Using AI responsibly: a one-page policy for nonprofits

The context

AI assistants reach daily use in most nonprofit teams before anyone writes a policy. Without one, each person invents their own rules for privacy, review, and disclosure — usually under deadline. One page settles the recurring questions.

The pattern

Five rules cover most situations:
  1. Say when you used AI internally. Name the tool and roughly how ("Claude drafted this, I rewrote the intro"), so colleagues learn what works.
  2. Keep a human in the loop. AI never makes final decisions about participants, donors, or staff, and important communications get a human review before they go out.
  3. Protect personal data. No names, email addresses, or other identifiable details in chat prompts — anonymize first ("Participant A"). Authorized connectors to your drive or mail run under the vendor's data-processing agreement; use them for work tasks only and keep the data inside.
  4. Keep an approved-tools list. One primary assistant plus a short list of approved integrations, with a quick review before any new tool touches organization data.
  5. Share learnings, failures included. A dedicated chat channel or a recurring workshop slot is enough.
Decision test: would you be comfortable explaining exactly how you used AI to the people affected? If unsure, ask a colleague before proceeding.

What to use

What's mandatory regardless

  • GDPR: personal data in a prompt is data processing. A tool without a data-processing agreement can't receive it.
  • Never create fake content (testimonials, deepfakes) or misrepresent authorship, in either direction.

Your variation

Record your approved tool list, who reviews new integrations, your disclosure norm, and where learnings get shared.