Most AI acceptable use policy templates you'll find online were built for American state laws or EU GDPR compliance. They reference regulations that don't govern Canadian businesses and miss the ones that do — PIPEDA, Quebec's Law 25, and Ontario's January 2026 AI disclosure rule, which is already in force.
This template is built for Canadian small and medium businesses — around the law that actually applies to how you operate. The fields in square brackets are decisions you need to make for your own business: which tools, which data rules, which disclosure commitments. A copied policy doesn't protect you; a policy that reflects decisions your business actually made does.
Legal note: This template is a starting point, not legal advice. It's designed to help you think through the right questions and get something workable in place. If you operate in a regulated sector — healthcare, financial services, law — or you handle personal data at significant scale, review this with a lawyer before putting it in front of your team.
What Canadian Law Actually Requires
There is no comprehensive federal AI law in Canada. Bill C-27 — which included the Artificial Intelligence and Data Act — died in early 2025 when Parliament dissolved. In June 2026, the federal government released "AI for All," a strategy document that commits existing regulators to use their current powers. No new obligations for businesses.
What does govern you: PIPEDA (the federal privacy law, in force since 2000), and provincial privacy statutes depending on where you operate — Quebec's Law 25, Alberta's PIPA, or BC's PIPA. Every law that already applied to how you treat people and handle their data still applies when AI touches that data. The tool is new; the obligation isn't.
Quebec's Law 25 is worth particular attention: it includes transparency requirements for automated decision-making that affect how you can use AI in ways that impact individuals. If you have customers or employees in Quebec, it applies to you regardless of where your business is headquartered.
Ontario is the province with the most specific AI rules for private-sector employers. As of January 1, 2026, Ontario's Employment Standards Act requires employers with 25 or more employees to disclose AI use in job postings when AI is used to screen, assess, or select candidates. That's a live obligation. If you're in Ontario and using AI in hiring, check Section 4 of the template carefully.
An AI policy isn't preparing you for a future regulatory wave. It's operationalising obligations you already have.
The Template
[COMPANY NAME] AI Acceptable Use Policy
Approved AI Tools
Your team is almost certainly already using AI tools. This section makes explicit which ones are permitted, under what conditions, and who decides when a new tool is added.
The following AI tools are approved for work use at [Company Name]:
- [Tool name] — approved for [specific use cases, e.g., drafting emails, summarising meetings, internal research]
- [Tool name] — approved for [specific use cases]
- [Add additional approved tools]
Employees may not use AI tools not listed above for work purposes without prior approval from [ROLE].
To request approval for a new AI tool, contact [ROLE] with: the tool name and URL, the intended use, and whether a paid or enterprise version is required. Approval is based on where data is stored, whether the vendor trains models on user inputs, and whether enterprise terms of service are available.
Note: Free consumer tiers of most AI tools (ChatGPT Free, Gemini, etc.) have different data retention and training terms than paid enterprise versions. Know which version your team is using.
Data Handling
This is the PIPEDA line. Personal information cannot go into an AI tool without a legal basis and appropriate safeguards. This section defines what that means for your team.
Personal information — names, email addresses, phone numbers, financial data, health information, or any information that identifies a living person — may not be entered into any AI tool unless:
- the tool is specifically designated for personal information use in Section 1, and
- the vendor has confirmed in writing that they will not train on your data, and that data is stored in [Canada / North America / specify jurisdiction]
All other approved tools are for internal, non-personal use only: drafting, research, summarising, and similar work that does not involve identifying information about clients, customers, or employees.
Confidential business information — pricing, contracts, unreleased plans, client files, or information covered by NDA — may only be entered into enterprise-tier tools with appropriate confidentiality terms. When uncertain, do not enter it.
Test: if you would not email this information to a stranger, confirm it is appropriate for your AI tool before entering it.
Output Review
Speed is the risk. AI tools produce outputs fast, but fast does not mean accurate or appropriate. This section defines what requires human review before use.
The following outputs must be reviewed and approved by a qualified human before being sent, published, or acted upon:
- All communications to clients or customers (emails, proposals, reports, recommendations)
- All content published on any public platform (website, social media, marketing materials)
- All documents that create legal obligation (contracts, agreements, terms of service)
- All content related to employment decisions (job postings, offer letters, performance feedback, termination notices)
- Any submission to a regulator, legal proceeding, or compliance process
Internal drafts, meeting notes, research summaries, and working documents may move at normal pace. Employees are responsible for the accuracy of anything they act on, regardless of how it was produced.
Disclosure
Some disclosure is legally required. The rest is a matter of trust. This section covers both.
Ontario employers with 25 or more employees: As of January 1, 2026, Ontario's Employment Standards Act requires that if AI is used to screen, assess, or select candidates for a position, that use must be disclosed in publicly advertised job postings.
Does this apply to [Company Name]? [Yes — we will include disclosure language in all job postings where AI is used in screening / No — we do not use AI in candidate screening / Under review]
Internal disclosure: Any employee may ask whether AI was used in a decision that affects them. [Company Name] will provide a direct, honest answer upon request.
