Governance
My Responsible AI and Data Protection Policy
How I use artificial intelligence responsibly across all of my work, and what I require of the people I work with.
Version 1 · 2026-07-21 · John Zoltner, CEO
For any organization I have control over, such as AIChildSafety.org, its Childhood and AI Lab, or AI4SocialImpact, I adhere to strict responsible-AI and data-protection policies, and I require my staff, consultants, and collaborators to do the same. This policy sets out those commitments across all of my work. It is not a single joint policy of the organizations; each applies these commitments to its own obligations, and where a nonprofit mission or a child-protection duty makes a rule stricter, the stricter rule applies.
1 · Guiding principles
Every use of AI is measured against eight commitments, adapted from the NIST AI Risk Management Framework and the OECD and UNICEF principles.
2 · Governance and accountability
3 · Responsible use of AI
4 · Data protection and security
Data is handled at one of four tiers. The tier sets which tools and controls apply.
| Tier | Examples | AI-tool rule |
|---|---|---|
| Public | Published reports, public web content | Any approved tool |
| Internal | Draft strategy, internal notes, non-personal operations | Approved tools with a no-training account setting |
| Confidential | Contact data, donor data, unpublished partner or client material | Only accounts set and verified not to train on our data; enterprise terms with a data processing agreement where personal data at scale is involved |
| Restricted | Children's data; other special-category data; safeguarding case material; legal material | Not entered into any general cloud AI tool; segregated and access-restricted |
5 · Children's data and heightened safeguards
6 · Responsible AI in consulting engagements
Applies to consulting and service work (for example, through AI4SocialImpact).
7 · Research fellows and collaborators
8 · Relationship to child safeguarding
An organization that helps others adopt AI well has to hold itself to those standards first. These commitments are how I do that, and they travel with me into every organization I lead.
This policy states operational commitments, not legal advice. Grounded in the NIST AI Risk Management Framework, the OECD AI Principles, UNICEF guidance on AI and children, NTEN and NetHope nonprofit-AI guidance, the ICO Age Appropriate Design Code, and the International Child Safeguarding Standards. This page was drafted with AI assistance, directed and edited by John Zoltner.
