Template

Nonprofit AI Use Policy Template

A board adoptable AI policy: scope, permitted and prohibited uses, a four level data classification table, a register of approved tools, the nine questions to ask a vendor, and disclosure positions. Free Word download. The core rule is that donor data never goes into a consumer chatbot.

Most nonprofit AI incidents are not sophisticated. They are a well meaning staff member pasting a donor list into a free chatbot to get a mail merge sorted, because nobody had ever told them which tools were approved for which kind of information.

A policy fixes that, and it is the cheapest risk control available to you. This is a Word file written to be adopted broadly as it stands, with a board sign off block at the end.

The part that actually does the work

Section 5 of the template is a data classification table. If you take nothing else from this page, take this and put it somewhere people see it.

Class Examples May be used with
A. Public Your website, published filings, press releases Any tool
B. Internal Draft plans, internal memos, correspondence with no personal data Approved tools only
C. Confidential Donor names, gift amounts, contact details, giving histories, employment records, board papers Approved tools with a signed agreement. Never a consumer tool.
D. Sensitive Health information, immigration status, safeguarding, service user records, anything about a child, hardship narratives Not in any AI tool without written approval

The distinction that carries most of the weight is between a consumer tool and a contracted one. A free or personal account has no agreement between the vendor and your organization, which means no commitment about training, retention, or who can see what. That is fine for rewriting a newsletter paragraph. It is not fine for anything in class C.

What the policy covers

Section What it settles
1 to 3. Purpose, scope, definitions That it covers volunteers, board and contractors, and personal accounts used for work
4. Permitted and prohibited uses The operative list, including no final decisions about people
5. Data classification Which class of information may touch which class of tool
6. Register of approved tools Nothing outside the register may be used above class A
7. Vendor questions Nine questions to answer in writing before approving anything
8. Accountability The user owns the output, and factual claims are verified at source
9. Transparency When you disclose AI involvement, including to funders
10 to 12. Training, consequences, adoption Reporting without blame, annual review, board signatures

The nine questions to ask a vendor

Ask them in writing. A vendor unwilling to answer in writing has answered.

Question Answer you need
Is our data used to train models, and can we opt out No, or a documented opt out
Is our data isolated from other customers Yes
Where is data stored and processed A named location
Who at the vendor can access it, and when A documented answer
Is personal data removed before processing, and at what point Before indexing, not only at output
Can we export everything, and in what format Yes
What is retained after cancellation, and for how long A stated period
Is there an independent audit, such as SOC 2 Yes, or a stated timeline
Does output cite the records it used Yes, for anything factual

The fifth is the one people miss and it separates serious products from the rest. Redacting personal data from what is displayed to a user is cosmetic if the underlying system already ingested and indexed it. The meaningful control removes identifiers before anything reaches an index, an embedding or a prompt. Ask specifically at which point it happens.

The eighth is where most of this category currently falls short, including products we rate well. It is reasonable to accept a stated timeline rather than an existing certification, and it is not reasonable to skip the question.

What the policy should prohibit outright

Four things, and they are in the template.

Confidential information in a consumer tool. The single most common failure and the easiest to prevent.

Final decisions about people. No AI tool decides employment, a grant to an individual, or eligibility for a service. A named person decides, having read the material themselves.

Unverified facts published externally. Any figure, quotation, citation or legal reference generated by a tool is checked at source before it leaves the organization. Confident and wrong is the normal failure mode of these systems, not a rare one.

Synthetic images of real people. Particularly of clients or beneficiaries, presented as real. The reputational exposure is severe and entirely avoidable.

Disclosure, which is a board decision rather than a technical one

The template offers positions rather than dictating one, because reasonable organizations differ and the right answer depends on what your board is willing to defend publicly.

Routine drafting that a person then edits does not generally warrant disclosure. Substantially AI generated public content does. Images that could be mistaken for photographs should be labelled or not used.

Grant applications deserve particular care. Follow each funder’s stated rule, and where a funder is silent, assume disclosure is expected rather than assuming it is not. Funders are actively writing these rules now and a mismatch discovered later is a serious problem with a relationship you depend on.

Which tools belong in the register

For most organizations the honest answer is a small list. A general purpose assistant approved for class A and B work covers the majority of the realistic benefit, at a free tier or roughly $20 a month, and it is where almost every nonprofit should start.

Tools that connect directly to donor records are a different decision with a different price and a different level of scrutiny. If you are considering one, the questions above are the minimum and the assessment belongs in the register with a date and an approver. We set out what that category does, what it costs, and who it suits in AI tools for nonprofit fundraising.

The gap most policies miss

Nearly every policy in circulation is written as though AI is something staff go to a website to use. Increasingly it is not. It arrives as a feature inside software you already run and already approved: a summarise button in your email, a drafting assistant in your word processor, note taking in your video calls, scoring built into your CRM.

Nobody signs up for these and nobody thinks of them as adopting an AI tool, so they sit outside a register that only lists products someone chose. That is the most likely route by which confidential information reaches a system your policy never assessed.

