
AI Policy for Nonprofits: A Privacy-Safe Checklist for Small Charities
Why it matters: A practical AI policy for nonprofits does not need to be long. This checklist helps small charities and community organisations set safe boundaries for everyday AI use without l...
You'll explore:
- Before You Use AI: The Minimum Safe Rules
- Checklist 1: Decide What AI Is Allowed to Help With
- Checklist 2: Define What Not to Put in ChatGPT or Any AI Tool
- Checklist 3: Assign Responsibility Before Volunteers Try AI Tools
- Checklists 4 and 5: Set Human Review Rules and External Communication Rules
- Checklist 6: Create Rules for Meeting Notes, Summaries, and Records
- Checklist 7: Explain How to Handle Mistakes
- Checklist 8: Keep the Policy Short, Visible, and Easy to Follow
- Low-risk, higher-risk, and not-allowed AI tasks
- Do-not-paste list and safer alternatives
- Simple AI responsibility matrix
- Minimum safe rules before using AI
- Checklist 1: Decide what AI is allowed to help with
- Checklist 2: Define what not to put in ChatGPT or any AI tool
- Privacy warning
- This is a starting point, not legal advice
- Use placeholders instead of real details
- Frequently asked questions
Before You Use AI: The Minimum Safe Rules
Quick answer: a small charity or community organisation should only use AI for low-risk drafting, brainstorming, formatting, and routine admin where no personal, sensitive, confidential, safeguarding, donor, volunteer, or service-user information is entered into the tool. Every AI-assisted output should be reviewed by a responsible person before it is shared, published, stored as a record, or used to guide a decision. A short AI policy for nonprofits is useful because it gives trustees, coordinators, staff, and volunteers the same simple rules before people start experimenting in different ways.
- Use AI only for low-risk work unless a named person has approved the task.
- Never paste personal, sensitive, confidential, safeguarding, donor, volunteer, service-user, HR, payment, or password information into public AI tools.
- Do not send credentials, private records, analytics exports, screenshots containing private information, or identifiable sensitive records.
- Require human review for facts, tone, confidentiality, accessibility, consent, safeguarding implications, and suitability.
- If unsure, stop and ask the named policy owner before using AI.
Checklist 1: Decide What AI Is Allowed to Help With
Start with the task, not the tool. AI may be a reasonable helper for generic outlines, first drafts, formatting, plain-language rewrites, and brainstorming where the prompt contains only public or fictional information. Avoid using AI where the task could affect a person’s access to support, funding, services, opportunities, benefits, safety, or reputation. If the organisation would feel uncomfortable explaining the AI use to a service user, volunteer, donor, trustee, or community member, treat the task as too risky until reviewed.
- Is the task low-risk and administrative?
- Is the information already public, fictional, or safe to share?
- Could the output harm someone if it is wrong?
- Could the task affect access to support, funding, services, opportunities, or safeguarding decisions?
- Would the organisation be comfortable explaining the AI use to a service user, volunteer, donor, or trustee?
- If unsure, do not use AI until a named person has approved it.

Checklist 2: Define What Not to Put in ChatGPT or Any AI Tool
Your clearest rule should be the do-not-paste rule. Volunteers should not need technical knowledge to follow it. If information identifies a person, reveals a private situation, relates to safeguarding or support needs, or belongs in a secure internal record, do not paste it into ChatGPT or any other AI tool. Use anonymous placeholders, fictional details, or a general description instead, and keep the original information inside the organisation’s normal approved systems.
- Do not paste names, addresses, phone numbers, email addresses, dates of birth, reference numbers, or account details.
- Do not paste service-user stories, case notes, complaints, safeguarding concerns, health information, immigration information, disability information, financial circumstances, or personal support needs.
- Do not paste donor details, volunteer records, HR information, payment details, passwords, private board papers, internal disputes, or grant plans that are not meant to be shared.
- Do not paste meeting notes, chat logs, transcripts, screenshots, or analytics exports if they contain private or identifiable information.
- Do not ask AI to decide people’s eligibility, needs, risks, benefits, suitability, or priority for support.
- Use anonymous examples, fictional details, or general descriptions instead.
