The use of artificial intelligence (AI) by Canadian companies is growing rapidly, but its use in workplaces raises a number of ethical, legal, and operational questions for employers. Which AI technology should we use? How do we ensure AI is used securely and effectively? How should we safeguard the business from privacy risks? How can we manage and govern employee AI usage?
Following on from our recent webinar on AI in the workplace, we’re answering the questions we received from business leaders and managers about the implications of adopting AI and their concerns around its safe use in today’s workplace.
Artificial intelligence (AI) is the use of computer systems to perform complex tasks in a similar way to humans. Here are some core concepts and definitions:
Chatbot: a digital tool or software application designed to simulate conversation with users (primarily via text or synthesised speech).
Generative AI (GenAI): a type of AI system that can create or generate new content (e.g. text, images, video, music, code) based on models and patterns detected in existing data.
Large language models (LLMs): specialised type of Generative AI focused on creating and processing human language, e.g. ChatGPT, Gemini, Claude.
Machine learning (ML): computers learning from data without explicit programming.
Predictive AI: tools that use historical data, statistical analysis, and machine learning to forecast future events, anticipate behaviours, and identify hidden patterns.
Given that many organizations and employees use AI in the workplace, every business should have a robust policy to ensure you are able to harness the benefits of AI while assessing and minimizing risks to the company, your employees and clients.
An effective AI policy should:
Explain why you are adopting AI and provide a framework for identifying areas where the technology can improve operations.
Define acceptable use, e.g. roles that can use AI, the tools to use, and types of data that can be used vs restricted data.
Describe what training and support you will offer employees to ensure they know how to use AI safely and effectively.
Ensure use of AI complies with privacy, human rights, anti-discrimination, and health and safety laws, as well as meeting all employment obligations, e.g. consulting with affected employees if roles change substantially.
Define roles and responsibilities for monitoring AI use, and identifying and addressing issues.
For more guidance, read our post on why you need a workplace AI policy.
See above. We recommend making the policy as robust as possible so it establishes clear guidelines for use of AI tools by employees while also protecting your organisation from data leaks, and legal and reputational risks.
For government advice, see the Canadian Centre for Cyber Security's guidance on the use of generative AI.
Absolutely. MyHR’s advisory team works with customers to create customized AI usage policies that ensure the responsible use of AI by employees and safeguard the business.
There is no need to halt work progress while considering content for your AI usage policy. Open communication with employees is key and will provide a good basis for your policy.
Talk your team about AI and that you are creating a policy to cover its use in the workplace. Clearly outline any guardrails you want to have in place - e.g. tools that can be used, settings so company data is not used to train the model, deleting chats monthly - and share these to your team via normal channels.
To find the best AI solution for your business, you will need to do some scoping work to define your main goal (or problem) and compare platforms based on your needs and budget.
There are a lot of options to consider and you should fully understand how each tool works, its security settings, and how it will integrate with your operations. You should also test tools before adopting them.
For many smaller employers without specialist technical staff, it pays to consult experts.
Whether your employees are able to use generative-AI tools like ChatGPT will depend on the type of industry you are in, the tasks performed by individual roles, and your company’s expectations around AI use.
We recommend you start by assessing the benefits and risks of using AI, so you fully understand the tools’ capabilities and any potential downsides. You should also seek to understand whether employees are already using AI tools at work (many people may not realize they are already using AI, e.g. Gemini answer summaries on Google search result pages).
From there you can decide if using AI will be beneficial for the business, and then create an AI use policy to define and formalize use of AI tools in your workplace. As with introducing any new policy or technology, you should couple the roll out with education and training for employees.
Many AI tools archive user input and may use it for training, potentially exposing company data to the public or your competitors. Before using any AI tool in the workplace, we recommend undertaking a privacy impact assessment to understand how the tool(s) work, what data sources they are trained on, how data is used and stored, and other potential risks to privacy and confidentiality.
Regardless, the basic rule of thumb to remember is if the information is something you wouldn't want others to know or see, it's best not to enter it into a public AI tool. This includes personally identifiable information (PII), intellectual property or proprietary information (including ideas, plans or code), financial or legal documentation, or sensitive communications.
What AI tools do with user data differs from platform to platform, but if you are paying a subscription you should be able to adjust privacy and data-sharing settings to minimize the risk of leaks. Some tools, like Claude, have the option of opting in to their development program, which means chats and coding sessions are used to train its models.
