What Should Our Nonprofit AI Policy Cover, and What Oversight Should the Board Provide in 2026?
A practical guide to creating an AI governance framework that protects your nonprofit, satisfies board fiduciary duties, and provides clear guidance to staff — without becoming a bureaucratic barrier to responsible AI adoption.
Bottom line
Every nonprofit using AI needs a policy, and every board has a fiduciary responsibility to oversee AI use. But what should the policy actually cover? How much oversight is appropriate versus excessive? And how do you create governance that enables responsible AI use rather than just restricting it? This guide provides a policy template, board oversight framework, and practical answers to the governance questions nonprofit leaders are asking.
In this guide
The Short Answer
A nonprofit AI policy should cover eight things: (1) which AI tools are approved for organizational use, (2) what data can and cannot be entered into AI tools (by data classification tier), (3) when AI use must be disclosed to stakeholders, (4) what human review is required before AI output is used externally, (5) how AI-related incidents and near-misses are reported and handled, (6) roles and responsibilities for AI governance, (7) how the policy is updated as tools and regulations change, and (8) the board's specific oversight responsibilities.
The board's role is not to approve individual AI tools or review specific AI outputs. It is to ensure that: an AI policy exists and is current, AI risks are being identified and managed, AI use aligns with the organization's mission and values, and the board receives regular reporting sufficient to exercise oversight. Board members don't need to be AI experts — they need to ask good questions and ensure the answers are satisfactory.
The Eight Essential Components of a Nonprofit AI Policy
Component 1: Purpose and Scope
State clearly why the policy exists and who it applies to. Example: 'This policy governs the use of artificial intelligence tools by all staff, volunteers, contractors, and board members in the course of [Organization Name]'s work. Its purpose is to enable responsible AI use that advances our mission while protecting the people we serve, our donors, our staff, and our organization from AI-related harm.'
Component 2: Approved Tools and Procurement
List the AI tools approved for organizational use, by tier if appropriate (e.g., 'Tier 1 — approved for general use with organizational data,' 'Tier 2 — approved for specific purposes only,' 'Tier 3 — prohibited'). Include a process for requesting approval of new tools: who evaluates the request, against what criteria (data privacy, mission alignment, cost, security), and how quickly they respond. The approved list should be reviewed and updated quarterly — the AI tool landscape changes too fast for annual review.
Component 3: Data Classification and Handling
Define your organization's data classification tiers (see Article 5 in this series for a detailed framework) and specify what tiers of data can be entered into what tiers of AI tools. The minimum safe configuration: public data can go into any tool; internal operational data requires team/business-tier tools with data protection; sensitive stakeholder data requires explicit protocols, data minimization, and documented purpose; protected/high-risk data generally should not go into AI tools without legal review and formal data protection agreements.
Component 4: Human Review and Accountability
Specify the minimum human review required before AI-generated content is used externally. The standard: 'No AI-generated content may be sent to donors, funders, beneficiaries, partner organizations, or the public without review and approval by a qualified staff member who takes responsibility for its accuracy, appropriateness, and alignment with organizational values.' For high-risk use cases (legal information, health information, benefits eligibility, crisis communication), consider requiring two-person review.
Component 5: Disclosure Requirements
Specify when AI use must be disclosed and to whom. Detailed guidance is in Article 8 of this series, but the policy should establish the principle: disclose when a reasonable stakeholder would consider AI involvement material to their assessment of the communication or decision, when required by law or funder policy, and when your organization has made public commitments to AI transparency.
Component 6: Incident Reporting
Establish a clear process for reporting AI-related problems: what constitutes a reportable incident (data exposure, harmful output reaching stakeholders, regulatory violation, near-miss), how to report it (a specific email, form, or designated person), what happens after a report (investigation, containment, notification, remediation), and the non-punitive norm (staff should feel safe reporting AI problems, including their own mistakes).
Component 7: Roles and Responsibilities
Define who is responsible for what: the executive director or designated AI lead is responsible for policy implementation and maintenance, all staff are responsible for following the policy and reporting concerns, managers are responsible for ensuring their teams understand and follow AI guidelines, and the board is responsible for oversight (see below).
Component 8: Policy Review and Update
Specify how often the policy is reviewed (at minimum quarterly given the pace of AI and regulatory change), who is responsible for review, and how updates are communicated to staff. Date-stamp every version. Archive previous versions.
Board Oversight: What the Board Should (and Shouldn't) Do
What the Board SHOULD Do
Ensure an AI policy exists and is current. This is a basic fiduciary responsibility. If your nonprofit is using AI without a policy, the board should direct management to create one within a specified timeframe and report back.
Ask five specific questions at least annually: (1) How is our organization using AI, and for what purposes? (2) What are the most significant AI-related risks we face, and how are they being managed? (3) How do we know our AI use is consistent with our mission, values, and legal obligations? (4) Have there been any AI-related incidents or near-misses, and what did we learn? (5) What AI-related regulations or funder requirements are emerging that might affect us?
Ensure AI risk is integrated into the organization's risk management framework, not treated as a separate technology concern. AI risks — privacy, accuracy, bias, reputational, regulatory, mission — are organizational risks, not IT risks.
Model responsible AI use. Board members who use AI for board work should follow the same guidelines as staff. If the board expects staff to review AI output before use, board members should do the same with AI-generated board reports or communications.
Consider whether the board needs AI expertise. Most nonprofit boards don't need an AI expert, but they do need at least one board member who understands enough about AI to ask informed questions and help the full board exercise oversight. If no current board member has relevant knowledge, consider it in your next board recruitment cycle or provide AI literacy training to the full board.
What the Board Should NOT Do
- Micromanage tool selection. The board's job is to ensure a sound process exists, not to pick which AI tools the organization uses.