Client and external disclosure: [Company Name] will disclose AI use to clients when: [describe the circumstances — e.g., "AI-generated content is used in deliverables without significant human revision" / "AI is used to make recommendations affecting a client's operations" / "upon client request"]
Policy Owner and Review
A policy without an owner is a document that lives in a folder and gets forgotten. This section names accountability and sets a review cadence appropriate for how fast AI is moving.
This policy is owned by: [ROLE]
The policy owner is responsible for maintaining the approved tools list, evaluating requests for new tools, answering questions about this policy, and updating it when our tools, practices, or legal obligations change.
Review schedule: Quarterly · Next review: [DATE]
On each review, the policy owner will confirm: the approved tools list is current; any tools adopted since the last review have been formally evaluated; any incidents or near-misses have been documented; any regulatory changes have been incorporated.
Questions about this policy: [EMAIL or ROLE]
What to Change — and What to Keep
Fill in every field in square brackets. Each one is a decision your business needs to make. Which tools are approved? Which jurisdiction governs your data storage? Does the Ontario rule apply to your hiring process? Name the policy owner. Set the next review date. A template with unfilled fields is not a policy.
Adapt the data handling section to your industry. A healthcare practice has different obligations than a marketing agency. If you handle sensitive personal data at scale — health records, financial data, children's information — get a lawyer to review that section specifically. For most small businesses, the default language is a solid starting point.
Keep the structure. The five sections cover the questions that come up when something goes wrong: Was this tool approved? Should that data have gone in? Did anyone review it before it went out? Did we disclose what we needed to? Who owns this? If your policy can answer all five, it's doing its job.
Set a calendar reminder. Quarterly. The policy you write today will need updating — new tools get adopted, regulations evolve, your team's practices change. A quarterly check-in keeps it current. If you're still in the early stages of figuring out how AI fits into your operations, the AI Adoption Checklist for Canadian Businesses is a good place to start before you write the policy — it covers the groundwork that makes a policy like this easier to fill in accurately.
When to Get Help
Most small businesses can adapt this template and run with it. You don't need a consultant to write an AI policy. You need clarity about your own decisions, and the template is designed to force that clarity.
Where it helps to have a second pair of eyes: regulated industries (healthcare, legal, financial services), businesses handling personal data at significant scale, businesses using AI in ways that directly affect employee or customer rights, or any situation where you're not confident the policy you've drafted reflects your actual obligations under PIPEDA or your provincial privacy law.
If that's you, a working session with someone who knows the Canadian legal landscape can make sure the policy you put in front of your team actually holds up. Reach out at [email protected] or book directly at bynorthlight.ca.
Frequently Asked Questions
What is an AI acceptable use policy?
An AI acceptable use policy tells your team which AI tools are approved, what data can go into those tools, what outputs require human review before use, and who is accountable for keeping the policy current. It makes "use AI responsibly" mean something specific enough to act on.
Is an AI policy legally required in Canada?
No federal law requires a written AI policy. But PIPEDA, provincial privacy statutes, and Ontario's 2026 employment disclosure rule create obligations that a policy helps you meet and document. It isn't legally required — it's practically necessary if your team uses AI tools and you want to manage the liability that creates.
What does PIPEDA have to do with AI use?
PIPEDA governs how businesses collect, use, and disclose personal information. If your team is entering customer names, client emails, employee data, or any other identifying information into an AI tool, PIPEDA applies. The tool is new; the obligation isn't. Your accountability for how personal information is handled doesn't end because you passed it through an AI system.
What are Ontario's AI disclosure requirements?
As of January 1, 2026, Ontario's Employment Standards Act requires employers with 25 or more employees to disclose in publicly advertised job postings when AI is used to screen, assess, or select applicants. This is a live requirement. Other provinces are watching but have not passed equivalent legislation as of mid-2026.
What makes a Canadian AI policy different?
Canada has its own legal framework — PIPEDA at the federal level, Quebec's Law 25 with its automated decision-making transparency requirements, provincial privacy acts in Alberta and BC, and Ontario's employment AI disclosure rules that came into force January 1, 2026. A Canadian AI policy is built around these laws — around how Canadians have chosen to govern privacy, consent, and the use of personal information. Most templates found online were written for US state laws or European GDPR compliance. They're not wrong for the markets they serve; they just don't reflect the law you operate under.
How often should I update my AI policy?
Quarterly. Annual reviews are standard for many policies — AI is moving fast enough that a year is too long. A quarterly review doesn't mean rewriting the document. It means confirming your approved tools list is current, checking whether your practices have changed, and noting whether any new rules have come into effect.
Do I need a lawyer to write an AI acceptable use policy?
Not for a standard policy. If you operate in a regulated sector — healthcare, legal, financial services — or you handle personal information at significant scale, legal review of the data handling section is worth the investment. For most small businesses using AI for drafting, research, and internal work, a clear framework adapted to your tools and team is enough to start.
Can I use this template for free?
Yes. Adapt it for your business, add it to your employee handbook or operations manual, and use it. If you find it useful and want help implementing it — or want a second pair of eyes on the version you've adapted — that's what a consultation is for.