Nonprofit AI policy checklist

A Practical AI Policy Checklist for Nonprofits

A policy should help staff make better everyday decisions. If it only defines artificial intelligence and warns people to be careful, it has not finished the job.

Updated July 21, 2026 • Minnesota-focused practical guidance

Start with the work, not the tool list

Nonprofit teams may use AI while drafting communications, planning programs, organizing internal information, researching funding, or preparing first versions of routine material. The policy should connect rules to those situations instead of treating every use as identical.

This checklist is operational guidance, not legal advice. Organizations should route the final policy to legal counsel, HR, insurance, funders, or compliance reviewers when those responsibilities apply.

The core decisions every policy should answer

Staff should be able to find a clear answer to each of these questions without guessing.

  • Which AI tools are approved, restricted, or prohibited
  • What participant, client, donor, employee, financial, health, or confidential information must stay out
  • Which outputs require fact-checking, source review, editing, or supervisory approval
  • Whether AI may be used for decisions that affect services, employment, funding, safety, or eligibility
  • How AI-assisted work should be disclosed when transparency is appropriate
  • Who owns exceptions, incident reporting, policy updates, and vendor review
  • How staff receive training and acknowledge the policy

Human review must be specific

Telling people to use human review is too vague. The policy should say what the reviewer checks: facts, tone, privacy, bias, source quality, permissions, contractual requirements, and fit with the organization’s mission and voice.

The National Institute of Standards and Technology’s AI Risk Management Framework provides a useful structure for thinking about governance, measurement, and risk management. A smaller organization does not need to reproduce the entire framework, but it can use the same discipline: name the risk, assign ownership, document the control, and review whether it works.

Plan the rollout before approval

A policy becomes useful when staff understand how it applies to their work and know where to take uncertain questions.

  • Use role-specific examples instead of only reading the policy aloud
  • Give staff an approved-tool list and a short data-handling reminder
  • Name the person or group that answers questions
  • Set a review date because tools, contracts, and organizational needs change
  • Capture incidents and near misses so future training improves

Frequently asked questions

Can a small nonprofit use a short AI policy?+

Yes. A short policy can work when it clearly covers approved tools, restricted information, required review, prohibited decisions, ownership, and training. Clarity matters more than page count.

Should the policy name ChatGPT, Copilot, Gemini, or other tools?+

It can. A practical format combines a changeable approved-tool list with durable rules that apply even when products change.

Is an AI policy the same as staff training?+

No. The policy sets expectations. Training helps people apply them to real situations. Most organizations need both if they expect consistent behavior.

Ready when you are

Turn the reading into a practical next step.

Bring the audience, the work, and the risk questions. We will recommend the smallest useful training, policy, or workflow engagement.