Skip to content

How to Write a Nonprofit AI Policy Your Board Will Adopt

A nonprofit AI policy comes down to four decisions: the data AI may touch, how much it may do on its own, who approves, and what you disclose. Here is how to make them and get the policy adopted.

StratusLIVE16 min read

A nonprofit AI policy is a short, board-adopted document that answers four questions: which of the organization’s data AI tools may touch, how much AI may do on its own, who approves new tools and reviews AI output, and when donors and funders are told that AI was involved. Everything else in the policy, from the tool register to the review cadence, follows from those four decisions.

The usual reason to write one is that someone asked: a board member, a funder, or an IT reviewer. This guide covers what the policy has to decide, where fundraising and finance need specific rules, what to ask vendors before approval, and how to get the draft to the board ready for a vote.

If you want a starting draft built from your own answers, the Nonprofit AI Policy Template produces one from a short set of questions, and the outline needs no email. The rest of this article is the thinking behind it.

Key takeaways:

  • 92% of surveyed nonprofits use AI in some capacity and 47% have no AI governance policy, according to the 2026 Nonprofit AI Adoption Report from Virtuous and Fundraising.AI (346 organizations surveyed).
  • The strongest single line in any nonprofit AI policy is the data boundary: what may never be entered into an AI tool that is not on the approved list.
  • “Draft and recommend only” versus “routine actions after approval” is the decision boards most need to make explicitly, and the one most policies leave implied.
  • Vendor requirements belong in the policy as written confirmations you can check, not as principles. There are eight of them, from no training on your data to export on exit.
  • A policy is governance only when it names an approver, keeps a register of approved tools, and carries a review date.

Why the request lands on your desk now

In the 2026 Nonprofit AI Adoption Report from Virtuous and Fundraising.AI (346 nonprofits, published February 2026), 92% use AI in some capacity, 81% use it on an ad hoc basis without documentation, and 47% have no AI governance policy. NTEN and The Bridgespan Group surveyed 917 nonprofit staff and executives for The State of Nonprofit AI Adoption and Governance (September 2026). Among executives, 38% have written guidance on safe AI use in place, another 38% have it in development, and 23% have nothing. Among the same executives, only 22% have staff training on safe AI use in place.

What that means in practice: in most organizations, staff adopted AI before leadership decided anything about it. The policy is not introducing AI. It is catching up with it.

The people writing these policies say the same things in public. In an r/nonprofit thread asking who has an AI policy, the original poster’s reason was compliance language about personal information (PII) appearing in contracts. Others described unguided use as a free-for-all, an approved-tool list with a rule that PII and client or donor data never go in, and an IT team that keeps a list of every tool it has denied. A grant writer in a sister thread gave the worst case: a colleague pasting donor PII into a free tool with no data retention policy, with nobody finding out until a funder asks.

Three triggers come up again and again:

  1. A contract or a funder. Grant agreements and vendor contracts now carry AI and PII clauses. Someone has to attest to something.
  2. A board member or an IT reviewer. Directors have read about data and chatbots. IT wants a rule for the consumer accounts staff already use.
  3. A platform decision. The organization is evaluating a nonprofit CRM or fundraising platform with AI built in, and the board wants governance settled before the contract, not after.

If the third trigger is yours, write the policy first. It becomes the list you hold every vendor to.

What should a nonprofit AI policy include?

A nonprofit AI policy should include purpose and scope, principles, approved and prohibited uses, the data AI may use, human oversight rules, how new tools are approved, vendor requirements, disclosure, roles, training and incident handling, and a review cadence with a standing board report, plus a tool register and a board resolution. That is eleven short sections and two appendices, and each one is a decision.

The table shows what each section decides and who usually owns it. The owner column is a suggestion, not part of the template; the policy’s own roles section is where you fix it.

