AI Policy for Nonprofits: A 5-Line Starter Template

Nearly half of nonprofits using AI have no policy for it. Here is a 5-line AI policy any small team can put in writing this week to protect donor data and cut risk.

Half of nonprofits using AI have no policy for it. That is not a shortcut. It is exposure.

Nonprofit leader burnout climbed to 46% this year, and almost every team is now leaning on AI to keep up with fundraising, communications, and program work. The tools genuinely help. But the same tools easing the workload are quietly touching donor names, client records, and case notes, often with no rules at all. That gap is where legal and trust risk lives.

You do not need a twenty page policy or a lawyer on retainer. You need five lines your whole team can actually follow. Here is a starter you can put in writing this week.

The 5-line AI policy for nonprofits

  1. Approved tools. Name the two or three AI tools your team is allowed to use. One general assistant, maybe one for design, maybe one built into the tools you already pay for. If it is not on the list, it is not approved yet.
  2. Never in a prompt. List what never gets pasted into an AI tool: donor personal information, client records, financials, board minutes, anything you would not email to a stranger. When in doubt, leave it out.
  3. Human review. A person checks AI output before it reaches a donor, the board, or the public. AI drafts. People decide.
  4. Volunteer training. Anyone who touches the tools, staff or volunteer, gets the same five rules on day one. A shared standard beats a dozen private habits.
  5. Where it lives. One page, linked in your handbook, reviewed twice a year. A policy nobody can find is a policy nobody follows.

Why this matters now

Adoption is nearly universal and the pressure is real, but the guardrails have not kept up. Recent sector research found that a large share of organizations using AI still have no formal policy covering donor or client data. That is not a technology problem. It is a governance problem, and governance is something small teams can actually control.

The cost of getting it wrong is not abstract. Donor trust is the asset the whole organization runs on. One careless prompt with the wrong data in it can undo years of relationship building, and it can create obligations you did not plan for. Five lines will not eliminate every risk, but they turn "we hope everyone is being careful" into "here is what careful means here."

Start today

Pull your team together for fifteen minutes. Fill in the five lines with your real tools and your real data. Put the page where people work. Revisit it when the tools change, which they will.

That is a policy you can write this week. It protects the people who trust you, and it lets your team keep the time AI gives back.