Acceptable Use Policy

Policy template governing staff use of AI tools in advancement operations. Download, then adapt the placeholders and approved-tool inventory for your institution.

DRAFT — Adapt for your institution. Replace all bracketed fields and route through legal counsel before adoption.

Acceptable Use Policy: Artificial Intelligence in Advancement

Institution [Institution Name]
Department [Department name]
Effective date [MM/DD/YYYY]
Next review date [MM/DD/YYYY]
Policy owner [Name, Title]
Contact [email@institution.edu]
Supersedes [Prior policy reference, or "N/A"]

Purpose

This policy establishes requirements for the responsible use of artificial intelligence tools and AI-powered features within the advancement operation at [Institution Name]. It applies to all advancement staff, contractors, volunteers, and third-party partners (collectively, "covered personnel") who access institutional data or use AI tools in the course of advancement work.

This policy operates within the broader AI governance framework adopted by [Institution Name] and does not supersede institutional IT security, data governance, or records retention policies.

1. Approved AI tools

Only AI tools listed in this inventory or approved through the governance process described in the AI Governance Committee Charter may be used with institutional data. The AI governance committee maintains this inventory and reviews it quarterly.

Tool name Approved uses License type Risk tier
CRM-native prospect scoring Propensity, affinity, and capacity scoring within the CRM platform; portfolio prioritization; segment-level reporting Enterprise (included in CRM contract) Tier 2 — Elevated
Enterprise generative AI platform Internal document drafting; meeting summarization; data analysis on non-PII datasets; proposal boilerplate generation Enterprise site license Tier 1 — Routine
Wealth screening service Prospect research; capacity rating; wealth indicator analysis; batch screening of new records Enterprise (annual contract) Tier 2 — Elevated
Meeting transcription tool Internal meeting recording and summarization; action item extraction; attendee notification and consent where required by law; note distribution to attendees only Enterprise Tier 1 — Routine
[Tool name] [Approved uses] [License type] [Risk tier]
[Tool name] [Approved uses] [License type] [Risk tier]

Requests to add tools to this inventory must be submitted to [Governance contact]. Tool requests are evaluated against the risk classification matrix in the AI governance framework. Approval timelines depend on risk tier: Tier 1 requests are typically resolved within two weeks; Tier 2 and Tier 3 requests require committee review and may take 30–60 days.

2. Permitted uses

The following uses of approved AI tools are permitted, subject to the data handling rules in Section 4 and the disclosure requirements in Section 5.

  • Internal document drafting. Using AI to generate first drafts of internal memos, reports, talking points, and briefing documents. All drafts must be reviewed by a staff member before distribution.
  • CRM AI features. Using approved AI-powered features within the CRM platform (scoring, segmentation, recommendations) as documented in the system inventory.
  • Meeting summarization. Recording and transcribing internal meetings with approved tools, with attendee notification and, where required by applicable state law, documented consent. Transcripts are internal documents subject to institutional records retention policy.
  • Donor communication drafts. Generating initial drafts of donor correspondence, proposals, stewardship reports, and appeal copy. All donor-facing content must pass through the content approval workflow before distribution.
  • Data analysis and visualization. Using AI tools to analyze, summarize, and visualize internal data or publicly available data. Analysis on datasets containing PII requires Tier 2 approval and must use enterprise-licensed tools.
  • Prospect research summarization. Summarizing publicly available information about prospective donors using approved research tools. AI-generated summaries must be verified against source material before entry into the CRM.
  • Template and boilerplate generation. Using AI to produce reusable templates for proposals, grant applications, stewardship reports, and standard correspondence.
  • Translation and accessibility. Using AI tools to translate communications or improve accessibility of advancement materials, subject to human review for accuracy.

3. Prohibited uses

The following uses of AI are prohibited regardless of tool approval status. Violations are subject to the enforcement provisions in Section 7.

3.1 Data exposure

  • Entering personally identifiable information — names, addresses, phone numbers, email addresses, giving amounts, pledge details, Social Security numbers, dates of birth, or student records — into any AI tool that is not on the approved inventory with an enterprise license.
  • Sharing confidential contact reports, gift intentions, bequest details, estate plan information, or donor financial disclosures with any AI tool not approved for Tier 2 or Tier 3 use.
  • Using personal-tier AI accounts (free or individual subscriptions) for any work involving institutional data, regardless of data sensitivity level.
  • Circumventing data access controls by using AI tools to query, aggregate, or infer information that the user is not authorized to access directly.

3.2 Decision-making

  • Making final solicitation decisions (ask amounts, timing, vehicle, or assignment) based solely on AI output without human review and approval by a gift officer or manager.
  • Using AI to infer protected attributes — including race, ethnicity, national origin, religion, age, health status, disability, sexual orientation, gender identity, political affiliation, or any other characteristic protected by applicable federal, state, or local law — about constituents, whether for segmentation, scoring, targeting, or any other purpose.
  • Implementing automated outreach sequences, communication cadences, or AI-driven solicitation triggers without Tier 3 approval from the governance committee and documented human oversight procedures.

