Free Resource

Nonprofit AI Acceptable Use Policy Template

Your team is already using AI. Make it safe.

Download a ready-to-use policy pack built for nonprofits, so you can move fast without breaking trust.

  • 1-page staff policy template (copy/paste)
  • Red flags checklist: what never goes into public AI tools
  • Vendor due diligence questions for AI tools

Download the Policy Pack

Fill in your details to get instant access.

We won't sell your info. We'll only send occasional product updates and resources. Unsubscribe anytime.

Most nonprofit AI policies fail for the same reason: they ban the tools. A ban is unenforceable when the tools are free, on personal phones, and already in use, so it converts a governance problem into a shadow IT problem and you lose the visibility you had.

This nonprofit AI policy takes the opposite approach. It assumes staff are using AI, and sets out what is allowed, what is never allowed, and who is accountable.

On this page

Why does a nonprofit need an AI policy?

The 2026 Nonprofit AI Adoption Report from Virtuous and Fundraising.AI, based on 346 organizations surveyed in late 2025, found that 92% of nonprofits now use AI tools, 47% have no AI governance policy, and 81% use AI on an ad hoc basis without documented workflows.

Read together, those numbers say the adoption debate finished without anyone announcing it, and the governance conversation is years behind the behaviour. The risk is not that someone uses AI. It is that nobody wrote down what they may use it for.

A nonprofit AI policy template, ready to copy

Replace the four bracketed items with your own details. It is deliberately one page: a policy nobody reads protects nobody.

[Organization name] Acceptable Use of AI Tools Effective [date]. Owner: [name and role]. Next review: [date, six months from the effective date].

1. Purpose. This policy sets out how staff and volunteers may use artificial intelligence tools in their work, so we can use them without putting the people we serve, our donors, or our reputation at risk.

2. Approved tools. Staff may use the AI tools on our approved list, held by the policy owner. Any other tool must be approved before use, including free ones. Personal accounts may not be used for organizational work.

3. What must never be entered into a public AI tool. Donor names, contact details, giving histories and staff notes about donors. Client, patient or beneficiary information of any kind. Employee records. Safeguarding information. Anything covered by HIPAA, FERPA or an equivalent obligation. Passwords, keys and financial account details. If you would not post it publicly, do not paste it in.

4. Removing identifiers. Where AI would help with a task that involves real records, remove the identifying details first, or use a tool that removes them before anything reaches the model. A first name and a gift amount can be enough to identify someone in a small community.

5. Human review. A person checks AI output before it reaches a donor, a funder, a board member or the public. The person who sends it owns it. AI output is a draft, never a final answer.

6. Facts and figures. Numbers about donors, gifts, grants or programs come from our records, not from an AI tool. If an AI tool states a figure, verify it against the source before it is used.

7. Disclosure. We tell people when AI has materially shaped something they receive, in line with our communications standards. We do not present AI generated impact stories, quotes or testimonials as real.

8. If something goes wrong. If confidential information is entered into a tool by mistake, tell [name and role] the same day. The response is to contain it, not to assign blame. Concealment is the problem, the mistake is not.

9. Review. This policy is reviewed every six months, because the tools change faster than policies do.

We are not lawyers and this is not legal advice. It is a starting point written for organizations that have nothing, which is most of them. If you hold health or student records, or you operate outside the US, have someone qualified read it before you adopt it.

What never goes into a public AI tool

Print this next to the policy. It is the part staff actually need on a Tuesday afternoon.

CategoryExamplesWhy it matters
Donor dataNames, addresses, giving history, wealth notes, staff notesDonors never agreed to have their details typed into a chatbot
People you serveClient, patient, student or beneficiary records, case notesOften the most sensitive data your organization holds, and the people least able to object
Regulated dataHealth information, student records, anything under HIPAA or FERPAConsumer AI plans are not covered by the agreements these rules require
Employee dataReviews, salaries, disciplinary notes, referencesStaff have the same expectations of privacy your donors do
CredentialsPasswords, API keys, bank detailsTreat a prompt box as a public forum
Unpublished materialBoard papers, legal advice, draft budgets, grant applications in progressConfidential until you decide otherwise

AI vendor risk assessment: twelve questions to ask

This is the vendor risk assessment most nonprofits never run. Ask these before you buy, and keep the answers. They are also in the pack as a one page questionnaire.

