The AI acceptable use policy: the document most SMEs are missing
Shadow AI, seven principles, roles, prohibited uses, practical appendices: how to give your SME an AI acceptable use policy that meets Law 25.

Shadow AI is already in your offices
An estimator in Granby pastes three pages of a quote into ChatGPT to rewrite it before sending. An assistant drops the client list into a free tool to prepare a mailing. A controller asks a public AI to analyze the payroll file to spot discrepancies. Nobody meant any harm. Everybody wanted to save time.
This phenomenon has a name: shadow AI, meaning the use of artificial intelligence tools without the company’s approval or oversight. The problem is not the tool itself. It is that personal information, pricing and trade secrets leave your perimeter for servers outside Quebec, without the prior assessment section 17 of Law 25 requires, sometimes under a licence that lets the provider reuse whatever is submitted. And there is no record of what went out.
Law 25 applies to every business that holds personal information in Quebec, with no size or revenue threshold. The risk is no longer theoretical: the first penalties from the Commission d’accès à l’information (CAI) were made public in 2026. The CAI can impose administrative penalties directly, up to $10M or 2% of worldwide revenue, the courts can impose penal fines reaching $25M or 4%, and anyone harmed has a private right of action carrying punitive damages of at least $1,000 where the fault was intentional or gross.
Banning AI settles nothing: employees switch to their personal phones and the problem goes invisible. The durable answer is a short, clear, signed document that says what is allowed, what is controlled and what is prohibited. That is exactly what an AI acceptable use policy is for.
$10M
maximum administrative penalty the CAI can impose directly (or 2% of worldwide revenue)
$1,000
minimum punitive damages per person where the fault was intentional or gross (private right of action)
Seven guiding principles, not one more
An effective policy fits on a few pages. It does not try to cover every eventuality: it sets principles anyone can apply when the situation is new. Seven are enough.
- A human in the loop: no decision with a significant effect on a person (hiring, credit, dismissal, a claim) is made by AI alone; a human able to review signs off before anything happens.
- Sovereignty and confidentiality: sensitive data stays in Quebec or in Canada; local hosting is preferred and any transfer outside Quebec requires a prior assessment.
- Transparency: it is disclosed when content or a decision comes from an AI, internally and to clients.
- Fairness and non-discrimination: uses are checked for bias, particularly in HR and customer service.
- Security: controlled access, encryption, logging; AI must not become a back door into your systems.
- Compliance: Law 25, Law 96 and sector obligations apply to AI as much as to anything else; French remains the working language.
- Accountability: every AI output has a human owner; “the AI said so” is never an excuse.
Two roles to name, one of them mandatory
The first role is the privacy officer. It is not optional: Law 25 has required it since September 22, 2022. By default that function falls to the person with the highest authority in the business, often without their knowing it. It can be delegated in writing, and the officer’s title and contact details must be published on your website. In the AI context, this is the person who settles the questions touching personal information: redaction, consent, transfers, incidents.
The second role is the AI lead. The law does not require that one, but experience makes it indispensable. They keep the register of approved tools and the register of use cases, receive requests to add tools, organize training and serve as the single point of contact. In an SME the same person can wear both hats, provided it is written down.
Around them, the policy sets out what is expected of management (setting the tone and providing the resources), of IT (securing and monitoring), of managers (applying the rules within their team) and of every employee (following them and flagging doubts).
Allowed, controlled, prohibited: the structure that works
The heart of the policy fits in three columns. Every AI use falls into one of them, and anything not yet classified is treated as controlled until the AI lead decides.
The examples have to speak to your teams. At a manufacturer, name the drawings and the bills of materials. At an accounting practice, clients’ financial statements. The most important prohibition comes down to one sentence to pin up by the coffee machine: never put personal information, trade secrets, pricing or quotes into an unapproved public AI tool.
When in doubt, put no sensitive data into the AI and ask the AI lead.
| Category | Concrete examples | Condition |
|---|---|---|
| Allowed | Rewriting text with no sensitive data, summarizing a public article, generating headline ideas | No identifying or confidential data goes into the tool |
| Controlled | Analyzing internal documents, preparing a quote, transcribing a meeting | Tool approved in the register, personal information redacted beforehand, human sign-off on the result |
| Prohibited | Submitting identifying or confidential data (personal information, trade secrets, pricing, quotes) to an unapproved public tool; letting AI make a decision with legal effect on its own | No exception without written authorization |
Aligning with ISO/IEC 42001 and the NIST AI RMF without drowning
Two international frameworks now structure AI governance. ISO/IEC 42001:2023 defines an artificial intelligence management system, as ISO 27001 does for information security, and overlaps a good part of the requirements in the European AI Act. The NIST AI RMF, published by the American standards institute, organizes risk management into four functions: govern, map, measure and manage.
