Write your organisation's AI rules in one hour
Sixty minutes, a pen, and the person who can actually sign. 71% of the organisations we surveyed have no written AI rule at all.
- Time needed
- 60 minutes · 11 steps
- What it takes
- Nothing to install
- What it costs
- A free path exists
- Last checked
- 2026-08-31
- Director or leadership
- Grants and operations
- Journalist or editor
- Documentation and monitoring
- Protecting sensitive information
- Grants and admin
- Drafting reports and advocacy material
These are instructions, not case studies
A recipe tells you what to do. It is not a report of something that already happened somewhere else. Nothing here claims that any organisation did this. It is written for you to do now, and every step tells you how to check it worked.
With no written rule, the decision falls to whoever is tired at six in the evening with a deadline.
You need sixty minutes, three to five people, and the person who can actually sign. Nothing here has to be reachable from Iraq, because nothing here touches the internet.
What you walk out of the room with
A signed policy that sorts your information into three levels, green, amber and red, sorts tools the same way, and states which level of tool may touch which level of information. With it: an approved-tools annex, an incident procedure that does not punish honesty, and a review date.
The safety line
The finished policy is itself a sensitive document. Its red list is a precise map of what your organisation holds that could get someone hurt. So is the honest inventory you collect from staff the day before. Collect that in person or on paper, never as an email thread: a written answer like “I ran the witness recordings through a free transcription site in March” is a confession log with a name on it.
Do not paste either document into a chatbot to tidy the wording.
What this will not do
It is not legal advice and it is not a compliance certificate. It will not satisfy a European funder’s formal data protection assessment on its own. It will not protect anyone if your devices are seized or your office is raided: that is a physical and digital security plan, a different and more urgent document.
What happens to your information
Never use this for
This is not legal advice and it is not a compliance certificate. It will not satisfy a European funder's formal data protection assessment on its own, and it will not protect anyone if your devices are seized or your office is raided. That is a physical and digital security plan, a different and more urgent document. It also does not replace consent from the people whose testimony you hold. And the no-blame amnesty in step 1 binds your own management only: it is not protection against a funder audit, a prosecutor, a court order or a hostile incoming board, all of which can reach the written record the amnesty creates. Say that out loud to staff rather than letting them assume otherwise.
What leaves your device
Whose law it lands under · The fully offline option
Nothing, if you follow the recipe as written. You are writing a document by hand in a room, in a word processor or on paper. No AI tool is used at any point, and there is no website you need to open to get the template. It is printed in full at step 3.
Four warnings that matter more than they look.
First, the finished policy is itself a sensitive document. Its RED list is a precise map of exactly what your organisation holds that could get someone hurt, safe-house locations, witness categories, which funders, which minors. Do not paste your draft into a free chatbot to 'tidy the wording', do not email it to a consultant on a personal account, and do not put it in a public shared folder. Treat the draft at the same level as the material it describes.
Second, and this is the one the recipe used to get wrong: the replies to the amnesty message in step 1 are MORE sensitive than the policy. They are a written, dated, attributable inventory of exactly which sensitive material has already left your organisation and whose it was. A sentence like 'I ran the Anbar witness recordings through a free transcription site in March' is a confession log with a name on it. Collect those replies verbally or on paper, never as an email thread, and destroy the written ones once Annex A is built. Step 1 tells you how.
Third, the incident log created by section 5 of the policy is RED by the policy's own definition, because it names whose information was exposed. The template now says where it lives and who can open it. Do not skip that blank.
Fourth, and this one was hiding inside the recipe's own instructions until this pass: the filled-in RED list is RED. Step 4 tells you to name real projects, real districts, real sets of recordings, which is what makes the list usable. That same specificity means the finished master copy must not be pinned on a wall where visitors, cleaners or a delivery driver can read it, and must not be handed to fixers, translators or community contacts. The wall copy and the copy that goes to anyone outside your own staff carries the levels, the rule table and the approver's name, with the RED headings in general terms only. The master, with your real examples in it, lives where your case files live.
Whose law it lands under
None involved, the work is local. Jurisdiction becomes relevant only for the tools you later put on your approved list: US law for Anthropic, OpenAI and Google consumer services; wherever your own file storage sits for the document itself. Note that 'not used for training' is a promise about model training, not about jurisdiction: material sent to a US consumer service sits on US infrastructure and is reachable by US legal process regardless of any training toggle.
The fully offline option
This is the fully local option, and it needs no internet connection at any point. Pen, paper and a table are enough. The blank template is printed in full at step 3 of this recipe, so if you are reading this recipe on paper or from a downloaded copy you already have everything. There is no page to visit and nothing to download. If you want a digital copy, any word processor already on the machine works offline; LibreOffice Writer also works fully offline and saves to your own disk, but weigh the roughly 360 MB Windows download against your connection before you start.
What it costs
Paying for this from Iraq
Nothing to pay, so no card and no payment route is needed for the hour itself. For the tools list you will build in step 6: both Anthropic and OpenAI list Iraq on their supported-countries pages (both opened and confirmed in this session, Iraq appears in Anthropic's list for both the API and Claude.ai, and in OpenAI's supported countries and territories), so the services are not geo-blocked. Service availability is not the same as payment. Iraqi-issued cards are still frequently declined by international SaaS billing systems, and payment and access restrictions are a named blocker in our needs assessment. This has a direct consequence for your policy that most templates miss: Level 2 in this policy means an account the ORGANISATION controls, with training switched off. If you cannot pay for an organisational plan, you cannot hold an organisation-controlled account, and your Level 2 column may be legitimately empty. A policy with an empty Level 2, GREEN work on free tools at Level 3, AMBER and RED on nothing at all, is a valid, complete, adopted policy, not a failed one. Do not invent a Level 2 entry you cannot actually buy.
The free path
If you pay
Free, and it stays free. This recipe needs no AI tool, no account, and no software purchase. You can complete it on paper with a pen, or in whatever word processor you already have, Word, Notepad, Pages, Google Docs. The full blank template is printed inside this recipe at step 3; copy it by hand or retype it. There is no separate download and no website you have to visit to get it. If you have no word processor at all, LibreOffice is free, open source under the Mozilla Public License v2.0, needs no account, and downloads from libreoffice.org for Windows, macOS and Linux, but the Windows installer is about 360 MB, so on a metered or shared connection use paper instead. Paper is not a lesser version of this recipe. It is the recommended one.
If you pay
USD 0. Nothing in this recipe has a paid tier. Costs only appear later, if you decide your approved-tools list needs a paid organisational account with training switched off, but you can adopt and run this policy indefinitely on free and offline tools. If you do reach that decision, do not trust any price printed in this recipe or in any other handout: open the vendor's own pricing page on the day you decide, because these prices change and a conference handout is read for a year. Anthropic's is at https://claude.com/pricing, OpenAI's at https://openai.com/pricing, Google's at https://gemini.google.com, check what an organisational or team plan actually costs, in your currency, on the day.
Before you start
- Sixty uninterrupted minutes with the person who can actually decide, the director or the executive committee. A policy written by staff and never approved is not a policy.
- Two or three other people, no more than five in the room. Include whoever handles case files or testimony, and whoever handles money and funder reporting. These two people know where the real risk sits.
- A pen and paper, or any word processor. Nothing needs to be installed, and there is no website you need to reach. The full blank template is printed at step 3 of this recipe.
- An honest, blame-free list of what your staff are already doing with AI. Ask for it before the meeting and promise in writing that nobody is in trouble for answering. In our needs assessment, 14 MENA civil society organisations, August 2026, 43% had put, or may have put, sensitive material into an AI tool. Assume yours is one of them and that you simply do not know it yet. Read step 1 before you send that message: the replies are more sensitive than anything else this recipe produces.
- The names of the actual people who will hold each role. A policy that says 'management' decides is a policy where nobody decides.
- ACCOUNTS SETTLED BEFORE THE MEETING, NOT DURING IT. Step 6 asks you to open a tool's real settings and switch training off in the room. If you do not already have a working account on a tool you intend to place at Level 2, create and verify it the day before, see step 2. Claude.ai requires SMS verification on a mobile number from a supported location and rejects VoIP, Google Voice, app-generated numbers and landlines. If verification fails on your number, that tool is Level 3 and stays there; that is a finished decision, not a problem to solve mid-meeting.
