[Name of Charity]
Approved by the Board of Directors: [Date]
Next scheduled review: [Date, no later than 12 months from approval]
Policy owner: [Executive Director / designated senior staff member]
This Policy sets out how [Name of Charity] (the "Charity") permits, restricts, and prohibits the use of artificial intelligence ("AI") tools by its directors, officers, employees, volunteers, contractors, and other representatives (collectively, "Personnel").
The Charity recognizes that AI tools can support its mission by improving productivity, reducing administrative burden, and freeing Personnel to focus on higher-value work. The Charity also recognizes that AI tools introduce legal, ethical, operational, and reputational risks that must be actively managed. This Policy is intended to allow the Charity to capture the benefits of AI while managing those risks in a manner consistent with its legal obligations and its duty to the individuals it serves.
This Policy applies to all Personnel and to all use of AI tools in connection with the Charity's operations, whether the tools are:
(a) provided by the Charity;
(b) accessed through Personnel's own accounts or devices in the course of Charity work; or
(c) embedded within third-party software the Charity uses.
This Policy applies to both generative AI (tools that produce content, summaries, translations, images, audio, code, or similar outputs) and agentic AI (tools that take autonomous action across systems, sometimes referred to as "AI agents"). It applies regardless of whether the AI tool is free, paid, standalone, or integrated into other software the Charity already licenses.
This Policy operates alongside the Charity's Privacy Policy, Acceptable Use of Technology Policy, Records Retention Policy, Code of Conduct, Confidentiality Policy, and other governance documents. In the event of a conflict, the more restrictive provision applies.
"AI tool" means any software, service, or system that uses machine learning, large language models, generative models, or similar techniques to produce content, analyze data, make recommendations, or take action.
"Generative AI" means an AI tool that produces content (text, images, audio, video, code, or similar outputs) in response to prompts or instructions.
"Agentic AI" or "AI agent" means an AI tool that can plan and execute multi-step tasks with a degree of autonomy, including accessing other software, retrieving or transmitting information, making decisions, or taking action on behalf of a user, without requiring human confirmation at each step.
"Personal information" has the meaning given in the Personal Information Protection and Electronic Documents Act (Canada) and applicable provincial privacy legislation, including Quebec's Act respecting the protection of personal information in the private sector (Law 25), as amended from time to time.
"Confidential information" includes personal information, donor information, beneficiary information, employee information, volunteer information, financial information, strategic information, information subject to solicitor-client privilege, information covered by a duty of confidence, and any other information the Charity has an obligation to protect.
"High-risk use" is defined in Section 8.
The Charity's use of AI is guided by the following principles:
(a) Human accountability. AI tools support human decision-making. They do not replace it. A Personnel member who uses an AI tool is responsible for the output.
(b) Privacy by default. Confidential information must not be exposed to AI tools that do not offer appropriate legal, contractual, and technical protections.
(c) Legal compliance. AI use must comply with applicable Canadian federal and provincial law, including privacy, human rights, intellectual property, employment, and charity law.
(d) Fairness. AI tools must not be used in ways that produce discriminatory outcomes prohibited by the Canadian Human Rights Act or applicable provincial human rights legislation.
(e) Transparency. The Charity is honest about how and when it uses AI, both internally and in dealings with donors, funders, beneficiaries, and the public.
(f) Proportionality. AI tools are used where the benefit is clear and the risk is understood and controlled. Novelty is not a reason to deploy.
(g) Continuous review. AI technology and the law governing it are evolving. This Policy is a living document.
5.1 Approved tools. Personnel may use only AI tools that have been approved in writing by [the Executive Director / the designated policy owner]. The current list of approved tools is maintained at [location] and updated as tools are added or removed. Approval takes into account, at minimum: data protection commitments in the tool's terms of service, data residency, whether the tool trains on submitted content, the vendor's security posture, and the availability of enterprise or paid tiers with stronger protections.
5.2 Free consumer versions. Free consumer versions of AI tools (including free tiers of otherwise reputable services) generally use submitted content to train future models and offer limited contractual protections. Personnel must not input any Confidential information into a free consumer AI tool, regardless of purpose. Where a free tool has been specifically approved under Section 5.1 for a specific limited use, Personnel must respect the scope of that approval.
5.3 Personal accounts. Personnel must not use personal AI accounts to perform Charity work involving Confidential information, even where the underlying tool is one the Charity has approved for enterprise use.
