The AI policy nobody knows about
September 7, 2026 · 6 min read
The board adopted something last spring. It is in the shared drive, in a folder called Policies, in a document with a version number in the filename. Ask five people what the organization's position on AI is and you will get one confident answer, two guesses, and two versions of not sure. That is an AI policy nobody knows about, and it is a more common outcome than a policy that does not exist.
This is worth separating from a discipline problem, because it is not one. Nobody reads the policy folder. Nobody has ever read the policy folder. The document was written to be correct, which is the right goal for a document and a poor strategy for reaching people.
Why an AI policy nobody knows about is common
Three things produce it, and all three are ordinary.
The policy was written once and communicated once. It went out in an all-staff email in March, and everyone who joined after March has never seen it. At an organization with any turnover at all, a one-time announcement decays to nothing within about two years.
The policy is written in policy language. A document that says the organization is committed to the responsible and ethical use of emerging technologies has not told anyone whether they can run a donor letter through a chatbot. People do not remember positions they cannot apply.
And nobody knows who to ask. A policy without a named person attached is a document; a policy with a named person attached is a route. When there is no route, the question gets resolved privately in whatever way seems reasonable at the time, and the resolution never comes back.
Find out which gap you have
Before you fix anything, work out who does not know. Board and staff produce the same symptom for different reasons, and the fixes do not transfer.
If board members cannot say what the position is, the problem is usually that the policy was approved in a consent agenda and never discussed. It got a vote, not a conversation, and a vote is not a memory. The fix runs through the board's own information habits, not through staff communication.
If staff cannot say what the position is, the problem is distribution and language. The people who most need the answer are the ones using the tools, and they are the least likely to have opened the folder.
If both groups are unsure but each assumes the other is clear, you have the version that causes the most trouble, because everyone is confident that somebody has this handled.
An assessment can tell you which one you have, and this is one of the few questions where an anonymous survey is much better than asking around, since almost nobody will volunteer in a meeting that they do not know what the policy says. A staff section releases at 4 or more responses and at least 60% of the roster, so a team of eight needs five people to answer before you see anything. Nothing in the result can be traced to a person, which is the only reason the answers are worth having.
Five things that actually move the number
Write a one-page version that is not the policy. Same rules, plain sentences, arranged by what a person is about to do rather than by section number. Three headings work: what you can use without asking, what needs a check before it goes out, and what never goes into these tools at all. The full policy stays where it is for the board and the auditor. The one-pager is what people actually consult.
Put it where the work happens. In the shared folder people open every day, not the one called Policies. Pinned in the channel where staff talk about work. In the first paragraph of the grant application template. Invented example: a housing nonprofit added two sentences to the top of its donor letter template, and the number of people who could describe the rule went up more than the all-staff email had ever moved it.
Answer the questions in public. When somebody asks whether they can use a tool for something, answer where everyone can see the answer, and keep a short running list of the answers. Six months of that list is more useful than the policy, because it is made of real situations. It also shows people that asking is normal rather than an admission of something.
Put it in onboarding for both groups. New staff get the one-pager in week one, with a named person to ask. New board members get it in the board packet with the bylaws and the conflict of interest policy. Board orientation is where most of these documents go to be forgotten, and the fix is the same one that works for everything else in the packet, described in what a new board member actually needs in the first 90 days.
Spend ten minutes on it once a year, with real examples. Not a reread of the document. Three situations from the past few months, asked out loud, answered out loud. Can I use the meeting notetaker in a case conference. Can I put last year's budget into a tool to explain a variance. Can I use a tool to draft the annual appeal. People remember the answers to questions they might have asked.
Check that it worked
This is the step almost everyone skips, and it costs about fifteen minutes.
Six to eight weeks after you do the work, ask three people who were not involved in writing any of it to tell you, in their own words, what the organization's rule is. Not whether they have seen the policy. What it says. If two of the three can give you the shape of it, you are in reasonable condition. If none of them can, the problem is the one-pager, not the audience, and you should rewrite it rather than send it again.
The same check works at the board table. Ask at the start of a meeting, before anyone can look anything up. Boards that do this discover fairly quickly which of their policies exist and which merely have been approved. BoardSource publishes research on board information practice that makes the general version of this point across governance, not only for anything to do with AI.
If you do not have a written position yet, the drafting is a smaller job than the communicating, and there is an outline for it in writing a nonprofit AI policy. And if what people are missing is less the rule than the skill to follow it, that is a different problem with a different answer, covered in training staff on the tools already in use.
The organization did the hard part already. Somebody thought about this, wrote it down, and got it approved. What is left is the unglamorous work of putting it in front of people at the moment they need it, which nobody puts on a work plan and which is most of the value.