What Shadow AI Looks Like in a Canadian Advisory Practice
What shadow AI looks like in a Canadian advisory practice. The tools, the workflows, and what CIRO, PIPEDA, and Law 25 mean when it touches client data.

TL;DR
Across Reddit, LinkedIn, and advisor-publication comment sections scanned in April 2026, zero posts described a specific AI workflow in a Canadian advisor's own voice. That silence has held as CIRO moved AI from a single trend-scan line in its 2025 Compliance Report to a FinOps examination priority (Administrative Bulletin 26-0034, February 17, 2026). The quietest period in public advisor narration has become the period of sharpest regulator attention.
What shadow AI actually looks like inside a Canadian advisory practice
Shadow AI in a Canadian advisory practice means consumer AI tools used for client work without dealer approval. Personal ChatGPT open on a firm laptop. Otter joining a Zoom before compliance has seen the vendor. A Copilot prompt running through a home Microsoft 365 subscription. IBM Canada's September 2025 workforce survey found 79% of Canadian office workers using AI at work, with only 25% using enterprise-grade tools. Canadian advisors sit inside that sample as one profession among many, and the advisor-specific rate isn't separately published.
The shape of the workflow matters more than the headline rate. An advisor I worked with on his practice system pointed out a pattern in his own book of business: most of the advisors he works with don't have defined processes for how meetings get documented, how follow-up gets tracked, or how client-facing drafts get reviewed before they go out. Practice management is built meeting by meeting, assembled rather than designed. When a new AI tool arrives, it drops onto unstructured ground. The tool produces output. The advisor still has to turn that output into something usable, and often spends longer cleaning it than he saved generating it.
The canonical user of consumer AI tools is the advisor running ten or twelve hour days, unable to retain staff, making decent money but far less than the practice is earning his peers. He reaches for ChatGPT or Claude because it's the cheapest available productivity patch. The problem underneath is structural, and ChatGPT can't reach it.
Why personal ChatGPT replaces firm software when the process is undefined
Three tasks show up most often in the substitution pattern: meeting transcription where there's no agreed template, client email drafting where there's no style standard, and KYC narrative writing where the narrative is rebuilt from scratch every time. ChatGPT and Claude fill the gap the workflow didn't define. Copilot sits in a different category at some dealers, where it's approved as part of a Microsoft 365 environment and uses the sanctioned rail rather than a personal account.
The cleanup is where the cost appears. An AI meeting tool produces a transcript, a summary, and a set of action items. The advisor then has to decide which of those summary points is useful, which action items are real, which wording is fit for a compliance file, and which details the tool hallucinated or misattributed. The output is raw material, not a finished document. The advisor who doesn't have a documentation standard to check it against spends the saved time on cleanup, and the time saved evaporates into the time spent cleaning up.
Why the architecture doesn't notice
The dealer-visibility question is structural rather than incidental. An advisor pasting a transcript into a personal Claude account on a firm laptop is using a cognitive tool, not integrating a vendor. The firm's technology stack sees a browser tab. No CRM connection, no data-pipe handshake, no vendor due-diligence trigger. The use is private and the architecture doesn't notice it, which is the reason the pattern has persisted through widespread adoption.
Why dealers haven't approved the tools advisors want
The permission architecture at a Canadian dealer is built for system attachment, not cognitive use. When a vendor arrives with a tool that will integrate with the firm's CRM, calendar, or email, five roles take a look before the tool is approved: Chief Compliance Officer, Legal, Information Security, Privacy, and Senior Management. Industry estimates place the full vendor diligence cycle at 18 to 36 months, with smaller firms running faster but without well-quantified numbers. The gate clicks at integration, not at use.
This is the reason the advisor with a personal Claude account on a firm laptop is invisible to the process, and the Zocks or Focal AI vendor attempting to attach to the same firm's CRM is not. Same advisor, same intention to document meetings better, two entirely different paths through the dealer's oversight architecture. One path is private and immediate. The other is public, sequenced, and long.
Permission is named as the gate. Integration is named as the point where the gate clicks.
