AI Policy for Nonprofits: A Practical Governance Template

Content authorArtem LozinskyPublished onReading time15 min read
A light blue infographic featuring a central translucent card labeled 'AI Policy for Nonprofits' with branching flowcharts and stakeholder silhouettes.

This article walks you through building an AI policy for nonprofits based on what your staff already do. You'll get plain-language principles and use boundaries, with safeguards built into a copy-ready template and an implementation checklist you can adapt this week.

Why your first policy matters more than perfect

An AI policy for nonprofits starts with an uncomfortable truth: your staff are almost certainly using these tools already, whether or not anyone signed off on it. A 2026 Virtuous survey of nonprofit organizations found that 81% use AI on an ad hoc basis without documented workflows, and 47% have no governance policy at all. The gap between what people do and what the organization has agreed to is where the risk lives.

This guide is for the moment you realize that gap exists and want to close it without hiring a compliance department. A clear picture of current use and boundaries staff can follow provide the foundation for a workable AI policy for nonprofits. You also need a plan for when something goes wrong.

Start with current AI use

Before you write a single rule, find out what's happening. The instinct is to draft principles first, but an AI policy for nonprofits built on guesses protects nobody. Start by mapping the tools people already reach for and who uses them. Record what data goes in and comes out.

Build a short inventory that captures each of these:

  • The tool and its vendor, including free consumer accounts and AI features baked into software you already pay for

  • Record who uses it and what data they enter. Note how the output is used and which decisions it influences

Once you have that list, rank the uses by risk. A volunteer using ChatGPT to reword a public newsletter is a different conversation from a caseworker pasting client notes into a chatbot. Pull in the people who understand the work. That group should include program and fundraising staff. It should also include whoever handles information technology (IT) and privacy, as well as human resources (HR). Where you can, include representatives of the communities you serve. This discovery step grounds an AI policy for nonprofits in your actual operations.

AI policy for nonprofits

Start the document itself by defining who it covers. Scope should reach employees and volunteers, along with contractors and board members. It should cover both free and paid tools, including AI features embedded in existing software. Make clear that the AI policy for nonprofits applies whether content or a decision was produced entirely by AI or only partly with its help. That last point closes the loophole where someone claims a lightly edited AI draft doesn't count. Then set out the ethical AI guidelines for nonprofits in plain language, because staff won't follow rules they can't understand.

A workable AI policy for nonprofits rests on a handful of commitments:

  • Mission alignment and meaningful human control over what AI produces

  • Every output should protect privacy and ensure fairness. Clear accountability requires transparency as well as security

Amy Sample Ward, CEO of the Nonprofit Technology Enterprise Network (NTEN), argues that data discipline comes first. Nonprofits "should have a clear policy on data collection and retention," Ward said, because "if you gathered data without consent, then you'll also be using that data without consent when sharing it with A.I." Record the document's owner and approval date. Add its version number and review schedule. Link it to your privacy and security policies, as well as the policies governing records and HR. Include the communications policy so the document remains connected to related organizational rules.

Set clear use boundaries

Calm SaaS infographic featuring a central white card with a shield icon for 'AI Governance' and three surrounding cards on permitted uses.

"Use AI responsibly" merely expresses a wish. Staff facing a real deadline need to know which side of the line a task falls on, so sort AI activities into permitted and prohibited uses. Activities between those categories require approval. Base each bucket on the potential for harm and the sensitivity of the data. Also consider whether a mistake can be undone and how strongly the output affects a person's rights or access. Account separately for effects on reputation and safety.

The distinction pays off. The Virtuous report found that organizations with enabling governance achieve major impact at higher rates than organizations with restrictive policies or none at all. Such nonprofit AI governance uses clear policies about encouraged and prohibited activity, with approval requirements for uses in between. Use nonprofit examples throughout so fundraisers and communications leads recognize their own work in the rules. Program managers should recognize theirs as well.

Permitted low-risk uses

These are the tasks staff can do with approved tools and ordinary review, without asking anyone first. Think of campaign brainstorming and reformatting text that contains nothing sensitive. Drafting an internal outline or summarizing information that's already public also fits. The point is to free people from seeking case-by-case permission for work that carries little downside.

Permitted doesn't mean unchecked, though. Staff still verify what the tool produces and follow copyright rules. They also keep confidential information out of the prompt. Tailor the examples in your AI policy for nonprofits to the workflows people actually run each day, because a generic list teaches nobody what "low-risk" looks like in your organization.

