Do You Need an AI Policy?
At this point you have probably already dabbled with AI or at least heard about its impending take over…
The truth is that AI has been around since the 1950s, but its development and usage are quickly accelerating. It is no longer a matter of if AI will be as ubiquitous as Google, but when.
Key Questions for Your Nonprofit
There are many questions surrounding the use of AI, but the following are most important for your nonprofit to answer:
- How can AI be best deployed for fundraising?
- How can we keep sensitive donor and other data private?
- What are the best resources for incorporating AI into our work?
- Who will be responsible for the use of AI at our nonprofit?
Join Our GO BIG! Training Seminar
We will discuss some of these topics and more at our GO BIG! training seminar on February 6–7, 2025. Reserve your spot now to stay on the cutting edge of fundraising best-practices and gain all the tools you need to launch a capital, capacity, or endowment campaign. Click on the picture below to register today!
Sample Nonprofit Policy for Internal AI Use
The following policy has been adapted from Fundraising.ai:
Policy Brief & Purpose
Our nonprofit AI tool usage policy outlines best practices for the use of artificial intelligence tools in the workplace, especially as it pertains to using sensitive data and proprietary company and customer information in these tools. We’ll explain how and how not to use AI tools especially as they become more prevalent in day-to-day work.
Scope
Artificial Intelligence (AI) tools are transforming the way we work. They have the potential to automate tasks, improve decision-making, and provide valuable insights into our operations.
However, the use of AI tools also presents new challenges in terms of information security and data protection. This policy is a guide for employees on how to be safe and secure when using AI tools, especially when it involves the sharing of potentially sensitive company and customer information.
Purpose
The purpose of this policy is to ensure that all employees use AI tools in a secure, responsible and confidential manner. The policy outlines the requirements that employees must follow when using AI tools, including the evaluation of security risks and the protection of confidential data.
Policy Statement
Our organization recognizes that the use of AI tools can pose risks to our operations and donors. Therefore, we are committed to protecting the confidentiality and integrity of all company and donor data. This policy requires all employees to use AI tools in a manner consistent with our security best practices.
Security Best Practices
All employees are expected to adhere to the following security best practices when using AI tools:
- Evaluation of AI tools: Employees must evaluate the security of any AI tool before using it. This includes reviewing the tool’s security features, terms of service, and privacy policy. Employees must also check the reputation of the tool developer and any third-party services used by the tool.
- Protection of confidential data: Employees must not upload or share any data that is confidential, proprietary, or protected by regulation without prior approval from the appropriate department. This includes data related to donors, employees, or partners.
- Access control: Employees must not give access to AI tools outside the company without prior approval from the appropriate department or manager and subsequent processes as required to meet security compliance requirements. This includes sharing login credentials or other sensitive information with third parties.
- Use of reputable AI tools: Employees should use only pre-approved reputable AI tools and be cautious when using tools developed by individuals or companies without established reputations. Any AI tool used by employees must meet our security and data protection standards.
- Compliance with security policies: Employees must apply the same security best practices we use for all company and customer data. This includes using strong passwords, keeping software up-to-date, and following our data retention and disposal policies.
- Data privacy: Employees must exercise discretion when sharing information publicly. As a first step, employees must ask themselves the following questions before uploading or sharing any data into AI tools: “Would I be comfortable sharing this information outside of the organization? Would we be okay with this information being leaked publicly?” The second step is to follow section b. from above.
Review and Revision
This policy will be reviewed and updated on a regular basis to ensure that it remains current and effective. Any revisions to the policy will be communicated to all employees.
Conclusion
Our organization is committed to ensuring that the use of AI tools is safe and secure for all employees and donors, as well as the organization itself. We believe that by following the guidelines outlined in this policy, we can maximize the benefits of AI tools while minimizing the potential risks associated with their use.
Acknowledgement and Compliance
All employees must read and sign this policy before using any AI tools in the organization. Failure to comply with this policy may result in disciplinary action, up to and including termination.
By signing this policy, I acknowledge that I have read and understand the requirements outlined in this policy. I agree to use AI tools in a manner consistent with the security best practices outlined above and to report any security incidents or concerns to the appropriate department or manager.
Employee Signature: ____________________________
Date: ____________________________







