Generative AI tools like ChatGPT, Gemini, and Claude create content in response to user prompts and can be genuinely useful for drafting content, summarizing information, generating ideas, or supporting research and analysis. An increasing number of AI apps and services can also carry out tasks on your behalf via what are known as "AI agents."
When used responsibly, AI can be seriously useful. However, these tools can also introduce significant risks regarding data security, accuracy, and bias while their presence in everyday life will continue to increase.
Small nonprofits often manage sensitive data with limited oversight, making a clear AI policy essential. A good policy doesn’t need to be complex — but it does need to be clear, actionable, and grounded in how staff members actually work.
Clearly state the policy's purpose and its application. Define whether the policy applies to staff, contractors, volunteers, or clients.
An effective policy ensures all users understand the following:
Shift the focus from tools to data. AI is primarily a data-risk issue, not a tool issue. Focus your policy on the security risks (low or high) associated with the type of data that is fed into AI tools rather than individual applications. If your existing data-security rules prohibit uploading specific information to external services, those same restrictions should apply to generative AI tools.
Center your policy on principles that reflect your organization’s mission, values, and risk tolerance. Frame these by identifying your organization’s goals, including what you want to prevent as well as what you want to achieve:
Principles alone are insufficient; staff require specific rules to translate values into day-to-day decisions. Make sure that your policy covers the following:
Beyond establishing boundaries, strong AI use policies should also encourage staff to learn from one another and build shared understanding over time.
As you draft your policy, consider how it aligns, intersects with, and builds on your other organizational technology policies (e.g., acceptable computer use, data security and privacy, confidentiality, or records retention).
In practice, generative AI tools often introduce the same risks as other external tools — just in a more accessible and informal way. Framing AI use as an extension of existing policies and expectations makes policies easier to understand and enforce.
To ensure that your team has read and understood the guidelines, include somewhere for them to sign. This reinforces personal responsibility for their AI on a day-to-day basis and provides organizational clarity if issues are encountered going forward.
Remember: It’s safe to assume that informal use of AI tools is already happening! Therefore, you'll want to focus your efforts on policies that acknowledge that informal experimentation is already happening and focus on clarity, education, and risk reduction rather than relying solely on prohibition or enforcement.
AI is rapidly evolving: The technological landscape looks significantly different now than it did a year ago, and it will probably look significantly different a year from now. So it's a good idea to review your policies from time to time to make sure you are covering any emerging areas of concern.
All that said, a well-crafted policy will provide a solid foundation that you won't have to completely rework whenever you need to update it to account for new risks.
Originally published October 31, 2023.
Originally written by Amy Hooper. Updated by Elizabeth Orbison and Michael Enos.
Microsoft Copilot was used to assist in the writing process.
Top photo: Shutterstock