- Accept before you start that Level 2 may be empty for you, and that Level 1 may be unavailable on 8 GB laptops. Both outcomes produce a valid policy. See platformNotes and the Iraq payment note.
Which machines this works on
The meeting itself is platform-independent: it runs on paper, or in whatever word processor is already on the machine. Nothing in the hour requires Windows, macOS or Linux specifically.
WINDOWS (the majority of this room): Word or Notepad are already installed and are enough. If the office has no word processor at all, LibreOffice is free and needs no account, but the Windows installer is about 360 MB, which is a serious download on a metered or shared connection. If your connection is poor, do not download anything: write the eight headings on paper. Paper is the recommended route, not the fallback.
macOS: Pages or TextEdit are already installed. Same LibreOffice note applies.
Linux: LibreOffice is usually already installed via the distribution's package manager.
PLATFORM-LIMITED ROUTE, SAY IT BEFORE YOU START: the only tool tier this recipe calls honestly safe for RED information is Level 1, a model running fully on your own machine through Ollama or LM Studio. As a rule of thumb. Our judgement from practical use, not a benchmark we ran. That route wants a laptop with roughly 16 GB of RAM to be useful, and it is genuinely awkward on Windows machines with 8 GB. If your office is on 8 GB laptops, treat Level 1 as unavailable to you, and the correct answer for RED information is not "find a lighter model". It is "no AI tool at all, ever, for that material". A policy that says that is a complete and correct policy. Do not spend the hour trying to engineer around it.
The steps
Step 1 / 11
At least a day before the meeting, send this one message to all staff. It buys you an honest starting picture, which is the only thing that makes the hour productive. Read the note underneath BEFORE you send it, how you collect the replies matters more than the wording.
Copy this exactly
On [date] we are writing our organisation's rules for using AI tools. To write rules that fit what we actually do, I need to know what we actually do. Please tell me, by [date]: which AI tools you have used for work (ChatGPT, Claude, Gemini, Copilot, a translation website, a transcription website, a photo tool, anything), and roughly what you used them for. Come and tell me in person, or hand me a note on paper. Please do NOT reply by email or on a messaging app, and please do not name any case, source or person in what you tell me. Say 'a set of interview recordings', not whose. Nobody will be disciplined, warned, or asked about this again as a result of what they tell me. I am asking so that our rules protect you. One thing I have to be straight with you about: this promise is mine, and it covers what I and this management will do. It cannot bind a funder's auditor, a court, or a future board. That is exactly why I am asking for this in person or on paper rather than in writing on a server.Check it worked
Before the meeting, count the replies against your staff list. If fewer than half of your staff have answered, the amnesty is not believed yet and the meeting will be built on a false picture, postpone a day and have the director ask two or three people directly and in person. A second signal that it worked: at least one reply should surprise you. If every answer is 'only for translating public documents', you have collected the answer people think is safe, not the true one. Ask again, in person, with the specific question 'has anything with a name in it ever gone into one of these tools?'
Note
This is the single highest-value step and most organisations skip it. You cannot classify your risk if you do not know that someone has been running interview recordings through a free transcription website for eight months. The written amnesty is not a courtesy. It is what makes the answers true.
WHAT CHANGED AND WHY IT MATTERS: an earlier version of this recipe asked staff to REPLY BY EMAIL. Do not do that. The replies are a dated, attributable inventory of which sensitive material has already left your organisation and whose it was, the single most dangerous document this whole exercise creates, more dangerous than the policy itself. Sitting in a Gmail or Outlook thread it is backed up, synced to phones, and discoverable by anyone who later gets into that account. Collect it in person or on paper. Take your own notes as tool names and rough purposes only, with no case names and no client names. Once Annex A is built in step 6, shred the paper notes and destroy your own. What you keep is the tools list, not the confessions.
Step 2 / 11
The day before the meeting: if you intend to put any tool at Level 2, meaning an account the organisation controls with training switched off, make sure that account exists and you can log into it, today, before anyone is in the room. Do this alone. It takes ten to thirty minutes and it is the step most likely to stall the meeting if you leave it until then.
Copy this exactly
Checked against the vendors' own help pages in this session, 30 August 2026. Every one of these pages carries its own 'last updated' stamp, look at it when you read the page, and believe the page over this recipe. CLAUDE (Anthropic), phone verification IS required and cannot be skipped. Anthropic's help centre states you will be asked to enter a phone number from a supported location to receive a code by SMS, that they 'require phone verification for all new users, and there isn't a way to skip this step', and that "you cannot use VoIP numbers, Google Voice, phone numbers created using apps, landlines, or other numbers that can't receive texts." Iraq IS listed as a supported location for Claude.ai. So an ordinary Iraqi mobile is the right kind of number, but delivery through a given carrier can still fail. If no code arrives, the vendor's own advice is that it may take a few minutes, and if it has been more than five minutes to click 'Try again' and re-enter the number; if it still fails, you need a different mobile number. CHATGPT (OpenAI), as of this session, OpenAI's help centre states plainly: "Phone verification is no longer required for new OpenAI account creation or ChatGPT usage." An email address is enough. Phone verification IS still required once, on platform.openai.com, to generate your FIRST API key, and for that, OpenAI does not accept landlines, VoIP, Google Voice or premium numbers, only a mobile by SMS. OpenAI supports WhatsApp verification in some countries as an alternative; Iraq is NOT on that list, so for an API key you need an SMS-capable +964 mobile. GOOGLE GEMINI: a Google account you already have is enough. IF VERIFICATION FAILS: that tool is Level 3. Write it in the policy as Level 3 and move on. Do not use a colleague's personal number to get an organisational account past the gate. You will have created an organisational account that one individual can be locked out of, or held responsible for, and you will not remember whose number it was in a year.Check it worked
Log out of the account completely and log back in from the machine you will use in the meeting. If you can reach the settings screen from a cold login, the account is real and the meeting can proceed. If you only ever tested it in a browser tab that was already logged in, you have not tested anything.
Note
This step did not exist in the earliest draft, and its absence was a real defect: step 6 told a room to 'open the settings and switch training off, in the room, now', which quietly assumed an account already existed. For an organisation creating its first one, that is where the meeting dies. Note also the honest asymmetry we found while checking: OpenAI has dropped the phone gate for ChatGPT signup, Anthropic has not. That was true when we checked, and both vendors change it without notice, if it has changed by the time you read this, believe the vendor's page and not us.
Step 3 / 11
Spend the first five minutes of the meeting writing the blank template out. Copy the text below into your word processor, or write the eight headings on a large sheet of paper. Do not customise anything yet. Read it aloud once, top to bottom, so everyone knows what the hour is going to produce.
