The operational companion to the Board Brief. This handbook spells out the rules of the road for day-to-day AI use. Adapt bracketed placeholders to your organization, then issue under the AI Use Officer’s signature. Last reviewed: May 25, 2026.
Contents
- Introduction and Scope
- Definitions
- Data Classes
- The Three-Tier Framework in Practice
- Approved-Tool List
- Requesting Approval for a New Tool
- Disclosure Standard
- Prohibited Uses
- Training Requirements
- Incident Reporting
- Recordkeeping
- Appendix A: Tool Approval Worksheet (reference)
- Appendix B: Disclosure Examples
- Appendix C: Federal-Award Overlay (Uniform Guidance)
- Acknowledgment of Receipt
1. Introduction and Scope
This handbook implements [Organization Name]’s AI Use Policy adopted by the Board on [Date]. It applies to all staff, contractors, volunteers, and board members in the conduct of organizational work, including the use of personal devices when those devices are used for organizational tasks.
Where this handbook is silent, defer to the Board-adopted policy. Where this handbook is inconsistent with applicable law, contract, or funder requirement, the stricter standard governs.
2. Definitions
AI tool. Any software application, plug-in, or service that uses machine learning or generative models to produce text, code, images, audio, video, classifications, predictions, or recommendations. Includes general-purpose assistants (ChatGPT, Claude, Microsoft Copilot, Google Gemini), in-product AI features (transcription, summarization, scoring), and AI-powered analytics or decision-support tools.
Enterprise-grade AI tool. A tool offered to the organization under a written agreement that (a) prohibits the vendor from using organizational inputs to train models, (b) provides for confidentiality of inputs and outputs, and (c) commits to a defined retention and deletion practice. Free or consumer-tier accounts do not meet this definition.
AI Use Officer. The person designated under the AI Use Policy to administer this handbook. At [Organization Name], this is [Executive Director or designee]. The AI Use Officer maintains the approved-tool list, approves Restricted-tier uses, reviews incidents, and reports to the Board.
Participant data. Any information about an identified or identifiable person who is or has been enrolled in, applied to, or otherwise engaged with an organizational program or service.
3. Data Classes
Every piece of information you might consider entering into an AI tool belongs to one of four data classes. The class determines what’s allowed.
- Public. Already public information — your website copy, public funder reports, press releases, BLS data, published research.
- Internal. Non-public organizational information that is not sensitive: draft program descriptions, board agendas, internal meeting notes that do not name participants or contain regulated data.
- Confidential. Non-public information whose disclosure could harm the organization, staff, donors, or partners: financial records, donor identities and giving history, personnel files, draft contracts.
- Sensitive / Regulated. Information that is protected by law or contract: PII (names with SSNs, dates of birth, etc.), PHI (HIPAA), educational records (FERPA), child-welfare information, attorney-client privileged communications, and any data restricted by federal-award or state-program data-use terms.
When in doubt, treat data as one class higher than your first instinct.
4. The Three-Tier Framework in Practice
Permitted Tier
No advance approval required. You may use approved AI tools at the Permitted tier for tasks that meet all of the following:
- The input is Public or Internal data only.
- The output will be substantively reviewed by a human before any external use.
- The use does not affect a decision about any specific participant, staff member, or stakeholder.
Typical examples: drafting first versions of public-facing communications you then edit; summarizing publicly available reports for internal briefings; brainstorming options; spell- and grammar-checking; cleaning up the formatting of an existing document; generating headline or subject-line options.
Restricted Tier
Advance approval required. A use is Restricted if any of the following apply:
- The input includes Confidential or Sensitive / Regulated data.
- The output will be presented to a funder, regulator, court, or other external authority as part of the organization’s work product.
- The use involves a tool that is not on the Approved-Tool List, or a tool at the Approved-Tool List that has not been approved for this data class.
- The use materially affects how the organization documents a participant’s program experience (e.g., AI-assisted case notes, AI-summarized intake content).
Approval is granted by the AI Use Officer in writing using the Tool Approval Worksheet. Approvals are time-limited (12 months default) and tied to a specific tool, data class, and use case. A different use of the same tool requires a new approval.
Prohibited Tier
Not permitted under any circumstances. See Section 8.
5. Approved-Tool List
The AI Use Officer maintains a current Approved-Tool List, available to all staff. For each approved tool, the list specifies:
- Tool name, vendor, tier or plan.
- Data classes permitted (Public, Internal, Confidential, Sensitive / Regulated).
- Use cases approved.
- Approval date and expiration.
- Tier under this handbook (Permitted vs. Restricted) for each approved use case.
- Vendor agreement reference (BAA, DPA, MSA) where applicable.
Staff may not use AI tools that are not on this list to process anything beyond Public data.
6. Requesting Approval for a New Tool
To request approval of a new AI tool or a new use case for an already-approved tool:
- Complete the Tool Approval Worksheet and the Vendor Evaluation Checklist.
- Submit both to the AI Use Officer at least ten business days before intended first use.
- The AI Use Officer reviews, may request changes, and either approves (in writing, with conditions if needed) or denies (in writing, with rationale).
- An approval is added to the Approved-Tool List and expires after 12 months unless renewed.
Federally funded program staff who anticipate AI tool costs being charged to a federal award follow the additional steps in Appendix C before approval.
7. Disclosure Standard
The organization discloses AI use where a reasonable participant, funder, or regulator would want to know about it. Use the three-tier disclosure pattern below; when in doubt, default to the higher tier.
- Silent. No disclosure required. The AI’s role is functionally equivalent to spell-check, search, or a calculator, and the output is fully human-edited.