SectionWhat it decidesUsually owned by
1. Purpose and scopeWho the policy covers (staff, volunteers, contractors, board) and which tools (built into a platform or standalone, free or paid)Executive
2. PrinciplesThe commitments every use is measured against: mission first, human-led, proportionate, transparent, secure, accountableBoard
3. Approved usesThe kinds of work AI may assist, each with its own limit, and the uses never permittedExecutive and department heads
4. Data AI may useThe data categories AI tools may work with, the categories excluded, and the rule for consumer chatbotsExecutive and IT
5. Human oversightWhether AI drafts only or may take routine actions after approval, and who reviews drafts to donors and fundersBoard sets the rule, executive names the reviewers
6. Approving tools and new usesThe request, the check, the decision, the register entryExecutive or a designated approver
7. Vendor requirementsThe written confirmations a vendor provides before approvalExecutive, IT, and finance
8. DisclosureWhen donors, funders, clients, and the public are told AI was involvedBoard
9. RolesWhat the board, executive, approver, IT, finance, and staff are each responsible forExecutive
10. Training, incidents, exceptionsHow staff learn the rules, what counts as an incident, how exceptions are granted and when they expireExecutive
11. Review and reportingThe review cadence, the standing board report, and the questions the board still has to decideBoard
Appendix AThe AI tool registerApprover
Appendix BA draft board resolution adopting the policyBoard chair

Two sections carry most of the weight: section 4 and section 5. Get those right and the rest is administration.

The four decisions the board is really making

1. The data boundary

The data boundary is the line between the categories AI tools may work with and the categories that never enter one. A workable data boundary permits public information, constituent contact records, and giving history inside approved platforms, excludes financial, program, client, and employee records until the board revisits the question, and keeps sensitive categories out entirely: health information, information about minors, account and card numbers, government identifiers, beliefs, and immigration status.

The rule that matters most is the one for consumer tools. Any AI service used under a personal account, or without an organizational agreement, may be used only with public information and the organization’s own published material. Personal data of any kind never enters it. That one sentence covers most of the risk boards worry about, because it addresses what staff are already doing.

Two details are worth writing down. Communication preferences and do-not-contact flags on a constituent record apply to AI-assisted work exactly as they apply to a person. And a vendor’s promise not to train on your data is a setting, not a data policy. Data a vendor promises not to train on can still be subpoenaed, which is a reason to keep sensitive categories out rather than rely on a toggle. The broader controls belong in your donor data security program; the AI policy only has to say which categories cross the line.

2. How much AI may do on its own

The autonomy decision has two workable settings. Under draft-only, AI prepares and recommends, and a named person reviews and sends, posts, or saves everything it produces. Under routine actions after approval, low-risk actions may run once a person has approved the workflow, and anything outbound or financial still waits for individual approval. Undecided is a valid starting position, provided the policy says so and puts the question on the board’s agenda.

Policies tend to leave this decision implied, and that is where boards get uncomfortable later. Approval has to mean that a person read the specific item, not that a workflow was switched on. Write it that way. The practical test is the acknowledgement to a major donor. Under draft-only it waits for the relationship owner. Under routine actions after approval it still waits, because it is outbound.

This is also where the board’s question about chatbots gets answered. AI features inside the platform your organization already runs, including AI agents, should work on data the organization controls, under the vendor agreement in section 7, with the approval controls the policy requires; if a platform cannot meet that, section 7 is where it fails. A staff member’s personal chatbot has none of that. The policy should say both are covered, and treat them differently.

3. Who approves, and who reviews

Name one approver for new tools and new uses: the executive director, a designated AI lead, a staff committee, or a board committee. Name the reviewer for drafts to donors and funders: the relationship owner, a supervisor, or a tiered rule where the owner reviews routine messages and a supervisor reviews anything to major donors or funders. The approver’s decisions go into a register with the date, the approved uses, the data categories, and which actions the tool may take on its own.

The register is the part boards find reassuring, because it turns “what are we using AI for, and who decided?” into a list. Keep it short and current. Approvals can be conditional or time-limited, and they are withdrawn when a vendor changes its terms or a tool is used outside its approved scope.

4. Disclosure

Three disclosure settings work in practice: whenever AI helped produce a communication; when AI produced the substance rather than the grammar or formatting; or on request and in public-facing content. The middle setting is the template’s starting rule when a board is undecided, and the easiest to apply. Whatever the setting, a person’s name on a message means that person reviewed it and stands behind it, and AI never signs.

