Create your organization's AI policy

A section-by-section worksheet for writing an AI policy your staff will use, with starter questions for each section and a skeleton outline you can copy.

Guide Policy & governance Updated July 20, 2026

Why write a policy at all

Most organizations we talk with are already using AI tools. Staff are likely drafting emails, summarizing meetings, and researching topics with whatever tool they found first. The policy’s job is to write down what people otherwise have to guess: which tools are okay to use, what data can go into them, and when a human has to check the output.

Keep the policy short, specific, and easy to revisit. Two pages are usually enough.

This worksheet covers seven sections and gives your team starter questions for each one. Write rough answers now and improve them later.

Several animal advocacy organizations publish their full policies. Compare three examples: values-led (Stray Dog Institute), tool-by-tool (Faunalytics), and operational (Animal Charity Evaluators). Reading them before your team conversation will sharpen the answers below.

1. Purpose and values fit

Staff will read the first paragraph and skim the rest. Say, in plain language, why your organization is engaging with AI and what it will never use AI for. Connect the policy to your mission: using technology carefully in service of the animals.

Starter questions:

  • What do we hope AI helps us do more of (research, supporter communication, operations)?
  • What uses are off the table regardless of efficiency (for example, fully automated public statements, or fabricated imagery presented as real)?
  • What do we promise staff about where AI gains go? (ACE commits those gains to increased output for the mission while protecting staff roles. Saying this early addresses the most personal concern in the room.)
  • How does our approach to AI reflect the same care we ask of others in how they treat animals?

2. Approved tools and accounts

“Use AI responsibly” means little unless staff know which tools and account types are approved. Name them directly, including whether personal accounts may be used for work.

Starter questions:

  • Which two or three tools do we approve today, and on what account tier?
  • Who can approve a new tool, and how does someone request one?
  • Are personal free-tier accounts allowed for work tasks? (Our suggested default: no, because data terms differ.)
  • Do connectors, extensions, and AI note-takers follow the same approval path as tools? (They can reach far more data than a paste — see the connectors section of our data-security guide. ACE’s default is a good one: not allowed until approved, and note-takers require participant consent.)

3. Data rules by sensitivity tier

For most small organizations, the likeliest risk is mundane: someone pastes a donor list or a whistleblower’s identity into a consumer chatbot. Tiered data rules give staff a simple decision path. See Data security and privacy basics for a full walkthrough.

Starter questions:

  • What counts as public, internal, confidential, and regulated-or-personal data at our organization?
  • Which tiers may be pasted into approved tools, and under what account settings?
  • What do we do if someone realizes they pasted something they should not have?

4. Human review requirements

AI gives you a draft; a person still makes the decision. Name where review is required and who does it, especially for public, legal, financial, personnel, and investigation work.

Starter questions:

  • Which outputs always require a human sign-off before they leave the building?
  • Who is accountable for an AI-assisted work product — the tool, or the staff member who used it? (It should always be the staff member.)
  • For factual claims in public materials, what is our verification standard?

5. Disclosure norms

Decide in advance when you will tell colleagues, supporters, and the public that AI was involved. Clear disclosure rules protect trust and keep staff from improvising under pressure.

Starter questions:

  • When do we disclose AI assistance externally (published reports, fundraising appeals, images)?
  • What is our line on photorealistic AI imagery? (Stray Dog Institute draws the clearest line, and it is worth adopting: where an image bears witness — documenting what animals endure — it must be real. Fabricated evidence erodes the trust that undercover investigators risked so much to build.)
  • What do we say internally when sharing AI-drafted work with colleagues?
  • Are there contexts where we avoid AI entirely because disclosure would undermine the work?

6. Experimentation guardrails

Staff need room to experiment before useful workflows emerge. Let them work freely with public and approved internal data, share what they learn, and ask before connecting AI to live systems or real audiences.

Starter questions:

  • What can anyone try without asking (drafting, summarizing, research on non-sensitive material)?
  • What requires a conversation first (automations that send email, tools that touch the donor database)?
  • Where do staff share experiments — a channel, a monthly demo, a shared doc?

7. Review cadence

Tools and terms change quickly. Put the policy’s next review date on the calendar; quarterly is a reasonable rhythm for the first year.

Starter questions:

  • Who owns this document, and when is the next review scheduled?
  • What would trigger an out-of-cycle review (a new tool, an incident, a vendor terms change)?
  • How do we collect staff feedback on what is unclear or unworkable?

Skeleton policy outline

Copy this outline into a document and fill in each section with your team’s answers. Most organizations can produce a workable first draft in a single 90-minute meeting.

  • Purpose — why we use AI, what we will not use it for, values fit (2-4 sentences)
  • Approved tools — named tools, account types, how to request additions
  • Data rules — the four tiers, what may go into AI tools per tier
  • Human review — what always needs sign-off, who is accountable
  • Disclosure — when and how we say AI was involved
  • Experimentation — what is open, what needs a conversation first, where we share learnings
  • Review — owner, cadence, next review date

A first-draft checklist:

  • Fits on two pages or fewer
  • Names specific tools and account types
  • Data tiers defined with org-specific examples
  • Review requirements name a role, not just “someone”
  • A review date is on the calendar

Prefer to start from a draft? Our AI policy builder walks you through these questions and produces a starter document. The outline and a candid team conversation will also get you there.

The AI Policy Builder: a form asking about organization type, tools in use, data sensitivity, and review posture

The policy builder turns the seven sections above into a five-question form and generates a starter draft you can copy into a doc. Click the screenshot to try it.

Keep going

Related Resources

Want help putting this to work?

Vegan Hacktivists offers free AI and automation support to animal protection organizations — from a first conversation to a full build.

A beaver carrying a branch through the water