For these not-for-profit CIOs, AI can’t risk public trust


Arun Dixit doesn’t answer to shareholders. He answers to a board of engineers, and every year he has to explain why the money spent on cybersecurity last year needs to be spent again this year.

“Even if transformation was done with X dollars in 2026 to strengthen to a certain degree, the threat landscape is evolving very, very quickly,” says Dixit, vice president of digital transformation and corporate operations at Professional Engineers Ontario. “So those same dollars, practically the same amount, if not higher, are necessary just to even maintain our cybersecurity posture level.”

He’s one of three finalists for this year’s CanadianCIO of the Year award in the not-for-profit category, presented by the CIO Association of Canada. All three run technology for organizations funded by member fees or public money, answering to boards of engineers, physicians and scientists, where the return on investment isn’t revenue. It’s public trust.

Scroll down for the full conversation

Read profiles of each finalist

The board conversation has moved from blocking to enabling

Nair says his board used to spend its energy stopping new technology. Now the questions run the other way, how to put AI and other tools to use, how to make collaboration and information sharing easier across the organization.

That change shows up in what boards ask about. 

Nair says the boards he’s worked with in the nonprofit sector tend to weigh two things, the risk being avoided and the impact being made possible, and for his organization, impact rarely comes down to dollars.

Engelbrecht makes a similar case to his board, tying new investment to the college’s mandate to protect the public by regulating the practice of medicine in Ontario.

Dixit says cybersecurity spending becomes a permanent part of the budget once it starts.

“Those are costs of doing business,” he says. “Even if transformation was done with X dollars in 2026 to strengthen to a certain degree, the threat landscape is evolving very, very quickly. So those same dollars, practically the same amount, if not higher, are necessary just to even maintain our cybersecurity posture level.”

AI is already in daily use. The guardrails came with it

All three have moved past piloting. Engelbrecht’s college is fully implemented with Microsoft Copilot, embedded into operational workflows. Dixit is six months into an enterprise generative AI rollout with access to his organization’s systems, data and networks. Nair has guidance in place across TRIUMF on what tools staff can use and how.

Engelbrecht built an innovation lab alongside that rollout, a room where staff bring ideas for new uses of AI before they become part of daily work.

“The users got very excited when we started launching our innovation lab, where people can come into a room and have a business analyst there, a developer, everybody, and they sit around a table and tell their story about how they want to use AI and how they think they can implement it into their day-to-day operation,” he says.

Dixit doesn’t know yet how well his organization’s chosen platform performs against the data an Ontario engineering regulator holds, six months in. He calls the rollout an ongoing exercise in developing a skill.

Nair splits his organization’s guardrails into three categories, research security, privacy, and cybersecurity, and says cybersecurity is the one everybody thinks of first.

Near the end of our conversation, in an ongoing effort across these roundtables to get someone to disagree with someone, I asked each of them for a hot take, a controversial opinion about their industry.

“You can’t teach smart people not to be stupid,” says Nair, crediting a former CEO with the line. “The smarter you are at something, the more likely you are to be narrowly focused on that thing, and the breadth of knowledge you need to capture all the areas where you think you’re smart is not going to be an easy thing to do.”

Dixit offered his own answer, fail early, fail often, and admitted upfront it probably wasn’t much of a hot take.

“That approach to innovation, that kind of small, let’s-test-things-out, iterate approach ends up paying dividends later, as we learn frequently, and not too late, from some lessons,” he says.

Trust is hard to earn and easy to lose. These three run the technology in their organizations with that in mind.

Watch the conversation:

This article is part of a series profiling the finalists for the 2026 CanadianCIO of the Year Awards, not-for-profit sector category, presented by the CIO Association of Canada. The winner will be announced Oct. 1 in Toronto. Digital Journal is the national media partner for the CIO Association of Canada.



For these not-for-profit CIOs, AI can’t risk public trust

#notforprofit #CIOs #risk #public #trust

Leave a Reply

Your email address will not be published. Required fields are marked *