Two provisions handle it. Define an AI tool to include features built into existing software, which the template does in section 3. And add a line to the register review asking what has changed in the tools you already have, rather than only what has been added. A meeting transcription feature switched on by default in a video platform will process a board discussion about a staff member, and nobody will have decided that it should.

Making it real

A policy nobody has read does nothing, which is why the template sets a training requirement rather than assuming one.

Three things make the difference. Everyone reads it at induction and annually, including board members and volunteers. Mistakes and near misses are reported without blame, because a policy that punishes disclosure guarantees you find out late. And the register is reviewed at least annually, because the tools your staff use will change faster than your policy does.

Adopt it, minute it, and diary the review. The version that sits unread in a shared drive is the version that will not help you when it matters.

Download this template

Free, no email address, no signup. The full text is on this page as well, so you can read it before you download it.

Questions people ask

Does a nonprofit need an AI policy?

If anyone in your organization uses AI tools for work, and they do, then yes. The policy is not about restricting a technology. It is about establishing which information may go where, which nobody can guess.

The realistic risk is not a dramatic breach. It is a volunteer pasting a donor list into a free chatbot to sort out a mail merge, because there was no rule and it seemed helpful. That is a disclosure of donor data to a third party under no agreement with you, and it is entirely preventable with one page of clear guidance.

Boards are increasingly asking for this, and several funders now ask about it directly.

What should a nonprofit AI policy include?

At minimum: who it applies to including volunteers and contractors, a list of permitted and prohibited uses, a data classification scheme saying which information may be used with which tools, a register of approved tools, the requirement that a named person is accountable for any output, and a position on disclosure.

The data classification table is the part that does the real work. Four levels is enough: public, internal, confidential and sensitive. The critical line is that confidential information, which includes all donor records, never goes into a tool you have no agreement with.

Add a training requirement and an annual review, or it will be out of date within a year.

Is it safe to use ChatGPT at a nonprofit?

For work involving no personal data, yes, and it is where most organizations should start. Drafting an appeal, rewriting a newsletter, summarising a funder's guidelines and turning meeting notes into minutes are all fine and genuinely useful.

For anything involving donor or client information on a free or personal account, no. There is no agreement between the vendor and your organization covering how that data is handled, so you cannot tell a donor or a board what happened to it.

The practical rule that fits on a sticker: if you would not put it in an email to a stranger, it does not go in a consumer chatbot.

What is the difference between a consumer AI tool and an approved one?

A contract. A consumer tool is a free or personal account with no agreement between the vendor and your organization, which means no enforceable commitment about training on your data, retention, isolation from other customers, or who can access it.

An approved tool is one your organization has assessed and contracted for, where those answers exist in writing and someone signed off on them. It may be a paid business tier of the same product.

That distinction, rather than which company makes the tool, is what should determine whether donor data may go near it.

Should we tell donors we use AI?

It depends on what you used it for, and it is a board decision rather than a technical one.

Routine drafting that a person then edited does not generally warrant disclosure, on the same basis that you do not disclose using a spell checker or a template. Substantially AI generated public content does. Images that could be mistaken for photographs of real people should be labelled or not used at all.

The test worth applying is whether a donor learning about it later would feel misled. Personal thank you letters are the sensitive case: a supporter who discovers that a heartfelt note was generated and unread may reasonably feel the relationship was not what they thought.

Do funders require AI disclosure in grant applications?

Some now do, and the number is growing quickly. There is no single sector standard yet, so the requirement has to be checked funder by funder for each application.

Where a funder is silent, the safer assumption is that disclosure is expected rather than that it is not. A mismatch discovered after an award is a serious problem with a relationship you depend on, and the downside of disclosing unnecessarily is close to zero.

Whatever you use these tools for in an application, the factual claims, figures and citations must be verified at source before submission. Fabricated references in a grant application are the worst version of this failure.

Who should own the AI policy?

The board adopts it, and a named staff member owns it day to day. In a small organization that is usually the executive director. In a larger one it may sit with operations or finance.

The owner maintains the register of approved tools, receives incident reports, and brings the policy back to the board annually. Without a named owner the register goes stale within months and the policy becomes a document rather than a control.

Keep incident reporting blameless. A policy that punishes people for admitting mistakes guarantees you hear about problems late, which is precisely when they are expensive.

How often should the policy be reviewed?

Annually as a minimum, and additionally whenever you adopt a new tool, whenever a tool you use materially changes what it does with your data, and whenever a funder or regulator introduces a requirement.

The register of approved tools needs more attention than the policy body. The rules about data classification are stable. The list of what your staff actually use changes constantly, and features that quietly add AI to software you already run are the easiest thing to miss.

Diary the review when you adopt the policy. It is the step most often skipped.

This is reference information, not legal or tax advice. Rules vary by state and change over time. For a decision that carries real consequences, check the current text at irs.gov or your state registry, and talk to a nonprofit attorney or CPA.