Ethical AI Guardrails
A clear, comprehensive AI policy gives your team permission and direction to use general-purpose AI in service of purposeful work. It’s a core piece to answering questions on how you apply AI coming from a beneficiary, board member, funder, or colleague.
What this solves
Almost all mission-driven organizations are using AI now (92%), but few are seeing their mission advance from it (7%), and about half (43%) have no shared rules. Virtuous’s 2026 study of 346 organizations shows the gap is most teams use AI ad hoc, with no agreements. One instinct is to treat that as a risk that needs to be contained. But a more useful question is: what becomes possible for your mission when your team uses AI well, and what do you need to protect while they find these uses?
For most teams, the biggest worry underneath is safety. Two things go wrong most often before tailored team AI agreements:
- Private information leaks. Someone pastes confidential or personal details into a tool, and it leaves your control.
- Inaccuracies get published. After AI responses are mostly right and perhaps under a deadline, someone puts an AI hallucination in front of a stakeholder.
For an organization whose impact depends on trust, responsible AI use is about protecting the people the mission exists for. Most teams are working with the riskiest, free AI tier. Guardrails turns those worries into clear rules: which tools to trust for what, what data never goes in, and how to use AI outputs in a way aligned with your values.
An AI policy is the same category of thing as your HR or conflict-of-interest policy: shared rules, built with the people they affect. Generic templates can’t take it the next steps, because the real question is where AI belongs in your work and where it doesn’t. Guardrails produces rules from the people who use AI in your work, anchored to your values and tested against real scenarios. It’s also what you can point to when boards, funders, new EU AI rules, and headline-conscious questions raise the stakes.
What shared rules make possible:
Right now, the opportunity cost of no rules shows up as internal hesitation. People who aren’t sure what’s allowed use AI quietly or not at all, while the legitimate uses staff find stay hidden and siloed. Clear rules change that status so your strongest AI users can share out loud what works within bounds, while the unsure get guidance and a place to start. Things safe to delegate to AI are increasingly shared so everyone can shift creative energy from busywork to work that matters. You also get to say, plainly, confidently, how you use AI and why, to staff, funders, and the people you serve.
How it works
Three steps, built around your mission, not a template of someone else’s.
Listen, interview, and understand
We learn how your team uses AI and their concerns and goals with it. Free fit call, short readiness intake, and a quick survey of key staff.
Decide
One facilitated work session turns your values and concerns into clear decision criteria and working rules: the tools, data, and automation boundaries in your context.
Draft, test, and hand off
We draft your policy, stress-test it against 20+ common and three real scenarios from your work, and hand it to a named owner on your team, with a 30-day check-in.
What you get
Working rules your team can use, and your board and funders can read. The core deliverable is your AI Policy & Decision Guide, with guides for staff.
You don’t have to become an expert on responsible use of AI to make progress on it. That’s our job. You bring the mission and judgment; we carry the complexity.
AI Policy & Decision Guide
A 4 to 6 page working policy written for your organization, marked v1.0 and designed to evolve, with a documented next review date.
Tool & data rules
The tools your team actually uses, with conditions and last-verified dates, plus your relevant plain-language green / yellow / red data handling, including how to use free tools safely (what to redact, what never goes in) when an enterprise license isn’t on the table.
Mission-based decision criteria
Five to seven “what we protect” statements drawn from your values, used as the standard when a more specific rule doesn’t apply to handle rapid changes in AI.
Human review standards
What needs review, who reviews it, and at what stage, with allowed / restricted / not-yet / prohibited use lists, and where automation belongs, and doesn’t.
Staff one-pager & rollout notes
A two-minute staff-facing summary, plus what to say to staff, board, and funders in the first 30 days.
Stress test, owner & cadence
20+ common tough questions and three real scenarios from your work tested against the draft, plus a guided named Policy Owner inside your team and a schedule to keep it current.
Delivered as an editable Google Doc set plus shareable PDF. Want staff training, role guides, a board briefing, or a tool fit analysis on top? Those are optional add-ons, scoped during the fit call (see FAQ).
Preparing for the future: Where automation belongs, and where it doesn’t
The next two years of AI are shaping to go beyond the current strengths of faster drafts, research, and content quality improvement. Agentic AI has a trajectory of becoming more reliable at acting in the world of computers on your behalf. The hype can be off, but delegating routine multi-step tasks to software is likely to become more practical. Developing experience with the current useful cases can help prepare to see the opportunities from the dead ends while the stakes are still low.
Mission-driven organizations have a specific question to answer: where does it serve your work to make things more software-like, and where would that flatten the trust, dignity, voice, or judgment your work depends on? Guardrails helps you decide that on purpose, before the choice gets made for you by whichever staff member tries the new feature first. It also builds the literacy now, on lower-stakes tools.