Copy this exactly
[ORGANISATION NAME], RULES FOR USING AI TOOLS Adopted: [date] Next review: [date, six months later] Owner of this document: [APPROVER, name, role] Applies to: everyone who does work for us, staff, volunteers, interns, consultants, board members, and, through a spoken briefing rather than a signature, everyone we work alongside: fixers, translators, drivers, community contacts. See section 8. 1. OUR THREE LEVELS OF INFORMATION GREEN: already public, or we would be content to see it on a website tomorrow. Our examples: [fill in] AMBER: internal. Embarrassing if it leaked. Not dangerous to anyone. Our examples: [fill in] RED: if this leaks, a person can be detained, deported, harmed, dismissed, or our registration can be attacked. Our examples: [fill in] If you are not sure whether something is AMBER or RED, it is RED. HOW THIS PAGE IS HANDLED. Once the RED examples above are filled in with our real projects, districts and files, THIS PAGE IS ITSELF RED. The master copy, with the examples in it, is kept where we keep case files. Our own staff hold a full copy because they need it to do their work. The copy we pin on the wall, and any copy we hand to someone who is not our own staff, carries sections 2, 3 and 4 and the three headings above in general terms only, never our specific examples. 2. OUR THREE LEVELS OF TOOL Level 1, Offline. Runs on our own computer with the internet switched off. Nothing leaves the device. Level 2, an account controlled by this organisation, with model training switched off, on a tool approved in Annex A. Level 3. Everything else: free consumer chatbots, browser extensions, free translation and transcription websites, free PDF websites, anything on a personal phone, anything not in Annex A. READ THIS TWICE. Level 2 means the company has promised not to TRAIN its models on what we send. It does not mean the information stayed here. At Level 2 the information still left our building: it travelled over the internet, it sat on someone else's computer in another country, it may be kept for years, it may be read by a human reviewer, it can be handed over under a court order there, and it can be exposed if that company is breached. 'Training switched off' is a promise about one use of our information, not a wall around it. That is why RED information does not go to Level 2 even with every toggle switched off. If our Level 2 column is empty because we cannot pay for an organisational account, that is fine. The policy still stands. It means GREEN work only, on Level 3 tools. 3. THE RULE Level 1 offline Level 2 approved Level 3 everything else GREEN yes yes yes AMBER yes yes NO RED yes* NO NO * Level 1 with RED information is allowed only on an organisation-owned device, and only after the offline check in Annex A has been done on that device. If we have no machine that passes that check, the rule for RED is simply: no AI tool, ever. That is a complete rule and we are content with it. And always: - Nothing produced with AI is published, sent to a funder, filed in court, or given to a journalist until a named person has checked every fact, name, number, date, quotation and citation against the original source. Write that person's name on the draft. - We say when AI helped produce something we publish. - We never let an AI tool decide anything about a person: who receives assistance, who is believed, who is hired. - We never put a partner's or another organisation's information into any AI tool without their written permission. - Deleting names does not turn RED into AMBER. A testimony with the name removed is still identifiable by its content. - We never press the thumbs-up or thumbs-down button on an AI answer that contained our own material. On some services, giving feedback sends that entire conversation for training even if we have switched training off. 4. WHO DECIDES [APPROVER, name, role] approves a tool before anyone uses it for work. Ask before, not after. A decision takes no more than [3] working days. While [APPROVER] is away, [DEPUTY, name, role] decides. If a tool is not in Annex A, it is Level 3. 5. WHEN SOMEONE MAKES A MISTAKE We want to hear about it. Nobody is disciplined for reporting their own mistake promptly and honestly. We can only protect the people we know are at risk. 1. Stop using the tool. Do not delete anything yet. We may need to know exactly what was sent. 2. Tell [APPROVER] the same day. Say what you entered, into which tool, and roughly when. 3. [APPROVER] writes down: the date, the tool, what information, whose information, and what was done. This incident log is RED. It lives in [WHERE, the same place we keep case files, named here], and only [APPROVER] and [DEPUTY] may open it. It is never emailed and never kept on a phone. Point 1 above says preserve the material; that preservation is also RED and is held the same way. If we are at real risk of a raid or device seizure, physical security comes first: we record only what is needed to warn the people affected, and we do not build an archive of our own exposures. 4. Within [3] working days we decide whether anyone named in that information must be told or moved. THE PERSON AT RISK IS WARNED FIRST, BEFORE ANY OTHER NOTIFICATION. Then, and separately, we consider who else must be informed, a funder, a partner, or an authority where the law requires it. WE DO NOT NOTIFY ANY AUTHORITY about material concerning a source, a witness, a person at risk or anyone under 18 without first taking legal advice from a lawyer we trust. For some of what we hold, telling an authority IS the disclosure we are trying to prevent. If we cannot reach a lawyer, we wait, and we warn the person. 5. Within [14] days we change this document, the tool list, or our training so the same mistake is harder to make. 6. Discipline applies to two things only: hiding an incident, and deliberately breaking the RED rule. 6. REVIEW We read this document again on [date, six months from adoption], and immediately after any of: an incident; adopting a new tool; a tool changing its privacy terms; a change in the law; a new funder requirement. 7. ANNEX A: APPROVED TOOLS Tool | Level | May be used for | Highest information level allowed | Who pays | Approved on ---- | ----- | --------------- | --------------------------------- | -------- | ----------- Offline check, required before any tool is written in at Level 1: with the model already downloaded, turn the internet off completely, unplug the cable, switch off Wi-Fi, switch off the phone hotspot, then ask the model a question and confirm it still answers. If it fails or reports a network error, it is not running on this machine and it is not Level 1. 8. SIGNATURES Our own people sign: staff, volunteers, interns, board members, and any consultant working under our name on our material. Sign and date below, in the language you work in. WE DO NOT COLLECT SIGNATURES FROM FIXERS, TRANSLATORS, DRIVERS OR COMMUNITY CONTACTS. Their identities are on our RED list, and a signed roster naming them would be exactly the document our own rules say must never exist. They are briefed out loud instead, by a named colleague, and we record only that the briefing happened and who gave it, never a list of who attended. This signature sheet is AMBER and is kept with our personnel records, at the same protection as those records. If any name on it would itself be dangerous, that person is briefed out loud instead and does not sign.Check it worked
Read section 2 aloud, including the paragraph in capitals, and ask one person in the room to say back in their own words what Level 2 does and does not protect them from. If they answer 'it means it's safe' or 'it means it stays with us', read it again. That misunderstanding is the single most common way an organisation whose top fear is information leaving ends up sending material to a Level 2 tool believing it stayed home. Then read the HOW THIS PAGE IS HANDLED paragraph aloud too, and settle one thing before you go further: name, out loud, where the master copy will live and who will pin the short version on the wall. Finally check the page count: if what you have typed runs past two pages, you have added something. Take it out.
Note
Eight sections, one page. Resist adding a ninth. Every template we reviewed that ran past two pages, including the corporate ones, is a template nobody in a five-person office ever reads twice.
FOUR THINGS CHANGED IN THIS TEMPLATE AND YOU SHOULD KNOW WHY. First, section 8 previously told you to collect a signature from every fixer, translator and driver, which would have manufactured a signed, dated, filed roster of precisely the people the RED list says must never be identifiable. That was a real-world harm sitting inside the deliverable. It is now a spoken briefing with no attendance list. Second, section 2 now spells out that 'not used for training' does not mean 'not transmitted, not stored, not retained, not disclosable'. Third, section 5 now says where the incident log lives, and puts an explicit brake on notifying an authority, because for this sector, notification is sometimes the leak. Fourth, and newest: the HOW THIS PAGE IS HANDLED paragraph in section 1. Until this pass the recipe told you to make the RED list specific and then, three steps later, to pin the policy on the wall and hand it to your community contacts. Those two instructions contradicted each other, and the wall would have won.
Step 4 / 11
Spend ten minutes filling in the RED list, and do RED first. Do not write abstract categories like 'personal data'. Write the actual things sitting on your actual computers this month. Go around the room and make each person name two.
Copy this exactly
Starter RED list, delete what does not apply, and add your own real examples: - Witness and victim testimony, in any form: audio, video, notes, transcripts - Names, phone numbers, addresses, photographs, ID or passport numbers of anyone we work with or document - Case files and legal files - The location of a shelter, safe house, or safe meeting place - The identity of a source, a fixer, or a person who introduced us to a community - Medical records and psychological assessments - Minutes or reports naming individuals who are at risk - Anything at all concerning a person under 18 - Anything given to us under a promise of confidentiality - Staff home addresses, travel plans, and family details - Our own security plans, our incident logs, and this document's RED list - Passwords, recovery codes, and API keys - Unpublished investigation material and the identity of a whistleblowerCheck it worked
Count your own additions. If the RED list you leave the room with is the starter list above with nothing added and nothing deleted, the step did not happen. You copied a list instead of describing your organisation. You should have at least four entries that name something specific to you: a project, a district, a category of file, a particular set of recordings. Second check: read each line and ask 'could a new colleague on their first Tuesday tell whether the file in front of them is this?' If the answer is no, the line is still too abstract. Third check, and do it the moment the list is finished: the last line of the starter list classifies this list as RED, and you have just made it specific. Say out loud where this page is going to be kept, and confirm nobody is about to photograph it into a group chat.
Note
Doing RED first is deliberate. If you start with GREEN, the room drifts into a comfortable conversation about newsletters. Starting with RED puts the reason for the meeting on the table in the first two minutes, and everything after it goes faster.
The uncomfortable consequence of doing this step properly: a good RED list is a shopping list for anyone who wants to hurt the people you document. That is not a reason to write a vague one. It is a reason to keep the specific version where you keep case files, and to circulate the generalised version. Section 1 of the template says so; make sure whoever types up the master has read it.
