In Uncategorized

What to Consider When Building an AI Policy, with Examples

Artificial Intelligence (AI) tools are rapidly changing the way people and organizations work. A recent River Network poll of 41 organizations found that, despite water-related concerns about AI use and data center development, the network’s response to the technology ranges from complete rejection to enthusiastic acceptance. 

66% of respondents reported no internal AI policy at their organizations.

This range of responses is present not just across organizations, but across staff at the same organizations. The purpose of an internal AI policy is to recognize that, while these tools are widely available and free to use, there are significant privacy-related, ethical, and environmental concerns in adopting AI on behalf of a water organization. Broadly, an internal AI policy gets your staff on the same page in terms of ethical concerns. A policy might also: 

  • List approved and prohibited uses, 
  • Educate staff on opportunities and impacts, and 
  • Provide appropriate use guidelines depending on the type of AI.

Understanding How Water Advocates are Using AI

To build an internal AI use policy at your organization, it is first necessary to understand how your colleagues are using these tools. Network members had a lot to say about the pros and cons of AI adoption at water organizations. 

Adopters

Some water advocates believe that generative AI (GenAI) can be a boon to an organization’s mission, despite land-use, water, and environmental justice concerns. The benefits they cited are primarily related to increased capacity, efficiency, and productivity with tools like Claude, Gemini, and ChatGPT. 

These tools have helped members draft grant applications, newsletters, and social media; quickly translate content from one format to another (i.e., Word document to a presentation); create summaries of long documents; transcribe audio and video content; and conduct research. At least a few of these adopters believe that AI is here to stay, and they may as well get on board.

Cautious Users & Abstainers

Advocates who are taking a more cautious approach to or have outright rejected AI often acknowledge that there is no way to completely detach from these tools. AI is deeply embedded in most search engines, design software, email platforms, and billing software, but we do have a choice in how we use GenAI, if at all. One surveyed organization is saying no to AI until the organization can develop a robust policy that addresses all associated risks. 

Those who have said no to GenAI cite the protection of sensitive data as a primary reason. Inputting member, donor, or staff data into these tools is often a violation of deeper internal and legal privacy policies. Furthermore, AI use in meetings, especially note-takers and automated summaries, compromise sensitive conversations and misgender meeting participants. One respondent noted a boilerplate policy at their organization that AI note-takers are never allowed in meeting rooms. Another organization provided an alternative approach: 

Example from the Network

“If AI notetaking software is present in a meeting, employees must: (1) notify all participants before the meeting, and (2) obtain explicit consent from all participants before activating the software.”

Building Your Internal Policy

It is widely acknowledged that GenAI tools are biased and can contribute to misinformation. How does this information change your approach to these tools? And, if you choose to pursue constraints, how can your teams work to reduce inaccuracy and bias?  

These tools are changing fast. Another organization formalized everything they don’t know in their policy: 

Example from the Network

“We recognize that the impact of AI is yet to be fully understood and are mindful of the many considerations inherent in its use, from mitigating algorithmic biases against vulnerable or marginalized groups to navigating compliance and copyright concerns to reconciling the complex environmental impacts, environmental justice, societal and economic consequences of its infrastructure.” 

Internal Training and Understanding AI

Many respondents, whether their organization has established an AI policy or not, believe training on how AI works and how it can be used would be helpful for staff. When building your internal policy, be sure all staff understand the difference between: 

  • Generative AI (GenAI): Tools like ChatGPT, Gemini, and Claude that produce text, images, and summaries. 
  • Embedded AI: Support tools built into other tools like Canva Magic Studio. 
  • AI Agents: Like an assistant that performs tasks based on instructions. 

Guardrails and Limitations

Of the advocates and organizations surveyed, 43% reported that they do not use GenAI at all. Among those who do use GenAI, 35% use it for writing support (think grant reports, newsletter writing, and social media), and 19% use it as a supplementary research tool.  

Some water organizations may choose not to allow the use of GenAI at all to preserve trust and publication integrity: 

Example from the Network

“Our original editorial content is of the highest standard, and the use of AI tools for its creation is not permitted by staff or contributors. This applies to the original text, photography, audio, video, and multimedia content published across our channels and platforms.” 

Others may choose to limit GenAI use in staff communications with specific audiences, again to preserve integrity and trust: 

Example from the Network

“The use of AI tools to generate official communications to or messaging for government officials, including representatives of Tribal nations, is not permitted.” 

One organization has designed a framework for when to use GenAI based on the task: 

Example from the Network

“The more complicated the task, or the higher the risk, the more human expertise will be required to oversee and check the output of the AI. 

  • Green – Low risk, internal use. AI can be used for routine tasks where the output stays internal or informal, no sensitive data is involved, and you can personally verify the quality. Examples: improving the readability of an internal email, brainstorming ideas… 
  • Yellow – Moderate risk, expert review required. AI can be used, but the output requires review by someone with the expertise to catch errors, misrepresentations, or gaps that a general reader might miss. Apply this level when the work involves technical, scientific, or specialized content; when AI is generating or manipulating substantive material rather than simply refining it; or when an inaccurate output could mislead internal audiences or weaken the quality of work that will eventually go through further review or to external audiences… 
  • Red – Prohibited unless specifically authorized. AI must not be used in these contexts unless the specific tool and use case have been vetted and approved by the Data Governance Team or IT Steering Committee as appropriate. Apply this level when the task would require sharing confidential, personal, or sensitive data with an AI tool; when the use poses serious legal or copyright risk; or when the environmental costs of the AI tool are disproportionate to the task… 

Organizations’ policies outline which AI products are allowed to be used internally, and some specify that large language models (LLMs) are never permitted. Instead, they use products like Grammarly Premium, also an AI product, to support human-generated writing.  

