AI Policy for Nonprofits: A Privacy-Safe Checklist for Small Charities banner image preview
← Back to all posts Human Centred Ai And Admin Workflows

September 6, 202614 min read

AI Policy for Nonprofits: A Privacy-Safe Checklist for Small Charities

Why it matters: A practical AI policy for nonprofits does not need to be long. This checklist helps small charities and community organisations set safe boundaries for everyday AI use without l...

You'll explore:

Share this article

LinkedInFacebookX

Before You Use AI: The Minimum Safe Rules

Quick answer: a small charity or community organisation should only use AI for low-risk drafting, brainstorming, formatting, and routine admin where no personal, sensitive, confidential, safeguarding, donor, volunteer, or service-user information is entered into the tool. Every AI-assisted output should be reviewed by a responsible person before it is shared, published, stored as a record, or used to guide a decision. A short AI policy for nonprofits is useful because it gives trustees, coordinators, staff, and volunteers the same simple rules before people start experimenting in different ways.

  • Use AI only for low-risk work unless a named person has approved the task.
  • Never paste personal, sensitive, confidential, safeguarding, donor, volunteer, service-user, HR, payment, or password information into public AI tools.
  • Do not send credentials, private records, analytics exports, screenshots containing private information, or identifiable sensitive records.
  • Require human review for facts, tone, confidentiality, accessibility, consent, safeguarding implications, and suitability.
  • If unsure, stop and ask the named policy owner before using AI.

Checklist 1: Decide What AI Is Allowed to Help With

Start with the task, not the tool. AI may be a reasonable helper for generic outlines, first drafts, formatting, plain-language rewrites, and brainstorming where the prompt contains only public or fictional information. Avoid using AI where the task could affect a person’s access to support, funding, services, opportunities, benefits, safety, or reputation. If the organisation would feel uncomfortable explaining the AI use to a service user, volunteer, donor, trustee, or community member, treat the task as too risky until reviewed.

  • Is the task low-risk and administrative?
  • Is the information already public, fictional, or safe to share?
  • Could the output harm someone if it is wrong?
  • Could the task affect access to support, funding, services, opportunities, or safeguarding decisions?
  • Would the organisation be comfortable explaining the AI use to a service user, volunteer, donor, or trustee?
  • If unsure, do not use AI until a named person has approved it.
Chart for Privacy-safe AI use checklist for small charities and community organisations.
ChartChart showing the main primary visual aid: a yes/no decision flowchart whether a small charity task is signals.

Checklist 2: Define What Not to Put in ChatGPT or Any AI Tool

Your clearest rule should be the do-not-paste rule. Volunteers should not need technical knowledge to follow it. If information identifies a person, reveals a private situation, relates to safeguarding or support needs, or belongs in a secure internal record, do not paste it into ChatGPT or any other AI tool. Use anonymous placeholders, fictional details, or a general description instead, and keep the original information inside the organisation’s normal approved systems.

  • Do not paste names, addresses, phone numbers, email addresses, dates of birth, reference numbers, or account details.
  • Do not paste service-user stories, case notes, complaints, safeguarding concerns, health information, immigration information, disability information, financial circumstances, or personal support needs.
  • Do not paste donor details, volunteer records, HR information, payment details, passwords, private board papers, internal disputes, or grant plans that are not meant to be shared.
  • Do not paste meeting notes, chat logs, transcripts, screenshots, or analytics exports if they contain private or identifiable information.
  • Do not ask AI to decide people’s eligibility, needs, risks, benefits, suitability, or priority for support.
  • Use anonymous examples, fictional details, or general descriptions instead.

Checklist 3: Assign Responsibility Before Volunteers Try AI Tools

A small organisation does not need a complex structure, but it does need ownership. Name one person, such as a trustee, manager, coordinator, or administrator, to keep the AI policy visible, answer questions, approve tools, and handle mistakes. Make clear that volunteers should not test random AI tools for organisation work without permission. If the task touches safeguarding, confidentiality, employment, financial records, or legal duties, route it through the organisation’s normal responsible person instead of relying on AI.

