FirmSideAINonprofit AI Academy | Governance

Loading your saved answers

A template for nonprofit organizations

AI Usage and Governance Policy

A ready-to-adopt policy that a nonprofit can make its own in an afternoon. It is written in plain language, built from the lessons in the FirmSideAI Nonprofit AI Academy, and designed to protect the people you serve while letting your team use AI with confidence.

How to use this template

Every highlighted field is a blank for you to fill in with your organization’s own answer. Read each section, replace the blanks, delete anything that does not apply, and add anything specific to your work. When you are done, download it as Word or PDF, have your board or leadership approve it, share it with staff and volunteers, and set a date to review it again.

This is a starting point, not the final word. A good policy is short, understood, and actually followed.

This policy at a glance

Organization
Policy owner
Applies to
All staff, volunteers, contractors, and board members who use AI tools in the course of 's work.
Effective date
Next review

1 Purpose

uses artificial intelligence tools to help us serve our mission. This policy exists so that we use those tools in a way that is safe, honest, and accountable to the people we serve.

By AI tools we mean software that generates text, images, code, or other content, or that helps sort, score, or decide. This includes tools you open on purpose, features built into software we already use, and vendor systems that make decisions in the background.

The goal is not to slow good work down. It is to make sure that a person stays responsible for what we produce, that private information stays protected, and that no one is harmed by a confident mistake.

2 Our principles

Everything in this policy follows from a few commitments. When a situation is not covered by a specific rule, use these to decide.

  • A person stays responsible. AI can help with a task, but a named human owns any decision that affects a person, and can change it.
  • Mission before novelty. We use AI where it helps us serve people better, not because a tool is new or fast.
  • Protect the information. We keep private and sensitive information out of tools that are not approved for it.
  • Be honest. We do not present AI-made work as something it is not, and we keep a record of how AI was used.
  • Serve everyone. We check that a tool works for all the people we serve, and we always keep a way to get help without using AI.
  • Leave a way to be questioned. Anyone affected by a decision can ask why and challenge it.

3 What information is safe to use

Whatever you type into an AI tool, treat as shared. Before you enter anything, decide what kind of information it is. A simple way to sort it, and you may adjust these labels, is by how sensitive it is.

Kind of informationExamplesMay it go into an approved tool?
PublicAlready published material, like a program description or an event flyer.Yes.
InternalEveryday internal notes with no personal or sensitive detail.Usually yes, in an approved tool.
ConfidentialPrivate plans and undecided matters.No, unless cleared.
RestrictedThe most tightly controlled information, like Social Security numbers, health records, or immigration status.No.
Beneficiary-sensitiveAny other detail about the people we serve that could harm them if exposed.No.

When you need to work with real material, remove the private parts first, or use made-up stand-in information. Aggregate numbers are usually fine. A named person's details are not.

A legal floor you cannot consent your way around

Some information is governed by law, such as health information under HIPAA, student education records under FERPA, or state privacy and breach rules. When a law applies, it sets a floor that policy and consent cannot lower. If you are unsure whether a law applies to a piece of information, treat that uncertainty as the signal to ask before you use it.

4 Approved tools

A tool being free, popular, or already inside our software does not tell us how it handles our data. Staff may use AI only through tools that has reviewed and approved for the kind of information involved. A personal account is not an approved tool.

Our current approved tools are listed below. To request a new one, contact , who reviews it before it may be used with any non-public information.

Approved toolApproved forNot to be used for

If a tool has not been reviewed, treat it as public and keep all sensitive information out of it until someone with the authority to approve it has signed off.

5 How to use AI well

Good results come from a steady, human-led method, not from clever prompts. Use this approach for any real work.

Define the task, and give safe context

Say what you want: the purpose, the audience, what a good result looks like, and any limits. Provide the material and examples the tool needs, and no more. Strip out anything private, following Section 3.

Verify before you use

Never pass an AI answer straight into real work. Run these five checks first.

  1. Math. Recompute any number yourself.
  2. Sources. Confirm any fact or citation against the real source. Assume citations, links, and quotes can be fabricated even when they look real, and open them to check.
  3. Scope. Check that it did not overreach or invent a requirement.
  4. Supported facts. Make sure every claim is backed by something you provided.
  5. Owner. Confirm the right person reviews and approves before it goes out.
Know when to stop

Hand a task to a person, rather than finishing it with AI, when the stakes are high, the authority is missing, the information is sensitive, you are uncertain, or checking the result well would take longer than doing the work yourself. Stopping is good judgment, not failure.

6 Levels of risk

Not every use of AI needs the same care. The right level of caution follows the stakes of the task and who is affected, not the tool. We sort uses into four levels.

