A one-page AI use policy, put in writing, prevents most of the risk that comes from informal, unmanaged adoption.
- Name which tools are approved. Staff should know which AI tools are sanctioned for work use, rather than each person choosing independently.
- Define what data can and can't be entered. Client, donor, patient, and financial data generally should not be pasted into a public AI tool unless its data-handling terms have been reviewed.
- Require human review before anything goes external. AI-assisted drafts of client communications, proposals, or public content should always get a human read-through before they go out.
- Clarify ownership of AI-generated output. Understand your chosen tool's terms around who owns content it generates, particularly for anything public-facing.
- Name who owns the policy. Someone should be responsible for updating it as tools and risks change — this shouldn't be a one-time document.
None of this requires banning AI tools, which tends to just push their use further out of sight. A short, clear policy gets more value out of the tools while managing the actual risk.

