Staff are already using AI. That’s the starting point most nonprofit leaders miss when they think about whether their organisation needs an AI policy. It’s not a question of whether AI use is coming — it’s a question of whether it’s happening with any guidance, consistency, or safeguards in place. The communications coordinator is using ChatGPT to draft donor emails. The program officer is using Claude to summarise evaluation reports. The volunteer running your Instagram is using Canva’s AI features to generate captions. None of them have been told what’s acceptable, what’s off-limits, or what to do when something goes wrong. That’s not their failure. It’s an organisational gap that a simple AI policy closes.
Research consistently shows that the vast majority of nonprofits — figures around 76% — have no formal AI policy at all. Most are in a position where AI use is happening informally, inconsistently, and without any shared understanding of the risks. For communications and marketing teams specifically, this matters most acutely. The content your team produces goes out under your organisation’s name and to your donors, funders, and community. If that content is being shaped by AI tools without any governance around how those tools are used, what data goes into them, or how the output is reviewed, your organisation carries the risk without having made a conscious decision about it.
An AI policy doesn’t need to be a lengthy legal document. For most small and mid-sized nonprofits, a single page of clear, practical guidance covers the ground that needs to be covered. The goal is not to restrict your team’s use of tools that make them more effective — it’s to give them a clear framework for using those tools responsibly, so they can act with confidence rather than uncertainty. This article walks through how to build that framework, specifically for communications and marketing functions, without requiring a legal background or a technology committee.
Why Your Communications Team Needs This More Than Anyone
AI policy conversations in nonprofits often start with data — who has access to your donor database, whether beneficiary records are protected, how financial information is handled. These are legitimate concerns. But the most immediate and practical need for AI governance in most nonprofits sits in communications and marketing, because that’s where AI use is already most active and where the consequences of getting it wrong are most visible.
Your communications team is producing content that represents your organisation publicly. Every donor email, social media caption, grant narrative, and impact report that goes out carries your name, your credibility, and your community’s trust. If a staff member pastes your entire donor database into a free AI tool to personalise an email campaign — something a well-intentioned person might do without realising the risk — that data may be used to train the AI model. If AI-generated content goes out without an editing pass and contains an invented statistic or a fabricated quote, it undermines the accuracy your funders and supporters expect. If your team is using five different AI tools with no consistency, your organisation’s voice fragments across everything you publish.
These are not hypothetical risks. They are the predictable consequences of AI adoption without guidance, and they are already playing out in organisations that haven’t addressed them. A communications-focused AI policy prevents them by establishing clear expectations before something goes wrong rather than scrambling to respond after it does. For a small team, it also creates confidence — staff who know what’s permitted and what isn’t can move faster and make better decisions than those operating in an unclear environment where every AI-assisted task feels like a judgment call they’re making alone.
What a Nonprofit AI Policy for Communications Actually Covers
Before writing a single word of your policy, it helps to understand what it needs to address. A communications-focused AI policy for a small or mid-sized nonprofit covers five areas: approved tools, prohibited data inputs, required human review, voice and accuracy standards, and a process for updating the policy as tools evolve. Each of these is simpler to document than it sounds.
Approved tools is a list of the AI tools your organisation permits staff to use for communications work, along with the tier or version permitted. This matters because a paid tier of a tool with explicit data privacy commitments is a different risk profile from a free tier that may use input data for model training. Specifying which tools are approved — and at which tier — removes ambiguity and prevents staff from defaulting to whichever tool they happen to have a personal account with.
Prohibited data inputs defines what types of information should never be entered into an AI tool, regardless of which tool it is or what tier it’s on. For most nonprofits, this includes personally identifiable information about donors, personally identifiable information about beneficiaries, financial data, and confidential partner or funder communications. This is the section that prevents the most significant risks, and it’s the section that needs to be communicated most clearly to all staff who use AI tools, not just the communications team.
Required human review establishes that all AI-generated content must go through a human editing and approval process before it is published or sent. This applies regardless of how good the first draft looks. The review requirement exists not because AI output is always wrong, but because AI output is sometimes wrong in ways that are hard to detect — invented statistics, subtle tone problems, inaccurate program descriptions — and the cost of those errors in donor communications or public content is higher than the time saved by skipping the review.
