Your Employees Are Already Using AI. Can You Prove It?
As of August 26, 2026, the session endpoints of Anthropic's Compliance API have exited beta: an organization can now programmatically retrieve the Cowork and Claude Code work sessions of its members, with coverage extending to Claude Science and Claude for Microsoft 365 (Excel, PowerPoint, Word, Outlook) sessions. In other words: AI use inside your organization just became auditable. This is no longer a question of tooling. It is a question of governance, and Law 25 was already asking it.
Why This Technical Announcement Is a Leadership Question
Until now, most Quebec SMB leaders lived with the same grey zone: AI was being used in the organization, often well, sometimes with personal information, and nobody could say who, when, or on what data. A log you cannot keep is not a log.
The August 26, 2026 release note changes the nature of the problem. What the platform did not expose before, it now exposes in a structured way. The obstacle is no longer technical; it becomes a governance decision you are in a position to make.
A second dated fact, from August 27, 2026: the Anthropic console now distinguishes personal keys (personal keys) from service account keys (service account keys). It sounds minor. It is actually the end of a classic SMB failure mode: a single API key, created under one employee's name, running every automation in the company. The day that person leaves, the organization learns two things at once: that the key existed, and that it just broke everything.
What Does Law 25 Actually Require Here?
Two obligations apply directly to AI use:
- Traceability of processing activities. You must know which personal information is flowing, where, and through what means. An AI tool used without a usage log is a processing activity you cannot document, and therefore cannot defend.
- Automated decisions (s. 12.1). Specific obligations apply when a decision is based exclusively on automated processing, without meaningful human intervention. The practical implication is often misread: compliance does not mean banning AI. It means being able to demonstrate where a human is still deciding.
In both cases, the expected deliverable is the same: proof. And proof comes from a log, not from memory. (Article reference for the governance policy obligation: [to be confirmed before publication].)
Concretely, Where Do You Start?
Order matters. We apply the CAPE methodology:
- Conceive: inventory the actual AI use in the organization (who, which tools, which data) before choosing anything. Most surprises surface at this step.
- Activate: separate personal keys from service account keys, and attach every automation to a named service account, never to an employee.
- Propel: connect the session export to your processing register, so that proof is produced automatically rather than on demand.
- Evolve: revisit the policy when the platform changes. It does change: both facts in this article are three weeks old.
The Detail Nobody Notices, and Why It Matters to You
While verifying these facts, we found that docs.anthropic.com/en/release-notes/api now returns a 301 Moved Permanently to platform.claude.com/docs/en/release-notes/api, and the page is now titled "Claude Platform release notes."
This is a lesson in documentation governance: if your internal AI use policy cites documentation URLs, those URLs age. A policy that points to a page that has moved is a policy an auditor cannot follow.
FAQ
Does Law 25 apply to my SMB if I only have 8 employees? Yes. The law sets no employee threshold: it applies to any organization that collects, holds, or uses personal information in Quebec.
Is session auditability available on any subscription tier? No, access to the Compliance API depends on the subscription tier. [to be confirmed before publication: Team / Enterprise]
How long do sessions remain retrievable? [to be confirmed before publication: retention duration is not stated here due to lack of a verified primary source.]
Should AI be banned while waiting for a policy to be put in place? This is generally the worst of both worlds: use continues without oversight. It is more effective to govern actual use than to ban use you are not measuring.
Is Claude for Microsoft 365 available to Canadian organizations? Availability and data residency: [to be confirmed before publication].
Next Step
If you cannot answer today's question, "who used AI in our organization this week, and on what data," this is the right time to run the inventory. It is the first step of CAPE, and it takes one meeting.
Sources Cited
- Claude Platform release notes, Anthropic: entry of August 26, 2026 (Compliance API session endpoints out of beta; Cowork, Claude Code; addition of Claude Science and Claude for Microsoft 365: Excel, PowerPoint, Word, Outlook).
https://platform.claude.com/docs/en/release-notes/api, accessed 2026-09-14. - Claude Platform release notes, Anthropic: entry of August 27, 2026 (personal keys and service account keys in the console). Same page, accessed 2026-09-14.
- Redirect verified on 2026-09-14:
docs.anthropic.com/en/release-notes/api→301 Moved Permanently→platform.claude.com/docs/en/release-notes/api. - Law 25 (Quebec): s. 12.1, decision based exclusively on automated processing. (Article reference to be confirmed against the official source before publication; governance policy obligation: [to be confirmed].)
LinkedIn Version (ProspèrIA)
Can you name, today, who used AI in your organization this week, and on what data?
For two years, the honest answer from virtually every SMB was "no, and we have no way of knowing." That was true. It no longer is.
On August 26, 2026, Anthropic moved the session endpoints of its Compliance API out of beta: an organization's Cowork and Claude Code sessions become programmatically retrievable, with coverage extending to Claude for Microsoft 365 (Excel, PowerPoint, Word, Outlook). The following day, the console finally separated personal keys from service account keys.
Two technical release notes. One leadership consequence: AI use inside your organization just became demonstrable.
This matters because Law 25 does not ask you to ban AI. It asks you to document your processing activities, and to demonstrate where a human is still making the call. Proof comes from a log, not from memory.
The first move is not buying a tool. It is the inventory: who, which tools, which data. One meeting is enough to do it.
Sources: Claude platform release notes, August 26 and 27, 2026 (accessed September 14, 2026).