So Your Board Said Yes to AI. Here's How Not to Regret It.
My non-negotiables if you are going to use AI in the boardroom
Last week, I made my position clear: AI notetakers in nonprofit board meetings are a governance risk you shouldn’t take on. Discovery exposure, broken trust in the boardroom, potential legal violations… the potential problems are serious.
But I’m also a realist. Even with my warnings, some of you are going to use AI tools anyway. Maybe your board secretary already decided and this ship has sailed. Maybe the executive director demoed a tool at the last retreat and people loved it. Maybe you’ve been using one for months and are just now reading this wondering if you’ve made a terrible mistake.
(You may have. But let’s fix it.)
Below I talk about how to use AI tools while minimizing legal and governance risk. If you're still on the fence, last week's piece lays out why I'd still steer you away entirely.
Bottom line, up front: If you’re going to use AI in board meetings, these are my recommended essential protections you cannot skip.
Jump:
🔍Vet Your Vendors Like Your Risk Depends on It (Because It Does)
🔒Make Sure This Doesn’t Conflict With Your Existing Data Privacy Commitments
Up next in my AI & Nonprofit series…
The Non-Negotiables
📄AI Transcripts Are NOT Your Official Minutes. Full Stop.
AI tools should only produce draft materials for reference, and should never substitute for proper board minutes. Your board secretary or governance professional should still prepare official minutes that:
Document only essential information (quorum, decisions, due diligence, resolutions)
Exclude preliminary discussions and speculation
Maintain confidentiality of sensitive matters
Meet your state’s legal requirements for nonprofit records
Why does this matter? Because if an AI transcript becomes your official record, you’ve massively expanded what’s discoverable in litigation.
⚡The action: Write this into your AI usage policy explicitly. AI transcripts are working documents. Official minutes are prepared by a human.
🗑️Immediate Destruction After Approval
Once your board approves final minutes, there is no legitimate business reason to keep the raw recording or AI transcript. None. .
Not “eventually.” Not “when we get around to it.” Immediately.
I know it feels wrong. What if someone has a question? What if there’s a dispute? Here’s the thing: your approved minutes exist precisely to answer those questions. That’s what they’re for. Keeping transcripts “just in case” creates more things that can go wrong.
Auto-delete features in your software are not good enough. You need a documented process where a human confirms deletion actually happened, and that confirmation goes in the meeting record.
⚡The action: Your record retention policy needs explicit language requiring destruction of transcripts upon minutes approval. Assign someone responsibility for confirming it and track it.
✅All-Party Documented Consent, Every Time
About a dozen states require all-party consent to record a conversation. If you’re in one of those states, or if participants are calling in from one, recording without consent is potentially a criminal violation. What documented consent actually looks like in practice:
Announce at the start of every meeting that AI recording is in use.
Get explicit verbal confirmation from each participant (not just silence).
Document who consented in the meeting record.
If someone joins late, pause and get their consent before continuing… yes, even if it’s awkward.
Make it clear that anyone can object and the recording will stop.
⚡The action: Build a consent script into your meeting agenda template. Make it routine so it doesn’t feel like a big deal.
🏢Enterprise-Grade Tools Only
Free AI tools and standard consumer platforms are not appropriate for board meetings. Consumer AI tools (the free versions, the standard tiers) often explicitly retain your data, use it to train their models, and may share it with affiliates. Your board’s discussions about strategy, donors, personnel, and legal matters would become training data for a profit-driven company.
What you need from any tool you use:
End-to-end encryption.
Explicit no-training-on-data policies (your conversations won’t train their AI).
Data residency controls (you know where data is stored geographically).
Security certifications (SOC 2, ISO 27001, etc.).
Contractual right to data deletion (not just user-side deletion).
No third-party data sharing.
⚡The action: If you’re currently using a free or consumer tier of any AI tool in board meetings, stop. Evaluate enterprise options before your next meeting.
🔍Vet Your Vendors
Third-party vendors are one of the most common sources of data breaches and privacy violations. And here’s the thing: if your vendor mishandles your data, you are still on the hook legally. ‘Our vendor did it’ is not a defense.
Before adopting any AI tool:
Read the complete privacy policy and terms of service
Understand exactly how long they retain data and how deletion actually works.
Verify their security protocols and certifications.
Confirm compliance with relevant regulations for your sector (HIPAA if you’re in healthcare, FERPA if you’re in education, applicable state privacy laws everywhere).
Why this matters: Most data breaches and privacy violations happen through third-party vendors. You’re legally responsible for how your vendors handle your data.