5.4 Prohibited tools and uses. The following are prohibited without exception:
(a) Any AI tool used to make final decisions about employment (including hiring, discipline, or termination), volunteer eligibility, service eligibility for beneficiaries, or the allocation of benefits or funds.
(b) Any AI tool used to generate content that impersonates a real person, including donors, staff, board members, beneficiaries, or public figures.
(c) Any AI tool used to produce legal advice, medical advice, or other professional advice that will be relied upon by the Charity or a third party.
(d) Any AI tool where the vendor's terms permit the vendor to use submitted Confidential information for purposes other than providing the service, unless expressly overridden by an enterprise agreement.
(e) Any AI tool used to circumvent this Policy, the Charity's other policies, or applicable law.
6.1 General rule. Personnel must not input Confidential information into an AI tool unless: (i) the tool has been approved for that category of information under Section 5.1; (ii) the input is necessary for a legitimate Charity purpose; and (iii) the use complies with the Charity's Privacy Policy and applicable law.
6.2 Personal information. Personal information about donors, beneficiaries, members, employees, volunteers, or other identifiable individuals must not be input into an AI tool unless the tool has been specifically approved for that purpose. Consent requirements under PIPEDA, Quebec's Law 25, and other applicable privacy legislation continue to apply. Personnel must consult the [Privacy Officer / designated staff member] before any new use of personal information with an AI tool.
6.3 Sensitive personal information. Sensitive personal information (including health information, information about children, information about vulnerable individuals, and information subject to sector-specific privacy legislation such as PHIPA in Ontario) requires heightened protection. Personnel must not input sensitive personal information into any AI tool without prior written approval from the [Executive Director / Privacy Officer] and confirmation from legal counsel that the intended use complies with applicable legislation.
6.4 Third-party confidential information. Personnel must not input into any AI tool information the Charity holds under a duty of confidence to a third party (including funders, partner organizations, or clients) without confirmation that the intended use is consistent with that duty.
6.5 Solicitor-client privileged information. Communications with legal counsel, and materials prepared for the purpose of obtaining legal advice, must not be input into any AI tool without the written approval of the [Executive Director] following consultation with counsel. Waiver of privilege through AI use is a real risk and treated accordingly.
7.1 Human review. All AI-generated output that will leave the Charity or influence a decision affecting an individual must be reviewed and approved by a human Personnel member before use. AI output is a draft, not a final product.
7.2 Responsibility for output. The Personnel member who releases, transmits, files, or otherwise uses AI-generated output is responsible for that output, including its accuracy, its compliance with applicable law, and its consistency with the Charity's mission and values. "The AI generated it" is not a defence to inaccuracy, defamation, infringement, breach of privacy, discrimination, or any other consequence.
7.3 Hallucinations and inaccuracy. AI tools regularly produce content that is confidently stated but factually incorrect (commonly called "hallucinations"). Personnel must verify factual claims, citations, references, statistics, quotations, and legal or regulatory statements in AI-generated output before use.
7.4 Content sent externally. AI-assisted content sent to donors, funders, beneficiaries, regulators (including the Canada Revenue Agency), the courts, government, media, or the public must be reviewed by a human Personnel member and, where the content involves legal, financial, or regulatory statements, approved by the appropriate senior Personnel member.
8.1 Definition. A "high-risk use" of AI is one involving:
(a) decisions affecting an individual's employment, volunteer engagement, service eligibility, or receipt of benefits;
(b) communications with regulators (including the CRA), the courts, or law enforcement;
(c) processing of sensitive personal information;
(d) financial transactions, including donations, grants, disbursements, and procurement;
(e) content published to the public or to a wide audience (including websites, social media, press releases, fundraising campaigns, and educational materials);
(f) content addressed to vulnerable individuals; or
(g) any use flagged as high-risk by the [Executive Director / policy owner] on a case-by-case basis.
8.2 Additional requirements. High-risk uses require:
(a) prior written approval from the [Executive Director / policy owner];
(b) documented human review of AI-generated content before release;
(c) a documented rationale for using AI in the specific context; and
(d) recording of the use in the AI use log maintained under Section 12.
8.3 Prohibited high-risk uses. No AI tool may be used to make a final adverse decision about an individual (including denial of employment, denial of services, or termination of a relationship) without meaningful human involvement in the decision.
9.1 Additional caution. Agentic AI tools, which take autonomous action across systems, present risks that go beyond those associated with generative AI. This Section applies in addition to the rest of the Policy whenever an AI agent is used.
