Can Canadian lawyers use ChatGPT? What the law societies, the courts and PIPEDA actually require in 2026

No Canadian law society bans ChatGPT. But the Law Society of Ontario, Alberta, BC and Quebec guidance, two fake-citation decisions and PIPEDA set real conditions on how a lawyer can use any AI tool. Here is what they are, with sources.

Every week a Canadian lawyer asks some version of the same question: am I allowed to use ChatGPT for this? The honest answer is that the question is slightly wrong. Nobody has banned the tool. What the regulators, the courts and the privacy statutes have done is attach conditions to how you use any generative AI on client work — and those conditions are specific enough that you can check yourself against them in an afternoon.

This is that checklist, with the sources linked so you can read the primary material rather than take our word for it.

Can lawyers in Canada use ChatGPT at all?

Yes. The Law Society of Alberta keeps a running tally of who has said what: as of its last update, eleven Canadian courts, nine law societies, two professional liability insurers, one provincial government, the Canadian Judicial Council, the Canadian Bar Association and the College of Patent Agents have all issued generative AI guidance. Not one of those documents prohibits the technology. The through-line, in the Law Society of Alberta's words, is that lawyers are responsible for the truth and accuracy of their work and must use generative AI carefully.

That framing matters because it tells you where the risk sits. The tool is not the regulated party. You are. Your existing duties — competence, confidentiality, supervision, candour with the client, not misleading a tribunal — apply to AI-assisted work exactly as they apply to work done by an articling student, and the law societies have been explicit that those duties are the lens.

What the Law Society of Ontario actually says

The LSO's Futures Committee published its white paper, Licensee Use of Generative Artificial Intelligence, on April 25, 2024. It is short and worth reading in full. It ties generative AI to six obligations under the Rules of Professional Conduct:

  1. Competence. You must understand the tool well enough to know what it cannot do. Judgment is not delegable.
  2. Confidentiality. Before confidential or privileged material goes into any generative AI system, you need "adequate security measures" in place. The paper does not say what those are — that is the point of the rest of this post.
  3. Supervision. Rule 6.1-1 requires you to supervise delegated work. The LSO applies the same logic to an AI assistant: review its output the way you would review a junior's.
  4. Fees. Bill for the time actually spent. Efficiency gains are not a licence to bill the hours the tool saved.
  5. Honesty and candour. If a court's practice direction requires disclosure of AI use, you comply.
  6. Not misleading a tribunal. You own every citation and every proposition in what you file.

On telling clients, the LSO deliberately did not impose a blanket disclosure rule. Instead it lists four factors that should push you toward disclosure: a court or public disclosure requirement; the client's expectation about who is doing the work; whether the client's personal or proprietary information is being input; and reputational risk to the client. If any of those is live on a file, the conservative reading is to say so in the retainer or in a short email.

The LSO's Technology Resource Centre pairs the white paper with a quick-start checklist and a summary of professional obligations. If your firm has no AI policy, that checklist is the shortest path to one.

What Alberta, British Columbia and Quebec add

Alberta moved first. The Law Society of Alberta released its Generative AI Playbook in January 2024, and it also publishes a model Generative AI Use Policy that a firm can adapt in an hour. Alberta recommends but does not require disclosure of AI use.

British Columbia's Guidance on Professional Responsibility and Generative AI is the most concrete of the four on confidentiality. It says that ideally, client confidential information — including anything that identifies the client — would be omitted from what is supplied to a generative AI tool. Where redaction is not possible, it points to fully informed client consent under the Code's definitions of "consent" and "disclosure", and it flags the risk that using a third-party tool could give rise to arguments about waiver of privilege. It also says something vendors should be honest about: because these tools learn from what is input, the tool "may reuse the confidential information you supply for other purposes over which you may have no control." Its suggested answer is that firms may create or purchase their own bespoke AI solutions, since a private tool that only uses information provided by the firm might help avoid some of those concerns.

Notably, the LSBC states it cannot endorse any product. Lawyers have asked it to publish a certified "safe" list of AI tools anyway. Do not expect one; the vetting is yours to do.

Quebec has gone furthest. The Barreau du Québec published its Guide pratique pour une utilisation responsable de l'intelligence artificielle générative in November 2024, and as of April 1, 2026, every member must complete a mandatory two-hour online course, Encadrer l'IA générative dans la pratique du droit, by April 1, 2027. It counts toward the three mandatory hours in ethics and professional practice. If you are a Quebec lawyer reading this, that course is not optional.

Is ChatGPT confidential enough for client information?

This is really two questions: what the vendor does with your input, and whether the material is still privileged afterward.

What the vendor does with it. On the consumer ChatGPT plans — Free, Plus and Pro — conversations are used to improve OpenAI's models by default. You can turn that off under Settings → Data Controls → "Improve the model for everyone", but it is on until you do. ChatGPT Business and Enterprise and the API do not train on your content by default, and say so contractually. So the practical risk is not the tool in the abstract. It is a lawyer on a personal Plus subscription who has never opened the data controls, pasting a client's financial statements into a system that will learn from them. That is precisely the scenario the LSBC guidance describes.

