Law 25 and generative AI: your prompts are data too

A prompt can contain personal information, generate inferences, and create new privacy obligations. What Quebec business leaders should understand before connecting AI to company data.

A company can carefully protect its CRM, ERP, and servers, then allow an employee to paste a customer's full email, a job application file, or a table containing financial information into a generative AI tool.

The problem is not the prompt itself. It is what the prompt contains, what it becomes, and what happens to it afterward.

In Quebec, personal information is information that can directly or indirectly identify a person. The Commission d’accès à l’information now makes clear that information generated by an artificial intelligence system or inferred about an individual can also be personal information subject to applicable privacy laws.

Source: Commission d’accès à l’information — What is personal information?

Generative AI therefore does not create a separate legal universe. It creates new ways to collect, use, disclose, and generate personal information.

A prompt can contain much more than a question

Consider a simple example.

An employee receives a customer complaint. To save time, she asks an AI tool to rewrite the response more professionally. She pastes the original email, which contains the customer's name, order number, address, details about the situation, and part of the service history.

From the employee's point of view, she simply asked for help writing an email.

From a data perspective, several things may have happened: personal information was transmitted to another system; it may have been logged; a response was generated from it; derived data or inferences may have been created; and the provider may apply its own retention or usage rules.

That is why the first question a company should ask is no longer only: “Are we allowed to use this tool?”

It should also ask: what information are we allowing it to receive, for what purpose, and what happens to that information after the answer is generated?

The CAI investigation into generative AI changes the discussion

On May 6, 2026, the Commission d’accès à l’information published, with other Canadian privacy authorities, the results of its investigation into OpenAI and ChatGPT. The investigation looked in part at the collection, use, and disclosure of personal information to train and deploy a generative AI system.

The authorities identified issues involving overcollection, consent, transparency, accuracy, access, correction, retention, and organizational accountability. For Quebec, the CAI concluded that OpenAI had not fully complied with the obligations described in the report.

Source: CAI — Results of the joint investigation into OpenAI and ChatGPT

The decision is especially instructive for businesses because the CAI did not limit itself to cybersecurity.

It focused on secondary use of conversations.

Among other things, the CAI recommended that use of chat content for training be disabled by default, that users be informed when their conversations may be used for training, and that historical retention be explained or, failing that, the information be destroyed or anonymized.

This is not a universal rule stating that every company must always disable all training. It is, however, a strong regulatory signal: secondary purpose and default settings matter.

The real problem is often invisible

When a company collects personal information to process an order, manage an employee, or respond to a customer, it has a defined purpose.

Putting that information into another system for a new use may raise a different issue.

The CAI reminds organizations that personal information is generally used for the purposes identified at collection, and that reuse for another purpose must be assessed under the rules on necessity, consent, and statutory exceptions.

Source: CAI — Use and disclosure of personal information

This becomes especially important where a provider may use interactions to improve a service, train a model, perform analytics, or retain a history.

A prompt is therefore not just text. It can be a data transaction.

The company must know the path of the information

Now imagine an AI assistant connected to the CRM.

The user asks: “Summarize this customer's file and prepare the reply.”

The system reads the CRM, retrieves several data points, sends them to a model, produces a response, and may log the conversation.

To govern this properly, the company needs to answer questions far more precise than “Is our AI secure?”

It must know what information the system can access, which models may receive it, what uses are permitted, how long the data is retained, who can access logs, and whether secondary uses are allowed.

Canadian privacy authorities recommend that organizations using generative AI establish retention schedules for information contained in prompts and outputs, use anonymized or de-identified data where possible, and include sensitive information in prompts only where authorized. They also state that, unless otherwise indicated, prompts should not be retained for secondary purposes or disclosed.

Source: Office of the Privacy Commissioner of Canada — Principles for responsible, trustworthy and privacy-protective generative AI

The Belarel perspective: govern data while AI is working

An internal policy that says “do not put confidential information into AI” is a starting point. It is no longer enough when AI is directly integrated into operations.

When systems can themselves read customer records, emails, and internal documents, governance has to become executable: what data may be used, by which agent, with which model, for what task, and under what conditions?

The issue is no longer only employee training. It is technically controlling what AI is allowed to do with the information entrusted to it.

A business leader should be able to ask: if I take one piece of personal information from our CRM and follow its path through our AI environment, do we know exactly where it goes, why it goes there, how long it stays there, and what can be done with it?

If answering that question takes several days of investigation, the challenge is probably no longer AI adoption. It is governance.