The situation
The quarterly business review is nearly over when the client's managing partner, or CFO, or clinic director, asks the question: "Half our staff are using ChatGPT. What should we be doing about it?" Some people have a Microsoft Copilot licence. Others use free accounts on their phones and in a second browser tab. There is no written policy, or there is a one-page memo nobody has read since it was sent.
The client is not asking for a lecture on large language models. They want to know whether they have a problem, what a reasonable organization does about it, and what it will cost. The firewall, endpoint protection and email security you already manage were not built to see what someone types into a prompt box, so "we have you covered" is not an honest answer. If the client needs a primer first, what shadow AI is is a useful starting point.
This guide gives you a structured answer you can deliver in that meeting and then turn into a scoped engagement.
What the rules actually say
For most private-sector clients in Canada, no single law says "do this about generative AI". What exists is a set of frameworks and guidance that describe what reasonable looks like, sitting on top of the privacy and professional duties the client already carries. Tell the client which of these are binding and which are voluntary.
- NIST AI Risk Management Framework. The AI RMF 1.0, released in January 2023, is voluntary and written for organizations that design, develop, deploy or use AI, not only for developers. Its Govern function includes an inventory of AI systems (GOVERN 1.6), AI risk training for personnel and partners (GOVERN 2.2), policies for risks from third-party AI and data (GOVERN 6.1), and ongoing monitoring and periodic review (GOVERN 1.5). NIST's Generative AI Profile (July 2024) lists data privacy, including leakage and unauthorized disclosure, and intellectual property among the risks particular to generative AI.
- ISO/IEC 42001. Published in December 2023, ISO/IEC 42001 sets requirements for establishing and maintaining an AI management system in organizations that develop, provide or use AI. It is voluntary.
- Canadian privacy regulators. The federal, provincial and territorial privacy commissioners issued joint principles on generative AI in December 2023. They are not binding, but they suggest organizations prefer de-identified information in prompts and enter personal information only where authorized.
- Canadian Centre for Cyber Security. Its generative AI awareness guidance recommends that organizations set policies on how AI is used and that staff avoid entering personal or proprietary business information.
The duties that bind are the ones the client already has: privacy law such as PIPEDA or Quebec's Law 25, sector regulation, and professional codes for lawyers, accountants and clinicians. Encourage the client to confirm the specifics with counsel or its regulator.
Why policies and bans fall short
A policy on its own is a document. It tells people what not to do, but it does not act at the moment someone is about to paste a client spreadsheet into a chatbot at six in the evening. According to IBM's 2025 Cost of a Data Breach Report, 63% of organizations had no AI governance policy at all, so writing one is a real step. It is just not the last one.
Blocking AI sites at the firewall has the opposite problem. Staff move to personal accounts, phones and home networks, which removes the little visibility the client had. Category blocking also cannot tell the difference between a harmless request and one that carries a client's financial records.
Neither approach deals with irreversibility. Once content is submitted to a public AI tool, it cannot be recalled. It becomes subject to the provider's terms, which can permit retention, sub-processing and in some cases training. A control that only reports after the fact leaves the client with an incident, not a prevented one.
What a practical control looks like
Present the answer as five steps the client can see and budget for.
- Discovery. Spend two to four weeks finding out which AI tools are actually in use and by which teams. Combine DNS or proxy data, SaaS discovery, a short staff survey and browser-level telemetry. This is the inventory the NIST AI RMF points to.
- Policy. Agree on a short acceptable-use policy: approved tools, the data types that never go into a public tool, and who to call after a mistake. The AI acceptable use policy generator is a reasonable draft to adapt.
- Sanctioned tools. Help the client choose the enterprise AI tools it will pay for, and review their data terms as part of third-party risk. Staff need an approved path, or they will find their own.
- Data-level controls at the browser. Most AI use happens in a browser tab. Put a control there that coaches people at the prompt, and redacts or blocks sensitive data before submission, on sanctioned and unsanctioned tools alike.
- Monthly reporting. Report which tools are in use, what was caught, which teams need coaching, and what to change next. A sample client AI risk report shows what that can contain.
Add an incident path alongside these: when someone reports that sensitive data was submitted, who assesses it and how the client's privacy obligations are handled.
Sanitized Ai is one way to deliver step four and feed step five. It is a browser extension for Chrome, Edge and Firefox that detects sensitive data (client names and identifiers, personal information, health and financial data, source code, deal terms) in AI prompts and file uploads, then redacts or blocks it before submission. The person sees a plain-language explanation of what was flagged and why, so each near-miss becomes a short piece of training. Administrators get a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) that never shows prompt content, which gives you audit-ready records for the monthly review without reading anyone's prompts.
If you want to discuss using Sanitized Ai with your clients, get in touch through the intake form.