How to Write an AI Policy for a Small Charity

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for How to Write an AI Policy for a Small Charity.
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for How to Write an AI Policy for a Small Charity.

Keep it to two or three pages covering six things: which AI tools are approved, what must never go into them (beneficiary, health and safeguarding details above all), when a person checks the output, how you'll be open with supporters, which trustee owns it, and when it's reviewed. Draft from a template with AI's help; trustees approve it.

A small business AI policy won't do the job on its own, because the risks sit in different places. Your volunteers probably use personal free accounts. Your records hold details about people in hard circumstances, often including health information. Your income depends on supporters trusting what you tell them. And your trustees, not a managing director, are accountable. The general structure is in writing an AI usage policy for a small business; what follows is what a charity has to add and decide.

Follow me on Instagram@sagnikteaches

Where a charity's AI risks differ from a company's

Before drafting, list how people in your charity already use AI. Ask staff and a few volunteers directly; you'll almost certainly find more than you expected. Then look for these charity-specific exposures:

Connect on LinkedInSagnik Bhattacharya
  • Volunteers on personal accounts. A volunteer drafting social posts on a free ChatGPT account on their own phone is fine for public information and a problem the moment they paste in a case note.
  • Beneficiary information. Health, family circumstances, immigration or housing status, children's details. Under data-protection law such as the GDPR, much of this is treated as especially sensitive.
  • Safeguarding. Anything involving concerns about a child or adult at risk must stay inside your safeguarding process, never in a general AI tool.
  • Donor trust. Invented stories, AI images of "beneficiaries" and inflated figures in appeals damage a charity faster than any data breach.
  • Funders' conditions. Some grant agreements restrict how beneficiary data is shared or processed. Check yours.
  • No IT department. Rules have to be simple enough that a volunteer can follow them without asking anyone.

Three questions are enough for the survey: which AI tools do you use for charity work, what for, and on whose account. When the example nursery asked, five of nine staff and four of 12 volunteers said they used AI. Most uses were harmless: newsletter drafts, rewording event posts, a first go at a funding bid. Two practitioners, separately, had been pasting children's learning-journal entries into a free chatbot on their phones to "make them sound more professional" before parents saw them. Neither thought of it as sharing data; they thought of it as spell-checking. That one answer decided the first line of section 3 in the policy below, and it's why the survey should be anonymous or at least blame-free. People only tell you about the risky uses if they're sure the question isn't a trap.

Subscribe on YouTube@codingliquids

Seven decisions to settle before anyone drafts

The policy is just these decisions written down clearly. Settle them in a short meeting first; drafting takes minutes once you have them. Here they are with example answers for an illustrative charity-run community nursery with nine staff, 12 volunteers and 48 children on roll:

  1. Which tools are approved for charity information? Example: Gemini in the charity's Google Workspace account, because business content isn't used for training by default and the charity already controls those accounts. Personal accounts only for work with public information.
  2. What never goes into any AI tool? Example: children's names, photos, development notes, health or allergy details, family circumstances, safeguarding records, staff HR matters, donor bank details.
  3. When must a person check AI output? Example: always, before anything is sent, published or saved to a record. Two people check anything going to parents, funders or the public that includes figures.
  4. What about AI images? Example: never generate images that look like real children, families or staff. Illustrations and graphics are fine if they're clearly not photos.
  5. How open are we with supporters and families? Example: a line on the website saying AI helps draft some materials and people check everything; any chatbot says it's automated in its first message.
  6. Who owns the policy? Example: the nursery manager day to day; the trustee who leads on safeguarding and data on behalf of the board.
  7. When is it reviewed? Example: every 12 months, and whenever a new tool is proposed or something goes wrong.

The same seven questions give quite different answers in a different charity. Take an illustrative food bank with two paid coordinators and about 40 volunteers, running on free email accounts rather than a workspace plan. Its sensitive data is referral information: names, addresses, household size and the reason for referral, which can reveal debt, illness or domestic abuse. Its answers:

  • Approved tools: two ChatGPT Business seats for the coordinators, at OpenAI's nonprofit price of $8 per user a month on annual billing, checked against its eligibility rules first. Claude for Nonprofits offers Team at the same $8 per user with a two-seat minimum, so either would do.
  • Never goes in: anything from a referral form, the reason for any referral, and the volunteers' own contact details.
  • Volunteers: personal accounts for public information only, such as the opening-times post or a donation drive appeal.
  • Owner: the senior coordinator, with the treasurer as trustee lead, because the food bank has no safeguarding trustee.

The shape of the policy is the same; the lists inside it are not. That's why adapting another charity's policy word for word rarely works, even a good one.

A two-page policy you can adapt

Here is the complete policy for the example nursery. Replace the details with your own decisions; keep the plain language.

[CHARITY NAME] POLICY ON USING ARTIFICIAL INTELLIGENCE (AI) TOOLS
Approved by the board of trustees on [date]. Review due [date + 12 months].
Owner: [manager name]. Trustee lead: [trustee name].

1. Why we have this policy
We use AI tools to save time on writing and admin so we can spend more time
with children and families. This policy makes sure we do that without putting
anyone's privacy, safety or trust at risk. It applies to staff, volunteers
and trustees whenever they do charity work, on any device.

