WiderGood

What Should Be in an AI Acceptable-Use Policy for a 20-Person Nonprofit?

A short one: who can use which tool, on which data, and who signs off before it touches a donor or client. Everything else in the policy supports those three lines.

Who can use which tool: list what's actually approved, not "AI" as a category. A request to try something new is one line, not a board meeting.

On which data: classify what the team handles as public, internal, or donor- and client-restricted, and say plainly what never goes into a consumer AI tool. Grant records and client files belong in the restricted tier.

Who signs off: anything donor- or client-facing gets a named human reviewer before it goes out — a specific person in the policy, not "someone checks it."

The rest is upkeep: a published do-not-build list, vendor terms that rule out training on the data, and a note on how the policy gets revisited when a new tool shows up. Approved in one meeting, not four — if it takes longer than that, nobody will read it.

Bring a few areas that eat your team's time. Thirty minutes. If AI can't fix them, I'll say so.