92% of Nonprofits Use AI. 47% Have No Policy. NIH Will Not Consider an Application Substantially Written by AI.

Executive Summary

  • NIH policy notice NOT-OD-25-132, effective September 25, 2025, states that NIH will not consider applications substantially developed by AI to be the original ideas of applicants. Discovery after an award can lead to referral to the Office of Research Integrity, disallowed costs, withheld awards, suspension, and possible termination. This is an NIH policy for NIH research applications, not a government wide grant rule.
  • Private foundations are far behind the federal agencies. In Candid’s 2024 survey of 527 foundations, 67 percent were still undecided about whether to accept applications containing AI generated content, and 57 percent did not know whether they had already received one.
  • The 2026 Nonprofit AI Adoption Report found 92 percent of nonprofits using AI while 47 percent have no AI governance policy at all. That gap, not the technology, is what creates the exposure.
  • Two thirds of nonprofits held at least one government grant or contract in 2023, counting federal, state, and local awards. Public funding does not by itself trigger NIH policy, but it does mean most nonprofits sign government award terms every year without reading them for AI provisions.
  • The fix is unglamorous and cheap: a short written AI use policy, a standard disclosure sentence, and a record of who verified each AI assisted section before submission.

1. What the 2026 grant AI rules actually require

There is no single government wide grant AI rule in 2026. Requirements are set agency by agency and funder by funder, and the strictest published policy belongs to NIH, which applies it to NIH research applications rather than to grants generally. What travels across every funder is the underlying expectation: that a human originated the substance, that facts and citations are verified, and that you can describe how AI was used if you are asked.

That distinction matters, because most nonprofit leaders are either waiting for a government wide rule that has not arrived or assuming the NIH policy binds funders it does not reach. Neither posture is safe. The practical unit of compliance is the specific funding opportunity in front of you and the certifications you sign with it.

The broader federal rulebook is being rewritten, and notably without an AI provision. The Office of Management and Budget published a proposed rule, Regulation for Federal Financial Assistance, at 91 FR 32198 on May 29, 2026. Comments were due on or before July 13, 2026, and OMB states that it proposes to issue a final rule effective by October 1, 2026 so that a single set of government wide requirements applies to awards made during fiscal year 2027. The phrase artificial intelligence does not appear anywhere in the proposed rule. A June 5, 2026 client alert from Crowell & Moring reaches the same reading. Check the docket for the final rule before relying on the effective date, because a proposed rule can change or slip.

So the rules that bind you today are agency policies, funder application terms, and the ordinary law of misrepresentation. That is a thinner rulebook than people expect, and a more demanding one, because thin rules get enforced through misconduct findings and award actions rather than through tidy compliance checklists.

The audience is larger than the research world, even though the NIH rule is not. The Urban Institute found that in 2023, two thirds of nonprofits received at least one government grant or contract, government sources supplied roughly one quarter of revenue for the average nonprofit, and about two in ten nonprofits drew more than half their revenue from government. That figure counts federal, state, and local awards together, and public funding does not by itself pull you under NIH policy. It does mean most nonprofits sign government award terms every year, and those terms are where agency specific AI expectations actually appear.

2. What NIH means by substantially developed by AI

NIH means that the intellectual substance of the application has to be yours, and it has said so in binding policy language rather than guidance. Notice NOT-OD-25-132, titled Supporting Fairness and Originality in NIH Research Applications, was released July 17, 2025 and took effect September 25, 2025. Its operative sentence is short: NIH will not consider applications that are either substantially developed by AI, or contain sections substantially developed by AI, to be original ideas of applicants.

Read that carefully, because the clause most people skip is the second one. It is not only a whole application problem. A single section substantially drafted by a model is enough to put the application outside what NIH will consider. NIH has published no word count threshold, no percentage, and no safe harbor, and it has not announced a formal test for what counts as substantial. Do not fill that silence with a number of your own. The workable response to an undefined standard is a conservative and documented one: make sure human researchers originate, evaluate, and take responsibility for the scientific ideas, methods, claims, facts, and citations in the application.

The notice does leave room for ordinary tool use. NIH’s own Extramural Nexus explainer, published July 31, 2025, says applicants may use AI in limited aspects to reduce administrative burden while preparing applications, provided they stay mindful of concerns around research misconduct and lack of originality. Editing human written text for readability, formatting, and grammar are the kinds of limited administrative uses that language contemplates. Treat them as lower risk rather than as approved safe harbors, because the applicant still carries responsibility for accuracy, originality, confidentiality, and the terms of the specific funding opportunity.