  • Name an AI policy owner and a backup person.
  • List which AI tools, if any, may be used for organisation work.
  • Say who is allowed to use approved tools and for what types of tasks.
  • Require prompts to use generic, public, fictional, or anonymised information only.
  • Name who reviews AI-assisted outputs before publication or sharing.
  • Agree where mistakes should be reported and how quickly people should raise them.

Checklists 4 and 5: Set Human Review Rules and External Communication Rules

AI-assisted wording should be treated as a draft, not as an approved organisational message. Human review protects accuracy, tone, confidentiality, accessibility, consent, and trust. This matters especially when content is going outside the organisation, such as newsletters, social posts, grant drafts, website pages, donor updates, volunteer messages, or service-user communications. The reviewer should check that the content reflects the organisation’s values, does not reveal private information, does not overpromise, and is appropriate for the audience.

  • Checklist 4: Human review rules — check facts, dates, names, links, venue details, eligibility wording, and contact information before sharing.
  • Checklist 4: Human review rules — check tone, accessibility, plain language, inclusion, safeguarding implications, and whether the wording could be misunderstood.
  • Checklist 4: Human review rules — remove private details and confirm that any story, quotation, image description, or example has the right consent before use.
  • Checklist 5: External communication rules — do not publish AI-assisted content without a named human reviewer.
  • Checklist 5: External communication rules — do not use AI to send automatic replies about sensitive support needs, complaints, safeguarding, eligibility, or urgent help.
  • Checklist 5: External communication rules — keep a final human-approved version in the normal place where communications are stored.

Checklist 6: Create Rules for Meeting Notes, Summaries, and Records

Meeting notes are a common temptation because AI can appear useful for summaries and action lists. Treat them carefully. Minutes, transcripts, chat logs, recordings, and screenshots may contain identifiable people, private concerns, safeguarding details, volunteer issues, complaints, donor information, or internal disagreements. Do not paste full notes into a public AI tool. If notes are genuinely non-sensitive, remove names and private details first, ask for a summary of generic actions only, and review the result manually before it becomes a record.

  • Do not paste full minutes, transcripts, recordings, chat logs, or screenshots into public AI tools if they include private, identifiable, confidential, or sensitive information.
  • Do not use AI to summarise safeguarding discussions, service-user casework, complaints, HR matters, donor records, or private board disputes.
  • For non-sensitive meetings, remove names, contact details, locations, and identifying context before using AI.
  • Ask AI only for a generic structure, action list, or plain-language rewrite, not for judgement about people or risks.
  • A human note-taker or reviewer should confirm the final record is accurate, fair, accessible, and stored in the correct internal place.
  • If an AI meeting assistant, transcription tool, or recording feature is being considered, get approval first and make sure participants understand what is being used.

Checklist 7: Explain How to Handle Mistakes

People are more likely to report problems if the policy explains what to do without blame. Mistakes may include pasting private information into an AI tool, publishing unreviewed content, relying on inaccurate AI wording, sending an inappropriate message, or using AI for a task that should have been handled by a person. The first rule is to stop further sharing. The second rule is to tell the named policy owner quickly. If safeguarding, confidentiality, legal, employment, or data protection concerns may be involved, use the organisation’s normal escalation route and seek appropriate advice.

  • Stop using or sharing the AI output as soon as a problem is noticed.
  • Tell the named policy owner, coordinator, manager, trustee, or safeguarding/confidentiality lead if relevant.
  • Record what happened in a simple internal note without adding unnecessary private details.
  • Remove or correct unreviewed, inaccurate, or inappropriate content where possible.
  • Do not paste the incident details into another AI tool to ask what to do.
  • Review whether the policy, training, tool approval, or human review step needs to change.

