Resource Hub

AI Governance for Nonprofits

Nonprofit AI governance is the set of policies, review habits, and guardrails that let your organization use AI tools without putting donor data, funder trust, or your mission at risk. It is not a single document. It is a short written policy, a clear owner, a rule for what data may and may not go into a tool, and a light process for reviewing new uses as they come up. Most nonprofits can put a workable version in place in a week — the goal is a policy your board understands and your staff will actually follow, not a legal treatise nobody reads.

What should a nonprofit's AI policy actually cover?

A usable AI policy answers five questions in plain language: which tools are approved, what data is allowed in them, who signs off on new uses, when AI involvement must be disclosed, and who owns the policy. That is enough to start. You can add detail later, but a policy that tries to anticipate everything on day one usually never ships. Keep the first version to a page or two so the whole staff can read it in one sitting.

Element What it decides
Approved tools Which AI tools staff may use for work
Data rules What may never be entered (e.g. donor PII, financials, board matters)
Ownership The one person or role accountable for the policy
Disclosure When and how you tell funders, clients, or the public that AI was used
Review A simple path to approve a new use case

Is it safe to put donor data into AI tools?

It depends entirely on the tool and the data. Public consumer chatbots on their default settings may retain and train on what you enter, so donor names, contact details, giving history, and anything a donor shared in confidence should not go in. Enterprise or business-tier tools with a signed data agreement that turns off training and specifies where data is stored are a different matter — those can be appropriate for sensitive work. The safe default is to strip or anonymize identifying details before using any tool, and to check for a data-processing agreement before trusting a vendor with anything private.

How do we get our board comfortable with AI?

Boards get comfortable when they see governance before they see the tools. Bring them a short briefing that frames AI as something you are managing responsibly: the policy, the data rules, the owner, and one or two concrete uses with clear value. Avoid hype and avoid asking them to evaluate the technology itself — their job is oversight, not tool selection. A board that sees a clear policy and a named owner will approve far faster than one shown an impressive demo with no guardrails.

Six-Dimension Readiness Model

The Six-Dimension Readiness Model scores how prepared a nonprofit is to adopt AI responsibly, so you can start where you are strong and shore up where you are not. Rather than asking "should we use AI," it asks "are we ready to use it well," across six areas:

  • Data and privacy — do you know what data you hold and what is safe to use?
  • Policy and governance — is there a written policy and a clear owner?
  • Skills and training — can staff use these tools competently and safely?
  • Use cases and value — have you identified where AI actually saves time or improves work?
  • Risk and oversight — can you catch errors, bias, and misuse before they cause harm?
  • Culture and change — is the organization willing and able to adopt new ways of working?

A readiness score across these six dimensions turns a vague "we should look into AI" into a specific, prioritized plan.

Want help putting this in place? Charity Search Group works with nonprofit boards and leadership teams on readiness assessments, board-ready policy, and staff training. If you would rather not build it from scratch, see how we help.

Resources in this series

Frequently asked questions

Do we need an AI policy if staff only use ChatGPT occasionally?

Yes — occasional use is exactly when accidents happen, because there are no shared rules. A one-page policy that says which tools are approved and what data may never be entered is enough to prevent the most common mistakes.

Who should own AI governance at a nonprofit?

One accountable person or role, usually an operations, finance, or executive leader — not a committee. The owner does not have to be technical; they have to be responsible for keeping the policy current and answering "can we use AI for this?"

What is the difference between an AI policy and an acceptable-use policy?

An AI policy is the broader governance document covering approved tools, data rules, disclosure, and review. A staff acceptable-use one-pager is the short, practical extract that staff actually keep at their desk. Most organizations want both: the policy for the board, the one-pager for the team.

How often should we update our AI policy?

Review it at least once a year, and any time you adopt a materially new tool or use case. AI tools change quickly, so a policy written even a year ago may reference options or risks that no longer apply.

Can we use AI for grant writing without disclosing it?

Sometimes, but norms are shifting and some funders now ask. The safe practice is transparency: use AI to draft and organize, keep every factual claim verifiable and in your own voice, and disclose AI assistance when a funder requests it or when the work is presented as fully human-authored. When in doubt, disclose.

Last updated: 2026-07-05

Join Our Network of Nonprofits Empowered by Exceptional Leadership

At Charity Search Group, we believe that people are the key to impact. Let us help you find the leaders and teams that will propel your organization forward.

Request a Proposal Today!
Select Guide Badge