By David Chernitzky, Co-Founder and CEO, Armour Cybersecurity | Serving organizations across Canada, the US, and beyond | Last updated August 17, 2026
Quick answer: AI compliance risk in regulated industries is compounded. Financial services, healthcare, legal, and energy organizations handle exactly the personal data, confidential client information, and regulated content that employees submit to AI tools to accelerate their work. When that content reaches a public AI platform through a personal account without a data processing agreement, without a disclosed purpose, and without a legal basis for processing, it creates privacy law violations, confidentiality breaches, and in some sectors specific regulatory enforcement exposure. Regulators in Canada, the EU, and the US are no longer issuing warnings; they are conducting investigations and imposing penalties.
Key Takeaways
- Privacy law violations from AI usage do not require a data breach. Submitting personal information to a public AI platform without a data processing agreement and without the consent or legal basis required by applicable privacy law is itself a violation, regardless of whether the data was later exposed, stolen, or misused. This is the core generative AI privacy risk regulated organizations carry.
- Quebec Law 25 imposes some of the strictest AI-specific privacy obligations in North America, including a requirement to disclose when a decision is based exclusively on automated processing of personal information and to give individuals a means to have a human review that decision.
- OSFI’s guidelines apply directly to AI. B-13 (Technology and Cyber Risk Management) requires board and senior management accountability and a documented technology risk framework; B-10 (Third-Party Risk Management) requires due diligence on third-party AI providers. Personal accounts on public AI platforms satisfy neither.
- Solicitor-client privilege may be waived when lawyers or in-house counsel submit privileged communications to public AI platforms. Law societies in multiple Canadian provinces have issued guidance warning lawyers about the privilege and confidentiality implications of using public AI tools for client work.
- Healthcare organizations subject to HIPAA that permit employees to submit protected health information to public AI platforms without a Business Associate Agreement are in violation of HIPAA regardless of whether the submission was intentional. PHI is PHI wherever it is processed.
What Makes AI Compliance Risk Different in Regulated Industries
Every organization that adopts AI without governance faces the same foundational risks: data leaving the organization through unsanctioned channels, compliance obligations not mapped to AI usage, and no visibility into what employees are doing with AI tools. Regulated industries face all of these plus a layer of sector-specific obligations that amplify the consequences. The personal information, confidential communications, and regulated data that are the daily inputs of financial services, healthcare, legal, and energy operations are exactly the content that creates the highest value for AI-assisted work, which means regulated-industry employees face the strongest productivity incentive to use AI and handle the most sensitive categories of data when they do.
The regulatory frameworks that govern these sectors were written before generative AI existed, which means the obligations they impose apply to AI usage without the regulations needing to be updated. A financial advisor who submits client financial information to a public AI platform has provided that information to a third party without an appropriate data sharing agreement, which violates existing financial services data handling rules whether the third party is a human consultant or an AI system. The fact that the submission was made to an AI tool rather than a person does not change the compliance analysis; it simply makes the disclosure harder to detect. Managing that exposure is an extension of the organization’s privacy risk management and governance, risk and compliance programs, not a separate track.
Canadian Privacy Law and AI: PIPEDA and Quebec Law 25
PIPEDA, Canada’s federal private sector privacy law, requires organizations to obtain consent for the collection, use, and disclosure of personal information, to use personal information only for the purposes for which it was collected, and to protect personal information using safeguards appropriate to its sensitivity. When an employee submits personal information about a customer or another individual to a public AI platform, the organization has disclosed that personal information to a third party. That disclosure requires a legal basis. For most personal information in a business context, the legal basis is consent, which means the individual whose information is being submitted must have consented to it being provided to an AI platform for the purpose of the submission.
Most customer consent collected by Canadian businesses does not include consent to the use of personal information for AI processing on external platforms. The privacy notice a customer accepts when creating an account or entering a business relationship describes how the organization will use their information for the organization’s own purposes; it does not contemplate submission to a third-party AI platform as a processing activity. Organizations that have not updated their privacy notices and consent mechanisms to address AI processing, and that have not put data processing agreements in place with the AI platforms their employees use, are likely in violation of PIPEDA for any personal data submitted to those platforms.
