Guides
Straight answers to the AI questions your practice is actually facing
Each guide starts from a specific situation, a patent agent drafting claims, an associate who pasted a client file, an MSSP whose clients keep asking about AI, and answers it: what the rules say, where policies fall short, and what a practical control looks like. Sources are verified against the regulator or statute and dated.
Law firms and patent and trademark agencies
An associate pasted a client file into ChatGPT: the next 48 hours
Treat it as a possible confidentiality breach, not a training issue. In the first 48 hours, preserve the facts, find out exactly what was submitted and under which account, assess whether privacy law requires a report (PIPEDA or Quebec's private sector act), decide how the client will be told, and give your professional liability insurer prompt notice. Confirm each step with your law society's practice advisors and your insurer.
Read the answerCan a Quebec lawyer use ChatGPT? The Barreau du Québec, professional secrecy, and generative AI
Yes: the Barreau du Québec encourages supervised use of generative AI, but professional secrecy leaves no room for approximation. Its practical guide states that simply entering information protected by professional secrecy into an open system, such as a public AI tool, is a breach, even without any actual reproduction or disclosure. In practice, that means anonymizing, keeping data to the strict minimum, not using the tool when anonymizing is impossible, and supervising how the whole team uses it.
Read the answerCan patent and trademark agents use ChatGPT under the CPATA Code?
Yes, with care. The CPATA Code of Professional Conduct does not mention or prohibit generative AI, and CPATA's 2025 guidance treats it as a tool agents may adopt if they use it safely and competently. The Code does require agents to hold client information in strict confidence, take reasonable care to protect it, and directly supervise their staff, so confidential client material should not reach AI tools the firm has not vetted.
Read the answerCan you translate patent specifications with AI for national phase or French filings?
Often yes for text that is already public, such as an international application that WIPO has published, provided a qualified person checks the result, because the applicant is responsible for the accuracy of any translation filed with CIPO. The risk sits elsewhere: unpublished applications, claim amendments not yet filed, client instructions, and new matter for divisional or continuation filings are still confidential. Those should not go into AI or translation tools the firm has not vetted.
Read the answerCan you use AI tools to draft freedom-to-operate and patentability opinions?
Yes, but only with tools and settings the firm has approved, and never with the client's unreleased product details, the unfiled invention, or the draft conclusions pasted into a personal AI account. These inputs are confidential, often privileged, and may later be examined in litigation, so the firm needs to control what reaches any AI tool before it is submitted.
Read the answerCanadian firms prosecuting at the USPTO: how do you meet US guidance on AI use?
Canadian agents registered to practise before the USPTO are bound by its rules, and the USPTO's April 2024 guidance explains how those existing rules apply to AI tools. In practice, that means keeping client information confidential under 37 CFR 11.106, personally reviewing anything filed under 37 CFR 11.18, disclosing information material to patentability, and supervising staff. The guidance specifically warns that entering invention details into AI tools can disclose confidential information and raise export control issues, so firms need controls on what reaches those tools.
Read the answerDoes pasting into AI affect patent and trademark agent privilege?
It can, although no Canadian court has yet applied the statutory agent privilege to AI tools. Section 16.1 of the Patent Act and section 51.13 of the Trademarks Act protect agent and client communications that are intended to be confidential and made for advice on protecting an invention or a trademark, and the protection ends if the client expressly or implicitly waives it. Sharing that advice with a third-party AI service gives an opposing party an argument about confidentiality and waiver, so the safer course is to keep privileged material out of tools the firm has not vetted.
Read the answerHow does a law firm with outsourced IT and no security team govern AI?
Give ownership to the managing partner and an operations lead, not to the MSP. Adopt a short policy and one sanctioned AI tool, then ask the MSP to deploy browser-level controls through the browser management it already runs, and review a simple monthly report. The professional duties stay with the firm; the MSP carries out the technical pieces.
Read the answerIs it safe to put an unannounced brand name into an AI tool during trademark clearance?
Not in a personal or unapproved AI account, and not together with launch plans. Until the application is filed, a new mark and the strategy around it are confidential client information, and in Canada entitlement turns on who filed or used first, so a firm should keep that combination out of AI tools it does not control.
Read the answerNew managing partner: a 90-day AI risk checklist
Spend days 1 to 30 finding out how AI is actually used across the firm, days 31 to 60 deciding on a policy, approved tools, and rules for client data, and days 61 to 90 putting controls and training in place and collecting evidence that they work. Anchor each step in the guidance your law society has already published, and in what clients and insurers are starting to ask.
Read the answerOutside counsel guidelines with AI clauses: how to comply
AI clauses in outside counsel guidelines tend to ask for the same things: notice or consent before AI is used on the client's matters, no client confidential information in public AI tools, no training on client data, fair billing for AI-assisted work, and disclosure of which tools the firm uses. Comply by recording each client's terms, mapping every obligation to a control and a piece of evidence, and making sure the rule operates at the prompt, not only in a memo.
