What is shadow AI, and what should Ontario firms do about it?
Short answer: your team is probably already using AI on private files, and the fix isn't a ban. It's a private tool that keeps the files inside your office.
Every factual claim below is footnoted to a source you can open, and each source link jumps to and highlights the exact passage on the original page.
What "shadow AI" means
Shadow AI is the use of AI tools your firm hasn't vetted or approved: a lawyer summarizing a discovery document in ChatGPT, a bookkeeper asking a chatbot to make sense of a client's statements, an associate pasting a contract into a free tool to "put it in plain English." It's the AI version of shadow IT: useful tools adopted by individuals, faster than the firm can set policy, and invisible to whoever is responsible for confidentiality.
The tools themselves aren't the problem. The problem is that the client's information goes with them.
Why it's already happening in your firm
You don't need a policy to have shadow AI; you need staff with deadlines and a browser. Free chatbots are one tab away, they are genuinely useful, and reaching for one rarely feels like "sending client data to a third party." It feels like typing into a search box.
This isn't a fringe habit. In a 2025 survey of North American office workers, IBM found that 79% use AI at work while only 25% rely on enterprise-grade tools. The rest lean on personal tools, alone or alongside their employer's.[1] If your firm has more than a handful of people, the realistic assumption is that some client text has already been pasted into a tool nobody approved, in a personal browser tab or on a phone, where firm systems can't see it.
The confidentiality problem
For a regulated firm, this is where it stops being a productivity story. A lawyer must "hold in strict confidence all information concerning the business and affairs of the client acquired in the course of the professional relationship."[2] A breach doesn't require anything to be published. Disclosing client information to a third party, such as an AI vendor's servers, without the client's consent is already the problem. Accountants carry a parallel duty: CPA Ontario's Rule 208, Confidentiality of information, requires members to protect confidential client information acquired through professional relationships (CPA Ontario Code of Professional Conduct).
And the exposure is real the moment the file leaves. Three-quarters of employees who use shadow AI admit to feeding potentially sensitive information into unapproved tools, most often employee data, customer data, and internal documents. As the Journal of Accountancy puts it, "Once sensitive data enters an unsecured AI tool, you lose control. It can be stored, reused, or exposed in ways you'll never know about."[3] For a firm holding privileged material, that's the whole point: you can't un-send it, and you can't audit where it went.
Why a ban doesn't work on its own
The instinct is to prohibit it, and a clear policy does help set expectations. But a ban on its own tends to fail for a simple reason: it takes away a tool people found genuinely useful without replacing what it did for them. Prohibition usually pushes the behaviour further into the shadows, onto personal phones and home laptops, where the firm has even less visibility and no logs at all.
The firms that actually shrink their exposure do the opposite. They give people an approved tool that is as easy as the one they were reaching for, so there's no reason to go around it.
The approach that removes the risk
The cleanest way to end shadow AI is to make the sanctioned option the easy one, and one where the confidentiality question never comes up. That's the idea behind FirmDocs: a small, dedicated machine that sits inside your office and reads your matter documents right there. Nothing is sent to the cloud, nothing is transmitted to us, and it keeps working even if you unplug the internet.
Your team gets what they wanted from ChatGPT: ask a question in plain English and get an answer, but every answer cites the exact document and page it came from, and the material never leaves your custody. When the approved tool is right there and just as fast, the shadow version loses its pull.
So what should your firm do about shadow AI?
Assume it's already happening. Don't rely on a ban to stop it. And give your team a private alternative that does the same job without sending client files outside the firm. That's how you capture the productivity people are quietly chasing without taking on the confidentiality exposure that comes with it. As always, confirm your own approach against the Law Society of Ontario's and CPA Ontario's current guidance and your firm's risk tolerance.
Sources
Click a source to read the quoted passage. Each link opens the original and highlights it.
IBM — Canadian workplace AI studySept 2025 · Censuswide survey of 4,000 North American office workers
"While 79% of full-time office workers said they use AI at work, only 25% rely on enterprise grade AI tools, signaling a widening disconnect between employee expectations and enterprise readiness."Read the release at ibm.com ↗
Law Society of Ontario — Rules of Professional ConductRule 3.3-1 · Confidentiality
"A lawyer at all times shall hold in strict confidence all information concerning the business and affairs of the client acquired in the course of the professional relationship and shall not divulge any such information unless (a) expressly or impliedly authorized by the client; (b) required by law or by order of a tribunal of competent jurisdiction to do so; (c) required to provide the information to the Law Society; or (d) otherwise permitted by rules 3.3-2 to 3.3-6."Read the highlighted rule at lso.ca ↗
Journal of Accountancy — "Lurking in the shadows: the costs of unapproved AI tools"Nov 2025 · AICPA & CIMA
"Once sensitive data enters an unsecured AI tool, you lose control. It can be stored, reused, or exposed in ways you'll never know about."Read the article at journalofaccountancy.com ↗
See it in action
The same thing this page just did (ask a question, get an answer that cites its source), but pointed at your own files and running on a machine inside your office. Book a 15-minute screen share; nothing leaves the building.
Book a 15-minute demoAI can make mistakes, so always check an answer against the source it cites. The quoted passages here are verbatim from the linked sources, and each link opens the original and highlights the passage. This article is general information, not legal, compliance, or professional advice. For your own obligations, consult the Law Society of Ontario's or CPA Ontario's resources, or your practice advisor.