A project manager in Montreal pastes a supplier contract into ChatGPT to summarize the payment terms. The contract names two individuals, their titles, and their direct email addresses. The prompt takes three seconds to write. In those three seconds, personal information about identifiable people has left the organization's control and become subject to a public AI provider's terms of use — retained, possibly processed by sub-processors elsewhere, possibly used to improve the provider's models. Nobody logged it. Nobody consented. And under Quebec Law 25, that quiet moment is where liability begins.
Most discussion of Law 25 focuses on the visible things: privacy policies, consent banners, breach notifications, the mandatory privacy officer. Generative AI creates a quieter exposure that sits underneath all of that — the routine, unremarkable act of an employee moving personal information into a tool the organization never evaluated, for a task nobody reviewed. It doesn't look like a data transfer. It looks like getting work done faster.
Why a prompt counts as a disclosure
Law 25 governs how organizations collect, use, and communicate personal information about Quebecers. It is built on data minimization and control of disclosure — the principle that personal information should only flow where it needs to, with a basis for each transfer. A generative AI prompt breaks that principle in an ordinary way. The person writing it is not thinking about a communication of personal information to a third party. They are thinking about a task: summarize this, translate that, clean up these notes.
But the content of a prompt is data, and if it contains a name attached to a phone number, a client file, an employee's medical accommodation request, or a customer's financial details, then submitting it to an external tool is a communication of personal information to that tool's operator. Law 25 tightened the rules around communicating personal information outside Quebec and to third parties. It expects an organization to know where the information goes and to have assessed the transfer. A prompt written into a personal ChatGPT account satisfies none of that — and the organization usually has no idea it happened.
The scale is the problem. Cyberhaven found in 2025 that roughly 40% of AI interactions involve sensitive data, and that the sensitive share of corporate data going to AI has risen to around 35%, up from about 11% two years earlier. LayerX reports that 77% of AI users paste data into prompts, 82% of that from unmanaged personal accounts. This is not a rare edge case. It is a steady stream of undocumented disclosures happening across every department.
The part Law 25 makes hard to walk back
The irreversibility is what separates this from other privacy risks. A misconfigured folder can be locked down. An email sent to the wrong recipient can sometimes be recalled or contained. But once personal information is submitted to a public AI tool, there is nothing left to retrieve. It may be retained, processed by parties you cannot name, or used to train the provider's models. The disclosure is complete the moment the prompt is sent.
That matters for two Law 25 obligations in particular. The first is breach handling: when a confidentiality incident presents a risk of serious injury, you have reporting and record-keeping duties. An organization that cannot see its AI usage cannot know whether an incident occurred, let alone assess the risk or document it. The second is the penalty regime. Law 25 carries administrative monetary penalties and fines reaching up to C$25 million or 4% of worldwide turnover. Those numbers are directional, not a prediction about any single prompt — but they set the scale of what sits behind a gap most organizations are not even measuring.
Consider a healthtech company running trials in Quebec. A coordinator, under deadline, pastes a batch of participant notes into an AI tool to reformat them into a report. The notes carry names, dates of birth, and health details. That is a communication of sensitive personal information, made without assessment, to a tool the organization never approved. If it surfaces later, the question will not be whether the coordinator meant well. It will be what controls the organization had in place to prevent it — and whether it can show them.
Governance that survives contact with a deadline
The instinct is to ban public AI tools. It does not work. Gartner reports that 88% of employees with enterprise AI access also use personal AI tools for work, and that 69% of organizations suspect or have evidence of prohibited public GenAI use. When a tool is banned, the work does not stop — it moves to a personal account on a personal device, where the organization has even less visibility. A ban converts a manageable problem into an invisible one.
What aligns with Law 25 is not prohibition but control at the point of disclosure. That means three things working together. Visibility, so the organization actually knows where personal information is flowing into AI. Data-level controls, so a name, a SIN, or a health detail is caught and redacted before the prompt reaches the tool rather than after. And in-the-moment education, so the person writing the prompt learns what was flagged and why — turning a near-miss into a moment of training instead of a silent incident. IBM's 2025 breach data underscores how rare this is: only 17% of organizations have technical controls to redact or block sensitive data at the point of entry.
This is the principle Sanitized AI is built on — that the control has to act before submission, because after submission there is nothing left to control. Catching personal information in the prompt and redacting it before it leaves keeps the disclosure from happening in the first place, and produces a record of the policy event without ever logging what the person typed.
The question worth asking this quarter is simple: if a Quebec resident's personal information were pasted into a public AI tool today, would your organization know, and could you show what stopped it? If the answer is no, that is the gap to close. Request a demo to see how catching prompt data before it leaves fits into a Law 25 posture.