Voice and accuracy standards set out what your organisation expects from communications content — what the voice sounds like, what claims require evidence, what language is and isn’t appropriate when describing your communities and your work. These standards apply to all content regardless of how it was produced, but documenting them alongside the AI policy reinforces that AI is a drafting tool operating within your editorial standards, not a replacement for them.
The update process acknowledges that AI tools are changing faster than any policy can keep pace with in real time, and establishes a schedule — quarterly or semi-annual — for reviewing the policy against the current tool landscape. A policy written in the first half of this year may need adjustment by the end of it. Building the review cadence in from the start prevents the policy from becoming outdated and irrelevant within months of being written.
Building Your Policy Step by Step
Step 1: Audit What’s Already Happening
Before you write anything, spend an hour finding out what your team is already doing. Ask staff directly — individually, not in a group setting where people may feel less comfortable being honest — which AI tools they’re currently using, what they’re using them for, and whether they have any concerns about how they’re using them. You may be surprised by the range of tools already in use and the variety of tasks they’re being applied to.
This audit serves two purposes. First, it gives you an accurate picture of your starting point rather than one based on assumptions. Second, it signals to your team that the policy is being built with their reality in mind, not handed down from above without awareness of how they actually work. Staff who feel their input shaped the policy are significantly more likely to follow it than those who receive it as a directive with no context. Keep the audit informal and the questions open — you’re gathering information, not conducting a compliance check.
Step 2: Define Your Approved Tool List
Based on your audit and your organisation’s existing technology infrastructure, identify the AI tools you’re going to formally approve for communications use. For most nonprofits, this will be a short list of two to four tools. A reasonable starting point for a communications team with no existing AI infrastructure might look like this:
- ChatGPT free tier — approved for content drafting, brainstorming, and summarisation of non-sensitive public documents; not approved for input of any personal or confidential data
- Claude free tier — approved for the same uses as ChatGPT; staff are encouraged to test both and use whichever produces better results for their specific task
- Canva free tier or Canva for Nonprofits — approved for visual content creation and AI-assisted design; no personal data to be uploaded to the tool
- Google Gemini via Google Workspace for Nonprofits — approved for use within Gmail and Google Docs for drafting and summarisation; subject to the same data input restrictions as other tools
The list doesn’t need to be exhaustive or permanent. It needs to be clear. Staff should be able to read it and know immediately whether the tool they’re considering using is approved or whether they need to check with a manager first.
Step 3: Write the Data Input Rules Clearly
This is the most important section of the policy and the one that needs the clearest language. Vague guidance like “be careful with sensitive data” doesn’t tell staff what they actually need to know. Specific guidance does. The following categories of information should appear on your prohibited inputs list:
- Donor personal information including names, email addresses, giving history, contact details, or any combination of information that could identify an individual donor
- Beneficiary information including names, case details, location information, health data, or any other information relating to people your organisation serves
- Staff personal information including salaries, performance records, contract details, or personnel files
- Financial information including bank account details, transaction records, budget documents marked confidential, or funder financial data
- Confidential partner or funder communications including emails, grant agreements, or strategic documents shared in confidence
Staff should be able to read this list and apply it without needing to make judgment calls about borderline cases. If there’s any doubt about whether a piece of information falls into one of these categories, the rule is to err on the side of not inputting it. The policy should say this explicitly.
Step 4: Set the Human Review Requirement
The human review requirement should be stated simply and without exceptions. All AI-generated content must be reviewed and approved by a named staff member before it is published, sent, or shared externally. For most small communications teams, this means the communications lead or the most senior person working on that piece of content. For organisations where communications is managed by volunteers or program staff in addition to their other work, the review requirement still applies — it just means the person who prompted the AI also reviews the output before it goes anywhere.
The review should check three things: accuracy of all factual claims including statistics, program outcomes, and dates; alignment with the organisation’s voice and editorial standards; and appropriateness of the content for the specific audience and platform. It does not need to be an exhaustive editorial process — a fifteen-minute review of a social media caption or a thirty-minute review of a donor email is sufficient. The point is that a human who is accountable for the content has read it carefully before it leaves the organisation, not that AI is treated with suspicion at every turn.