3.3 Content and media

  • Sending AI-generated content to donors, alumni, or other external constituents without human review and approval through the established content approval workflow.
  • Creating AI-generated images, audio, video, or deepfake content depicting identifiable donors, alumni, staff, or institutional leaders without written consent from the depicted individuals.
  • Using AI to generate synthetic donor data, fabricated testimonials, or simulated giving histories for external reporting, marketing materials, or board presentations.

3.4 Institutional

  • Representing AI-generated analysis, projections, or recommendations as human-produced work product in board reports, regulatory filings, or audit documentation without disclosure.
  • Using AI tools to monitor, evaluate, or make employment decisions about advancement staff without HR and legal review.
  • Training or fine-tuning AI models on institutional data without written authorization from [Governance contact].

3.5 Exception process

Requests for a temporary exception to any prohibition in this section must be submitted in writing to [Chair of AI Governance Committee]. The request must document the business justification, proposed safeguards, and requested duration (not to exceed [90] days). The approving authority may grant, deny, or modify the exception. All granted exceptions shall be documented, reported to the governance committee at its next meeting, and reviewed for renewal or termination at expiration.

4. Data handling rules

4.1 Data classification for AI use

Before using any data with an AI tool, determine the data sensitivity level per the institutional data classification policy. The following rules apply specifically to AI tool use.

Sensitivity level Examples AI tool requirements
Public Published donor lists, press releases, public event information, annual report data Any approved tool (Tier 1+)
Internal Aggregate giving reports, campaign projections, internal memos, meeting notes Enterprise-licensed tools only (Tier 1+)
Confidential Individual giving records, contact reports, prospect ratings, donor PII, wealth screening results Enterprise tools with Tier 2+ approval; data must not leave institutional systems unless vendor DPA is in place
Restricted SSNs, FERPA-protected records, HIPAA data, estate/trust documents, donor financial statements Tier 3 approval required; legal review of vendor terms mandatory; may be prohibited entirely depending on tool

4.2 Enterprise vs. personal licenses

  • All AI tool use involving institutional data must occur through enterprise-licensed accounts provisioned by [IT department].
  • Enterprise licenses must include a data processing agreement (DPA) that confirms the vendor will not use institutional data for model training, will comply with applicable data retention and deletion requirements, and will provide audit access upon request.
  • Personal AI accounts — including free tiers, individual subscriptions, and trial accounts — are not approved for institutional data use under any circumstances.

4.3 Output verification

  • AI-generated prospect research must be verified against at least one independent source before entry into the CRM or inclusion in briefing materials.
  • AI-generated giving projections, capacity estimates, and propensity scores must be labeled as model outputs in all internal reports and must not be represented as independently validated data points.
  • Remove unverified AI-generated claims from donor communications before distribution. If AI drafts a donor letter referencing specific institutional facts, statistics, or donor history, verify each claim against institutional records.

4.4 Data retention and deletion

  • AI tool usage involving confidential or restricted data must comply with the institutional records retention schedule.
  • When an AI tool is decommissioned or a vendor contract terminates, confirm deletion of institutional data per the DPA within [30/60/90] days.
  • AI-generated outputs that constitute advancement records (e.g., prospect research summaries entered in the CRM) are subject to the same retention requirements as manually created records of the same type.
  • Conversation logs and prompt histories in AI tools containing confidential data must be purged according to the schedule defined in the DPA or within [timeframe], whichever is shorter.

5. Disclosure requirements

5.1 Constituent-facing disclosure

Disclosure of AI involvement is required in the following circumstances:

  • When constituents interact directly with an AI-powered chatbot, virtual assistant, or automated communication system, the system must clearly identify itself as AI-powered at the start of the interaction.
  • When AI-generated content forms a substantial portion of a donor communication, and the constituent could reasonably expect the communication to be personally authored, disclosure is required when AI-generated text constitutes the majority of the communication's substantive content. The governance committee will issue additional guidance on disclosure thresholds.
  • When AI is used to make or substantially influence decisions that affect a constituent's experience (e.g., event invitation lists, solicitation targeting, portfolio assignment), document the AI's role in the decision process in the CRM.

5.2 State law requirements

Several states have enacted or are considering legislation that imposes specific disclosure obligations for AI use. As of the effective date of this policy, the following states have relevant requirements. This list is not exhaustive and must be reviewed by legal counsel at each annual policy review.

