Nonprofit AI Policy Template
A fill-in-the-blank AI use policy built for nonprofits — donor and beneficiary data, funder disclosure, fairness, volunteers, and board oversight, all in one.
A nonprofit AI policy is the written rulebook that says how your staff, volunteers, and board may — and may not — use AI tools like ChatGPT, Copilot, or Gemini on your organization's work. A nonprofit AI policy has to answer questions a generic company policy skips: Can we put donor records or beneficiary case notes into an AI tool? Does a funder expect us to disclose AI use in a grant application? How do we keep AI from treating the people we serve unfairly? Who on the board signs off? An all-purpose acceptable-use policy ignores all of this, which is exactly why a nonprofit that adopts one is still exposed on the issues its funders, donors, and beneficiaries care about most.
This page gives you the full policy on-screen — every section written in plain language with [bracketed] blanks you fill in for your organization. Read it, copy it, or grab the editable DOCX download and customize it with your organization name, approved tool list, and oversight roles in minutes.
How to Use This Template
This template is a starting point, not finished legal advice. Work through it top to bottom, fill in every [bracketed] field, and delete anything that does not fit how your nonprofit operates. An all-volunteer food pantry and a 200-person health nonprofit need different versions — the final section shows you what to change for each.
Have the person or committee that owns risk (executive director, board, or a technology committee) approve the final version before you circulate it. Then have every staff member and volunteer sign the acknowledgment so you have a clear record that everyone agreed to the rules.
- Fill in every [bracketed] field — organization name, approved tools, policy owner, effective date.
- Match Section 4 to your actual funders — pull the AI or data terms from each grant agreement.
- Have your ED or board approve it, then collect signed acknowledgments from staff and volunteers.
- Re-read it against your funders' requirements and your data privacy obligations before you adopt it.
This nonprofit AI policy template gets you started, but a signed PDF is not a program. Layer3 Labs helps nonprofits turn it into working AI governance that protects donor and beneficiary data and satisfies funders — approved tools, grant-writing workflows, and volunteer training. Book a consultation to scope it.
Book a ConsultationSection 1 — Purpose & Scope
This section says why the policy exists and who it applies to. Keep the scope broad so a new volunteer or a contract grant writer cannot say the rules did not cover them.
- Purpose: This policy governs how everyone at [ORGANIZATION NAME] uses artificial intelligence (AI) tools in their work, so the organization protects the people it serves, honors donor trust, and meets its obligations to funders.
- "AI tools" means any generative or machine-learning system that creates, summarizes, drafts, analyzes, or predicts — including [ChatGPT, Microsoft Copilot, Claude, Gemini], any nonprofit-specific tools like [list approved tools], and any AI feature built into other software.
- This policy applies to all staff, volunteers, board members, interns, contractors, and any vendor working on organization matters.
- It covers AI used on any device — organization-issued or personal — whenever the work touches donor data, beneficiary data, or other organization information.
- Where this policy conflicts with a specific funder's grant terms or a data privacy law, the stricter rule controls.
Section 2 — Approved Tools & Approval Process
Staff and volunteers should only use AI tools the organization has vetted for security and data handling. This section names what is approved today and how to get something new approved — so people do not quietly paste donor or beneficiary data into whatever free tool they found.
- Only tools on the organization’s Approved AI Tools list may be used for organization work. As of [DATE], the approved tools are: [list — e.g., enterprise ChatGPT with data-retention off, Copilot for M365, Google Workspace AI].
- Approved "enterprise" tools are those with a signed data agreement, a no-training-on-our-data commitment, and appropriate security — verified by [IT / POLICY OWNER].
- Consumer or free versions of AI tools may NOT be used for anything involving donor, beneficiary, or confidential information.
- To request a new tool, submit [form / email] to [POLICY OWNER / IT]; do not use it on organization work until it is added to the list.
- Nonprofits can access discounted or donated software through programs like TechSoup and Google for Nonprofits — vet these the same way before adding them.
- The Approved AI Tools list is maintained by [POLICY OWNER / ROLE] and reviewed at least [quarterly].
Section 3 — Donor, Beneficiary & Confidential Data
This is the heart of a nonprofit AI policy. Your organization holds sensitive information about donors and the people you serve. Entering that data into a public AI model can expose it to third parties and break the trust your mission depends on. The rules below keep donor and beneficiary data out of any tool that is not locked down.
- Never enter donor records, beneficiary case notes, health or immigration status, financial details, board minutes, or other confidential information into any AI tool that is not on the organization’s approved, secured list.
- Never use a public or consumer AI tool (free ChatGPT, public chatbots, browser AI features) for anything involving personal data about donors or the people you serve.