Advisor.ca reported in late 2025 that Canadian advisors evaluating AI notetakers "should check with their firm to ensure they have permission" before integrating with CRM and calendar systems. The advisor quoted is Christian Battistelli, a CIRO-registered senior wealth advisor at CI Assante Financial Management in Bowmanville, Ontario. That sentence carries the architecture on its own. Permission is named as the gate, and integration is named as the point where the gate clicks.
The pattern inside firms where AI tools have been mandated rather than chosen runs differently again. Advisors adopt what they choose. Mandated tools sit unused. A dealer that tries to solve the shadow AI question by pushing an approved tool into advisor workflows without advisor input tends to find the tool fitting badly with how advisors actually work. The compliance logs fill up, and the advisor's real work continues in the tools that match the shape of the meeting and the client relationship.
This is what Meeting Notes Pro was built for.
One process. Fifteen minutes to set up. Your meeting information captured, your practice protected, your compliance documented.
Learn more about Meeting Notes ProWhat four Canadian regulators say when shadow AI meets client data
Four regimes converge when a Canadian advisor's AI use touches client information.
| Regulator | Instrument | What it says about AI touching client data |
|---|---|---|
| CIRO | Compliance Report for 2026 (Administrative Bulletin 26-0034, February 17, 2026) | AI use in dealer operations is now a FinOps examination priority. Operational controls will be reviewed where dealers use AI. |
| CSA | Staff Notice 11-348 (December 5, 2024) | Securities law applies to AI systems used in regulated activities. Firms carry accountability for AI output. |
| OPC (federal) | PIPEDA, Principle 4.1.3 | Organizations remain accountable for personal information transferred to third parties for processing, including AI service providers. |
| Quebec CAI | Law 25, Section 17 | A privacy impact assessment is required before transferring personal information outside Quebec or implementing new automated processing. |
CIRO named the shift in plain language. On February 17, 2026, Administrative Bulletin 26-0034 stated that "as part of our FinOps examination approach, we will be enquiring about the use of AI in dealers' operations." The companion sentence went further: "to the extent dealers are using AI, we will be reviewing the operational controls they implemented to ensure AI is working as designed." Two sentences, both inquiry verbs, both operational.
CIRO chose supervision over rulebook. The Compliance Report does not publish model risk management standards, explainability requirements, or AI inventory mandates. It relies on existing rules plus examination authority. What counts as compliant AI will be decided at the examination interface, not in a rule consultation. Compliance officers reading the report will recognize the architecture immediately: the regulator has named AI as a topic of inquiry without narrowing in advance what acceptable AI looks like. That puts the burden of defining acceptable use on the dealer, and the burden of documenting actual use on the advisor.
Staff Notice 31-368, published December 10, 2025, named the gap in the regulator's own words. Across 105 firms reviewed, widespread deficiencies were found. The Notice observed that in some cases, firms' policies "simply repeated the rule requirements without any detail regarding how compliance is to be achieved at the specific firm and what level of documentation is required to provide evidence of compliance." Documentation. Evidence of compliance. The gap the regulator has named is a documentation gap.
Two handholds follow. An advisor serving any Quebec client needs to confirm whether a Section 17 privacy impact assessment exists for the tool in use. An advisor at any other CIRO-registered firm needs to confirm whether AI adoption has been assessed as a material business change under Guidance Note GN-2200-21-001, and if so, whether the firm has filed advance written notification and updated its Form 33-109F5 registration. Two questions, jurisdiction-matched.
What sanctioned firm AI governance looks like in practice
Sanctioned firm AI governance, in practice, comes down to four moving parts. Three signals point in the same direction. CIRO has moved AI from mention to examination. The E&O market in Canada and the US has started pulling back on AI coverage where governance maturity is thin, with US carriers (AIG, W.R. Berkley, Great American) leading the underwriting tightening and BOXX representing the clearest Canadian signal. Advisors who have already chosen a sanctioned AI tool are doing so on specific, defensible grounds.
Carlo Valle runs Delta Financial Analytics in Montreal as an independent fee-for-service planner. He chose his AI meeting tool on the basis of Canadian terminology (RRSP, TFSA, RRIF) and French-language transcription capability, not feature breadth. Scott Sather at Awaken Wealth Management in Regina chose on the basis of security safeguards and stated willingness to pay a premium for them. Battistelli, quoted above in the permission-gap section, described the same evaluation question from the approved-path side: check with the firm first, confirm permission before integrating, then proceed.
