Nonprofit AI Acceptable Use Policy Template
Your team is already using AI. Make it safe.
Download a ready-to-use policy pack built for nonprofits, so you can move fast without breaking trust.
- 1-page staff policy template (copy/paste)
- Red flags checklist: what never goes into public AI tools
- Vendor due diligence questions for AI tools
Download the Policy Pack
Fill in your details to get instant access.
We won't sell your info. We'll only send occasional product updates and resources. Unsubscribe anytime.
Most nonprofit AI policies fail for the same reason: they ban the tools. A ban is unenforceable when the tools are free, on personal phones, and already in use, so it converts a governance problem into a shadow IT problem and you lose the visibility you had.
This nonprofit AI policy takes the opposite approach. It assumes staff are using AI, and sets out what is allowed, what is never allowed, and who is accountable.
Why does a nonprofit need an AI policy?
The 2026 Nonprofit AI Adoption Report from Virtuous and Fundraising.AI, based on 346 organizations surveyed in late 2025, found that 92% of nonprofits now use AI tools, 47% have no AI governance policy, and 81% use AI on an ad hoc basis without documented workflows.
Read together, those numbers say the adoption debate finished without anyone announcing it, and the governance conversation is years behind the behaviour. The risk is not that someone uses AI. It is that nobody wrote down what they may use it for.
A nonprofit AI policy template, ready to copy
Replace the four bracketed items with your own details. It is deliberately one page: a policy nobody reads protects nobody.
[Organization name] Acceptable Use of AI Tools Effective [date]. Owner: [name and role]. Next review: [date, six months from the effective date].
1. Purpose. This policy sets out how staff and volunteers may use artificial intelligence tools in their work, so we can use them without putting the people we serve, our donors, or our reputation at risk.
2. Approved tools. Staff may use the AI tools on our approved list, held by the policy owner. Any other tool must be approved before use, including free ones. Personal accounts may not be used for organizational work.
3. What must never be entered into a public AI tool. Donor names, contact details, giving histories and staff notes about donors. Client, patient or beneficiary information of any kind. Employee records. Safeguarding information. Anything covered by HIPAA, FERPA or an equivalent obligation. Passwords, keys and financial account details. If you would not post it publicly, do not paste it in.
4. Removing identifiers. Where AI would help with a task that involves real records, remove the identifying details first, or use a tool that removes them before anything reaches the model. A first name and a gift amount can be enough to identify someone in a small community.
5. Human review. A person checks AI output before it reaches a donor, a funder, a board member or the public. The person who sends it owns it. AI output is a draft, never a final answer.
6. Facts and figures. Numbers about donors, gifts, grants or programs come from our records, not from an AI tool. If an AI tool states a figure, verify it against the source before it is used.
7. Disclosure. We tell people when AI has materially shaped something they receive, in line with our communications standards. We do not present AI generated impact stories, quotes or testimonials as real.
8. If something goes wrong. If confidential information is entered into a tool by mistake, tell [name and role] the same day. The response is to contain it, not to assign blame. Concealment is the problem, the mistake is not.
9. Review. This policy is reviewed every six months, because the tools change faster than policies do.
We are not lawyers and this is not legal advice. It is a starting point written for organizations that have nothing, which is most of them. If you hold health or student records, or you operate outside the US, have someone qualified read it before you adopt it.
What never goes into a public AI tool
Print this next to the policy. It is the part staff actually need on a Tuesday afternoon.
| Category | Examples | Why it matters |
|---|---|---|
| Donor data | Names, addresses, giving history, wealth notes, staff notes | Donors never agreed to have their details typed into a chatbot |
| People you serve | Client, patient, student or beneficiary records, case notes | Often the most sensitive data your organization holds, and the people least able to object |
| Regulated data | Health information, student records, anything under HIPAA or FERPA | Consumer AI plans are not covered by the agreements these rules require |
| Employee data | Reviews, salaries, disciplinary notes, references | Staff have the same expectations of privacy your donors do |
| Credentials | Passwords, API keys, bank details | Treat a prompt box as a public forum |
| Unpublished material | Board papers, legal advice, draft budgets, grant applications in progress | Confidential until you decide otherwise |
AI vendor risk assessment: twelve questions to ask
This is the vendor risk assessment most nonprofits never run. Ask these before you buy, and keep the answers. They are also in the pack as a one page questionnaire.
