Someone in your organisation is already using AI. A volunteer pasting a draft into ChatGPT, a fundraiser polishing an appeal, a coordinator summarising notes. The question isn't whether AI is in your charity — it's whether anyone has written down how it should be used. A one-page AI use policy is the smallest document that turns "people are just figuring it out" into "we have a shared rule everyone knows."
This guide explains why a short written policy matters, what it needs to contain, and gives you a ready-to-adapt one-page template. It's written for people who run organisations, not for lawyers — and it's built to be finished in an afternoon.
This article is general information, not legal advice. It does not constitute legal advice, and Vedomia does not provide legal services. For legal questions about your specific situation, speak to a qualified solicitor.
Why a written policy, and why now
Three reasons, in plain terms.
First, it's part of a duty you already have. Since 2 February 2025, Article 4 of the EU AI Act has required organisations that use AI to make sure the people operating it have a "sufficient" level of AI literacy — and to take deliberate measures, not just hope staff pick it up. A written policy is one of the clearest measures you can point to. It applies to employees, contractors and volunteers — anyone using AI on your behalf.
Second, it protects the people you serve. Most AI mistakes in a small organisation aren't dramatic — they're a service user's personal detail pasted into a public tool, or a confidently wrong AI answer sent out unchecked. A one-page rule that says "never enter service users' personal data" and "a human checks before it goes out" prevents most of them.
Third, it's the honest version of transparency. You can't tell the public or your funders that you use AI responsibly if you've never written down what "responsibly" means inside your own walls. The policy is where that definition lives.
A policy nobody can find isn't a policy. The goal is one page a new volunteer can read in three minutes and actually follow.
The seven things a good policy covers
Keep it short. Every section below can be two or three sentences. The value is in having an answer to each, written down and agreed.
1. Purpose and scope
One line on why the policy exists, and who it applies to — every staff member, volunteer and contractor using AI on the organisation's behalf. State plainly that AI is allowed, within these rules, so the policy reads as enabling, not banning.
2. Approved tools
List the AI tools people may use, and note that new tools need a quick check before adoption. An open-ended "use whatever you like" is how sensitive data ends up in random services.
3. What must never go in
The single most important line: no service users' personal or sensitive data, no confidential or safeguarding information, into a public AI tool — unless you've specifically cleared that the tool is safe and lawful for it. Spell out examples so it's concrete.
4. Human review before anything goes out
Nothing an AI produces reaches a service user, funder or the public without a person reading it and taking responsibility for it. The AI drafts; a human decides. This one rule carries most of the risk protection.
5. Being open about AI use
Say where you'll tell people AI was involved — in line with the AI Act's transparency direction. If AI writes to service users or makes content they see, they should be able to know. A short note in your public AI transparency statement is usually the place.
6. Data protection and accountability
Point to your GDPR obligations, and name a person — a role, not necessarily a named individual — who owns questions about AI use. Note that some new AI tools may need a Data Protection Impact Assessment before rollout.
7. Who to ask, and review
Where to go when unsure, and a review date. A policy written once and never revisited goes stale the moment you adopt a new tool. Put a "review at least yearly, and whenever tools change" line at the bottom.
The one-line test: could a volunteer who joined this morning read your policy and correctly answer "can I put this into ChatGPT?" If the honest answer is "there's nothing written for them to read", the template below is your afternoon.
A ready-to-adapt one-page template
Copy this, change the bracketed parts to fit your organisation, and keep it wherever your other policies live. It's deliberately plain — a real one-pager, not a legal document.
[Organisation name] — AI Use Policy
| Section | What it says |
|---|---|
| Purpose & scope | We use AI tools to work more effectively. This policy applies to everyone using AI on our behalf — staff, volunteers and contractors. AI is permitted within these rules. |
| Approved tools | Approved AI tools: [list, e.g. tool A for drafting, tool B in our CRM]. Before using a new AI tool for work, check with [role]. |
| Never enter | Never put into a public AI tool: service users' personal or sensitive data, safeguarding information, or anything confidential — unless [role] has confirmed the tool is safe and lawful for it. |
| Human review | A person always reviews AI output before it reaches a service user, funder or the public, and takes responsibility for it. AI drafts; a human decides. |
| Being open | We are honest about our use of AI. Where AI meaningfully shapes content people receive, we make that visible [e.g. in our AI transparency statement]. |
| Data & accountability | AI use follows our GDPR obligations. New tools that process personal data may require a DPIA first. Questions about AI use go to [role]. |
| Questions & review | Unsure? Ask [role / contact]. This policy is reviewed at least once a year, and whenever we adopt or change an AI tool. Version [x], dated [date]. |
Keep a simple record of who has read it and when — that record is part of showing your Article 4 literacy measures are real.
How to roll it out without it gathering dust
- Walk your team through it once — a 20-minute session, using your own tools as examples, beats emailing a PDF nobody opens.
- Add it to onboarding so every new person and volunteer meets it on day one.
- Log who's seen it. A single spreadsheet row per person — date, name — is enough, and it's exactly the evidence Article 4 expects you to keep.
- Revisit on every new tool. The moment you adopt a new AI system, the policy gets a quick look. That habit keeps it alive.
How Vedomia can help
Vedomia is an Irish company focused on one thing: helping organisations make their processes and their use of AI visible, explainable and auditable. We work mainly with charities, nonprofits and publicly funded organisations.
A good AI use policy rests on knowing where AI actually lives in your organisation — which is exactly the map most charities are missing. That's where we start.
- Transparency Self-Audit (free). Around 20 questions across four pillars — Visibility, Sequence, Justification, Auditability. It surfaces where AI is used, who touches it, and where your review and evidence are thin — the raw material your policy needs.
- Mapped with you (€1,450, one-off). A single 90-minute session: you describe how one key process really runs, Sandra maps it live, and you leave with a finished, official document — the process end to end, where AI enters it, the evidence to keep and a prioritised 30–90 day plan. No homework, and it begins with a free Clarity Call.
To be clear about what we do and don't do: Vedomia supports readiness, helps you document your AI use, and identifies transparency gaps. We do not certify compliance, we do not provide legal advice, and nothing we provide guarantees legal conformity. This is not legal advice.
The people in your charity are already using AI. A single page — read, agreed and reviewed — is the difference between hoping they use it well and being able to show you helped them.
This article is general information about responsible AI use and the EU AI Act, and does not constitute legal advice.
Prepared with the help of an AI assistant, reviewed by Sandra Fedakova.
Want to map where AI is used across your organisation before you write the policy?
Take the Free Transparency Self-Audit