---
title: "What to put in an AI policy for a small nonprofit · Jeyki Security"
description: "A practical starting point for deciding which AI tools staff can use, what information stays out and who checks the work, with a one-page policy to adapt."
url: "https://jeyki.ca/ai/writing/ai-policy-small-nonprofit"
---

1.  [Home](https://jeyki.ca/)
2.  [AI for organizations](https://jeyki.ca/ai)
3.  [Writing](https://jeyki.ca/ai/writing)
4.  What to put in an AI policy for a small nonprofit

Policies and people

# What to put in an AI policy for a small nonprofit

A practical starting point for deciding which AI tools staff can use, what information stays out and who checks the work, with a one-page policy to adapt.

By [Ashwin Charathsandran](https://jeyki.ca/about)

Last reviewed October 7, 2026 · 7 min read

## In this article

-   [Start with three ordinary tasks](#start-with-three-ordinary-tasks)
-   [Name the approved tools and settings](#name-the-approved-tools-and-settings)
-   [Say what stays out](#say-what-stays-out)
-   [Make a person responsible for the result](#make-a-person-responsible-for-the-result)
-   [Decide when to tell people](#decide-when-to-tell-people)
-   [Give mistakes somewhere to go](#give-mistakes-somewhere-to-go)
-   [A one-page starter policy to adapt](#a-one-page-starter-policy-to-adapt)
-   [Try it with your staff before calling it finished](#try-it-with-your-staff-before-calling-it-finished)

A staff member wants help shortening a grant application. A volunteer is trying to write a social post. Someone else has started uploading meeting notes to a chatbot. A useful AI policy should tell each of them what they can do next without needing a board meeting.

Start with the decisions people actually face: which tool, which information, which task and whose approval. A short policy that answers those questions is easier to teach than a long statement about responsible innovation.

There is a real gap to close. Imagine Canada and the Canadian Centre for Nonprofit Digital Resilience’s January 2026 report estimated that only 10% of Canadian nonprofits had written policies or guidelines for staff AI use. That figure comes from a weighted online survey with 963 responses collected between June and September 2025. It is a survey estimate of that period, not a count of every nonprofit or a measure of adoption today. [Read the report and its methodology](https://imaginecanada.ca/sites/default/files/the-state-of-ai-adoption-in-canadian-nonprofits-en.pdf).

## Start with three ordinary tasks

Before writing rules, ask staff where they already use AI and where they want help. Make this a practical conversation. If the first response is punishment, you may stop hearing about the tools people use.

Pick three real tasks, such as drafting a public event description, summarizing a published funding guide and preparing an internal agenda. For each one, write down the input, the intended output and the person who will review it.

Then try a harder example: a caseworker’s notes about a family. That should prompt a different decision from a public event description. If your policy treats both tasks the same, it needs more work.

## Name the approved tools and settings

“Staff may use AI responsibly” leaves too much unanswered. Keep a short approved-tool list beside the policy. For each entry, record:

-   The product, subscription plan and organization-managed account or workspace
-   The tasks and categories of information approved for that tool
-   Required privacy, training, retention and sharing settings, with the date they were checked
-   Whether file uploads, meeting recordings, web access or connections to other systems are permitted
-   The staff member responsible for access, billing and reviewing changes

Approve the actual setup. A product name alone does not describe the account, settings or connected apps someone is using. Require staff to ask before adding a browser extension, meeting assistant or inbox connection.

The Canadian Centre for Cyber Security recommends an AI risk plan, clear oversight and review, careful vendor selection and avoiding personal or sensitive corporate information in prompts. Those are useful starting points when reviewing your own tools. [See the Cyber Centre’s guidance](https://www.cyber.gc.ca/en/guidance/generative-artificial-intelligence-ai-itsap00041).

## Say what stays out

Give staff examples from your organization. For a small nonprofit, a sensible starting restriction for general-purpose chatbots includes client case notes, donor lists, employee records, identifiable information about children, financial account details and private board discussions. Passwords, recovery codes and access keys should never be pasted into a chatbot.

Removing names is not enough if a combination of details still identifies someone. A rare medical condition, a small community and a service date may say more than a name would.

Use made-up examples, public information you are entitled to use or properly approved summaries instead. If a task genuinely needs personal information, pause it for a separate privacy and security assessment. Do not make individual staff decide whether a vendor’s marketing claim is sufficient.

## Make a person responsible for the result

Name the review that happens before AI-assisted work leaves a draft. For a grant application, that means checking every claim, budget figure, eligibility rule and reference against the original material. For a public post, it also means checking tone, accessibility, permissions and whether the text misrepresents the people you serve.

The reviewer should be able to explain the output without relying on the chatbot’s confidence. If nobody can verify it, do not use it.

Set a clear boundary around consequential decisions. A starter policy can prohibit using general-purpose AI to decide hiring, access to services or other outcomes that significantly affect people. Any proposal to use AI in those processes deserves its own review, rather than an exception made during a busy afternoon.

## Decide when to tell people

Choose a disclosure rule people can follow. Require disclosure when a funder, contract or professional standard calls for it, when people interact directly with an AI system, and when AI materially contributes to a decision that affects someone. Explain the role of the tool and who is responsible.