See the questions worth putting to any vendor.
- Do you train your models on our data? Ask for the default, not the option.
- What happens to our data if we cancel? Deletion, timescale, and whether it is certified.
- Where is our data processed and stored? Countries, not marketing terms.
- Do you offer a Data Processing Agreement? And a BAA, if you handle health information.
- Is personal information removed before it reaches a language model? If so, how, and can we see it working. See the technical whitepaper.
- Can every answer be traced to a source record? A tool that cannot cite is guessing.
- Are donor figures calculated from our data or generated by the model? These are not the same thing.
- Who at your company can see our data, and under what circumstances?
- What is your breach notification process and timescale?
- Which subprocessors do you use? Ask for the list, not a summary.
- What security certifications do you hold? SOC 2, ISO 27001, or an honest answer about what is in progress.
- What does it cost in year two? Not a policy question, but the one most often skipped.
How to adopt an AI policy in a week
- Fill in the four blanks. Organization name, effective date, owner, review date. Ten minutes.
- Write the approved tools list. Ask your team what they already use. You will be surprised, and that is the point.
- Send it, do not file it. One email with the policy in the body, not an attachment nobody opens.
- Spend fifteen minutes in a staff meeting on section 3. The list of what never goes in is the only part most people need to remember.
- Put the review date in the calendar. Six months. Tools change, and a policy nobody revisits becomes a policy nobody follows.
Where the pack goes further
The policy above is the whole policy, ungated, because a policy you cannot read is not much use. The downloadable pack adds the Word and PDF versions to edit and circulate, the vendor questionnaire as a form you can fill in, and role based guidance for development, programs, marketing, leadership and IT.
What's inside
Safe AI Policy
A 1-page staff policy ready to adopt in minutes
Red Flags Checklist
What never goes into public AI tools
Vendor Questionnaire
12 due diligence questions for any AI vendor
Role-Based Guidance
Dev, Programs, Marketing, Leadership & IT
Who it's for
Whether you're leading a development team, managing operations, or setting organizational strategy, this pack gives you a clear framework.
Development Teams
Protect donor data while leveraging AI for stewardship
Ops & IT Leaders
Vet tools and enforce data classification standards
Executive Leadership
Set the tone for responsible AI adoption org-wide
Frequently asked questions
What should a nonprofit AI policy cover?
Nine things: which tools are approved and who approves new ones, what must never be entered, how to remove identifiers, who reviews output before it goes out, where figures come from, when you disclose AI use, what to do after a mistake, who owns the policy by name, and when it is reviewed. All nine are in the template above.
Does a small nonprofit really need an AI policy?
Yes, and it is easier than it sounds. If staff are using AI at all, and 92% of organizations report that they are, then the choice is between a written rule and an unwritten one. One page is enough.
Should we just ban AI tools instead?
A ban is unenforceable when the tools are free and on personal phones. It pushes use out of sight, which is worse than use you can see and guide.
Can we put donor data into ChatGPT if we have a paid plan?
A business or enterprise workspace changes what the vendor does with your data, but it does not change what your donors agreed to. Remove identifying details first, whatever plan you are on. Our guide to donor data redaction covers how.
Who should own the policy?
One named person, usually whoever owns operations or IT. Ownership by a committee means ownership by nobody.
How often should it be reviewed?
Every six months. Model behaviour, pricing and data terms all changed materially in the last year, and a policy written against last year's tools quietly stops matching reality.
Can we use this policy as it is?
Yes. Copy it, adapt it, put your name on it. There is no attribution requirement. One caveat: we are not lawyers and this is not legal advice. If you hold health or student records, or operate outside the US, have someone qualified review it first.