Step 5 / 11
Spend ten minutes on GREEN and AMBER. GREEN is genuinely published material. AMBER is the large middle where most daily work sits. If a category causes an argument, put it in AMBER, arguing about it is itself evidence that it is not GREEN.
Copy this exactly
Starter GREEN list: - Our published reports and press releases - Our public website text and social media posts - Public laws, gazettes, court judgments already published, official statistics - Training material we hand out openly - Job advertisements and public calls Starter AMBER list: - Draft reports before publication, with names removed - Budgets, financial reports, and funder narrative drafts - Internal policies and workplans - Meeting notes that name no one at risk - Correspondence with a funder about programme delivery - Aggregate statistics that cannot identify an individual - This signed policy itself, and its signature sheet (but NOT its RED list, which is RED)Check it worked
Take the three most common documents your office actually produces in a normal week and place each one out loud. If any of the three cannot be placed without a two-minute argument, that document type is not covered clearly enough, add it by name to whichever list wins the argument before you move on. If a category ended up in GREEN because someone said 'well, it's basically public', move it to AMBER; 'basically public' is not published.
Note
Two traps. First: a funder budget is AMBER, but a budget line that names a local partner in a hostile district is RED, the sensitivity is in the detail, not the document type. Second: 'draft report with names removed' is only AMBER if the removal was done properly and the surrounding detail does not identify the person anyway. In a small community, 'a 34-year-old teacher from the village' is a name.
Step 6 / 11
Spend ten minutes building Annex A, the approved tools list. Start from what you learned in step 1. Those tools are already in use and pretending otherwise helps nobody. For each tool, decide the level and write it in. Then, for anything you want to place at Level 2, open its settings on the account you prepared in step 2 and switch model training off before you write it down.
Copy this exactly
Where to switch training off, and what it does and does not buy you. Every claim below was opened on the vendor's own page in this session, 30 August 2026. Every one of those pages shows its own 'last updated' stamp, read it when you open the page, and believe the page over this recipe. CHATGPT (OpenAI). OpenAI's help article states that for services for individuals such as ChatGPT and Codex, "we may use your content to train our models", and that you opt out through the privacy portal at privacy.openai.com by clicking "do not train on my content", or through the Data Controls FAQ in ChatGPT. Once you opt out, new conversations will not be used to train their models. TWO TRAPS ON THE SAME PAGE. First: "Even if you have opted out of training, you can still choose to provide feedback to us about your interactions with our products (for instance, by selecting thumbs up or thumbs down on a model response). If you choose to provide feedback, the entire conversation associated with that feedback may be used to train our models." That means one thumbs-up on a helpful answer hands over the whole conversation. Tell your staff not to press it. Second: Temporary Chat (the icon at the top right) keeps a chat out of your history, creates no memories and is not used for training, but it is not a privacy shield. The conversation still travelled to OpenAI. CLAUDE (Anthropic). The privacy page, which carried a last-updated date of 16 March 2026 when we opened it, confirms consumer Free, Pro and Max are NOT used for training by default, model improvement is opt-in, under a setting called Model Improvement in Privacy Settings. Verify the toggle is off anyway. "Your Incognito chats are not used to improve Claude, even if you have enabled Model Improvement in your Privacy Settings." RETENTION: "When you provide us feedback via our thumbs up/down button, we will store the entire related conversation, including any content, custom styles or conversation preferences, in our secured back-end for up to 5 years." Same instruction as for ChatGPT, do not press the feedback buttons on anything containing your own material. GOOGLE GEMINI (free). Google's own help page states that "Human reviewers (including trained reviewers from our service providers) review some of the data we collect for these purposes"; that chats reviewed by human reviewers "are not deleted when you delete your activity. Instead, they are retained for up to three years"; and it advises directly: "Please don't enter confidential information that you wouldn't want a reviewer to see or Google to use to improve our services, including machine-learning technologies." The setting is called Keep Activity. Turning Keep Activity off still leaves chats retained with your account for 72 hours. Because reviewed chats survive deletion for three years, we recommend you place free Gemini at Level 3 and permit GREEN only. LEVEL 1, OFFLINE, READ THIS BEFORE YOU WRITE ANYTHING IN. Ollama and LM Studio can run a model entirely on your own machine, and that is the only category honestly safe for RED. But 'I am using Ollama' no longer proves you are offline. Ollama now also serves CLOUD-HOSTED models through the exact same `ollama run` command, and its own documentation says cloud models "are automatically offloaded to Ollama's cloud service". Cloud model names carry a -cloud suffix; the example in Ollama's own docs is `ollama run gpt-oss:120b-cloud`. Somebody who types that is sending every prompt to a company's servers while believing they are offline. Two checks, and do both: 1. Look at the model name. If it ends in -cloud, it is not local. On Windows open Command Prompt (press the Windows key, type cmd, press Enter); on macOS open Terminal (press Command and Space, type Terminal, press Enter); on Linux open your terminal. Then type this and press Enter: ollama ls That is the command Ollama's own CLI documentation gives for listing models. Every model you intend to use at Level 1 must appear in that list WITHOUT a -cloud suffix. 2. Then prove it. Turn the internet off completely, unplug the cable, switch Wi-Fi off, switch off any phone hotspot, and ask the model a question. If it answers normally, it is local. If it errors or hangs, it was never local. This second check is the one that actually decides it; the name check only catches the obvious case. As a rule of thumb. Our judgement, not a benchmark, Level 1 wants roughly 16 GB of RAM to be worth using. If your office is on 8 GB laptops, do not write anything into Level 1. Write into the policy that RED information goes into no AI tool at all. That is the correct answer, not a compromise. After you change each setting, take a screenshot of the switched-off toggle and keep it with the policy, with the date. CROP IT FIRST. A settings screenshot routinely captures the account email, the organisation name, and a sidebar of recent chat titles, which in this sector are case names. Crop to the toggle and its label only, and look at what else is in the frame before you save it.Check it worked
For each Level 2 tool: after switching the toggle, log out fully, log back in, and open the setting again. Vendors sometimes fail to save a setting change without showing an error. If it is still off after a fresh login, it is really off. That, not the click, is what you screenshot. For anything at Level 1: you have not verified it until the machine has answered a question with the network physically off. Do that in the room, in front of someone else. Finally, look at each screenshot at full size before filing it and confirm no email address, workspace name or chat title is visible. If one is, delete the image and take it again.
Note
The screenshot is not bureaucracy. Vendor defaults change without notice, and in six months you will not remember whether you actually switched it or only meant to. It is also the single thing a funder's due-diligence officer will ask you for, which is exactly why it must be cropped before it leaves your office.
The Ollama warning is the highest-consequence correction this recipe has carried. An earlier draft said flatly that a model run through Ollama or LM Studio 'sends nothing anywhere once the model is downloaded' and called it the only category honestly safe for RED. The first half of that is no longer unconditionally true, and the two halves together would have pointed someone's most dangerous material at a cloud endpoint they believed was their own laptop. Note also what we removed from this step: a previous draft told you the local models would appear in the list 'with a size in gigabytes'. We could not find that in Ollama's documentation and could not test it here, so we cut it. The -cloud check and the network-off proof are what carry Level 1, and the network-off proof is the one that cannot be faked.
Step 7 / 11
Spend five minutes on section 4. Write two real names, APPROVER, the person who approves tools, and DEPUTY, the person who approves while APPROVER is travelling. Write a real number of working days. Say it out loud so both people hear themselves accept it. Use the same two names everywhere they appear in sections 4, 5 and 7.
Check it worked
Search your draft for the words 'management', 'the team', 'the department', 'IT' and 'legal'. Every one of those is a role you probably do not have; replace each with a person's name or delete the sentence. Then ask APPROVER and DEPUTY, out loud, in front of the room: 'do you accept that you decide this, within three working days?' If either hesitates, you have found the real answer now rather than during an incident.
Note
In an organisation of five to twenty people this is almost always the director plus one operations or programme person. Do not create a committee. If approval takes longer than three days, staff will stop asking and go back to using whatever they like, and you will have converted a written policy into a false one.
Step 8 / 11
Spend ten minutes on section 5, the incident procedure. Fill in APPROVER, DEPUTY, the real deadlines, and the blank saying WHERE the incident log is kept. Then say the following sentence aloud to the room, and make sure the director is the person who says it.
