ApiaryActiveLive
Try: pause · settings · learn · wipe
← Community / Reading Room
HT
craft · 13 min read

How to Write an AI Policy for a Small Club or Nonprofit in One Page

This is for small groups run mostly by volunteers or a tiny staff:

By Austin Little

Somebody on your board already uses AI to draft the newsletter. Somebody else is nervous about it. A third person pasted the member list into a chat window last month to "clean it up" and nobody's sure whether that was okay. A one-page AI policy settles those questions before they turn into arguments. This guide shows you how to write one for a small club or nonprofit, with a sample template you can adapt.

AI disclosure. This page was drafted with AI assistance and edited for Apiary. We don't invent quotes, stats, people, or events.
Not legal advice. This is a practical starting point for small, volunteer-run groups. Laws about privacy, data, employment, fundraising, and charities vary by country, state, and the type of organization you are. Where we flag a legal or donor-data point, check it with a qualified advisor, your state charity regulator, or your umbrella organization.

Who this is for

This is for small groups run mostly by volunteers or a tiny staff:

  • Garden clubs, beekeeping associations, and community orchards.
  • PTAs, booster clubs, and scout troops.
  • Food pantries, mutual aid groups, and tenant associations.
  • Small arts groups, faith-community committees, and neighborhood associations.
  • Small registered nonprofits with a part-time director and a board.

If you're a large organization with HR, legal counsel, and an IT department, you'll need more than one page. But many large-organization policies started as something like this.

Why one page

A long policy nobody reads protects nobody. A small group's AI policy should do three things:

  1. Say what's okay, so careful volunteers feel free to use helpful tools.
  2. Say what's off-limits, especially around people's private information.
  3. Say who to ask, so gray areas get a quick answer instead of a guess.

One page fits on a shared drive, a pinned message, or the back of a volunteer handbook. It can be read at a board meeting in five minutes. That's the point.

What an AI policy is not

  • It's not a ban. You can ban AI if your group wants to, but most groups find it more useful to set guardrails.
  • It's not an endorsement of any product. Your policy should be about behavior, not brands. Tools change every few months.
  • It's not a replacement for your privacy and data practices. If you have a privacy policy, donor-privacy promise, or data-handling rules, your AI policy should point to them and follow them.
  • It's not legal compliance on its own. It's a practical guide.

Before you write: a 20-minute inventory

You can't write a sensible rule about something you haven't looked at. Spend twenty minutes at a board meeting or in a shared doc answering these:

What are people already using AI for?

Ask without judgment. You'll probably hear things like:

  • Drafting newsletters, social posts, and event flyers.
  • Summarizing meeting notes.
  • Writing grant narratives or thank-you letters.
  • Translating announcements for members who speak other languages.
  • Making spreadsheets or formulas.
  • Brainstorming event ideas.

What information does your group hold?

The Federal Trade Commission's guide for businesses, Protecting Personal Information, opens with a plain first step: take stock, meaning know what personal information you have and where it is. That's useful advice for a club, too. Make a simple list:

  • Member names, emails, phone numbers, addresses.
  • Donor names and giving history.
  • Payment or bank details.
  • Information about children or youth.
  • Health, dietary, or disability information (for example, allergy lists for events or pantry intake forms).
  • Volunteer background-check results.
  • Immigration status or other sensitive personal circumstances (common for mutual aid and legal-help groups).

The FTC guide's next principle is to scale down: keep only what you need. That applies to AI too. If information doesn't need to go into a tool, it shouldn't.

Who is responsible?

Pick one person, or a role like "secretary" or "board chair," who answers AI questions. In a small group this is often whoever already manages the shared drive or email list.

The four rules that matter most

If your policy said nothing else, these four would cover most of the risk for a small group.

1. Don't put private information about people into AI tools

This is the big one. Member lists, donor records, intake forms, children's names, health details, addresses, and phone numbers shouldn't be pasted into a public AI chat tool.

Why: when you paste text into a cloud service, it goes to that company's servers, under that company's terms and your account settings. You don't control what happens next the way you control your own spreadsheet. Your members and donors gave you their information for a reason, and that reason probably wasn't "so a volunteer could ask a chatbot to sort it."

2. A human checks everything before it goes out

AI tools can produce confident, fluent text that's wrong. Before anything AI-assisted is published, sent to members, or submitted to a funder, a person reads it and checks:

  • Facts, dates, times, and places.
  • Names and titles (spelled right, correct person).
  • Numbers (attendance, money raised, budget figures).
  • Tone (does it sound like us?).
  • Promises (did the AI commit us to something we can't do?).

3. Be honest about AI use where it matters

You don't need a disclaimer on every flyer. But be honest where people would reasonably expect a human wrote it or where trust is on the line:

  • Grant applications: follow the funder's rules. Some funders ask about AI use.
  • Personal messages: a condolence note or a thank-you to a long-time donor should be in your own words, even if you used a tool to help with a first draft.
  • Images: if you use an AI-generated image in place of a real photo of your event, don't present it as a real photo.

