You don't need a lawyer or a 20-page document. You need one page your whole team has read. Here's what to put in it — and a template you can copy right now.

The short version: most nonprofits experimenting with AI still have no written policy — the consistent finding across recent nonprofit-tech surveys. Fine when one person tinkers, a real risk when the whole team does. The fix is a one-page policy with a handful of clear rules. Copy the template, fill the brackets, done.

Key takeaways

  • Draw the safety line at the tool's settings, not its price. Real protection means training turned off and a data agreement in place. A paid account is not automatically safe.
  • Keep a human responsible — AI drafts, people decide. And AI never decides anything about a person.
  • Disclose AI wherever someone would feel misled to learn about it later.
  • Write it with your team, on one page they'll actually read.
  • A clear policy shows your board and funders you're using AI on purpose.

1. Why you need one

Start with the people you serve. A loose approach to AI puts their information and their outcomes at risk before it ever risks you. Someone on your team is probably already using AI. The trouble shows up when they use it with no shared sense of what's safe. A one-page policy protects the people you serve, lets staff work without second-guessing, and shows your board you're deliberate about it.

2. What it's not

Skip the legal document. Skip the 20-page manual nobody finishes. And don't reach for a ban, either — a wall of "don't" just pushes AI use into the shadows.

3. The free one-page template (copy & adapt)

[Organization Name] — AI Use Policy
Last updated: [date]  ·  Owner: [name / role]
Applies to: everyone who does work for us — staff, board, volunteers, contractors.

Purpose. We serve [the people we serve]. AI tools help us spend less time on
admin and more on them — as long as we use AI in a way that keeps them safe,
keeps us honest, and never puts a machine in charge of a person's life.

1. What we use AI for. Drafting, summarizing, brainstorming, repurposing
content, cutting repetitive admin — always as a first draft a person finishes.

2. What never goes into an AI tool without protection. No information about a
real person — donors, clients, the people we serve, staff, volunteers — goes
into a tool unless it (a) is set not to train on our inputs and (b) has a data
agreement with us. A paid or "approved" account is not automatically safe. This
covers names tied to details, financial or health data, immigration status,
contact lists, and case notes — and removing the name isn't enough if the
remaining details still identify someone. It covers files, screenshots, and
CSVs, not just what you type. AI notetakers count: only record with everyone's consent,
and never a client, counseling, or minor conversation without approval.
(Which tools are safe? See the box below.)

3. A human is always responsible. AI drafts; a person reviews and approves
everything before it's sent, published, or acted on. We check facts, names,
numbers, and dates — AI invents them confidently.

4. AI never makes a decision about a person. No AI decides who gets help, who's
a priority, who's eligible, or anything touching safeguarding. It can gather or
summarize; a person always decides.

5. Approved tools. We use [tool(s)]. Ask [owner] before adding a new one.

6. Be honest about AI. Disclose AI's involvement whenever someone would feel
misled to learn about it later — published content, donor appeals written to
feel personal, board and funder materials, and letters or assessments to the
people we serve. No need to flag internal drafts or routine admin. Never sign
AI text as a personal note from a named person. And once or twice a year, have
someone from the community we serve review a sample of AI-touched messages
about them — for tone and dignity, not just accuracy.

7. Fundraising and reporting. Check each funder's stance on AI before you
submit. Never let AI invent a beneficiary, an outcome, or a number.

8. If something goes in that shouldn't have. Tell [owner] right away — no blame.
The point is to delete it and limit harm, not to catch anyone out.

9. Questions. When in doubt, ask [owner]. It's always okay to ask.

We'll revisit this on [review date].

A good AI policy isn't a wall. It's guardrails that let your team move faster because they know where the edges are.

Which tools are actually safe?

The whole policy rests on this one call, so draw the line where it belongs: settings, not price.

  • Consumer / personal accounts — free or personal logins that may train on whatever you type (free ChatGPT, a personal Gemini or Copilot). Fine for public, non-personal work. Never for a real person's details.
  • Protected accounts — a business or nonprofit tier with training turned off and a data agreement in place (a DPA, or a BAA if you handle health data): ChatGPT Team/Enterprise, Google Workspace under its data terms, Microsoft Copilot under your business agreement. Safe for more — but only within what that agreement covers.

Do this today: in free ChatGPT, turn training off before any work use — Settings → Data Controls → turn off "Improve the model for everyone." Most tools have a similar switch; find it before you paste anything real.

Before you approve a tool, four questions: Business/nonprofit tier, not a personal login? Training on your inputs disablable? A data agreement in writing? Covers your team's main uses? Owner's gate: what data will people put in this, is training off, do we have it in writing?

Which specific tool to pick is a bigger question — see AI getting started and DIY vs. freelancer vs. agency.

4. Where the law comes in

This template sits on top of your legal duties; it doesn't replace them. If your work touches health data, minors, or people in the EU or UK — or your grant agreements include data-handling terms — check those obligations before any AI tool touches that data. You can draft v1 yourself; if you handle regulated data, have someone qualified review it before you rely on it. Orgs serving high-risk groups may want more later (consent workflows, a redress channel, a minors sub-policy) — note them as next steps, don't let them stall v1.

AI's failures with non-English speakers, disabled users, and marginalized communities get their own read in the digital divide essay.

5. How to put it to work

  1. Draft v1 in about 20 minutes, then have one short team conversation — a week of calendar time, not a week of work.
  2. Write it with your team, not at them. That's how quiet, fearful use turns into safe use.
  3. Fill the two brackets that matter: your approved tools, and the owner.
  4. Make it official: shared drive and staff handbook, have the board note it, point funders to it.
  5. Put the review date on the calendar — twice a year is plenty.

Traps to skip: over-restricting (people ignore a wall of "don't"); copying a corporate policy (it won't fit a small team); writing it alone (your unsupervised volunteer is often the highest-risk user). Keep basic account hygiene too — org logins, access removed when people leave; the rest lives in the digital audit.

FAQ

Does a small team really need one? Yes — arguably more, with less margin for error and no legal team down the hall.
Who writes it? Whoever owns ops or tech (often the ED), with team input. Draft v1 yourself; get it reviewed before you rely on it if you handle regulated data.
How long? One page.
How often to update? Twice a year, plus whenever you adopt a major new tool.
Do funders care? A growing number now ask applicants to disclose AI use in grant applications. A clear policy is a point in your favor.


Free first move: Take the free Audit to see where AI fits your whole setup — it's the fastest way to know what's actually worth doing next. Then copy the template and fill the brackets: grab the copyable template. Not sure how exposed you are first? The free AI Policy Risk Check scores it in two minutes. A policy answers what's safe; when you want the bigger picture, it points on to strategy on a budget.

And if you want a second set of eyes on the whole picture — not just the policy — Board-Ready Digital Clarity is there for that.

Disclosure: MissionAssist is my company, and paid work like Digital Clarity is how I make my living. Everything here is free to use on your own — whether we ever work together or not.

Author: Weston Cox — founder of Tomorrow Labs and MissionAssist; a decade in nonprofit digital. Portland, OR.