A “Safe Use” Policy for Small Businesses + Nonprofits
AI tools are already part of how your team works. Someone is using them to draft a grant narrative, clean up a policy, brainstorm a training outline, or summarize meeting notes. Most of the time, that is a good thing. AI can save real hours for small teams that never have enough of them.
The problem is not that people want to use AI. The problem is that many teams are using it without a shared standard for what is allowed, what is off limits, and who checks the work before it leaves the building.
Different Types of AI
Not all “AI tools” work the same way. A few common categories you will run into:
- Generative AI (text, images, audio): Creates new drafts (emails, policies, job descriptions, graphics). Most “chat” tools fall here.
- AI assistants inside other software: The same generative capability, but embedded in tools like email, docs, CRMs, or project management. This often changes what data the tool can “see,” so access controls matter.
- Automation + AI (workflows): Uses AI to route work (triage inboxes, tag requests, summarize meetings, draft responses) and then triggers actions. The risk is usually the automation part—mistakes can spread faster.
- Predictive / scoring models: Produces a score or recommendation (e.g., likelihood to donate, risk flags, screening or hiring support). These can raise fairness, compliance, and transparency concerns.
- Search and “chat with your files”: Answers questions from your internal documents. Great for speed, but requires careful permissioning and a clear rule for what is allowed to be ingested.
For a lightweight policy, you don’t need perfect technical definitions. You need a practical list: (1) the AI categories your team actually uses (drafting chat tools, AI inside Google/Microsoft/Notion, transcription, chat-with-files, and any automations), (2) the specific tools approved for each category, and (3) clear data rules, especially what can never be entered (client records, donor details tied to individuals, HR files, payroll/banking/tax info, passwords/tokens). When in doubt, staff should assume the prompt could be seen outside the organization and either anonymize the input or don’t use AI.
Case Study: AI Automation Error
A while back, I dealt with a situation where another organization had added AI to its finance workflow. A payment that was meant for my organization went to an organization with a similar name. It was not malicious. It was not even careless, exactly. It was a process that moved faster than the people checking it, and it took real time and cleanup to untangle.
That experience shaped how I think about AI at work. Any AI use without human oversight makes me extremely nervous. The tool is not the risk. The missing review step is the risk.
The Real Risk Is Not AI. It Is Unmanaged AI.
When AI use is unmanaged, the same problems show up again and again:
- confidential information pasted into tools without approval
- inconsistent tone and messaging across the organization
- invented facts and figures in grants, board packets, and public communications
- HR or policy language that does not match how your organization actually operates
The answer is not to ban AI. Bans rarely stop use and at the end of the day, they just push it out of sight. The answer is to use AI with guardrails that everyone understands.
Five Decisions to Make as an Organization
Before you write a policy, decide:
- What categories of data are never allowed? Think client records, payroll, and donor details.
- What tools are approved? Name them specifically.
- Who can approve exceptions?
- What work must be reviewed by a human before it is sent or published? Hint, the answer to this should be "all."
- Where do you store final outputs and prompts?
If you can answer these five questions, you can write your policy in an afternoon.
Where AI Mistakes Can Cause Real Harm
If an AI-produced document is inaccurate and no human reviews it, the damage is not theoretical. Client trust, funding, and legal exposure are all on the table.
I also want to name it again because it's so important. Financial decisions, legal decisions, and people decisions like hiring and firing should be overseen by certified professionals. If you are thinking about adding AI tools to those processes, bring your accountant, attorney, or HR professional into the conversations early. Ask them how, when, if, and why AI belongs in that workflow. Their answers belong inside your policy.
The One-Pager · Copy + Adapt
A One-Page AI Safe Use Policy
Everything below is the template — copy it, paste it, and make it yours.
AI “Safe Use” Policy (Template)
Copy/paste and adapt to your organization.
Purpose
We use AI tools to increase efficiency and improve quality while protecting confidential information and maintaining human accountability.
Approved tools
- [List approved AI tools here]
Data rules (non-negotiable)
Staff may NOT enter:
- personally identifiable information (PII)
- donor names or amounts tied to individuals
- client or participant records
- HR files, performance notes, or investigations
- banking, payroll, or tax data
Allowed use cases (examples)
- first drafts of internal SOPs (no confidential data)
- formatting checklists and templates
- brainstorming training outlines
- rewriting for clarity using anonymized examples
High-risk use cases (require approval and review)
- grant narratives referencing program outcomes
- donor communications that include financial information
- HR policy language
- legal or compliance interpretations
Human review requirement
Any external-facing content created with AI must be reviewed by a named staff member before it is published or sent.
Accuracy rule
AI outputs are not factual sources. Staff are responsible for verifying every claim and number.
Storage and versioning
Final documents must be stored in our standard system (Notion, Drive, etc.) with version history. Do not store sensitive prompts in ad hoc locations.
Training Your Team in 30 Minutes
You do not need a big rollout. One short meeting is enough:
- 10 minutes: why the policy exists (risk and trust)
- 10 minutes: allowed vs. not allowed, using real examples from your work
- 10 minutes: how to anonymize a prompt and how to request approval for a high-risk use
Then revisit the policy quarterly. AI tools change fast. Your policy should be a living document, not a PDF no one ever opens.
Safe vs. Risky (Quick Guide)
✓ Usually safe
- brainstorming topics
- drafting a checklist
- rewriting a generic policy in plain language
- generating a meeting agenda
✗ Usually risky
- anything with client, donor, or personnel details
- anything that claims compliance guidance
- anything where a wrong fact could cost funding
Your team can still move fast. They just need to move fast together, with the same rules. A one-page policy and a 30-minute training will not slow anyone down. They will keep speed from turning into a messy cleanup.
Additional Recommended Reading
Affiliate disclosure: These links below are affiliate links. If you make a purchase through them, I may earn a small commission at no extra cost to you.
Understanding and Using AI: A Resource for Nonprofit Leaders
A practical, nonprofit-focused guide to what AI can (and can’t) do in day-to-day operations. It’s especially useful if you’re trying to separate hype from reality and want straightforward examples of how leaders can evaluate tools, set expectations, and reduce risk while still benefiting from automation and better workflows.
This book is a helpful mindset-and-practice guide for people who need to manage AI work, not just use a chatbot. It’s a strong fit if you’re building repeatable processes (guardrails, review steps, quality checks, and “who owns what”) so AI improves output without creating inconsistency, compliance risk, or rework.
This post is informational and not legal, financial, or compliance advice. For decisions involving employment, finances, or legal obligations, consult a qualified professional.
.png)
No comments:
Post a Comment