How to write an AI policy for your nonprofit
Your team is probably using AI already. A short policy makes sure everyone uses it the same safe way. Here is what to put in it, what the law says in Canada, and how to write yours in one meeting.
An AI policy is a short set of rules your team agrees on before using AI. For a Canadian nonprofit, it should answer six questions: who is in charge, which tools are approved, what information never goes into AI, who checks the work, when you tell people AI helped, and what you do when something goes wrong. Write it together in one meeting, have your board or executive director approve it, and review it every six months.
- 1Why you need one now
- 2What the law says in Canada
- 3The six questions
- 4Write it in one meeting
- 5Keep it working
- 6Questions people ask
Why your nonprofit needs one now
AI is already part of nonprofit work in Canada. Most organizations just haven't written down the rules.
Source: Imagine Canada and CCNDR, The State of AI Adoption in Canadian Nonprofits, January 2026. 963 organizations surveyed.
A policy doesn't stop your team from using AI. It gives them clear rules, so they can use it without guessing. It also gives your board, funders and the people you serve something to point to when they ask, "How do you use AI?"
What the law says in Canada
Canada does not have an AI law for nonprofits yet. That doesn't mean anything goes. The laws you already follow still apply when AI is involved.
- Privacy. Which privacy law covers you depends on your province and your work. British Columbia and Quebec have privacy laws that cover nonprofits. In most other provinces, the federal law (PIPEDA) applies mainly to commercial activities, like selling a donor list. Health information may fall under a separate health privacy law.
- Quebec. Quebec's Law 25 also says you must tell a person when a decision about them is made only by automated processing.
- Human rights and employment. You can't use a tool that treats people unfairly, whether a person or a program made the choice.
- Indigenous data. If you hold information about First Nations, Inuit or Métis people or communities, use it with AI only with the community's agreement. For First Nations data, follow the OCAP® principles.
Even where a law doesn't strictly apply, treat personal information as if it does. The people you serve and your funders expect it.
The six questions your policy must answer
Keep each answer short. Two pages your team actually reads beat twenty pages nobody opens.
1Who is in charge?
Name one AI lead. This person keeps the tool list, answers questions and reviews the policy. Name who approves the policy, usually your executive director or board. Use names or roles, not "the team".
2Which tools are approved?
List every AI tool your team may use. For each one, write down who owns it, where it keeps your data, and whether it uses your data to train its AI. Turn that setting off where you can. If a tool isn't on the list, staff ask the AI lead first.
3What information never goes into AI?
Use a simple traffic light:
- GREENPublic information and drafts with no names. OK in any approved tool.
- YELLOWInternal information, like budgets or grant drafts with no names. Only in approved tools, with training on your data turned off.
- REDAnything about a person: the people you serve, donors, volunteers and staff, plus health, money, housing, immigration and safety details. Never in chat tools or personal accounts.
4Who checks the work?
Write one rule everyone remembers. Ours is:
AI can hold the pen. Only a person signs.
A person checks every fact before anything leaves your organization. And AI never decides who gets help, money or a job. It can sort, summarize and flag. A person makes every decision about a person.
5When do you tell people AI helped?
Be open about it. People trust you more when you tell them. Decide where you'll say so: in email signatures, reports, grant applications and images. A simple line works: "Written with AI assistance. Reviewed by a person."
Also tell the people you serve when AI is part of a service that affects them, and always offer a person instead.
6What happens when something goes wrong?
Mistakes will happen. Decide now what to do: stop using the tool, tell the AI lead the same day, fix the harm, and tell anyone affected quickly. Write down what happened and what you changed, so it doesn't happen twice.
How to write it in one meeting
Our free AI Policy Kit includes everything for this meeting: the policy in two versions, a staff card, a session guide and ten scenario cards.
Keep it working
A policy only helps if people use it. Four habits keep it alive:
- Keep a register. One spreadsheet lists every AI tool and automation, who owns it and how to switch it off.
- Train new people. Walk every new staff member and volunteer through the staff card when they start.
- Report to your board. Ask three questions each quarter: what are we using, what went wrong, and what are we changing?
- Review every six months. AI tools change fast. Update the tool list and the rules, and get the policy approved again.
If AI works inside your systems
Some AI does more than write. It can sort forms, update records or send messages. If your team uses AI this way, add a few more rules:
- Start read-only. The helper can read and draft. It gets more access only when you decide that in writing.
- A person says yes first before it sends, deletes, pays or changes a record.
- Give it its own account, never a staff member's login, so you can shut it off without locking anyone out.
- Every automation has an owner and an off switch, listed in your register.
If your systems aren't connected yet, that's the place to start. AI works best on clean, connected information. See how we connect systems first →
Five common mistakes
- Copying a US template. US policies cite US laws. Yours should reflect Canadian privacy law and your province.
- Banning AI outright. Staff often keep using it on personal accounts, where you have no control at all. Clear rules work better than a ban.
- Writing it alone. A policy written by one person misses how the work really happens. Include the front line.
- No owner. If nobody is named as the AI lead, nobody updates the tool list, and the policy goes stale.
- Forgetting the people you serve. Say how you'll tell them about AI and how they can ask for a person.
Questions people ask
Does Canadian law require a nonprofit to have an AI policy?
No law requires one yet. But privacy, human rights and employment laws still apply when you use AI, and a written policy is the clearest way to show you follow them. Funders and boards are also starting to ask for one.
How long should our AI policy be?
Short enough that people read it. Two to five pages is enough for most nonprofits. Put the most-used rules on a one-page staff card.
Should we ban ChatGPT?
Usually no. Bans tend to push staff toward personal accounts, where you can't see or protect what they share. It's safer to approve the tools you trust, set clear rules on information and check the work.
Do we need a lawyer to write it?
You can write the first version yourselves using a template. Have a lawyer or privacy professional review it before approval, especially if you handle health, children's or other sensitive information.
Who should approve the policy?
Your executive director or board. Many boards approve the policy itself and let the executive director keep the tool list up to date.
Do we have to tell donors when we use AI?
It's a good idea. Openness protects trust. Say where AI helped in reports, appeals and grant applications, and keep a person responsible for everything you send.
Start with the free kit.
The policy in two versions, a staff card, an AI register, a board brief and a one-hour session guide. Plain language, free to use and change.
Get the free kit →Read Nimara's own AI policy
Want help putting it in place? We help nonprofits set their AI rules, train their teams and build AI into everyday work, now or when they're ready. Book a Call →
AI can hold the pen. Only a person signs.
Updated October 2026. This guide is general information, not legal advice. Written with AI assistance. Reviewed by a person.