Read the answerWe rolled out Harvey, CoCounsel, or Copilot, and staff still use ChatGPT
This is normal, and a sanctioned tool alone will not end it. People keep using the AI they already know because it is fast, familiar, on their phone, and sometimes better at a given task than the approved tool. Close the gap by finding out which tasks drive people elsewhere, setting a clear rule on personal accounts, and adding a control at the prompt that catches client data before it reaches any tool the firm has not approved.
Read the answerWhat does the Law Society of BC's generative AI guidance require?
The Law Society of British Columbia has not created AI-specific rules. Its practice resource, Guidance on Professional Responsibility and Generative AI, applies existing BC Code duties: competence (rule 3.1-2), confidentiality (rule 3.3-1), candour, supervision (rule 6.1-1), fair fees, and the records security obligations in Law Society Rules 10-3 and 10-4. Its core advice on confidentiality is to leave client confidential and identifying information out of generative AI tools, and to consider informed client consent where redaction is not possible.
Read the answerWhat does the Law Society of Ontario say about generative AI?
The Law Society of Ontario has not adopted AI-specific rules. Its April 2024 white paper and companion practice resources explain how existing duties apply to generative AI: technological competence under rule 3.1-2, confidentiality under rule 3.3-1, supervision under rule 6.1-1, candour with clients, fair billing, and not misleading a tribunal. The guidance tells licensees not to put confidential or privileged client information into a generative AI tool unless adequate safeguards are in place.
Read the answerDeal, litigation, and innovation advisers
Can litigators put discovery documents into AI tools under the implied undertaking rule?
Canadian law has not settled this, so treat discovery material as restricted. Documents and answers obtained on discovery may be used only for the proceeding in which they were produced, and in Ontario rule 30.1.01 expressly binds parties and their lawyers. Building a chronology for the same case may be a permitted use, but sending the material to an AI provider whose terms allow retention or training raises a real question about disclosure to a stranger to the litigation, so use a vetted tool and get advice first.
Read the answerCan researchers use AI tools on invention disclosures before a patent is filed?
Not with the unfiled technical details, unless the tool is one the institution has approved for confidential research information. A prompt is not automatically a public disclosure, but it hands the invention to a third party under that party's terms, creates novelty questions nobody can fully answer, and Europe offers no general grace period to fall back on.
Read the answerM&A boutiques: can the deal team put data room documents and diligence summaries into AI?
Only into a tool the firm has vetted, and only if the NDA, the client and the law allow it. Evaluation material is usually shared under an NDA that limits who may receive it and what it may be used for, personal information in the data room is often shared under a privacy law exception tied to the transaction, and a public company deal may involve undisclosed material facts. Pasting that material into a personal AI account can fall outside all three.
Read the answerSR&ED consultants: can you draft client project descriptions with AI?
Yes, if the client's technical data stays out of tools your engagement does not cover. CRA has not published guidance on AI use by claim preparers that we could find, so the limits come from your client contracts and NDAs, privacy law for the personal information in a claim, and any professional code you belong to. Draft with abstracted facts in a vetted tool, and keep source code, experimental results and unreleased product details out of public AI accounts.
Read the answerMSSPs, MSPs, and vCISOs
Adding an AI governance service line to an MSSP
Package it as four parts clients already understand: a fixed-scope AI use assessment, a policy and sanctioned-tool decision, managed data-level controls in the browser, and a monthly report with a regular review. Measure outcomes the client can see, such as AI tools discovered, sensitive-data events caught before submission, and repeat events by department, and map the program to the NIST AI RMF or ISO/IEC 42001 so it speaks the language auditors recognize.
Read the answerClients are asking "what do we do about AI?": an answer for MSSPs
Answer with a program, not a yes or a no. Find out which AI tools staff already use, agree on a short policy, sanction the tools the client will pay for, put data-level controls in the browser where prompts are typed, and report on it every month. Each step maps to frameworks the client may already track, such as the NIST AI RMF and ISO/IEC 42001.
Read the answerHow do you deploy browser AI controls across many client environments?
Force-install the extension through each client's own browser management: the ExtensionSettings or ExtensionInstallForcelist policies for Chrome and Microsoft Edge (by Group Policy, Intune or Chrome Enterprise Core), and the ExtensionSettings policy for Firefox. Keep one template per client in that client's own tenant, roll out in rings, and be clear that the control covers managed browsers, not personal devices.
Read the answerWhat goes in a client AI risk report? A sample outline for MSSPs
A useful monthly client AI risk report covers which AI tools are in use, which of them are sanctioned, flagged events by data type and policy, trends against last month, coaching outcomes, and recommended actions. It is built from event metadata (which tool, what type of data, which policy, when), not from what staff typed, so leadership gets evidence without anyone reading prompt content.
