What Do Nonprofit Boards Actually Need to Own About AI?
- Courtney Reeve

- Jul 17
- 5 min read
By Courtney Reeve · July 2026 · AI Governance
Most AI work in a nonprofit belongs to staff: choosing tools, writing procedures, training people, managing day-to-day use. A small set of decisions does not. The board owns the risk appetite, the policy's adoption, the oversight rhythm, the organization's accountability when AI causes harm, and the decision about its own use of AI. Those five cannot be delegated, because they are governance rather than management. The most common failure in nonprofit AI oversight is not a missing policy. It is a board that never settled which decisions were its own.
Why does the board-versus-staff question matter more than the policy?
By now, most organizations have crossed the adoption line. Sector research in 2026 puts AI use in nonprofits above ninety percent, while nearly half still operate without any policy. That gap gets the headlines.
But watch what happens inside organizations that do have a policy. The executive director drafted it. Staff follow it. The board approved it in eight minutes on a consent agenda, and nobody has mentioned it since.
Is that governance?
Everyone in that room would say the organization "has AI governance." What it actually has is staff-level management with a board signature on it. The work products exist. Who decides what was never settled. And when something goes wrong, that question gets answered in the worst possible moment, in real time, with a harmed constituent or an alarmed funder on the other end.
The useful question is not whether your organization has a policy. It is whether your board knows which parts of AI belong to it.
What belongs to the board, and what belongs to staff?
Here is who decides what. The board's list is shorter than most boards expect.
The board owns five things:
The risk appetite. How much risk this organization will accept in exchange for AI's benefits, given who it serves. A legal aid organization and an arts education nonprofit should answer differently. Staff can inform this decision. Staff cannot make it.
The policy's adoption, as a real decision. Approving the AI policy is a governance act, and it deserves the treatment of one: read, questioned, understood, and owned. A policy adopted on a consent agenda was filed, not governed. That is not an argument against consent agendas, which exist precisely to protect board time for decisions like this one. It is an argument for knowing which items deserve the time the consent agenda saves.
The oversight rhythm. When AI comes back to the board table, in what form, and what the board expects to see. Once a year, with a written report, is a reasonable floor. Never is the current norm.
Accountability when it goes wrong. If an AI tool leaks constituent data or produces a harmful decision, the organization's answer is a board-level matter, because the duty of care sits with the board. That accountability can be exercised through staff. It cannot be transferred to them.
The board's own use. Whether and how board members themselves use AI with board materials. Confidential financials pasted into a free chatbot is a governance breach, and only the board can set that rule for itself.
Staff own the rest. Tool selection. Written procedures. Training. Vendor management. Approved-use lists. Day-to-day judgment calls. Incident response steps. Nearly everything a policy document actually contains is staff work, and a board that reaches into it is managing, not governing.
One thing runs through both columns: the organization's values. When someone asks whether the tools you are choosing amplify certain voices and perspectives over others, that is not a technical question. It is a values question, and an organization's values are always available as a lens for its decisions.
Staff apply that lens when they select tools and write procedures. The board's job is to make sure the lens is actually in use, and that the policy reflects who the organization is and what it stands for, particularly in how it protects the people it serves.
And owning a decision does not mean making it alone. The best AI oversight happens when the board and the Executive Director/CEO think these questions through together. The division determines who decides; the shared conversation is how they decide well.
The line is the same one that runs through all governance: boards decide what the organization will and will not accept; staff decide how the work gets done.
AI does not change the line. It just arrives fast enough that many boards never drew it.
What happens when boards never settle who decides what?
Two failure patterns, and they look nothing alike.
The first is absence. The board treats AI as a technology matter, technology as an operations matter, and operations as staff territory, so AI never reaches the board table at all. The risk appetite gets set by default, by whoever adopted a tool first. Sector commentators have started naming this plainly: AI in nonprofits is a governance question, not just a technology question, and corporate law is moving the same direction, with board-level oversight of AI increasingly framed as part of directors' duty of care.
The second is the opposite. An anxious board pulls the whole subject upward, debating tool choices and rewriting staff procedures. It feels like diligence. It is a board governing below its elevation, and it usually means the five decisions that actually belong to the board still have not been made, because the board's attention went to the parts it recognized instead of the parts it owns.
Both patterns come from the same root: no one ever decided who decides.
Where should a board start?
With one agenda item, and not a technology presentation.
Put the five board-owned decisions in front of the board and ask which have actually been made. Most boards discover that the honest answer is one, the policy approval, and that even that one happened without much of a decision behind it.
Then work through them in the order the questions suggest.
Start with the current state: who is leading AI decisions inside the organization today, and has client, donor, or personnel data already been entered into any tool?
Set the risk appetite from there, because everything else flows from it.
Bring the policy to the board as a real decision: what does it permit, what does it prohibit, who owns it day to day, and does it reflect who the organization is and what it stands for?
Put the oversight rhythm on the calendar, with an annual written report as a reasonable floor.
Name who speaks and decides for the organization if something goes wrong.
And set the rule for the board's own use, starting with the one that matters most: no client data, donor data, or confidential organizational information goes into any AI tool.
None of this requires technical expertise. It requires the board to recognize the work as its own. That recognition, more than any document, is what nonprofit AI oversight actually is.
If your board is earlier in the process, start with where the organization stands: Four Stages of Nonprofit AI Governance.
If the policy already exists and the question is follow-through, the next piece is what boards need to do after adopting an AI policy.
And if the pressure you are feeling is a vendor pitch, the software question has its own answer: do nonprofit boards need AI governance software.
The tools will keep changing. The ownership does not. That part stays with the board.

Courtney Reeve is the founder of Fine Point Consultants, a governance and strategy consultancy. A former executive director and board officer, she works with nonprofit boards and executive directors on board design, AI governance, and organizational strategy. finepointconsultants.com



Comments