Grant applications follow the funder’s own disclosure rules where they are stricter than yours. Grant writers already report funders asking about AI in applications directly, so write the clause now.

Fundraising and finance need specific rules

Generic policies stay generic exactly where the risk is highest: the place donor data, money, and outbound communication meet. Four workflows deserve their own line in section 3.

  • Prospect research and donor briefings. AI may research prospective donors and funders from public sources and prepare briefings. Capacity and wealth indicators come only from vendors under contract, never from a chatbot’s guess. A person verifies a briefing before it informs an ask.
  • Donor communications and acknowledgements. AI may draft acknowledgements, stewardship messages, appeals, and follow-ups. A named person reviews every draft. The name on the message belongs to a person who read it.
  • Gift entry, coding, and receipting. AI may prepare entries and flag anomalies. A person posts. Receipts and tax acknowledgements go out only after a person confirms the amount, the fund, and the donor.
  • Reconciliation and reporting. AI may assemble reports and reconciliations from the organization’s own data. Figures presented to the board are checked against the system of record by the person presenting them, and the finance lead reviews any tool that touches financial data before it is approved.

The reason to write these limits precisely is not to slow the work down. It is so the board can say yes to AI in fundraising with a straight answer to the question directors ask most quietly: does this mean fewer staff? A well-written policy answers no. AI prepares. The gift officer, the finance lead, and the steward decide, and the time AI returns goes back into relationships. That is what human-led, AI-assisted means once it is written into a policy.

What to ask every vendor before approval

Section 7 should be a list of written confirmations, because a principle cannot be checked and a confirmation can. Put the list to each vendor, and to each consultant or agency that uses AI on your data.

Ask the vendor to confirm in writingWhy it matters to the board
Your data, prompts, and outputs are not used to train the vendor’s models or anyone else’sThe question directors have read about, and the one a vendor answer tends to blur
A current SOC 2 report or an equivalent independent audit, shared under NDA if neededSomeone outside the vendor has checked the controls
Named model providers and where processing happensYou cannot govern what you cannot name
Human approval controls on the actions AI can take, and how you configure themSection 5 only works if the tool can enforce it
A record of what the AI proposed, who approved it, and what changedAccountability needs a trail
A data processing agreement and a published subprocessor list, with advance notice of changesThe legal shape of the data boundary
The ability to turn AI features offGovernance without an off switch is a request
Export of your data in a usable format, and confirmed deletion when you leaveLock-in is a governance risk the board owns

If a vendor cannot confirm an item, the approver decides whether to proceed with a documented, time-limited exception or to decline. Keep the confirmations with the register entry, and put the same questions to any vendor that adds AI features to a product you already run.

For readers evaluating the Ignite Active Intelligence Platform, our answers to most of this list are public. On the trust page: agents are read-only by default, and anything that changes a record goes through the approval gates your team configures; prompts and outputs are not used to train foundation models by default; and a current SOC 2 Type II report is available on request, under NDA where one is needed. The data processing agreement and subprocessor list are on the legal pages. The two that are not on a page, turning AI features off and export and deletion at exit, are fair to ask us in writing too. How governed AI works in practice is on its own page. Hold any platform to the same list.

Getting it through the board

The board adopts the policy by resolution, receives a standing report at least once a year and the register at each review, decides the questions the draft leaves open, and sets the review cadence: quarterly, twice a year, annually, or annually plus whenever a new tool or data category is proposed. A policy with no review date is a document, not governance.

Expect these ten questions when the policy reaches the agenda. Bring answers to all of them.

  1. What are we using AI for today, and who decided?
  2. What donor data can the AI see?
  3. Is our data training somebody else’s model?
  4. Can the AI send something to a donor without a person seeing it?
  5. Who is accountable when it gets something wrong?
  6. Will donors know when AI was involved?
  7. What happens to our data if we leave the vendor?
  8. How is this different from staff using a chatbot on their own?
  9. Does this mean fewer staff?
  10. How will we know it is working, and when do we revisit this?

