Nonprofits Need Realistic AI Policies + a Free Resource
- Gillia Bakie

- Jul 6
- 7 min read
July 6, 2026
AI is no longer a future-facing question for nonprofits. It is already here.
Staff are using AI to draft emails, summarize meeting notes, create grant language, analyze data, polish reports, build presentations, generate social media content, and move faster through the daily work of running mission-driven organizations.
In many cases, they may be using AI without even thinking of it as “AI,” because it is increasingly embedded in the tools nonprofits already rely on: Microsoft 365, Google Workspace, Canva, Zoom, Salesforce, CRMs, email platforms, transcription tools, project management systems, and document storage platforms.
That means the central question is not should you use AI, it's: How can nonprofits use AI responsibly, practically, and safely?
The old guidance is not enough
A lot of early AI policy guidance for organizations sounded something like this:
“Do not put sensitive data into AI." But as our tools evolve, so does the data already being shared with AI platforms.
For nonprofits using tools like Microsoft Copilot, Google Gemini, ChatGPT Team or Enterprise, Claude Team or Enterprise, AI meeting assistants, or AI tools connected to shared drives and workspaces, sensitive data may already be part of the environment.
AI may be able to interact with internal documents, meeting transcripts, emails, donor materials, board packets, grant drafts, program reports, HR files, or client-related documents depending on how accounts and permissions are configured. Many organizations hold sensitive information about donors, staff, volunteers, clients, students, families, community members, partners, finances, and strategy.
The answer cannot simply be: “Never use AI with sensitive information.” That places too much burden on individual staff and too little responsibility on the organization to create safe systems. A stronger approach is to shift from individual avoidance to organizational governance.
The policy standard: approved tools, accounts, devices, and settings
A practical nonprofit AI policy should make several things clear:
Staff should use organization-approved AI tools for organization work.
They should use organizational accounts, not personal accounts.
AI tools should be configured so organizational data is not used to train public or general AI models where that setting is available.
AI tools should be used only on approved organizational devices, or on devices that meet the organization’s security standards.
AI tools should not be connected to shared drives, email, CRMs, HR systems, finance systems, or other organizational platforms without approval.
Staff must understand that AI can support their work, but it does not replace their judgment, responsibility, or accountability.
AI governance cannot effectively rely on every staff member making a perfect decision every time they open a browser window. Nonprofits need to create the conditions for responsible use through approved systems, secure configurations, role-based access, training, and clear expectations.
Personal AI accounts are a major risk
One of the clearest policy lines for nonprofits should be this:
Do not use personal AI accounts for organizational work involving organizational content, data, documents, or systems.
That includes using a personal ChatGPT, Claude, Gemini, Grammarly, transcription, design, or summarization account to process nonprofit work materials.
This does not mean every casual brainstorm is a critical issue, but once staff are uploading grant drafts, donor communications, board notes, program reports, client-related information, internal strategy, or meeting transcripts, the organization needs to know where that information is going, what settings apply, whether data may be retained or used for model training, and who controls access.
A personal AI account is not governed by the organization. The organization may not be able to manage settings, revoke access, confirm retention practices, audit use, or protect information when a staff person leaves. Investing in organizational accounts, for most nonprofits, is a critical step that needs to be taken as early as possible so personal accounts don't default to a part of the staff workstream and administrative ecosystem.
“No sensitive data” is not enough
Sensitive data should not go into unapproved AI tools. That remains an important rule.
But the more realistic standard is:
Sensitive data may only be used in AI systems that are approved by the organization, accessed through organizational accounts, configured with appropriate privacy and security settings, and used on approved devices by authorized users.
This is especially important for nonprofits using AI tools that integrate with Microsoft 365, Google Drive, SharePoint, Slack, Teams, Salesforce, or other internal platforms. In those environments, the key question is not only what someone pastes into a chatbot. It is also what the AI tool can access through permissions and connectors.
Good AI policy should therefore address:
Which tools are approved.
Which data each tool may access.
Which users are authorized.
Which connectors are allowed.
Whether model training is disabled.
What device standards apply.
Who owns ongoing review.
What uses require additional approval.
And these policies need to be regularly updated and reviewed as tools and systems rapidly change.
Disclosure requirements should be meaningful and focused
Disclosure is another area where nonprofits need nuance.
A blanket rule that says “disclose anytime AI was used” may sound transparent, but it quickly becomes unworkable. AI is now embedded in grammar tools, search tools, design tools, writing assistants, transcription software, email platforms, spreadsheets, and productivity suites. If every AI-assisted sentence, summary, outline, or formatting change required disclosure, disclosure would become noise.
