Browse Blog Posts
Topics

How to Create a Generative AI Use Policy

An acceptable use policy for AI is no longer optional. Here's what to consider as you craft yours.

What You'll Learn

  • Generative AI opens nonprofits to risks involving data security, the accuracy of information, and bias, among other concerns.
  • An AI acceptable use policy is essential for defining how your staff and volunteers can — and can't — use AI in their work
  • Good policies are clear and actionable, and account for how your staff actually works.



Generative AI tools like ChatGPT, Gemini, and Claude create content in response to user prompts and can be genuinely useful for drafting content, summarizing information, generating ideas, or supporting research and analysis. An increasing number of AI apps and services can also carry out tasks on your behalf via what are known as "AI agents."

When used responsibly, AI can be seriously useful. However, these tools can also introduce significant risks regarding data security, accuracy, and bias while their presence in everyday life will continue to increase.

Small nonprofits often manage sensitive data with limited oversight, making a clear AI policy essential. A good policy doesn’t need to be complex — but it does need to be clear, actionable, and grounded in how staff members actually work.

drawing of a man sitting in the countryside and using generative AI on his laptop

1. Define Objectives and Scope

Clearly state the policy's purpose and its application. Define whether the policy applies to staff, contractors, volunteers, or clients.

An effective policy ensures all users understand the following:

  • Guidelines: What is permitted and what is prohibited
  • Rationale: Why these guardrails exist
  • Compliance: How to confirm understanding and adherence to the policy

Shift the focus from tools to data. AI is primarily a data-risk issue, not a tool issue. Focus your policy on the security risks (low or high) associated with the type of data that is fed into AI tools rather than individual applications. If your existing data-security rules prohibit uploading specific information to external services, those same restrictions should apply to generative AI tools.

2. Start with Your Guiding Principles

Center your policy on principles that reflect your organization’s mission, values, and risk tolerance. Frame these by identifying your organization’s goals, including what you want to prevent as well as what you want to achieve:

  • Enablement: What do you want to foster? (e.g., responsible experimentation, efficiency, shared learning.)
  • Protection: What do you need to avoid? (e.g., data exposure, harm to communities, reputational damage.)

Example Principles

  • Use AI tools in ways that align with our mission and respect the people we serve.
  • Do not share confidential, personal, or sensitive data with public AI tools.
  • Be transparent about when and how AI is used in work products.

3. Establish Clear, Actionable Guidelines for Use

Principles alone are insufficient; staff require specific rules to translate values into day-to-day decisions. Make sure that your policy covers the following:

  • Data handling: Clearly define what data must never be entered into AI tools and provide simple "do and don't" examples (e.g., "If you wouldn't email it, don't paste it into an AI tool").
  • Tool categorization: Distinguish between approved enterprise AI tools and public or consumer tools, as their risk profiles differ significantly.
  • Operational expectations: Include guidance on:
    • Verifying content for accuracy and bias.
    • Adhering to standards on plagiarism, copyright, and attribution.
    • Human-in-the-loop requirements: AI output must be reviewed by staff before external sharing or decision-making.
  • Support: State clearly who staff can contact when they are unsure about a use case to encourage transparency and risk management.

4. Encourage Learning

Beyond establishing boundaries, strong AI use policies should also encourage staff to learn from one another and build shared understanding over time.

  • Create ways for staff to share useful prompts with colleagues, such as via a chat group or by creating a prompt library. This can help accelerate effective use of AI tools.
  • Share best practices, such as how to create test data or when to strip out sensitive data from a data set to safeguard against data leaks.

5. Align It with Other Organizational Policies

As you draft your policy, consider how it aligns, intersects with, and builds on your other organizational technology policies (e.g., acceptable computer use, data security and privacy, confidentiality, or records retention).

In practice, generative AI tools often introduce the same risks as other external tools — just in a more accessible and informal way. Framing AI use as an extension of existing policies and expectations makes policies easier to understand and enforce.

6. Include a Compliance Statement

To ensure that your team has read and understood the guidelines, include somewhere for them to sign. This reinforces personal responsibility for their AI on a day-to-day basis and provides organizational clarity if issues are encountered going forward.

Remember: It’s safe to assume that informal use of AI tools is already happening! Therefore, you'll want to focus your efforts on policies that acknowledge that informal experimentation is already happening and focus on clarity, education, and risk reduction rather than relying solely on prohibition or enforcement.

7. Revisit Your Policies Periodically

AI is rapidly evolving: The technological landscape looks significantly different now than it did a year ago, and it will probably look significantly different a year from now. So it's a good idea to review your policies from time to time to make sure you are covering any emerging areas of concern.

All that said, a well-crafted policy will provide a solid foundation that you won't have to completely rework whenever you need to update it to account for new risks.

Explore More AI Topics

 



Originally published October 31, 2023.
Originally written by Amy Hooper. Updated by Elizabeth Orbison and Michael Enos.

Microsoft Copilot was used to assist in the writing process.

Top photo: Shutterstock