.

Confidentiality. Sending client information into a service you have not diligenced is a separate wrong from getting the answer wrong. The Privacy Commissioner's principles for responsible, trustworthy and privacy-protective generative AI state plainly that generative AI does not occupy a space outside current legislative frameworks, and that organisations developing, providing or using it must ensure their activities comply with applicable Canadian privacy laws.

Records. If the file cannot show what was done, you argue the standard of care with no evidence. In tax practice the retention obligation is statutory: section 230 of the Income Tax Act requires records adequate to determine the taxes payable, paragraph 230(4)(b) sets a general six-year floor from the end of the last taxation year to which the records relate, and subsection 230(4.1) requires electronic records to be kept in an electronically readable format for that period.

What does not help

Two instincts are worse than useless. The first is a disclaimer. Treadstone Law's note on whether a professional can avoid liability with a disclaimer in the engagement letter explains how Ontario courts approach these, and the short version is that they are not a switch. The second is blaming the client for supplying bad inputs; contributory negligence by a client reduces rather than eliminates, and pleading it can look like an admission.

What does help is boring: a written scope, a record of what was verified, and a firm policy that a reviewer can point to. If a claim is brought against the firm rather than you personally, the vicarious liability analysis is a further reason the policy needs to exist in writing.

Worked example (illustrative)

A consulting engineer's report cites a code clause that a model produced and nobody opened. The clause number is real; the requirement it states is from an earlier edition. The client builds to it, a reviewing authority rejects the work, and the rectification cost is the claim.

Notice which element that scenario satisfies effortlessly. Standard of care: a reasonable engineer opens the code. Breach: nobody did. Causation: the client relied and spent. Damages: the rectification invoice. The presence of AI is not the wrong; it is the reason the trail is short and clear.

The countable control is equally short: the proportion of external references in issued documents that carry a verifier's initials and a date. That is a number a firm can report to its insurer.

Questions we get asked

Does telling the client I used AI protect me?
No. Disclosure is a professional and sometimes a court requirement; it is not a defence to negligent work.

Can I sue the AI vendor if its output was wrong?
That is a contract question against the vendor's terms and is separate from your client's claim against you. Your client sues you.

Should we ban AI to reduce risk?
Firms that ban it usually get shadow use with no record, which is the worst evidentiary position of the three. A written policy with a verification step is the defensible middle.

See where AI pays off first in your firm.

A 30-minute call is enough to tell you whether AI pays for itself here.