Need help with your AI visibility?

Book a free consultation with our experts we'll help you determine exactly which services your organization needs.

Approval-required uses

Some uses are promising enough to try but carry enough risk to require review before launch. Donor segmentation and grant scoring belong here. So do a beneficiary-facing chatbot and translation of critical information. HR support and any analysis touching confidential data also require approval. Each one needs documented sign-off before it goes live.

Approval should weigh the purpose and the people affected. Review the data involved and the vendor's terms, then assess the risk of bias and the human oversight in place. The fallback if the tool fails also belongs in the assessment. Name an owner for the use and require a testing plan before an approved pilot becomes routine practice. This is the stage where a good idea undergoes pressure testing.

Prohibited AI uses

Some things are simply off the table. Ban entry of sensitive donor or beneficiary data into unapproved tools. The ban should also cover employee and health information. Include financial and credential data as well. Apply it to case-management data too. The reason is concrete: consumer AI accounts reuse inputs. OpenAI states that free and Plus plan data can be used to train models unless a user opts out, while business tiers are excluded by default.

Prohibit fully automated high-impact decisions and impersonation. Also ban deceptive synthetic media and fabricated citations. Unlawful surveillance is prohibited as well. Any use that breaks a contract or violates the organization's values is prohibited. Make one thing explicit: convenience and a vendor's marketing claim do not automatically make a risky use safe. Risk remains after a person's name is stripped from a record. Re-identification is easier than it looks, so the ban has to hold for data described as anonymized.

Build practical safeguards

Ethical AI guidelines for nonprofits are easy to write and hard to apply. Safeguards close that distance by turning broad ideas into checks before data entry or output acceptance. A final check also occurs before publication. Safeguards tighten with confidentiality and potential harm. Decision impact can tighten them further.

This approach mirrors the NIST AI Risk Management Framework. The framework starts with Govern and Map before moving to Measure and Manage; its functions ask who approves high-risk uses and how incidents get handled. A team without a dedicated compliance function can apply the framework through the simple evidence and review requirements of an AI policy for nonprofits. Clear escalation requirements complete the approach.

Protect sensitive data

Define what "sensitive" means in your world, with examples staff recognize. That covers donors and beneficiaries, including minors. It also covers employees and volunteers. Payment details and protected health information are sensitive as well. The same applies to immigration status and case records. Vague categories get ignored, so name them.

Then require data minimization, which the General Data Protection Regulation (GDPR) sets out in Article 5(1)(c) as keeping personal data "adequate, relevant and limited to what is necessary." Approve storage and retention practices, and control who can access what. Confirm that prompts or uploads won't be reused for model training where that's unacceptable. When you de-identify, account for whether scattered details could be recombined to identify someone again. The stakes are real for the sector: the BBB Wise Giving Alliance found that 28% of donors would not give to a nonprofit again if their data had been stolen from the group.

Verify facts and sources

AI writes with confidence whether or not it's right, so require staff to check factual claims and calculations against reliable original sources before use. Quotations and citations require the same check, as do links. An AI-generated citation is not evidence. The person approving the work owns the accuracy of the final output, full stop.

The cost of skipping this step is documented. In the 2023 case Mata v. Avianca, a lawyer submitted a brief with six fabricated citations from ChatGPT and drew a $5,000 fine, and a Bloomberg Law analysis has since counted over 280 court filings containing hallucinated citations. Apply stricter review to anything legal or medical. Financial and safety-related work also requires stricter review. The same applies to work tied to grant compliance or facing the public.

Check rights and fairness

Models learn from historical data, and history carries bias. That's how AI can reproduce discrimination and exclude communities. It can also produce different outcomes across demographic groups. When a use could shape services or funding, test it with representative scenarios and bring in program staff or affected communities. Employment and outreach uses require the same approach.

The danger isn't theoretical for organizations serving vulnerable people. A 2025 study in BMC Medical Informatics and Decision Making tested AI summaries of 617 real social care case notes and found Google's Gemma model described men's needs with words like "disabled" and "complex" far more often than women's with similar needs. On copyright, require lawful source material and respect licenses and permissions. Run originality checks where it matters. Escalate when ownership or fair-use questions aren't clear.

Need help with your AI visibility?

