← Back to Insights
AI for Legal

Three Law Societies, No Common Standard: Ontario, Quebec and BC on AI in Practice

Ontario, Quebec and BC regulators have issued different AI guidance for lawyers. A comparison of what each requires and where Canadian AI tools fit.

By Augure Newsroom·
a red background with a line of white circles

The Law Society of Ontario has not issued a formal rule on generative AI use in legal practice. Neither has the Law Society of British Columbia. The Barreau du Québec has gone further than either, publishing practice guidance in 2024 that ties AI tool selection to Law 25 obligations. It is the only one of the three that names a specific privacy statute in its AI guidance.

A lawyer in Toronto, one in Vancouver, and one in Montreal are working from three different documents with three different emphases. A Canadian AI tool that satisfies one jurisdiction's expectations does not automatically clear the others. What follows is a comparison of what each regulator has actually said.

Ontario's Silence

The Law Society of Ontario addresses AI through its existing Rules of Professional Conduct rather than a standalone AI policy. Its guidance, published on the Law Society's website, frames generative AI as falling under the competence obligation in Rule 3.1-2 and the confidentiality obligation in Rule 3.3-1. Lawyers must understand a tool well enough to use it competently, and must not disclose client information to a system that was never vetted for confidentiality.

There is no technology-specific checklist. The Law Society has instead flagged recurring problems drawn from disciplinary and court filings: fabricated case citations produced by generative tools and submitted without verification, and confidential client documents uploaded to consumer-facing AI chat tools with no enterprise data agreement in place. A Toronto lawyer was formally reprimanded in 2024 after filing a factum citing cases that did not exist. That case circulated widely in Canadian legal press and became the reference point most Ontario firms now cite internally when drafting AI use policies.

Two firms can reach opposite conclusions about the same tool and both claim to be compliant. Ontario's principle-based approach gives firms latitude, and latitude cuts both ways. It also means the Law Society has no mechanism to pre-clear a tool. There is no vendor registry, no approved list, nothing a managing partner can check against before rolling out a platform firm-wide. The burden sits entirely on the individual lawyer's judgment at the point of use, which is a harder thing to audit after the fact than a checklist would be, and a harder thing to defend in a complaint if that judgment turns out to have been wrong.

Quebec's Law 25 Changes the Calculus

Quebec is different, and the difference is not stylistic. Law 25, the province's modernized private sector privacy statute in force in full since September 2023, requires a privacy impact assessment before personal information is transferred outside Quebec. That requirement applies whether the transfer happens because a firm changed cloud vendors or because a lawyer pasted a client's contract into a chatbot hosted in another country.

The Barreau du Québec's guidance connects those dots explicitly. Its practice notes on AI tools instruct members to consider where a vendor stores data, whether the vendor's infrastructure sits under a foreign legal regime, and whether the firm has documented an assessment before adopting the tool. This is the most concrete of the three sets of guidance, and it is concrete because Law 25 gave the Barreau a specific statute to point to rather than a general competence duty. A privacy impact assessment is a documented precondition once personal information crosses provincial or national borders, according to the Barreau's published practice guidance on technology use.

What that assessment actually involves is not exotic, but it is not a form a firm fills out once and forgets, either. A Montreal litigation boutique that switched AI vendors this year described the process as three separate documents rather than one: an inventory of what categories of personal information the tool would touch, a mapping of every jurisdiction the data passes through between input and output, and a risk mitigation section explaining what happens if a foreign authority compels access. The firm's privacy lead said the mapping step took longer than expected, because the vendor's own sales materials described infrastructure in general terms and the firm had to go back twice for specifics before it could finish the document. That single detail — a vendor unwilling or unable to say precisely where inference happens — is what several Quebec privacy practitioners say now functions as an informal red flag during procurement, independent of anything the Barreau has published.

Firms operating in Quebec that use a US-hosted AI platform are not automatically offside. They are the ones who need the assessment on file, and that assessment has to grapple honestly with where inference happens and who can compel access to it under foreign law. The CLOUD Act is the recurring concern for anything routed through an American provider. A firm that skips the assessment entirely is the one exposed if the Commission d'accès à l'information ever asks to see it, not the firm that documented a foreign transfer and proceeded anyway with mitigations on file.

