Make it a team norm
Individual caution fades. A shared, written team norm is what keeps safe use in place after the workshop ends.
Draft the rule in five lines
- Alone, five minutes: everyone writes five lines on what staff may do with AI and what they may never do.
- Read them out. Keep only the lines that more than one person wrote.
- For each surviving line, name who answers questions about it. That sheet is the first draft of your team norm.
What did you write that nobody else did, and why does it matter to you?
- Turn the workshop into a written acceptable-use policy so safe practice survives after people forget the details. A shared, written norm holds up when one person leaves or a new hire arrives.
- State plainly what AI is approved for at your agency: drafting a letter or email, translating a gist to get started, summarizing a long document, and organizing next steps.
- State what to always verify before acting: any name, number, date, deadline, eligibility rule, or legal or medical detail, checked against an official source or a colleague.
- State what never goes into a chatbot: client names, dates of birth, addresses, case or A-numbers, immigration details, or anything that could identify a client. Consumer AI tools are not built to hold sensitive information.
- Put the interpreter rule in writing. Machine translation can help staff get started, and a qualified interpreter handles consent, rights, safety, and any high-stakes conversation.
- Name an internal point person for AI questions, and name what gets escalated to a supervisor, so staff are not left guessing where the line is.
- Add a short AI check to regular supervision, revisit the ground-rules card, and begin with low-risk tasks before using AI in high-stakes casework.
A new practice does not hold on its own. A review of the research on program sustainability found that the gains from training often fade once the initial push ends, and that lasting use depends on building the practice into an organization's routines (Wiltsey Stirman and colleagues, 2012). Writing this workshop into a shared norm is how the caution you built outlasts the training.
Whether staff follow a practice depends on the signals around them. Work on evidence-based practice shows that a supportive organizational climate, the shared expectations and support that make a practice the way things are done here, predicts whether frontline staff actually use it (Ehrhart and colleagues, 2014). A short policy that leadership stands behind turns careful AI use into the expected norm.
The parts of a norm that fade fastest are the do-not-do rules. When frontline health workers were reassessed after training, they kept most steps but scored lowest on the ones that told them not to act, and refresher training was recommended (Gobezayehu and colleagues, 2014). For AI use, the never-enter and never-use-it-for rules are the ones to put in writing and revisit, because they slip first.
Nonprofit AI guidance points the same way. NTEN and TechSoup both offer acceptable-use policy templates that spell out approved uses, what to verify, and what data never goes into a tool that was not built for sensitive information (NTEN Generative AI Use Policy Template; TechSoup). Guidance for refugee resettlement programs adds that agencies should start with low-risk administrative work and keep a person checking the output before AI goes anywhere near client-facing tasks (Switchboard).
Adopting a norm also means naming who owns it. Legal aid guidance stresses testing a tool and keeping human review before it touches real cases (Legal Services Corporation), and equitable-adoption work with nonprofits finds that many agencies want to use AI well but lack the internal structure to do it safely (Project Evident and Stanford HAI). Naming an internal point person and adding a short AI check to supervision gives the norm a place to live.
What your one-page AI policy should cover
- What AI is approved for: drafting letters and emails, translating a gist to get started, summarizing long documents, and organizing next steps.
- What to always verify before acting: any name, number, date, deadline, eligibility rule, or legal or medical detail, checked against an official source or a colleague.
- What never to enter: client names, dates of birth, addresses, case or A-numbers, immigration status, or anything that could identify a client, because consumer AI tools are not built to hold sensitive information.
- The interpreter rule: machine translation can help staff get started, and a qualified interpreter is used for consent, rights, safety planning, and any high-stakes conversation.
- Who to ask when unsure, and what gets escalated to a supervisor, named by role so nobody has to guess.
- Which tools and languages the policy covers, named specifically, since your agency uses particular tools and serves particular client languages.
- Who owns the policy and when the team will review it, so it stays current as tools and rules change.
Individual caution fades; a written norm holds
A resource navigator turns the workshop into a team norm
- A small immigrant services agency finishes the workshop. People are careful at first, then a new caseworker starts and pastes a client's full name and case details into a chatbot to speed up a letter, because nobody had told her the rule.
- The team sits down and writes a one-page policy that lists what AI is approved for, what to always verify, what never gets entered, when a qualified interpreter is required, and who to ask when unsure.
- They name the intake supervisor as the point person for AI questions, and they agree what gets escalated to her.
- The supervisor adds one line to regular supervision: did AI touch any of this, and if so, what did you verify. The ground-rules card goes up by the shared workstation.
- They begin with low-risk tasks like drafting and summarizing before allowing AI near eligibility decisions or immigration matters.
- Later the team reads the card together again. The never-enter rule had started to slip, so they restate it and add a plain example for new hires.
Fill in your team's ground rules
As a team, fill in the ground-rules card at the end of this page together. Add the tools and languages your agency actually uses. Each person names one thing they will do differently starting Monday, and the team picks where to post the card.
Draft your one-page AI use policy
Split into small groups and give each group one section of a policy to draft: what AI is approved for, what to always verify, what never gets entered, the interpreter rule, and who to ask when unsure. Use a public template such as the NTEN or TechSoup policy guide as a starting point, then rewrite each line in your agency's own words and name the tools and languages you actually use. Bring the sections together into a single page, decide who will own it, and agree on when the team will look at it again.