Writing a nonprofit AI policy
September 7, 2026 · 6 min read
Somebody at your organization used an AI tool this week. Maybe the development director tidied up a grant narrative, maybe the program manager let the meeting software write the notes, maybe someone pasted a paragraph into a chatbot to make it shorter. Nobody asked permission, because there was nobody to ask and nothing written down to check against. A nonprofit AI policy is the document that ends that situation, and most small organizations do not have one yet.
The instinct when use is already ahead of the rules is to ban everything until the board has time to think. It rarely works. These tools are inside software you already pay for, often switched on by the vendor, and a rule that everyone quietly ignores is worse than no rule at all because it teaches people that written rules here are decorative.
What you want instead is a short document that tells a reasonable person what to do on a Tuesday afternoon.
What a nonprofit AI policy should cover
Open a blank document and fill in these nine headings. Finished, it should run one or two pages. Longer than that and nobody reads it, which defeats the point.
1. Who it applies to. Staff, board members, volunteers, interns, and contractors doing work in your name. Contractors are the ones people forget. If a freelance grant writer runs your program data through a tool, it is still your data and still your problem.
2. What counts as an AI tool. Say plainly that you mean software that generates text, images, audio, code, or summaries, including features built into tools you already use. Describing a category rather than listing products keeps the policy from expiring the week a vendor ships a new button.
3. Information that never goes into one. The most important section, and it has to be specific rather than a wave at confidentiality. Donor records, client and participant names or case details, personnel files, unpublished financials, board material that is not public, and anything a grant agreement or a privacy law obliges you to protect. This decision deserves its own conversation, which is what may never go into an AI tool.
4. Which tools people may use. An internal list can name products, because it describes accounts you actually hold. Say which ones are approved, whether a personal free account on a tool counts as approved, and how somebody asks for a new one. A request route with a named person is what stops a shadow list forming.
5. What a person checks before anything leaves the building. Every fact, number, name, date, and quotation verified against a source a human can point to. Put the responsibility on the person whose name is on the work, not on the tool.
6. Work you do not use these tools for at all. Deciding who receives services or how much. Screening job applicants. Anything where a person is being judged rather than a sentence being drafted. Write down whatever your version of that list is, because the absence of a list is how those uses arrive by accident.
7. What you tell people. Whether you disclose AI involvement to funders, donors, or the people you serve, and in what circumstances. A common landing spot is that routine internal work needs no disclosure, and anything presented as a person's own words or professional judgment does.
8. Who decides. One named role, not a committee. Somebody has to be the person you ask when the policy does not obviously cover the situation.
9. When you look at it again. A date, six or twelve months out, written into the document. This section is what keeps the policy from becoming a 2026 artifact nobody can update without a whole new process.
The three decisions that outline hides
Most of the nine headings are transcription. Three of them are real decisions, and if the board or the leadership team has not made them, the drafter will make them by default.
The never-goes-in list is the first, and it is the one with consequences you cannot take back. Do it before the rest of the policy rather than as a bullet inside it.
The disclosure position is the second, and it is where organizations tend to discover they disagree with themselves. Invented example: a food bank agrees quickly that using a tool to clean up a newsletter needs no disclosure, then spends twenty minutes finding out that half the room thinks a personalized appeal letter is different in kind and half thinks it obviously is not. That twenty minutes is the useful part. Write down where you land, including the parts you are unsure about.
The third is whether the consumer version of a tool is allowed, or only accounts your organization holds. Free accounts are how most people first try these tools, and the terms attached to them are usually not the terms attached to an account your organization holds in its own name. You do not need to become an expert in vendor contracts to make this call. You need to decide it on purpose and say so.
Who writes it, and who approves it
At an organization with staff, the chief executive or an operations lead drafts it, two or three people who actually use the tools mark it up, and the board approves the finished version at a regular meeting. Board approval matters less as a control than as a record. It puts a date on the organization's position and makes the policy something the next executive director inherits rather than something they have to relitigate.
At an organization with no staff, the board writes it, which usually means one board member writes it and the rest read it properly.
Either way, do not send the first draft to the whole board for comment. A document with nine headings and eleven authors comes back as a paragraph with everything in it. Draft, review with the two or three people closest to the work, then take it to the board as a recommendation with the open questions flagged.
Boards that have adopted a conflict of interest policy have done this exact exercise before. The same reasoning applies, and it is laid out in what a conflict of interest policy is actually for: the point is not the signature, it is that the organization decided something in advance rather than in the middle of a problem. For general policy templates and the state association nearest you, the National Council of Nonprofits is the usual starting place.
Getting it read is a separate job
A policy that exists and a policy people know about are different achievements, and the second one takes work that looks nothing like drafting. Plan for it now, because the most common outcome of a policy adopted in October is a survey in March showing that half the staff do not know it exists. That failure has its own fixes, described in the AI policy nobody knows about.
If you want to know where your own organization actually stands before you write anything, the AI readiness assessment asks the board and the staff the same questions about what is in place, what is in use, and where people think these tools should and should not be used. It takes about seven minutes per person, it is free, and there is nothing to buy.
The reason to write this down is not that AI is an emergency. It is that your colleagues are making these calls one at a time, alone, in the ten seconds before they hit send, and none of them wanted that job.