Copy this exactly
Nobody in this organisation will be disciplined for telling me that they put something into an AI tool that they should not have. I need to know within the same day, because within three days I have to decide whether someone out there needs to be warned or moved. If you hide it from me, I cannot protect them. That is the only thing I will treat as serious. And I want to be honest about the limit of that promise. It is mine and it is real: I will not discipline you. It does not stop a funder's auditor, a court, or a future board from reading whatever we write down. That is why we keep the incident log small, keep it where we keep case files, and warn the person at risk before we tell anyone else.Check it worked
Look at section 5 and confirm three blanks are actually filled: a name, a number of days, and a physical or digital location for the incident log. If the location blank still says [WHERE], the log will end up in the approver's email, which is where an earlier draft of this recipe would have left it. Then ask the room one question out loud: 'if the exposed material was a witness statement, who do we tell first?' The right answer is the witness, and nobody outside until a lawyer has been asked. If anyone in the room answers 'the authorities', read point 4 again before you move on.
Note
This is the clause that makes the whole document work, and it is the clause missing or buried in almost every template we reviewed. NTEN's template has an INCIDENT MANAGEMENT heading carrying a single bullet; Community IT's routes violations upward to a blank department or title holder; none of them state that self-reporting carries no penalty. The reasoning is simple: an organisation that punishes disclosure stops receiving disclosures, and it does not thereby have fewer incidents, only fewer incidents it knows about. Where testimony has been exposed, the difference between hearing about it on day one and hearing about it on day forty is the difference between warning a witness and reading about them.
The second paragraph of the spoken text matters. A director who does not understand that their amnesty binds only their own management is making a promise they may be unable to keep, to a staff member who took a real risk to answer.
Step 9 / 11
Spend five minutes on section 6. Write the review date six months from today, then open your calendar and create the appointment before you leave the room, with the director and the same people invited.
Check it worked
The appointment exists in a calendar that will actually alert someone, with invitations accepted by at least two people, before anybody leaves the room. A date written only in the document is not a review; it is an intention. If your office does not use a shared calendar, write it on the wall planner in front of everyone.
Note
Six months, not twelve. NTEN's template recommends reviewing 'at least annually'. For this sector twelve months is too slow, and a policy that names ChatGPT's settings menu goes stale faster than that, while we were repairing this recipe, OpenAI's phone-verification requirement had changed outright since the previous pass. If nothing has changed at your six-month review, the review takes four minutes and costs you nothing.
Step 10 / 11
Spend the last five minutes adopting it. The director signs and dates the master copy. Everyone in the room who is one of your own people signs. Save the master copy in your own storage, not in a public shared folder, not in an email attachment chain. Then send it to the rest of your staff, volunteers, interns and board and ask them to sign a copy within one week.
Check it worked
Look at the signature sheet before you file it and ask one question about every name on it: would this person be endangered by appearing on a list held in this office? Fixers, translators, drivers and community contacts should not be on the sheet at all. They get the spoken briefing in step 11 and no attendance list. If any staff name on the sheet would itself be dangerous, take it off and brief that person out loud instead. Then confirm three things about what you circulate: the circulated copy carries the policy WITHOUT the signature sheet; your own staff get the full version including the specific RED examples, because they need it; and anything that leaves your staff, the wall copy, the copy for community contacts, carries the RED headings in general terms only.
Note
An unsigned policy is a draft, and a draft is what people argue with when something goes wrong. The signature is not a legal instrument here; it is the moment a person cannot later say they had not seen it. Keep the signed copies with your other personnel records, at the same protection level.
The restriction on who signs is deliberate and it corrects an earlier draft, which asked for signatures from fixers, translators and drivers. A signed, dated, filed list of every fixer you use is exactly the artefact your own RED list forbids, and it would sit in personnel records that are not protected as case files are. Brief them; do not enrol them.
Step 11 / 11
Within the following week, deliver a ten-minute spoken briefing to all staff, in the language they actually speak, delivered by a person and not by email. Deliver the same briefing separately to fixers, translators, drivers and community contacts. They get the rules out loud instead of a signature. Do not read the policy aloud. Cover four things only.
Copy this exactly
The four-point briefing: 1. Here are our three levels. To your own staff, hold up the master RED list and read some of it. To anyone who is not your own staff, describe the categories out loud, testimony, identities, case files, anything about a child, and do not display or hand over the page with your real examples on it. These things never go into any AI tool that connects to the internet. (Two minutes.) 2. Here is the list of tools you may use, and here is what each one may be used for. If it is not on this list, ask first. And when a tool says it is not training on your words, that means it will not learn from them. It does not mean they stayed in this building. (Three minutes.) 3. If you make a mistake, tell [APPROVER] the same day. You will not be in trouble. I need to know so I can protect the people in that information. (Two minutes.) 4. Nothing produced by an AI tool leaves this organisation until a person has checked every name, number, date and quotation against the original. Put your name on the draft when you have checked it. Never press the thumbs-up or thumbs-down button on an answer that contained our material. (Three minutes.) WHAT YOU PRINT, AND WHAT GOES ON THE WALL. Your own staff each get a printed one-page copy in their working language, the full version, kept the way they keep their case notes. The copy that goes on the wall where people work, and any copy handed to a fixer, translator, driver or community contact, is the SHORT version: the three levels named but not itemised, the rule table, the approver's name, and the four points above. A wall is read by visitors, cleaners, delivery drivers and anyone who walks in. Your specific RED list does not belong on one.Check it worked
Before you print more than one copy of the Kurdish Sorani version, print exactly ONE and look at the paper. Check that ڕ ڵ ۆ ێ ژ گ چ ک ە all appear as those letters, not as empty boxes, not silently missing, not replaced by an Arabic lookalike, and that the right-to-left line and paragraph order survived. Some fonts render correctly on screen and fail at the printer, so screen-checking is not enough. If anything is wrong, change the font and print one page again. Do the same one-page check for Arabic. Then, before you pin anything up, stand where a visitor stands and read the wall copy from there: if you can read a real project name, a district or a named set of recordings off it, take it down and print the short version. After the briefing itself, the check is a question, not a nod: ask two people, separately, to name one thing on the RED list from memory. If neither can, the briefing was a reading rather than a briefing, give it again, shorter, holding the page up.
Note
Our needs assessment found 43% of organisations have two hours a week or less to learn anything new, so ten spoken minutes plus one page on the wall is the entire realistic training budget. Design for that rather than for a workshop that will never happen. For a mixed Arabic and Kurdish team, deliver the briefing twice rather than once bilingually, a bilingual briefing is understood by nobody fully.
The font check is not fussiness. For a recipe whose entire output is a printed page on a wall, a font that silently drops Kurdish-specific letters is the failure that will actually happen to you, and it is invisible until the paper is in your hand.
The two-copy rule, a full staff version and a short wall version, is worth carrying beyond this document. A long internal policy plus a short public-facing paragraph your donors and the communities you document can actually read is a good shape for any policy you write. That is our own recommendation, not a claim about anyone else's template.
How to know the whole thing worked
Run the Wednesday test, one week after adoption, and take it seriously, a policy that reads well and fails this test has not worked. Pick three real pieces of work from the previous week: a specific document, a specific recording, a specific spreadsheet. Ask two staff members separately, without letting them confer, which level each one is and which tool they would be allowed to use on it. If the two answers differ on any of the three, your categories are not yet clear enough to act on, go back to the RED and AMBER lists and add the disputed item explicitly by name. Repeat until two people independently give the same three answers.
Second check, immediately: take the tool you placed at Level 2, open its settings in front of another person, and confirm the training toggle is still off and matches the cropped screenshot you filed in step 6. If you wrote anything into Level 1, repeat the network-off test on that machine: turn the internet fully off and confirm the model still answers. A Level 1 entry that has never been tested with the cable out is an assumption, not a control.
Third check, one question with a right answer: ask any staff member 'if I use the approved tool with training switched off, does my document leave the office?' The correct answer is yes, it leaves the office, and the toggle only stops the company learning from it. If they say no, section 2 has not landed, and the people whose top fear is information leaving are the ones most likely to be misled by their own policy.