Each one maps to a section above. The policy template writes a suggested answer to each from your own draft, and puts anything you leave undecided into section 11 as an explicit question for the board. That is a better outcome than a policy that pretends the decision was made.

Two practical notes on the meeting. Bring the register, even if it has three rows; directors respond to a list. And lead with the data boundary and the oversight rule, because those are the two decisions the board is being asked to own. Everything else can be delegated to the executive under the policy.

A five-step plan for writing it

  1. Find the quiet users. Ask staff which AI tools they already use and for what. Their workarounds show where the demand is, and their near-misses show where the risk is. Put one or two of them in the drafting group.
  2. Make the four decisions. The data boundary, how much AI does on its own, the approver and reviewer, and disclosure. Write each as one paragraph. If you cannot decide one, write “not decided yet” and list it for the board.
  3. List the work and the vendors. Approved uses with a limit for each, the register of tools in use today, and the eight confirmations sent to every vendor on it.
  4. Draft it, then read it as a staff member. If a sentence needs a lawyer to interpret, rewrite it. The policy shapes behavior only if people can hold it in their heads. Then have counsel review it, especially where health, education, employment, or financial regulation applies.
  5. Take it to the board with the resolution and a review date. Adopt it, record the open questions, and schedule the first report.

Questions leaders ask about nonprofit AI policies

Does a small nonprofit need an AI policy?

If anyone uses an AI tool on the organization’s behalf, yes. Size changes the length, not the need. For a small organization, a two-page policy with the four decisions, a register, and a review date can be enough; the template’s eleven sections mostly get shorter, not fewer. What does not change with size is the data boundary: a small human services agency holds client records as sensitive as a hospital’s.

Should the policy ban ChatGPT and other consumer chatbots?

Bans are hard to enforce and push use underground. Staff describe unofficial policies that are frequently disregarded, and a real ban means blocking every chatbot at the network level. A workable rule permits consumer tools for public information and the organization’s own published material, forbids any personal data in them, and steers staff toward approved tools where the data is covered by an agreement. Say which tools are approved and how to request another.

What if the organization decides not to use AI at all?

Write that down too. A policy that says the organization does not use AI, and why, still needs the consumer-tool rule for staff and the vendor clause for platforms that add AI features to products you already run, because those features arrive whether or not you asked. Some organizations have taken exactly this position for mission reasons, including climate organizations that cite the energy cost of AI, and documented it.

Who should own a nonprofit’s AI policy?

One named person, usually the executive director in organizations without a dedicated lead, with IT or a security advisor reviewing anything that connects to systems and the finance lead reviewing anything that touches money. A board committee (governance, audit, or finance) receives the report. Shared ownership is no ownership. In the NTEN and Bridgespan survey, 42% of executives report a named owner or group responsible for AI oversight in place.

How often should a nonprofit review its AI policy?

At least annually, and whenever a new tool or a new data category is proposed. Vendors add AI features between renewals, and the policy has to catch that moment. Quarterly is reasonable for the first year, while the register is still forming. Put the review date in the policy itself and on the board calendar, and treat a change in any vendor’s terms as a trigger for a review between cycles.

Do we need a lawyer to write a nonprofit AI policy?

Not to write it. A template, including ours, is a starting point for a board conversation, and the draft is best written by the people who will live with it. Counsel comes in before adoption: have a lawyer review the draft where health, education, employment, or financial regulations apply to your organization, and wherever a funder agreement sets rules of its own. A template is not legal advice, and the document should say so on its first page.

Start with a draft built from your own answers

The Nonprofit AI Policy Template turns the decisions in this article into a draft: eleven sections, the tool register, a draft board resolution, and the ten board questions with a suggested answer to each from your own choices. The outline is free on the page, and a link to the editable Word document is sent by email. No AI writes it, and the policy body names no vendor, because a board policy should outlive any tool.

If your board’s questions are already on the agenda, bring them to a working session. We walk through how governed AI works inside Ignite, and what stays human.

Sources

Put the ideas to work.

See how Ignite turns strategy into capacity. 30 minutes. Live demo.