Brazen Solutions · Digital Tools / AI
Should our nonprofit have an AI policy? Yes — and writing it is the easy part.
What an AI policy actually covers, what Canadian privacy law already expects of you the day donor data touches a chatbot, and why the document is the smallest piece of the work.
August 2026 · 7 min read
Third item on the agenda is the fall appeal. Twenty minutes in, the development coordinator asks a question that isn't on the agenda.
Am I allowed to put donor notes into ChatGPT?
She isn't asking in theory. She's been doing it for about six weeks — pasting in meeting notes, asking for a cleaned-up summary, sometimes a draft thank-you. It's saved her three or four hours a week. She read something over the weekend and now she isn't sure.
Everyone in the room turns and looks at the ED.
The ED has nothing written down. No policy, nothing in the handbook. What she has is about four seconds to answer a question with real consequences attached, in front of five people who will treat whatever comes out of her mouth as the rule from here on.
That's the question underneath should our nonprofit have an AI policy. Compliance comes later. First it's a person on your team, doing her job, asking permission for something she started months ago and never mentioned.
What's already happening in your office
Answer this before you write a word, because it changes what the policy has to do.
Your staff are using AI. Not all of them, and almost never in the way you'd guess. The grant writer is using it for first drafts. Somebody on the program side is running intake notes through a transcription tool that came bundled with the subscription. A good chunk of it sits on personal accounts, because the organization never bought anything, so people used what was free.
That isn't a nonprofit failing. In May 2026, an Ontario provincial review reported thousands of government staff using unsecured AI tools — inside the very sector Ontario's own AI accountability law regulates. If it's happening there, with an IT department and a written directive, it's happening at your organization of nine people on a Tuesday night.
And it's the norm. Imagine Canada's research has about eight in ten Canadian nonprofits using AI in some form — and roughly one in ten with anything written down about it. That gap matches every room I've sat in.
So the gap isn't between organizations that use AI and organizations that don't. It's between organizations where the use is visible and organizations where it isn't.
Yes, you need one. Here's the honest reason.
The honest reason is donor data.
The minute a donor's name, her giving history, the note about her husband's diagnosis, or the reason she paused her monthly gift goes into a prompt, personal information has moved into a system your organization doesn't control and can't audit. That's the exposure. The disclosure question and the accuracy question both sit on top of it.
Canada has no national AI law. AIDA — the Artificial Intelligence and Data Act — died on the Order Paper in January 2025, and the national AI strategy released in June 2026 is direction rather than legislation. Which means the rules that apply to you today are the privacy rules that already did.
Those rules have teeth, and Canadian regulators have now used them on AI twice in ways that should change how you buy software.
In 2021, the federal Privacy Commissioner and the Alberta, BC and Quebec commissioners found that Clearview AI's mass collection of images to train a facial recognition system without consent violated PIPEDA. Scraping the public web is not a defence.
Then in May 2026 — PIPEDA Findings #2026-002 — that same group of regulators found OpenAI had collected personal information from publicly accessible websites to train its GPT models without valid consent, in breach of PIPEDA and all three provincial acts. Including information people could not reasonably have expected would end up training an AI system.
That matters to you as a customer. The largest AI vendor in the world was found offside by Canadian regulators, which means vendor terms of service are not a safeguard you can stand behind. If your policy amounts to "we use enterprise tools, so we're covered," it says nothing.
The Privacy Commissioner has also set out, jointly with every provincial and territorial privacy office, what regulators expect from organizations that use generative AI rather than build it. Three of those belong on your page in plain words.
An inference the tool makes about a real, identifiable person — a capacity estimate, a likelihood-to-give score, a tidy summary of what a donor "seems to care about" — is that person's personal information, carrying every obligation that comes with it.
Anonymize what goes into prompts. Strip names and identifiers before anyone pastes. This one costs nothing and almost nobody does it.
And verify a tool's accuracy claims before you use it for anything that affects a person. "The vendor says it's 94% accurate" is a marketing sentence until you've tested it against your own records.
One more thing, said plainly. PIPEDA's application to charities is narrow and turns on commercial activity, and it shifts by province — BC's PIPA covers non-profits expressly, and Quebec's Law 25 is stricter than anything else in the country. A policy helps you meet your obligations. It is not a legal opinion and neither is this article. If you hold health information, or you can't tell which act applies to you, ask a lawyer. That's a two-hour conversation, not a retainer.
The policy is one page. The practice is the rest.
Most organizations treat the policy as the deliverable. Get it approved, put it in the shared drive, tell the board it's handled. Six months later the coordinator is still pasting donor notes into a chatbot, because nobody ever told her what to do instead.
A policy is a permission structure. It works only if the people it governs know what it says, believe it applies to them, and have somewhere to go when they hit a case it doesn't cover. That's practice, and practice gets built in conversations.
Practice looks like someone asking in a meeting and getting an answer in a day instead of a quarter. A short list of approved tools that actually gets updated. A person who is allowed to say yes. And a workplace where nobody hides what they're using — because hiding it is how client intake notes end up in a free transcription tool nobody has ever looked at.
Writing the policy takes an afternoon. Getting your team to tell you what they're already using takes trust you have to build first.
What a usable policy actually covers
Which tools are approved, by name. Not "generative AI tools." The actual list — the ChatGPT account you pay for, Copilot, the transcription feature in your Zoom plan. A category isn't a decision anybody can follow.
What never goes into a prompt. The most useful page in the whole document. Donor records, client and service-user information, anything about a child, health details, HR files, anything you wouldn't read out loud in your own lobby. Write it as a list of things, not a principle.
Who decides, and how fast. One named person. Plus a route for "I found a tool that would save me six hours a week" that doesn't take a quarter. Slow permission is where shadow use comes from.
What you tell people. Whether AI touched a donor communication, a grant narrative, a case note. Funders are starting to ask. The harder version — is it ethical to use AI on our donors without telling them — is worth settling before a donor asks you cold. Blackbaud's 2026 research found 76% of donors say disclosure matters to them; that's US data, but I wouldn't bet on Canadian donors feeling differently.
Who owns the words. Nothing reaches a donor, a funder or your board without a human who read every line and stands behind it. Unchecked AI output becomes your organization's statement the moment it leaves the building.
Where the data physically goes. Most tools your team uses are hosted in the United States, which means US authorities can compel access under the CLOUD Act no matter where the person lives. For general communications, that's a risk you can accept knowingly. For health information, immigration files, or anything involving kids in your programs, decide on purpose whether a US-hosted tool belongs near it.
What to do this month
Book forty-five minutes and call it an amnesty. Ask everyone what they're already using, and promise nobody is in trouble. You'll hear three or four things you didn't know about. That list is your real starting point and it beats any template.
Then write the never-list. One page, ten lines, the things that never go into a prompt. Circulate it that week while the meeting is still warm. It will do more work in a month than a fifteen-page policy does in a year.
Name the person who decides. The rest of the document can wait until October.
If you'd rather work from a structure than a blank page, the free AI policy builder walks you through the decisions and produces a draft shaped for a Canadian nonprofit — approved tools, the never-list, disclosure, human review, where the data lives. It takes about twenty minutes and costs nothing.
And if what you really want is to sit with other EDs working the same problem out loud, the Free AI Reality Check runs September 8. Ninety minutes, free, nothing to buy at the end. We work through what's already happening inside your organization and what to do about it.
Your coordinator asked a fair question in a staff meeting. She deserves a real answer. Give her one this month.
Wondering whether your organization could carry a capital campaign? The free readiness assessment scores you across the eight areas that decide it.
Take the free readiness assessment