The consequences are post award, not just pre award

The enforcement language is where this stops being an editorial preference. If AI development is discovered after an award is made, NIH may refer the matter to the Office of Research Integrity to determine whether there is research misconduct, while simultaneously taking enforcement actions including disallowing costs, withholding future awards, suspending the grant wholly or in part, and possible termination.

Those are the same tools an agency uses for financial misconduct. A university research office summary from Ohio State, published August 22, 2025, reaches the same reading and pairs the AI provision with the notice’s other change: a cap of six new, renewal, resubmission, or revision applications per principal investigator per calendar year, excluding T series training grants and R13 conference grants, with the full calendar year restriction applying from January 1, 2026.

GOVERNANCE INSIGHT

The risk is not the tool. It is the absence of a record.

If a funder asks how AI was used on an application you submitted eight months ago, the answer has to come from a file, not from memory. Organizations that lose these arguments are rarely the ones that used AI badly. They are the ones that cannot show what a human did.

3. Where private foundations actually stand right now

Private foundations have not settled on a position, and the honest summary is that most of them do not yet know what they think. Candid surveyed 2,156 US foundations for its 2024 Foundation Giving Forecast Survey and received 527 responses, a 24 percent response rate. Asked whether they would accept grant applications containing content created by generative AI, one in ten said yes, 23 percent said no, and a full 67 percent were undecided.

The awareness numbers are more striking than the policy numbers. In the same survey, 57 percent of grantmakers did not know whether they had received applications created with generative AI, 42 percent believed they had not, and only four respondents, under 1 percent, said they had. The survey does not establish how many AI assisted proposals funders actually received. What it establishes is that most funders cannot tell, which is a different and more useful fact: you should not assume a funder’s silence reflects a considered position, and you should not assume non detection will last.

Grantmakers are also not, at least yet, automating their side of the process. Candid’s follow up analysis published November 20, 2025 reported that 97 percent of responding foundations do not currently use AI to screen applications, with 1 percent saying yes and 2 percent unsure. Looking a few years ahead, 66 percent said no, 3 percent said yes, 19 percent said maybe, and 12 percent did not know. Roughly a third have not ruled it out.

For a development director, the practical translation is this. You cannot rely on a funder having published a rule, because most have not. You also cannot rely on the absence of a rule as permission, because undecided funders decide, and they tend to decide after something goes wrong. The defensible position is to behave as though disclosure will be asked for, and to make that cost you almost nothing.

4. The governance gap that turns a writing habit into a finding

The gap is between how many nonprofits use AI and how many have written down what they allow. The 2026 Nonprofit AI Adoption Report, a benchmark study of 346 nonprofits released by Virtuous and Fundraising.AI on February 16, 2026, found 92 percent of nonprofits using AI and 47 percent with no AI governance policy.

Two other findings from the same study explain why the gap persists. Only 7 percent reported major improvements in organizational capability, and 81 percent said staff use AI individually without shared workflows. That combination is the shape of what governance people call shadow adoption. Individual use, no shared process, no policy, and no record.

The reading that follows is our interpretation rather than a survey finding, but it is what shadow adoption reliably produces. When a grants manager pastes a program description into a chatbot on a Thursday night before a deadline, three things can happen at once that nobody logged. Program data may leave the organization’s control. The output may contain a statistic or citation nobody checked. And the organization has no way, later, to describe what happened.

Boards should recognize this pattern, because it is the same one that produced conflict of interest policies twenty years ago. The IRS already asks every filing organization on Form 990, Part VI whether it has adopted a written conflict of interest policy at Section B, Line 12, a written whistleblower policy at Line 13, and a written document retention and destruction policy at Line 14. The National Council of Nonprofits lists these among the five policies the Form 990 asks about. None of them is required by federal tax law simply because the form asks. Nearly every well run nonprofit has them anyway. Answering no is not unlawful and is not a finding, but it does invite questions from board members, donors, watchdogs, funders, and regulators about governance maturity. There is no AI line on the Form 990 today. Adopting a policy before there is one costs a single board meeting.

