Separate staff rules from strategic choices and board oversight, then decide which AI documents your nonprofit needs immediately and next.

A Canadian nonprofit may need immediate rules for staff AI use before it has a complete AI strategy. That does not make policy a substitute for strategy. Policy defines permitted behaviour, strategy chooses organizational priorities, and governance assigns the authority to approve and oversee the work.

Confusing the three produces predictable gaps. A strategy can recommend new tools without telling staff what information they may enter. A policy can prohibit risky behaviour without identifying any useful investment. A governance committee can meet without knowing what decisions it owns.

Three documents with different jobs
Document or arrangement Main question Typical contents
AI policy What may staff do? Approved uses, information limits, review and reporting rules
AI strategy What should the organization pursue? Priorities, expected outcomes, resources and sequencing
AI governance Who decides and checks? Approval authority, ownership, monitoring and escalation

Respond to current use first

If employees are already experimenting, establish a short interim instruction while broader work proceeds. Identify approved tools and permitted information. Tell staff who can answer questions and how to report an accidental disclosure or unsuitable output.

A practical interim rule might allow drafting from published organizational material while requiring approval before entering personal or confidential information. Another might require staff to verify generated facts before external use. These are examples to adapt to the actual environment, not a complete policy or a claim of legal compliance.

Do not let policy become an empty prohibition

Explain how staff can request a useful new use. A rule that bans everything without an approval route may discourage disclosure without eliminating experimentation. Conversely, a broad permission to “use AI responsibly” gives employees little help when they face a specific information question.

Use examples drawn from the nonprofit’s work: donor communications, client documentation, funder reporting and public resources. Specify who reviews outputs and what must never be sent automatically under the current approval.

Develop strategy from the organization’s priorities

Once immediate boundaries are clear, examine recurring problems and available capacity. Choose a small number of candidate projects, compare them with non-AI alternatives and identify the evidence needed to proceed. The strategy should make trade-offs explicit instead of endorsing every suggested use.

Keep the legal assessment tied to the activity. The Privacy Commissioner notes that nonprofit status does not automatically determine PIPEDA applicability. Avoid copying a generic compliance paragraph into policy without establishing the organization’s circumstances.

Connect the documents through a real approval process

Suppose the strategy proposes a reporting assistant. Governance identifies the executive who approves the trial and the information owner who authorizes inputs. Policy tells participating staff how to use it and report problems. Evaluation determines whether the approved conditions should change.

Review the documents when the use changes materially, not just when the annual calendar says to do so. Nimblox can help identify which policy, strategy and accountability gaps need attention first.