Someone on staff is already pasting donor names into a chatbot to draft thank-you letters. Someone else used it to write a grant narrative last month. Nobody has decided whether either is allowed, because nobody has written anything down.
That is the state of most nonprofits in 2026. The 2026 Nonprofit AI Adoption Report, a survey of 346 organizations by Virtuous and Fundraising.AI, found that 92 percent of nonprofits use AI in some form and that 47 percent have no governance policy for it. Boards are beginning to ask, funders have started to take positions, and donors say they want to know. Here is what an AI policy for a small nonprofit needs to say, in language a board can approve in one meeting.
Why the policy comes before the tools
A policy is not a brake on using AI. It is the permission that lets a small team use it well, because it answers in advance the questions that otherwise stop every use at "is this okay?" It also protects three things the organization cannot afford to lose: donor and client data, the trust of funders and supporters, and the accuracy of everything the organization publishes. A March 2026 Blackbaud survey of more than a thousand donors found 76 percent saying it matters that organizations disclose when and how they use AI, and 68 percent calling the protection of their personal data inside AI use very important. The policy is how you earn the first and protect the second.
A policy does not slow the team down. It is the reason the team can say yes without asking.
What the policy needs to cover
- Purpose. One paragraph: the organization uses AI to serve the mission more effectively, under human judgment, with the same standards of honesty and care that apply to everything else it does.
- Approved uses. Drafting, summarizing, research, translation, data cleanup, first drafts of routine communications, brainstorming. Name them so staff know what is welcome.
- Uses that require review. Anything published, sent to donors or funders, submitted in a grant, or used in a program decision must be reviewed and approved by a named person before it goes out. Nothing AI-drafted reaches a donor unread.
- Prohibited uses. Entering client or donor personal information into any AI service not approved for it. Generating images or claims that misrepresent the organization's work. Making decisions about people, such as eligibility or hiring, on AI output alone.
- Data protection. Which services are approved for which kinds of information, who approves new ones, and the rule that sensitive personal data stays out of consumer chat services. Our article on how we handle your information describes the standard we hold ourselves to.
- Accuracy. Every fact, figure, and quotation in AI-assisted work is checked against a source before use. AI drafts; people verify.
- Disclosure. When and how the organization tells donors, funders, and the public that AI was used, in plain terms, without apology.
- Grant applications. Funders differ. Candid's Foundation Giving Forecast Survey found that 23 percent of foundations will not accept applications containing generative AI content, 10 percent will, and 67 percent had not decided. The policy requires checking each funder's stance before submitting, and it forbids submitting anything the organization has not reviewed and made its own.
- Ownership and review. One person owns the policy. The board approves it. It is reviewed every six months, because the technology and the rules move.
Where the human stays
The single most important sentence in the policy is the one that keeps a person accountable for every output. AI can draft the appeal, summarize the report, and propose the keyword list; a named staff member decides whether it is true, whether it sounds like the organization, and whether it goes out. This is the standard our own staff work to: our AI staff do the reading and drafting, a person on our team reviews the work before it reaches a client, and the client's people approve what runs. Our articles on what an AI employee actually is and why AI does not replace your people describe the model.
Talking to the board and the staff
Staff assume an AI policy is a layoff plan unless told otherwise, and the Center for Effective Philanthropy's 2026 research on burnout shows why: teams are already stretched, and a policy that arrives without a stated position on jobs reads as a threat. State the position. AI is being adopted to remove routine work from overloaded people, not to remove the people. Then involve staff in writing the approved-uses list, because they know where the routine work is. Bring the board a one-page policy, the data points above, and a six-month review date, and ask for a vote. Our article on the phrase every nonprofit is tired of is the context for that conversation.
Writing the policy, evaluating the services, training the team, and holding the review is work our Ops and Finance department does for organizations without an operations lead, alongside the bookkeeping and compliance calendar. See how our staff keep the organization governed.
A one-page template, in outline
- Purpose and principles: mission, honesty, human judgment.
- Approved uses, reviewed uses, prohibited uses.
- Approved services and the process for adding one.
- Data rules: what may and may not be entered where.
- Accuracy and disclosure standards.
- Grant application rule.
- Owner, board approval date, next review date.
Questions nonprofits ask about AI policies
Do we need a policy if only one person uses AI?
Yes, because that person is making the organization's decisions about data and accuracy alone. A policy makes those decisions the organization's.
Should we disclose AI use to donors?
Donors say they want to know, and a plain statement of responsible use has been associated with better retention. Disclose the practice, not every draft.
Can we use AI to write grant proposals?
To draft and organize, yes, if the funder allows it and a person makes the proposal their own. Some funders refuse AI-generated content; check before submitting.
Who should own the policy?
The executive director or an operations lead, with board approval and a named backup, so the policy survives a staff change like every other governing document.
Your mission is bigger than the tools you use
AI is already in your organization; the policy decides whether it serves the mission under your standards or drifts without them. You do not need to become a technology governance expert on top of everything else. You need a staff that is already drafting the policy, already reviewing the services, and already holding the six-month review while you lead the mission only you can lead. Find out what our staff can do for you.
Zoya Syal is Content and Production Manager at Nonprofits Engine, where she leads the content and testimonial work for a team that helps small nonprofits get set up and funded.
Grants
Fundraising
Marketing
Outreach
Ops and Finance