Free to adapt. Take any of this that is useful. It is written for a mid-sized community nonprofit handling client and donor data; your risks and wording will differ. If you would rather start from your own answers, the AI Policy Builder generates one calibrated to your organisation. This is a sample, not legal advice.
This is a sample policy for a fictional organisation, used to demonstrate how an AI Policy Assistant works. It is illustrative, not legal advice.
Version 1.0 — Adopted March 2026 | Owner: Operations Director
1. Purpose
Riverside Community Trust supports families across the Riverside area through housing advice, financial counselling, and youth programming. This policy explains how staff and volunteers may use generative AI tools in their work.
Our goals are simple: let people use AI where it genuinely helps, protect the people we serve, and be honest about how we work.
2. Who this applies to
All staff, volunteers, board members, and contractors, whenever they use AI tools for Trust business — on Trust devices or their own.
3. Data classification
Before putting anything into an AI tool, decide which category it falls into.
Green data — safe to use with approved AI tools
- Published material: our website, newsletters, annual report, press releases
- Draft internal documents containing no personal information
- Generic questions, research, brainstorming, and writing help
- Anonymised or aggregated programme statistics
Amber data — only in approved enterprise tools, never consumer accounts
- Internal operational documents: budgets, board papers, strategy drafts
- Staff-facing material such as procedures and training notes
- Funder reports that do not name individual clients
Red data — never enter into any AI tool
- Any information identifying a client or their family, including names, addresses, dates of birth, case notes, and benefit details
- Donor names, giving history, and contact details
- Personnel records, disciplinary matters, and salary information
- Safeguarding records or anything relating to a child protection concern
- Login credentials, API keys, or financial account details
If you are not certain which category applies, treat it as Red and ask.
4. Acceptable uses
The following are approved for Green and Amber data using approved tools:
- Writing assistance — drafting, editing, shortening, and proofreading emails, reports, and communications
- Summarising — condensing long documents, meeting notes, or research
- Brainstorming — generating ideas for programmes, campaigns, and events
- Research — background reading and explanation of unfamiliar topics, with the expectation that you verify anything factual
- Translation — first-pass translation of published material, reviewed by a fluent speaker before use
- Data formatting — reorganising spreadsheets and tidying anonymised data
- Learning — using AI to understand a tool, a concept, or a piece of software
5. Prohibited uses
The following are not permitted under any circumstances:
- Entering Red data into any AI tool
- Using AI to make or substantially influence a decision about an individual's eligibility for services, benefits, or support
- Using AI to screen, rank, or assess job applicants
- Generating content that impersonates a real person, including AI-generated voice or likeness
- Publishing AI-generated material externally without human review and approval
- Using AI to produce safeguarding assessments or case decisions
- Uploading Trust documents to an AI tool that has not been approved (see the Approved Tools List)
- Using AI to write grant applications in a way that misrepresents our capacity or results
6. Human review
AI output is a draft, never a final product. A person must read, check, and take responsibility for anything AI helped produce before it is sent, published, or filed. This applies without exception to anything leaving the organisation.
You remain accountable for work you produce with AI assistance, exactly as if you had written it yourself.
7. Disclosure
Be honest about material AI use:
- External communications and publications — add a brief note where AI played a substantial role in drafting
- Funder reports and grant applications — follow the funder's own AI disclosure requirements; where they have none, disclose substantial use
- Internal documents — no disclosure needed for routine drafting or editing help
- Board papers — note AI use where it shaped analysis or recommendations
Routine assistance such as fixing grammar or shortening a paragraph does not require disclosure.
8. Personal accounts
Do not use personal AI accounts for Trust work involving Amber or Red data. Personal accounts may be used for Green data only.
Where the Trust provides an organisational account, use it. Organisational accounts carry contractual protections that personal accounts do not.
9. Client-facing AI
Any AI tool that interacts directly with clients — chatbots, automated triage, automated responses — requires written approval from the Operations Director and the Board before deployment. Clients must always be told when they are interacting with an AI system and must always be offered a route to a human.
10. Volunteers
Volunteers may use AI for Green data tasks only. Volunteers must not be given access to systems containing client information for AI-assisted work.
11. When something goes wrong
If you think Red data has been entered into an AI tool, or AI output has caused an error that reached a client or funder, tell the Operations Director the same day. We treat these as learning events, not disciplinary matters, provided they are reported promptly.
12. Questions and review
This policy is reviewed every six months, or sooner if the tools change materially.
If you are unsure whether something is allowed, ask before you act. Contact the Operations Director.
See it in use
The AI Policy Assistant answers staff questions from this policy and an accompanying approved tools list — returning Green, Yellow or Red, with the clause it relied on. Trying it against a policy you can read in full is the quickest way to judge whether the approach would work for your own.