Read the answerClinics and health research
Can a research team put participant data into ChatGPT under an REB-approved protocol?
Only if your REB-approved protocol and the participants' consent allow it. TCPS 2 requires researchers to describe their data safeguards to the REB and to obtain approval before substantive changes, including changes to privacy and confidentiality measures, so running identifiable participant data through an unapproved AI tool may fall outside what was approved. Ask your REB before using the tool, not after.
Read the answerCan Quebec clinics use ChatGPT under the health and social services information act (Bill 3)?
Not with identifiable patient information unless the Act's conditions are met. Since July 1, 2024, the Act treats everything a covered clinic holds as confidential, and handing it to an outside provider generally requires a written agreement with prescribed clauses and, if the data leaves Quebec, a prior privacy impact assessment. A personal ChatGPT account meets neither condition, so clinics should provide approved tools and stop identifiable data at the prompt.
Read the answerOur clinic approved an AI scribe. Can clinicians still paste notes into ChatGPT?
Approval attaches to a tool, not to the patient data. An AI scribe chosen through Ontario's AI Scribe Program comes with vetting, contract terms and a privacy assessment; a personal ChatGPT account comes with none of those, so pasting identifiable patient notes into it can be an unauthorized disclosure under PHIPA. Close the gap by giving clinicians a sanctioned way to draft letters and summaries, and by catching identifiable data before it reaches unapproved tools.
Read the answerFinance, accounting, payroll, and insurance
Can payroll and HR providers put SINs and payroll data into AI tools?
Not into a public AI tool. Service Canada treats employee SINs as confidential and limited to income-related purposes, and privacy law requires safeguards matched to the sensitivity of the data, so pasting a SIN, pay stub or benefits file into a personal AI account is very hard to justify. Payroll and HR teams can still use AI for formulas, policy drafts and reconciliation logic, as long as identifying employee data is removed before anything is submitted.
Read the answerCredit unions, wealth managers, and MGAs: do OSFI B-10 and B-13 apply to employee AI use?
OSFI Guidelines B-10 and B-13 bind federally regulated financial institutions, so most provincially regulated credit unions, wealth managers, and MGAs are not directly subject to them. They still tend to reach you through the federally regulated insurers, banks, and trust companies you work with, and through provincial guidance built on the same expectations. Either way, the practical test is the same: can you show that client and member data does not leave in an employee's AI prompt?
Read the answerFractional CFOs: is it safe to keep several clients' financials in one AI account?
Not without deliberate separation. Features such as memory, chat history, projects and custom GPTs are built to carry context forward, so one client's figures can shape the answers you get for another. If you are a CPA in Ontario, Rule 208 of the CPA Code prohibits using one client's confidential information for the advantage of a third party and requires measures that limit access to it, and CPA Ontario's 2026 AI guidance says confidential data should go only into environments verified as secure.
Read the answerOther regulated organizations
Can contact centre agents use AI to draft replies that contain customer personal information?
Agents can use AI to improve tone and structure, but customer identifiers, account numbers, card data and health or claim details should not go into a public AI tool. The organization remains accountable for customer information it hands to any third party, and a personal AI account comes with no contract that protects it. The practical answer is to keep AI in the workflow while removing personal information before a prompt is submitted.
Read the answerCan federal government suppliers use generative AI with Protected B information?
Not into a public AI tool. Suppliers are bound by the security requirements in their contract and by the Contract Security Program, which only allow protected information to be processed on IT systems the program has approved and only by people with the right screening and a need to know. The Treasury Board guide on generative AI speaks to public servants rather than suppliers, but it points the same way and is a sensible floor for what a department will expect of its contractors.
Read the answerOur cyber insurance renewal is asking about AI controls: how do we answer?
Answer only what you can support with evidence. Renewal applications increasingly ask whether you know which AI tools staff use, whether a written AI policy exists, whether technical controls stop sensitive data from reaching those tools, and whether staff are trained. Gather the inventory, policy, training records, and control records before you fill in the form, and ask your broker how the insurer treats answers you cannot fully support.
Read the answerOur interns and co-op students use their personal AI accounts for work. What should we do?
Assume they will use AI, and plan for it from day one. Privacy law makes the host organization responsible for training the people who handle personal information and for safeguarding it, whether that person is a permanent employee or a four-month co-op student. Give interns a clear rule on what never goes into AI, an approved tool for ordinary tasks, and a safety net that catches sensitive data before it leaves.
Read the answerThe AI section of an enterprise security questionnaire: how should a SaaS vendor answer?
Split the AI section into two questions and answer each with evidence. The first is about AI in your product: which models you use, which providers process customer data, whether that data trains any model, and how AI is governed. The second, which vendors often answer weakly, is about your employees: what stops staff from pasting customer data into AI tools, and how would you know if they did?
Read the answerNot seeing your situation?
Tell us what your team is dealing with. We will point you to the rules that apply and show how Sanitized Ai fits.