Fourth check, over the first three months: has anyone reported an incident? If nobody has, do not conclude that nothing happened. In our needs assessment, 43% of organisations had put, or may have put, sensitive material into an AI tool, so silence in the first quarter more likely means people do not believe the no-blame clause yet. Ask the director to repeat the sentence from step 8 in a staff meeting, and check again. The first reported incident is the moment the policy started working, not the moment it failed.
Fifth check, and do it now rather than in three months: go and confirm that the step 1 replies are gone. No email thread, no notes app, no scanned pile in a drawer. If they still exist anywhere, destroy them today. They are the most dangerous document this exercise produced.
Sixth check, and it takes ten seconds: walk to the wall where the policy is pinned and read it from where a visitor stands. If your real project names, districts or file categories are legible from there, take it down and replace it with the short version. Then ask whoever briefed your fixers and community contacts whether they handed over a page, and what was on it.
What goes wrong, and what to do about it
- The hour produces a document and nothing changes, because it was never adopted or signed. Fix: the director signs before anyone leaves the room. If the director cannot attend, postpone the meeting rather than hold it, a policy written by staff and 'sent up for approval' is, in practice, never approved.
- The amnesty replies become the leak. Staff answer honestly by email, and the organisation now holds a dated, attributable list of exactly which sensitive material has already left and whose it was, sitting in a consumer inbox that syncs to phones. Fix: collect them in person or on paper, forbid case names and client names in the answers, and destroy the written record once Annex A is built. This failure is worse than the one the policy is meant to prevent, because the organisation caused it deliberately.
- The RED list ends up on the wall. You did step 4 properly, so the list names real projects, real districts and real sets of recordings, and then the policy gets pinned up where people work and handed to fixers and community contacts, which is what the briefing step used to tell you to do. You have published your own map. Fix: the master with real examples lives where case files live and goes to your own staff only; the wall copy and any copy leaving your staff carries the levels and the rule table with the RED headings in general terms.
- Everyone believes 'training switched off' means 'safe'. Staff then route AMBER, and eventually RED, through a Level 2 tool in good faith. Fix: the paragraph in capitals in section 2 of the template, said out loud, and the one-question check above. Training off means the company will not learn from it. It still left your building, it still sits on someone else's computer in another country, it can still be retained for years, read by a human reviewer, produced under a court order there, or exposed in a breach.
- Someone runs a cloud model believing it is offline. Ollama serves cloud-hosted models through the same command as local ones, and a model name ending in -cloud sends every prompt to a company's servers. Fix: `ollama ls` must show the model with no -cloud suffix, and the machine must answer a question with the network physically off before anything is written into Level 1. Untested, Level 1 is the most dangerous line in your policy, because it is the only one you have allowed for RED.
- Nobody reports incidents, and leadership concludes there are none. Fix: assume there are. The no-blame clause has to be said out loud by the most senior person present and then repeated. Written amnesty on paper without a spoken version is not believed, particularly in hierarchical workplaces.
- The organisation notifies an authority about an incident involving a source or a witness, and the notification is itself the disclosure. Fix: warn the person at risk first, always, and take legal advice before telling any authority about material concerning a source, a witness, a person at risk or a minor. If a lawyer cannot be reached, wait.
- The RED list is written in abstractions, 'personal data', 'sensitive information', so nobody can apply it on a Tuesday afternoon under deadline pressure. Fix: rewrite it as the specific things on your specific computers. 'The Anbar interview recordings' beats 'audio files containing personal data' every time.
- Approval takes too long, so staff stop asking and quietly return to whatever they were using. Fix: cap approval at three working days in writing, name a deputy for when the approver travels, and treat a missed deadline as a policy failure rather than a staff failure.
- Someone removes names from a testimony and files it as AMBER. Fix: the policy already says so, but say it again in the briefing, in a small community, the surrounding detail identifies the person. Age, village, occupation and date together are a name. De-identification is a skilled task, not a find-and-replace.
- You place a tool at Level 2 based on a vendor's marketing page rather than on the actual toggle in the actual account. Fix: switch it in the room, log out, log back in, confirm it saved, screenshot it cropped to the toggle, file it with the date. Re-check every six months, because defaults do change: ChatGPT's individual plans train on content unless you opt out, one feedback click can hand over an entire conversation even after you have opted out, Anthropic keeps feedback conversations for up to five years, and free Gemini retains already-reviewed chats for up to three years even after you delete them.
- The compliance screenshot leaks what the policy protects. A settings screenshot captures the account email, the organisation name and a sidebar of recent chat titles, case names, in this sector, and then gets sent to a funder's due-diligence officer. Fix: crop to the toggle and its label, and look at the whole frame before saving.
- The signature sheet becomes the RED artefact. Collecting signatures from every fixer, translator and driver builds a filed roster of exactly the people your RED list says must never be identifiable. Fix: your own people sign; everyone else is briefed out loud with no attendance list.
- The policy is written in English for a team that works in Arabic or Kurdish, and lives in a folder nobody opens. Fix: one printed page per person in their working language, plus one on the wall. For the Kurdish Sorani version, have a Kurdish-speaking colleague write it rather than machine-translate it, see the language section.
- The Kurdish page prints with letters missing. ڕ ڵ ۆ ێ ژ and their neighbours are dropped or substituted by fonts that carry Arabic but not Kurdish, and this is invisible on screen in some setups. Fix: print ONE page, look at the paper, change the font and print one page again until all nine letters are right. Do this before you print sixty.
- You copy a corporate template wholesale and inherit clauses that do not fit you: an in-house legal department you do not have, an IT security team you do not have, a procurement policy that does not exist. Fix: every role named in your policy must be a person who is actually employed by you and who knows they hold it.
- The policy quietly becomes a ban on AI, staff use it anyway on personal phones, and you now have the same exposure with none of the visibility. Fix: a workable route for GREEN and AMBER work is what makes the RED rule survivable. A pure prohibition on everything is the least safe policy you can write, but note the difference: a prohibition on RED specifically, with GREEN work permitted on free tools, is not a pure prohibition and is a perfectly good policy for an office that cannot afford Level 2 or run Level 1.
How well it works in your language
Arabic (Modern Standard) · Iraqi Arabic · Kurdish (Sorani)
Arabic (Modern Standard)
Good. A policy is formal, short, and full of standard institutional vocabulary, which is the single easiest register for both machine translation and for AI assistance, far easier than testimony, dialect speech, or literary text. Write the master version in whichever language your leadership actually argues in, then produce the Modern Standard Arabic version and have one Arabic-speaking colleague read it aloud to the team before you sign. Real Arabic reference material exists and is worth reading before you start: ARIJ's AI strategy playbook for small and medium Arab newsrooms is written in Arabic and is the only genuinely MENA-specific resource we found. The Rory Peck Trust's four safety templates are published in Arabic as well as English, re-checked on their page in this session, all four have an Arabic version. One correction that this recipe carried before and still stands: we once claimed an official Arabic version of RSF's Paris Charter at rsf.org/ar. We opened the Charter page again in this session and could not confirm that. See the evidence field, plan on the English or French Charter, and treat an Arabic one as a bonus if you find it.
Iraqi Arabic
Do not translate the policy into Iraqi dialect, a written policy in dialect reads as informal and people will treat it as a suggestion. MSA is the correct register for the document. Iraqi Arabic belongs in the ten-minute spoken briefing in step 11, delivered by a person, not by a machine. Machine translation into Iraqi Arabic remains weak and inconsistent, and there is no reason to expose yourself to that risk when a colleague can simply explain the document out loud.
Kurdish (Sorani)
Weaker, and you should plan for it. We could not find a single AI policy, AI ethics framework, or AI governance template published in Kurdish Sorani for organisations, not among the international civil society sources we searched, and not from the Kurdish organisations we could reach. We are stating that as the limit of our own search, not as a fact about the world: if your organisation holds one, we are wrong and we want it, and it would be worth more to the region than anything on our source list. Every reusable template we located is English-only or English-and-Arabic.
Machine translation into Sorani is noticeably less reliable than into Arabic. Practical instruction: have a Kurdish-speaking colleague write the Sorani version by hand from the English or Arabic master. Do not machine-translate it and then post-edit, for Sorani, post-editing bad output takes longer than writing it fresh, and the errors that survive are the quiet ones. Budget an extra 45 to 60 minutes for this, outside the hour.
