Here's a safe assumption: someone in your organisation is already using AI. Drafting a grant application in ChatGPT, tidying up a newsletter, summarising a long report, writing a tricky email. It's happening whether or not you've said anything about it, which is exactly why it's worth saying something.

The goal isn't to ban AI. Used well, it's genuinely useful for small, stretched teams. The goal is to make sure your people use it without accidentally putting the organisation, or the people you serve, at risk. And charities have particular reasons to be careful, because you hold information people trust you with, often about vulnerable people, and that trust is the thing you can least afford to lose.

Good news: most of it comes down to one simple rule.

The one rule that covers most of it

Never put anything into a public AI tool that you wouldn't be comfortable posting on your website.

Free, public AI tools may use what you type to improve their systems. So treat the chat box like a public place. If you wouldn't publish it, don't paste it in. That single habit prevents most of the trouble.

Everything below is really just that rule, spelled out.

1. Protect the people you serve

This is the big one for charities. Never put personal or sensitive information about beneficiaries, clients, donors or staff into a public AI tool: names, contact details, case notes, health information, financial details, anything about someone's circumstances.

If you want AI's help with something involving real people, take the details out first. "Draft a supportive email to a client who's missed two appointments" works perfectly well without the client's name or story attached.

Sensitive information, health, and details about vulnerable people especially, deserves extra care, and in many cases you have legal obligations to protect it. When in doubt, leave it out.

2. Always keep a human in charge

AI sounds confident even when it's wrong. It will happily invent a statistic, a legal fact, or a funding rule that doesn't exist. That's fine when you're brainstorming a newsletter headline; it's dangerous when the output goes into a grant application, advice to a beneficiary, or anything involving money, law, health or safety.

Treat AI as a fast, tireless assistant, never the final word. A person should read, check and take responsibility for anything that leaves the organisation.

3. Don't let it make decisions about people

Be especially careful using AI to decide, or heavily influence, who gets help, who's prioritised, or how someone is treated. AI can carry hidden biases, and decisions about vulnerable people carry a duty of care that shouldn't be handed to a chatbot. Use it to draft and inform; keep the judgement human.

4. Be open about using it

Honesty protects your reputation. Don't use AI in ways that would embarrass you if a supporter found out, like passing off an AI-written personal thank-you as heartfelt, or generating "real" stories or images of the people you help. If AI helped with something public-facing and disclosure would matter to your audience, be upfront.

5. Agree on which tools, and keep accounts secure

Pick a short list of AI tools your organisation is happy for people to use, rather than everyone signing up to whatever they find. Secure those accounts like any other important login: strong, unique passwords and multi-factor authentication. And check the settings: paid or business versions often let you turn off using your data for training, which is worth doing.

6. Mind what you upload

Don't feed AI tools confidential documents from partners or funders, or copyrighted material that isn't yours to share. And know that the ownership of AI-generated content is still a grey area, so don't rely on it for anything where clear ownership matters, like a logo or signature campaign asset.

7. Put someone in charge of it

Name one person as the point of contact for AI questions, not to police it, but so there's somewhere to take a "is it okay if I…?" A fifteen-minute team chat about these rules will do more than a fifty-page policy nobody reads.

Your starter policy, copy, adapt, share

Here's a plain-language starting point. Lift it, change what doesn't fit, and share it with your team.

[Organisation]'s AI Guidelines

  1. Golden rule: don't put anything into a public AI tool that you wouldn't be happy posting on our website.
  2. Never enter personal or sensitive information about our clients, beneficiaries, donors or staff. Remove real details first.
  3. AI is an assistant, not the decision-maker. A person checks and takes responsibility for anything that leaves the organisation.
  4. Don't use AI to decide who receives our services or how they're treated.
  5. Use only our approved tools: [list them]. Secure those accounts with strong passwords and multi-factor authentication.
  6. Don't upload confidential or copyrighted material that isn't ours to share.
  7. Be honest about AI use in anything public-facing where it would matter to our supporters.
  8. Questions? Ask [name]. There's no such thing as a silly one.

This is general guidance to get you started, not legal advice, and Australia's approach to regulating AI is still taking shape, so treat these as sensible good practice and keep an eye on developments that affect your obligations.

Want help turning this into a policy that fits your organisation, and works alongside your privacy and data-handling obligations? That's a conversation we have often.