Checklist 3: Assign Responsibility Before Volunteers Try AI Tools
A small organisation does not need a complex structure, but it does need ownership. Name one person, such as a trustee, manager, coordinator, or administrator, to keep the AI policy visible, answer questions, approve tools, and handle mistakes. Make clear that volunteers should not test random AI tools for organisation work without permission. If the task touches safeguarding, confidentiality, employment, financial records, or legal duties, route it through the organisation’s normal responsible person instead of relying on AI.
- Name an AI policy owner and a backup person.
- List which AI tools, if any, may be used for organisation work.
- Say who is allowed to use approved tools and for what types of tasks.
- Require prompts to use generic, public, fictional, or anonymised information only.
- Name who reviews AI-assisted outputs before publication or sharing.
- Agree where mistakes should be reported and how quickly people should raise them.
Checklists 4 and 5: Set Human Review Rules and External Communication Rules
AI-assisted wording should be treated as a draft, not as an approved organisational message. Human review protects accuracy, tone, confidentiality, accessibility, consent, and trust. This matters especially when content is going outside the organisation, such as newsletters, social posts, grant drafts, website pages, donor updates, volunteer messages, or service-user communications. The reviewer should check that the content reflects the organisation’s values, does not reveal private information, does not overpromise, and is appropriate for the audience.
- Checklist 4: Human review rules — check facts, dates, names, links, venue details, eligibility wording, and contact information before sharing.
- Checklist 4: Human review rules — check tone, accessibility, plain language, inclusion, safeguarding implications, and whether the wording could be misunderstood.
- Checklist 4: Human review rules — remove private details and confirm that any story, quotation, image description, or example has the right consent before use.
- Checklist 5: External communication rules — do not publish AI-assisted content without a named human reviewer.
- Checklist 5: External communication rules — do not use AI to send automatic replies about sensitive support needs, complaints, safeguarding, eligibility, or urgent help.
- Checklist 5: External communication rules — keep a final human-approved version in the normal place where communications are stored.
Checklist 6: Create Rules for Meeting Notes, Summaries, and Records
Meeting notes are a common temptation because AI can appear useful for summaries and action lists. Treat them carefully. Minutes, transcripts, chat logs, recordings, and screenshots may contain identifiable people, private concerns, safeguarding details, volunteer issues, complaints, donor information, or internal disagreements. Do not paste full notes into a public AI tool. If notes are genuinely non-sensitive, remove names and private details first, ask for a summary of generic actions only, and review the result manually before it becomes a record.
- Do not paste full minutes, transcripts, recordings, chat logs, or screenshots into public AI tools if they include private, identifiable, confidential, or sensitive information.
- Do not use AI to summarise safeguarding discussions, service-user casework, complaints, HR matters, donor records, or private board disputes.
- For non-sensitive meetings, remove names, contact details, locations, and identifying context before using AI.
- Ask AI only for a generic structure, action list, or plain-language rewrite, not for judgement about people or risks.
- A human note-taker or reviewer should confirm the final record is accurate, fair, accessible, and stored in the correct internal place.
- If an AI meeting assistant, transcription tool, or recording feature is being considered, get approval first and make sure participants understand what is being used.
Checklist 7: Explain How to Handle Mistakes
People are more likely to report problems if the policy explains what to do without blame. Mistakes may include pasting private information into an AI tool, publishing unreviewed content, relying on inaccurate AI wording, sending an inappropriate message, or using AI for a task that should have been handled by a person. The first rule is to stop further sharing. The second rule is to tell the named policy owner quickly. If safeguarding, confidentiality, legal, employment, or data protection concerns may be involved, use the organisation’s normal escalation route and seek appropriate advice.
- Stop using or sharing the AI output as soon as a problem is noticed.
- Tell the named policy owner, coordinator, manager, trustee, or safeguarding/confidentiality lead if relevant.
- Record what happened in a simple internal note without adding unnecessary private details.
- Remove or correct unreviewed, inaccurate, or inappropriate content where possible.
- Do not paste the incident details into another AI tool to ask what to do.
- Review whether the policy, training, tool approval, or human review step needs to change.
