Does Your Museum or Nonprofit Have an AI Policy Yet?

Has your museum, archive, library, historical society, or nonprofit developed an artificial intelligence policy?

If so, what prompted it? Was it written because staff were already using AI tools? Because leadership wanted to encourage innovation? Because there were concerns about privacy, accuracy, copyright, or public trust? Or because the institution realized that AI was entering the workplace faster than formal policies could keep up?

If your organization has a policy, what does it contain?

These are questions more cultural and nonprofit institutions should be asking now.

AI tools are no longer theoretical. Staff are using them to draft emails, summarize documents, generate social media copy, revise grant language, create image descriptions, brainstorm exhibit ideas, translate text, clean up metadata, and support research. Used carefully, these tools can save time and help staff manage workloads that are often already stretched thin.

But museums are not ordinary workplaces. They are built on authority, evidence, interpretation, stewardship, and public trust. They hold collections, records, donor information, community stories, cultural knowledge, restricted materials, unpublished research, institutional history, and objects that may be understood by the public as evidence of the past.

That makes AI use in museums more complicated than simply asking whether a tool is efficient.

The central issue is not whether AI can help museums work faster. It can. The more important question is whether museums have defined where AI assistance ends and museum authority begins.

That is where policy matters.

An AI policy does not need to ban AI. In most cases, that is neither realistic nor useful. But it should define what is acceptable, what requires review, and what should not be done at all.

For museums, the greatest risk is not that AI will write an awkward sentence. The greater risk is that AI-assisted work may appear authoritative when it has not been verified. AI can produce polished language that sounds confident even when the content is incomplete, misleading, or false. In a museum setting, that can be dangerous.

A published error in an exhibit label, online exhibit, collection record, catalog entry, press release, educational material, social media post, or research response does more than create a correction problem. It raises doubt about the institution’s knowledge and expertise.

Museums ask the public to trust them with history, memory, evidence, objects, stories, and interpretation. If AI-assisted content introduces wrong dates, false attributions, fabricated sources, incorrect object identifications, invented provenance, inaccurate technical descriptions, or oversimplified cultural interpretation, the damage may not stop with that single mistake. It can make audiences wonder what else the institution has gotten wrong.

That is the real risk.

AI does not have to be malicious to cause harm. It only has to be convincing, fast, and unchecked.

This is especially important in collections and archives work. AI may be useful for first-draft image descriptions, accessibility text, transcription cleanup, metadata suggestions, or identifying repetitive data issues. But those uses must remain draft support until reviewed by qualified staff.

AI should not be used to authenticate objects, assign value, determine provenance, make acquisition or deaccession decisions, replace collections review, rewrite donor history, create object histories without evidence, or respond to research inquiries in ways that imply the museum has verified information when it has not.

Museums also need to be careful with the use of public-facing AI systems and private or confidential information. The risk is not simply that AI will “put something on the internet.” The concern is that once information leaves the institution’s controlled environment, the museum may lose control over where that information goes, how long it is retained, who may review it, whether it is processed by third-party systems, and whether it may be used to improve the service.

For museums, that matters. Donor records, accession information, loan agreements, board materials, restricted collection locations, unpublished research, private correspondence, internal reports, object condition concerns, provenance questions, insurance information, and non-public collection records should not be casually pasted into public AI tools. If an institution would not email the information to an outside company without a contract or review, it should not be placed into a public AI system without the same level of care.

This is not paranoia. It is basic stewardship.

A useful museum AI policy should address several basic questions:

What types of AI use are allowed for routine work?

What types of work require human review before being shared or relied upon?

What information should never be entered into a public AI system?

How should AI-assisted public-facing content be reviewed or disclosed?

Can AI be used with collections records, donor records, restricted material, unpublished research, personnel information, or financial records?

Can AI be used to draft exhibit text, marketing copy, educational material, image descriptions, or collection summaries?

Who is responsible when AI-assisted content contains errors?

Can AI be used for decision-making, or only as a support tool?

How does the institution protect copyright, privacy, cultural sensitivity, historical accuracy, professional authority, and public trust?

These questions matter because AI can create a false sense of authority. It can summarize quickly, but it can also invent facts. It can produce polished language, but polished language is not the same as verified information. It can help draft interpretive text, but it cannot replace curatorial judgment, archival ethics, collections knowledge, lived experience, or institutional responsibility.

This concern also extends beyond collections departments.

In accounting and finance, AI use can create legal, privacy, and compliance risks if staff enter budgets, audits, payroll information, banking information, vendor contracts, donor financial records, or restricted financial reports into unapproved systems. AI should not be used to process payroll, interpret audits, analyze banking information, summarize restricted financial records, or prepare financial explanations without accounting review and approved safeguards. Financial information is not just administrative data. It involves internal controls, donor trust, compliance, and institutional accountability.

In HR, AI use can create serious risk if it involves personnel files, employee medical or leave information, disciplinary matters, workplace complaints, performance evaluations, hiring materials, or internal investigations. AI should not be used to make or justify employment decisions, evaluate staff performance, summarize workplace complaints without safeguards, draft disciplinary action without review, or process sensitive personnel records through unapproved systems. These are not routine shortcuts. They involve privacy, liability, workplace fairness, and employee trust.

In creative, exhibits, and marketing work, AI may be useful for brainstorming, drafting, accessibility support, campaign planning, and early-stage design concepts. But creative work still carries the museum’s voice, reputation, and authority. AI-generated exhibit graphics, promotional images, donor appeals, social media posts, public statements, educational materials, and marketing campaigns need review before release. Museums should be especially careful that AI-generated images or text are not mistaken for historical evidence, collection material, documentary photography, or verified interpretation.

A strong AI policy should apply across the institution. It should not be limited to junior staff or one department. Employees, volunteers, interns, contractors, consultants, department heads, senior leadership, and board members should all understand the same expectations when using AI for institutional work.

That point matters. AI use is not only a technology issue. It is a governance issue.

If leadership uses AI casually with confidential information, staff will assume the same behavior is acceptable. If collections, archives, exhibits, marketing, education, development, accounting, and HR each use AI according to their own informal rules, the institution ends up with uneven risk. If no one defines the boundaries, informal practice becomes institutional practice whether anyone approved it or not.

A basic policy protects the organization. It protects staff. It protects leadership. Most importantly, it protects the public trust that museums and nonprofits depend on.

The goal should not be fear. The goal should be responsible use.

AI can be useful. It can help small teams move faster, improve accessibility, support writing, identify repetitive tasks, organize information, and make complex material easier to work with. But the use of AI should be intentional, reviewed, and appropriate to the institution’s mission and responsibilities.

For museums and nonprofits, a good starting point may be simple:

Low-risk uses may be allowed.

Sensitive uses require review.

Confidential, restricted, legal, personnel, HR, donor, accounting, financial, security, creative, and high-risk collections information should not be entered into public AI tools.

AI should not replace human judgment.

AI should not make or justify collections, historical, legal, employment, financial, donor, creative, or governance decisions.

Public-facing AI-assisted work should be reviewed before release.

The person, department, or institution using AI remains responsible for the final product.

The rise of AI does not remove the need for professional standards. It makes those standards more important.

So I am curious: has your museum or nonprofit developed an AI policy yet? If so, what did you include? If not, who is responsible for starting that conversation?


Originally published on LinkedIn on July 6, 2026. Read the original article on LinkedIn.

Related insights: What AI Misses Between Policy and Practice · One Institution, One Voice