See the questions worth putting to any vendor.

  1. Do you train your models on our data? Ask for the default, not the option.
  2. What happens to our data if we cancel? Deletion, timescale, and whether it is certified.
  3. Where is our data processed and stored? Countries, not marketing terms.
  4. Do you offer a Data Processing Agreement? And a BAA, if you handle health information.
  5. Is personal information removed before it reaches a language model? If so, how, and can we see it working. See the technical whitepaper.
  6. Can every answer be traced to a source record? A tool that cannot cite is guessing.
  7. Are donor figures calculated from our data or generated by the model? These are not the same thing.
  8. Who at your company can see our data, and under what circumstances?
  9. What is your breach notification process and timescale?
  10. Which subprocessors do you use? Ask for the list, not a summary.
  11. What security certifications do you hold? SOC 2, ISO 27001, or an honest answer about what is in progress.
  12. What does it cost in year two? Not a policy question, but the one most often skipped.

How to adopt an AI policy in a week

  1. Fill in the four blanks. Organization name, effective date, owner, review date. Ten minutes.
  2. Write the approved tools list. Ask your team what they already use. You will be surprised, and that is the point.
  3. Send it, do not file it. One email with the policy in the body, not an attachment nobody opens.
  4. Spend fifteen minutes in a staff meeting on section 3. The list of what never goes in is the only part most people need to remember.
  5. Put the review date in the calendar. Six months. Tools change, and a policy nobody revisits becomes a policy nobody follows.

Where the pack goes further

The policy above is the whole policy, ungated, because a policy you cannot read is not much use. The downloadable pack adds the Word and PDF versions to edit and circulate, the vendor questionnaire as a form you can fill in, and role based guidance for development, programs, marketing, leadership and IT.

See what ChatGPT costs a nonprofit.

What's inside

Safe AI Policy

A 1-page staff policy ready to adopt in minutes

Red Flags Checklist

What never goes into public AI tools

Vendor Questionnaire

12 due diligence questions for any AI vendor

Role-Based Guidance

Dev, Programs, Marketing, Leadership & IT

Who it's for

Whether you're leading a development team, managing operations, or setting organizational strategy, this pack gives you a clear framework.

Development Teams

Protect donor data while leveraging AI for stewardship

Ops & IT Leaders

Vet tools and enforce data classification standards

Executive Leadership

Set the tone for responsible AI adoption org-wide

Frequently asked questions

What should a nonprofit AI policy cover?

Nine things: which tools are approved and who approves new ones, what must never be entered, how to remove identifiers, who reviews output before it goes out, where figures come from, when you disclose AI use, what to do after a mistake, who owns the policy by name, and when it is reviewed. All nine are in the template above.

Does a small nonprofit really need an AI policy?

Yes, and it is easier than it sounds. If staff are using AI at all, and 92% of organizations report that they are, then the choice is between a written rule and an unwritten one. One page is enough.

Should we just ban AI tools instead?

A ban is unenforceable when the tools are free and on personal phones. It pushes use out of sight, which is worse than use you can see and guide.

Can we put donor data into ChatGPT if we have a paid plan?

A business or enterprise workspace changes what the vendor does with your data, but it does not change what your donors agreed to. Remove identifying details first, whatever plan you are on. Our guide to donor data redaction covers how.

Who should own the policy?

One named person, usually whoever owns operations or IT. Ownership by a committee means ownership by nobody.

How often should it be reviewed?

Every six months. Model behaviour, pricing and data terms all changed materially in the last year, and a policy written against last year's tools quietly stops matching reality.

Can we use this policy as it is?

Yes. Copy it, adapt it, put your name on it. There is no attribution requirement. One caveat: we are not lawyers and this is not legal advice. If you hold health or student records, or operate outside the US, have someone qualified review it first.