Checklist 8: Keep the Policy Short, Visible, and Easy to Follow
A one-page policy is better than a long document that volunteers never see. Put it where people already look for admin guidance, such as an induction pack, shared drive, volunteer handbook, or trustee folder. Review it after a tool change, a mistake, a new activity, or an agreed review date. Self-serve next step: copy the template below into your own document and adapt it using only non-sensitive examples. Capacity note: Chestnut Communities is not currently offering paid AI policy reviews, implementation, urgent support, or automatic AI replies; this checklist is intended as a self-serve starting point, not a managed service.
- One-page AI policy template: 1. Purpose — We use AI only to support low-risk drafting, brainstorming, formatting, and routine admin.
- 2. Approved tools — Only tools named by the organisation may be used for organisation work.
- 3. Do-not-paste rule — We do not enter personal, sensitive, confidential, safeguarding, donor, volunteer, service-user, HR, payment, password, private record, private screenshot, or analytics export information into AI tools.
- 4. Allowed uses — Generic outlines, public event wording, plain-language rewrites, non-sensitive action lists, and ideas for internal planning may be allowed with human review.
- 5. Not allowed — AI must not make decisions about people, assess risk, replace safeguarding processes, provide personalised advice, or handle private records.
- 6. Human review — A named person checks accuracy, tone, confidentiality, accessibility, consent, and suitability before anything is shared or stored.
- 7. Mistakes — Stop, report quickly, record what happened, and use the normal escalation route if sensitive information or safeguarding may be involved.
- 8. Review — The policy owner reviews this policy after incidents, tool changes, or the agreed review date.
Low-risk, higher-risk, and not-allowed AI tasks
| Task type | AI use allowed? | Why | Safer approach |
|---|---|---|---|
| Brainstorming a newsletter outline | Usually yes | Lower risk if no private details are included | Use generic prompts and human editing |
| Rewriting a public event description | Usually yes | Based on information already intended for public use | Check accuracy, tone, dates, venue details, accessibility information, and contact details |
| Turning public information into a plain-language checklist | Usually yes | The source is already public and the task is editorial | Keep links to the original source and have a human reviewer check meaning |
| Creating meeting action lists from non-sensitive notes | Sometimes | Depends on what the notes contain | Remove names and private details first; review manually before storing |
| Summarising service-user case notes | No | May expose personal or sensitive information | Summarise internally without public AI tools or seek appropriate advice |
| Drafting advice to a beneficiary | High risk / avoid | Could be inaccurate, unsuitable, or outside the organisation’s role | Use approved guidance and qualified human review |
Do-not-paste list and safer alternatives
| Do not paste | Examples | Safer alternative |
|---|---|---|
| Personal information | Names, addresses, phone numbers, email addresses, dates of birth, reference numbers | Replace with anonymous placeholders such as Volunteer A or Service user B |
| Sensitive information | Health, finances, immigration, safeguarding, disability, faith, ethnicity, personal circumstances, support needs | Do not use a public AI tool; handle through the normal internal process |
| Confidential organisation information | Private donor details, grant plans, passwords, internal disputes, private board papers | Keep in approved internal systems |
| Credentials and access information | Passwords, login links, recovery codes, API keys, shared mailbox details | Never enter them into AI tools; use approved password and access processes |
| Private records or exports | Case files, volunteer records, HR files, payment records, analytics exports, screenshots containing private information | Keep inside the correct internal system and minimise sharing |
| Meeting notes with identifiable details | Volunteer names linked to concerns, service-user stories, complaints, safeguarding discussions | Create a manual summary or anonymise heavily before any AI use |

Simple AI responsibility matrix
| Decision or activity | Who should own it | Minimum rule |
|---|---|---|
| Choosing which AI tools may be used | Trustee, manager, or named coordinator | Only approved tools may be used for organisation work |
| Creating prompts | Approved user or volunteer | Use generic, public, fictional, or anonymised information only |
| Reviewing AI-assisted content | Named human reviewer | Check facts, tone, confidentiality, accessibility, consent, and suitability before sharing |
| Publishing external communications | Coordinator, communications lead, manager, or trustee | No AI-assisted external message should be published without human approval |
| Handling mistakes | Policy owner or safeguarding/confidentiality lead if relevant | Report quickly, stop further sharing, and record what happened |
| Reviewing the policy | Named policy owner | Revisit after tool changes, incidents, new activities, or the agreed review date |
Minimum safe rules before using AI
- Name one person responsible for the AI policy.
