top of page

You Don’t Need AI Glasses to Have an AI Glasses Problem

  • Writer: Jim Crocker
    Jim Crocker
  • Jun 25
  • 4 min read


Recently, I posted this blog on AI glasses. It was based on a Threads post where a patient realized partway through an EKG that their doctor was wearing AI-enabled smart glasses. The on-line exchange that followed helped raise a set of helpful consumer questions: How would I know if someone is wearing these? Where does the recording go? Who else can see it? What happens to it after the appointment ends?


There's a different perspective worth taking, and it matters if you sit on a board or run an organization: the governance risk of deploying AI capture tools.


What is the governance risk of deploying AI capture tools?

AI tools being deployed everywhere are capturing client, patient, and employee data. The tools being deployed include AI glasses worn by staff; meeting notetakers like Otter.ai and Fireflies; and, through built-in features like Zoom AI Companion and Microsoft Teams Copilot.


The risk is that a tool can be adopted without anyone confirming what the tool does with the data it collects: where it's stored, who can access it, whether it's used to train AI models, and how long it's retained. That lack of understanding matters because of what happens when something goes wrong:

·         a recording surfaces somewhere it shouldn't

·         A client or patient asks a question nobody on staff can answer

·         A regulator opens an inquiry


It's a serious risk because the way the law sees it, when something does go wrong, accountability sits with the organization that turned the tool on, not the vendor that built it. 


Under Canadian privacy law, the organization collecting personal information is the one with obligations to meet, regardless of which vendor's product did the collecting. A vendor's terms of service won't shield your organization from that. Neither will "we didn't know the feature was on."


Proof that organizations are running this risk

In 2024 an Ontario hospital reported a privacy breach after a former physician's personal AI scribe tool rejoined and recorded a clinical meeting more than a year after he'd left the organization. Nobody had reviewed what would happen to his access when he departed.


In the US, both Otter.ai and Fireflies are facing litigation in testing whether the account holder, not the vendor, bears responsibility for getting consent from everyone in a meeting.


Personally, a trusted service provider I work with sent me an AI-generated recording of a call we'd had. It was created automatically by a feature built into their well-known video platform. When I asked what they knew about how the recording was stored or who had access to it, they didn't know. They easily admitted the feature came bundled with a service they already used, and they had never thought to ask about it.


How Canadian laws apply to AI capture

Canada is a one-party consent country. Under the Criminal Code, anyone who is a participant in a conversation can legally record it without telling the other person. That governs the individual in the moment. It says nothing about what the organization employing them is required to do.


That obligation comes from a separate layer: privacy law that governs organizations, not individual recording itself. PIPEDA governs how businesses collect, use, and disclose personal information, regardless of which tool does the collecting. Provincial health privacy laws, including Ontario's Personal Health Information Protection Act and Alberta's Health Information Act, impose additional, more specific requirements in clinical settings. Ontario's privacy commissioner issued guidance this year requiring healthcare organizations to address privacy and consent before deploying AI listening tools. British Columbia's commissioner went further, requiring patient consent in nearly all clinical situations.


What this means for your organization is straightforward: an employee not having to disclose a recording under criminal law does not mean your organization has met its obligations under privacy law. Those are two different questions, and only one of them is settled by an employee's individual conduct. The other one is yours to answer.


AI Capture Tools Governance

The practical takeaway is that adopting any of these tools is a governance decision, not just a technology decision. It deserves the same scrutiny your organization would apply to any other system that touches client, patient, or employee information.


These are concrete governance steps worth taking

  • Take an inventory of ai-capture tools already in use. Most organizations underestimate how many AI capture tools are active across meetings, client interactions, and clinical encounters, because many arrived as default features rather than deliberate purchases.

  • Assign ownership for the tools. Someone in your organization should be responsible for reviewing a tool's data practices before it's turned on, not after a problem surfaces.

  • Build in a consent step that goes beyond visibility. If a tool is recording or transcribing a meeting, participants should be told what happens to that data, not just that the tool is present.

  • Revisit vendor terms periodically. Privacy policies for these tools change, sometimes significantly, and a review done a year ago may no longer reflect current practice.

  • Question vendors directly about bundling AI features are bundled into an existing platform.


The case for taking action now

Each of these steps closes a specific gap.

1.      The inventory tells you what you're actually exposed to

2.      Assigned ownership means someone answers for a tool's data practices

3.      A real consent step reduces liability and reputational exposure

4.      Periodic vendor reviews catch policy changes while you can still act on them

5. Direct questioning eliminates confusion



This kind of oversight is standard practice by Boards in other parts of the organization like finance. It should be be applied to AI.


Acting quickly before there’s a failure is much better than the pain that could result after one.

Comments


bottom of page