AI tools are being adopted quickly, often without a clear policy behind that adoption. A few questions are worth answering first.
What data would this tool see?
Understand what information — including client, donor, or employee data — a tool would have access to, and whether that's appropriate.
Who owns the output?
Understand the tool's terms around content ownership, especially for anything client-facing or public.
What happens if it's wrong?
AI tools can produce confident, incorrect output. Know where human review is required before anything goes out the door.
Does staff have guidance?
If staff are already experimenting with AI tools informally, a short internal policy reduces risk far more than trying to ban the tools outright.
Adopted thoughtfully, AI and automation can meaningfully reduce repetitive work. Adopted carelessly, it can introduce new risk faster than most organizations realize.