- Decide which AI tools, if any, are approved for organisation work.
- Allow AI only for low-risk drafting, brainstorming, formatting, and summarising of non-sensitive material.
- Ban pasting personal, sensitive, confidential, safeguarding-related, donor, volunteer, service-user, HR, payment, password, private record, screenshot, or analytics export information into public AI tools.
- Require human review before anything AI-assisted is shared, published, stored as a record, or used for a decision.
- Tell volunteers what to do if they make a mistake.
- Keep the policy short, visible, and easy to find.
Checklist 1: Decide what AI is allowed to help with
- Is the task low-risk and administrative?
- Is the information already public or safe to share?
- Could the output harm someone if it is wrong?
- Could the task affect access to support, funding, services, or opportunities?
- Would the organisation be comfortable explaining the AI use to a service user, volunteer, donor, or trustee?
- If unsure, do not use AI until a named person has approved it.
Checklist 2: Define what not to put in ChatGPT or any AI tool
- Do not paste names, addresses, phone numbers, email addresses, or dates of birth.
- Do not paste service-user stories, case notes, complaints, safeguarding concerns, or health information.
- Do not paste donor details, volunteer records, HR information, payment details, passwords, or private board papers.
- Do not paste meeting notes if they identify people or sensitive situations.
- Do not ask AI to make decisions about people’s eligibility, needs, risks, benefits, or suitability.
- Use anonymous examples, fictional details, or general descriptions instead.
Privacy warning
This is a starting point, not legal advice
Use placeholders instead of real details
Frequently asked questions
Do small charities and community groups really need an AI policy?
Yes, a short policy is sensible before routine AI use. It does not need to be complicated. The main purpose is to set plain rules on approved tools, low-risk uses, information that must never be pasted into AI tools, human review, and what to do if something goes wrong. This checklist is a governance starting point, not a guarantee of legal compliance.
Can volunteers use free AI tools for charity admin?
Only if the organisation has approved the tool and the task. Volunteers should use AI only for low-risk work, such as generic drafting, brainstorming, formatting, or rewriting public information. They should not paste private records, credentials, screenshots containing private information, analytics exports, service-user details, donor records, safeguarding information, or other identifiable sensitive records into free AI tools.
What information should never be pasted into an AI tool?
Do not paste personal information, sensitive information, safeguarding details, service-user stories, case notes, complaints, donor details, volunteer records, HR information, payment details, passwords, private board papers, confidential plans, private screenshots, analytics exports, or identifiable meeting notes. Use anonymous placeholders or fictional examples instead.
Can AI help write newsletters, grant drafts, or social media posts?
AI can help with outlines, first drafts, plain-language rewrites, and ideas if the prompt uses public, generic, or fictional information. A human reviewer should check facts, dates, eligibility wording, tone, accessibility, consent, confidentiality, and suitability before anything is sent or published. Do not include private service-user, donor, volunteer, or internal information in the prompt.
Can AI summarise meeting notes?
Be cautious. Do not paste full minutes, transcripts, recordings, chat logs, or screenshots into a public AI tool if they contain identifiable people, private details, complaints, safeguarding matters, donor records, HR issues, or confidential discussions. For genuinely non-sensitive notes, remove names and identifying details first, ask only for a generic action list or structure, and have a person review the final record.
Who should be responsible for AI use if we do not have IT or legal staff?
Name one practical policy owner, such as a trustee, manager, coordinator, administrator, or experienced volunteer. Their role is to keep the policy visible, approve tools, answer everyday questions, make sure human review happens, and route concerns through existing safeguarding, confidentiality, governance, or advice channels when needed.
Interactive checklist
Assess readiness with the Community AI checklist
Work through each section, get a readiness score, and print the results to align your team before you launch any AI project.



