
— KEY TAKEAWAYS
An AI policy for nonprofits is a written document that says which AI tools staff may use, what data may go into them, who reviews the output before it reaches the public, and who is accountable when something goes wrong. It applies to everyone, including volunteers and board members.
- If you’re nervous about AI, that could actually be good—the organizations that get it right are the ones that worry about it. A policy turns that worry into concrete limits.
- Four rules do most of the work: no private data in unvetted tools, every output is a draft, no fully automated decisions about people, and disclose AI use.
- Nearly half of nonprofits have no acceptable use policy at all, while 72% of donors we surveyed said it matters that a real human is involved in what they receive from you.
- The most common mistake isn’t a bad policy; it’s a decent policy that nobody enforces. Train everyone, offer amnesty first, and keep your tools register current.
It’s hard to talk about the importance of having written AI policies at nonprofits without sounding like you’re describing The Invasion of the Bodysnatchers.
Your development director started using ChatGPT to draft appeal letters back in March. Your program manager has an AI notetaker sitting in on case reviews. Your summer intern pasted last year’s donor list into something free to fix the formatting.
You thought you had time, but it’s already too late!!!
Still, we can’t ignore that things like this are already happening, and they’re happening every single day—heck, more like every single hour.
Really, truly, it’s not just you. Recent benchmark research found that 92% of nonprofits use AI in some capacity, but only 7% say it has meaningfully expanded what their organization can do. Meanwhile, nearly half of nonprofits in that same report have no AI governance policy at all.
But, unlike with the bodysnatchers, it’s actually not too late. If the best time to write a firm AI policy at your nonprofit was one year ago, then the second best time is right now.
And when we say “right now”, we mean it: Just download our free Nonprofit AI Governance Policy Template and follow along as we walk through what you need.
What Is an AI Policy for Nonprofits?
An AI policy is a written document that says which AI tools your staff may use, what data may go into them, who reviews the output before it reaches the public, and who is accountable when something goes wrong. It applies to everyone, including employees, contractors, interns, volunteers, and board members.
Like with any policy, the goal is to make making the right decision easier. You have a clear set of instructions on when (and when not) and how (and how not) to use AI in your work, which lets you put your brain cells to better, more productive uses.
Your Worries About AI Are the Most Useful Thing You Have
If you’re reading this because you’re nervous about AI, that’s good. You should be—and not just for reasons related to data center takeovers or the possible (probable?) rise of our new robot overlords.
Organizations that get AI right are the ones who fret about it, just as the organizations that get it badly wrong are the ones that don’t. AI is incredibly powerful, but it can also be incredibly erratic, and it’s as impressive for what it can’t do as what it can.
Your standard LLM could fully segment your nonprofit’s donor list by cross-referencing volunteer shifts, event attendance, and gifts—but then ask it to count to 100 and it just … won’t be able to. Or, it will state with the utmost confidence that the number 12 comes after 63.
Organizations that don’t worry about AI just start to use it in the wild without any plans for how it could go wrong. An AI chatbot that answers sensitive beneficiary questions could start doling out harmful advice, an AI-generated “slop” image purporting to be of your donors could cause a PR meltdown—there are so many scenarios where “worrying” is the only sane way to think about this!
AI policy makes those worries concrete and turns them into walls that limit what harm these systems can do while maximizing the amount of good they can achieve. If you’re not concerned about AI going to work at your nonprofit, you’re not doing it right. And to all you worrywarts out there: We see you, and we salute you. Channeling your concern into creating an effective policy will help protect your organization.
5 Times When Nonprofits Should NOT Use AI
What Goes Into a Nonprofit AI Policy
A good AI policy doesn’t have to be long, but it does have to be specific. Here’s what topics our AI governance policy template covers, section by section.
Scope and Plain-English Definitions
Start by saying who the policy applies to and defining the terms. For instance:
- Generative AI creates new content: text, images, summaries.
- Predictive AI analyzes patterns in data you already have to forecast something, like which donors are likely to lapse.
- Personally identifiable information (PII) means anything that identifies a specific person. This can include donor addresses and giving histories, but also client health status, legal histories, and housing records.
Define these terms once, in language anyone, like let’s say a new volunteer, can follow. Ask any compliance professional, and they’ll tell you that a majority of mistakes in adhering to a policy come from someone not realizing that what they were doing counted.
Governance Roles
You probably don’t have a full-time IT or compliance department. That’s fine—the accountability for your nonprofit’s AI use just has to live somewhere specific.
Our template splits it three ways, all of which involve individual people, not committees:
- An Executive Sponsor who owns board transparency and signs off on high-risk uses
- A Policy Lead who maintains the tools register and runs training
- Department Liaisons who watch how their own teams actually work
An Approved Tools Register
This is the single most useful page in the document. List the tools that are approved, what each one is approved for, and what data is allowed in it. If a tool isn’t on the list, the data stays out of it.
Keep it short and keep it current, because these things are a two-way street; A register nobody updates becomes a register nobody uses.
The 4 Rules That Do Most of the Work
Out of everything in the AI policy template, there are four principles that deliver the most security for your org. Those four rules are:
- No private data in unvetted tools. No donor details, no client case notes, no internal financials in general-purpose AI that your org does not have a business or enterprise agreement with. Only your policy lead can approve a tool for private data, and only after reviewing the vendor’s data processing agreement. Staff shouldn’t be reading contract language on their own.
- Every output is a draft. Nothing AI-assisted goes to a supporter without a person reviewing, editing, and approving it. Fact-check every date, figure, and research claim against a primary source, because models state wrong things with total confidence (61… 62… 63… 12!).
