Your treasurer used ChatGPT to draft last month’s financial summary. Your newsletter editor ran the spring announcement through an AI writing tool before sending it to 340 members. Your secretary pasted the board meeting recording into an AI transcription service to generate minutes. None of them asked permission. None of them did anything wrong, exactly. But none of them thought about what data they were feeding into these tools, either.
This is already happening in your organization. The question isn’t whether your volunteers should use AI. They’re using it. The question is whether you’ve told them what’s okay and what’s off-limits.
Why a Policy Matters Right Now
According to BDO’s 2024 Nonprofit Standards Benchmarking Survey, 82% of nonprofits reported using AI in some capacity. The gap? Only about 15% of U.S. and Canadian nonprofits surveyed by the AI Equity Project had actually put a formal policy in place. That means the vast majority of organizations have people using AI tools with zero guidelines.
For a volunteer-run club or community group, the stakes feel lower than they do for a hospital or a bank. No one’s making medical decisions with ChatGPT. But the risks are still real.
Member data leaks. A board member pastes a list of member names, emails, and payment statuses into an AI chat to “help sort overdue dues.” That data now lives on a third-party server. If your organization collects sensitive information, like immigration status for a cultural association, or health details for a support group, the exposure gets serious fast.
Inaccurate communications. AI tools generate confident-sounding text that’s sometimes flat-out wrong. A volunteer uses an AI tool to draft a message about your nonprofit’s tax-exempt status and gets the IRS rules wrong. That email goes to 200 members before anyone catches it.
Trust erosion. Members expect that the board president’s message actually came from the board president. If people find out that communications are AI-generated without disclosure, it can feel dishonest, even when the intent was just saving time.
Legal exposure. Copyright questions around AI-generated content remain unsettled. If your organization publishes AI-generated material, you may not own it the way you’d own content written by a volunteer.
A written policy doesn’t eliminate these risks. But it gives your volunteers a clear framework. And it shows members that the board has thought about this.
What Your Policy Should Cover
You don’t need a 20-page corporate document. A single page works. The National Council of Nonprofits, NTEN, and organizations like Whole Whale have all published resources on AI and nonprofit operations, and they converge on a handful of essentials.
Here’s what to include.
1. Approved Uses
Spell out the things people can do with AI. Be specific. “Improving efficiency” means nothing. Instead, list concrete activities:
- Drafting email announcements, newsletters, and social media posts (with human review before sending)
- Summarizing meeting notes or lengthy documents
- Generating agenda templates and event planning checklists
- Brainstorming ideas for fundraisers, programs, or outreach
- Proofreading and grammar checking existing text
- Translating communications for multilingual membership
The key phrase in every approved use: with human review. No AI-generated content should go out to members without a real person reading it first and confirming it’s accurate.
2. Data Privacy Rules
This is the section that actually prevents harm. Three rules cover most situations:
Never paste member personal information into AI tools. That means names paired with emails, phone numbers, addresses, payment records, or any identifying details. If someone needs AI help analyzing membership trends, they should anonymize the data first, or better yet, work from aggregate numbers only.
Don’t upload internal financial records. Your treasurer’s spreadsheet with bank account details, donor lists with giving amounts, or vendor contracts shouldn’t go into any AI tool. Period.
Don’t input confidential board discussions. If the board discussed a sensitive personnel issue, a legal dispute, or a member complaint, that content stays out of AI tools. Summaries are fine if they’ve been stripped of identifying details.
Community IT Innovators, an IT services firm for nonprofits, recommends a clear rule: employees, contractors, and volunteers shouldn’t upload or share any data that’s confidential, proprietary, protected by regulations, or contains internal organizational information.
Simple enough to remember. Simple enough to follow.
3. Disclosure Requirements
When should you tell members that AI helped create something? Organizations differ on this, and you need to make a deliberate choice.
Option A: Always disclose. Every newsletter, email, or document that involved AI assistance includes a brief note. Something like: “This communication was drafted with AI assistance and reviewed by [Name].” Transparent. Some organizations find it builds trust.
Option B: Disclose for substantial use only. If AI wrote most of a document, disclose. If someone just used a grammar checker or spell-check tool, no disclosure needed. This draws a line between using AI as an editor versus using it as a ghostwriter.
Option C: Internal tracking only. You don’t disclose to members, but you keep an internal log of which communications used AI assistance. This gives the board visibility without making every email feel like it carries a disclaimer.
Most small clubs we’ve seen go with Option B. It’s practical without being burdensome.
4. Prohibited Uses
Just as important as what’s allowed. Say clearly what’s off-limits:
- Making membership decisions based on AI analysis or recommendations (who to accept, who to remove)
- Generating legal documents, contracts, or bylaws without attorney review
- Creating fake testimonials, endorsements, or member quotes
- Using AI to impersonate a specific person in communications
- Uploading member data, donor records, or financial details into AI tools
- Relying on AI-generated financial calculations without manual verification
5. Accountability and Review
Who’s responsible for this policy? Name a person or a committee. In most small organizations, this falls to the board secretary or a designated tech-savvy board member. Their job: answer questions about edge cases, update the policy annually, and handle any incidents where the policy was violated.
