Navigating the Maize
A weekly, 15-minute podcast on nonprofits and AI — real workflows, no hype, hosted by a 30-year nonprofit development veteran.
Navigating the Maize
Why Your Nonprofit Needs an AI Governance Policy (Even a One-Pager)
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Back in episode two, Sean cited a stat and moved past it fast: 47% of nonprofits have no AI governance policy at all. This episode unpacks why that’s riskier than it feels, not one dramatic AI failure, but a slow buildup of small, ungoverned decisions made by well-meaning staff with no guidance.
Sean breaks down exactly what belongs in a real policy, and makes the case it can fit on one page: what data can and can’t go into an AI tool, what needs human review before it goes out, which tools are actually approved, transparency with donors and candidates, and clear ownership for keeping it updated. The episode closes with a practical path to actually getting this written this month, without it stalling into a six-month committee project.
Sean is the founder of Magnolia Philanthropic Services, advising nonprofits nationwide on development strategy, with 25+ years in the field.
Back in episode 2, I mentioned a number and moved past it pretty quickly. 47% of nonprofits have no AI governance policy at all. No guidance on what data can go into a tool, no standard for how outputs get checked, nothing written down anywhere. I'm going to spend this whole episode on that one number because I think we'll figure it out as we go is a much riskier plan than it sounds like in the moment. Today, what a real AI governance policy actually needs to cover and why it doesn't have to be a 20-page document to be worth having. This is navigating the maze. Let's talk about the boring thing that actually protects you. Here's why I think this number matters more than almost anything else in that report. When there's no policy, AI use in your organization isn't actually absent. It's just invisible and inconsistent. Someone on your team is already pasting donor information into a free AI tool to draft a thank you letter faster. Someone else is using a different tool to summarize board minutes. Neither of them is doing anything malicious, but neither of them has ever been told what's off limits, and neither of them knows if the other person is doing something completely different with the same category of sensitive information. Now that's the actual risk. Not one dramatic AI mistake, but a slow accumulation of small, ungoverned decisions, each made by a well-meaning person with no guidance. That eventually adds up to a real problem: a donor's financial information ending up somewhere that it shouldn't. A grant report with a fabricated statistic that nobody caught. Or a hiring decision is quietly shaped by a tool that nobody vetted. A governance policy isn't about distrust of your staff. It's about giving well-meaning people a clear, consistent answer to a question they're already facing. Whether or not you've written anything down. I want to walk through what a what I think a real usable policy needs to cover. And I mean this literally. This can fit on one page. It doesn't need a task force or six months of drafting. So first, what data can and can't go into an AI tool? This is the single most important line item, and the one that I think most organizations get wrong by never addressing it at all. Be specific. Donor financial details, social security numbers, health information, anything from HR files. These should never go into a general-purpose AI tool without your organization explicitly vetting that specific tools, data handling first. Staff need a clear, simple answer, not a judgment call they're making alone in the moment. Second, what needs human review before it goes out the door? Anything that AI drafts that will reach a donor, a funder, or a board member or the public, an email, a grant report, a social post, needs a human read-through before it's sent. Not because the AI is untrustworthy, but because AI can produce confident sounding errors and the person that's hitting send is accountable for what goes out, not the tool. Third, which tools are actually approved and who decides? This does not need to be complicated. It can be as simple as our organization uses these two tools for these purposes. If you want to use something else, go and ask so-and-so first. That single line prevents the scenario where five staff members are using five different tools with five different data handling practices, none of which anyone at the organization ever actually reviewed. Fourth, transparency with the people your AI use touches. If AI is helping screen job applicants, donors deserve to know their data might be processed by AI-assisted tools, and candidates deserve to know AI played a role in how their application was handled. This connects directly to what I talked about in the hiring episode. The actual guidance is simple. If it touches a real person's information or opportunities, tell them. So that's it. Five items, one page, and it's genuinely more protective than most organizations currently have, which is nothing at all. If you're listening to this and you know that your organization is in that 47%, here's how I'd actually get this done without it becoming a stalled six-month project. Don't wait for a committee. Draft the five items above yourself in an afternoon based on what you already know about how your team is actually using these tools right now. Not some ideal future state, but the actual current reality. Bring it over to your ED, your CEO, or your board chair as a draft, not a proposal for a project. Here's a one-page policy. I'd like 10 minutes of feedback. Can move faster than I think we need to form a task force on AI governance. And don't aim for perfect. A genuinely imperfect one-page policy that exists and gets revisited in six months is infinitely more useful than a comprehensive policy that never gets written because it felt too big to start. That's the number from episode two, finally unpacked. 47% of nonprofits with no policy at all, and a genuinely simple path to not being one of them. Five items, one page, an afternoon of work. If you write one of these this month, I'd like to hear how the conversation went with your board. What pushback you got, and maybe what surprised you? I'm Sean. This has been Navigating the Maze. See you next week.