BC's Lighter Touch

The Law Society of British Columbia has taken a position closer to Ontario's than Quebec's. Its guidance references the same core obligations: competence, confidentiality, supervision of AI-assisted work product. It does so without a dedicated privacy statute equivalent to Law 25 to anchor it. BC's Personal Information Protection Act covers private sector data generally, but the Law Society's AI-specific commentary does not build the kind of transfer-assessment framework the Barreau has.

BC lawyers get less specific instruction and, correspondingly, more discretion. A firm in Vancouver evaluating a Canadian AI platform against a US alternative is doing so against professional conduct rules that ask whether the lawyer understood and verified the tool's output. There is no statute requiring a paper trail before data crosses a border. A skeptic might ask why that matters if PIPA still applies regardless of what the Law Society says. It does still apply, but PIPA does not require a documented impact assessment as a precondition to a specific transfer the way Law 25 does; it governs collection and use generally and leaves enforcement to complaint-driven investigation after the fact, which is a materially weaker forcing function on procurement decisions made before a tool goes live.

Where a Sovereign Platform Fits

The practical question underneath all three sets of guidance is the same: where does client data go, and who can access it once it is there. A Canadian AI platform can answer that question more directly than a US-headquartered one, because the answer to "who can compel access" changes depending on whose jurisdiction the infrastructure sits in.

Augure, a Toronto-based platform aimed at regulated Canadian organizations including law firms, stores customer data in Canada and runs inference on Canadian infrastructure and with vetted EU partners under zero-data-retention agreements, handling certain model tiers and providing failover capacity. Customer conversations, documents, and AI inference are never handled by US-jurisdiction providers, according to the company. That claim is scoped to customer content. The CLOUD Act's reach over US-controlled providers applies to that content specifically, not to every system a SaaS vendor touches. Augure's own privacy policy discloses limited US processing for payment card networks and email delivery, the same as most SaaS platforms. That is narrower and more defensible than the blanket "data never leaves Canada" language some vendors use.

That distinction is what a Law 25 privacy impact assessment is supposed to surface. A Quebec firm running that assessment on a US-hosted competitor has to document a foreign jurisdiction's legal reach over client data. A firm running the same assessment on a Canadian tool with disclosed EU inference for specific tiers produces a shorter document, and a fuller one, because there is less to explain away and more that the vendor has already put in writing.

Augure's legal-specific product, Augure Legal, adds contract review, NDA triage, and clause extraction aimed at the workflow the Barreau's guidance describes: something a firm can point to when asked how it vetted the tool. Pricing runs from C$149 a month for solo practitioners to C$799 for full platform access with integrations, according to the company's published rates. It is one option among a growing list. Canadian firms are also evaluating homegrown legal research platforms and enterprise deployments of larger foreign models with Canadian data-residency add-ons. None of them turns a Law Society's principle-based rules into a checklist that guarantees compliance on a firm's behalf.

The Gap Regulators Haven't Closed

None of the three law societies has said what happens when a lawyer relies on AI-generated research that turns out to be subtly wrong rather than obviously fabricated. That is the harder case than the fictional-citation scandals that made headlines in 2023 and 2024. Ontario's competence rule covers it in theory. Nobody has tested it in a reported disciplinary decision yet.

There is a narrower version of that gap worth naming directly: none of the three regulators has addressed what happens when the AI tool is correct but the underlying data behind it was mishandled — a document uploaded without client consent to a jurisdiction the client never agreed to, where the resulting research is unimpeachable but the process that produced it was not. Competence rules ask whether the output was good. Confidentiality rules ask whether the input was protected. Neither Ontario's guidance nor BC's addresses the case where both answers point in opposite directions, and only the Barreau's Law 25-anchored framework forces the transfer question to be answered before the work starts rather than after a complaint is filed.

Firms building internal AI policies in 2026 are, in effect, writing the guidance regulators have not gotten around to. The three provinces disagree on how much structure to impose. They agree, without saying so directly, that the lawyer using the tool remains the one accountable for what it produces.

More detail on Augure's data residency architecture and its legal product is at augureai.ca and legal.augureai.ca.

A

About Augure

Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.

Ready to try sovereign AI?

Start free. No credit card required.

Get Started