Instead, nonprofits should ask: When would disclosure preserve trust?
Disclosure is more likely to matter when AI materially shapes:
Public-facing reports or research.
Evaluation findings.
Donor- or funder-facing analysis.
Chatbots or automated interactions with the public.
Communications with clients, students, beneficiaries, or community members.
Synthetic images, video, voice, or testimonials.
Recommendations that may affect people’s access to services, opportunities, employment, funding, or organizational decisions.
Routine AI-assisted brainstorming, grammar review, formatting, internal drafting, or summarization may not require disclosure, as long as a human reviews and takes responsibility for the final work. Disclosure may or may not be recommended in areas where AI may be tacitly accepted (as AI perspectives change) but not overtly supported.
AI can support work, but humans remain accountable
For nonprofits, the human accountability principle is essential.
AI-generated content may sound polished and confident, but it can still be wrong. It can invent facts, misstate requirements, flatten nuance, reinforce bias, or produce language that does not reflect an organization’s values or community relationships.
That means staff remain responsible for reviewing AI-assisted work for:
Accuracy.
Confidentiality.
Tone.
Bias.
Equity.
Accessibility.
Cultural responsiveness.
Legal or funder requirements.
Alignment with mission and values.
This is especially important in fundraising, communications, grant writing, evaluation, advocacy, HR, and direct service contexts. AI can help draft, synthesize, and organize. It should not make final decisions about people, replace lived experience, or substitute for relationship-based judgment.
What a strong nonprofit AI policy should include
At minimum, a nonprofit AI policy should address:
Approved tools and accounts: Which AI systems staff may use, under what account structure, and for what purposes.
Personal account restrictions: Clear rules against using personal AI accounts for organizational work involving organizational content or data.
Privacy and model training settings: Requirements that organizational data not be used to train public or general AI models where configurable.
Device standards: Rules requiring AI access from approved organizational devices or devices that meet minimum security standards.
Connectors and integrations: Approval requirements before connecting AI tools to Drive, Microsoft 365, email, calendars, Slack, CRMs, HR, finance, or other systems.
Data use categories: Clear distinctions between public, internal, sensitive, restricted, and prohibited data uses.
Human review: Expectations for fact-checking, editing, bias review, and final approval.
Disclosure framework: Guidance on when AI disclosure is meaningful, required, or unnecessary.
Restricted and prohibited uses: Clear boundaries around HR, eligibility, service decisions, legal matters, financial determinations, impersonation, synthetic media, and automated decisions about people.
Training and review: A plan for staff training, tool review, policy updates, and incident response.
The board and leadership role
AI governance should not sit only with one staff member who is “good at technology.”
It requires leadership attention because it touches risk, trust, data, labor, equity, communications, fundraising, programs, and governance. Boards and executive teams should be asking:
What AI tools are staff already using?
Are staff using personal accounts or organizational accounts?
What organizational systems are connected to AI?
What sensitive data could AI access?
What settings are in place to prevent training on organizational data?
What tools are approved for which uses?
What uses are restricted or prohibited?
What training do staff need?
When should we disclose AI use?
How will we monitor and update this policy over time?
This is a critical, emerging, and ongoing governance question that must be held throughout the organization in order to capitalize ethically, safely, and effectively on emerging technology.
AI policy is not about fear. It is about readiness.
The nonprofits that handle AI well will not necessarily be the ones that ban it or embrace it without limits. They will be the ones that build clear, practical, mission-aligned systems for using it responsibly.
AI can help nonprofit teams reduce administrative burden, improve drafting and analysis, strengthen internal knowledge management, and make better use of limited time. But only if organizations pair experimentation with governance.
A good AI policy should make safe use easier, not harder. It should help staff understand what is allowed, what requires review, what is prohibited, and where to go with questions.
Most importantly, it should reflect how AI is actually being used.
Because for nonprofits, trust is not a side issue. It is the work.
Featured Resource
To help nonprofit leaders move from conversation to implementation, Flicker Consulting has developed a practical Nonprofit AI Use Policy Resource Packet that includes:
A nonprofit AI acceptable use policy template.
Staff AI use checklist.
AI risk matrix.
Approved AI systems and data access register.
AI disclosure decision framework.
Board and leadership discussion guide.
Staff training agenda.
Implementation roadmap.
Authorship and responsible AI use language.
Disclaimer and review language for organizational adaptation.
This resource is designed to help nonprofits adopt AI thoughtfully, with clear standards for organizational accounts, approved devices, privacy settings, connectors, sensitive data, human review, and meaningful disclosure.
Click below to download the packet or reach out to talk through how to implement AI policy at your organization.



Comments