September 2026 Employer Alert: Skynet Is Here – Better Establish an AI Policy

The use of AI in the workplace is increasing quickly, often without any formal consideration of how and when employees can use it. Employees are using AI to draft emails, prepare reports, figure out problems, and review resumes.

There are real benefits to using AI. But there are also significant risks when employees use AI tools without understanding what happens to the information they enter, how reliable the output is, or whether the AI tool is appropriate for the task. An employee can inadvertently disclose confidential information, rely on an answer that is simply wrong, spark a discrimination claim, or trigger various legislative obligations.

Simply prohibiting AI is unlikely to be practical or effective. You’ll end up like an early 2000s employer demanding communication by phone or fax, not email. Employers should instead have a clear AI policy that identifies which tools and uses are permitted, what information cannot be entered, and when meaningful human review is required.

When drafting your AI policy, there are five main areas of concern to consider:

  1. Confidential Information – Entering information into an AI tool may amount to providing it to an outside service provider, where it may be retained, accessed, or used to improve the system. Your AI policy should identify approved tools and prohibit employees from entering confidential business, customer, or employee information without authorization.
  2. Human Accountability – AI can produce an answer that is polished, detailed, and completely wrong. It may invent facts or sources, overlook important information, or draft an email that feels very unhuman. Your AI policy should confirm that employees remain responsible for their work and require them to understand, review, and verify all AI-assisted content before using or sharing it. You may also want the policy to identify higher-risk work for which AI cannot be used without approval.
  3. Privacy Laws – Privacy legislation restricts how and when employers can take and use personal information. This includes sharing a customer’s information, payroll records, performance reviews, accommodation requests, and information collected through employee monitoring.

    When a company shares these sorts of records with an AI tool, this may amount to a new use or disclosure of personal information. The applicable rules vary by jurisdiction and industry. In Alberta and British Columbia, provincial private-sector privacy legislation applies to personal information, including employee information. In Ontario, the federal Personal Information Protection and Electronic Documents Act (“PIPEDA”) generally applies to personal information collected, used, or disclosed in commercial activities. However, for provincially regulated Ontario employers, it does not generally govern employee information. No matter what jurisdiction an employer falls under, the best course of action is to consider whether the planned AI use has a legitimate and identified purpose, whether the information provided is reasonably necessary, what notice or consent is required, and whether adequate contractual and security safeguards are in place.

    There is also a further issue created when monitoring employees through AI. Employees may be actively monitored through AI tools that track keystrokes, screen activity, communications, location, or productivity, or passively monitored through AI features embedded in ordinary workplace software that analyze usage patterns, generate performance data, or flag unusual activity in the background. In addition, employers may use AI to analyze existing workplace records, such as hours worked, attendance, productivity, communications, or performance data, to identify patterns or assess employees. This monitoring triggers its own privacy legislative obligations. For example, in Ontario, employers with 25 or more employees must have a written electronic monitoring policy explaining how and in what circumstances employees are monitored and how the information may be used.

    Given the above, your AI policy should restrict the personal information employees may enter, establish approval requirements for AI tools that process personal information, and explain how AI use may be monitored.
  4. Anti-Discrimination Laws – Human rights legislation across Canada prohibits discrimination in hiring and throughout the employment relationship. This includes both direct discrimination and adverse-effect discrimination, where an apparently neutral standard disproportionately disadvantages people based on disability, age, race, sex, family status, or another protected ground.

    AI can repeat or amplify bias when used to screen applicants, assess interviews, evaluate performance, recommend discipline, or identify employees for termination. A screening tool may, for example, treat a gap in employment as a negative factor, disadvantaging applicants who were absent from the workforce because of disability, pregnancy, or family responsibilities. An employer cannot avoid responsibility by simply blaming AI. Instead, your AI policy should confirm that AI cannot be the sole decision-maker in employment matters, that criteria or rules given to AI should be given careful consideration, and that AI may not be appropriate in certain circumstances.
  5. AI-Specific Legislative Requirements – The legal requirements governing AI are developing and differ across Canada. For example, since January 1, 2026, Ontario employers with 25 or more employees must disclose in a publicly advertised job posting if AI is used to screen, assess, or select applicants. Your AI policy should ensure that the current AI-specific obligations are being met.

These issues are not limited to employers that have deliberately purchased or implemented an AI system. They can arise from an employee using a free online tool, an AI feature added to existing software, or a payroll provider using AI on the employer’s behalf. Given this, now is the time for employers to take stock of the AI tools being used by their employees and service providers, adopt a policy that identifies approved tools and permitted uses, protects confidential and personal information, requires employees to review and verify their work, and preserves meaningful human responsibility.

For assistance with preparing your AI policy or reviewing how AI is being used in your workplace, please contact our firm.