- No fully automated decisions about people. AI can score, suggest, and flag. A human makes the call on eligibility, service allocation, and all decisions that have to do with money. Predictive scores are directional, but they are not final. That’s your job.
- Disclose AI use. Label AI assistance internally so your team knows what they’re looking at, and disclose externally when AI materially created something a supporter sees. It’s a good idea to create a blanket AI disclosure on your website that covers all its uses at your org so nothing goes unaddressed.
Risk Tiers
Not every task that you use AI for needs the same level of scrutiny, so sort them. These are three basic tiers our governance template recommends:
- Tier 1 is AI suggesting, like drafting social posts, event agendas, summaries of public documents, and this tier needs normal peer review.
- Tier 2 is AI analyzing, like identifying donor engagement scores, and requires staff to check the output against what they already know.
- Tier 3 is AI acting on its own, and it’s prohibited without a written risk assessment and executive sign-off.
Most of what your team wants to do is probably Tier 1. Letting them know that using AI for these tasks won’t result in nine extra levels of scrutiny will come as a relief.
Incident Reporting
AI can make mistakes, but so can people. Mistakes happen! Make sure you account for that in your AI policy.
Let’s say, for example, someone on staff accidentally posts your donors’ PII into an unapproved ChatGPT account. Give them 24 hours to report it, give them a person to report it to, and make clear that timely reporting is the point. A policy that punishes honesty will only get you silence, and silence is how a small slip-up turns into an actual breach notification to donors and funders.
AI for Nonprofits 101: A Beginner’s Guide to Using AI Tools Safely & Effectively
Why AI Disclosure Rules Make Your Work Better
Do your supporters really care if you used AI to write that fundraising appeal or analyze their information? Well, instead of speculating, we went and asked over 2,000 donors about it, and the answer is, generally speaking, yes!
Specifically, there are two findings from this research that should shape how your AI policy handles disclosure.
- Donors want a person involved. 89.9% said it matters to them that a real human being is involved in creating the communications they receive from a nonprofit. Only 9.1% said it didn’t. People don’t care so much about you using AI to help communicate with them better. But they want to hear from you, not your AI.
- Donors want to be informed. 63% of respondents said it was important for nonprofits to disclose if a message or image was made with AI. And not even 10% said AI disclosure was “not at all important” to them.
But there are risks to disclosing AI usage: 19% of survey respondents said that seeing an AI disclosure on a message from a nonprofit would make them trust it less, while 25% said it would depend on the message.
And yet, on topic after topic, our research found that donors were more likely to be neutral or even lean positive on disclosed AI usage than they were to run negative.
So, what’s the best way to move forward? Confidently but carefully.
The human review rules contained in your AI policy cover exactly the kinds of situations described in this research. Your donors want to hear from you, not your LLM chatbot. If a person genuinely rewrote the AI draft and made the key judgment calls, then your AI use is covered by a general disclosure, and your supporters are still satisfied.
The second is that disclosing your AI use is not the same as making it the main story every time you send this message. Put a public-facing AI policy on your website instead and link it in your email footer. Donors who want to know how you work can find out in one click. Everyone else will just read your impact update.
This is one of the ways that a good AI policy pulls double duty. It protects your data and protects—and even strengthens—your reputation.
A Policy Nobody Enforces Is Just a Document
This is where most AI policies die. Heck, it’s where most policies of any stripe go to die. They get written, they get circulated, and they live in a shared drive folder that nobody opens ever again—the business equivalent of Siberia.
That’s why you need to make sure your AI policy actually gets enforced. It starts with training, but it ends at… actually, it never ends.
Here are the four basic things you need to keep your AI policy in use:
- Offer amnesty first. If staff members are already using tools you haven’t sanctioned, a purely punitive rollout drives that underground. Ask what people are using, then get them a secure version of it.
- Train everyone, including new hires within their first month, and refresh your AI training annually.
- Keep the tools register current, because an outdated register is what pushes people back to unapproved tools.
- Report to your board once a year: share what’s in the register, what got approved, who completed training, what incidents came up.
The goal here isn’t compliance theater. It’s for everyone to feel comfortable enough with your policy that they don’t just grudgingly use it; they actively appreciate it.
Though, when in a pinch, grudging acceptance will do just fine.
How We Handle AI in the Neon One Platform
We ask you to create an AI policy because we’ve done the same work on our side.
AI features in the Neon One platform can easily be turned off. Every account has an admin setting that controls whether data from your instance can reach AI services at all, and if you turn them off, those tools are unavailable and can’t touch your data.
When they are on, they run against your own records rather than from memory. We only work with AI providers under contractually binding zero-retention agreements, and AI-generated content in the platform is labeled as such.
We’re not going to pretend that settles the question for you. It’s just what our own version of this policy looks like in practice. You can read more about how we approach AI if you want the longer version.
How Neon One Approaches AI (and What It Means for Nonprofits)
AI is Just Another Tool; Treat it Like One
Here’s the golden rule for using AI at your nonprofit: AI tools are worth it when they give your staff more time with the people you serve, and when they don’t, they aren’t. (Click that link in the previous sentence for an example of how we put that principle to work here at Neon One.)
Your AI policy is a service to that rule. It helps you make sure that these tools are being used the right way to deliver the right outcomes, and that the time you save on meeting notes goes into making thank-you calls.
It’s also why you don’t want to get bogged down forever writing your policy when you could be actually working on, you know, your real work. That’s why we created our free Nonprofit AI Governance Policy Template; just fill in your org’s info and download it to get a massive head start on the process.


