Most Canadian charities do not have an AI policy. Many of those that do haven't looked at it in over a year.
Neither situation is safe anymore.
Two years ago, the big question for charity boards was whether staff should be allowed to use ChatGPT. That question already feels outdated. In 2026, the conversation has shifted to AI agents that can take action on a charity's behalf without a person checking every step. That shift raises new legal questions, and most policies haven't caught up.
This article walks through what a solid AI policy should cover for a Canadian charity, why each piece matters, and where the next wave of risk is likely to come from. For a broader look at how AI intersects with charity law generally, see our companion piece on AI and Canadian charities.
An AI policy isn't about restricting staff. It's about giving them clear rules so the charity isn't caught off guard.
Charities across Canada are under real pressure. Staff are stretched thin. Administrative work keeps piling up. Donors expect more, faster.
AI tools genuinely help with this. They can draft newsletters, summarize board reports, transcribe meetings, and respond to routine questions. The productivity gains are real.
But here's the problem: staff using AI without any rules puts the charity at risk. Not because anyone is being careless on purpose. Usually, it's the opposite.
Canada doesn't have AI-specific legislation yet. That doesn't mean AI use is unregulated.
Several existing laws already apply:
An AI policy is how a charity shows it understands all of this.
A mid-sized Canadian charity found out, during an unrelated privacy review, that its volunteer coordinator had been pasting background check results into a free AI tool to summarize them.
The reports contained sensitive personal information about applicants. The AI tool was American-based, and its terms allowed it to train on submitted content. The result was a reportable privacy breach.
The coordinator wasn't being reckless. She was trying to keep up with her workload. Nobody had told her not to do this.
That's the pattern behind almost every AI incident at charities. It's rarely a bad actor. It's usually a well-meaning staff member with no rules to follow.
A good AI policy doesn't need to be long. It needs to address the right things clearly. It fits alongside the other core documents every organization should have — see our list of 10 essential policies for Canadian charities and nonprofits.
Every charity is different in size and AI use. Still, the following elements belong in almost every policy.
The policy needs to name which tools are approved. Free consumer versions? Enterprise accounts with data protections? Something specific, not vague.
It also needs a clear "never" list. This typically includes:
"We follow best practices" is not a policy. "Staff may use Microsoft Copilot under our enterprise licence for the following purposes" is a policy.
This is where most charities are quietly bleeding risk, often without realizing it.
Free versions of many AI tools use whatever gets typed into them to train future models. Pasting donor names, client files, board minutes, or employee information into these tools is, in plain terms, a privacy breach. Canadian privacy regulators addressed this directly in their joint Principles for responsible, trustworthy and privacy-protective generative AI technologies.
Staff need to understand this deeply, not just read it once in a document. Training matters more than the policy text itself.
AI produces a draft. A human signs off on the final version. That's the rule.
"ChatGPT said so" is not a defence for anything. Canadian courts have already sanctioned lawyers for filing AI-generated legal submissions with made-up case citations.
The same logic applies to a fundraising appeal, a CRA filing, or a donor letter. If the output contains errors, the staff member who sent it out owns the result — not the software.
AI carries the biases baked into whatever data trained it. If a charity uses AI to screen volunteers, score grant applications, or triage requests for service, it needs to know whether the results are fair.
The Canadian Human Rights Act and provincial human rights codes apply to discriminatory outcomes no matter how they were produced. Decisions about individual people should never be left to AI alone. The policy should say this outright.
When should a charity tell people that AI was involved? This needs a clear default.
Some funders already require disclosure. Donors are also starting to notice when they're speaking with a machine instead of a person, and many don't like it.
The policy should spell out when disclosure is mandatory, especially for communications with funders, beneficiaries, and the public.
Canadian privacy law requires meaningful consent, a clearly defined purpose, and reasonable safeguards. AI tools complicate every one of these requirements.
The policy should explain what consent is needed before AI touches personal information, particularly information about children, clients, beneficiaries, or members. For the fundamentals of whether and how PIPEDA applies to your organization, see Should Canadian Charities Comply with PIPEDA?
Canadian copyright law is still unsettled on AI-generated content. But the policy can at least confirm two things:
AI-generated images that closely resemble an existing artist's style are a common way this goes wrong by accident.
Encryption, access controls, and authentication still matter, arguably more once AI tools are connected to internal systems. The AI policy doesn't need to reinvent this. It just needs to point back to the charity's broader IT security rules.
This one deserves its own attention. A clumsy, human thank-you letter beats a polished AI-written one almost every time. Donors give to people, not to language models.
The policy should set expectations around tone, personalization, and where AI-assisted writing ends and AI-written writing begins. There's a harder question too: using AI to analyze donor data and recommend fundraising asks. That's not really a communication issue — it's a privacy and fairness issue, and it needs its own guardrails.
AI tools change every few months. A policy written a year ago is probably already behind.
Annual review should be the minimum, not the goal. Staff training needs to be mandatory and refreshed whenever the technology shifts in a meaningful way. A policy nobody has actually read does no work at all.
Most of what's discussed above concerns generative AI — tools that produce content for a person to review. Agentic AI is different, and it's the next challenge headed toward charity boards.
An AI agent doesn't just produce a draft. It takes action.
It can plan out steps, log into other software, send messages, retrieve information, and complete multi-step tasks with very little human involvement. Instead of drafting a donor email for someone to review, an agent might draft it, send it, log the interaction in the CRM, and update the donor's record — all without a person checking in between.
