AI Policy for Canadian Charities: What Your Board Needs to Cover in 2026

Dov Goldberg

Most Canadian charities do not have an AI policy. Many of those that do haven't looked at it in over a year.

Neither situation is safe anymore.

Two years ago, the big question for charity boards was whether staff should be allowed to use ChatGPT. That question already feels outdated. In 2026, the conversation has shifted to AI agents that can take action on a charity's behalf without a person checking every step. That shift raises new legal questions, and most policies haven't caught up.

This article walks through what a solid AI policy should cover for a Canadian charity, why each piece matters, and where the next wave of risk is likely to come from. For a broader look at how AI intersects with charity law generally, see our companion piece on AI and Canadian charities.

Why Canadian Charities Need an AI Policy

An AI policy isn't about restricting staff. It's about giving them clear rules so the charity isn't caught off guard.

Charities across Canada are under real pressure. Staff are stretched thin. Administrative work keeps piling up. Donors expect more, faster.

AI tools genuinely help with this. They can draft newsletters, summarize board reports, transcribe meetings, and respond to routine questions. The productivity gains are real.

But here's the problem: staff using AI without any rules puts the charity at risk. Not because anyone is being careless on purpose. Usually, it's the opposite.

The Legal Frameworks Already in Play

Canada doesn't have AI-specific legislation yet. That doesn't mean AI use is unregulated.

Several existing laws already apply:

  • Privacy law — PIPEDA applies federally. Quebec's Law 25 applies to any organization collecting personal information from Quebec residents, which includes most national charities. Alberta and British Columbia have their own private-sector privacy statutes. See our privacy guide for Canadian charities for a full breakdown.
  • Health privacy law — PHIPA and similar provincial laws add another layer when health information is involved.
  • Human rights law — applies to discriminatory outcomes, whether a human or a machine produced them.
  • Copyright law — applies to AI-generated content that copies someone else's work.
  • Employment law — applies when AI is used in hiring, performance reviews, or termination decisions.
  • CRA rules — apply to fundraising communications and information returns, no matter what tool drafted them.
  • Fiduciary duty — requires the board to oversee operational risk, and AI now falls squarely into that category. Our overview of charity governance best practices covers this duty in more depth.

An AI policy is how a charity shows it understands all of this.

A Real Example: The Volunteer Coordinator

A mid-sized Canadian charity found out, during an unrelated privacy review, that its volunteer coordinator had been pasting background check results into a free AI tool to summarize them.

The reports contained sensitive personal information about applicants. The AI tool was American-based, and its terms allowed it to train on submitted content. The result was a reportable privacy breach.

The coordinator wasn't being reckless. She was trying to keep up with her workload. Nobody had told her not to do this.

That's the pattern behind almost every AI incident at charities. It's rarely a bad actor. It's usually a well-meaning staff member with no rules to follow.

What a Strong Charity AI Policy Should Cover

A good AI policy doesn't need to be long. It needs to address the right things clearly. It fits alongside the other core documents every organization should have — see our list of 10 essential policies for Canadian charities and nonprofits.

Every charity is different in size and AI use. Still, the following elements belong in almost every policy.

Acceptable and Prohibited Use

The policy needs to name which tools are approved. Free consumer versions? Enterprise accounts with data protections? Something specific, not vague.

It also needs a clear "never" list. This typically includes:

  • Decisions about beneficiaries
  • Staff performance reviews
  • Anything resembling legal advice
  • Any process where a biased outcome could break human rights law

"We follow best practices" is not a policy. "Staff may use Microsoft Copilot under our enterprise licence for the following purposes" is a policy.

What Goes Into the Tool

This is where most charities are quietly bleeding risk, often without realizing it.

Free versions of many AI tools use whatever gets typed into them to train future models. Pasting donor names, client files, board minutes, or employee information into these tools is, in plain terms, a privacy breach. Canadian privacy regulators addressed this directly in their joint Principles for responsible, trustworthy and privacy-protective generative AI technologies.

Staff need to understand this deeply, not just read it once in a document. Training matters more than the policy text itself.

Accountability for AI Output

AI produces a draft. A human signs off on the final version. That's the rule.

"ChatGPT said so" is not a defence for anything. Canadian courts have already sanctioned lawyers for filing AI-generated legal submissions with made-up case citations.

The same logic applies to a fundraising appeal, a CRA filing, or a donor letter. If the output contains errors, the staff member who sent it out owns the result — not the software.

Bias and Fairness in Automated Decisions

AI carries the biases baked into whatever data trained it. If a charity uses AI to screen volunteers, score grant applications, or triage requests for service, it needs to know whether the results are fair.

The Canadian Human Rights Act and provincial human rights codes apply to discriminatory outcomes no matter how they were produced. Decisions about individual people should never be left to AI alone. The policy should say this outright.

Transparency and Disclosure

When should a charity tell people that AI was involved? This needs a clear default.

Some funders already require disclosure. Donors are also starting to notice when they're speaking with a machine instead of a person, and many don't like it.

