30 Days Gen AI Risk Trial -Start Now
Skip to main content
Australian NFP AI policy template

Set clear AI rules. Make them workable.

A not-for-profit AI policy should tell staff, volunteers and contractors which tools and uses are approved, what donor or beneficiary information must never enter an unapproved AI service, when human review is mandatory, how incidents are reported, and who owns each decision. This copy-ready template gives Australian charities that minimum operating baseline.

Practical NFP resource
Reviewed
1Inventory real use
2Set rules by use case
3Brief the whole workforce

For Australian organisations

For Australian charity executives, boards, privacy leads, IT teams and program managers adapting a policy to their own services and risk appetite.

Reviewed: 14 August 2026Australian context | General guidance, not legal advice

What the key terms mean

Not-for-profit (NFP)

An organisation that applies its income and assets to its purpose rather than distributing profit to members. Charity is a distinct legal status, although many charities are NFPs.

Approved AI tool

A named product and account tier that the organisation has assessed for a defined use, data class, owner and review date.

Personal information

Information or an opinion about an identified individual, or an individual who is reasonably identifiable, using the Privacy Act definition.

Law and recommended practice

Legal position: the Privacy Act 1988 and Australian Privacy Principles apply where your organisation is an APP entity and handles personal information. Recommended practice: the policy controls below are a practical baseline, not legal advice, and should be adapted to your charity's obligations, contracts, services and governing document.

A practical implementation workflow

Use this sequence to turn the resource into an owned, reviewable process rather than a document that sits on a shared drive.

1

Inventory real use

Ask teams what they use, then validate that list across managed devices and browser-based AI services. Include free accounts, embedded assistants and volunteer workflows.

Output: tool, owner, account tier, purpose and data classes

2

Set rules by use case

Approve a tool for a particular task, not for every task. Drafting a public event post is different from summarising a beneficiary case note.

Output: approved, conditional and prohibited use list

3

Brief the whole workforce

Give staff, contractors and volunteers short examples, an approval channel and a no-blame route for reporting accidental disclosure.

Output: briefing, acknowledgement and escalation contact

4

Review evidence

Review new tools, exceptions, incidents and high-impact use cases on a regular schedule and report material changes to the board.

Output: decision log, exceptions and next review date

Copy-ready not-for-profit AI policy clauses

Replace bracketed text, remove clauses that do not fit, and obtain appropriate privacy or legal review before approval. Keep the approved-tools list as a controlled appendix so it can change without rewriting the full policy.

1. Purpose, scope and ownership

[Organisation] permits responsible AI use where it supports our charitable purpose and meets our legal, ethical, privacy, security and contractual obligations. This policy applies to employees, contractors, volunteers and Responsible People. [Role] owns the policy and [Board/Committee] approves material changes.

  • Name one accountable executive and one operational contact.
  • Cover standalone tools and AI features embedded in existing software.
  • Record the policy version, approval date and next review date.

2. Approved tools and permitted uses

Only tools listed in the approved-tools appendix may be used for organisational work. Each approval must state the account tier, owner, permitted purposes, allowed data classes, required human review and expiry or review date.

  • Allow low-risk drafting from public or synthetic information.
  • Require separate approval for integrations, file uploads and meeting bots.
  • Do not treat a personal paid account as organisational approval.

3. Donor, beneficiary and workforce information

Do not enter personal information, sensitive information, case notes, donor records, credentials or confidential material into a public or unapproved AI tool. Use de-identified or synthetic information only where re-identification is not reasonably possible and the use is approved.

  • Names removed from a detailed case story may still leave a person identifiable.
  • Treat health, disability, cultural and safeguarding information as high sensitivity.
  • Check both prompts and uploaded files before sending.

4. Human review and prohibited uses

A suitably qualified person must verify AI output before it is used. AI must not make or recommend a final decision about eligibility, service access, safeguarding, employment, grants or complaints without documented human authority and an approved assessment.

  • Verify facts, citations, tone, bias and accessibility.
  • Do not fabricate beneficiary stories, quotes, consent or impact evidence.
  • Provide a way for affected people to question consequential outcomes.

5. Incidents, records and review

Suspected disclosure, harmful output or unauthorised AI use must be reported promptly to [contact]. Preserve the prompt, output, tool, account, time and actions taken. [Owner] will assess privacy, safeguarding, contractual and notification obligations and review this policy at least annually and after material change.

  • Make internal reporting simple and time-sensitive.
  • Do not promise that every AI incident is a notifiable data breach.
  • Link policy reviews to the AI inventory and risk register.

Example rules teams can apply

These examples are policy choices, not universal legal conclusions. Adjust them after assessing your tools and services.

Use caseDefault positionMinimum condition
Draft a public fundraising headlineAllowed in an approved toolUse public facts and human review
Summarise a beneficiary case noteProhibited by defaultUse only an assessed workflow with necessary authority and controls
Screen grant applicantsHigh-risk approval requiredDocument purpose, fairness, human decision authority and review
Upload a volunteer contact listProhibited in public AIUse an approved service only where privacy requirements are met

Move from policy text to enforceable practice

Aona is relevant after the policy is approved: it can help organisations discover workforce AI use, guide people towards approved tools, apply data controls and retain evidence for governance review. A policy still needs accountable owners, training and case-by-case decisions.

Build an inventory of AI services used across the workforce.

Give in-context guidance when a tool or data use conflicts with policy.

Support data-loss prevention controls for prompts and files.

Provide usage evidence for operational and board review.

See how the Aona platform works
Questions from NFP teams

Frequently asked questions

There is no general Australian law that says every NFP must adopt a document called an AI policy. A policy is recommended practice for translating existing privacy, governance, employment, security and contractual duties into clear workforce rules. The right level of detail depends on your size, services, data and AI use.
Put the guidance into practice

See and govern AI use across your workforce

Aona helps not-for-profits discover AI use, guide teams to approved tools, protect sensitive information and bring evidence into governance reviews.