Quebec Law 25 goes further. In addition to consent and data handling requirements that parallel PIPEDA, Law 25 requires that any decision based exclusively on automated processing of personal information must be disclosed to the individual affected, that the individual must be given the means to have a human review the decision, and that the organization must provide information about the personal information used and the factors that led to the decision. For financial services, insurance, and other organizations that use AI in any customer-facing decision process, these requirements create documentation and process obligations that require active program design rather than a generic privacy notice update.
Financial Services: OSFI B-13, B-10, and AI Risk
For federally regulated financial institutions, two OSFI guidelines govern AI risk together. B-13, Technology and Cyber Risk Management, sets the expectation that the board and senior management are accountable for technology and cyber risks, including risks arising from AI and machine learning systems, and that the institution maintains a documented technology risk management framework covering the identification, assessment, and mitigation of those risks. B-10, Third-Party Risk Management, which came into effect in May 2024, governs the vendor side: due diligence on third-party AI providers, including assessment of data handling, model governance, and the concentration risk created by reliance on a small number of AI platform providers, with contractual protections in third-party arrangements. Standing up that documented governance is the kind of work a virtual CISO is often brought in to lead, and it feeds the board cyber governance accountability B-13 expects.
Read together, these guidelines mean that AI tools used in any capacity that touches regulated activities or customer data are subject to vendor assessment, contractual protections, and documented governance. Personal accounts on public AI platforms, which are consumer products rather than enterprise services and which have not been through any vendor assessment process, do not satisfy these expectations. Financial institutions that permit employee use of public AI tools for work involving customer data or regulated activities without enterprise-grade controls are out of compliance regardless of whether they have an explicit policy permitting the usage.
Healthcare: HIPAA and Protected Health Information
HIPAA requires that covered entities (healthcare providers, health plans, healthcare clearinghouses) and their business associates protect the privacy and security of protected health information. A Business Associate Agreement is required whenever PHI is disclosed to a third party that will create, receive, maintain, or transmit PHI on behalf of a covered entity. Public AI platforms accessed through personal accounts are not covered by Business Associate Agreements. A healthcare employee who submits patient records, clinical notes, diagnostic information, or any other protected health information to a public AI platform is creating an unauthorized disclosure of PHI.
This violation occurs at the moment of submission, not at the moment of any subsequent breach or misuse. The organization’s HIPAA compliance program does not protect against this exposure unless it includes controls that prevent or detect PHI submission to non-BAA-covered AI platforms, the kind of monitoring many organizations run through a managed SOC. Healthcare organizations that have deployed productivity assistants across the clinical and administrative workforce without reviewing whether those assistants process PHI, and without ensuring appropriate BAAs are in place with the AI platform providers, are carrying unquantified HIPAA exposure. OCR enforcement actions have resulted in multi-million-dollar settlements for HIPAA violations involving smaller-scale unauthorized disclosures.
Legal Privilege and Professional Responsibility
Solicitor-client privilege is one of the most important protections in the legal system: it prevents compelled disclosure of confidential communications between a lawyer and client for the purpose of obtaining legal advice. Privilege can be waived by voluntary disclosure of the privileged communication to a third party without the client’s consent. When a lawyer submits privileged client communications to a public AI platform, the submission may constitute a voluntary disclosure to a third party, potentially waiving privilege for those communications.
Law societies in British Columbia, Ontario, and other Canadian provinces have issued AI guidance that specifically addresses privilege and confidentiality concerns. The Federation of Law Societies has published guidance encouraging lawyers to understand the data handling practices of AI tools before using them for client work, to ensure clients are informed of AI usage where appropriate, and to consider the implications of AI tool usage for professional confidentiality obligations. Firms that have not issued guidance to lawyers about AI usage, that have not reviewed the data handling terms of AI tools in use, and that have not implemented governance controls over client data submitted to AI platforms are carrying professional responsibility and privilege risk that could affect client relationships and regulatory standing.
Armour Cybersecurity’s Secure AI Adoption Program addresses regulated-industry compliance obligations as a core component of the governance design, ensuring that the acceptable use standard, data handling policies, and tool assessment process reflect the specific regulatory framework applicable to the organization.

Frequently Asked Questions
Does using an enterprise AI subscription fix the compliance problem?