The appeal is obvious. Charities are stretched thin, and agentic AI promises to handle communications, scheduling, and routine record updates so staff can focus on higher-value work.
The risk is just as obvious. The same speed that makes agentic AI useful also makes its mistakes harder to catch.
Here's the core legal concern: a bad output can become a bad input.
A traditional AI tool produces a flawed answer, and a human catches the error before anything happens. An agentic system might produce that same flawed answer, act on it immediately, and use the result as the input for its next step.
An inaccurate summary becomes a misleading email. That becomes an upset donor. That triggers a rushed record update. By the time a person notices, the chain of errors is already several steps deep, and it's harder to unwind.
In Moffatt v. Air Canada, 2024 BCCRT 149, the British Columbia Civil Resolution Tribunal held Air Canada responsible for incorrect information its AI chatbot gave a passenger about bereavement fares.
Air Canada argued the chatbot was essentially a separate entity, responsible for its own statements. The Tribunal disagreed entirely. The company was on the hook for what its AI told the customer.
Apply this logic to a charity. If an AI agent tells a beneficiary they qualify for a service they don't, issues a tax receipt to the wrong person, or sends an inaccurate response to a CRA inquiry, the charity is on the hook. The software provider isn't going to step in and take the blame.
A regular AI tool only collects what a person types into it. An agentic system can go much further — accessing databases, pulling files, and passing information to other services as part of completing a task.
The volume of personal information moving through the system can quickly exceed what the charity actually disclosed in its privacy notice, often without anyone tracking it in real time. PIPEDA's accountability principle requires an organization to know what's happening with personal information under its control. That obligation doesn't pause just because an AI agent is doing the work.
An agent given authority to "handle the booking" could accept terms of service or agree to charges the charity never intended to take on. An agent that gets compromised could disclose sensitive information or approve transactions it should never have touched.
None of this means charities should avoid agentic AI altogether. It means the controls need to be built in before deployment, not added after something goes wrong.
A handful of safeguards belong in every charity's AI policy, whether it covers generative tools, agentic systems, or both.
A few resources are worth bookmarking for ongoing reference.
Building an AI policy from scratch doesn't need to be complicated. Here's a straightforward path forward.
Does my charity need a written AI policy, or is informal guidance enough?
A written policy is strongly recommended. Informal guidance is inconsistent and hard to prove during a privacy review or regulatory inquiry. A written policy shows the board took reasonable steps.
Is using free AI tools like ChatGPT a privacy breach for a Canadian charity?
It can be, especially if personal information is entered into a free tool that uses submissions to train its model. This has already caused reportable breaches at Canadian charities.
Who is legally responsible when an AI chatbot or agent gives a beneficiary wrong information?
The charity is. Canadian tribunals, including in the Moffatt v. Air Canada case, have held organizations responsible for what their AI tools tell the public.
Does Quebec's Law 25 create extra obligations for charities using AI?
Yes. Law 25 applies to any organization collecting personal information from Quebec residents, which includes most national charities, regardless of where the charity is headquartered.
How often should a charity review its AI policy?
At least once a year. Charities actively deploying AI should review every six months, since the technology and legal landscape are both changing quickly.
Is there a Canadian law that specifically regulates AI yet?
Not yet. The proposed Artificial Intelligence and Data Act (AIDA) is still working its way through Parliament. In the meantime, existing laws — privacy, human rights, copyright, and employment law — already apply to AI use.
An AI policy won't make every risk disappear, but it turns an unmanaged risk into a manageable one. If your charity's board hasn't reviewed its AI policy in the past year, or doesn't have one at all, now is the time to close that gap before an agentic AI system or an unclear staff practice creates a problem the board didn't see coming.
B.I.G. Charity Law Group works with Canadian charities and not-for-profits to build AI policies that hold up to real scrutiny, not just templates pulled off the shelf. Whether your board needs a first policy drafted, an existing one reviewed against 2026 risks, or guidance on agentic AI specifically, Dov Goldberg and the team can help tailor a policy to how your organization actually operates.
Schedule a free consultation to talk through your charity's AI policy, or reach out directly at dov.goldberg@charitylawgroup.ca or 416-488-5888. Visit CharityLawGroup.ca to learn more about how the firm supports Canadian charities on governance and compliance matters.
This article is general information, not legal advice. Charities considering AI deployment, or reviewing an existing AI policy, should speak with legal counsel familiar with both the Canadian charity sector and the AI regulatory landscape.
The material provided on this website is for information purposes only.. You should not act or abstain from acting based upon such information without first consulting a Charity Lawyer. We do not warrant the accuracy or completeness of any information on this site. E-mail contact with anyone at B.I.G. Charity Law Group Professional Corporation is not intended to create, and receipt will not constitute, a solicitor-client relationship. Solicitor client relationship will only be created after we have reviewed your case or particulars, decided to accept your case and entered into a written retainer agreement or retainer letter with you.

DOV GOLDBERG, J.D. is a lawyer at B.I.G. Charity Law Group and has dedicated his career exclusively to Charity and Not-for-Profit Law for over a decade. Dov guides charities, foundations, and non-profit organizations through every stage of the registration process, offering practical legal advice with a focus on compliance, governance, and long-term success. Known for his hands-on approach and deep knowledge of CRA requirements, Dov is committed to helping clients build strong, sustainable, and legally sound organizations.