Most nonprofits are already using AI. Almost none of them wrote the rules.

An oversized open book with completely blank pages stands on a stone pedestal at the center of a nonprofit office, while four staff members work at laptops around it, each screen glowing a different color and trailing light out of the frame.
// JOURNAL · OPERATE / YEAR 10 SD

Most nonprofits are already using AI. Almost none of them wrote the rules.

TechSoup and Tapp Network surveyed about a thousand nonprofits last year. Three quarters of them are using AI in some form. Eighty percent have no acceptable use policy. Seventy-six percent have no AI strategy at all.

Read those two sentences again in order, because the sequence is the whole story. The tools showed up first. The rules never showed up.

There is a version of this conversation happening all over the sector right now, and it is mostly about tone. Will AI make our appeals sound robotic. Will donors be able to tell. Will we lose the human touch. Those are fair questions and they are also the comfortable ones, because they are questions about writing, and everyone at a nonprofit has an opinion about writing.

The uncomfortable question is quieter. Right now, today, somebody on your staff is pasting something into a chatbot. Do you know who, and do you know what they pasted?

// THE GAP

What the gap actually looks like

The same survey found that 42% of nonprofits have exactly one or two people exploring AI. Only 3% have brought in outside help to make the decisions. Half of these organizations run on annual budgets under $500,000.

Put that together and you get a specific picture. AI at a small nonprofit is not a program. It is a personal habit that two or three people picked up on their own, unevenly, with no shared standard, using whatever free tier they signed up for on a Tuesday. The development director has one workflow. The comms person has a completely different one. Nobody has compared notes. Nobody has asked whether the donor list that got pasted into a summarizer is now sitting on a server nobody at the org can name.

That is not a human touch problem. That is a governance problem wearing the costume of an efficiency win.

And it is not solved by banning anything. The staff using these tools are not being reckless, they are being resourceful, usually because they are three people doing the work of six. Take the tools away and you get the same behavior with worse hiding. The answer is not less AI. It is somebody owning the map.

// ORDER OF OPERATIONS

Write the policy second, not first

Here is where I disagree with most of the advice on this topic. The standard recommendation is to write an AI use policy, then adopt carefully. I think that is backwards for an organization your size, and I think it is why so many of these policies never get written.

A policy written before you have used anything is a guess. It will be either so vague it does nothing or so strict it gets ignored by week three. Meanwhile the work of drafting it falls on whoever is least busy, which at a nonprofit is nobody.

Do it in this order instead:

  • Pick one recurring, boring, low-stakes task. Meeting notes into summaries. Event photos into caption drafts. Last quarter’s donor spreadsheet standardized into something you can actually sort. Something where a human reads the output before anyone outside the building sees it.
  • Automate that one thing and run it for a month. Not a pilot program. One task, one person, four weeks.
  • Then write the page. By now you know which tool you actually use, what data touched it, where it was wrong, and who caught the error. The policy writes itself out of that experience, and it fits on one page, because it is describing something real.

One page is genuinely enough at your scale. Which tools are approved. What data never gets pasted anywhere, and for most nonprofits that list starts with donor records, beneficiary information, and anything a board member said in a closed session. Who reviews output before it goes to a donor. Where you say out loud that AI helped. Sign it, date it, revisit in six months.

// THE LINE

The line worth defending

The advice to automate the mundane and protect the meaningful is right, it is just soft on where the line sits. Here is a sharper test.

Automate anything where a human reads the output before it leaves the building. Never automate anything where a donor would feel deceived if they found out. A first draft of an appeal is fine, because you edited it and you signed it. A quote you attribute to a beneficiary is not, ever, under any circumstance, because that is not a writing shortcut, that is putting words in someone’s mouth. Same with impact numbers. Same with a thank-you that reads like it came from a person who remembered something specific about that donor when nobody did.

The touch you are protecting is not the prose. It is the truth of the claim.

// WHERE I FIT

Where I fit

I run the operations side of this for small organizations in California. Finding which three workflows are eating the hours, building the one with the cleanest inputs, training somebody internal to own it, and writing the short version of the rules from what we learned doing it.

One example. The Apartment Association of Greater Los Angeles is a trade association representing rental housing providers, and it was moving its rental forms library off fillable PDFs onto a real forms platform. They wanted to know whether members were actually making the switch. So we built a dashboard that reads their live membership data alongside the weekly platform usage reports and shows who has moved and who has not. Their leadership team uses it to steer the rest of the rollout. Nothing about it is exotic. It reads data they already had and puts it somewhere a person can act on it.

For an organization with no idea what its current AI surface even looks like, the entry point is an AI Stack Audit. Every tool you pay for and what to cut, where the manual hours actually go, a ranked list of what to automate first, and a one-page answer to the question your board is going to ask about donor data. It runs about a week and it usually pays for itself out of software you did not know you were still subscribed to.

Details on the AI Architect page. Or the contact page if you would rather just describe the mess and see what I say.

Figures from The State of AI in Nonprofits 2025, TechSoup and Tapp Network, surveying roughly 1,000 nonprofit professionals.