Checklist 8: Keep the Policy Short, Visible, and Easy to Follow

A one-page policy is better than a long document that volunteers never see. Put it where people already look for admin guidance, such as an induction pack, shared drive, volunteer handbook, or trustee folder. Review it after a tool change, a mistake, a new activity, or an agreed review date. Self-serve next step: copy the template below into your own document and adapt it using only non-sensitive examples. Capacity note: Chestnut Communities is not currently offering paid AI policy reviews, implementation, urgent support, or automatic AI replies; this checklist is intended as a self-serve starting point, not a managed service.

  • One-page AI policy template: 1. Purpose — We use AI only to support low-risk drafting, brainstorming, formatting, and routine admin.
  • 2. Approved tools — Only tools named by the organisation may be used for organisation work.
  • 3. Do-not-paste rule — We do not enter personal, sensitive, confidential, safeguarding, donor, volunteer, service-user, HR, payment, password, private record, private screenshot, or analytics export information into AI tools.
  • 4. Allowed uses — Generic outlines, public event wording, plain-language rewrites, non-sensitive action lists, and ideas for internal planning may be allowed with human review.
  • 5. Not allowed — AI must not make decisions about people, assess risk, replace safeguarding processes, provide personalised advice, or handle private records.
  • 6. Human review — A named person checks accuracy, tone, confidentiality, accessibility, consent, and suitability before anything is shared or stored.
  • 7. Mistakes — Stop, report quickly, record what happened, and use the normal escalation route if sensitive information or safeguarding may be involved.
  • 8. Review — The policy owner reviews this policy after incidents, tool changes, or the agreed review date.

Low-risk, higher-risk, and not-allowed AI tasks

Task typeAI use allowed?WhySafer approach
Brainstorming a newsletter outlineUsually yesLower risk if no private details are includedUse generic prompts and human editing
Rewriting a public event descriptionUsually yesBased on information already intended for public useCheck accuracy, tone, dates, venue details, accessibility information, and contact details
Turning public information into a plain-language checklistUsually yesThe source is already public and the task is editorialKeep links to the original source and have a human reviewer check meaning
Creating meeting action lists from non-sensitive notesSometimesDepends on what the notes containRemove names and private details first; review manually before storing
Summarising service-user case notesNoMay expose personal or sensitive informationSummarise internally without public AI tools or seek appropriate advice
Drafting advice to a beneficiaryHigh risk / avoidCould be inaccurate, unsuitable, or outside the organisation’s roleUse approved guidance and qualified human review

Do-not-paste list and safer alternatives

Do not pasteExamplesSafer alternative
Personal informationNames, addresses, phone numbers, email addresses, dates of birth, reference numbersReplace with anonymous placeholders such as Volunteer A or Service user B
Sensitive informationHealth, finances, immigration, safeguarding, disability, faith, ethnicity, personal circumstances, support needsDo not use a public AI tool; handle through the normal internal process
Confidential organisation informationPrivate donor details, grant plans, passwords, internal disputes, private board papersKeep in approved internal systems
Credentials and access informationPasswords, login links, recovery codes, API keys, shared mailbox detailsNever enter them into AI tools; use approved password and access processes
Private records or exportsCase files, volunteer records, HR files, payment records, analytics exports, screenshots containing private informationKeep inside the correct internal system and minimise sharing
Meeting notes with identifiable detailsVolunteer names linked to concerns, service-user stories, complaints, safeguarding discussionsCreate a manual summary or anonymise heavily before any AI use
Graph for Privacy-safe AI use checklist for small charities and community organisations.
GraphGraph showing the main primary visual aid: a lightweight responsibility map showing three roles—policy signals.

Simple AI responsibility matrix

Decision or activityWho should own itMinimum rule
Choosing which AI tools may be usedTrustee, manager, or named coordinatorOnly approved tools may be used for organisation work
Creating promptsApproved user or volunteerUse generic, public, fictional, or anonymised information only
Reviewing AI-assisted contentNamed human reviewerCheck facts, tone, confidentiality, accessibility, consent, and suitability before sharing
Publishing external communicationsCoordinator, communications lead, manager, or trusteeNo AI-assisted external message should be published without human approval
Handling mistakesPolicy owner or safeguarding/confidentiality lead if relevantReport quickly, stop further sharing, and record what happened
Reviewing the policyNamed policy ownerRevisit after tool changes, incidents, new activities, or the agreed review date