Canada’s privacy regulators emphasize transparency about personal information and meaningful notice where AI is used in significant decisions. A label saying “AI-assisted” does not by itself explain what happened to someone’s information. [Read the regulators’ principles](https://www.priv.gc.ca/en/privacy-topics/technology/artificial-intelligence/gd_principles_ai/).

For routine editing of a public paragraph, your organization can choose a proportionate internal rule. Keep a record of substantial AI assistance where it will help the next reviewer understand the work.

## Give mistakes somewhere to go

Name one person and a backup who can receive reports. Include accidental uploads, unexpected sharing, fabricated claims that reached an audience and a tool taking an action nobody approved.

Staff should stop the affected workflow and report the time, tool, account and kind of information involved. They should avoid spreading the original sensitive material while reporting it. The responsible person can preserve appropriate evidence, assess containment and determine any notification duties with qualified advice. Deleting a chat is not proof that all copies have disappeared.

## A one-page starter policy to adapt

This is a practical template, not legal advice or a complete privacy programme. Replace the brackets, agree on the rules and review them against your obligations before adopting it.

> **\[Organization\] staff AI policy**
> 
> **Owner:** \[name and backup\]. **Approved:** \[date\]. **Next review:** \[date\]. Applies to staff, volunteers and contractors working for this organization.
> 
> **Approved use.** Use only the tools, plans and organization-managed accounts on \[approved-tool list\], with its required settings. Permitted tasks are \[specific tasks\]. Ask \[owner\] before using a new tool or feature, recording a meeting, uploading files or connecting another system.
> 
> **Information.** Use public material we are entitled to use, fictional examples or information explicitly approved for that task and tool. Never enter passwords, verification codes, recovery codes or access keys. Do not enter client, donor, employee or child records, financial account details or confidential board material into general-purpose chatbots. Removing a name does not automatically make information anonymous. Ask if unsure.
> 
> **Human review.** The staff member using AI remains responsible for the work. Before sharing or relying on it, verify facts, figures, sources, permissions and suitability. \[Named role\] approves public or consequential outputs. Do not use AI to make hiring, service-access or other significant decisions about people under this policy.
> 
> **Disclosure.** Follow funder, contract and professional requirements. Tell people when they interact with AI or when it materially supports a decision affecting them. Record substantial AI assistance in \[work record\] so reviewers understand its role.
> 
> **Actions and connections.** AI must not send messages, publish content, change records or spend money without the approval required by our existing procedures. Connections need separate approval and the minimum access needed.
> 
> **Problems.** Stop the affected use and tell \[contact and backup\] promptly about accidental sharing, inaccurate published output or unexpected actions. Record the tool, time and type of issue without recirculating sensitive information. The owner coordinates containment and any required notifications.
> 
> **Review.** \[Owner\] reviews this policy and the approved-tool list on \[schedule\], and after a material tool change or incident. Questions and improvement suggestions go to \[contact\].

## Try it with your staff before calling it finished

Read through a public newsletter draft, a donor spreadsheet and a meeting recording together. Ask what the policy permits, what it prohibits and who decides when something is unclear. Any disagreement is a useful edit to make now.

Give new staff the same examples during onboarding. Put the policy where they work, keep the approved-tool list current and set a review date. You do not need to predict every future AI product. You need a dependable way to make the next decision.

## Sources and further reading

Official guidance checked on October 7, 2026. Product settings and guidance can change.

1.  [Imagine Canada and CCNDR: The State of Artificial Intelligence Adoption in Canadian Nonprofits, January 2026](https://imaginecanada.ca/en/research/ai-report)
2.  [Imagine Canada and CCNDR: full report and survey methodology (PDF)](https://imaginecanada.ca/sites/default/files/the-state-of-ai-adoption-in-canadian-nonprofits-en.pdf)
3.  [Canadian Centre for Cyber Security: Generative artificial intelligence](https://www.cyber.gc.ca/en/guidance/generative-artificial-intelligence-ai-itsap00041)
4.  [Canadian privacy regulators: Principles for responsible, trustworthy and privacy-protective generative AI technologies](https://www.priv.gc.ca/en/privacy-topics/technology/artificial-intelligence/gd_principles_ai/)

Practical help

## Need a policy your staff can actually use?

I can help you turn your tools, information and everyday tasks into clear rules for your organization.

[See the AI policy package](https://jeyki.ca/ai#ai-policy)

## Keep reading

-   Privacy and everyday use
    
    ### [What your staff should never paste into an AI chatbot](https://jeyki.ca/ai/writing/what-staff-should-never-paste-into-ai-chatbot)
    
    A red, yellow and green checklist for work information, plus the settings and habits that matter before anyone uploads a file or starts a chat.
    
-   Connected workflows
    
    ### [Before you connect AI to your inbox: prompt injection in plain English](https://jeyki.ca/ai/writing/prompt-injection-inbox-plain-english)
    
    An AI assistant can mistake something it reads for something it should do. Here is how to limit that risk before connecting email, files or other work tools.
    

[All AI writing](https://jeyki.ca/ai/writing)
