Leadership & Strategy

How to Write an AI Policy for Your Nonprofit (with Template)

Peer-reviewed research points to a surprise: the conversation that produces an AI policy predicts success more than the document itself.

A nonprofit leadership team reviews the sections of an AI policy together in a conference room

The policy gap is a leadership gap

Consider a case recently documented in the Journal of Public Affairs Education. A charity made what looked like a careful ethical choice: rather than photograph the people it serves for a fundraising campaign, a practice many in the sector criticize as exploitative, it used AI-generated images instead. The campaign avoided one ethics problem and created another. Donors were never told the images were synthetic, and researchers concluded the practice risked misleading the very people whose trust the organization depends on.

Reasonable people can disagree about what that charity should have done. What is harder to dispute is that the question should never have rested on one campaign manager's judgment in the middle of a production deadline. It was a governance question, and there was no policy to govern it.

The sector data suggests this situation is the rule, not the exception. In a survey of 179 nonprofits by Stanford's Institute for Human-Centered Artificial Intelligence and Project Evident, 84 percent of nonprofit respondents reported using generative AI at work at least occasionally, yet 78 percent said their organization has no policy regulating its use. TechSoup's 2025 sector benchmark points the same direction: 76 percent of nonprofits have no AI strategy at all. Adoption is running well ahead of governance, and the gap between the two is where organizations get hurt.

This is why the framing of an AI policy matters so much. It is not compliance paperwork, and it is not an IT document. An AI policy is the moment your leadership team formally begins governing a technology your staff already use. And the research now points to something most policy guides miss entirely: the process of writing it may matter more than anything it says.

Why the process matters as much as the document

There is now peer-reviewed evidence that how a nonprofit talks about AI internally shapes how well it adopts it. In a 2026 study published in Nonprofit and Voluntary Sector Quarterly, Wanzhu Shi and Lauren Azevedo surveyed 168 nonprofit organizations and interviewed 14 executive directors. Organizations that had never held an internal conversation about AI tools were significantly less likely to support healthy adoption, while those with an innovative culture and an open communication process were more likely to adopt deliberately. The same study found that roughly half of nonprofits feel pressure to adopt AI simply because other organizations are doing so. That is adoption for defensive reasons, which is precisely what a policy process should replace with intention.

A second finding tells you who should help write the policy. Studying human service organizations, Lauri Goldkind and colleagues found that nearly every organization has staff members who are already quietly using AI in their daily work, often without telling anyone. Rather than pretend these early adopters do not exist, the authors recommend that leaders engage them openly, and they belong in the room when the policy is drafted. They are the fastest route to a realistic document: their workarounds show you where the demand is, and their mistakes show you where the risk is.

Nonprofit staff of different generations discussing how their organization should use AI
The internal conversation itself predicts healthy adoption, the research suggests.

The finding matches what I have seen across more than fourteen years in nonprofit leadership, most of it with one of the largest nonprofit organizations in the country. I have never watched a policy succeed because it was well written. The policies that actually change behavior are the ones the staff helped build, argued about, and understood before the board ever saw them. The ones that arrive finished, by email, get skimmed once and filed.

Taken together, the research and the experience point to one practical conclusion: do not hand a template to a single manager with a deadline. The copy-paste policy that gets adopted in one meeting and filed away is the most common failure mode in the sector, and it forfeits the one benefit the evidence says matters most, which is the conversation itself.

What an AI policy actually decides

Strip away the boilerplate and a working AI policy makes eight decisions. Each one below comes with the reason a board member should care.

1. Scope. Who does this policy cover, and which tools? Staff is the obvious answer, but most nonprofits run on volunteers, board members, and contractors who touch donor data and beneficiary information. A policy that ignores them governs a fraction of the actual risk.

2. Permitted and prohibited uses. Resist the flat list of banned tools. Tier uses by risk instead: encouraged uses (drafting, summarizing, brainstorming), uses requiring review, and prohibited uses. Anything that affects a person's access to services, employment, or benefits belongs in the highest tier with mandatory human review.

3. Data protection. The single most important line in the policy: what may never be entered into a public AI tool. Donor records, beneficiary details, health information, and anything covered by a grant agreement or privacy law. Researchers studying AI in the philanthropic context note that mainstream AI tools were not built with nonprofit data obligations in mind, so the obligation falls on you.

4. Human oversight. Name where a person must review AI-assisted work before it goes out, and who is accountable for it. Accountability for an error cannot rest with a chatbot, and boards should insist the policy says so plainly.

5. Disclosure. Decide when you will tell donors, funders, and beneficiaries that AI was involved. The fundraising case that opened this article was a disclosure failure, not a technology failure. A one-sentence disclosure standard would have prevented it.

