AI Impact HubFor whoever owns "we should probably have a policy": ops, the ED, or the accidental AI person.
Create an account & download →Create a free account to download this and every other template on the Hub.
An Australian nonprofit with no AI policy had staff upload confidential client information to ChatGPT, and the organisation's response was a blanket two-year ban on all AI tools. That is what this template insures against. Roughly 70 to 80 per cent of an AI policy is the same across organisations; borrow this skeleton, spend your time on the decisions, and write it with the whole leadership team in one room.
Six sections make this policy work. Whether you have one or not, tap through honestly: does your current position cover each of these?
It covers staff, volunteers and contractors, and says out loud that you actively explore AI inside the rules: permission and boundary, not just restriction.
A reviewed and paid-for list, an unreviewed default for everything else, and "if unsure, tier up" with a named person to ask.
Green (public) can go anywhere. Yellow (internal) goes in approved tools only. Red (client records, health information, donor personal and payment details, credentials) never enters any AI tool.
AI tools now reach email, shared drives and CRMs in one click. Every new connection is approved by a named role first, and reviews check for permission creep.
You say when AI has materially helped produce something carrying your name, and a person remains accountable for it either way.
Every two months, fifteen minutes, three questions, because capabilities change monthly, and policies written a year ago said nothing about connectors.
Nothing scored yet. Start at the top.
A policy is not bureaucracy. It is insurance against the overreaction that follows a preventable mistake.
Score yourself, copy the prompts, download the file. It all runs right here, and every other template on the Hub comes with it.