What this compares to
Organizations handle this a few ways:
- Have a lawyer draft it. European lawyers bill roughly €175 to €500 an hour, and a bespoke policy runs into several thousand euros. Thorough on liability, rarely built with the staff who have to follow it, so it often goes unread.
- Leave staff to it. Free, until a data slip or a funder question costs you trust you spent years building. The large breach figures you’ll see (IBM puts the global average at $4.44M) refer to enterprises, not small or medium nonprofits or social enterprises. For a team your size, the real cost is trust, not a headline fine.
- Build working rules with your team. Anchored to your mission, owned by someone inside, and made to be used at your org. The Starter is a flat €4,900. That’s Guardrails.
Pricing
The Starter is a flat €4,900 and includes a facilitated work session, your draft policy and staff materials, a stress test against 20+ common tough questions and three real scenarios from your work, a handoff session with your Policy Owner, and a 30-day check-in. Larger, more complex engagements (multiple programs, sensitive beneficiary data, multi-department rollout) typically run €10,000 to €20,000, scoped after a fit call.
One thing that lowers the risk of saying yes: if the draft misses at the v0.9 review, one reshape round is included before we invoice the balance, so you see the work take shape before the final commitment.
Smaller nonprofits and grant-funded teams: a community-rate Starter covers the minimal case. It usually needs funding earmarked for it, and it tends to fit three budgets: capacity-building (where AI work is going mainstream in 2026), your own data-security or IT line, and the cybersecurity grants for civil-society organizations that are expanding this year. Clear AI rules cut real exposure (staff pasting sensitive data into tools, unvetted apps, AI taking actions no one approved), so this work sits in those budgets honestly. If you have, or can get, a grant line that fits, reach out and we’ll help you scope the work to the funding.
Prices in EUR; USD available on request. Excludes legal advice, security audit, vendor contract review, and compliance certification.
Best fit if…
- Your staff is already using AI informally
- The organization has started and tabled conversations about AI policy
- Leadership wants shared AI rules
- Staff have thoughtful concerns about AI, and leadership wants a process that takes those concerns seriously
- You’re trusted to protect sensitive information and people: vulnerable communities, field operations, public claims, research, advocacy, donor relations
- The team needs to decide which vendors and tools are okay to use
- Staff need independence and clarity on edge cases
- Board and funders are raising questions about AI
- You want your org to keep its groundedness and direction while building literacy applied to your operations
Who delivers this
- Dan Garmat and Caroline Stauss, founders and directors of AlignIQ.
- 30+ years combined from data science with highly-sensitive data, statistics, communications, and teaching.
- We help purpose-driven teams transition into ethical, practical AI use.
Ready to get this off the screen and into action?
A short, no-cost call. We’ll confirm whether Ethical AI Guardrails fits your situation and determine the right scope. If wAI-Finder readiness and opportunity assessment, training, or outside review would serve you better, we’ll say so.
Frequently asked questions
I’m the one pushing for this. How do I make the case to my ED or board?
This is the common situation: the person who sees the need isn’t always the person who signs to commit resources. We’ll give you a short, forwardable summary written in leadership’s language, what’s at stake for the mission and its trust, the questions a board or funder will ask, and the bounded cost and time. The free fit call and our occasional webinars are also low-commitment ways to get your leadership in the room without anyone committing budget first.
What can we add on top of the Starter?
Common add-ons, scoped during the fit call:
- Fuller role guides for managers, programme staff, operations, communications, or external collaborators
- Rollout pack for managers (talking points, FAQ, escalation paths)
- 90 to 120 minute team workshop to brief staff on the new rules
- Board briefing or external responsible AI statement, or a public-facing AI use page
- Deeper tool fit review
We already have a draft policy. Is that wasted?
No. Most teams that come to us have something. We start with what you’ve drafted, identify the unresolved decisions, and build from there. The existing draft becomes part of the intake and review, and we take it past common hurdles of legitimate ethical concerns and lack of time to become an AI expert.
Want a quick read on where your draft stands first? Run it through our free AI Policy Health Check. It scores your draft against 40 stakeholder questions and shows the gaps in about two minutes.
What if we’re not sure policy is the right next step?
Then wAI-Finder (AI Risk & Opportunity Triage) may be the better starting point. Guardrails fits best when policy, data boundaries, tool choices, or staff rules are already live issues.
What if staff still disagree after rollout?
Some concerns won’t be fully resolved in a short policy project. We help the team decide which concerns become rules, which become review gates, which need an owner, which require outside review, and which should be revisited as AI changes. The policy is marked v1.0, designed to evolve. The methods practiced add to your team’s AI governance literacy to effectively handle staff concerns around AI.
How do we keep this current as tools change?
The policy is built in stages, starting with your org’s mission and values, so your team has guidance it needs from prior work to update it. The decision criteria, data stoplight, tool guidance, and review cadence are documented at a level that survives many tool changes. Each tool entry has a “last verified” date and a re-verification cadence. For larger shifts, advisory follow-on or a refresh engagement is available.