Before introducing any AI tool into your workplace, you should fully understand the privacy implications (as above, complete a privacy impact assessment), and if you don’t understand all the technical details, get expert help.
There are also options for running AI tools on your own servers or within your own cloud platform, but this will require some technical expertise.
We recommend undertaking a full privacy assessment before adopting AI, so you understand what the technology does with entered data, e.g. how is it stored and for how long, is it used to train the model, is it shared with third parties? Also investigate the privacy settings.
You should then create a comprehensive AI policy to govern its use in the organization, and ensure all employees (and the board) know about it and how to use the tool safely. Refresh the policy and training regularly.
Confidentiality is key, so employees should still generally treat AI tools like a public space. This means redacting personal info, using dummy data, and never pasting credentials or private knowledge.
As when introducing any new tool or technology, you should encourage employees to adopt AI by communicating a clear vision of its benefits (and any limitations), as well as establishing clear usage guidelines (via an AI policy), providing training, and addressing any employee concerns.
Staff that are reluctant to use AI or who lack technical skills may need extra training and support. You could also look at appointing staff champions to help people, and remember to celebrate any early wins.
As above.
There are ways to spot the use of AI in people’s work - e.g. in writing style, or a sudden lift in an employee’s level of productivity or skill level - but they require manual checking. There is also software for tracking AI use, but there are costs and technical inputs required.
Being transparent with your team is best, so start by creating a clear AI usage policy that defines which AI tools are approved for use and how they should be used. The policy should also explain that unauthorized use of AI is prohibited and that employees must disclose the AI tools they are using.
Then you can get together with employees to introduce the policy and explain why the company needs employees to follow it (e.g. to protect company and client data, avoid errors or bad outputs, ensure legal compliance).
Only you will know whether AI has the ability to replace real people within your business. If you reach a point where there is a legitimate business case for reducing headcount because of AI technology, you need to follow the proper process for ending employment. That means adhering to all legal requirements regarding employees' notice periods and calculating and paying final pay (including any vacation pay or statutory/public holiday pay).
If employees are consistently producing low-quality AI-generated work, you may need to clarify expectations around AI use and the outputs generated. Discuss the issue with employees, explaining why “AI slop” can create more work for other employees and how that impacts team productivity and cohesion.
You may need to update your AI usage policy with clear guidelines around employees reviewing and editing their work before they submit it and any consequences for consistent breaches. Also, look at your performance metrics so they prioritize accuracy, authenticity, and original thought, rather than output speed or volume.
The Canadian legal system views AI as a tool (not a legal entity) so accountability rests with the person who used the output or the business that enabled it, not the AI provider.
If an AI tool, chatbot, or agent gives bad advice, the organization is typically liable for any resulting harm or financial loss. If an individual uses AI in a professional context (e.g. medicine or law) and relies on its bad advice, they are legally and ethically responsible for that action.
Yes, we suggest all managers get specific training to sense-check AI and spot mistakes before any output is used for work purposes. AI tools can generate errors or false facts, and introduce biases. Managers should also understand what information is and isn’t safe to enter into AI tools.
This is a developing area of law and the ownership of work generated with AI assistance depends on the level of human involvement and the AI platform's terms of service.
Basically, the more human involvement goes into creating the work, the more likely it is that it will be protected by copyright. However, this has yet to be tested in court.
Ownership and use of AI outputs may also be affected by the contractual terms imposed by the provider, e.g. transferring ownership to the provider or user, restrictions on how outputs may be used commercially.
For more information, see the Canadian Intellectual Property Office's who owns AI-generated creations (and why you should care).
Yes, AI screening software can make it much easier and quicker to review resumes and shortlist job applicants. However, their use does carry risks to your company and job candidates, including:
Also be aware that many job applicants use AI tools to help write their applications and can include keywords to trick the screening software.
There are no regulations against candidates using generative AI tools to help with job applications. If you do or don’t accept applications created with AI assistance, make sure you cover it in your AI usage policy and reference it in the job posting or application portal so candidates are aware of the requirements.
Healthcare providers increasingly use AI scribes to listen to consultations and draft daily and clinical notes automatically (there is a national AI Scribe Program for primary care clinicians).
The use of scribe tools does raise ethical and privacy issues and you should understand the implications before introducing them to your organization. Experts recommend getting clients’ consent before using the tools and fully reviewing, editing, and approving every generated note to ensure accuracy and confidentiality. Most scribe tools have been found to make mistakes.
For more information, see: Canada Health Infoway's AI Scribe Program.