The situation
It is three weeks before a client's SR&ED filing deadline. The consultant has a folder from the client's engineering lead: commit messages, a test log from a failed batch process, a slide deck on an unreleased product, and two pages of notes on what did not work. The project description has to explain the technological uncertainty, the work done, and the advancement, within strict word limits. The consultant pastes the notes and the test log into a personal ChatGPT account and asks for a first draft of the three answers.
The draft is a real time saver. It is also a copy of the client's most sensitive technical material, now sitting with a provider that neither the client nor the consultant has a contract with for this purpose.
What the rules actually say
What CRA asks the claim to contain
CRA's Guide to Form T661 sets out the project description questions: line 242 on the scientific or technological uncertainties (up to 350 words), line 244 on the work performed to overcome them (up to 700 words), and line 246 on the advancements achieved or attempted (up to 350 words). Line 244 asks for the hypotheses, experiments or analysis, results and conclusions. Line 260 asks for the names of up to three key individuals, and line 261 for their qualifications and titles. The guide's appendix on supporting evidence explains that dated, contemporaneous documents are the best evidence if a claim is reviewed.
These reflect CRA's eligibility framework: work aimed at a scientific or technological advancement, carried out through a systematic investigation. In practice, a good claim requires exactly the material a client most wants kept private.
CRA sees who prepared the claim
Under CRA's Filing Requirements Policy, Part 9 of Form T661 must identify each claim preparer who accepted consideration to prepare or assist with the claim, with billing information. If that information is missing or wrong, a $1,000 penalty may apply, and the claimant and the preparer are jointly and severally liable for it. Consultants are named participants in the claim, not invisible helpers.
AI-specific guidance
We did not find any CRA guidance on the use of AI tools by SR&ED claim preparers. The general duties apply instead:
- Client contracts and NDAs. Engagement letters and confidentiality agreements typically limit use of client information to the engagement and restrict disclosure to third parties. Check whether an AI provider counts as a permitted subcontractor.
- Privacy law. Names, qualifications and payroll details are personal information. PIPEDA's principle 4.1.3 keeps an organization responsible for information it transfers to a third party for processing and requires comparable protection by contract. See our PIPEDA overview.
- Professional codes. Consultants who are CPAs in Ontario are bound by Rule 208 of the CPA Code, which requires appropriate measures to protect client information and the written agreement of anyone given access to keep it confidential.
Why policies and bans fall short
SR&ED work is seasonal and deadline-driven, and the narrative is exactly the kind of writing generative AI does well. A consultant with a dozen clients due in the same month will reach for the fastest tool. A ban moves that work to personal accounts on personal devices. IBM's 2025 Cost of a Data Breach Report found that only 17% of organizations have technical controls that block or redact sensitive data at the point of entry.
The stakes are also higher than they look. A client's uncertainties and failed experiments can point directly at its trade secrets and future patent filings, as our post on why your valuation is your IP explains. Once submitted, that material cannot be recalled.
What a practical control looks like
- Put AI in the engagement letter. Say whether AI tools are used, which ones, under what data terms, and which categories of client data never go into them.
- Choose a sanctioned tool. Use a business account with contractual commitments on training, retention and confidentiality, and confirm it fits each client's NDA.
- Draft from abstractions. Describe the uncertainty and the approach in generic terms, then add product names, parameters and results back into the final document yourself. Source code and raw test data stay out.
- Keep clients separate. Do not let one client's material sit in chat history or shared projects alongside another's. Our guide on multiple clients in one AI account covers the same risk for finance advisors.
- Review every draft against the evidence. The claimant certifies the claim, and AI drafts can overstate or misdescribe work.
- Set an incident path for client data that reaches an unapproved tool, including when to tell the client.
Sanitized Ai is a browser extension that supports steps 3, 4 and 6 at the moment it matters. When someone is about to submit source code, invention details, client names and identifiers, financial data or personal information to an AI assistant, it redacts or blocks that content before submission and explains in plain language what was flagged and why. That coaching at the prompt helps staff learn to draft from abstractions, and it keeps a client's unreleased work from becoming subject to a provider's terms.
Administrators see a dashboard of flagged-event metadata (which tool, what type of data, which policy, when), never prompt content. That gives the firm an audit-ready record to show clients how their data is protected, without anyone reading staff prompts. See how it fits engineering and R&D teams.