Step 5: Document Your Voice and Accuracy Standards
Your communications voice exists whether or not you’ve ever written it down. The AI policy is a useful prompt to do so, because the standards that define good communications content for your organisation are the same standards AI output needs to be held against. A simple voice guide doesn’t need to be long. It needs to answer a few specific questions: What tone does your organisation use — formal, conversational, somewhere in between? What words or phrases does your organisation avoid — jargon, pity language, certain sector buzzwords? How does your organisation describe the communities it works with — with what level of specificity, and with what care around dignity and agency?
Accuracy standards are equally straightforward to document. Any statistical claim included in external communications should be sourced from your organisation’s own data, a funder report, or a publicly available research document your team has verified. Beneficiary stories should be drawn from real cases with appropriate permissions, not generated or embellished by AI. Program outcomes should reflect what has actually been achieved, not what was hoped for or projected. These aren’t new standards — they’re the ones your team already applies, or should be applying, to all communications. Writing them down alongside the AI policy makes them explicit and gives staff a clear benchmark for the editing review.
Step 6: Set an Update Schedule and an Owner
A policy without an owner is a document that gathers dust. Assign one person — the communications lead, the executive director in a small team, whoever is responsible for communications governance — as the policy owner. Their job is to review the policy on the schedule you’ve set, flag when tools change significantly enough to warrant an update, and be the first point of contact when staff have questions about whether a specific use case is covered.
Quarterly reviews are reasonable for organisations actively expanding their AI use. Semi-annual reviews are appropriate for organisations using AI in a stable, limited way. At each review, the policy owner should check whether the approved tool list still reflects what the team is actually using, whether the data input rules have been tested and found clear, and whether anything in the broader AI landscape — new tools, changed terms of service from existing tools, new guidance from funders or sector bodies — requires an update to the document.
Common Questions From Nonprofit Communications Teams
What If a Funder Asks Whether We Use AI?
This is an increasingly common question as funders develop their own policies around AI use in grant applications and program delivery. The honest answer is always the right answer. If your organisation uses AI tools for communications and that use is governed by a clear policy with human oversight and accuracy standards, that is a defensible and professional position. Some funders now explicitly prohibit AI-generated grant applications — in which case your policy should specify that grant applications to those funders are produced without AI assistance. Others are comfortable with AI as a drafting tool as long as human judgment shapes the final product. Knowing your funders’ positions and documenting how your policy addresses them is the appropriate response.
Does This Apply to Volunteers?
Yes, with adjustment. Volunteers who contribute to your communications — managing social media, writing newsletters, producing content — should receive a simplified version of the core rules: which tools are approved, what data must never be entered, and that all content needs a review pass before it goes out. A one-page summary of the key points, shared as part of volunteer onboarding, is sufficient. The full policy document is for staff who use AI tools regularly as part of their role. The simplified version is for anyone who might use them occasionally.
What if Staff Use Personal AI Accounts?
This is a real gap in most nonprofit AI governance. Staff may have personal ChatGPT or Claude accounts that they use for work tasks because it’s more convenient than setting up an organisational account. Your policy should address this directly: the same data input rules apply regardless of whether the account is personal or organisational. Staff using personal AI accounts for work communications are still bound by the organisation’s prohibited data inputs. The account ownership is irrelevant to the data protection obligation.
Final Remarks
An AI policy for your nonprofit’s communications team is not a bureaucratic formality. It’s a practical tool that protects your organisation, gives your staff clarity, and ensures that the AI tools increasingly embedded in your communications workflow are working within a framework your organisation has consciously chosen rather than one that evolved by default. The organisations that handle AI adoption well are not the ones that restrict it most tightly — they’re the ones that set clear expectations early, communicate them simply, and revisit them regularly as the landscape shifts.
Writing this policy doesn’t require a technology committee or a legal review. It requires one afternoon, honest conversations with your team about what they’re already doing, and a willingness to put clear rules in writing rather than leaving things to individual interpretation. Most of the content is guidance your organisation already holds implicitly — about voice, about accuracy, about what information is confidential. The policy makes it explicit and applies it specifically to AI. That’s the whole job. For a full overview of how nonprofits can use AI tools, visit our AI for Nonprofits resource page.
If you’re working through how to build your communications function with AI as part of the toolkit rather than an afterthought, the resources on this platform cover the practical side — from social media strategy to donor email systems — for teams that don’t have a dedicated digital specialist and need guidance that meets them where they actually are.