The policy should spell out when disclosure is mandatory, especially for communications with funders, beneficiaries, and the public.

Privacy and Consent

Canadian privacy law requires meaningful consent, a clearly defined purpose, and reasonable safeguards. AI tools complicate every one of these requirements.

The policy should explain what consent is needed before AI touches personal information, particularly information about children, clients, beneficiaries, or members. For the fundamentals of whether and how PIPEDA applies to your organization, see Should Canadian Charities Comply with PIPEDA?

Intellectual Property

Canadian copyright law is still unsettled on AI-generated content. But the policy can at least confirm two things:

  • Work created for the charity belongs to the charity
  • Staff should avoid using AI in ways that copy someone else's protected work

AI-generated images that closely resemble an existing artist's style are a common way this goes wrong by accident.

Cybersecurity

Encryption, access controls, and authentication still matter, arguably more once AI tools are connected to internal systems. The AI policy doesn't need to reinvent this. It just needs to point back to the charity's broader IT security rules.

Fundraising and Donor Communications

This one deserves its own attention. A clumsy, human thank-you letter beats a polished AI-written one almost every time. Donors give to people, not to language models.

The policy should set expectations around tone, personalization, and where AI-assisted writing ends and AI-written writing begins. There's a harder question too: using AI to analyze donor data and recommend fundraising asks. That's not really a communication issue — it's a privacy and fairness issue, and it needs its own guardrails.

Training and Review

AI tools change every few months. A policy written a year ago is probably already behind.

Annual review should be the minimum, not the goal. Staff training needs to be mandatory and refreshed whenever the technology shifts in a meaningful way. A policy nobody has actually read does no work at all.

Agentic AI: The Next Risk Category for Boards

Most of what's discussed above concerns generative AI — tools that produce content for a person to review. Agentic AI is different, and it's the next challenge headed toward charity boards.

What Makes Agentic AI Different

An AI agent doesn't just produce a draft. It takes action.

It can plan out steps, log into other software, send messages, retrieve information, and complete multi-step tasks with very little human involvement. Instead of drafting a donor email for someone to review, an agent might draft it, send it, log the interaction in the CRM, and update the donor's record — all without a person checking in between.

The appeal is obvious. Charities are stretched thin, and agentic AI promises to handle communications, scheduling, and routine record updates so staff can focus on higher-value work.

The risk is just as obvious. The same speed that makes agentic AI useful also makes its mistakes harder to catch.

The Feedback Loop Problem

Here's the core legal concern: a bad output can become a bad input.

A traditional AI tool produces a flawed answer, and a human catches the error before anything happens. An agentic system might produce that same flawed answer, act on it immediately, and use the result as the input for its next step.

An inaccurate summary becomes a misleading email. That becomes an upset donor. That triggers a rushed record update. By the time a person notices, the chain of errors is already several steps deep, and it's harder to unwind.

A Canadian Precedent Worth Knowing

In Moffatt v. Air Canada, 2024 BCCRT 149, the British Columbia Civil Resolution Tribunal held Air Canada responsible for incorrect information its AI chatbot gave a passenger about bereavement fares.

Air Canada argued the chatbot was essentially a separate entity, responsible for its own statements. The Tribunal disagreed entirely. The company was on the hook for what its AI told the customer.

Apply this logic to a charity. If an AI agent tells a beneficiary they qualify for a service they don't, issues a tax receipt to the wrong person, or sends an inaccurate response to a CRA inquiry, the charity is on the hook. The software provider isn't going to step in and take the blame.

An Expanding Privacy Footprint

A regular AI tool only collects what a person types into it. An agentic system can go much further — accessing databases, pulling files, and passing information to other services as part of completing a task.

The volume of personal information moving through the system can quickly exceed what the charity actually disclosed in its privacy notice, often without anyone tracking it in real time. PIPEDA's accountability principle requires an organization to know what's happening with personal information under its control. That obligation doesn't pause just because an AI agent is doing the work.

Contracting and Cybersecurity Risks

An agent given authority to "handle the booking" could accept terms of service or agree to charges the charity never intended to take on. An agent that gets compromised could disclose sensitive information or approve transactions it should never have touched.

None of this means charities should avoid agentic AI altogether. It means the controls need to be built in before deployment, not added after something goes wrong.

Practical Safeguards for Boards

A handful of safeguards belong in every charity's AI policy, whether it covers generative tools, agentic systems, or both.

Safeguard What It Means in Practice
Map use cases Find out where AI is actually being used, restricted, or banned across the organization
Require human checkpoints Any decision involving employment, service eligibility, or legal rights needs real human review — not a rubber stamp
Limit agent autonomy Set clear boundaries: an agent can draft an email but not send it, or identify candidates but not offer interviews
Vet vendors carefully Confirm data use, storage location, and what happens if something goes wrong
Build feedback channels Give staff a way to flag concerns about AI use without fear of discipline
Review the policy annually This area of law is moving fast; a policy from 18 months ago is already outdated
Document everything Keep records of training, vendor assessments, and any incidents — this is what regulators will ask for

Canadian Resources for Charity AI Governance

A few resources are worth bookmarking for ongoing reference.