Whether it stays privileged. Solicitor-client privilege protects communications between you and your client for the purpose of legal advice. A conversation with a vendor's chatbot is not a communication with your client, and Canadian courts have not yet settled whether routing privileged material through a third-party tool waives anything. The LSBC guidance flags the waiver argument for exactly that reason. The safest working rule, as one Ontario estates litigation firm puts it, is to treat an AI conversation the way you treat email and text messages: a record that could be produced.

So what do "adequate security measures" look like in practice? Before any client material goes into a tool, you should be able to answer these from the vendor's terms, not from its marketing:

  • Training. Does the contract say your content is never used to train a model? Is that the default, or a setting you had to find?
  • Location. Where is the content stored at rest, and where is it processed? Those are often different answers, and both are relevant to a client in Quebec.
  • Retention. How long is a prompt kept, who at the vendor can read it, and can you delete it?
  • Isolation. Is one client's material walled off from another's, or is everything in one pooled chat history?
  • Verification. Does the tool link the primary source for every authority it cites, so checking is a click rather than a research project?

Nothing in any law society's guidance prohibits a vendor processing content outside Canada. What the guidance and the privacy statutes require is that you know, that the protection is comparable, and that you can tell the client.

What happens when the citations are fake

Two Canadian decisions now define the downside, and every lawyer using AI for research should be able to describe both.

Zhang v. Chen, 2024 BCSC 285, was Canada's first reported fake-citation case. In a family matter, counsel filed a notice of application relying on two cases that ChatGPT had invented. The cases were withdrawn once opposing counsel could not find them. Justice Masuhara declined special costs, finding no intent to deceive, but ordered ordinary costs against counsel personally to compensate the other side for the work of running down authorities that did not exist, and directed her to review her other files before the court. He added that it would be prudent for counsel to tell the court and opposing parties when material she files includes AI-generated content.

Ko v. Li, 2025 ONSC 2766, went further. A Toronto lawyer filed a factum in a matrimonial and estates matter citing cases that could not be retrieved, and relied on two of them in oral argument. Justice Myers ordered her to show cause why she should not be held in contempt, describing the citation of fake cases in court filings as an abuse of process. In the follow-up decision, 2025 ONSC 2965, after counsel admitted the facts and apologized, the court dismissed the contempt proceeding on conditions: at least six hours of continuing professional development in legal ethics and AI, no fee to the client for the research, the factum or the attendance, and new verification protocols in her practice. The court's summary of the duty is hard to improve on: lawyers should read cases before relying on them, and at a minimum make sure they exist.

The lesson is not "AI research is dangerous." It is that the sanction lands on the individual lawyer, and that opening every authority on CanLII before it goes into a document is the floor, not a best practice.

Do you have to tell the court you used AI?

It depends on the court, and you should check the current direction before every filing.

The Federal Court issued its first notice on December 20, 2023, directing that authorities be verified against trusted sources such as CanLII and official court websites. Its May 7, 2024 notice added the requirement that any document containing content created or generated by AI carry a declaration in its first paragraph saying so, for the whole document or for identified paragraphs. Content a human wrote and merely revised with an AI tool does not need the declaration. On September 29, 2025, the Court published interim principles on its own use of AI, committing not to use generative AI to decide cases or write judgments without public consultation.

Provincially, per the Law Society of Alberta's tally, courts in Manitoba, Yukon and, in some contexts, Nova Scotia require disclosure; British Columbia and Alberta courts recommend it; Ontario and Quebec courts do not require it. Where disclosure is not required, the LSO's honesty-and-candour factors still apply to the client, and Zhang suggests that a judge may regard voluntary disclosure as the prudent course.

Does PIPEDA apply? What about Quebec's Law 25?

Yes to both, and this is the part most AI-policy templates skip.

PIPEDA governs personal information handled in the course of commercial activity, and a law practice is a commercial activity. The medical records in a personal injury file, the financial statements in a family matter, the employee particulars in a wrongful dismissal — all of it is personal information you are accountable for. Under the accountability principle, you remain responsible when a service provider processes it on your behalf, including outside Canada. The Privacy Commissioner's long-standing position on cross-border processing is that you must ensure a comparable level of protection, usually by contract, and be transparent with individuals that their information may be processed in another country and be subject to that country's laws. An AI vendor is a service provider like any other for this purpose.

Quebec's Law 25 is stricter and fully in force. Before personal information is communicated outside Quebec, the firm must conduct a privacy impact assessment. If a decision about a person is based exclusively on automated processing, the person must be told. Every firm must designate a person responsible for the protection of personal information. Administrative penalties run to $10 million or 2% of worldwide turnover, and penal fines to $25 million or 4%. The Barreau's own transparency and consent toolkit walks through what to put in a retainer.

The practical consequence for a lawyer anywhere in Canada is the same: you need to know where each AI tool stores and processes what you give it, and you need to be able to say so in plain language to a client who asks.