- Assume that anything typed into a non-approved tool could be seen by outsiders — treat the prompt box like a public post.
- When an approved tool is used, still minimize what you enter: strip names and identifiers where the task does not need them.
- If you are unsure whether information is confidential or whether a tool is safe, do NOT enter it — ask [POLICY OWNER / ROLE] first.
- Report any suspected exposure of donor or beneficiary data through an AI tool immediately under Section 9.
Section 4 — Grant Writing & Funder Disclosure
Funders are starting to ask whether AI was used to write grant applications, and some grant agreements now include AI or data terms. This section makes those funder rules operational so a grant writer cannot use AI in a way a funder prohibits. Always check each funder's guidelines before using AI on an application.
- Before using any AI tool on a grant application or report, check that funder's guidelines for AI-use or AI-disclosure terms and follow them.
- Where a funder requires it, disclose that AI assisted with an application, and describe how — do not hide or misstate AI use.
- Never enter a funder’s confidential materials, or your beneficiaries’ personal data, into a non-approved AI tool while preparing an application.
- A qualified person must review every AI-assisted grant application for accuracy before submission — AI can invent statistics, outcomes, or citations that are not true.
- Keep a record of each funder's AI position in [grants management system], and treat a matter as "AI disclosure required" when the funder's stance is unclear.
- Tools built for nonprofits like Grantable or Instrumentl still require human review and funder-rule checks before use.
Section 5 — Prohibited Uses
A short, blunt list of things nobody at the organization may do. These are the actions most likely to break donor trust, harm a beneficiary, or put a grant at risk.
- Do NOT enter donor, beneficiary, or confidential information into any non-approved or public AI tool.
- Do NOT send, publish, or rely on AI-generated work — grant applications, reports, communications, beneficiary decisions — without a qualified person reviewing and verifying it first.
- Do NOT let AI output stand in for a human's judgment on decisions that affect a person who receives your services.
- Do NOT use AI in a way a funder, donor, or grant agreement prohibits.
- Do NOT use AI to create anything false or misleading in fundraising, grant applications, or public communications.
- Do NOT use AI to make an eligibility or benefits decision about a person without a documented human review of the result.
- Do NOT bypass the approval process by using a personal account or unapproved tool for organization work.
Section 6 — Human Review & Accuracy
AI tools make things up — including fake statistics, quotes, and sources that look real. Publishing them can embarrass your organization and mislead funders. ABA-style rules do not apply here, but your duty to be accurate with donors and funders does. A human always owns the final work.
- A qualified person must review and verify every piece of AI-assisted work before it is used, sent, or published.
- Check every statistic, quote, and source the AI produces against the actual data — never assume a number or citation is real.
- Confirm the substance is correct and current: AI can be outdated or simply wrong about your programs or your field.
- The reviewing person is fully responsible for the work as if they had written it themselves — "the AI wrote it" is never an excuse.
- Only use AI for tasks you are competent to check; if you cannot evaluate the output, do not rely on it.
- Supervisors must make sure staff, volunteers, and contractors follow this review step.
Section 7 — Fairness & Bias in Beneficiary Decisions
When AI touches decisions about the people you serve — who qualifies for help, how cases are prioritized, who gets outreach — it can quietly repeat bias in its training data. A nonprofit exists to serve people fairly, so this section keeps AI from causing harm to the communities you serve.
- Do not let an AI tool make a final decision about a person’s eligibility, benefits, or priority — a human must review and own every such decision.
- Watch for bias: AI can disadvantage people by race, gender, disability, language, immigration status, or ZIP code even when no one intends it to.
- Test AI-assisted decisions for unfair patterns before you rely on them, and keep a way for a person to appeal or ask for a human review.
- Be transparent with beneficiaries when AI plays a meaningful role in a decision that affects them.
- Prefer approved tools that let you document how a decision was reached over black-box tools you cannot explain.
- When you cannot explain or justify an AI-driven outcome to the person it affects, do not use AI for that decision.
Section 8 — Volunteer & Staff Use
Nonprofits run on volunteers and part-time staff who may not have security training. This section makes the everyday rules clear for everyone, not just full-time employees, because a well-meaning volunteer is a common way data leaks.
- Volunteers, interns, and contractors must follow this policy exactly as staff do, and sign the acknowledgment before doing AI-assisted work.
- Use only your organization-managed account for AI work; do not use a personal AI account for organization tasks.
- Do not share donor or beneficiary data with an AI tool just because it would make a task faster.
- New volunteers and staff get a short briefing on this policy as part of onboarding.
- [POLICY OWNER / ROLE] is available to answer AI questions — when unsure, ask before you act.