  • California (CPRA/CCPA). Right to know about automated decision-making; opt-out rights for profiling.
  • Colorado (CPA). Right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects.
  • Connecticut (CTDPA). Right to opt out of profiling; requires data protection assessments for certain AI processing.
  • Minnesota (MCDPA). Profiling disclosure and opt-out requirements for covered data controllers.
  • Montana (MTCDPA). Consumer opt-out rights for profiling in decisions with significant effects.
  • Oregon (OCPA). Profiling opt-out and disclosure requirements for controllers.

Note to adopting institutions: Several of these laws exempt nonprofit organizations or educational institutions (including CCPA/CPRA, CTDPA, OCPA, and Montana's consumer data privacy act), while others (Colorado's CPA, Minnesota's MCDPA) lack blanket nonprofit exemptions. Legal counsel should evaluate whether nonprofit status, FERPA preemption, or other exemptions affect the institution's obligations under each applicable law before adopting this section.

Institutions operating across state lines or soliciting donors in multiple states should apply the most restrictive applicable standard unless legal counsel advises otherwise.

5.3 Internal documentation

  • Document AI involvement in prospect scoring, segmentation, and recommendation processes in the system inventory maintained by the governance committee.
  • When AI output is a material factor in a gift solicitation strategy (ask amount, timing, vehicle), note this in the contact report or strategy record.
  • Annual reports to the governance committee must include a summary of AI tool usage patterns, incident reports, and any identified bias or accuracy concerns.

6. Reporting procedures

6.1 What to report

Report any of the following to [AI governance contact]:

  • Biased or discriminatory output. AI results that appear to systematically favor or disadvantage constituents based on protected characteristics, geography, or other attributes unrelated to giving capacity or affinity.
  • Unauthorized use. Use of unapproved AI tools with institutional data, or use of approved tools outside their approved scope.
  • Data exposure. Institutional data entered into AI tools in violation of the data handling rules in Section 4, including accidental exposure of PII or confidential records.
  • Accuracy failures. AI-generated outputs that contain material errors and that were or could have been acted upon (incorrect giving history, misattributed wealth data, fabricated biographical details).
  • Uncertainty about compliance. Situations where it is unclear whether a proposed use of AI is permitted under this policy.

6.2 How to report

  • Email [ai-governance@institution.edu] with a description of the incident, the tool involved, the data affected, and the date of occurrence.
  • For urgent data exposure incidents, follow the institutional data breach notification procedure and notify [IT security contact] immediately.
  • Anonymous reports may be submitted through [institutional ethics hotline or reporting system].

6.3 Response timelines

Report type Acknowledgment Resolution target
Data exposure / breach Same business day Per institutional incident response policy
Bias or discrimination concern 2 business days 30 days (investigation and corrective action)
Unauthorized use 2 business days 14 days
Accuracy failure 3 business days 14 days
Compliance question 5 business days As needed

6.4 Non-retaliation

[Institution Name] prohibits retaliation against any employee who reports, in good faith, a concern about AI use under this policy, regardless of the investigation's outcome.

7. Compliance and enforcement

7.1 Training requirements

  • All advancement staff must complete AI acceptable use training within [30/60] days of this policy's effective date or within [30] days of hire, whichever is later.
  • Annual refresher training is required for all staff who use AI tools. Training must cover updates to this policy, new tools added to the approved inventory, and lessons learned from reported incidents.
  • Staff who use Tier 2 or Tier 3 AI tools must complete supplemental training specific to those tools and their risk controls before receiving access.
  • Training completion records are maintained by [Records owner] and reviewed annually.

7.2 Acknowledgment

All covered personnel must sign the acknowledgment in Section 8 before using AI tools in advancement work. Signed acknowledgments are retained by [Records owner].

7.3 Consequences for violations

Violations of this policy will be addressed through the institutional disciplinary process. Consequences may include:

  • Required retraining on AI acceptable use
  • Temporary or permanent revocation of AI tool access
  • Formal counseling or written warning
  • Disciplinary action up to and including termination, consistent with institutional HR policy
  • For contractors or third-party partners, contract remedies including termination of engagement
  • For volunteers: removal from volunteer roles and revocation of access to institutional systems and data

The severity of consequences will be proportionate to the nature of the violation, the sensitivity of the data involved, the impact on constituents, and whether the violation was intentional or inadvertent.

7.4 Annual review

This policy will be reviewed and updated at least annually by the AI governance committee. Reviews will incorporate:

  • Changes in the regulatory environment (new state privacy laws, federal guidance, FERPA/HIPAA updates)
  • Incident and reporting trends from the preceding year
  • Changes to the institutional AI tool inventory
  • Vendor contract renewals and DPA updates
  • Feedback from staff, leadership, and legal counsel
  • Developments in AI technology that affect risk classification

8. Acknowledgment

I have read, understand, and agree to comply with this Acceptable Use Policy for Artificial Intelligence in Advancement. I understand that violations may result in disciplinary action as described in Section 7.3.

Name [Employee full name]
Title [Job title]
Department [Department]
Date [MM/DD/YYYY]
Signature