Association AI Policy: What to Say When Your Board Asks

Sooner or later, at a board meeting, someone asks it. Maybe a director who read something alarming, maybe one who read something excited. "So what's our AI policy?"
This post is about having a good answer ready, and it's the third in the series. The first covered the public site and member area, and the second covered the member experience. This one is the governance that makes both defensible. A useful association AI policy is short, specific to New Zealand, and backed by controls rather than intentions.
Most organisations are doing AI by accident
The reason this matters isn't abstract. The 2026 Nonprofit AI Adoption Report from Virtuous and Fundraising.AI, surveying 346 US nonprofits, found 92% were using AI. Only 4% had documented, repeatable workflows. 81% were using it individually with no shared process at all, and 47% had no AI governance policy.
So the typical picture isn't an organisation that decided to adopt AI. It's an organisation where several people quietly started using it and nobody wrote anything down. A board is right to ask for better than that, and the good news is that boards are already onside: in Momentive Software's 2025 Association Trends Study, reported by Associations Now, 61% of association professionals said their board supports AI use, up from 23% the year before. The question in the room is no longer whether, it's under what rules.
Start with the Privacy Act, because that's the real question
In New Zealand the starting point isn't a software setting. It's the law.
The Privacy Act 2020 and its 13 Information Privacy Principles apply whenever you collect, use or share personal information. They're technology-neutral, so they apply to an AI tool exactly as they apply to a spreadsheet. The Office of the Privacy Commissioner published specific guidance, "Artificial intelligence and the Information Privacy Principles", on 21 September 2023. It reads almost like a board checklist:
- Senior leadership approves the use of an AI tool, having actually considered the risks.
- Do a Privacy Impact Assessment before you start, not after.
- Ask whether it's necessary and proportionate, or whether something simpler would do the job.
- Be transparent with people that AI is being used.
- Keep a human in the loop for decisions affecting people.
- Minimise the data you put into the tool, and consider engagement with Māori where that's relevant.
The single biggest risk the Commissioner flags is that personal or confidential information entered into a generative AI tool may be retained or disclosed by the provider. Everything below exists to contain that one risk.
That list is most of your policy already. If your board adopts those six points as organisational rules and you can show how each one is enforced, you're ahead of the roughly half of the sector running with no AI governance policy at all.
The four controls that turn an association AI policy into practice
A policy nobody can enforce is a document, not a control. These four are what to ask for, on any platform:
- Filtering what leaves. Automatic checks that strip or block personal information, email addresses, phone numbers and card numbers, before anything is sent to an AI provider. This answers the Commissioner's main concern directly, and it shouldn't depend on staff remembering.
- Validating what comes back. Screening AI output against your content standards before it reaches a person, let alone a member.
- An audit trail and cost visibility. You should be able to answer "what did the AI do, when, and what did it cost" without guessing. Boards ask the cost question more often than the ethics question, and an uncapped usage bill is a genuine risk on a fixed budget.
- Human approval gates. A structural requirement that AI output is reviewed before it publishes or sends. Not a cultural expectation, an actual gate.
Ask your provider which of the four you have. If the answer is "we trust our staff", you have none of them.
Worth knowing that this is achievable rather than aspirational, and not only at enterprise budgets. On open-source stacks like Drupal, most of these now ship as free, ready-made configuration. There's a PII guardrails recipe that pattern-matches contact details and card numbers in both directions, on the way out and on the way back, with no extra usage cost. AI Observability logs every prompt and response with token usage and cost, and exports to standard monitoring tools. AI Metering adds cost estimation and per-user quotas so the bill can't run away. That matters for the board conversation because it moves your answer from "we have a policy" to "we have a control", and it does it without a budget line.
One thing that changed in May 2026
Worth flagging because it's new and it catches membership organisations specifically. A new principle, IPP3A, came into force on 1 May 2026. It covers indirect collection: when you collect someone's personal information from a source other than that person, you now have to take reasonable steps to make them aware of it, as soon as reasonably practicable.
Associations do this constantly. Delegate lists from a partner event, member details supplied by an employer paying for a corporate membership, contacts imported from an affiliated body. It applies to indirect collections made on or after 1 May 2026, so it isn't retrospective, but it does mean your data intake process needs a notification step. That's a governance question with or without AI, and it's the sort of thing worth handling in the same conversation.
How to answer a member who objects
Eventually a member emails to say they don't want AI touching their data. A good answer has three parts:
- Point to your written AI policy and the Privacy Act principles it follows.
- Explain that a person reviews AI output before anything is sent or published.
- Offer a real opt-out from AI-assisted personalisation, keeping them on standard communications.
The third one only works if your system can actually honour it, and that's worth proving rather than assuming. On the NZSAE portal we found the membership platform's API had no way to trigger a password reset, which is about as table-stakes as a flow gets. It wasn't a crisis, because we found it during planning and designed a hand-off around it. It would have been one if we'd promised members something first and discovered the gap afterwards. Same test here: before you offer an opt-out in writing, have someone demonstrate the system can action it.
What not to do
Being specific about the "no" list is what makes a policy credible.
- No auto-sent AI summaries. Every AI-generated summary, digest or reply gets human sign-off before it reaches a member. The confident-errors problem is reason enough on its own.
- No general-purpose member chatbot, for now. A bot with broad access to member data and free rein to answer anything is the highest-risk, lowest-reward option on the table, and the technology that would power it well is still immature everywhere. Say no this year and revisit.
- No pasting member data into consumer AI tools. Given the adoption gap in the first post, some of your staff are already using these tools privately. Your policy has to name what's safe, like public content and marketing copy, and what's off-limits, like member records, financials and anything out of a board paper. The four controls above all live in your website and membership platform, so not one of them reaches this. It is the gap only a written rule closes, it is the most likely place a breach actually happens, and it costs nothing to fix.
What this costs
The Privacy Impact Assessment is a half-day of structured thinking rather than a consultancy project, and the Privacy Commissioner publishes the questions for you. The written policy is about two pages. The technical controls run from free and already available through to a small configuration project, depending on what you're on.
The real requirement is a short written policy your board adopts, and then the discipline to keep the human-in-the-loop rules you wrote down. Both are free. Neither is automatic.
Closing the series
That's the three. AI as roughly half an extra person in the back office, relevance over volume for members, and governance that lets the board say yes without crossing its fingers. None of it needs a bet on hype, and none of it needs a platform change to get started. The whole series is under Web for Associations.
If your board is asking the AI policy question and you'd like help drafting an answer that fits the Privacy Act 2020 and your risk appetite, get in touch. It's a short piece of work and you'll own the result.
Get the newsletter
Practical web and technology advice for associations, fortnightly. No spam, unsubscribe anytime.