Security Insights
Deep dives into Shadow AI, PII protection, and the future of secure LLM adoption.
What a Partner Owes When an Articling Student Pastes a Client File Into AI
An articling student pastes a client file into ChatGPT to speed up a memo. The partner signs the work and carries the risk. Here is what supervisory duty actually requires when juniors use AI.
What the Duty of Technological Competence Now Requires When Your Firm Uses ChatGPT
Law societies expect lawyers to understand the technology they use. When an articling student pastes a client's file into ChatGPT, that duty is no longer abstract — it's a disclosure you can't recall.
Why Banning ChatGPT Doesn't Work, and What Actually Reduces Shadow AI Risk
Blocking ChatGPT at the firewall feels decisive, but it just pushes AI use onto personal phones and accounts you can't see. Here's why bans backfire and what reduces Shadow AI risk instead.
Keeping PHI Out of LLM Prompts Under PHIPA and Bill C-27
Clinicians and researchers paste patient details into AI tools to save time, but PHI submitted to a public model can't be recalled. Here's how to keep it from leaving in the first place.
Keeping Client Tax Returns Out of ChatGPT During Busy Season
During busy season, an overloaded associate pastes a client's return into ChatGPT to summarize it faster. The client's SIN and income just left your firm's control, and it can't be recalled.
Your Valuation Is Your IP, and It Can Leave One Paste at a Time
For deep-tech and biotech companies, the balance sheet is the technology. When an engineer pastes source code or a draft claim into a public AI tool, the value backing your next round can quietly walk out the door.
How One Careless AI Prompt Can Waive Privilege
A single prompt pasted into a public AI tool can strip privilege or break confidentiality on a client's matter. Early court rulings show the disclosure is voluntary — and irreversible. Here's how firms are closing the gap.
How to Get Visibility Into Shadow AI Without Banning Every Tool
You can't govern what you can't see, and most organizations have no visibility into nearly 90% of their AI usage. Here's how to get that visibility without driving employees to personal accounts.
Your DLP Can't See the Prompt Box
Your DLP stack watches files, email, and downloads. The most revealing data in your company now leaves through a text box those controls were never built to read.
Sanitized AI is Officially Live on Chrome and Edge
Sanitized AI is now available on the Chrome Web Store and Microsoft Edge Add-ons store. Get real-time visibility into what your employees are sharing with AI platforms.
Canada Just Told OpenAI Its Training Data Practices Broke Privacy Law. Here's What That Means for Every Organization Using AI.
Canada's privacy regulators found OpenAI's original ChatGPT training practices violated privacy laws. Learn why this finding matters for your organization and how to address the hidden risks of employee AI usage.
Why Your AI Acceptable Use Policy Probably Isn't Working
Most organizations rolled out an AI acceptable use policy sometime in the last 18 months. Most of them aren't working, and the reason isn't what people think.
The Opt-Out Illusion: Why Turning Off AI Training Doesn't Make Your Data Safe
Turning off AI training doesn't mean your data is safe. Understand why 'don't train on our data' is a narrow promise, and why you need upstream controls to prevent data leaks.
US Cyber Defense Chief Falls Victim to Shadow AI
Even top cyber officials are not immune. Learn how a simple mistake led to a government data spill and how to protect your organization.
Shadow AI in 2026: The Insider Threat Draining Your Enterprise Data
75% of employees now use unauthorized AI tools, and 57% admit to inputting sensitive data. Discover the real cost of Shadow AI and how to prevent PII leakage before it breaches your organization.
The Hidden Dangers of Shadow AI: How PII Leaks Through LLMs
Employees are using AI tools without approval. Here is how that leads to massive PII leakage and what you can do about it.