AI Policy
Development Guide
A starting point for child and family service organizations at any stage of the AI journey.
Staff are already using AI tools today, with or without guidance. The question isn’t whether your organization will engage with AI, it’s whether that engagement is deliberate. A written policy turns “we’re figuring it out” into a clear, documented stance your board, funders, and MCP partners can see.
Understand it yourself
Build a personal baseline: try a real nonprofit-relevant prompt yourself before bringing anything to your team.
Establish your guardrails
A policy doesn’t need to be long, it needs to answer five questions clearly enough that any staff member can act on it.
Identify your first use case
Start at the low-risk end of the ladder below: no client PHI, a real recurring burden, and a human review before anything ships.
Start at 1. Earn your way to 5.
Grant research & drafting in an enterprise chatbot
No client data; human review before anything ships.
Staff training content
Internal-facing; mistakes get caught in review.
Family FAQs in plain language
External-facing; review for accuracy and reading level.
Meeting summaries
Approved tool only, with your consent process in use.
Clinical documentation & case notes
The biggest prize — and last for a reason. PHI at the center of the legal record: compliant vendor, BAA, consent workflow, and a pilot first.
Approved tools
What staff may and may not use.
Prohibited uses
No client PHI in consumer tools; no unapproved automation.
Confidentiality
How HIPAA, CMIA, and 42 CFR Part 2 apply to AI-assisted work.
Staff training
Expectations and accountability for anyone using an approved tool.
Review cadence
AI tools change rapidly; set a date to revisit the policy.
Building Your Policy: Eight Decisions
Write these eight decisions down and you have a policy your board can approve. A useful policy is short. Fill in the eight items, keep the tool list current, and you have something staff can follow and a board can sign.
Sort your information into levels
A few clear categories, from regulated client data down to public material. The rules follow the information, not the device it is on.
List the tools staff may use
If it is not on the list, it is not approved. Confirm each vendor agreement actually covers the AI features, not just the product.
Choose one path for sensitive information
Name a single approved tool for your most protected data. One clear path is followed more reliably than a set of exceptions.
State what is off limits
Short, absolute rules that need no interpretation. A starting set is below.
Say what happens when something goes wrong
Stop, do not delete anything, report right away. Name a contact and a number, and promise no retaliation for honest reporting.
Name an owner and a governance committee
One accountable person, plus a small committee that reviews vendors and data practices. The owner convenes it. Review policies at least annually, and again after any new tool, rule change, or close call.
Tell the people you serve
Disclose your use of AI in service delivery, and separately for any analysis or processing of their health information. Recording consent is not the whole obligation. Write the disclosure language once and use it consistently.
Train the users and the reviewers
Regular training for staff using AI tools, and separate training for the people responsible for oversight. Document who was trained and when.
Schedule yours: we’ll help turn this guide into a policy your board can sign off on.
Schedule your consultation →Have a Question?
Send us an email to info@advantagemicro.net
We’re here to help.