A five-question check before you paste anything

  1. Would I be comfortable if this prompt were produced in discovery? If not, redact, or do not send it.
  2. Does the vendor's contract say it will not train on my content — and have I actually checked the setting?
  3. Where is this stored, where is it processed, and can I tell the client both?
  4. Can I open every cited authority on CanLII before it goes into the document?
  5. Does the court I am filing in require a declaration?

If you can answer all five, you are inside every law society's guidance in Canada. If you cannot answer two and three, the tool is the problem, not the technology.

Where maplelaw sits in this

We built maplelaw to make questions two and three easy to answer, because we kept hearing lawyers redact and paraphrase client files into uselessness rather than answer them.

  • Each matter is its own workspace. Documents, saved conversations and drafts live inside the matter, not in a pooled history. Sharing with a colleague is explicit and per matter.
  • Documents are stored encrypted in Canada. Matter files sit in a private Canadian-region bucket that is never publicly reachable, served through authenticated, short-lived links. The application, the database and matter email stay in Canada too.
  • Nothing you file trains a model. Your prompts, documents and messages are not used to train maplelaw, public or third-party models, and our model provider is contractually barred from retaining them for training.
  • Quick chats are not stored. They stay in your browser and are never written to our database. Saved matter sessions persist until you delete them.
  • Every authority is linked. Research runs against CanLII and links the source, so question four is a click.
  • One boundary, stated plainly. Model inference runs through a cross-region profile, so prompt and document text sent to the model may be processed in a United States region. Everything else stays in Canada. We say this because a lawyer answering question three needs the real answer, not a slogan. The detail is in our privacy policy and in why we built it this way.

None of that makes anyone compliant. Verification, supervision, the disclosure decision and the client conversation stay with counsel, as every law society has said they must. What a private workspace does is remove the reasons to cut corners on them. The free plan is enough to see whether that is true for your practice.

Frequently asked questions

Can lawyers in Canada use ChatGPT?

Yes. No Canadian law society bans ChatGPT or any generative AI tool. The Law Society of Ontario, the Law Society of Alberta, the Law Society of British Columbia and the Barreau du Québec have all issued guidance instead, and all of it makes the lawyer responsible for confidentiality, competence and verifying every output before relying on it.

Is ChatGPT confidential for lawyers?

Not by default on consumer plans. ChatGPT Free, Plus and Pro use conversations to improve OpenAI's models unless the "Improve the model for everyone" setting is turned off. Business, Enterprise and API tiers do not train on content by default. Separately, an AI conversation is not a privileged communication with your client, and Canadian courts have not settled whether sending privileged material through a third-party tool risks waiver, so treat every prompt as a record that could be produced.

Does the Law Society of Ontario require me to tell clients I use AI?

Not as a blanket rule. The LSO's April 2024 white paper lists four factors that point toward disclosure: a court or public disclosure requirement, the client's expectations about who does the work, whether the client's personal or proprietary information is being input, and reputational risk to the client. If any of those applies, disclose in the retainer or in writing.

Do Canadian courts require lawyers to disclose AI use?

Some do. The Federal Court requires a declaration in the first paragraph of any filed document containing AI-generated content. Courts in Manitoba, Yukon and, in some contexts, Nova Scotia require disclosure. British Columbia and Alberta courts recommend it. Ontario and Quebec courts do not require it. Check the practice direction for the specific court before filing.

Has a Canadian lawyer been sanctioned for AI-generated fake cases?

Yes. In Zhang v. Chen, 2024 BCSC 285, counsel who filed two ChatGPT-invented cases was ordered to pay costs personally. In Ko v. Li, 2025 ONSC 2766 and 2025 ONSC 2965, a Toronto lawyer who filed a factum with non-existent cases faced a contempt show-cause and was required to complete at least six hours of ethics and AI training, forgo her fee for the work, and adopt verification protocols.

Does PIPEDA apply to client information I put into an AI tool?

Yes. Client and third-party personal information in your files is covered by PIPEDA, and you remain accountable when a vendor processes it on your behalf, including outside Canada. You need a comparable level of protection by contract and transparency with the individual about cross-border processing. In Quebec, Law 25 also requires a privacy impact assessment before personal information is communicated outside the province.

Is there mandatory AI training for lawyers in Canada?

In Quebec, yes. Since April 1, 2026, every member of the Barreau du Québec must complete a two-hour online course, Encadrer l'IA générative dans la pratique du droit, by April 1, 2027. Other law societies have published guidance and playbooks but have not yet made AI training mandatory.

What should a law firm AI policy include?

At minimum: which tools are approved and on which plan or contract, a rule that no client-identifying or privileged information goes into a tool without confirmed no-training terms, where each tool stores and processes data, a verification step that every cited authority is opened on CanLII, who reviews AI-assisted work, how AI use is disclosed to clients and courts where required, and how the policy is trained and updated. The Law Society of Alberta's model Generative AI Use Policy is a sound starting template.

Sources

This post is general information about professional obligations, not legal advice, and it reflects the guidance published as of its date. Check your own law society's current material and the practice direction of any court you file in.