← Back to Articles
Civics & Governance

The Road to Safe AI Governance

A roadmap for nonprofit leadership and boards on how to approach AI governance and usage policies.

The AI Governance Roadmap: How Nonprofit Leaders and Boards Can Safely Adopt Intelligent Tech

Chances are that your staff is already using generative artificial intelligence. Whether they are using it to draft a personalized donor thank-you letter, clean up an Excel sheet for a grant report, or summarize a grueling board meeting, "shadow AI" is quietly entering your organization's workflow.

As an executive leader, you do not need to ban these tools—but you do need to guide them. Leaving your team to navigate the ethical, legal, and security boundaries of AI on their own creates massive vulnerability. Crafting an AI acceptable use policy is no longer an item for next year's strategic plan; it is a critical, current-quarter priority that requires seamless collaboration between your executive leadership, your board of directors, and your front-line staff. This guide provides a collaborative roadmap to move your organization from conversational curiosity to formal policy adoption, along with the exact resources your team needs to get started.

Phase 1: Engaging the Board

Aligning on Fiduciary and Ethical Oversight

Your board of directors does not need to understand how large language models (LLMs) work, but they must be able to discuss and understand how using AI affects financial and reputation risk, data and systems security, and mission alignment.

Start with an Educational Briefing

Surprising your board with a complex, fully drafted policy at a regular quarterly meeting does not foster discussion or understanding. Instead, dedicate at least 15 minutes of an upcoming meeting to a high-level briefing. Focus on the reality of current staff usage and how a clear policy protects the organization's reputation.

Define the Board’s True Role

The board’s job is governance, not management. Frame the conversation around their fiduciary duties: · Fiduciary Duty: Ensuring that vendor selections and data-handling practices comply with existing state and federal privacy laws. · Duty of Care: Confirming that the organization has an active plan to train staff and protect intellectual property. · Mission Alignment: Ensuring that AI tools do not introduce algorithmic bias that actively harms the communities you serve. Form a Cross-Functional AI Committee Pass a resolution to create a temporary, agile task force or committee. Ideally, this group should include one or two board members (especially those with backgrounds in tech, law, or risk management), the Executive Director or CEO, and key staff representatives from IT and program delivery.

Phase 2: Engaging the Staff

Co-Creating a Practical Policy

Top-down tech mandates rarely work in the nonprofit sector. If a policy is too restrictive, staff will simply hide their usage. To build a policy that people actually follow, you must invite your team into the drafting process.

Conduct an Internal AI Audit

Before writing a single line of policy, find out what is actually happening on the ground. Send an anonymous, three-question survey to your staff and frequent volunteers:

  1. What AI tools (like ChatGPT, Claude, Grammarly, or Canva) do you use for work?
  2. What specific tasks do these tools help you complete?
  3. What guidelines do you think we need to keep our data safe?

Elevate "Super Users"

Identify the staff members who are already enthusiastic about AI. Appoint them as internal champions. They can help draft the practical "do’s and don’ts" for daily tasks, ensuring the final policy reflects real-world workflows rather than rigid theory.

Frame the Policy as Empowerment, Not Enforcement

When discussing the upcoming policy with staff, emphasize that the goal is to give them a safe sandbox to work in. A good policy does not say "Do not use AI." It says "Here is how to use AI safely so you don't accidentally compromise our data."

Phase 3: The Drafting and Adoption Process

Once it has gathered insights from the staff and oversight from the board, the AI committee can begin drafting the document. Keep the first iteration simple, memorable, and adaptive; further refinements can be addressed in future scheduled policy review cycles. The basic policy development life cycle is:

[Gather Staff Audit Data] ➔ [Draft 1-Page Core Rules] ➔ [Board Committee Review] ➔ [Full Board Vote & Rollout]

Focus on Four Core pillars

Your initial policy should easily fit on one or two pages and clearly address four key areas: 4. Approved Tools: A living list of software platforms that the organization has vetted and approved for work use. (This can be included as an appendix if needed.)
5. Data Privacy Rules: A strict prohibition against pasting personally identifiable information (PII), donor financial data, or sensitive beneficiary case notes into public AI models. 6. The Human-in-the-Loop Mandate: A strict rule that a human must review, fact-check, and edit every piece of AI-generated content before it is published, sent to a donor, or submitted to a funder. 7. Transparency: Guidelines on when and how to disclose AI usage to donors, foundations, and the public.

The Vote and Annual Review Cycle

Once the cross-functional committee finalizes the draft, present it to the full board for official adoption. Because technology evolves rapidly, embed an automatic review clause into the resolution: the policy must be revisited and updated every 12 months.

The AI Governance Toolbelt: Essential Resources

To save your committee from starting completely from scratch, utilize these vetted frameworks, templates, and guides to inform your policy discussions.

Policy Templates & Frameworks

· North Carolina Center for Nonprofits Sample AI Policies: A highly practical compilation of free, downloadable acceptable use templates from established sector leaders like FreeWill and Community IT Innovators. https://ncnonprofits.org/resources/sample-ai-policies · Nonprofit Learning Lab Library: Provides step-by-step roadmaps, templates, and educational webinars specifically designed to help leadership transition a written policy into a real-world workforce training program. https://www.nonprofitlearninglab.org/post/sample-ai-policies-and-resources-for-organizations-best-practices

Operational & Implementation Guides

· Candid Guide to Responsible AI Policy: A strategic roadmap focusing on how to write policies using accessible language that staff can easily understand, avoiding dense, alienating legal jargon. https://candid.org/blogs/how-to-create-responsible-ai-use-policy-for-nonprofits/ · Trustible AI Governance for Nonprofits Guide: A clear, multi-phase breakdown explaining how to build an internal software inventory and categorize tools by their level of organizational risk. https://trustible.ai/post/ai-governance-for-nonprofits/ · NTEN Artificial Intelligence Resource Hub: An equity-centered repository packed with foundational videos and material collections tailored for staff and board-level discussions. https://www.nten.org/learn/resource-hubs/artificial-intelligence

Security & Board Oversight Compliance

· Microsoft Tech Community AI Security Blueprint: An in-depth technical analysis explaining how to apply data classification and secure access controls to the entire AI lifecycle. https://techcommunity.microsoft.com/blog/nonprofittechies/comprehensive-security-in-the-era-of-ai-what-nonprofits-need-to-know-now/4493892 · BoardEffect Nonprofit Board AI Regulations Blog: Specifically covers the shifting legal landscape, detailing how boards can leverage digital committee workspaces to manage AI oversight. https://www.boardeffect.com/blog/regulations-ai-nonprofits/

Moving Forward Responsibly

Drafting an AI acceptable use policy is not about creating a thick binder of rules to shelf away. It is about sparking an open, ongoing conversation across every level of your organization. By aligning your board on risk, empowering your staff to share their workflows, and leveraging the open-source frameworks available to the sector, your nonprofit can confidently harness the power of AI without compromising its ethics, security, or mission.

If you would like help navigating AI governance adoption and exploring how your organization can leverage AI-driven tools safely and ethically, reach out to us at info@coreconduit.com to schedule a time to talk!

💬
Continue the conversation in the forum
Town Square · Community Tool Shed · The Tech Collective · Sustainable Communities · and more
Join the Forum →