9.2 Approval required. No AI agent may be deployed by or on behalf of the Charity without prior written approval from the [Executive Director / policy owner]. Approval requires:
(a) documentation of the tasks the agent is authorized to perform;
(b) documentation of the systems, data, and accounts the agent may access;
(c) a written statement of the agent's permission limits, including what the agent may not do without human confirmation;
(d) identification of the Personnel member responsible for the agent's activity; and
(e) a review of the vendor's terms in accordance with Section 10.
9.3 Permission boundaries. AI agents must be configured with explicit permission boundaries. As a default, an AI agent must not, without human confirmation:
(a) send communications outside the Charity;
(b) execute financial transactions of any kind;
(c) accept terms of service, contracts, or other binding commitments;
(d) modify records concerning individuals;
(e) disclose personal information to third parties;
(f) publish content to the public; or
(g) access systems beyond those specifically approved in the agent's deployment documentation.
Departures from these defaults require documented approval under Section 9.2.
9.4 Monitoring. AI agent activity must be logged and periodically reviewed by the Personnel member responsible for the agent, at intervals no less frequent than [monthly / quarterly]. Anomalies must be reported to the [Executive Director / policy owner] promptly.
9.5 Kill switch. Every AI agent deployed by the Charity must have a documented method by which its activity can be suspended immediately by a designated Personnel member. This method must be tested at deployment and at each subsequent review.
10.1 Vendor assessment. Before an AI tool is added to the approved list under Section 5.1, the [Executive Director / policy owner] must assess, at minimum:
(a) the vendor's terms of service, privacy policy, and data processing terms;
(b) whether the vendor uses submitted content to train models, and whether that use can be disabled;
(c) where the vendor stores and processes information (with a preference for Canadian data residency, particularly where personal information subject to Quebec's Law 25 is involved);
(d) the vendor's security posture, including encryption, access controls, breach notification, and any relevant certifications;
(e) the vendor's approach to model updates, deprecation, and changes in functionality; and
(f) the vendor's incident response and support commitments.
10.2 Contractual protection. Where feasible, AI tool use should be governed by a written agreement addressing confidentiality, privacy, security, allocation of liability, limits on autonomy (for agentic tools), permitted uses, ownership of outputs, indemnification, insurance, and termination rights. Vendors who refuse to provide reasonable contractual protection should be treated with heightened caution and, in most cases, avoided for uses involving Confidential information.
10.3 Periodic re-assessment. Approved AI tools must be re-assessed at least annually, or when the vendor materially changes its terms, functionality, or ownership.
11.1 General obligation. The Charity does not tolerate discriminatory outcomes prohibited by the Canadian Human Rights Act, provincial human rights legislation, or the Charity's own commitments to equity and inclusion, regardless of whether such outcomes are produced by human or AI decision-making.
11.2 Screening, scoring, and triage. Where AI is used to screen applications, score candidates, triage requests, or otherwise sort individuals in ways that affect their access to opportunities or services, the [Executive Director / policy owner] must:
(a) document the intended use;
(b) assess the tool for known bias risks;
(c) implement human review of decisions affecting individuals; and
(d) periodically audit outcomes for indicators of unjustified disparate impact on groups protected by human rights legislation.
11.3 No sole automated decisions. No decision that materially affects an individual's rights, opportunities, or access to services may be made by an AI tool alone. Meaningful human involvement is required.
12.1 AI use log. The Charity maintains an internal AI use log recording, at minimum:
(a) the AI tools currently approved and the scope of each approval;
(b) high-risk uses under Section 8;
(c) AI agent deployments under Section 9;
(d) incidents and near-misses under Section 14; and
(e) policy reviews under Section 16.
12.2 Records retention. Records relating to AI use are retained in accordance with the Charity's Records Retention Policy, subject to any specific retention requirements imposed by law.
13.1 External communications. The Charity may disclose the fact that it uses AI in its operations. Where AI has materially shaped a communication to a donor, funder, beneficiary, regulator, or the public, disclosure should be considered on the basis of: (i) any legal or contractual disclosure requirement; (ii) any funder or granting agency requirement; and (iii) the reasonable expectations of the recipient. When in doubt, err toward disclosure.
13.2 Beneficiary interactions. Where a beneficiary is interacting with an AI tool (rather than a human) in a way that could reasonably be mistaken for human interaction, the Charity will disclose that fact clearly and provide a straightforward path to reach a human.
13.3 Fundraising and donor communications. AI may be used to assist with drafting, analysis, and administration, but the Charity's donor communications must reflect the voice, values, and knowledge of the Charity and its people. Communications that are entirely AI-generated and sent without meaningful human input or review are not consistent with this Policy.