- Footer. Standing disclosure on the relevant publication, page, or document. Example footer: “Content on this site is drafted with the help of AI tools and reviewed by our team before publication. Our AI Use Policy is available at [link].”
- Explicit. Specific in-the-moment disclosure to the affected person before they continue. Required where AI is involved in: decisions about a participant; the use of a participant’s story; a chatbot or AI assistant the participant interacts with; AI-generated translations of legal or rights-bearing documents.
See Appendix B for worked examples.
8. Prohibited Uses
The following are prohibited under all circumstances and may not be approved as Restricted-tier uses:
- Eligibility determination. AI tools may not determine, or substantially drive, a determination of whether any person is eligible for a program, service, or benefit.
- Participant-affecting decisions without human review. AI tools may not make, or substantially drive, decisions about a participant’s services, placement, prioritization, sanction, or exit, without a documented, authoritative human-review step.
- Sensitive data in non-approved tools. Sensitive / Regulated data may not be entered into any AI tool that does not appear on the Approved-Tool List at that data class.
- Concealed AI authorship in material contexts. Representing AI-generated content as exclusively human-authored is prohibited in funder evaluations, regulatory filings, court submissions, and academic or journalistic outputs.
- Surveillance. AI may not be used to surveil staff, contractors, or participants — including sentiment analysis of internal communications, monitoring of online presence, or scoring of participant behavior without explicit consent.
- Impersonation. AI may not be used to generate content that impersonates a real, identifiable person without their written consent.
- Pasting and signing. AI-drafted case notes, performance evaluations, or other documents requiring professional judgment may not be saved or submitted without substantive human edit. Pasting an AI output into a case file or evaluation without edit is a documentation-integrity violation.
9. Training Requirements
All staff complete a brief AI Use Policy training within 30 days of hire and annually thereafter. Training covers: this handbook; the data classes; the three-tier framework; the prohibited uses; the disclosure standard; the approval and incident processes. Training is approximately 30 minutes and is documented in personnel files.
Staff whose roles include Restricted-tier uses receive role-specific guidance from the AI Use Officer before first such use.
10. Incident Reporting
Report the following to the AI Use Officer within one business day:
- Any entry of Confidential or Sensitive / Regulated data into a tool not approved for that data class.
- Any AI-generated output that reached an external recipient without required review.
- Any participant complaint connected to AI use.
- Any apparent vendor breach of the data-handling commitment in the agreement governing an approved tool.
- Any other event that you believe may be a breach of this handbook.
Good-faith reporting is protected; staff who report incidents in good faith will not be penalized for the report itself.
11. Recordkeeping
The AI Use Officer maintains the following records for the longer of seven years or the retention period required by any applicable funder or regulator:
- This handbook and all prior versions, with adoption dates.
- The Approved-Tool List and its version history.
- Completed Tool Approval Worksheets and Vendor Evaluation Checklists.
- Vendor agreements (BAA, DPA, MSA, etc.) governing approved tools.
- Incident reports and corrective actions.
- Training records.
Appendix A: Tool Approval Worksheet
See the standalone AI-Use Tool Approval Worksheet.
Appendix B: Disclosure Examples
- Silent. A development director uses ChatGPT to brainstorm donor-segment names; the final names are her own. No disclosure.
- Footer. A program manager uses Claude to draft a first version of a blog post that he then substantively edits and publishes. The site footer states that some content is drafted with AI assistance and reviewed by staff.
- Explicit. A case manager uses an approved enterprise AI tool to generate a draft summary of an intake interview. She tells the participant before the interview that an AI tool will be used to help draft the intake record, and that the case manager will edit it before it is saved. Her organization’s AI Use Policy is available on request.
- Explicit. A grant writer uses AI to assist with the narrative section of a federal proposal. The proposal includes a brief disclosure of AI-assisted drafting reviewed by staff before submission.
Appendix C: Federal-Award Overlay (Uniform Guidance)
Where AI tool costs are charged to a federal award, or where AI use is integrated into federally funded program activities, the following additional steps apply:
- Confirm cost allowability under 2 CFR 200.403 (factors affecting allowability) and applicable program-specific rules. “Hope is not a compliance strategy” — the analysis goes on paper before the first charge.
- If the tool serves more than one award or both award and non-award activity, document a defensible allocation methodology consistent with 2 CFR 200.405 (allocable costs).
- Classify the cost as direct or indirect consistent with 2 CFR 200.413 / 200.414 and your organization’s negotiated indirect cost rate.
- Maintain documentation sufficient to support cost allowability, including the Board-adopted policy, this handbook, the Approved-Tool List entry, the cost-allocation memo, and any pass-through agency correspondence.
- Where AI materially affected the production of a performance-report output, ensure performance reporting is consistent with 2 CFR 200.328 (financial reporting) and 200.329 (performance reporting) — i.e., honest representation of how outputs were produced.
- Where program rules are stricter than the general Uniform Guidance baseline (HIPAA, FERPA, child-welfare data, state PIRL data-sharing terms, etc.), follow the stricter rule.
For the per-tool template used to satisfy these documentation requirements, see Documenting AI Costs in Federal Grant Reports and the Federal Grants & AI Compliance Quick Reference.
Acknowledgment of Receipt
By signing below, I acknowledge that I have received, read, and agree to follow the [Organization Name] AI Use Policy and this Staff Handbook.
Name (printed): _____________________________________________
Signature: __________________________________________________
Date: ______________________________________________________
This is a template, not legal advice. If your organization has specific legal obligations — HIPAA, FERPA, child welfare, federal awards, state law — review with counsel before adoption. Pair with the Board Brief and the Board Briefing Pack for full implementation.