Using AI responsibly: a one-page policy for nonprofits

Using AI responsibly: a one-page policy for nonprofits

Puzzle Piece A Moral Fabric pattern, free for any nonprofit to use and adapt.

The context

AI assistants reach daily use in most nonprofit teams before anyone writes a policy. Without one, each person invents their own rules for privacy, review, and disclosure — usually under deadline. One page settles the recurring questions.

The pattern

Five rules cover most situations:
    Say when you used AI internally. Name the tool and roughly how ("Claude drafted this, I rewrote the intro"), so colleagues learn what works.
    Keep a human in the loop. AI never makes final decisions about participants, donors, or staff, and important communications get a human review before they go out.
    Protect personal data. No names, email addresses, or other identifiable details in chat prompts — anonymize first ("Participant A"). Authorized connectors to your drive or mail run under the vendor's data-processing agreement; use them for work tasks only and keep the data inside.
    Keep an approved-tools list. One primary assistant plus a short list of approved integrations, with a quick review before any new tool touches organization data.
    Share learnings, failures included. A dedicated chat channel or a recurring workshop slot is enough.
Decision test: would you be comfortable explaining exactly how you used AI to the people affected? If unsure, ask a colleague before proceeding.

What to use

  • One frontier-model assistant as the primary tool; team plans run €25–30 per user per month. Ethan Mollick's  Which AIs to use, and how to use them  is a regularly updated overview.
  • A European assistant (Mistral Le Chat, Proton Lumo) as a secondary option where data sovereignty matters to your board or funders.
  • Two companion patterns:  AI-assisted writing: humanize the draft before you read it  for text work, and  Managing AI usage limits on a Claude Team plan  for budget questions.

What's mandatory regardless

  • GDPR: personal data in a prompt is data processing. A tool without a data-processing agreement can't receive it.
  • Never create fake content (testimonials, deepfakes) or misrepresent authorship, in either direction.

Your variation

Record your approved tool list, who reviews new integrations, your disclosure norm, and where learnings get shared.