5. Which AI uses are lower, medium, or higher risk

Risk rises as the AI moves from form toward substance. Lower risk uses are those where a human produced the ideas and the tool touched only the presentation. Higher risk uses are those where the model produced the substance, the facts, or the citations. No use is categorically safe, because the applicant remains responsible for accuracy, confidentiality, and the terms of the specific opportunity. The table below is a practical risk framing under the NIH policy rather than a set of NIH approved categories, and private funder expectations vary.

How AI is used Risk level and why What to document
Grammar, spelling, and readability check on human written text Lower. Fits the limited administrative assistance NIH describes, but confidentiality and accuracy still apply Nothing beyond your standard policy
Reformatting an existing narrative to a new funder’s page limits Lower. Administrative in nature, though the output still needs a human read Tool name in the file note
Summarizing your own prior reports to build a background section Medium. Owning the source material does not prevent inaccuracy, unsupported inference, or borrowed phrasing Source documents, tool, reviewer name and date
Drafting a needs statement from a prompt describing your community High. The ideas originate with the model, which is the concern the NIH policy targets Rewrite substantively before submission
Generating statistics, citations, or literature references High. Must be independently verified against authoritative sources. Fabricated or inaccurate citations create misconduct and misrepresentation risk Every figure traced to a named primary source
Producing the specific aims or project description end to end Highest. Likely to raise serious concerns under the prohibition on applications or sections substantially developed by AI Do not submit

The row that catches most organizations is the fifth one. Fabricated citations are the single most common way AI use becomes a formal integrity matter, because they are trivially checkable after the fact and impossible to explain away. A reviewer who cannot find a cited study does not conclude that you made an honest error. Every number and every reference in an application should be traceable to a source a human opened.

6. How to write an AI disclosure statement

A usable disclosure statement names the tool, states what it did, and confirms that a qualified person verified the output. Three sentences is enough, and shorter is better than a hedged paragraph that invites questions. The goal is not to confess. The goal is to make it obvious that a human was accountable for the content. What follows is a best practice pattern for private foundation proposals, not a form of words NIH or any funder requires.

Here is a pattern that works for a foundation proposal where AI helped with editing only. Portions of this narrative were edited for clarity using a commercial AI writing assistant. All program descriptions, data, and citations were prepared and verified by our staff. Name and title reviewed the final document before submission.

Where to put it depends on the funder. If the application has a field asking about AI use, answer it there and answer it plainly. If there is no field and the funder has no published policy, keep the record internally rather than spending narrative character count on it. One caution before you treat silence as permission: read the certifications. Applications routinely ask you to attest to originality, authorship, accuracy, or the use of outside parties, and a certification like that can require disclosure even when no question mentions AI. Absence of an AI field is not the same as absence of an obligation.

Three rules keep disclosure from backfiring. Never describe AI use you did not have, because an overbroad statement invites a question you cannot answer. Never use language suggesting the AI generated substance if it did not, because you will have talked yourself into the disqualifying column. And never let the disclosure be the only artifact, because a sentence in a proposal is not a record of who checked what.

GOVERNANCE INSIGHT

One line in the grant file beats a policy nobody reads.

Add a single field to whatever tracker your grants team already uses: AI assistance, yes or no, tool, and who verified. That field, filled in consistently for a year, is a stronger compliance record than a twelve page policy that lives in a shared drive.

7. Donor and beneficiary data: the exposure most nonprofits miss

The second exposure is what leaves your organization when staff paste data into a tool, and it is larger than the authorship question because it touches people who never agreed to it. Grant applications routinely contain beneficiary demographics, program outcome data, partner information, and sometimes case level detail. Donor records carry giving history, capacity estimates, and contact data.

None of that is covered by the NIH originality rule. It is governed by your agreement with the tool vendor, by state privacy law where it applies, by sector rules such as HIPAA or FERPA where they reach your programs, and by whatever you told donors and program participants you would do with their information. The relevant question is which agreement you are actually operating under. Consumer grade AI accounts often come with standard published terms rather than a negotiated data processing agreement, and may not carry enterprise commitments on retention, model training, access control, or breach notification. An enterprise tenant, a reseller arrangement, or a separately negotiated contract can change that answer entirely, so check which one you have before assuming either way.

