If your staff uses ChatGPT or another AI tool for work—from drafting emails and social posts to summarizing research and analyzing data—relying on an individual employee or volunteer’s judgment alone becomes complicated.

A formal AI policy gives your team clear guidelines on what tools are acceptable, what information can and cannot go into an AI tool, when human review is required, and who employees should contact with their questions.

Nonprofits and associations may handle donor information, member records, client information, volunteer data, certification records, or other information people have entrusted to your organization. An AI policy helps your team use these tools without forfeiting those responsibilities.

Why Every Nonprofit and Association Needs an AI Policy Now

Imagine someone on your marketing team uses AI to brainstorm social post ideas and trends. A staff member uses an AI tool to summarize an article. A volunteer enters a list of member questions into a public AI chatbot to get help writing responses.

None of those uses automatically presents a problem. The problem comes in when employees don’t know where the line is.

For example, is it OK to enter a donor’s giving history into an AI tool to predict future giving? Can AI draft a response to a frustrated continuing education client? Should a staff member use AI to screen job applicants? Who reviews an AI-generated article before it goes on your website?

A policy answers these questions before staff and volunteers have to decide for themselves.

Associations have many of the same concerns as nonprofits, but their AI policies may need to address a few additional use cases.

Activities such as summarizing survey responses, analyzing event data, and personalizing communications involve information that members entrust to you and hope you’ll handle with care. Other association activities involve creating professional content where accuracy and human review are essential. 

That said, an AI policy doesn’t mean staff can’t use AI tools; it clarifies how to do so responsibly.

Build Your Nonprofit AI Policy, Section by Section

You don’t have to write your AI policy from scratch. The nine sections below give you the full framework—what to cover, why it matters, and the questions to answer for each one.

Work through them in order. The right policy for a small community nonprofit won’t look like the one a national association with thousands of members and a large technology stack needs, so treat each section as a prompt to adapt, not a form to copy.

Want more on responsible AI adoption? Our AI Resource Hub has webinars, research, and governance guidance built for nonprofits and associations.

Note: Your policy should reflect the AI tools your team uses, the information you handle, the people you serve, and any legal obligations that apply to your organization. This is for organizational guidance, not legal advice.

What To Include In a Nonprofit AI Policy: The Core Sections

Acceptable and prohibited uses of AI

A useful AI policy should answer a few basic questions: What can employees use AI for? What can’t they use it for? What information can they enter? Who reviews AI-generated work? And who is responsible for the policy?

Your nonprofit AI policy should generally address the following areas.

1. Purpose and Scope

Start your AI policy by explaining why it exists and who it applies to.

For a nonprofit, that might include employees, contractors, interns, and volunteers. Associations may also want to address volunteer leaders, committee members, and other people who have access to association systems or member information.

Be specific about whether the policy applies to:

  • Public AI tools such as ChatGPT
  • AI features built into software the organization already uses
  • AI tools purchased or approved by the organization
  • Free or personal AI accounts used for work

That last point is easy to overlook. For example, if someone does association work from a personal ChatGPT account, your organization may still need to address what information they can enter there.

Keep this section straightforward. Employees should understand what the policy covers without having to interpret technical language.

2. Acceptable Uses of AI

Give your staff and volunteers examples of acceptable (read: lower-risk) AI uses, such as brainstorming, creating outlines, editing grammar, summarizing public information, or generating a first draft that a staff member will review.

Associations might also permit AI for things like brainstorming conference session descriptions, drafting routine member communications, or organizing ideas for an education program.

The examples matter. “Use AI responsibly” is easy to agree with and difficult to interpret consistently.

3. Prohibited or Restricted Uses

This is where your policy draws the line at higher-risk activities. This could mean prohibiting the input of confidential information into AI tools or restricting AI usage for major decisions (such as reviewing employment applications).

Other potentially restricted activities include:

  • Handling donor or member information
  • Making decisions about program eligibility
  • Creating professional or educational content without human/expert review
  • Generating legal, financial, medical, or compliance advice
  • Using AI to make decisions that significantly affect an individual

Focus on uses that could create a meaningful privacy, accuracy, fairness, or reputational problem.

4. AI Data Privacy and Confidential Information

This section should tell employees what information they can and cannot put into an AI tool.

Depending on your organization, that may include donor records, member information, employee files, payment information, client records, unpublished financial information, board materials, or proprietary research.

Associations should also think about information collected through membership databases, conference registrations, surveys, certification programs, online communities, and job boards.

When employees aren’t sure whether something is sensitive, give them a simple rule: don’t enter it until they’ve checked with the appropriate person.

5. Human Oversight of AI

This may be the most important part of the policy.

AI can produce something that sounds confident and is completely wrong. It can also miss context, repeat biases, or make assumptions that a person would catch. That’s why someone should remain responsible for the final result.

For example, AI can help draft a member newsletter. A staff member should still check the dates, names, links, claims, and tone before it goes out.

The same principle applies to a nonprofit’s donor communications or an association’s education content. AI can help with the work, but it shouldn’t quietly become the decision-maker.

6. Accuracy, Attribution, and Transparency

Set expectations for checking AI-generated information before using or publishing it.

This is particularly important for associations because members may rely on association content as a professional resource. A made-up citation or an inaccurate explanation of an industry regulation can quickly damage credibility.

The policy can also address when staff must disclose the use of AI assistance.

7. Bias, Equity, and Accessibility

AI doesn’t necessarily produce neutral results. If your organization uses AI to support hiring, service delivery, member segmentation, program decisions, or other people-related activities, staff should consider whether the output could disadvantage a particular group.

Associations should also think about accessibility when using AI to create educational materials, event content, websites, or member communications.

The policy doesn’t need a technical explanation of algorithmic bias. It simply needs to tell people to question AI output rather than treating it as objective.

