You are probably already using AI on customer data, and Law 25 already applies
The conversation about Law 25 and AI is usually framed around a decision a business has not yet made: should we build something. That framing is comfortable and increasingly wrong. Most Québec businesses are already processing personal information with AI, in tools they bought for other reasons, through features that arrived in an update nobody read. The obligations attached to that are live now, not at the point you start a project.
This is a guide, not legal advice
Written for operators, by people who build these systems. It is not legal advice and it is not a substitute for your own counsel or your privacy officer. What it is, is a list of the places this has usually already happened, so you can go and look.
The full treatment of what the law requires is in the Law 25 and AI guide, with a French version at Loi 25 et IA. This post covers the narrower and more urgent question: what is already running.
Why nobody noticed
Because it did not arrive as a decision. It arrived as a feature.
Software you already pay for shipped an update. A summarise button appeared. Suggested replies turned up in the inbox. The scheduling tool started transcribing calls. None of that came through procurement, none of it got a privacy assessment, and in most cases the default was on.
Where it has usually already happened
Go through this list against your own stack. Most businesses find between three and six.
| Tool category | What the AI feature usually does | The question to answer |
|---|---|---|
| CRM and sales tools | Summarises contact history, drafts follow-up emails, scores or ranks leads | Lead scoring is the sharp one. If a score influences how a person is treated, you are in the territory of automated decision making and the disclosure obligations that come with it. |
| Shared inbox and helpdesk | Suggested replies, sentiment tagging, auto-categorisation of tickets | Customer messages are personal information. Where do they go to be processed, and is that outside Québec? |
| Meeting and call tools | Automatic transcription, summaries, action items | Everyone on the call is a person whose voice is being recorded and processed. Were they told? Consent for recording and consent for AI processing are not the same question. |
| Website chat | The widget answers visitors using a model | What is retained from those conversations, for how long, and what does the visitor get told before they type? |
| Marketing platforms | Segment building, send-time optimisation, subject line generation | Segmentation on inferred characteristics is a different activity from segmentation on what someone told you. |
| Scheduling and booking | No-show prediction, reminder wording, slot recommendations | A prediction that changes whether someone gets a booking is a decision about a person. |
| Accounting and document tools | Reads invoices, statements and receipts, extracts fields | Those documents contain other people's personal information as well as your own business data. |
| Recruitment and HR | CV screening, ranking, interview summarisation | The most sensitive category on this list, and the one where an automated decision is easiest to make without meaning to. |
The four questions to ask about each one
Same four for every tool, and none of them require a lawyer to gather. This is an inventory exercise, and the inventory is the part that is missing in almost every business we look at.
- Is personal information involved? Names, contact details, message content, voice, anything about an identifiable person. This is broader than most people assume, and free-text message content is the most commonly overlooked.
- Where is it processed, and by whom? Which sub-processor, in which country. Your vendor's documentation says this, and it is often the first time anyone has looked.
- What is retained, and for how long? Including whether your content can be used to improve the vendor's models, which is a setting in many tools and not always off.
- Does it produce a decision about a person? A score, a ranking, a prediction, an eligibility flag. If it does, and if that decision is used, the transparency obligations engage.
The one that catches people out
Automated decision making is the provision that surprises businesses, because they do not think of themselves as making automated decisions.
You do not need to have built a decision engine. If a tool produces a score, a ranking or a prediction about a person, and somebody acts on it, that is a decision made with automated processing. Law 25 attaches obligations to informing the person and to their ability to submit observations.
- Lead scoring that determines who gets called back first.
- No-show prediction that determines who gets asked for a deposit.
- CV screening that determines whose application a human ever reads.
- Risk or eligibility flags of any kind, in any sector.
A weekend's worth of work
This is genuinely smaller than it sounds. The first pass is an afternoon and it produces something you did not have, which is a list.
- List every tool that touches customer or employee information. Include the ones one person uses on their own initiative. Especially those.
- For each, find the AI features and whether they are on. Check the settings rather than the marketing page. Defaults have changed more than once.
- Read the sub-processor list for the ones that are on. Vendors publish these and they are more informative than the privacy policy.
- Turn off what nobody uses. The fastest compliance win available, and there is always something.
- Write down what is left, with where it is processed, what is retained and whether it produces a decision about a person.
- Take the list to whoever owns privacy in your business. That is the point at which this becomes a legal question rather than an inventory question.
What this is not
Not an argument that these tools are unsafe or should be switched off. Most are fine, most vendors take this seriously, and several offer configurations that resolve the issue entirely once someone goes and sets them.
The point is narrower. The obligations do not begin when you start an AI project. They began when the feature was switched on, which for most businesses was some months ago, decided by nobody in particular.
If you are about to build something
Everything above is about tools you already have. If you are planning to build, the decisions get made deliberately and in advance, which is considerably easier than discovering them afterwards.
The Law 25 and AI guide covers what has to be settled before anything is connected. The related obligations for software and client communications in French are in the Bill 96 guide. And if you are in a sector where this is the stated reason for not having automated anything yet, that is exactly the situation the financial and insurance page is written for.