6. Tool evaluation. Establish how a new AI tool gets approved before staff start using it, not after. Even a lightweight rule, a short form and a named approver, beats discovering a year later that donor data has been flowing through a free tool nobody vetted.

7. Training and literacy. A policy staff cannot apply is a liability document, not a governance document. Pair the policy with basic AI literacy so people understand why the rules exist. The evidence on capacity gaps between well-resourced and under-resourced organizations suggests literacy is where the sector divide will widen first.

8. Ownership and a review cycle. Name one owner and put the first review date on the calendar before adoption. AI capabilities change quarterly. A policy reviewed annually at best will spend most of its life out of date.

Five questions to ask before approving any AI use

Nonprofit researchers Billie Sandberg and Andrew Russo of Portland State University and Laura Hand of the University of North Dakota published a set of critical questions organizations should ask about data-driven tools, and they transfer directly to AI. Build a short version into your policy as a pre-approval checklist:

  • Who benefits from this use of AI, and who carries the risk if it goes wrong?
  • What data feeds this tool, why was that data collected, and would the people it describes be comfortable with this use?
  • Could we explain this decision, in plain language, to the people it affects?
  • Who is excluded or misrepresented by how this tool categorizes people?
  • When the tool is wrong, who will notice, and who will fix it?

If a proposed use cannot survive these five questions, the problem is not the paperwork. These questions also preview the deeper conversation every board should eventually have about AI, which deserves its own treatment.

How to run the process

Form a small working group: an executive sponsor, whoever owns your data, and two or three of the staff already using AI day to day. Give the board a touchpoint, a draft review and a final adoption vote, but do not ask the board to write it. Boards govern outcomes; staff govern workflows.

Plan on weeks, not quarters. A structured starting point helps, and the template that accompanies this article is built around the eight decisions above. Treat it as an agenda, not an answer. Every section your team adapts forces exactly the internal conversation the research says predicts healthy adoption. The adaptation is the point.

Done looks like this: adopted by leadership, acknowledged by every person it covers, one named owner, and the first review date already scheduled.

A policy that stays alive

The organizations that get value from an AI policy treat it as a governance instrument, not an artifact. Review it every six months. Route new tools and new use cases through it. Let it feed your board's broader AI conversation, and revise it when the technology or your programs change.

A policy is also just one dimension of AI readiness, alongside leadership, data, people, and current use. If you want to know where your organization stands across all of them, our free AI readiness assessment takes about ten minutes and returns a scored profile.

Download the CNAI Nonprofit AI Policy Template

It follows the eight decisions in this article, includes the five-question checklist, and marks every section your leadership team needs to customize. Free to adapt for internal use.

A nonprofit AI policy shown as a working checklist on a laptop
Michael Lugo · Founder, Center for Nonprofit AI

Michael Lugo is a nonprofit executive with more than 14 years of nonprofit leadership experience, including over a decade with one of the nation's largest nonprofit organizations, and service on numerous nonprofit boards. He is an MBA candidate at West Virginia University and a participant in MIT Professional Education's Leading AI Strategy program. More from Michael

Sources

Sandberg, B., Wasif, R., & Hand, L. C. (2025). Addressing the promise and peril of AI for nonprofit management through a data feminist pedagogy. Journal of Public Affairs Education. doi.org/10.1080/15236803.2025.2475589

Shi, W., & Azevedo, L. (2026). Determinants of AI adoption in nonprofit organizations. Nonprofit and Voluntary Sector Quarterly. doi.org/10.1177/08997640261429018

Goldkind, L., Ming, J., & Fink, A. (2025). AI in the nonprofit human services: Distinguishing between hype, harm, and hope. Human Service Organizations: Management, Leadership & Governance, 49(3), 225-236. doi.org/10.1080/23303131.2024.2427459

Sandberg, B., Hand, L. C., & Russo, A. (2023). Re-envisioning the role of "big data" in the nonprofit sector: A data feminist perspective. Voluntas, 34(5), 1094-1105. doi.org/10.1007/s11266-022-00529-9

Plaisance, G. (2025). Artificial intelligence (AI) in the context of nonprofits and philanthropy. Journal of Philanthropy, 2025(2). doi.org/10.1002/nvsm.70022

Di Troia, S., Parli, V., Pava, J. N., Badi Uz Zaman, H., & Fitzsimmons, K. (2024). Inspiring Action: Identifying the Social Sector AI Opportunity Gap. Stanford Institute for Human-Centered Artificial Intelligence & Project Evident. Working paper

TechSoup & Tapp Network (2025). 2025 AI Benchmark Report on Adoption, Impact, and Trends. page.techsoup.org

Images on this page are AI-generated, created by the Center for Nonprofit AI.

Get the next brief

Join nonprofit leaders reading The Nonprofit AI Brief.

A concise monthly briefing on AI strategy for the sector. Articles like this one, delivered when they publish.