LevelWhat it meansWhat it requires
RoutineLow stakes, easily reversible, no decisions about people. For example, drafting an internal note.Allowed by default, following the safe-use rules above.
ControlledReal stakes, but manageable with care. For example, an external communication.Allowed with a human review and approval before it goes out.
RestrictedHigh stakes that touch a person's outcome or sensitive data. For example, anything shaping a decision about eligibility, hiring, or services.Allowed only with strong safeguards, a named human owner, an appeal path, and sign-off from .
ProhibitedUses we have decided we will not do.Not permitted. Our current list: .

When a use does not clearly fit a level, or someone wants an exception, they ask , who decides and records the answer.

7 Human oversight and appeal

For any use that affects a person, a human stays meaningfully in control. That means a real person, with the knowledge, the authority, and the time to change the outcome, is responsible for it. A signature on whatever the tool produced is not oversight.

It also means the people affected can find out that a decision was made, understand the basis, and challenge it. For each restricted use, we name the human owner and give affected people a real way to appeal and reach a person who can answer.

Some rights are set outside our policy

For some decisions, especially about benefits, housing, employment, or eligibility, the law or a funder may already require specific notice and appeal rights. Our job is to meet those, not to invent our own. When a decision like this is in play, check with .

8 Records and disclosure

When AI helps with real work, keep a short record so anyone can later understand what happened. A few notes attached to the work are usually enough: what information was used, what the tool produced, how it was checked, who approved it, what was kept, and whether the use of AI was disclosed.

Be honest about AI use in a way that fits the audience. A quick internal draft may need nothing said. A public message, a fundraising appeal, or anything a person will rely on may need it made clear. We never present AI-made images or stories as real events that did not happen, and we do not use a real person's likeness or voice without the right to do so.

9 When something goes wrong

Even careful people hit incidents: information sent to the wrong place, a message pretending to be a colleague, a fake voice or image, or a tool used that was never approved. The first response is a short sequence you can run under pressure.

  1. Recognize the warning signs, especially pressure to move fast or go around the normal process.
  2. Stop, and do not act on the request yet.
  3. Preserve it. Do not delete or try to fix it yourself, because that can destroy the record we need to respond.
  4. Report it through our trusted route, below.
Report an incident to
By

Urgency is a warning sign, not a reason to skip this process. Slow down and report through a channel you already trust.

10 Choosing tools and vendors

Most AI we use comes from a vendor we do not control. Before adopts a new tool, whoever proposes it answers these questions, and reviews the answers.

  • Scope. What is the tool for, who does it affect, what information flows into it, and how would we leave and get our data back?
  • Data and training. Will our information be used to train the vendor's models? If we cannot turn that off, that is itself the answer for sensitive data.
  • Retention and deletion. How long is our data kept, and can we have it deleted on request?
  • Evidence. What proof supports the vendor's claims about accuracy, fairness, security, and accessibility? A missing answer counts as a risk.
  • Contract. How and how fast are we told about a breach, who carries the cost if something goes wrong, and how do we end the relationship cleanly? Route the hard terms to counsel.

Some uses may sit under state, federal, funder, or sector rules. Using AI in hiring, benefits, or eligibility is among the most regulated. When a real rule may be in play, treat it as a question for . This policy helps us spot the trigger and ask. It is not legal advice.

11 Who governs this, and how

This policy is owned by , who keeps it current and answers questions about it. We keep governance simple and ongoing, organized around four habits.

  • Govern. The culture, roles, and accountability that everything else runs inside. This policy is part of it.
  • Map. Keep an honest inventory of where AI is used, including embedded and vendor tools, each with a named owner.
  • Measure. Watch how our uses are performing, including any harm, not just the benefits.
  • Manage. Act on what we find, from adjusting a use to pausing or stopping it.

AI oversight is a standing item for on a schedule, with a short and honest set of measures. We review and update this policy at least once a year, and sooner when something important changes.

Who is responsible

ResponsibilityWho holds it
Owns and updates this policy
Approves new tools and exceptions
Receives incident reports
Board or leadership oversight

Adoption and sign-off

This policy takes effect when adopted by 's . It is shared with all staff, volunteers, and contractors who use AI tools.

Adopted by
Title
Signature
Date

How this connects to the training

Every section of this policy comes straight from a lesson in the FirmSideAI Nonprofit AI Academy. Section 3 is the safe-data lesson, Section 5 is the human-led method and the five checks, Section 6 is the risk-tier lesson, Section 7 is human oversight, Section 9 is incident response, Section 10 is vendor due diligence, and Section 11 is the governance model. Learn it, then run it.

Prepared by FirmSideAI for the Delaware nonprofit community. This template is a starting point you are free to adapt. It is not legal advice.