AI Security
AI security for Canadian businesses
Most AI security problems in small and mid-sized businesses aren't hackers. They're well-meaning staff using personal AI accounts, uploading whole files, connecting AI tools to work email, or letting a meeting bot record a call.
Free 30-min call · AI security assessment from C$1,500 · price confirmed for your team before you pay. Before tax.
Useful AI. Clear boundaries.
This page explains where the real risks are, which Canadian rules apply, and a practical checklist you can start on this week. Hero is based in Toronto and does this work with teams across Canada, in person in the GTA and online everywhere else.
Where AI tools actually leak information
- Personal accounts used for work. A free or personal account sits outside your control. You can't see what went in, and you can't remove it when someone leaves.
- File uploads. One spreadsheet can hold thousands of records, far more than the rows someone meant to ask about.
- Connectors. "Connect to Outlook, Gmail, Drive or SharePoint" lets a tool read everything that account can reach, not just one document.
- AI note-takers. Meeting bots can join through calendar invites and record conversations nobody agreed to share.
- Browser extensions that read every page you open, including email and client systems.
- Manipulated content (prompt injection). A document, email or web page can contain hidden instructions that steer an AI tool, for example to summarize something misleadingly or to pull in information from a connected account. The more an AI tool can read and do on your behalf, the more this matters.
- Over-trust. An AI answer that sounds confident but is wrong, sent to a client without checking, is a quality and liability problem even when no data leaks.
The Canadian rules to know
General information, not legal advice. Your privacy lead or counsel owns the interpretation.
- PIPEDA applies to most businesses' handling of personal information in commercial activity, outside Quebec, Alberta and BC. You remain accountable for personal information you give to a service provider, including an AI vendor, and you must protect it with safeguards that match how sensitive it is. A breach that creates a real risk of significant harm must be reported to the Privacy Commissioner of Canada and the affected people notified. Every breach, reportable or not, must be recorded and the record kept for 24 months.
- Quebec (Law 25) requires a privacy impact assessment before personal information is communicated outside Quebec, which can include a cloud AI provider. If you make a decision about a person based only on automated processing, you must tell them.
- Alberta and BC have their own private-sector privacy laws (both called PIPA), with similar principles.
- Ontario health information (PHIPA). Clinics and other health information custodians have their own duties. Ontario's Information and Privacy Commissioner has said that entering personal health information into an AI tool the custodian hasn't authorized is a privacy breach. In April 2026 the IPC published a case in which an unapproved AI transcription tool recorded a hospital meeting where patient information was discussed.
- Ontario job postings. Since January 1, 2026, Ontario employers with 25 or more employees must disclose in publicly advertised job postings if AI is used to screen, assess or select applicants.
- Professional rules. Lawyers, accountants, engineers, insurance brokers and health professionals have confidentiality duties on top of privacy law.
- What's coming. A new federal privacy bill (Bill C-36) was introduced in June 2026. It isn't law as of October 2026, so PIPEDA still applies.
A next stepWant to know where your own team stands? Start with a free 30-minute call, or read what information should never go into an AI tool.
A security checklist for ChatGPT, Copilot and Gemini at work
- Approve one tool on business accounts your organization controls. ChatGPT Business or Enterprise, Microsoft Copilot Chat signed in with work accounts, or Gemini in a Google Workspace business plan. Under their business terms, these vendors say they don't train their models on your content by default. Turning off a training setting in a personal account is not the same thing: the account is still outside your control.
- Publish a never-enter list: passwords and access codes, government ID numbers, banking and card details, health information, and anything under privilege or a confidentiality agreement.
- Teach people to de-identify properly or describe the situation instead of pasting the document. Deleting a name is often not enough.
- Review connected apps and note-takers. Remove what nobody can explain, and require approval before anyone connects an AI tool to email, calendars or files.
- Limit access by role. Not everyone needs AI connected to every shared drive.
- Have a same-day mistake process: what was entered, which tool, which account, when, and who decides whether it's a breach to record or report.
- Keep a person on anything that leaves the building. AI can draft. A person checks and sends.
- Review the policy and tool settings every six months, and whenever you add a tool or a vendor changes its terms.
For the detail behind steps 2 and 3, see what information should not go into AI. For the written rules, use the AI use policy template.
How a practical AI security assessment works
Hero's AI security assessment finds out what's really happening before anyone writes rules:
- Short interviews with leadership and a few staff, plus an anonymous survey about which tools and accounts people use
- A review of the AI-related admin settings in the tools you already pay for, such as Microsoft 365 or Google Workspace, with access you approve and can remove
- A sketch of where sensitive information goes
- Ranked written findings: what to stop today, what to fix next, and what can wait
After that, Hero can train the team on the findings and write a plain-language AI use policy with matching account settings. It is a practical assessment. It isn't a certification, a formal compliance report or legal advice. If you need one of those, we'll say so early and point you to the right kind of specialist.
Assessments start from C$1,500, with a written list of what to fix first 1 to 2 weeks after the working session. Every price is on the pricing page.
FAQ: AI security
Is this a certification?
No. It's a practical assessment with written findings and a policy. If a client or regulator needs a formal certification, we'll tell you and point you to the right kind of firm.
Do you need access to our systems?
Only what you choose to share, with access you approve and can remove. Much of the assessment is interviews and a survey.
Can you train our staff on AI security only?
Yes. Security training can run on its own as a private team session, and the security basics are part of every workshop seat.
Should we ban AI until this is sorted?
A ban with no approved alternative usually pushes use into personal accounts you can't see. A short interim rule works better: one approved tool on work accounts, nothing from the never-enter list, and check everything.
A CLEAR NEXT STEP STARTS HERE
Book a free Fit Call.
Tell us about your team. We will tell you whether training, an AI readiness assessment, or AI security work is the right next step.
Free 30-minute call with our founder · Video call, camera optional