An enterprise subscription with a data processing agreement addresses the most significant compliance gap: it provides a legal basis for data processing, establishes confidentiality obligations, defines data retention and deletion terms, and removes the data from consumer-facing model training pipelines. But an enterprise subscription alone does not establish the governance framework that regulators expect. OSFI expectations require documented governance of AI systems, not just a commercial agreement with an AI vendor. Quebec Law 25 requires process controls around automated decision-making, not just data handling terms. An enterprise subscription is a necessary component of compliance but not a sufficient one without the governance layer that defines what the tool is used for, by whom, for what purposes, and under what oversight.
What should a healthcare organization do right now about AI and HIPAA?
The immediate priority is an inventory of what AI tools clinical and administrative staff are using and whether any of those tools receive protected health information as input. This inventory should cover productivity assistants deployed by IT, coding assistants used by the technology team, and any individual-level tool usage discovered through network monitoring or staff interviews. For each tool that receives or could receive PHI, the organization needs to determine whether a Business Associate Agreement is in place with the AI platform provider, and if not, whether to obtain one, restrict the tool from PHI processing, or terminate its use. The governance framework that prevents future PHI-related AI incidents includes an AI acceptable use standard that clearly identifies PHI as a restricted data category for AI tool submission, training for staff on the applicable rules, and technical controls that detect PHI submission to non-BAA-covered platforms.
How does Quebec Law 25 apply to AI-based decision-making?
Quebec Law 25 requires that any enterprise using personal information to render a decision based exclusively on automated processing must inform the person that such a decision has been rendered, provide that person with the means to submit observations to a human, and upon request inform the person of the personal information used to render the decision and the factors that led to it. This applies when AI is used to make decisions affecting individuals, such as credit decisions, insurance underwriting, employment screening, or any other decision made by an AI system without meaningful human review of each individual case. Organizations that have deployed AI in any customer-facing or employee-facing decision process must design that process to satisfy these disclosure and human review requirements.
Are there specific AI governance frameworks we should align to?
Several frameworks provide useful structure for building an organizational AI governance program. The NIST AI Risk Management Framework (AI RMF) is a comprehensive, voluntary framework organized around four functions: Govern, Map, Measure, and Manage, and it is increasingly referenced by regulators and auditors as a benchmark for AI governance maturity. ISO 42001, the international standard for AI management systems, provides a certifiable framework analogous to ISO 27001 for cybersecurity. On the Canadian regulatory side, the proposed Artificial Intelligence and Data Act died on the order paper when Parliament was prorogued in January 2025 and has not been reintroduced; the federal government has signaled it will regulate AI through privacy legislation and policy rather than a single AI act, so the practical path today is to align to NIST AI RMF and ISO 42001 while tracking sector-specific guidance and the current federal direction.
Can an employee be held personally liable for submitting client data to an AI tool?
Personal liability for employees who submit confidential or regulated data to AI platforms is possible in specific circumstances. Lawyers who violate solicitor-client privilege through unauthorized disclosure may face professional discipline from their law society. Healthcare professionals who violate HIPAA through unauthorized PHI disclosure may face civil monetary penalties in their personal capacity in some enforcement contexts. Employees who violate the organization’s written acceptable use policy and cause material harm may face employment consequences including termination. The more significant liability exposure, however, rests with the organization itself for failing to implement governance controls that prevent these disclosures. Organizations that have a clear acceptable use standard, have communicated it to employees, and have implemented technical controls that enforce it have a significantly stronger position when an employee circumvents those controls than organizations that had no governance in place at all.

The Bottom Line
AI compliance risk in regulated industries is not a future problem; it is a present exposure that begins the moment an employee pastes regulated data into a public AI tool. The frameworks already on the books, PIPEDA, Quebec Law 25, OSFI B-13 and B-10, HIPAA, and professional privilege rules, apply to AI whether or not the organization has mapped them to it. A governed AI adoption program built around the specific regulatory framework the organization operates under is what turns that exposure into a defensible, documented position. Start with a use case discovery, classify regulated data as restricted for AI submission, put enterprise controls and vendor assessments in place, and document the governance regulators and auditors will ask to see.
About the author
David Chernitzky is Co-Founder and CEO of Armour Cybersecurity, a Toronto-based cybersecurity firm founded by military intelligence veterans and advised by senior leaders from PwC, KPMG, Deloitte, EY, and Mandiant. Armour serves more than 260 organizations across 52-plus industries, including finance, healthcare, technology, energy, legal, and government, with a 97 percent client retention rate.



