Canadian businesses are moving quickly to put artificial intelligence to work, but many may be adopting the technology faster than the policies and safeguards needed to govern it.
That’s one of the clearest takeaways from a new State of AI 2026 report from Prelia, a national business law firm that adopted its new name in late 2025. The report is based on responses from 121 organizations that includes startups, growth companies, and mid-market businesses.
AI Delivers Measurable Productivity Gains
Among respondents, 76% reported approved AI use or pilots within their organizations. The technology is also producing meaningful reported efficiencies: 30% estimated AI saves an average of at least four hours per week for each employee using it, while 68% estimated savings of at least one hour weekly.
For Michael Ginevsky, a Prelia partner who led the research project alongside lawyer Thomas Heine, the time savings were among the findings that stood out most.
“The four-hour number is significant,” Ginevsky said. “If you have 10 people each saving four hours, that adds up to another full-time employee’s working week. For a growing business, that could mean being able to take on more work with the team it already has. We have been talking about Canada’s productivity problem for years. If businesses can put that extra time to good use, the impact could be substantial.”
The scale of the reported savings suggests companies may increasingly need to determine how that AI-created capacity is used — whether that means producing more work, shifting employees toward higher-value responsibilities, or enhancing customer service practices.
Governance Is Struggling to Keep Pace
But Prelia’s research also points to a gap between AI adoption and how companies are managing it.
Just 33% of respondents reported having a written policy covering AI. Among organizations with fewer than 50 employees, that figure dropped to 9%, compared with 60% at organizations with 50 or more employees.
Other safeguards remain far from universal. Thirty-six percent reported rules governing confidential information shared with AI, 25% had rules concerning personal information, and just 14% identified employee training among the AI governance measures already in place.
The report also found 41% of respondents said employees share confidential business information or other potentially sensitive information with AI tools. Among that group, 46% reported no clear rules governing what employees can share.
“What really stood out to me from a legal perspective was how many organizations are using AI without a written policy or guidance,” Ginevsky said. “Someone might upload a confidential business plan just to get help with the wording. Depending on the tool and account settings, that information could be used to train future AI models and potentially show up in responses to someone else. The employee is just trying to do their job, but they may be sharing information the business would never want to get out. People need clear guidance on which tools they can use and what they can put into them.”
A Growing Role for Business Lawyers
That issue is becoming increasingly relevant for business lawyers as employees experiment with a widening selection of AI platforms, including tools accessed through individual accounts rather than centrally approved enterprise systems.
Among respondents whose organizations use enterprise or centrally managed AI subscriptions, 45% also reported use of free tools or paid individual subscriptions.
“Providing employees with company accounts is a good start, but it doesn’t solve the problem on its own,” Heine added. “Businesses also need to establish clear rules on whether free tools or personal subscriptions may be used for work and, if so, what types of information may be entered into them. Without that guidance, a business has little visibility into, or control over, what company information is being shared through these tools.”
When proprietary business information, client material, personal information, or intellectual property is entered into an AI platform, companies need to understand how that information is handled and what contractual, privacy, and confidentiality protections apply. Yet just 23% of respondents said their organization considers whether a vendor uses its data to train or improve AI when reviewing AI tools or vendors.
Businesses Know They Need to Catch Up
The findings suggest businesses recognize there is work to do. More than half of respondents selected an AI policy, employee training, or both among their organization’s top three priorities for managing AI during the coming year.
For Prelia, the survey also represents a different way for a law firm to approach the AI conversation with clients. Rather than looking solely at how lawyers themselves are adopting the technology, the research examines how AI is being used inside the businesses that lawyers advise — and where those clients may require new policies, contracts, and governance practices.
The voluntary survey was conducted in August and September of this year through Prelia’s client and professional network. Because respondents were not randomly selected, Prelia notes the findings describe participating organizations rather than Canadian businesses as a whole.
Still, the direction is clear: AI experimentation is rapidly becoming everyday business for companies. The legal and governance frameworks surrounding that use are now racing to catch up.