8. Approved Tools and Vendor Review

Consider establishing a basic process for deciding which AI tools staff can use for organizational work.

You don’t need a committee to evaluate every new AI feature. But someone should have responsibility for looking at higher-risk tools and asking basic questions about:

  • What data does the tool collect?
  • How is that data stored?
  • Who can access it?
  • What happens when the organization stops using the tool?
  • Does the vendor’s agreement create any concerns?

For a small organization, this might be a short checklist completed by an operations or technology lead. Larger associations may already have vendor review and procurement processes that can incorporate AI.

9. Training and Employee Responsibilities

A policy only works if people understand it.

Training doesn’t have to be a two-hour AI ethics course. A short staff discussion using examples from your actual work may be more useful.

Show employees what happens when someone pastes confidential information into a chatbot, accepts an AI-generated answer without checking it, or uses AI for a task that requires professional judgment.

Also give people somewhere to go with questions. A policy is much easier to follow when employees know who can give them a quick answer.

How To Customize Each Section For Your Organization

The framework in this guide gives you a starting point, not a finished document. To customize your policy, start by asking these questions:

  • What does our organization do? 
  • What information do we handle? 
  • Where are we already using AI tools?

Your answers will tell you where the policy needs more detail.

Consider Your Organization’s Size

A small nonprofit with six employees may not need a formal AI review committee. Its policy might simply name the executive director or operations manager as the person responsible for approving tools and answering questions.

A larger organization may need separate responsibilities for IT, HR, legal or compliance, communications, and department leaders.

Don’t build a governance structure your organization can’t realistically maintain.

Consider Your Mission and Programs

A food pantry, professional association, community foundation, healthcare nonprofit, and youth-serving organization won’t have identical AI risks.

Think about where mistakes or inappropriate data use could have the biggest consequences for the people you serve.

For associations, consider the information and services that are central to your member relationship. That could include membership records, certification data, event registrations, professional development records, member communities, or advocacy activities.

Consider Your Stakeholders

Who is affected by your organization’s use of AI?

That list might include:

  • Donors
  • Members
  • Employees
  • Volunteers
  • Clients or program participants
  • Job seekers
  • Vendors
  • Community partners
  • Board and volunteer leaders

You don’t need a separate rule for every group. But thinking through their expectations can reveal areas your policy should address.

International Policy Benchmarks: Applying Equity and Participatory Governance Principles

You don’t have to be an AI policy expert to borrow good ideas from broader governance frameworks.

International approaches to AI governance tend to stress the same principles: transparency, accountability, privacy, fairness, human oversight, and people’s ability to understand or challenge AI-driven decisions. These translate well to nonprofit and association work.

Take participatory governance, which means involving the people a decision affects rather than deciding everything from the top down. For a nonprofit, that might mean asking program staff and community members for input before building AI into service delivery. For an association, it might mean consulting staff and member representatives before using AI in ways that change how members interact with the organization.

A few practical questions to ask:

Who will this AI use affect, and have we asked for their input?

Can a person explain how the AI was used?

Is there a human someone can talk to?

Can someone challenge an AI-assisted decision?

Are we working as hard to check for bias as we are to measure efficiency?

You don’t need to adopt an international framework wholesale. These principles are a useful gut check when you’re deciding whether a specific AI use makes sense for your organization.

How Often Should You Review Your AI Policy — And Who Should Own It?

An AI policy shouldn’t sit untouched in your employee handbook for five years.

An annual review is a reasonable baseline. You should also revisit the policy whenever your organization adopts a significant new AI tool, changes how it uses AI, experiences a data or privacy incident, or encounters a new risk that the existing policy doesn’t address.

Policy ownership depends on the organization. A small nonprofit or association may assign ownership to the executive director or a board member. A larger organization might assign ownership to IT, compliance, HR, legal, or a cross-functional team.

Whatever structure you choose, make sure employees know who owns the policy and where to take questions.

Putting Your AI Policy Into Action

Once the policy is approved, don’t just email it to staff and move on.

Start by finding out how AI is actually being used. You may discover that employees are already using it for far more than leadership realized.

Then work through the following:

  • Inventory current AI use. Ask departments what tools they use and what they use them for.
  • Identify the highest-risk activities. Pay particular attention to sensitive data and decisions that affect people.
  • Decide which tools are approved. Make the process clear enough that employees don’t have to guess.
  • Set data boundaries. Spell out what information cannot be entered into public or unapproved AI tools.
  • Build in human review. Identify tasks where a person must verify or approve the result.
  • Train staff and volunteers. Use examples that relate to your actual work.
  • Give people a place to ask questions. This can be as simple as naming one person or team.
  • Review the policy regularly. Update it as your technology and AI practices change.

For associations, include member-facing teams in this process. Membership, events, education, communications, advocacy, and volunteer leadership may all use AI differently.

For nonprofits, involve the people closest to program delivery, as well as those responsible for technology and operations. They may spot risks that aren’t obvious from a purely administrative perspective.

An AI policy isn’t meant to slow your team down every time someone wants to try a new tool. It’s to give people enough guidance to use AI confidently without guessing where the boundaries are.

Start with the framework above, adapt it to the way your organization actually works, and revisit it as those practices change.

Put Your AI Policy Into Practice with MomentiveIQ

A policy sets the rules – MomentiveIQ helps you follow them. It puts AI to work on time-consuming workflows that eat up your team’s time, while keeping every action governed, auditable, and human-reviewed. Built for nonprofits and associations, on 40+ years of sector knowledge.

FAQs

Yes! AI tools can save time and help small teams accomplish tasks more efficiently, but they can also introduce new risks. Your AI policy should provide staff and volunteers with a consistent framework for using them responsibly.