Book a free consultation with our experts we'll help you determine exactly which services your organization needs.

Ethical AI guidelines for nonprofits

Strong ethical AI guidelines for nonprofits define what human approval actually means. Say who reviews the output and what evidence they examine. Define when they must reject it or escalate. "A human looked at it" is not oversight if that human had nothing to check against.

The EU AI Act's Article 14 frames this well for high-risk systems. It requires that people can "monitor, interpret, and override" an AI and stay aware of over-reliance on its outputs. Your ethical AI guidelines for nonprofits should also require disclosure when AI involvement would materially affect stakeholder trust or informed consent. Disclosure is also required when AI involvement affects someone's understanding of how content or a decision was made. Word that disclosure so it's specific enough to be useful without overstating what you actually know about the system. Building ethical AI guidelines for nonprofits this way makes the human accountable.

Assess every AI vendor

A tool is only as safe as the company behind it, and marketing pages don't tell you what a contract does. Review each vendor in proportion to the risk. Examine data use and ownership, then determine whether your inputs train the model. Check retention and deletion alongside security controls. Identify subprocessors and where data is hosted. Look also at confidentiality terms and accessibility. Review bias testing and incident notification. Check audit rights and service continuity. Examine how termination works.

Read the actual contract and privacy documentation to verify homepage claims and default consumer settings. Vendor commitments vary in ways that matter: Microsoft states that Copilot and Azure OpenAI customer data is never used to train foundation models, and Anthropic has publicly committed to no training on enterprise data. Any tool that handles sensitive data or supports a high-impact decision needs deeper review. Involve IT and privacy staff, with security and procurement input as your size allows. Seek legal input as well. Every approved vendor and use case should land in the maintained inventory supporting your AI policy for nonprofits, the same living list you started during discovery.

Assign owners and responses

The fear that nonprofit AI governance requires a big committee stops many organizations before they start. In practice, organizations can move forward. What you need is a role structure that scales to your staff and risk level, so responsibility is clear even when one person wears several hats.

Separate the jobs even if the same person holds them. Distinguish ownership of the AI policy for nonprofits from use-case approval. Assign technical review and legal or privacy advice. Define day-to-day staff responsibility and executive accountability. Establish board oversight as well. Just as important, give employees a reporting path so they can pause a questionable use without fear and know exactly who handles suspected harm or a data exposure. A caseworker who spots a problem shouldn't have to guess who to tell.

Nonprofit AI governance roles

Sound nonprofit AI governance assigns an executive sponsor and a policy owner. It also identifies a technical or security reviewer and a privacy or legal reviewer. Add a departmental use-case owner and a board liaison. In a small organization, one person can legitimately hold several of these. Clearly defined decision rights matter most.

Spell out who approves tools and who grants exceptions. Identify who maintains the inventory and who trains staff. Define who monitors performance and who reports material risks upward. Effective nonprofit AI governance also pulls in program experts and representatives of affected communities whenever a use could shape services or opportunities, because the people closest to the harm see it first. Clear responsibilities make nonprofit AI governance durable enough to survive contact with a busy week.

AI incident response

Decide in advance what counts as a reportable incident. Sensitive-data disclosure and harmful or biased output qualify. So do misinformation and a copyright complaint. An unauthorized tool or a security event also requires reporting. The same applies to an AI-supported decision made without required review. Naming these ahead of time means nobody has to improvise judgment during a crisis.

Then lay out the sequence. Stop or isolate the use and preserve the evidence. Then notify the owner. Assess who was affected and what obligations you have. Contain the harm and communicate appropriately. Document the corrective action. Connect this to your existing security and privacy plans. Tie in safeguarding and insurance plans as well. Add the crisis-communications plan, because an integrated process is easier to remember. The financial stakes justify the effort: BDO reports the average cost of a nonprofit data breach reaching up to $2 million once recovery and legal fees are counted. That figure also reflects reputational repair.

Adapt the policy template

Here's the part that saves you from the blank page. Build a copy-ready template for an AI policy for nonprofits with bracketed fields for purpose and scope. Add definitions and principles, followed by permitted and prohibited uses. Include approval-required uses between those categories. Add sections for data protection and accuracy and source verification. Include copyright and fairness, followed by human review and disclosure. Add vendor assessment and roles. Include incidents and training, along with exceptions and enforcement. Finish with review dates.

