Your employees are already using AI, with or without your approval
ChatGPT, Microsoft Copilot, Gemini: your employees use them to write faster, summarize a long document, or debug a problem. It's efficient, and it's human. The problem isn't that they're using AI. The problem is what they're pasting into it.
This is called shadow AI: the use of unapproved artificial intelligence tools, often through personal accounts, outside any company oversight. Recent studies estimate that the majority of employees feed company data into these tools, and that most do so through a personal account with no protection whatsoever. In many cases, neither management nor the IT manager is even aware.
The real risk: your data is leaving the company
When an employee adds a client contract, a patient file, a financial statement, or a price list into a public AI tool, that information leaves your environment. It is transmitted to an external provider, often hosted abroad, and may be retained or used to train models.
In other words, data you carefully protect within your systems can end up exposed in seconds, through good intentions and a simple copy-paste.
Why this is also a Bill 25 issue
For a Quebec SMB, this isn't just a security question, it's a compliance question. If an employee sends personal information about clients or patients to an external AI tool, your company is potentially disclosing that information to a third party, sometimes outside Quebec, without consent and without a privacy impact assessment.
Bill 25 requires you to know where the personal information you hold is going and to control it. Shadow AI creates exactly the gap the law asks you to close. For the basics, see our complete guide to Bill 25 compliance.
What you can do, concretely
Banning AI is neither realistic nor desirable. The goal is to govern it.
A clear usage policy
Tell your employees what is allowed, what isn't, and above all, what types of information should never be entered into a public tool.
Approved tools
Provide an enterprise AI solution (for example, a business version of Copilot) that keeps your data within your environment, rather than letting everyone improvise with a free account.
Training
Most leaks come from well-intentioned employees who don't realize the risk. A short training session changes a great deal.
Monitoring
Data loss prevention tools can detect and block the sending of sensitive information to unauthorized services.
In summary
AI is a tremendous productivity gain, but without governance, it becomes an exit door for your most sensitive data. The good news: a few simple measures are enough to benefit from AI without exposing your company.
At AIKI Secure, we help Quebec SMBs implement secure, compliant AI use as part of our managed IT services: policy, approved tools, training, and monitoring. To assess where your company stands, contact us or call 514-939-3222.