Many respondents noted that, per their policies, it is never permitted to release heavily AI-generated content, be it an email or a report, without a human reviewing the published versions. 

Example from the Network

“Generative AI should never be used to create final versions of content. There must always be a human involved in reviewing, editing, and approving anything generated by AI before it is shared publicly or acted upon.” 

“Staff remain responsible for reviewing, editing, fact-checking, and approving AI-generated content before use or distribution.” 

Safety and Accountability

An effective AI policy must always address privacy and protection of sensitive personal data of community members, staff, and partners: 

Example from the Network

“Staff are prohibited from using free AI software that does not require registration when accessed through organization email accounts. Staff must use approved platforms only on organization-issued devices. The use of generative AI tools must always align with the organization’s security and privacy standards. Never enter sensitive, proprietary, or personal information into any AI platform.” 

If you’re wondering what is considered sensitive information, think financial data, donor records, HR files, internal memos, or personal data of any kind including legal name, contact information, or addresses. 

Many policies exist to ensure that the user (or, in this case, the water advocate) is always responsible and accountable for their work. 

Example from the Network

“Technology is an enabler, not an excuse for lapses in judgment or accountability.” 

Advocates who use GenAI on a regular basis say that they turn off settings which would allow the tool to improve using their inputted data. (Note that this is impossible to turn off entirely.) Policies also state that staff must acknowledge AI use in heavily generated content, adding language to generated text: This report was prepared with the assistance of AI tools and has been reviewed for accuracy by [staff at organization].” 

At some larger organizations, IT is actively monitoring staff’s internet activity to ensure internal compliance with guidelines. 

Reducing Harm and Standing in Your Values

More than a few internal policies address the contradiction of acknowledging internal generative AI use while also advocating against development of new data centers. There is a kind of standard language in these policies that states that AI use must support the organization’s mission and values. As you consider building a policy for your own organization, we recommend working to define, with specificity, how AI can support the work of an organization that represents vulnerable communities and ecosystems.  

Example from the Network

“As an environmental nonprofit organization, we recognize that AI technologies require significant energy and water resources. Individuals choosing to use AI tools are encouraged to do so thoughtfully and efficiently in support of organizational work.” 

All respondents with existing policies noted that their organizations are working to reduce the water and energy use of GenAI. For example, one organization prioritizes use during California’s Renewable Energy Hours and another reminds employees that generating text is much more energy and water intensive than summarizing text.

Keeping the Work Human

Much of our water work is centered on trust-building and relationships between people and the natural world. One respondent noted that this connection is a distinctly human endeavor, and it is important that it remains intact for the integrity of our work.  

If we are to use GenAI in a way that supports our organizations’ missions and values, as all claim to do, we must consider the broader impacts of turning pieces of our work over to a tool built on intellectual and cultural extraction, and be sure that we are keeping all deliberation and decision-making in the hands of humans: 

Example from the Network

“AI tools must not be used to make final decisions—whether related to employment, advocacy positions, policy determinations, or strategic organizational actions—without independent human judgment, review, and approval.” 

Furthermore, at a time when AI tools are threatening employment, we must consider the ethics of outsourcing our work to these tools. Many organizations’ policies reference enhancing, not replacing, human work: 

Example from the Network

“Like other technological tools that have come before such as computers or smartphones, AI tools should be used to support and complement human expertise, judgment, and creativity, but should never replace the scientific rigor, ethical reasoning, and mission commitment that define [the organization]’s work. AI tools should be used to enhance, not replace, what humans do. No layoffs due to AI implementation.” 

It’s easy to feel like there is significant pressure to optimize our work and productivity through GenAI, but there are several organizations reminding us that it is okay to slow down. We can wait to adopt new tools until we know the full extent of their impact. As one organization simply states, “Until a fuller, more robust policy can be developed, our organization is intentionally not utilizing or subscribing to any AI platforms or programs.” 

Example from the Network

“I would like to see use of AI reduced/restricted. I believe that as conservation organizations, it is imperative that we use AI consciously and intentionally, if at all. We cannot be passive about the use of AI/chatbots and should decide what services they provide are worth the cost (if any). The energy and water costs enough should give us pause before using AI, not to mention the data privacy and ethical concerns.” 

Looking Ahead

Only 34% of organizations that responded to River Network’s survey have developed an internal AI policy at this time, but there is appetite for clearer guidance and organizational policy development alongside ongoing concerns about the social and environmental effects of AI use and data center development. 

River Network is among the organizations that have not yet developed an internal policy, but this is top-of-mind for us internally. We are open to sharing what we learn through the process. 

In addition to the example AI policy language we included above, here are more resources: 

Looking for resources on data centers? Find maps, local advocacy recommendations, ordinances, and regulations, model and pending/passed legislation, reports, and news articles here.

Thanks to those of you who took the time to participate in this survey. 

Leave a Comment