  • Office of the Privacy Commissioner of Canada (OPC) — publishes guidance on generative AI and how PIPEDA applies to AI systems.
  • Treasury Board of Canada — maintains a directive on automated decision-making. It applies to federal institutions, but it's a useful benchmark for any charity that works with government.
  • Commission d'accès à l'information du Québec — has published guidance on AI under Law 25, relevant to any charity working with Quebec residents.
  • EU AI Act and NIST AI Risk Management Framework — neither is binding in Canada, but both shape what's considered best practice internationally.
  • Sector guidance — Imagine Canada, the CRA's Charities Directorate, and various provincial nonprofit associations have started publishing AI-related guidance, with more expected.

Where to Start: A Practical Checklist

Building an AI policy from scratch doesn't need to be complicated. Here's a straightforward path forward.

  1. Find out what's actually happening. Ask staff and volunteers what AI tools they're using and why. The answer usually surprises the board.
  2. Identify the highest-risk uses first. Anything touching personal information, decisions about people, or public communications goes to the top of the list.
  3. Draft a short policy. Long policies don't get read. It doesn't need to be perfect — it needs to exist.
  4. Train the people who'll use it. The training matters more than the document itself.
  5. Set a review date. Six months out if AI is being actively used, twelve months if not.
  6. Talk to the insurer. Directors and officers policies are starting to ask AI-related questions at renewal.
  7. Talk to legal counsel. A general template gets a charity partway there. A tailored policy is what actually protects it.

Frequently Asked Questions

Does my charity need a written AI policy, or is informal guidance enough? 

A written policy is strongly recommended. Informal guidance is inconsistent and hard to prove during a privacy review or regulatory inquiry. A written policy shows the board took reasonable steps.

Is using free AI tools like ChatGPT a privacy breach for a Canadian charity? 

It can be, especially if personal information is entered into a free tool that uses submissions to train its model. This has already caused reportable breaches at Canadian charities.

Who is legally responsible when an AI chatbot or agent gives a beneficiary wrong information? 

The charity is. Canadian tribunals, including in the Moffatt v. Air Canada case, have held organizations responsible for what their AI tools tell the public.

Does Quebec's Law 25 create extra obligations for charities using AI?

Yes. Law 25 applies to any organization collecting personal information from Quebec residents, which includes most national charities, regardless of where the charity is headquartered.

How often should a charity review its AI policy? 

At least once a year. Charities actively deploying AI should review every six months, since the technology and legal landscape are both changing quickly.

Is there a Canadian law that specifically regulates AI yet? 

Not yet. The proposed Artificial Intelligence and Data Act (AIDA) is still working its way through Parliament. In the meantime, existing laws — privacy, human rights, copyright, and employment law — already apply to AI use.

Final Thoughts

An AI policy won't make every risk disappear, but it turns an unmanaged risk into a manageable one. If your charity's board hasn't reviewed its AI policy in the past year, or doesn't have one at all, now is the time to close that gap before an agentic AI system or an unclear staff practice creates a problem the board didn't see coming.

B.I.G. Charity Law Group works with Canadian charities and not-for-profits to build AI policies that hold up to real scrutiny, not just templates pulled off the shelf. Whether your board needs a first policy drafted, an existing one reviewed against 2026 risks, or guidance on agentic AI specifically, Dov Goldberg and the team can help tailor a policy to how your organization actually operates.

Schedule a free consultation to talk through your charity's AI policy, or reach out directly at dov.goldberg@charitylawgroup.ca or 416-488-5888. Visit CharityLawGroup.ca to learn more about how the firm supports Canadian charities on governance and compliance matters.

This article is general information, not legal advice. Charities considering AI deployment, or reviewing an existing AI policy, should speak with legal counsel familiar with both the Canadian charity sector and the AI regulatory landscape.

The material provided on this website is for information purposes only. It is not intended to be legal advice. You should not act or abstain from acting based upon such information without first consulting a Charity Lawyer. We do not warrant the accuracy or completeness of any information on this site. E-mail contact with anyone at B.I.G. Charity Law Group Professional Corporation is not intended to create, and receipt will not constitute, a solicitor-client relationship. Solicitor client relationship will only be created after we have reviewed your case or particulars, decided to accept your case and entered into a written retainer agreement or retainer letter with you.

DOV GOLDBERG, J.D.

DOV GOLDBERG, J.D. is a lawyer at B.I.G. Charity Law Group and has dedicated his career exclusively to Charity and Not-for-Profit Law for over a decade. Dov guides charities, foundations, and non-profit organizations through every stage of the registration process, offering practical legal advice with a focus on compliance, governance, and long-term success. Known for his hands-on approach and deep knowledge of CRA requirements, Dov is committed to helping clients build strong, sustainable, and legally sound organizations.