Write short drafting notes beside each section telling leaders what to customize and which clauses should point back to existing organizational policies. Keep the core document short enough that staff will read it, and push the detailed workflows and approved-tool lists into appendices you can update more often. Put assessment forms there too. You don't have to invent the structure alone: NTEN's Generative AI Use Policy and templates from Community IT and Emerson Collective give you a tested starting shape. Flag any provision touching privacy or employment for review by qualified legal counsel. Do the same for intellectual property and fundraising. Regulated services and contracts also require review. Jurisdictional duties do too, because a template is a starting point and advice must reflect your specific situation.

Implement and review it

A signed PDF is not a program. Move the policy from document to practice with a sequenced checklist:

  1. After confirming leadership sponsorship, complete the inventory. Use it to classify your uses

  2. Adapt the template with input from affected teams. Obtain legal and board review where it's warranted

  3. Approve tools and train users. Then publish the reporting channels and record who acknowledged the rules

Pilot the AI policy for nonprofits on a few real workflows before organization-wide rollout, since unclear rules surface fastest when someone tries to follow them under deadline. Set a review cadence matched to your risk, with earlier triggers when tools or laws change. Vendor changes and incidents also trigger earlier review. A significant new use case does too. Treat your first AI policy for nonprofits as a baseline that grows through monitoring and staff feedback. If you want help turning that baseline into working governance, Layer3 Labs helps nonprofits map approved tools to real workflows and keep donor and beneficiary data handled safely, so book a consultation to scope it.

Need help with your AI visibility?

Book a free consultation with our experts we'll help you determine exactly which services your organization needs.

Start with a confidential inventory, then pause uses that expose sensitive data or affect people’s rights. Ask staff to identify the tool, task, and data type involved. Provide approved alternatives before enforcement begins, because a complete inventory reduces hidden use and gives leaders a factual basis for decisions.

Set a written review date and revisit the ai policy for nonprofits earlier after a vendor change, incident, legal change, or significant new use case. The policy owner should record revisions and approval dates. Regular review keeps approved tools, data rules, and reporting contacts current.

Use free AI accounts only for low-risk work with public, non-sensitive information when your policy permits them. Check the provider’s data terms before use, since consumer accounts can use prompts or uploads for model training. Staff should never enter donor, beneficiary, employee, health, financial, or case-management data.

A beneficiary-facing chatbot requires documented approval before launch. The use-case owner should obtain technical and privacy review, assess bias and accessibility, and test the chatbot with representative scenarios. Set a human fallback route for questions it can’t answer safely, especially where services or eligibility are involved.

Layer3 Labs helps nonprofits map approved AI tools to real workflows and address donor and beneficiary data handling. Organizations should still ask qualified legal counsel to review clauses involving privacy, employment, intellectual property, contracts, or regulated services, because those duties depend on the organization and jurisdiction.

Book a Demo

Book a time that works best for you

You Might Also Like

Discover more insights and articles

An airy infographic featuring a central 'Trust' card surrounded by translucent strategy steps, metrics, and icons on a blue gradient background.

Nonprofit Brand Strategy: A Step-by-Step Framework for Building Trust

This article lays out a reusable framework for defining what your organization stands for and proving your claims with evidence. It covers research through measurement.

Calm infographic showcasing 'Tailored AI Training for Nonprofit Staff' with role-specific cards and best practices in a clean layout.

AI Training for Nonprofits: A Practical Curriculum for Teams

This article lays out a curriculum for turning scattered AI experiments across your staff into shared, documented practice. It covers how to assess skills and risks and design role-specific learning.

Infographic illustrating the nonprofit donor journey with rounded cards for each stage, set against a light blue to white gradient background.

Donor Journey Mapping for Nonprofits: From First Contact to Long-Term Support

This article gives you a practical framework for donor journey mapping, from the moment someone discovers your cause through recurring support and advocacy. You will learn how to pick a priority persona and map each stage of the nonprofit donor journey. The finished map then becomes a guide for coordinated fixes across your website and email, with search and campaigns folded into the same effort.

A layered SaaS infographic featuring a central translucent card showing the nonprofit logo design process, surrounded by mini-cards for key phases.

Nonprofit Logo Design: How to Create a Trustworthy Mission-Driven Logo

This article walks a small or newly formed nonprofit through nonprofit logo design without an in-house designer. It explains how to build the brief and choose a design direction, then takes the team through the remaining design process.