The practical control is boring and effective. Decide which categories of data may never be entered into a general purpose AI tool, write those categories down, and give staff an approved alternative for the work they were trying to do. Beneficiary case detail, donor financial records, and anything that identifies a person receiving services are the usual entries on that list. If your organization runs an AI assisted intake or client facing chatbot, the analysis gets more involved, and the same regulatory questions we walked through for patient intake chatbots at small clinics apply with the labels changed.

Getting your AI governance in order

Dynamic Comply helps small and medium sized businesses build a real AI governance foundation using the NIST AI RMF and ISO/IEC 42001.

Start the free AI maturity self assessment

8. Your 501(c)(3) status is not a state AI law exemption

Tax exempt status exempts nonprofits from some state privacy laws and from very few state AI laws, and the two questions have different answers. Nonprofit leaders who learned the privacy answer in 2023 are carrying the wrong assumption into 2026.

On the privacy side the split is real but partial. A Wiley analysis published December 17, 2024 found no uniform approach: as of that date, Colorado, Delaware, New Jersey, and Oregon did not exempt 501(c)(3) organizations from their comprehensive privacy laws, while California, Connecticut, Montana, Texas, Utah, and Virginia did. Most of those laws applied only above a minimum number of state residents, typically 100,000, with Delaware set at 35,000 and Texas and Nebraska applying no minimum threshold. Treat that list as a snapshot rather than a current answer. These statutes are amended frequently, exemptions are often partial rather than total, and an organization exempt from one state’s privacy law may still face that state’s data security or consumer protection rules. Confirm your own states against the current statutory text.

The newer AI statutes are drafted differently, and that is the part to watch. Connecticut’s omnibus AI law began as Substitute Senate Bill 5 of the 2026 session, An Act Concerning Online Safety, and was enacted as Public Act No. 26-15, signed May 27, 2026 according to the legislature’s own bill history. Law firm analysis from Holland & Knight describes a general effective date of October 1, 2026 with staggered obligations running into 2027, and a Sidley analysis published August 21, 2026 reads the act as applying to entities doing business in Connecticut without regard to the thresholds used in the state’s privacy act. Read the act itself before relying on that scope for your organization, because published summaries of this law already disagree with each other on basic details such as the signing date.

The transferable lesson does not depend on those details. A nonprofit exemption written into a privacy statute does not automatically carry across to a separate AI statute, because the two are drafted with different scope language and different definitions. That has to be checked statute by statute.

None of this means a 20 person nonprofit is suddenly a regulated AI developer. It means the exemption question has to be asked separately for every statute rather than answered once. Our explainers on the Colorado AI Act and what applies to employers and on Illinois SB 315 walk through how those applicability tests are actually structured. If your organization publishes AI assisted content in fundraising campaigns, the disclosure rules covered in our piece on California’s AI disclosure law are worth reading alongside this one.

9. Building an AI use policy your board can approve in one meeting

A workable nonprofit AI use policy is two pages and answers six questions. Long policies fail in organizations with five to fifty staff because nobody reads them and no one owns them. The point is not to anticipate every scenario. It is to give staff a bright line and give the board something to point at.

The six questions are these. Which tools are approved, and who approves a new one. What data may never be entered into any AI tool. Who verifies AI assisted output before it goes to a funder, a donor, or a board packet. How AI use gets recorded in the grant file. What gets disclosed to funders and when. And who owns the policy, meaning a named role that reviews it annually.

Assign the owner before you write the text. In a small nonprofit this is usually the operations director or the person who already owns the document retention policy, not the executive director and not a committee. A policy with a named owner gets reviewed. A policy owned by everyone gets reviewed once, at adoption, and then ages quietly for four years.

Map it to a recognized framework, briefly

Funders and larger partners increasingly ask which framework you follow, and the honest answer for most small nonprofits should be that you have aligned to one rather than certified against it. The NIST AI Risk Management Framework is the usual choice in the United States because it is free, voluntary, and structured around four functions that a nonprofit board can actually follow: govern, map, measure, and manage. ISO/IEC 42001 is the certifiable standard, and it is the right target only if a major funder or contract counterparty has asked for it in writing.

Naming the framework in your policy does two things. It answers the diligence question before it is asked, and it gives you a vocabulary for the annual review that is not just your own opinion about what changed. It does not, on its own, make you compliant with anything. The NIST AI RMF is a voluntary framework rather than a certification, and saying you follow it means very little unless the practices behind it are real.