Neither is mandatory in Quebec. An SME does not need to aim for certification; it needs a policy written in line with these frameworks, without claiming an attestation it does not hold. In practice that means named roles, a use case register, a proportionate risk assessment before each deployment, documented controls and a periodic review. If an important client or a prime contractor one day insists on ISO 42001, you will already have the frame.
When it goes wrong: incidents and the register
An employee admits they put the employee file into a public tool last month. That is a potential confidentiality incident, and Law 25 governs what happens next. If the incident presents a risk of serious injury, you have to notify the CAI and the people concerned “promptly.” A point of honesty: unlike the European GDPR and its 72-hour deadline, the Quebec statute sets no numerical deadline. Delaying without a documented reason will still count against you.
Every incident, reported or not, has to be entered in a register kept for at least five years (sections 3.5 to 3.8). The AI acceptable use policy extends that obligation: it provides for a blame-free reporting channel, because an employee who fears a sanction will stay quiet, and silence is what costs money. It also describes the first moves: stop the use, document what went out, assess the harm, fix the cause.
5 years
minimum retention period for the register of confidentiality incidents (Law 25, ss. 3.5 to 3.8)
The five appendices that keep the policy alive
A policy with no tools for applying it stays a pious wish. Five appendices keep it alive day to day.
- The register of approved tools: tool name, provider, hosting location, data permitted, restrictions. This is the reference an employee checks before using anything at all.
- The use case register: every AI use in production, its owner, the data processed, the risk level and the date of the last review.
- The simplified assessment grid: a privacy impact assessment proportionate to the size of the project, required by section 3.3 before any system that processes personal information.
- The incident log: the register the law requires, ready to fill in, with the fields needed to assess the risk of serious injury.
- The acknowledgment: every employee signs that they have read and understood the policy. Without a signature, it is hard to invoke a breach.
Where to start this week
Start by measuring the shadow AI in your own building: a five-question anonymous survey is enough to find out who is using what. You will probably be surprised. Then appoint the privacy officer, if that is not already done, and designate an AI lead. Draft a short first version of the policy, six pages at most, with the allowed, controlled, prohibited table and the five appendices. Get it signed. Schedule the review in a year: tools change fast, and a policy that mentions services that no longer exist loses all credibility with your teams.
The policy fits into a wider compliance effort. Our Law 25 compliance guide covers all the obligations in the Act, and our practical guide to the privacy impact assessment sets out the assessment required before each deployment. If your current tools are hosted in the United States, also read our analysis of the CLOUD Act and data sovereignty: which tools belong in the register depends directly on it.
Finally, the best policy is the one that offers an alternative. Banning public tools only works if employees have an approved assistant, hosted on your own infrastructure, that does an equivalent job. That is often where governance meets architecture.
Frequently asked questions
Is an AI acceptable use policy mandatory in Quebec?
No law requires a document with that title. Law 25 does require personal information governance policies, a privacy impact assessment before any system that processes such information, and rules around automated decisions. An AI acceptable use policy is the simplest way to demonstrate that those obligations are met once AI is in the picture.
Can we just block ChatGPT and the public tools?
Technically yes, but the usage immediately migrates to personal devices, out of IT’s sight entirely. Blocking with no alternative makes shadow AI worse rather than removing it. A clear policy, paired with approved tools that do an equivalent job, gets far better results.
Who should the privacy officer be?
By default, Law 25 assigns that role to the person with the highest authority in the business. The function can be delegated in writing to a member of staff or to a third party. In every case, the officer’s title and contact details must be published, on your website in particular.
Do we need a privacy impact assessment for every AI tool?
Section 3.3 of Law 25 requires a privacy impact assessment before any project to acquire, develop or redesign a system that processes personal information. An AI tool that touches client or employee data is therefore caught. The assessment has to be proportionate: a simplified grid is enough for a small project.
What do we do if an employee has already put sensitive data into a public tool?
Treat the situation as a potential confidentiality incident. Document what went out, assess the risk of serious injury, enter the incident in the register kept for at least five years and, if the risk is serious, notify the CAI and the people concerned promptly. Punishing the employee who came forward in good faith would send the worst possible message.
Does the policy have to be written in French?
Yes. The Charter of the French Language, strengthened by Law 96, requires an employer’s communications to staff to be in French. Since June 1, 2025, francization obligations apply from 25 employees. Nothing stops you offering a translation, but the French version governs.
Sources and references
This article is a plain-language summary, accurate as of the date shown. It is not legal advice: for your own situation, consult a legal adviser or contact the Commission d’accès à l’information.
Read next
Compliance
Law 25: the complete compliance guide for Quebec businesses
Read →
Compliance
The privacy impact assessment, demystified: how to assess an AI project before you deploy it
Read →
Sovereignty
CLOUD Act: why a server in Montreal is not always sovereign
Read →
A question about your own compliance?
The discovery call is free and takes half an hour. You leave with an honest read on your situation.
Let’s talk