Practical AI Readiness
AI Policy Minimum Viable: What to Decide Before Staff Starts Using Tools
You don't need a finished AI policy to give your team real guidance. You need four decisions. Here's what they are and why they matter first.

Most nonprofit leaders know they need an AI policy. They also know they do not have one yet. And in the gap between those two facts, staff are making their own calls: using tools that seemed fine, entering information that felt okay, improvising in ways that nobody planned for and nobody reviewed.
A finished AI policy is worth building. But it takes time, it needs legal review, and it requires decisions that your organization may not be ready to make all at once.
What you can do right now is make the four decisions that prevent the most common, and most serious, problems. That is the minimum viable AI policy. Not a document. Not a compliance exercise. Four clear calls that give your team actual guidance while you work toward something more formal.
The Four Decisions
This is the most important decision and the one most organizations skip because it feels hard to get exactly right. Don't wait until it's exactly right.
Start with the obvious categories: client records, donor information with personal details, staff personnel files, health information of any kind, legal documents, and anything your organization is contractually or legally obligated to protect.
The rule does not need to be complicated. It needs to be clear enough that a staff member knows, without asking, whether something crosses the line. If client intake forms are on the list, they're on the list. If donor names and giving history are on the list, they're on the list.
Write it down. Communicate it. That alone closes the gap that causes most of the problems.
Your staff aren't waiting for your policy to start using AI. They are using it now, or they will be soon. The question is whether they have any guidance about which tools are acceptable.
You do not need to evaluate every AI tool on the market. You need a short, current list of what is approved for organizational use, under what conditions, and what is not approved pending further review.
Approved does not mean forever. It means reviewed well enough to use now, with the understanding that terms change, features change, and the list will be updated.
Not approved does not mean never. It means not yet reviewed, or reviewed and found to have unresolved concerns.
Post the list somewhere staff can find it. Update it when something changes.
This is the decision that makes every other decision work.
If a staff member is unsure whether something is allowed, and there is no clear answer and no clear person to ask, they will either do nothing or make the call themselves. Neither of those is a policy.
Name a person. Give them the authority to answer questions and make judgment calls. Make sure staff know who that person is and how to reach them.
In most nonprofits, this is the executive director, the operations director, or whoever owns technology decisions. It does not need to be a new role. It needs to be a named responsibility.
Someone will eventually realize they shared something they shouldn't have. A tool will behave unexpectedly. A staff member will discover a feature nobody knew existed.
Before that happens, decide how incidents get reported and who handles it.
The reporting path does not need to be complicated. It needs to exist and it needs to be communicated before there's an incident, not after. Critically, staff need to know they can report an honest mistake without it becoming a disciplinary matter. A culture where people are afraid to report problems is a culture where problems stay hidden.
What These Four Decisions Do Not Replace
They do not replace a legal review. They do not replace a full AI policy. They do not cover every situation your organization will eventually face.
What they do is stop the worst outcomes from happening while you build toward something more complete. They give your staff real guidance today, and they give your leadership a documented record of the decisions that were made and when.
That is worth more than a perfect policy that is still six months away.
Next Step
Ready to Build the Full Structure?
The Nonprofit AI Readiness Toolkit walks you through the complete process: mapping sensitive information, documenting current AI use, evaluating vendor risk, formalizing your rules, and drafting your AI policy starting point.
If you made the four decisions above, you've already started. The toolkit helps you finish.
Lisa Montague is Partner and CEO at Coat Rack, a nonprofit technology consulting firm based in Cedar City, Utah.