4. No AI decisions about people

AI shouldn't decide who gets membership, who receives help from a pantry, which volunteer gets a role, or which applicant gets a scholarship. People make those decisions.

The rest of the page

Beyond the big four, a good one-page policy covers a few more things briefly.

Approved uses

List the kinds of things AI is welcome for. This gives cautious volunteers permission and makes the policy feel friendly. For example:

  • Drafting and editing newsletters, posts, and flyers.
  • Brainstorming event ideas and agendas.
  • Summarizing public documents or your own non-sensitive notes.
  • Rewriting text for clarity or a different reading level.
  • First-draft translations of public announcements, checked by a speaker of the language when possible.
  • Help with spreadsheet formulas using sample data.

Accounts and tools

Small groups usually don't buy software for this, and they don't need to. Free tools are fine for most of the jobs above. Your policy can simply say:

  • Volunteers may use free AI tools for approved uses.
  • Use your own account, not a shared one, unless the board sets up an organization account.
  • Don't sign the group up for paid AI services without board approval.
  • Don't connect AI tools to the group's email, drive, or member database without approval. Some tools ask for broad access to accounts; that's a decision for the board, not an individual.

If your group wants extra privacy, a volunteer with some technical comfort can run a free local model on their own computer (for example, with Ollama), so text doesn't leave the machine. That's optional, not required.

Images, logos, and other people's work

  • Don't upload photos of members, especially children, to AI image tools without permission.
  • Don't use AI to create images that imitate a real person.
  • Be careful about generating things "in the style of" a specific living artist for your materials.

Children and youth

If your group works with kids (a PTA, scouts, youth sports, a junior beekeepers program), be stricter:

  • No children's names, photos, or details in AI tools.

When something goes wrong

Mistakes will happen. Someone will paste the wrong file. A newsletter will go out with an AI-invented fact. Your policy should make reporting easy and shame-free:

  • Tell the policy contact right away.
  • Don't try to hide it.
  • The group fixes it, corrects the record if needed, and learns from it.

The FTC's guide recommends having a plan to respond to security incidents and, for breaches, notes that many states have laws about data breaches and advises consulting an attorney.

Review date

Put a date on the policy and plan to review it once a year. AI tools change quickly. A policy that says "reviewed March 2027" is more trustworthy than one nobody has looked at in three years.

Sample one-page AI policy

Copy this, adapt it, and delete what doesn't fit. Replace anything in [brackets].


[Group Name] AI Use Policy Adopted [date] by [board / steering committee]. Next review: [date one year later]. Questions go to: [name or role, contact].

Why we have this. AI tools can save our volunteers time. We want to use them in ways that protect the people who trust us with their information and keep our communications honest.

You're welcome to use AI tools for:

  • Drafting and editing newsletters, social posts, flyers, and agendas.
  • Brainstorming ideas.
  • Summarizing public information or non-sensitive notes.
  • Making writing clearer or easier to read.
  • First drafts of translations for public announcements (checked by a speaker of the language when we can).
  • Spreadsheet and formula help, using made-up example data.

Never put these into an AI tool:

  • Member, donor, client, or volunteer personal information: names with contact details, addresses, giving history, payment or bank information.
  • Information about children or youth, including names and photos.
  • Health, disability, immigration, or other sensitive personal details.
  • Passwords, account logins, or financial account numbers.
  • Confidential board matters or anything we've promised to keep private.

Always:

  • Have a person check AI-assisted work before it's published, sent, or submitted. Check facts, names, dates, numbers, and tone.
  • Follow funder rules about AI in grant applications, and answer honestly if asked.
  • Write personal messages (condolences, personal thanks) in your own words.
  • Label AI-generated images if they could be mistaken for real photos of our people or events.

AI doesn't make decisions about people. Membership, services, volunteer roles, awards, and hiring are decided by people.

Tools and accounts. Free tools are fine for the uses above. Don't sign up for paid AI services or connect AI tools to our email, shared drive, or member lists without [board] approval.

If something goes wrong, like personal information pasted into a tool, or a mistake published, tell [contact] right away. No blame. We'll fix it together.

This isn't legal advice. If our work involves legal, health, financial, or children's privacy rules, those rules come first.


That's it. One page. You can print it, pin it, or paste it into your volunteer handbook.

How to adopt it without a fight

Policies go down easier when people helped write them.

Bring a draft, not a blank page

Starting from scratch in a meeting leads to an hour of debate. Bring the template above, already adapted, and ask, "What's missing? What's wrong for us?"

Listen to both camps

You'll usually have enthusiasts and skeptics. Both have a point. Enthusiasts are right that AI can save a stretched volunteer hours. Skeptics are right that it can get things wrong and that privacy matters. A good policy gives the enthusiasts permission and the skeptics guardrails.

Keep the "never" list short and clear

People remember short lists. If your "never" list grows to twenty items, nobody will remember any of them. The privacy items above are the ones that matter most.

Vote, date it, share it

Adopt it formally, even if your "board" is five people around a kitchen table. Put the date on it. Share it everywhere volunteers look.

