Adopting AI in Your Organization: the Risks of Inadequate Security
The main risk that artificial intelligence poses in businesses is not technological, but rather the lack of a framework for its use.
The main risk that artificial intelligence poses in businesses is not technological, but rather the lack of a framework for its use.
Informal AI adoption is already well underway
According to Statistics Canada, 12.2% of Canadian businesses reported having used artificial intelligence to produce goods or deliver services during the second quarter of 2025. However, this statistic is misleading. In reality, the majority of employees have already adopted it.
Another survey conducted by Statistics Canada that focused on employees confirms this reality. The proportion of Canadians who have used generative AI in the workplace almost doubled in 10 months, increasing from 17% in September 2024 to 30% in July 2025. Employees used AI before it was greenlighted by management to:
- draft emails;
- summarize reports;
- generate lines of code;
- prepare presentations.
However, we know that, when usage precedes an official decision, it also outpaces the rules and guardrails that should govern it. As a result, your organization may have to secure a technology that it never formally adopted.
What’s the real danger of AI in business settings?
The danger is often day-to-day use without guidelines, which can expose sensitive information. An example of this could be the development team using an artificial intelligence tool to speed up writing code. In order to analyze and rework the existing code, the tool must access a portion of it. However, this code could contain intellectual property, which is then available to an external supplier outside of the organization’s environment.
The same scenario could impact your client data. An employee could upload a contract, a portion of code or client data to public software. While this action appears trivial, it essentially entails taking sensitive information out of your business environment.
If this data contains personal information, you could also infringe your obligations under Law 25 regarding the protection of personal information.
This phenomenon, which involves using artificial intelligence in the workplace without either approval or supervision, is known as Shadow AI. Personal tools make up a significant proportion of professional AI use. According to a study commissioned by IBM in 2025, 21% of Canadian office employees surveyed use only personal AI applications in the workplace and 33% combined them with their employer’s tools.
How can AI expose your organization’s systems?
A data breach is not the only risk. As the number of AI tools and agents grows, it’s becoming more difficult to keep track of the data and systems they can access.
The VARS offensive security team was recently retained by an insurance company to test an internal chatbot, which had access to a significant portion of the company’s information and systems.
In order to test the chatbot’s limits, it was provided with a fictional scenario (a princess imprisoned in a dungeon that represented the network). The artificial intelligence played the game and, step by step, revealed how to infiltrate the company’s systems. Essentially, the technology developed to answer employee questions provided instructions on how to attack the organization’s network.
Each tool adopted without supervision can expand your attack surface without you even knowing. However, you can’t protect yourself if you’re unaware of the threat.
Why are AI usage policies not enough?
A large number of businesses can anticipate these threats without changing their position on AI. According to an international survey of cybersecurity and IT professionals conducted by SANS in 2026, 78% of organizations reported confirmed or suspected AI-enabled attacks. However, only 16% of leaders refocused their priorities to better protect their companies.
Certain businesses have begun to adopt AI usage policies. However, such policies must be distilled into tangible rules and implemented in order to ensure they are respected.
In particular, employees must know:
- which AI tools they can use;
- what data they can share;
- which uses are allowed and prohibited.
The organization must also be capable of detecting usage that falls outside the scope of these rules. During this stage, business owners often realize they need additional control mechanisms. Essentially, organizations must raise awareness among AI users of the inherent risks.
Do security features slow down AI adoption?
One might fear that introducing additional rules and controls could slow down AI adoption. However, in reality, it’s actually the opposite.
Knowing where your data is circulating, controlling access and defining what AI can and cannot do allows you to expand usage without multiplying risks. Security processes build trust, which allows organizations to move forward faster.
Without proper oversight, you’ll have to slow down at some stage to manage a data leak, address an incident or rebuild a client’s trust. Therefore, providing a framework for AI goes beyond a technical team project. It’s a governance issue on par with financial and operational risk.
How can we help you?
With a view to developing guidelines for AI use without holding back its adoption, our cybersecurity experts can help you to:
- build a governance framework tailored to your organization;
- assess the risks relating to your AI usage;
- introduce control measures and technological solutions to protect your data.
Are you unsure whether your organization is exposed to these risks? Contact us.
This article was written in collaboration with Maxime Boutin, cofounder of VARS, a division of Raymond Chabot Grant Thornton that specializes in cybersecurity.