An AI policy gives your nonprofit clarity on how AI tools are used. Learn what an AI policy should cover, why you need one, and how to develop one practically.
AI is now a routine part of nonprofit work, whether boards have formally noticed or not. Staff are using it to draft proposals, summarize documents, respond to emails, and analyze data. Without a clear policy, your organization is making AI decisions one staffer at a time.
This guide covers what an AI policy should cover, why your nonprofit needs one, and how to develop a practical, light-weight policy without over-engineering it.
TL;DR: Quick Answers
- What is an AI policy? A short document that defines how AI tools are used in your nonprofit, who’s responsible, and what’s off-limits.
- Why do you need one? To protect confidentiality, ensure accuracy, comply with funder requirements, and give staff clarity.
- Who owns it? Usually the executive director, with board endorsement; updated annually.
- How long should it be? One to three pages for most small and mid-sized nonprofits.
Why an AI Policy Matters
Three reasons:
1. Confidentiality. Staff using consumer AI tools may be entering donor information, client data, or sensitive program information into systems they don’t fully understand. A policy clarifies what data can and can’t be shared.
2. Accuracy and accountability. AI generates fluent text, including fluent text that’s wrong. Without policy, an inaccurate AI-generated claim can end up in a grant report or external communication. See can funders tell if a grant was written by AI.
3. Funder compliance. Some funders require disclosure of AI use; some federal research funders restrict it. A policy ensures the organization can comply consistently.
Beyond risk, policy also unlocks responsible use. A clear “yes, here’s how” beats vague anxiety any day.
What to Cover
A practical AI policy typically addresses:
1. Scope. Which AI tools the policy covers, generative AI for writing, transcription, image generation, analysis, others.
2. Permitted uses. Drafting and editing, brainstorming, summarization, research support, grant writing, and similar productivity uses.
3. Restricted uses. What you don’t want AI doing without explicit approval, generating final-facing public statements without human review, making decisions about clients, creating fundraising appeals attributed to specific donors, etc.
4. Confidentiality and data handling. What data can and can’t be entered into AI tools. Donor PII, client personal information, financial records, HIPAA-protected information, and other sensitive data warrant care.
5. Human review requirements. All AI-generated content that goes external must be reviewed by a human. Anything making factual claims must be verified.
6. Voice and authenticity. AI-drafted content should reflect the organization’s voice, see training AI on your past proposals and making AI-written grants sound human.
7. Disclosure. When the organization will disclose AI use to funders, partners, or the public. Funder disclosure requirements should be followed, see can funders tell if a grant was written by AI.
8. Vendor and tool approval. Which tools the organization has approved; how new tools get evaluated, see best practices for evaluating AI software.
9. Training and support. How staff learn responsible use.
10. Review cycle. When the policy gets updated. AI changes fast; annual review is reasonable.
Two Common AI Policy Pitfalls
Over-restriction. Policies that effectively ban AI lose the productivity gains and drive use underground. Staff will use AI anyway; better to permit responsibly.
Under-restriction. Policies that say “use AI as appropriate” without defining what’s appropriate leave high-risk uses uncovered.
The goal is a middle path: clear yes, clear no, clear how.
Confidentiality in Practice
A few practical rules that often go into AI policies:
- No client PII in consumer AI tools. Names, addresses, identifying details, health information.
- No donor financial data. Especially identifiable giving records.
- No legally protected data without explicit safeguards. HIPAA, FERPA, GLBA, state privacy laws.
- Caution with personnel records. HR data warrants special care.
- Use of enterprise tools with appropriate data agreements for higher-sensitivity work.
Many AI tools now offer enterprise tiers with stricter data handling, see best practices for evaluating AI software. Match the tool to the sensitivity of the work.
Disclosure Norms
A widely workable rule: disclose AI use when asked, follow the funder’s published policy, and ensure that whatever you submit is genuinely your organization’s, with human responsibility. See can funders tell if a grant was written by AI for the funder-policy landscape.
Who Decides
In most small and mid-sized nonprofits, the AI policy is:
- Drafted by leadership, often the ED with input from staff.
- Reviewed by the board, especially the audit/risk or governance committee.
- Approved at the board level.
- Communicated to all staff with training.
- Updated annually, more often if landscape shifts.
The board doesn’t need to micromanage AI use; they should ensure the organization has a policy and is following it.
How AI Policies Connect to Operations
A clean policy supports rather than constrains:
- Grant writing. Staff can use AI tools confidently, knowing the boundaries.
- Donor and client communications. Clarity on what’s appropriate.
- Program work. Where AI is used in service delivery, the policy frames it.
- Funder relationships. Disclosure norms are consistent across applications and reports.
Without a policy, every decision is improvised. With one, the organization scales its AI use without scaling its risk.
How Grantboost Helps
Grantboost is built for responsible AI use in grant writing. It learns your organization’s voice (see training AI on your past proposals) and drafts proposals that already reflect your authentic content, with human review built into the workflow. A clear AI policy plus the right tooling makes the productivity gains accessible while keeping the risk manageable.
Try Grantboost free and operationalize AI in your grant writing responsibly.
Read next:
- Best Practices for Evaluating AI Software
- Can Funders Tell If a Grant Was Written by AI? What Reviewers Actually Notice
- Training AI on Your Past Proposals: Why Your Best Grant Writer Is Your Archive
Further Reading
- NIST AI Risk Management Framework
- Anthropic documentation
- OpenAI documentation
- Stanford Human-Centered AI Institute
- National Council of Nonprofits
- Grant Professionals Association (GPA)
Disclaimer: Grant programs, eligibility rules, deadlines, and policies vary by region and change frequently. The information in this article is for general informational purposes only and may not reflect the current rules in your area. Always consult a local grant writer or qualified expert in your region for advice specific to your organization, project, and jurisdiction.