2. Approved tools
Charity information may only be used in the tools on our approved list
(attached), using charity accounts. The list is kept by [owner] and only
includes tools that don't use our content to train their models.
You may use other AI tools, including personal accounts, only for
information that is already public, such as our website or published events.

3. Information that must never go into any AI tool
- Children's names, photos, observations, development or learning notes
- Health, allergy, medication or additional-needs information
- Family circumstances, contact details or anything a parent told us in confidence
- Anything to do with a safeguarding concern
- Staff or volunteer HR, disciplinary or health matters
- Donors' bank or card details
If you're not sure, leave it out and ask [owner].

4. Checking what AI produces
AI tools make mistakes and sometimes invent facts. A person must read and
correct all AI output before it is sent, published or saved. Anything with
figures, going to parents, funders or the public needs a second person's check.

5. Images and stories
We don't create AI images that look like real children, families, staff or
volunteers. We don't invent or embellish stories or quotes. Real stories
need written consent for each place we use them.

6. Being open
We tell people that AI helps us draft some materials and that staff check
everything. Any chatbot we use says it is automated in its first message.

7. Meetings and recordings
No AI note-taker or recording tool may join meetings where children,
families, safeguarding or staff matters are discussed.

8. New tools and problems
Ask [owner] before using any new AI tool for charity work. If you think
information has gone into an AI tool that shouldn't have, tell [owner] the
same day. We will deal with it under our data-protection procedures;
nobody will be blamed for reporting it.

9. Learning
Everyone who uses AI for charity work gets a short briefing on this policy
when they join and when it changes.

Attached: approved tools list (updated [date]).

Section 8's last line matters more than it looks. People who fear being blamed hide mistakes, and a data incident you hear about on day one is far easier to handle than one you find in six months.

Section 3 doesn't stop staff getting help with work about children; it changes what goes in. A before and after from the nursery's funder report shows the difference. The first attempt at a prompt read: "Write up how [child's first name], age 3, has come on since January. Speech delay, dad not around, now using two-word phrases." Every clause of that is on the never list. The version the manager used instead: "Write one paragraph for a funder report. Of our 48 children, 11 have additional needs. Our twice-weekly small-group speech sessions started in January. By July, 8 of those 11 children had met the speech goal set with their families. Plain, warm, no individual stories." The paragraph that came back was just as usable, because funders mostly want the aggregate picture. An individual story can still go in, but it's written by a person, from the record, with the family's written consent under section 5.

The approved tools list, filled in

The list is a separate one-page attachment so the owner can update it without a board meeting. Keep it short; three or four tools is plenty for a small charity. The example nursery's list might look like this:

Tool and accountApproved forNot approved forLast checked
Gemini in the charity's Workspace accountsDrafting letters, newsletters, bids and policies; summarising our own public reportsAnything in section 3 of the policySeptember 2026
Canva's AI features on the charity accountGraphics and illustrations for posts and postersPhoto-realistic images of peopleSeptember 2026
Personal ChatGPT or Claude accounts (training switched off)Rewording public information, such as event listingsAny charity record, email or document that isn't publicSeptember 2026

The "last checked" column is the owner's reminder to reread each vendor's terms once a year, because plans and data settings change. When a tool is dropped, say so in a line at the bottom ("Removed: [tool], March 2027, terms changed") so nobody keeps using it out of habit.

Drafting your version with AI, without the boilerplate

Paste the template and your seven decisions into an assistant and ask it to adapt one to the other:

Here is a template AI policy for a small charity and our seven decisions.
Rewrite the template for our charity using only our decisions.
Keep it under 900 words and plain enough for a new volunteer.
Don't add clauses, legal references or commitments we haven't decided.
Where our decisions leave a gap, list it as a question for me at the end.

Without that fourth line, drafts tend to grow clauses nobody agreed to. A realistic example of what comes back (illustrative):

The Charity will conduct an annual external audit of all AI systems and will ensure full compliance with all applicable laws, regulations and industry standards relating to artificial intelligence.

Nobody decided on an external audit, and a small charity can't afford one. "Full compliance with all applicable laws" commits you to something undefined. The edited version is the one line you actually meant: "The policy owner reviews our AI use every 12 months and reports to the board." Read every sentence of the draft and ask: did we decide this? If not, cut it or bring it to the meeting.

Volunteers, personal phones and free accounts

This is where most small charity policies are weakest, so make the volunteer section concrete. A few situations to cover explicitly:

  • The volunteer who writes your Instagram posts on their own ChatGPT account. Fine for event details and public news. Suggest they switch off model training in their privacy settings (on ChatGPT it's under Data controls, labelled "Improve the model for everyone" at the time of writing), and never paste in anything from the charity's records.
  • The trustee who asks an AI to summarise board papers. Board papers often include staff and beneficiary matters. Either they use a charity account on the approved list, or they don't upload them.
  • The key worker who wants help writing up notes. The honest answer under this policy is no, not in a general AI tool, however tempting. If the charity later adopts a tool built for case records with a proper data agreement, the policy and approved list change first.
  • Meeting recorders. AI note-takers that join video calls automatically are easy to switch on by accident. Section 7 bans them from sensitive meetings; tell people how to check their settings. Whether AI meeting note-takers are safe covers the settings in more detail.