- Report any AI mistake or suspected data exposure right away under Section 9, without fear of blame.
Section 9 — Security & Incident Reporting
This section covers how AI tools are secured, who is responsible, and what to do when something goes wrong — because an AI mistake with donor or beneficiary data is a data incident.
- The [POLICY OWNER / ROLE] owns this policy; [IT / SECURITY LEAD] vets tools and maintains security controls.
- Approved AI tools must use organization-managed accounts with data-retention and training settings configured for confidentiality.
- Access to AI tools handling donor or beneficiary data is limited to authorized people; no shared or personal logins for organization work.
- If you suspect donor or beneficiary data was exposed to a non-approved tool, report it to [POLICY OWNER / IT] within [24 hours].
- The organization will assess each reported incident for who must be notified — including affected people and, where required, funders or regulators.
- Retaliation for good-faith reporting is prohibited.
Section 10 — Board Oversight & Review Cadence
AI tools and funder expectations change fast, and the board carries ultimate responsibility for the organization. This section keeps the policy current and puts oversight where it belongs.
- The board (or a board committee) reviews this policy at least [annually] and whenever major funders, AI tools, or privacy laws change.
- The [EXECUTIVE DIRECTOR / POLICY OWNER] reports to the board on AI use, incidents, and any beneficiary-impact concerns at least [annually].
- Material changes are communicated to all staff and volunteers, and updated acknowledgments are collected.
- The Approved AI Tools list (Section 2) is reviewed more often — at least [quarterly].
- As a 501(c)(3), the organization uses AI in ways consistent with its charitable mission and does not let AI decisions drift from that purpose.
How to Customize This Policy for Your Org Size
Every nonprofit's version of this policy looks a little different. Use these notes to tailor it before you adopt it.
All-volunteer and small nonprofits: keep it lean. One person may be the policy owner, IT lead, and reviewer all at once — say so plainly, and lean on approved, low-cost tools rather than building review committees. Section 8 (volunteer use) matters most for you, since volunteers do much of the work.
Mid-size nonprofits: name real roles (executive director, program directors, a technology or data lead), tighten Section 2’s approval workflow, and build Section 4 around a real funder-tracking process since you likely juggle several grants with different terms.
Large nonprofits: add a board technology or AI committee, formalize the bias testing in Section 7, and expand Section 9 security controls — you hold more data and face more scrutiny from funders and regulators.
Program-heavy nonprofits that make eligibility or benefits decisions: expand Section 7 (fairness) — this is where your risk to the people you serve is highest.
Whatever your size, run the final version past your funders' requirements, your data privacy obligations, and — for higher-stakes uses — a qualified advisor before adopting it. Sector groups like NTEN publish nonprofit-specific AI guidance worth reviewing.
Frequently Asked Questions
- Yes. The full policy is on this page to read and copy at no cost, and the editable DOCX download is free too. Fill in the [bracketed] fields with your organization name, approved tools, and oversight roles, then have your ED or board approve it. It is a starting point — have a qualified advisor review your final version.
- Because a generic policy skips the issues that create the most risk for a nonprofit. It does not address donor and beneficiary data, funder AI-disclosure expectations, fairness in beneficiary decisions, volunteer use, or board oversight. A nonprofit that adopts a generic policy is still exposed everywhere its funders, donors, and the people it serves actually look. This template is built around those nonprofit-specific concerns.
- Yes. Section 3 keeps donor records, beneficiary case notes, and other confidential information out of any non-approved or public AI tool, because entering it can break donor trust and violate a privacy law. Section 9 adds security controls and an incident-reporting process for when donor or beneficiary data is exposed.
- Increasingly, yes. Some funders now ask whether AI helped write an application, and some grant agreements include AI or data terms. Section 4 makes checking each funder’s guidelines a required step, tells you to disclose AI use where a funder requires it, and requires a human to verify every AI-assisted application for accuracy before submission.
- AI can quietly repeat bias in its training data — disadvantaging people by race, gender, disability, language, immigration status, or ZIP code even when no one intends it. Section 7 requires a human to own every eligibility or benefits decision, tells you to test AI-assisted decisions for unfair patterns, and gives beneficiaries a way to ask for a human review.
- The person or group responsible for organizational risk — your executive director, your board, or a board technology committee. Because the board carries ultimate responsibility for a nonprofit, leadership should approve the policy, review it at least annually, and collect signed acknowledgments from all staff and volunteers.
Turn this template into a real AI program for your nonprofit
A policy on paper is step one. Layer3 Labs helps nonprofits stand up AI they can actually trust — approved tools, donor and beneficiary data protection, funder-safe grant workflows, and volunteer training.
Book a Consultation