Gavel & Glass Briefing - Ethical AI Use in Associations: What Leaders Need to Know
Generative artificial intelligence can help associations draft communications, summarize materials, brainstorm programs, and improve efficiency. It can also create legal, ethical, and reputational risks when staff treat it as private, reliable, or a substitute for human judgment.
Associations should be using AI where it can improve efficiency, expand capacity, and support better work. The goal is not to discourage adoption, but to use AI for what it is: a powerful tool that supports people rather than replaces human judgment, experience, or intuition.
Common Legal and Ethical Risks for Associations
Accuracy and transparency. AI can invent facts, sources, quotations, and citations—a problem commonly called a “hallucination.” Courts have repeatedly addressed lawyers filing AI-generated briefs that cited nonexistent cases or false quotations. In Mata v. Avianca, Inc., 678 F. Supp. 3d 443 (S.D.N.Y. 2023), a federal court sanctioned lawyers who submitted fabricated decisions. In 2025, the U.S. Bankruptcy Court for the Northern District of Illinois imposed sanctions for similar conduct. The lesson is not to avoid AI; it is to verify polished output. A 2024 Federal Trade Commission enforcement action also reinforced that existing consumer-protection rules apply to AI-related conduct.
Privacy, security, and confidentiality. Uploading personal or confidential information may conflict with privacy notices, contracts, consent requirements, or security obligations. The Cybersecurity and Infrastructure Security Agency’s Secure Our World resources include guidance advising users to avoid sharing sensitive or confidential information with AI systems.
Bias and discrimination. AI may reproduce bias, especially in employment, certification, awards, scholarships, membership, grants, or discipline. The association remains responsible for decisions made in its name.
Copyright and contracts. AI output may resemble protected text, images, code, trademarks, or branding, while material generated mainly by AI may receive limited copyright protection. Vendor terms may also restrict warranties, indemnification, deletion rights, or remedies. Associations should review important outputs and the terms for each product and connected application.
Volunteer-created AI systems. Volunteers may use personal AI accounts to write code, build automated databases, or develop tools for association use. This can drive valuable innovation, but informal development creates ownership, security, and continuity risks. The association does not automatically own a volunteer’s code merely because the volunteer created it for the association, and volunteer work does not automatically qualify as “work made for hire.” If the association expects ownership, it may need a signed transfer agreement. Federal copyright law generally places initial ownership with the author and requires a signed writing for most copyright transfers. See 17 U.S.C. §§ 201, 204.
The association should also control any operational account, credentials, source code, documentation, and backups. Otherwise, it may lose access when the volunteer leaves or may not know which data, open-source code, outside datasets, or licenses the system uses. Before adoption, the association should document ownership and confidentiality, review outside components, test security and reliability, and assign maintenance and offboarding responsibilities. NIST software supply-chain guidance supports this type of review.
Antitrust and competitive information. Associations should not use AI tools as uncontrolled repositories for members’ nonpublic pricing, wages, costs, strategic plans, or other competitively sensitive information. Existing antitrust controls continue to apply when AI is involved.
Misconception 1: “We Pay for the AI Tool, So Our Information Is Not Used to Train It”
Payment alone does not answer that question. Paid business and enterprise products often provide stronger protections than free versions, and some promise not to use customer prompts and outputs for training by default. However, protections vary by product, settings, and contract. Feedback features, shared links, plug-ins, and connected applications may operate under different terms.
“Not used for training” also does not mean “not collected, retained, reviewed, shared, or exposed.” Providers may keep information to deliver the service, monitor security, investigate misuse, provide support, or comply with law. Sharing settings, connected tools, human access, or security failures may expose information. If confidential information appears outside its intended setting, the association should investigate the cause rather than assume that the model “trained itself.”
The practical rule is simple: a paid account is not permission to upload confidential information. The association should approve the specific tool and use before staff enter member or donor data, personnel records, legal advice, board discussions, passwords, contracts, unpublished research, or confidential business information.
Misconception 2: “If the AI Created It, We Own It and the Vendor Will Protect Us”
These are separate questions: Can the output be copyrighted, and who bears the risk if it violates someone else’s rights?
Many providers state that the customer owns, or receives the provider’s rights in, generated output. That promise does not guarantee copyright protection. The U.S. Copyright Office’s 2025 report explains that copyright requires sufficient human authorship. Human writing, editing, selection, or arrangement may qualify, but entirely AI-generated material generally does not. Prompts alone usually do not provide enough human control.
Ownership language also does not guarantee that output is safe to use. AI may generate material that resembles protected text, images, or trademarks. Associations should review significant outputs for third-party rights.
Vendor indemnification—an agreement to defend or reimburse a customer for certain claims—depends on the contract. Exclusions, liability caps, and notice requirements may limit protection. “You own the output” does not mean “the vendor assumes every risk.”
Misconception 3: “AI Is Only a Drafting Tool, So Human Review Can Be Minimal”
AI can produce polished material that is inaccurate, biased, incomplete, or inappropriate. A confident tone is not proof of accuracy, and light proofreading may miss fabricated citations, hidden assumptions, or confidentiality issues.
Used properly, AI can help staff start faster, organize ideas, and improve routine work. Human review should match the risk. A brainstorming list may need limited review, while a public statement, employment decision, certification standard, contract, or legal summary requires qualified review. The reviewer should understand the subject, verify the result, apply judgment and intuition, and remain accountable for the final work.
Best Practice: Build a Practical AI Use Policy
A written policy gives staff clear boundaries and helps the association apply the same standards across departments. At minimum, the policy should:
identify approved tools, permitted uses, and whether volunteers may use personal accounts for association work;
require advance approval and a written agreement before a volunteer develops code, a database, an automated process, or another AI-enabled system for association use;
require association-controlled accounts, credentials, repositories, documentation, and backups for operational systems;
address ownership of code, data, prompts, documentation, and improvements, along with third-party and open-source components;
prohibit unauthorized uploads of confidential, personal, privileged, or security-sensitive information;
require meaningful human review before AI-assisted work is published, sent, relied upon, or used in a decision;
require verification of facts, quotations, citations, calculations, and source material;
address copyright, trademarks, ownership, attribution, and appropriate disclosure of AI use;
prohibit AI from serving as the sole decision-maker for consequential decisions;
assign responsibility for vendor review, training, monitoring, and incident reporting; and
require periodic review as technology, law, and vendor terms change.
The NIST AI Risk Management Framework offers a useful voluntary structure for this work: govern AI use, understand its context and risks, measure performance and harm, and manage identified risks.
Ethical AI use begins with three principles: know the tool, protect the information, and verify the work. AI can help associations work faster, extend limited staff capacity, and devote more time to higher-value judgment and member service. A practical policy, careful vendor review, meaningful human oversight, and staff training allow associations to gain those benefits without surrendering accountability.
Disclaimer: The information contained in this article is provided for educational and informational purposes only and should not be construed as legal advice on any subject matter. No recipients of content from this article, clients or otherwise, should act or refrain from acting on the basis of any content included in the article without seeking the appropriate legal or other professional advice on the particular facts and circumstances at issue from an attorney licensed in the recipient's state.