Set a review date. AI tools change fast. A policy written in September 2026 may need updates by spring 2027. Put it on the board calendar.
The Template: Copy, Customize, Adopt
Here’s a one-page policy you can adapt. Replace the bracketed items with your organization’s specifics.
[Organization Name] Policy on Artificial Intelligence Use
| *Adopted: [Date] | Review Date: [Date + 12 months]* |
Purpose: This policy provides guidelines for volunteers, board members, and committee chairs who use AI tools (such as ChatGPT, Google Gemini, Claude, or similar services) in their work for [Organization Name].
Approved Uses:
AI tools may be used to:
- Draft communications (emails, newsletters, social media posts) that will be reviewed and approved by the responsible volunteer before distribution
- Summarize meeting notes and lengthy documents
- Generate templates, checklists, and planning outlines
- Proofread and improve existing text
- Translate communications for our membership
- Brainstorm ideas for events, programs, and outreach
Data Privacy Requirements:
The following information must NEVER be entered into AI tools:
- Member names paired with contact information, payment status, or personal details
- Financial records, bank details, or donor information
- Confidential board discussions or personnel matters
- Passwords, account credentials, or access codes
- Any information a member has shared in confidence
When in doubt, anonymize. Remove names, addresses, and any identifying details before using AI tools.
Disclosure:
When AI tools are used to draft a substantial portion of a member-facing communication, the communication should include a note such as: “Drafted with AI assistance, reviewed by [Name/Role].”
Prohibited Uses:
AI tools must NOT be used to:
- Make decisions about individual members (acceptance, removal, standing)
- Create legal documents or financial filings without professional review
- Generate fabricated quotes, testimonials, or endorsements
- Impersonate any individual
- Process or analyze member personal data
Accountability:
[Role/Name] is responsible for answering questions about this policy and addressing potential violations. This policy will be reviewed and updated annually at the [month] board meeting.
Acknowledgment:
All board members and committee chairs should read this policy and confirm their understanding at the next board meeting.
That’s it. One page. No legalese. Adjust the language to fit your group’s tone, add specific tool names if your volunteers are all using the same one, and remove anything that doesn’t apply.
How to Present This to Your Board
You’ve got the template. Now comes the part that actually matters: getting your board to adopt it. Here’s how to do it without turning a 15-minute agenda item into a two-hour debate.
Don’t start with the policy document. Start with the problem. Open with a question: “Does anyone here use ChatGPT or a similar tool for club business?” Watch hands go up. Then ask: “Has anyone thought about what happens to the data we paste into those tools?” That usually gets the room’s attention.
Share one concrete example. Pick the most relevant risk for your group. If you’re a cultural association that collects sensitive member details, focus on the data privacy angle. If you’re a PTA that sends weekly newsletters, focus on the disclosure question. One vivid example beats a list of abstract risks.
Present the policy as a starting point, not a finished product. Board members are more likely to engage with something they can shape. Hand out the draft and say, “I’d like us to spend 10 minutes marking up what doesn’t fit our group.” You’ll get better buy-in than if you present it as a done deal.
Avoid framing AI as dangerous. Board members who already use these tools will get defensive if you lead with fear. The framing that works: “AI’s useful. We should keep using it. We just need a few ground rules so we don’t accidentally expose member data or send out something inaccurate.”
Set a vote for the next meeting. Don’t try to adopt it on the spot. Give people time to read it, think about edge cases, and come back with questions. A month between introduction and vote is plenty.
Common Pushback (and How to Handle It)
“We’re too small for a policy like this.”
You’re not too small. You’re the right size. A 50-member garden club with three board members can read, discuss, and adopt this policy in a single meeting. Large organizations spend months on theirs. Yours takes 15 minutes.
“Nobody’s going to follow this.”
Maybe not perfectly. But having a written policy means you’ve set expectations. When a volunteer does paste a member list into ChatGPT, you can point to the policy and explain why that’s a problem. Without a policy, you’ve got nothing to point to.
“AI changes too fast for a static policy.”
That’s why you set a review date. The policy doesn’t need to name every tool or anticipate every scenario. It sets principles: protect member data, review AI output before sending, disclose when it matters. Those principles hold up even when the tools change.
“Isn’t this going to slow people down?”
Not really. The policy doesn’t ban anything useful. It just adds two steps: don’t paste sensitive data, and review before sending. Most volunteers are already doing the second part. The first part takes five seconds of thought.
One More Reason to Do This Now
How would your members react if they found out their personal information was processed through an AI tool without their knowledge? What would that conversation look like at your next general meeting?
You’d rather have the policy in place before that question comes up. Not after.
The organizations that handle this well are the same ones that run their digitalization well. They think ahead. They communicate clearly. They respect their members’ trust enough to put guardrails in place before something goes wrong.
Your AI policy doesn’t need to be perfect. It needs to exist. Start with the template above, adapt it to your organization, and get it on the agenda.
Managing member data, communications, and organizational records is easier when you’ve got the right tools in place. Somiti helps volunteer-run clubs and community organizations handle membership, dues, and communications in one place, so your board can spend less time on spreadsheets and more time on what matters.