14.1 Duty to report. Personnel who become aware of any of the following must report the matter to the [Executive Director / Privacy Officer] as soon as practicable:
(a) input of Confidential information into an unapproved AI tool;
(b) release of inaccurate, misleading, defamatory, discriminatory, or infringing AI-generated content;
(c) unauthorized action by an AI agent;
(d) suspected privacy breach involving AI;
(e) suspected security compromise involving AI; or
(f) any other event that could reasonably be expected to expose the Charity to legal, regulatory, or reputational risk.
14.2 No penalty for good-faith reporting. Personnel who report an incident or near-miss in good faith will not be subject to discipline for the act of reporting, even where the underlying incident involved a breach of this Policy. This section is subject to the Charity's Whistleblower Policy.
14.3 Response. The Charity will investigate reported incidents, take corrective action, notify affected parties and regulators where required by law (including under PIPEDA and Quebec's Law 25 for privacy breaches), and update this Policy or its procedures where warranted.
15.1 Mandatory training. All Personnel with access to AI tools in the course of their work must complete AI training at the time of onboarding and at least annually thereafter. Training is refreshed when this Policy changes materially or when the AI tools in use change materially.
15.2 Content. Training covers, at minimum: this Policy and its practical application; identification of Confidential information; recognition of AI hallucinations and other output failures; agentic AI risks; and incident reporting.
16.1 Policy owner. The [Executive Director / designated senior staff member] is responsible for day-to-day administration of this Policy, including maintenance of the approved tool list, review of high-risk uses, and coordination with legal counsel where required.
16.2 Board oversight. The Board of Directors receives a report on AI use, incidents, and policy compliance at least [annually / semi-annually]. The Board approves material changes to this Policy.
16.3 Review cycle. This Policy is reviewed at least annually, and sooner if:
(a) applicable law changes materially (including if the Artificial Intelligence and Data Act or successor federal legislation is enacted, or if provincial AI legislation is introduced);
(b) the Charity's use of AI changes materially;
(c) an incident indicates a gap in the Policy; or
(d) the Board directs a review.
16.4 Legal counsel. The Charity consults legal counsel familiar with the Canadian charity sector and AI regulation on this Policy and on specific high-risk deployments as appropriate.
Failure to comply with this Policy may result in disciplinary action, up to and including termination of employment or engagement, and may result in personal liability for the individual involved where the conduct also breaches applicable law. Contractors and vendors who breach this Policy may have their engagement terminated.
This Policy should be read alongside the Charity's:
(a) Privacy Policy;
(b) Acceptable Use of Technology Policy;
(c) Confidentiality Policy;
(d) Records Retention Policy;
(e) Code of Conduct;
(f) Whistleblower Policy;
(g) Data Breach Response Policy; and
(h) Human Resources Policies.
Questions about this Policy should be directed to [name / role / email].
Version: 1.0
Approved: [Date]
Next review: [Date]
A few notes on how to use this and what to consider before adopting.
Choose your approver. Most of the "approved in writing by [Executive Director / policy owner]" references need to land on one specific role. In small charities, that's typically the ED. In larger ones, a Privacy Officer, CTO, or similar. Whoever it is, they need to actually have the bandwidth to do the approvals. A policy that requires ED sign-off on every AI tool at a charity where the ED can't get through her inbox is a policy that gets ignored.
Section 8 (high-risk uses) is where the real work happens. Charities often want to soften this section to reduce the approval burden. My advice is not to. The high-risk categories are where the actual liability lives, and the approval requirement is what makes the Board's oversight real rather than theoretical.
Section 9 (agentic AI) is the section most templates don't have. This is where your policy will differentiate itself from the off-the-shelf material floating around. If your charity isn't yet using AI agents, this section is future-proofing. If it is, this section is essential.
Section 5.4(a) (no AI-only decisions about people) is deliberately absolute. Some charity clients push back on this. My view is that the moment you allow AI-only decisions about individuals, you inherit both a human rights problem and a fiduciary duty problem that is hard to defend. Keep the absolute prohibition. Build the human review into the workflow.
On training. The single most common failure of AI policies I've seen is that they exist on paper and nobody has been trained on them. Section 15 is short but load-bearing. Budget for the training when the policy is adopted, or the policy will not do what you need it to do.
On the approved tool list. Section 5.1 references a list maintained separately. Keeping the list separate from the policy is intentional. Lists change quickly; policies should not. Publishing the list on your internal intranet or in a governance folder that Personnel can actually find is essential.