The practical failure that will actually happen to you, and which this recipe previously omitted: the printed page. Sorani uses Arabic-script letters that Arabic itself does not, ڕ ڵ ۆ ێ ژ گ چ ک ە, and several default fonts on Windows carry the Arabic set but drop or substitute these, so they come out as empty boxes, as the wrong letter, or silently vanish. This is a printing failure, not a translation failure, and it survives every spellcheck. Before you print sixty copies: type those nine letters into your document, set the font you intend to use, and PRINT ONE PAGE. Look at the paper, not the screen, some fonts render on screen and fail at the printer. If any letter is wrong or missing, change the font and print one page again. Free fonts with broad Kurdish coverage are available from fonts.google.com; we have not tested a specific one and will not name one we did not verify, so test whichever you pick against those nine letters. Right-to-left layout also still breaks in some word processors and web forms, check that your line and paragraph order survived the print, not just the letters.
What that rests on
Everything stated here was opened in this session, 30 August 2026. Anything we could not open today has been cut rather than restated on the strength of an earlier reading. That is the rule this pass was run under, and it is why some detail that appeared in earlier drafts is now simply gone.
RORY PECK TRUST, opened and read this session, and the language matrix is reproduced exactly as the page shows it. Four templates. Risk Assessment & Security Protocol: English, Arabic, Spanish (coming soon), Ukrainian, Russian (coming soon). Communications Plan: English, Arabic, Spanish, Ukrainian, Russian (coming soon). Digital Risk Assessment: English, Arabic, Spanish (coming soon), Ukrainian, Russian (coming soon). Proof of Life: English, Arabic, Spanish (coming soon), Ukrainian, Russian (coming soon). So: Arabic and Ukrainian for all four, Spanish live only for the Communications Plan, no Kurdish of any variety anywhere on the page, and no AI guidance on the page at all.
RSF PARIS CHARTER, opened this session at rsf.org/en/paris-charter-ai-and-journalism. The page states verbatim: 'Published on November 10, 2023, by Reporters Without Borders (RSF) and 16 partner organizations, this charter represents the first global ethical benchmark for AI and journalism', under a heading 'THE TEN PRINCIPLES'. RSF's site language switcher does offer العربية among others. We could not confirm an Arabic version of the Charter itself and we are not claiming one. Do not promise your team an Arabic Paris Charter on our word.
ARIJ, the playbook at arij.net/ai/playbook/arij-strategy/index.html was opened this session and is live and in Arabic, titled استراتيجية اريج للذكاء الاصطناعي. The English announcement at en.arij.net, also opened this session, is dated July 17, 2023 and states ARIJ released the first Arabic Language AI strategy for small to medium media outlets in the Arab World, supported by Google News Initiative, and that you can 'evaluate the AI maturity of any media organization, and explore AI glossary in Arabic'.
NTEN and COMMUNITY IT, both PDFs downloaded and read this session. NTEN's is 11 pages (an earlier draft of this recipe said nine; that was wrong and is corrected here), cover-dated 2024, with Exhibit A and Exhibit B, an 'INCIDENT MANAGEMENT' heading carrying a single bullet, an 'at least annually' review recommendation, and repeated references to 'Organization Legal'. Community IT's is 5 pages and routes violations to a blank: 'They must also report policy violations to Our Organization's _____________ department/title holder.' Both English-only.
TECHSOUP, PDF downloaded and read this session, 17 pages, front matter stating verbatim that the guide 'was commissioned and funded by Microsoft and was produced in partnership with TechSoup', with Microsoft Copilot named throughout.
POYNTER. We could NOT open it this session; poynter.org returned HTTP 403 to our request twice. Earlier drafts of this recipe described what the starter kit contains. We have deleted that description rather than repeat a reading we could not reproduce today. The link is in sources; open it yourself and judge it.
KURDISH SORANI, a targeted search for Kurdish Sorani AI policy or ethics guidance for organisations returned Kurdish AI products and a KRG orthography-standardisation initiative, but no policy or ethics guidance.
The Sorani machine-translation quality judgement is a general observation about low-resource-language MT, not a benchmark we ran, treat it as a caution, not a measurement. The Kurdish font warning is likewise a practical caution about font coverage, not a test of any named font; that is exactly why the instruction is 'print one page and look at it' rather than 'use font X'.
Software named in this recipe
- Pen and paper (the recommended route, the full template is inline at step 3)
- Any word processor already installed: Word, Notepad, Pages, TextEdit, Google Docs
- LibreOffice Writer, free, no account, Mozilla Public License v2.0; take whichever branch libreoffice.org is offering, and the older longer-tested branch on older machines. Windows installer approximately 360 MB
- NTEN Generative AI Use Policy Template for the Social Sector (11 pages, cover-dated 2024)
- Community IT Innovators Acceptable Use of AI Tools Template (5 pages)
- TechSoup / Microsoft AI Usage Policy resource guide (17 pages; commissioned and funded by Microsoft)
- Poynter AI Ethics Starter Kit. We could not open the page in this session; see sources before you rely on it
- ARIJ Arabic AI strategy playbook for small and medium Arab newsrooms
- RSF Paris Charter on AI and Journalism (English page confirmed this session; Arabic NOT confirmed, see evidence)
- Rory Peck Trust Essential Templates (English, Arabic and Ukrainian for all four; no Kurdish)
- Charity Excellence Framework AI policy template (free but login-gated; we did not register and did not read it)
- ChatGPT / OpenAI (data controls at privacy.openai.com, or the Data Controls FAQ in ChatGPT)
- Claude / Anthropic (Privacy Settings > Model Improvement)
- Google Gemini (Keep Activity setting)
- Ollama and LM Studio (offline Level 1, but verify with `ollama ls` and a network-off test; Ollama also serves cloud models)
Sources
- https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance · OpenAI, how your data is used to improve model performance. OPENED AND READ IN FULL IN THIS SESSION, 30 August 2026. Confirms verbatim that for services for individuals such as ChatGPT and Codex 'we may use your content to train our models', that the opt-out is the privacy portal ('do not train on my content') or the Data Controls FAQ, that 'Once you opt out, new conversations will not be used to train our models', and that Temporary Chat is excluded from history, memories and training. Also states, verbatim: 'Even if you have opted out of training, you can still choose to provide feedback to us about your interactions with our products (for instance, by selecting thumbs up or thumbs down on a model response). If you choose to provide feedback, the entire conversation associated with that feedback may be used to train our models.'
- https://help.openai.com/en/articles/8983040-what-does-phone-verification-look-like · OpenAI, phone verification. OPENED IN THIS SESSION. States plainly: 'Phone verification is no longer required for new OpenAI account creation or ChatGPT usage.' And: 'Phone verification is now mandated on platform.openai.com for generating your initial API key, though not for any subsequent API key generation after that.'
- https://help.openai.com/en/articles/8983024-can-i-use-a-premium-number-landline-google-voice-or-other-voip-phone-number · OpenAI. Cited for the rule that landlines, VoIP, Google Voice and premium numbers are not supported and verification is by SMS to a mobile. The same restriction is stated on the phone-verification article above, which we opened in this session.
- https://help.openai.com/en/articles/8983038-which-countries-do-you-support-for-whatsapp-phone-verification · OpenAI. OPENED IN THIS SESSION. The full list as shown: United Arab Emirates, Egypt, Indonesia, Israel, India, Malaysia, Nigeria, Pakistan, Saudi Arabia, Turkey, Ukraine, Vietnam. IRAQ IS NOT ON THE LIST, so an Iraqi organisation needing an API key requires an SMS-capable +964 mobile.
- https://privacy.claude.com/en/articles/10023580-is-my-data-used-for-model-training · Anthropic. OPENED IN THIS SESSION; the page's own last-updated date is 16 March 2026. Confirms consumer Claude Free, Pro and Max are not used for training by default, that model improvement is opt-in via the Model Improvement setting in Privacy Settings, and verbatim: 'Your Incognito chats are not used to improve Claude, even if you have enabled Model Improvement in your Privacy Settings.' Also verbatim: 'When you provide us feedback via our thumbs up/down button, we will store the entire related conversation, including any content, custom styles or conversation preferences, in our secured back-end for up to 5 years.'
