Free guide · Canada edition

How to write an AI policy for your nonprofit

Your team is probably using AI already. A short policy makes sure everyone uses it the same safe way. Here is what to put in it, what the law says in Canada, and how to write yours in one meeting.

The short answer

An AI policy is a short set of rules your team agrees on before using AI. For a Canadian nonprofit, it should answer six questions: who is in charge, which tools are approved, what information never goes into AI, who checks the work, when you tell people AI helped, and what you do when something goes wrong. Write it together in one meeting, have your board or executive director approve it, and review it every six months.

Get the free AI Policy Kit →

Why your nonprofit needs one now

AI is already part of nonprofit work in Canada. Most organizations just haven't written down the rules.

80%Up to 80% of Canadian nonprofits used AI for at least one task in 2025
10%had a formal AI policy
64%of those using AI had no policy and weren't writing one
5%of nonprofits under $500K in revenue had a policy

Source: Imagine Canada and CCNDR, The State of AI Adoption in Canadian Nonprofits, January 2026. 963 organizations surveyed.

A policy doesn't stop your team from using AI. It gives them clear rules, so they can use it without guessing. It also gives your board, funders and the people you serve something to point to when they ask, "How do you use AI?"

What the law says in Canada

Canada does not have an AI law for nonprofits yet. That doesn't mean anything goes. The laws you already follow still apply when AI is involved.

  • Privacy. Which privacy law covers you depends on your province and your work. British Columbia and Quebec have privacy laws that cover nonprofits. In most other provinces, the federal law (PIPEDA) applies mainly to commercial activities, like selling a donor list. Health information may fall under a separate health privacy law.
  • Quebec. Quebec's Law 25 also says you must tell a person when a decision about them is made only by automated processing.
  • Human rights and employment. You can't use a tool that treats people unfairly, whether a person or a program made the choice.
  • Indigenous data. If you hold information about First Nations, Inuit or Métis people or communities, use it with AI only with the community's agreement. For First Nations data, follow the OCAP® principles.

Even where a law doesn't strictly apply, treat personal information as if it does. The people you serve and your funders expect it.

This guide is not legal advice. Have a lawyer or privacy professional review your final policy, especially if you handle health or children's information.

The six questions your policy must answer

Keep each answer short. Two pages your team actually reads beat twenty pages nobody opens.

1Who is in charge?

Name one AI lead. This person keeps the tool list, answers questions and reviews the policy. Name who approves the policy, usually your executive director or board. Use names or roles, not "the team".

2Which tools are approved?

List every AI tool your team may use. For each one, write down who owns it, where it keeps your data, and whether it uses your data to train its AI. Turn that setting off where you can. If a tool isn't on the list, staff ask the AI lead first.

3What information never goes into AI?

Use a simple traffic light:

  • GREENPublic information and drafts with no names. OK in any approved tool.
  • YELLOWInternal information, like budgets or grant drafts with no names. Only in approved tools, with training on your data turned off.
  • REDAnything about a person: the people you serve, donors, volunteers and staff, plus health, money, housing, immigration and safety details. Never in chat tools or personal accounts.

4Who checks the work?

Write one rule everyone remembers. Ours is:

AI can hold the pen. Only a person signs.

A person checks every fact before anything leaves your organization. And AI never decides who gets help, money or a job. It can sort, summarize and flag. A person makes every decision about a person.

5When do you tell people AI helped?

Be open about it. People trust you more when you tell them. Decide where you'll say so: in email signatures, reports, grant applications and images. A simple line works: "Written with AI assistance. Reviewed by a person."

Also tell the people you serve when AI is part of a service that affects them, and always offer a person instead.

6What happens when something goes wrong?

Mistakes will happen. Decide now what to do: stop using the tool, tell the AI lead the same day, fix the harm, and tell anyone affected quickly. Write down what happened and what you changed, so it doesn't happen twice.

How to write it in one meeting

BeforeYour AI lead fills in the easy blanks: your name, your tools and who to contact. Ask staff, without blame, which AI tools they already use. You need the real list.
The meetingInvite two to five people, including someone from the front line. Name the worries out loud. Work through the six questions, then test them on a few real situations from your work.
AfterYour executive director or board approves it. Everyone signs that they've read it. Give staff a one-page card with the traffic light and the AI lead's name.

Our free AI Policy Kit includes everything for this meeting: the policy in two versions, a staff card, a session guide and ten scenario cards.

Keep it working

A policy only helps if people use it. Four habits keep it alive:

  • Keep a register. One spreadsheet lists every AI tool and automation, who owns it and how to switch it off.
  • Train new people. Walk every new staff member and volunteer through the staff card when they start.
  • Report to your board. Ask three questions each quarter: what are we using, what went wrong, and what are we changing?
  • Review every six months. AI tools change fast. Update the tool list and the rules, and get the policy approved again.

If AI works inside your systems

Some AI does more than write. It can sort forms, update records or send messages. If your team uses AI this way, add a few more rules:

  • Start read-only. The helper can read and draft. It gets more access only when you decide that in writing.
  • A person says yes first before it sends, deletes, pays or changes a record.
  • Give it its own account, never a staff member's login, so you can shut it off without locking anyone out.
  • Every automation has an owner and an off switch, listed in your register.

If your systems aren't connected yet, that's the place to start. AI works best on clean, connected information. See how we connect systems first →

Five common mistakes

  1. Copying a US template. US policies cite US laws. Yours should reflect Canadian privacy law and your province.
  2. Banning AI outright. Staff often keep using it on personal accounts, where you have no control at all. Clear rules work better than a ban.
  3. Writing it alone. A policy written by one person misses how the work really happens. Include the front line.
  4. No owner. If nobody is named as the AI lead, nobody updates the tool list, and the policy goes stale.
  5. Forgetting the people you serve. Say how you'll tell them about AI and how they can ask for a person.

Questions people ask

Does Canadian law require a nonprofit to have an AI policy?

No law requires one yet. But privacy, human rights and employment laws still apply when you use AI, and a written policy is the clearest way to show you follow them. Funders and boards are also starting to ask for one.

How long should our AI policy be?

Short enough that people read it. Two to five pages is enough for most nonprofits. Put the most-used rules on a one-page staff card.

Should we ban ChatGPT?

Usually no. Bans tend to push staff toward personal accounts, where you can't see or protect what they share. It's safer to approve the tools you trust, set clear rules on information and check the work.

Do we need a lawyer to write it?

You can write the first version yourselves using a template. Have a lawyer or privacy professional review it before approval, especially if you handle health, children's or other sensitive information.

Who should approve the policy?

Your executive director or board. Many boards approve the policy itself and let the executive director keep the tool list up to date.

Do we have to tell donors when we use AI?

It's a good idea. Openness protects trust. Say where AI helped in reports, appeals and grant applications, and keep a person responsible for everything you send.

Free AI Policy Kit

Start with the free kit.

The policy in two versions, a staff card, an AI register, a board brief and a one-hour session guide. Plain language, free to use and change.

Get the free kit →Read Nimara's own AI policy

Want help putting it in place? We help nonprofits set their AI rules, train their teams and build AI into everyday work, now or when they're ready. Book a Call →

AI can hold the pen. Only a person signs.

Updated October 2026. This guide is general information, not legal advice. Written with AI assistance. Reviewed by a person.