- Require board approval for individual AI use cases (unless they involve extraordinary risk or resource commitment).
- Write the AI policy. The board approves the policy; management drafts it based on operational knowledge.
- Set AI strategy. The board ensures strategy exists and is sound; management develops it.
- Ban AI use out of excessive caution. The board's duty is to ensure risks are managed, not eliminated at the cost of mission effectiveness.
When to Update Your AI Policy
Review and update your policy when: new AI tools are adopted for significant organizational use, regulations change (EU AI Act, state AI laws, funder requirements), an AI incident or near-miss reveals a policy gap, six months have passed without review (the AI landscape changes too fast for annual cycles), or your organization enters a new domain of AI use (e.g., moving from internal drafting to beneficiary-facing AI).
Sources and verification
Product details and claims were checked against the following primary sources.
Frequently asked questions
Our board has no AI expertise. Can they still provide meaningful oversight?
Yes. Meaningful AI oversight doesn't require technical expertise — it requires asking good questions and insisting on satisfactory answers. The five questions listed above (under Board Oversight) require no AI knowledge to ask, and the quality of management's answers will tell the board most of what it needs to know. Boards oversee finance without every member being an accountant, legal matters without every member being a lawyer, and programs without every member being a subject-matter expert. AI is no different. That said, having at least one board member with AI literacy — either existing or developed through training — will improve the quality of board discussion and oversight.
How detailed should our AI policy be? Our organization ranges from 5 to 50 employees.
The policy should be detailed enough that staff know what to do in common situations and short enough that they'll actually read and reference it. For a 5-person organization, a 2-3 page policy covering the essentials (approved tools, data rules, human review requirements, incident reporting) is sufficient. For a 50-person organization with more complex AI use, a 4-6 page policy plus role-specific guidance may be appropriate. The test: can a staff member facing a common AI question (Can I put this client data into ChatGPT? Do I need to disclose AI use on this grant report?) find the answer in the policy in under two minutes? If not, the policy is too long or poorly organized.
What's the minimum viable AI policy for a nonprofit just starting with AI?
A one-page document covering: (1) You may use [list of 2-3 approved tools] for work purposes. (2) Never enter client, donor, or employee personal information into free-tier AI tools. (3) All AI-generated content intended for external use must be reviewed and approved by a human before it goes out. (4) If you're unsure whether something is okay, ask [specific person]. (5) If something goes wrong — data gets entered where it shouldn't, AI produces harmful output, you're not sure what to do — tell [specific person] immediately. There will be no negative consequences for reporting in good faith. That's it. You can expand later as your AI use matures, but this covers the critical risks while enabling responsible experimentation.
Should our AI policy be a standalone document or part of existing policies?
Start with a standalone policy — it's easier to draft, update, and train staff on. Over time, as AI becomes integrated into organizational operations rather than a novel technology, AI provisions should be incorporated into relevant existing policies: data privacy policy (AI data handling), communications policy (AI disclosure), HR policy (employee AI use and training), IT policy (approved AI tools and security requirements), and ethics policy (AI-specific ethical commitments). Eventually, a standalone AI policy may become unnecessary because AI governance is embedded throughout organizational governance. But for now, a dedicated policy provides clarity and focus that distributed provisions don't.
Continue exploring
A useful next step
Canva AI for Brand Design: 2026 Workflow for Consistent Visual Assets
How to use Canva's AI tools — Magic Design, Brand Kit, AI photo editing, and Magic Write — to create and maintain a consistent brand identity without a design team.
Step-by-step workflow for using Canva's AI features to design a complete brand identity system. Covers Magic Design for initial concepts, Brand Kit for consistency, AI photo editing for on-brand imagery, and templates that scale across social media, presentations, print, and web.
Read guide
AI Brand Identity System: From Moodboard to Consistent Visual Assets in 2026
How to build a coherent brand identity system using AI tools — moodboards, color palettes, typography, logo concepts, and brand guidelines — without a design agency.
Complete brand identity system workflow using AI tools at every stage. Covers moodboard creation, color palette generation, typography pairing, AI-assisted logo concepts, brand guidelines documentation, and asset templates. Designed for founders, nonprofit leaders, and marketing teams building or refreshing a brand.
Read guide
How to Create an AI Acceptable Use Policy for Your Organization in 2026
A practical framework for small businesses and nonprofits to create clear, enforceable AI use policies — covering data privacy, tool approval, employee responsibilities, and governance.
Step-by-step guide to creating an AI acceptable use policy for your organization. Covers data privacy rules, tool approval processes, employee responsibilities and training, prohibited uses, enforcement, and template sections. Designed for small businesses, nonprofits, and lean operations teams who need practical governance without a dedicated legal department.
Read guide
How Nonprofits Can Use AI for Grant Reporting and Compliance in 2026
Reduce the burden of grant reporting with AI tools that help compile metrics, generate narrative, reconcile budgets, and meet funder requirements without cutting corners on accuracy.
Grant reporting is one of the heaviest administrative burdens nonprofits face. AI tools can dramatically reduce reporting time while maintaining the accuracy and transparency funders expect. This guide walks through the full workflow — from data compilation to narrative generation to compliance checklist verification.
Read guide
Keep the useful part coming
Practical AI guidance for lean teams.
Get one weekly email with important tool changes, carefully selected resources, and workflows you can actually use. No hype; unsubscribe any time.
Tools mentioned in this article
ChatGPT
The general-purpose AI assistant that started it all
OpenAI's flagship conversational AI model, powering everything from casual chat to complex reasoning, coding, and creative work.
Claude
Anthropic's thoughtful, safety-focused AI with exceptional long-form reasoning
Claude excels at deep analysis, long-form writing, and nuanced reasoning. Built by Anthropic with a focus on safety and helpfulness.