Small and mid-sized organizations hosting interns, co-op students and summer students

Our interns and co-op students use their personal AI accounts for work. What should we do?

Sources verified Sanitized Ai Team

The short answer

Assume they will use AI, and plan for it from day one. Privacy law makes the host organization responsible for training the people who handle personal information and for safeguarding it, whether that person is a permanent employee or a four-month co-op student. Give interns a clear rule on what never goes into AI, an approved tool for ordinary tasks, and a safety net that catches sensitive data before it leaves.

The situation

A 40-person engineering consultancy takes on three co-op students for the summer term. In the second week, one is asked to clean up a client's asset inventory spreadsheet. He uploads it to the AI assistant he has used all through university, on his personal account, and asks it to fix the formatting and flag duplicates. The spreadsheet includes the client's facility addresses, contact names, phone numbers and a column of notes about site access.

Another student, working on a proposal, pastes a competitor analysis and the firm's draft pricing into a different AI tool to tighten the wording. Neither student thinks of this as disclosure. To them, AI is the same as a spell checker, and nobody told them otherwise.

This is not a problem with the students. They arrive with habits formed in an environment where uploading a document to AI was normal and encouraged. The organization's job is to meet those habits with clear expectations and a practical safety net.

What the rules actually say

No Canadian law or regulator sets rules specifically for interns and AI. The obligations are the general ones every organization already carries for anyone who handles personal information on its behalf.

Under the federal private-sector privacy law, PIPEDA Schedule 1, principle 4.1 makes an organization accountable for personal information under its control. Clause 4.1.4 expects organizations to put policies and practices in place, including training staff and communicating the organization's policies to them. Principle 4.7 requires safeguards appropriate to the sensitivity of the information, and clause 4.7.4 asks organizations to make their employees aware of the importance of keeping personal information confidential. None of this depends on how long someone has been on the team.

In Quebec, the private-sector act as amended by Law 25 applies. The Commission d'accès à l'information describes the security measures businesses must take as reasonable and proportionate to the sensitivity of the information, and includes staff awareness and training among them. It also treats unauthorized communication of personal information as a confidentiality incident. Law 25 penalties can reach C$25 million or 4% of worldwide turnover, although most small organizations will be more concerned with client trust and incident handling than with maximum fines.

The federal, provincial and territorial privacy commissioners' generative AI principles are guidance, not binding rules, but they recommend limiting personal information in prompts and not entering sensitive or confidential information without authorization.

Confidential business information such as client pricing, designs and proposals is protected mainly by contract: client agreements, non-disclosure agreements and your own confidentiality terms with staff and students. Review those with counsel. Which privacy law applies depends on your province and sector, so confirm the details with your advisors.

Why policies and bans fall short

Most small organizations hand interns a policy binder or a link on the first morning, alongside many other onboarding tasks. An AI clause buried in it is unlikely to change a habit built over four years of school.

Personal accounts make the gap worse. Gartner's 2026 research found that 88% of employees with enterprise AI access also use personal AI tools for work, and interns, who often have no enterprise access at all, have even fewer alternatives to their own accounts. Anything submitted through a personal account is subject to that provider's consumer terms, which can permit retention, sub-processing and in some cases training. The organization has no contract with the provider, no admin controls, and no way to recall what was sent.

Banning AI outright tends to backfire with students in particular. They will still use it for research and writing, just on a phone or a home laptop. Supervisors then lose the chance to guide how it is used. The better approach is described in our guide on rolling out a sanctioned AI tool when staff still use ChatGPT.

What a practical control looks like

  1. Put AI in the onboarding agreement. Update your confidentiality agreement so it names AI tools and states that confidential and personal information may not go into any AI tool the organization has not approved.
  2. Give a one-page rule, not a binder. List what never goes into AI (client names and contact details, personal information, financial data, pricing, designs and source code) and what is fine. Our post on why AI acceptable use policies often fail explains why broad policies rarely reach people at the keyboard.
  3. Provide an approved tool. A business AI account for ordinary drafting and research removes the main reason interns reach for their own.
  4. Make supervisors responsible for AI coaching. Supervisors should review how interns use AI in the first weeks, the same way they review early work product.
  5. Teach the report-it-early habit. Tell interns that if they think they sent something they should not have, they should say so immediately, without fear of being blamed for asking.
  6. Close out at the end of the term. Remind departing students that confidentiality continues, and ask them to delete work files from personal devices and AI histories.

Sanitized Ai is a browser extension that gives interns the guidance they need at the moment they need it. When someone pastes or uploads content containing client names and identifiers, personal information, financial data, source code or other sensitive details into a major AI assistant, it redacts or blocks that content before submission and explains in plain language what was flagged and why. For a student in their first placement, that short explanation is often the most effective training they receive.

Supervisors and administrators see a dashboard of flagged-event metadata (which tool, what type of data, which policy, when), never prompt content. That shows where coaching is needed without reading anyone's prompts, and gives audit-ready records that can support a client question or a safeguards review. Engineering and technical firms can see how it fits their workflows on our engineering page.

Frequently asked questions

Should interns sign a confidentiality agreement that mentions AI?

Yes, it is worth updating your confidentiality or onboarding agreement to name AI tools explicitly. Say that confidential and personal information must not be entered into any AI tool that the organization has not approved, and explain what counts as confidential in your business. Have counsel review the wording, especially for unpaid placements or students placed through a school program.

Can we simply ban interns from using AI?

You can, but it rarely works. Many students have used AI tools throughout their studies, and a ban tends to move that use to personal phones and laptops where you cannot see it. A clear data rule plus an approved tool is easier to follow and easier to supervise.

Who is responsible if an intern discloses client data through a personal AI account?

Under Canadian privacy law the organization is accountable for personal information under its control, including what its staff do with it. The intern's inexperience does not shift that responsibility. Treat it as an incident, assess the risk of harm, and follow your breach process with advice from counsel.

Does this matter if our interns only do marketing or admin work?

Yes. Marketing and admin tasks often involve customer lists, email threads, contracts and pricing, which can contain personal information and confidential business details. The data rule should cover every role, not only technical or client-facing ones.

Close the gap between the rule and the prompt box.

Sanitized Ai is a browser extension that coaches staff at the moment they type, redacts or blocks sensitive data before it reaches an AI tool, and gives administrators audit-ready records of flagged events without showing prompt content.

Talk to us

Primary sources

This guide summarizes the cited sources as of the verification date. It is practical guidance, not legal advice. Confirm your obligations with your regulator or counsel.

For your industry

Standards that apply

Related guides

Further reading