10. What to do before your next application deadline

Before your next deadline, do four things that together take less than a week of staff time. None of them require legal counsel, a consultant, or a new system.

First, read the actual terms of the specific opportunity you are applying to. Federal opportunities may incorporate an agency AI policy by reference, and foundation portals increasingly carry a question about AI use. Most organizations have never checked, which is how a rule gets broken by people who would have followed it.

Second, verify every number and citation in the draft against a source a human opened. If a statistic came from an AI summary and nobody has seen the underlying document, either find the document or remove the claim. This single step eliminates the most common route from AI assistance to a misconduct finding.

Third, write the file note. Tool, what it did, who reviewed it, date. Four fields. Put it wherever the application materials already live so that it survives staff turnover, which is the actual failure mode in a small shop.

Fourth, adopt a two page AI use policy. Adoption is what converts an individual habit into an organizational control. No law requires a nonprofit board to approve an AI policy, and the right approval path depends on your bylaws and delegated authority. For most organizations, taking it to the board or asking the board to formally acknowledge it is worth doing anyway, because that is what establishes institutional ownership rather than leaving the policy as one staff member’s preference.

If you hold federal awards, watch the proposed 2 CFR Part 200 rewrite and confirm its status directly, since a proposed rule can change substantially or slip before it is finalized. As proposed it does not address AI, but it does rework termination authority and pre award review, and the terms of your next award will be written under whatever version lands.

Talk to Ross about your AI governance needs

Every business has different AI governance requirements. Let us talk about yours.

Contact Dynamic Comply

Frequently Asked Questions

Can my nonprofit use AI to write grant applications?

It depends on the funder, and NIH has the strictest published policy. NIH notice NOT-OD-25-132, effective September 25, 2025, states that NIH will not consider applications substantially developed by AI, or containing sections substantially developed by AI, to be the original ideas of applicants. NIH communications indicate that limited administrative assistance, such as editing human written text for readability or formatting, may be permissible when applicants remain responsible for the work. Other agencies and private funders set their own rules, so check the terms of the specific opportunity.

Do private foundations require nonprofits to disclose AI use?

Most have not decided. In Candid’s 2024 Foundation Giving Forecast Survey of 527 responding foundations, 67 percent were undecided about whether to accept applications containing AI generated content, 23 percent said they would not accept them, and one in ten said they would. Because the majority have no published rule, the safe practice is to keep an internal record of AI use and disclose it when asked.

What happens if a funder discovers AI use after the grant is awarded?

For NIH awards, the notice states that the agency may refer the matter to the Office of Research Integrity to determine whether there is research misconduct, while simultaneously taking enforcement actions including disallowing costs, withholding future awards, suspending the grant wholly or in part, and possible termination. Private foundation consequences depend on the grant agreement, and typically run through the representations you made in the application.

Does my nonprofit need a written AI policy?

No law requires one, which is exactly the situation that produced conflict of interest and document retention policies. The 2026 Nonprofit AI Adoption Report found 92 percent of the 346 nonprofits surveyed using AI while 47 percent had no AI governance policy. A two page policy naming approved tools, prohibited data, and a verification step is enough for most organizations with five to fifty staff.

Are nonprofits exempt from state AI laws because of their 501(c)(3) status?

Not reliably, and the answer differs from the privacy law answer. State privacy laws vary sharply. As of a December 2024 analysis, Colorado, Delaware, New Jersey, and Oregon did not exempt 501(c)(3) organizations from their comprehensive privacy laws, while California, Connecticut, Montana, Texas, Utah, and Virginia did. Newer AI statutes use different scope language, so a privacy exemption does not automatically carry across, and applicability has to be checked statute by statute against current text.

About the author

Ross J. is the founder of Dynamic Comply, an AI governance, compliance, and cybersecurity consulting firm based in Leesburg, Virginia. He brings more than 15 years of federal cybersecurity experience across the Department of State, the Department of Defense, and the Department of Homeland Security, and holds the CGRC certification along with credentials as a GSDC AI Compliance Lead Implementer and Auditor and Certified Ethical Hacker.

This article is provided for general informational purposes and reflects the state of the law as of August 2026. It is not legal advice. Regulations in this area are changing quickly. Confirm current requirements and consult qualified counsel before making decisions for your organization.

Leave a Reply

Your email address will not be published. Required fields are marked *