Employees are already experimenting with generative AI. They may use it to summarize meetings, draft donor emails, rewrite grant language, analyze spreadsheets or prepare participant communications.
Without clear rules, each employee decides independently what information is safe to enter, which tools are acceptable and whether AI-generated material needs review. That creates inconsistent practices and unnecessary exposure of confidential information.
A nonprofit AI use policy establishes boundaries before informal habits become standard operating procedure. It also helps the organization retain institutional knowledge about approved tools, review requirements and responsible uses of AI.
What an AI Policy Should Address
The policy does not need to prohibit AI or anticipate every possible tool. It should give employees a practical framework for deciding what they may do.
At minimum, it should define:
- Which AI tools are approved
- What information employees may enter
- What information must never be entered
- When human review is required
- How AI-generated content should be verified
- Who approves new AI uses
- How suspected errors or data exposure should be reported
- Whether AI-generated work must be disclosed
- Which decisions must remain entirely human
The NIST AI Risk Management Framework provides a voluntary structure for identifying and managing AI risks. Its generative AI guidance addresses concerns such as inaccurate output, privacy, security, bias and unreliable information. (NIST)
Microsoft’s responsible AI policy guidance recommends defining governance responsibilities, standard operating procedures and review processes rather than treating responsible AI as a one-time technical task. (Microsoft Learn)
Separate General Work From Restricted Information
Employees may be permitted to use approved AI tools for brainstorming, editing public material or creating first drafts. They should not paste confidential participant records, donor details, employee files, passwords, legal advice or unpublished financial information into unapproved systems.
The case-management system remains authoritative for participant records. The CRM remains authoritative for donor information. HR, payroll, accounting and grant-management platforms remain authoritative for their respective records.
An AI tool may help explain a procedure, but it should not make eligibility decisions, provide legal conclusions, approve disciplinary action or replace professional judgment.
Put the Policy Where Employees Can Use It
A policy hidden in an employee handbook will not control daily behavior. SharePoint should contain the approved policy, examples, prohibited uses, review procedures and instructions for reporting problems.
Copilot Studio can provide the conversational layer. Through Maisy, employees could ask:
- May I paste this document into an AI tool?
- Which tools are approved?
- Does this draft require manager review?
- Can AI summarize participant information?
- Who approves a new AI use case?
Maisy should return approved guidance based on the employee’s Microsoft 365 permissions. It should not independently authorize a use that the policy does not cover.
The NTIA AI Accountability Policy Report also emphasizes governance, transparency, assessments and recognized risk-management practices. (NTIA)
How Maisy Helps
Pixeldust begins by identifying how employees currently use AI, what information they handle and where unclear practices already exist. The discovery process includes locating authoritative policies, reviewing permissions, assigning policy owners and defining realistic review procedures.
Pixeldust then organizes approved guidance in SharePoint, configures Maisy through Copilot Studio and tests the questions employees are likely to ask. This allows the nonprofit to retain institutional knowledge about responsible AI use while keeping accountability with leadership, security professionals and human decision-makers.