Minimum safe rules before using AI

  • Name one person responsible for the AI policy.
  • Decide which AI tools, if any, are approved for organisation work.
  • Allow AI only for low-risk drafting, brainstorming, formatting, and summarising of non-sensitive material.
  • Ban pasting personal, sensitive, confidential, safeguarding-related, donor, volunteer, service-user, HR, payment, password, private record, screenshot, or analytics export information into public AI tools.
  • Require human review before anything AI-assisted is shared, published, stored as a record, or used for a decision.
  • Tell volunteers what to do if they make a mistake.
  • Keep the policy short, visible, and easy to find.

Checklist 1: Decide what AI is allowed to help with

  • Is the task low-risk and administrative?
  • Is the information already public or safe to share?
  • Could the output harm someone if it is wrong?
  • Could the task affect access to support, funding, services, or opportunities?
  • Would the organisation be comfortable explaining the AI use to a service user, volunteer, donor, or trustee?
  • If unsure, do not use AI until a named person has approved it.

Checklist 2: Define what not to put in ChatGPT or any AI tool

  • Do not paste names, addresses, phone numbers, email addresses, or dates of birth.
  • Do not paste service-user stories, case notes, complaints, safeguarding concerns, or health information.
  • Do not paste donor details, volunteer records, HR information, payment details, passwords, or private board papers.
  • Do not paste meeting notes if they identify people or sensitive situations.
  • Do not ask AI to make decisions about people’s eligibility, needs, risks, benefits, or suitability.
  • Use anonymous examples, fictional details, or general descriptions instead.

Privacy warning

Use placeholders instead of real details

Frequently asked questions

Do small charities and community groups really need an AI policy?
Yes, a short policy is sensible before routine AI use. It does not need to be complicated. The main purpose is to set plain rules on approved tools, low-risk uses, information that must never be pasted into AI tools, human review, and what to do if something goes wrong. This checklist is a governance starting point, not a guarantee of legal compliance.

Can volunteers use free AI tools for charity admin?
Only if the organisation has approved the tool and the task. Volunteers should use AI only for low-risk work, such as generic drafting, brainstorming, formatting, or rewriting public information. They should not paste private records, credentials, screenshots containing private information, analytics exports, service-user details, donor records, safeguarding information, or other identifiable sensitive records into free AI tools.

What information should never be pasted into an AI tool?
Do not paste personal information, sensitive information, safeguarding details, service-user stories, case notes, complaints, donor details, volunteer records, HR information, payment details, passwords, private board papers, confidential plans, private screenshots, analytics exports, or identifiable meeting notes. Use anonymous placeholders or fictional examples instead.

Can AI help write newsletters, grant drafts, or social media posts?
AI can help with outlines, first drafts, plain-language rewrites, and ideas if the prompt uses public, generic, or fictional information. A human reviewer should check facts, dates, eligibility wording, tone, accessibility, consent, confidentiality, and suitability before anything is sent or published. Do not include private service-user, donor, volunteer, or internal information in the prompt.

Can AI summarise meeting notes?
Be cautious. Do not paste full minutes, transcripts, recordings, chat logs, or screenshots into a public AI tool if they contain identifiable people, private details, complaints, safeguarding matters, donor records, HR issues, or confidential discussions. For genuinely non-sensitive notes, remove names and identifying details first, ask only for a generic action list or structure, and have a person review the final record.

Who should be responsible for AI use if we do not have IT or legal staff?
Name one practical policy owner, such as a trustee, manager, coordinator, administrator, or experienced volunteer. Their role is to keep the policy visible, approve tools, answer everyday questions, make sure human review happens, and route concerns through existing safeguarding, confidentiality, governance, or advice channels when needed.

Interactive checklist

Assess readiness with the Community AI checklist

Work through each section, get a readiness score, and print the results to align your team before you launch any AI project.

Start the interactive checklist