Before any tool goes on the approved list, someone should read its terms. What to check in an AI tool's privacy policy and terms gives a checklist the policy owner can use.

Taking it to the trustee board

Trustees will want to know three things: what's the risk, what does it cost, and who is accountable. A half-page cover paper answers all three. For example:

Staff and volunteers already use AI tools, mostly free personal accounts, for writing posts, emails and funding bids. Nobody has used them for children's records as far as we know, but nothing currently stops it. This policy sets clear limits, moves charity work onto accounts we control (included in our existing Workspace plan at no extra cost), and makes the manager responsible day to day, with [trustee] as board lead. We ask the board to approve the policy and review it in 12 months.

If you work with people in the EU or sell services there, add a line on the EU AI Act. Its AI literacy duty (Article 4) has applied since February 2025 and, as softened in July 2026, asks organisations to take measures to support staff AI literacy rather than guarantee a level; the briefing in section 9 of the template is that measure. Any supporter-facing chatbot must also tell people they're talking to AI. If anything in the policy touches legal duties you're unsure about, ask your data-protection adviser or a solicitor before the board meeting, not after.

Making it stick: a 20-minute briefing with five scenarios

A policy nobody has discussed is a policy nobody follows. At the next team meeting, spend 20 minutes on five scenarios and let people answer before you give the policy's answer:

  1. A practitioner wants AI to tidy up a child's learning journal entry before it goes to parents. Policy answer: not in a general AI tool; the child's details stay out.
  2. A volunteer generates a photo-realistic image of "a happy toddler at our nursery" for the summer appeal. Not allowed; use a real consented photo or a clearly illustrated graphic.
  3. The fundraiser uses the charity's Gemini account to draft a grant application from published reports. Fine, with a second person checking the figures.
  4. A trustee's video-call app starts recording and summarising a board meeting that includes a staffing issue. Stop it, delete the recording, tell the policy owner.
  5. Someone realises they pasted a parent's email, with the child's name, into a personal chatbot last week. Tell the owner today; nobody gets blamed.

Scenario five is the one to spend time on. The goal is that people report it. Walk the room through what the owner then does, so reporting doesn't feel like a leap into the unknown. The same day: ask the person to delete that chat, check whether the account had model training switched on, and write a short entry in the data incident log:

Date reported: [date]   Reported by: [role]
What happened: parent's email (child's first name, a medical
  appointment) pasted into a personal chatbot account on [date]
Account: personal, free. Training setting: was on, now off
Action taken: chat deleted by the staff member on [date]
Advice sought: data-protection adviser, [date]
Outcome: [adviser's view on whether to report or tell the family]
Change made: added "parents' emails" to the section 3 examples

Leave the decision on whether it must be reported, or the family told, to your data-protection adviser; the log's job is to show you acted promptly and learned something. The last line is the useful one for the policy, because each incident usually points to a gap in the examples people were given.

A second way to check the policy is working: at the 12-month review, run the same three-question survey as before. If the answers now show charity work on charity accounts, and nobody mentions pasting records anywhere, the policy has changed habits. If the personal-account uses have simply gone quiet rather than moved, ask again, more gently.

Rolling out an AI policy so staff actually follow it has more on keeping it alive after the first meeting. Then diary the review date, and bring the approved tools list to the board once a year alongside the policy.

Questions trustees ask about AI policies

Does a charity run entirely by volunteers need an AI policy?

Yes, and arguably more than a staffed one, because volunteers tend to use their own free accounts on their own phones. A one-page version is enough: which tools are fine for public information, what must never be typed into any AI tool, and who to ask when unsure. The data rules matter most, since that's where a well-meaning volunteer can cause real harm.

Should the policy name specific AI tools?

Name them in a short approved-tools list attached to the policy rather than in the policy itself. Tools change names, plans and terms often, and a list can be updated by the policy owner without a board meeting. The policy sets the rules (business accounts for charity data, no training on your content); the list says which products currently meet them.

Who should approve the AI policy?

The trustee board, like any other policy that affects safeguarding, data protection and reputation. Staff or a volunteer lead can draft it, and one trustee should own it on the board's behalf. Approval should be minuted, with a review date. If your charity has a data-protection adviser or safeguarding lead, ask them to read the draft before it goes to the board.

Can we just adapt a small business AI policy template?

You can start from one, but it will miss the parts that matter most for a charity: beneficiary and safeguarding data, volunteers on personal devices, images of the people you help, fundraising honesty and trustee oversight. Use a business template for the structure and add those sections, or adapt the charity example in this tutorial instead.

Further reads

Sources: EU AI Act Articles 4 and 50 and the Digital Omnibus on AI; OpenAI, Anthropic and Google help pages on consumer training settings and business-plan data use.

Want help turning this into your charity's policy?

On a 1:1 call we'll go through how your staff and volunteers already use AI, settle the seven decisions with you, and shape a policy your trustees can approve.

Book a 1:1 call with me