Across three advisors with three different criteria, the same pattern repeats. A named tool. A documented evaluation decision. A permission conversation with the firm where one applies. A documentation practice underneath the tool that the advisor can point to when a compliance officer asks.
Start with one thing that works.
Meeting Notes Pro handles meeting documentation so you can focus on what you do best. No complex setup. No platform to learn. No hundreds of dollars a month.
Learn more about Meeting Notes ProWhat Canadian advisors can do this week
Two questions close the gap between current practice and a defensible position, whichever side of it an advisor sits on today.
For firms serving one or more Quebec clients. Confirm whether a Section 17 privacy impact assessment exists for the AI tool currently in use or being considered. If the answer is no, that is the first document to build.
For CIRO-registered firms serving clients outside Quebec. Confirm whether AI adoption has been assessed against the material-business-change threshold in Guidance Note GN-2200-21-001. If the threshold has been crossed, confirm whether the firm has filed advance written notification and updated its Form 33-109F5 registration. If the answer is no at either step, that is the first conversation to have.
For independent and boutique advisors, where vendor approval is the advisor's own decision, Meeting Notes Pro offers a Canadian-built path that addresses the documentation question directly.
The broader point for advisors still inside the permission conversation with their firm is that most don't have the language to start it. The Compliance Conversation Kit is that language.
Key Takeaways
- Canadian advisors are adopting AI privately at rates consistent with the broader workforce, and narrating that adoption publicly at rates close to zero. The silence has structural causes in the dealer-visibility architecture.
- The dealer permission architecture gates on system integration, not on cognitive use. A personal Claude account on a firm laptop is invisible to the architecture; a CRM-integrated vendor triggers an 18-to-36-month diligence cycle.
- CIRO's February 2026 Compliance Report moved AI from a single trend-scan line to a FinOps examination priority. What counts as compliant AI will be decided at the examination interface, not in a rule consultation.
- Staff Notice 31-368 named the gap in the regulator's own words. Firms whose policies restate the rule requirements without specifying how compliance will be evidenced are the firms the regulator flagged. The gap is a documentation gap.
- For independent and boutique advisors, the permission conversation is the advisor's own. For advisors inside a dealer network, two jurisdiction-specific questions (Quebec Section 17, or CIRO material-business-change plus Form 33-109F5) close the gap between current practice and a defensible position.
Frequently asked questions
What does Quebec Law 25 require for AI tools handling client data?
An advisor serving any Quebec client needs to confirm whether a Section 17 privacy impact assessment exists for the AI tool in use. Law 25, Section 17 requires a privacy impact assessment before transferring personal information outside Quebec or implementing new automated processing. If no assessment exists, that is the first document to build.
Is AI adoption a material business change under CIRO?
An advisor at a CIRO-registered firm needs to confirm whether AI adoption has been assessed as a material business change under Guidance Note GN-2200-21-001. If the threshold has been crossed, the firm must file advance written notification and update its Form 33-109F5 registration.
Compliance & AI Dispatch
Once a month: what is changing across CIRO, PIPEDA, and Quebec Law 25, and what it means for advisors using AI tools. A five-minute read.

Sandra Lyne
Founder, Northern Catalyst | Developer, Meeting Notes Pro
Building tools for Canadian financial advisors
Related Posts
Does CIRO Allow AI Meeting Notes?
CIRO has no formal AI policy, but the 2026 Compliance Report signals exactly what examiners will ask about AI in your practice.
10 min read
What CIRO Requires in Meeting Documentation (2026)
CIRO's five-factor suitability standard and Staff Notice 31-368 show what meeting documentation must demonstrate. The gap is smaller than you think.
20 min read
Why Canadian Advisors Face Different AI Considerations
Canadian advisors face six distinct AI regulatory requirements with no US equivalent. The best AI guidance was written for SEC and FINRA. Here is what PIPEDA, CIRO, and Quebec Law 25 actually require.
7 min read