This isn’t a problem to punish. It’s an opportunity to get ahead of.
Without organisational guardrails, the risks are real. Staff might paste donor data, financials, or sensitive program information into a free AI tool with no data protections. They might publish AI-generated content without review. They might make commitments or claims in grant applications that the AI hallucinated. None of this is malicious — it’s what happens when useful tools arrive faster than policy.
What a simple AI use policy looks like:
- Encouraged: drafting content, brainstorming, summarising long documents, researching topics, generating first drafts of internal documents.
- Needs human review: anything published externally, anything involving donor communications, grant applications, financial reporting, board papers.
- Off limits: pasting personally identifiable information (names, addresses, donation histories) into AI tools unless you’re using an enterprise account with data protections. Making strategic decisions based solely on AI analysis without human verification.
- Approved tools: specify which AI tools your organisation endorses and at what subscription level. Free-tier tools typically use your inputs to train their models. Paid tiers usually don’t — but check the terms.
This doesn’t need to be a 20-page document. A single page that your team has actually read is worth more than a comprehensive policy gathering dust.