The Next Laptop You Buy Ships With AI Already On It
Sarvam AI just landed its assistant pre-installed across HP laptops in India. On its own that is a regional business story. As an instance of a pattern, it is the thing your AI policy is least prepared for. Assistants are moving from something a person downloads to something that arrives in the box, switched on, indistinguishable from the operating system. Every AI policy ever written assumes somebody chose a tool. Pre-installed AI skips the choosing entirely, which means it also skips whatever review you had attached to it.
Your controls are pointed at the wrong moment
Almost all AI governance sits at the point of adoption. Which tools are approved. What staff may sign up for. What the policy document says. That design assumes a decision happens, and that the decision is where you can intervene. Pre-installation deletes the decision. There is no signup, no expense line, no request for approval, and yet there is now an assistant on a work machine with some level of access to files, screen content, or what someone types, operating under terms nobody in your business has read. It is shadow AI that came in through procurement rather than around it.
Why this is harder than staff going rogue
The usual shadow-AI problem at least leaves traces. Pre-installed assistants leave none.
| Staff installs a tool | Tool ships pre-installed |
|---|---|
| There is an account and a login | No signup, no signal |
| Often an expense or a request | Included in the hardware price |
| Someone knows they chose it | Looks like part of the operating system |
| Policy has something to say | Policy never contemplated it |
And staff are not doing anything wrong. If a tool comes with the company laptop, assuming it was approved is the reasonable inference. That makes this a different problem from the shadow AI risk most businesses have started worrying about.
Move the check to device setup
The fix is to add a step where one does not currently exist. When a new machine is provisioned, someone looks at what AI assistants are present and enabled, exactly as you would review any other pre-loaded software, and makes a deliberate call on each. That takes minutes per device and closes the gap entirely. Pair it with a purchasing habit: ask what AI comes bundled before you buy, because that is the point at which you have both leverage and a clear answer. It is the same inventory discipline behind knowing how many AI agents you are running, extended to hardware.
Sensitivity decides, not preference
The decision should follow the data, not a blanket rule. A machine used for general office work can reasonably run a helpful built-in assistant. A machine that routinely displays client files, health information, or regulated records deserves a much harder look, because assistants with screen or file access raise exactly the questions we worked through in AI that watches your screen: what is captured, where it goes, and what happens to third-party data that was simply on display. Canadian privacy obligations attach to that information regardless of how it left.
Do not just block everything
Reflexive prohibition is the failure mode here. Many of these assistants are genuinely useful and effectively free with hardware you have already bought, and switching everything off tends to push people onto personal accounts and personal devices, which is a worse outcome that you can no longer observe. Be deliberate instead of restrictive: know what is present, understand its access, exclude the sensitive machines, and tell your team plainly which tools are sanctioned and which are not. That clarity is most of what an AI policy is actually for, and it is the part most policies now need updating to cover.
Frequently Asked Questions
What is actually happening?
AI assistants are moving from things you download to things that arrive in the box. Sarvam AI just landed its Kivi assistant pre-installed across HP laptops in India, and that is one instance of a much broader pattern: assistants baked into operating systems, phones, browsers, and office suites by default. The distinction matters because almost every AI policy ever written assumes a person made a choice, evaluated a tool, and installed it. Pre-installed AI skips all three steps. It is simply present the first time someone opens the lid.
Why is this a governance problem?
Because your controls are pointed at the wrong moment. Most businesses govern AI at the point of adoption: which tools are approved, what people may sign up for, what goes in a policy document. Pre-installation removes that moment entirely. Nobody adopted anything, so nobody triggered a review, and yet there is now an assistant on a work machine with some level of access to files, screen content, or keystrokes, governed by terms nobody in your business has read. It is shadow AI that arrived through procurement rather than around it.
Is this really different from staff installing their own tools?
It is worse in one specific way: it is invisible. When someone signs up for an AI tool without asking, at least there is an account, a login, sometimes an expense. Pre-installed assistants generate none of those signals. They are on by default, they look like part of the operating system, and staff reasonably assume that anything shipped with a company laptop has been approved. Nobody is behaving badly. The tool simply entered your environment through a door your policy did not know existed.
What should we actually do?
Four things, none of them heavy. Add an AI check to device setup, so someone looks at what assistants are present and enabled before a machine is handed over, the same way you would check any other pre-loaded software. Decide deliberately which stay on, which get switched off, and which are acceptable only on lower-sensitivity machines. Tell staff what is enabled and what it can see, since they will otherwise assume everything is sanctioned. And ask about bundled AI at purchase, because that is when you have leverage and clarity.
Should we just turn it all off?
Usually not, and reflexive blocking backfires. Some of these assistants are genuinely useful, they are free with hardware you already bought, and disabling everything tends to push people toward personal accounts on personal devices, which is a worse outcome you can no longer see. The better posture is deliberate rather than restrictive: know what is there, understand what it can access, keep it off machines that handle sensitive client or regulated data, and be explicit with your team about which is which.
Know what AI came in the box
We help Canadian businesses audit pre-installed AI on their devices, set sensible device-level rules, and update policies written for a world where people chose their tools.
Related Articles
Canadian AI Regulations 2026: AIDA, Bill C-27 & What's Next
AI That Watches Your Screen So You Stop Repeating Yourself
AI Reasoning Traces Leaked Real Passwords and Keys
Ajan leads the ChatGPT.ca team: 200+ custom GPT builds and automation projects for 50+ businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.