Teach it once

Spend ten minutes at a volunteer meeting walking through it. Show one example of a good use (drafting a flyer) and one example of what not to do (pasting the member spreadsheet). Then move on.

Special notes for common types of groups

Beekeeping and garden clubs

Your biggest risks are usually member contact lists and occasionally swarm-call lists with people's home addresses. Keep those out of AI tools. AI is genuinely handy for drafting meeting announcements, simplifying technical material for beginners (always fact-checked by an experienced member), and brainstorming workshop ideas. Be careful with AI-generated advice about bee health, treatments, or pesticides; check it against your local extension service or experienced mentors before sharing it with members.

Food pantries and mutual aid groups

You may hold very sensitive information: household size, income, immigration circumstances, health and dietary needs. Your "never" list should be strict, and intake data should never go into a public AI tool.

PTAs and youth groups

Children's information is the bright line. Many schools and national youth organizations already have technology or privacy rules, and your policy should defer to them. AI can help draft newsletters to parents and plan fundraisers, without kids' names or photos.

Small registered nonprofits with donors

Donor trust is your foundation. Your donor privacy statement, if you have one, is a promise, and your AI policy needs to keep it. Fundraising platforms and donor databases may also have their own terms.

If you want to go deeper

You don't need a framework to write a one-page policy. But if your group grows, or a board member wants something more formal, the U.S. National Institute of Standards and Technology publishes the AI Risk Management Framework. NIST describes it as intended for voluntary use, to help organizations manage risks associated with AI. NIST also published a Generative AI Profile (NIST-AI-600-1) in July 2024 to help organizations identify risks unique to generative AI. NIST's page notes the AI RMF 1.0 is being revised. These are written for organizations of all kinds and are much more than a small club needs, but they're free and a good reference if your group takes on bigger AI work.

The FTC's Protecting Personal Information: A Guide for Business isn't about AI, but its five principles (take stock, scale down, lock it, pitch it, plan ahead) map neatly onto how a small group should think about putting information into any outside tool.

Common questions

"Do we really need an AI policy? We're just a garden club." If nobody in your group uses AI and nobody holds personal data, maybe not yet. But if you have a member list and at least one person who uses AI to draft emails, a one-page policy is cheap insurance and saves future arguments.

"Can volunteers use free ChatGPT or other free AI tools for our work?" For approved uses like drafting and brainstorming, with no personal information pasted in and a human check before anything goes out, most small groups decide yes. Your board makes that call. Free tools are fine; nothing in this policy requires paying for anything.

"What about grant applications?" Follow each funder's rules. If a funder asks whether AI was used, answer honestly. Make sure every fact, number, and outcome in the application is true and checked by a person who knows your program.

"Should we disclose AI use in our newsletter?" That's a values choice for your group. Many groups don't label routine drafting help but do label AI-generated images. Some prefer a simple line like "We sometimes use AI tools to help draft; a volunteer reviews everything." Either is reasonable if it's honest.

"Someone already pasted our member list into an AI tool. What now?" Don't panic and don't blame. Note what was shared, which tool, and when. Check the tool's settings for deleting chat history. Talk to your board about whether members should be told. If the data was sensitive, consider getting advice, since notification rules can vary.

"Can we use AI to translate announcements for members?" Yes, for public announcements, and have a speaker of the language check it when you can. Don't put members' private details into translation tools.

"Who should own the policy?" Whoever already handles your group's records and communications is often a good fit: the secretary, communications chair, or director. What matters is that volunteers know who to ask.

Bottom line

A small group doesn't need a thick AI rulebook. It needs one honest page: here's what's welcome, here's what never goes into a tool, a human checks everything, people decide about people, and here's who to ask. Write it with your members, date it, and review it once a year. That's enough to protect the people who trust you, and to let your volunteers use helpful tools without guilt or guesswork.

References

  • Federal Trade Commission, Protecting Personal Information: A Guide for Business. https://www.ftc.gov/business-guidance/resources/protecting-personal-information-guide-business (fetched 2026-10-01)
  • NIST, AI Risk Management Framework overview page. https://www.nist.gov/itl/ai-risk-management-framework (fetched 2026-10-01)
  • Ollama. https://ollama.com
Frequently asked
What is How to Write an AI Policy for a Small Club or Nonprofit in One Page about?
This is for small groups run mostly by volunteers or a tiny staff:
What should you know about who this is for?
This is for small groups run mostly by volunteers or a tiny staff:
What should you know about why one page?
A long policy nobody reads protects nobody. A small group's AI policy should do three things:
What should you know about before you write: a 20-minute inventory?
You can't write a sensible rule about something you haven't looked at. Spend twenty minutes at a board meeting or in a shared doc answering these:
What are people already using AI for?
Ask without judgment. You'll probably hear things like:
References & sources
  1. Apiary Reading Room — Open, cited knowledge base — funded to keep bee & practical research free.
From the Apiary Reading Room. Opinion & editorial — not financial advice. We don't overclaim.
More from the Reading Room