🔒Make Sure This Doesn't Conflict With Your Existing Data Privacy Commitments
There is a good chance your organization already has data privacy commitments (to funders, to clients, to beneficiaries, to employees, etc). AI use in board meetings needs to be consistent with all of them. This means thinking through:
Data minimization: Are you collecting more than you need to?
PII protection: Are donor names, client details, employee information showing up in transcripts?
Regulatory obligations: Healthcare organizations, educational institutions, and social service agencies face stricter rules that may conflict with AI transcription entirely.
Funder and partner commitments: Some grants and partnerships include data privacy requirements you may not remember agreeing to.
⚡The action: Have someone review your existing privacy commitments before you finalize your AI policy.
📋Write a Policy.
“We’ll be careful” is not a policy. Policies have specificity, accountability, and teeth. Your written AI transcription policy needs to cover:
What can and cannot be recorded:
Executive sessions: never
Personnel matters: never
Conversations with legal counsel: never
Sensitive donor or client discussions: never
Routine business meetings: only with unanimous consent
Who can authorize recording: From leadership to individual directors
How transcripts are controlled: Who has access, how they’re stored, how (and to whom) they can be distributed
When transcripts are deleted: Define this specifically. “After approval” needs to be defined —- 24 to 48 hours.
Accountability: Who is responsible for compliance? What happens when the policy is violated? When does the policy get reviewed?
⚡The action: This policy needs to go through your full board for adoption. Everyone who participates in meetings should be bound by the same rules.
👁️Human Review Is Not Optional
AI transcription is impressive, but it makes mistakes. It misattributes quotes. It mishears names. It transcribes things that were clearly off the record or were part of a sidebar conversation.
More importantly, AI has no judgment about what should and shouldn’t appear in a written record. A human who understands governance is more likely to. Every transcript must be:
Reviewed by a human who understands governance requirements
Edited for accuracy (AI makes mistakes constantly)
Checked for proper attribution (AI misattributes speakers)
Redacted for sensitive content before any distribution
⚡The action: Assign this review responsibility to a specific person with governance knowledge (your board secretary, your governance committee chair, or an outside governance professional, etc.).
Before You Move Forward, Answer These Questions Honestly
Can you actually implement all of this? Can your organization, with your current capacity, meet all these requirements consistently? Including during your busiest periods when shortcuts are most tempting?
Do you have the budget? Enterprise AI tools cost more than consumer versions. In addition to software fees, you should account for legal review costs for vendor contracts, policy development, and compliance monitoring.
Who owns compliance? Someone specific needs to be accountable, by name and role.
Have you talked to your insurance carrier? Does your D&O coverage address AI-related governance failures?
What’s your plan when something goes wrong? Maybe a transcript gets forwarded too widely. A recording captures a privileged attorney-client conversation. A vendor has a breach. You discover you’ve been violating consent laws for six months. What do you do?
Is it actually worth it? Honestly calculate the time you’d save against the full cost of doing this right … the enterprise tools, the legal review, the compliance monitoring, the staff time. Then compare that to what it would cost to invest in training someone to write better minutes.
If you can’t answer all of these questions confidently, you’re not ready to move forward.
🎯The Takeaway
I said last week you shouldn’t use AI notetakers in board meetings and I stand by it. But if your board has decided to proceed anyway, do it right. My non-negotiables above are my professional opinion on the minimum required to avoid serious legal exposure.
Governance failures are expensive. Do the work now.
💡P.S.! Next up in my AI & Nonprofit series
How to build your AI policy from scratch … and how to get ahead of the AI tools quietly embedded in platforms your organization already uses. Subscribe for free to follow along.
🔗References & Continued Reading
TeDesco, B. S., Yurko, B. J., By: Chris Cannon & Michael Felberbaum, & Dressely, B. D. (2025, September 29). Responsible ai: How donorsearch is Shaping Nonprofit Tech. DonorSearch. https://www.donorsearch.net/resources/responsible-ai/
Polanco, H., Tiernan, K., & Lodewyck, S. (2025, May 6). A guide to nonprofit AI implementation for nonprofit leaders and staff. BDO. https://www.bdo.com/insights/blogs/nonprofit-standard/a-guide-to-nonprofit-ai-implementation-for-nonprofit-leaders-and-staff
How to ethically use AI for nonprofit organizations. Orr Group. (2024, July 29). https://orrgroup.com/your-roadmap-to-ethical-ai-organizational-readiness/
AI regulations: What Nonprofit Boards Need To Know. BoardEffect. (n.d.). https://www.boardeffect.com/blog/regulations-ai-nonprofits/
Deloitte. (n.d.). AI governance for Board members. Deloitte. https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/articles/generative-ai-governance-risk-management.html