- https://support.claude.com/en/articles/8287232-verify-your-phone-number · Anthropic help centre. OPENED IN THIS SESSION. Verbatim: 'you cannot use VoIP numbers, Google Voice, phone numbers created using apps, landlines, or other numbers that can't receive texts to verify your account'; 'We only accept phone numbers from our supported locations at this time'; 'Only users physically located in one of our supported locations can create and use Claude accounts'; that they 'require phone verification for all new users, and there isn't a way to skip this step'; and that if more than five minutes pass without a code you should click 'Try again' and re-enter the number.
- https://support.google.com/gemini/answer/13594961 · Google, Gemini Apps privacy. OPENED IN THIS SESSION. Verbatim: 'Human reviewers (including trained reviewers from our service providers) review some of the data we collect for these purposes. Please don't enter confidential information that you wouldn't want a reviewer to see or Google to use to improve our services, including machine-learning technologies.' Also verbatim: 'Chats reviewed by human reviewers (and related data like your language, device type, location info, or feedback) are not deleted when you delete your activity. Instead, they are retained for up to three years.' And: 'Temporary chats and chats you have when Keep Activity is off are retained with your account for 72 hours.'
- https://docs.ollama.com/cloud · Ollama cloud documentation. OPENED IN THIS SESSION. Verbatim: 'cloud models are automatically offloaded to Ollama's cloud service while offering the same capabilities as local models'. The documented command to run one is `ollama run gpt-oss:120b-cloud`, the same `ollama run` used for local models, with a -cloud suffix on the name. This is the basis for the Level 1 warning; the claim that Ollama 'sends nothing anywhere once the model is downloaded' is no longer unconditionally true.
- https://docs.ollama.com/cli · Ollama CLI reference. OPENED IN THIS SESSION. Under 'List models' the documented command is `ollama ls`. That is why this recipe now tells you to type `ollama ls` rather than the `ollama list` an earlier draft used, and why the earlier draft's added qualifier about a size in gigabytes has been deleted: no Ollama documentation we opened supports it.
- https://www.anthropic.com/supported-countries · OPENED IN THIS SESSION. Iraq is listed, between Indonesia and Ireland.
- https://developers.openai.com/api/docs/supported-countries · OPENED IN THIS SESSION. Iraq is listed among supported countries and territories, between Indonesia and Ireland.
- https://www.libreoffice.org/download/download-libreoffice/ · OPENED IN THIS SESSION. Free, no account, and the page states the source code is licensed under the Mozilla Public License v2.0. The page offers a current branch and an older longer-tested branch side by side; we have deliberately not printed the version numbers, because they will be wrong by the time you read this, take whichever branch the site offers, and the older one on older machines. Download size, measured in this session by requesting the headers of the Windows x86-64 MSI linked from that page: 374,906,880 bytes, which is about 360 MB. Do not pin a point release in a printed handout.
- https://rorypecktrust.org/get-help/safety/essential-templates/ · Rory Peck Trust Essential Templates. OPENED IN THIS SESSION. Four templates with the languages shown against each: Risk Assessment & Security Protocol (English, Arabic, Spanish coming soon, Ukrainian, Russian coming soon); Communications Plan (English, Arabic, Spanish, Ukrainian, Russian coming soon); Digital Risk Assessment (English, Arabic, Spanish coming soon, Ukrainian, Russian coming soon); Proof of Life (English, Arabic, Spanish coming soon, Ukrainian, Russian coming soon). No Kurdish of any variety. The Rory Peck Trust does not publish an AI policy or AI guidance, despite being an obvious place to look. The Digital Risk Assessment is the one to take. Its structure for naming a threat, its likelihood and its mitigation transfers directly onto AI tools, and it is already in Arabic.
- https://rsf.org/en/paris-charter-ai-and-journalism · Reporters Without Borders, Paris Charter on AI and Journalism. OPENED IN THIS SESSION. Verbatim: 'Published on November 10, 2023, by Reporters Without Borders (RSF) and 16 partner organizations, this charter represents the first global ethical benchmark for AI and journalism.' The page is organised as a Summary, THE TEN PRINCIPLES and PARTNERS. PRINCIPLES, NOT A POLICY. It will not tell you what to do on Tuesday, but it is the strongest available statement of why and it carries real institutional weight with funders. RSF's site language switcher offers العربية, but we could not confirm an Arabic version of the Charter itself and do not claim one.
- https://www.poynter.org/ai-ethics-journalism/ai-ethics-guidelines/ · Poynter AI Ethics Starter Kit. WE COULD NOT OPEN THIS IN THIS SESSION: poynter.org returned HTTP 403 to our requests, twice, with different headers. An earlier draft of this recipe described the kit's contents and structure; we have deleted that description rather than repeat a reading we could not reproduce today. The link is here because it is a well-known free newsroom resource and worth your own click. Judge it yourself; we are not vouching for what is on it.
- https://word.nten.org/wp-content/uploads/2024/07/GAI-Policy-Template.pdf · NTEN, Generative AI Use Policy: A Template for Organizations. PDF DOWNLOADED AND READ IN THIS SESSION: 11 pages (an earlier draft of this recipe said nine. That was wrong), cover-dated 2024, by Nolwenn Godard and Lindsey Washburn. GENUINELY REUSABLE, and the best free starting point in the sector. Includes an Exhibit A list of approved GAI tools and an Exhibit B of dos and don'ts, and covers permissible use, corporate accounts, personal-data inputs, output review and bias. Weaknesses for this audience: its INCIDENT MANAGEMENT section is a single bullet, it says nothing about non-punitive disclosure, it repeatedly routes decisions to an 'Organization Legal' function a five-person NGO does not have, and it recommends reviewing 'at least annually', which is too slow. English only.
- https://communityit.com/wp-content/uploads/2025/06/Template-Acceptable-Use-of-AI-Tools-in-the-Nonprofit-Workplace.pdf · Community IT Innovators, Acceptable Use of AI Tools template. PDF DOWNLOADED AND READ IN THIS SESSION: 5 pages. GENUINELY REUSABLE and the most permissively licensed: 'All or parts of this policy can be freely used by your organization. There is no prior approval required.' Short, plain, and requires a documented approved-tools list. Weaknesses: no data classification; incident handling is a blank. 'They must also report policy violations to Our Organization's _____________ department/title holder'; and it states that 'Our Organization reserves the right to review and monitor all communications' shared with generative AI systems, which is a reasonable corporate clause and a chilling one in a human rights office. English only.
- https://page.techsoup.org/hubfs/Downloads/AI-Usage-Policy.pdf · TechSoup, AI Usage Policy resource guide. PDF DOWNLOADED AND READ IN THIS SESSION: 17 pages. PARTLY USEFUL, NOT A TEMPLATE. It is a guide about writing a policy rather than a policy you can adopt, and the front matter states verbatim that it 'was commissioned and funded by Microsoft and was produced in partnership with TechSoup'; the worked examples steer toward Microsoft Copilot. The genuinely useful idea we kept is its tip to document low-risk, high-risk and completely-avoid task categories. Treat the tool recommendations as vendor-shaped.
- https://arij.net/ai/playbook/arij-strategy/index.html · ARIJ, Arabic-language AI strategy for small and medium Arab newsrooms. OPENED IN THIS SESSION and confirmed live and in Arabic, titled استراتيجية اريج للذكاء الاصطناعي. THE MOST RELEVANT MENA-SPECIFIC RESOURCE WE FOUND, and the only substantial Arabic one. Written for newsrooms rather than NGOs generally, so a human rights documentation organisation will need to adapt it, but the vocabulary problem it solves, how to talk about this in Arabic at all, is real and it solves it well.
- https://en.arij.net/news/arij-releases-the-first-arabic-language-ai-strategy-targeting-media-organizations-ai-strategy/ · ARIJ announcement. OPENED IN THIS SESSION, dated July 17, 2023. States that ARIJ released the first Arabic Language AI strategy for small to medium media outlets in the Arab World, 'supported by Google News Initiative', and that on the strategy site you can 'evaluate the AI maturity of any media organization, and explore AI glossary in Arabic'.
- https://www.charityexcellence.co.uk/ai-policy-charities-and-nonprofits/ · Charity Excellence Framework. PAGE OPENED IN THIS SESSION, BUT THE TEMPLATE ITSELF WAS NOT READ. The resource is free but requires you to register and log in, which we did not do, so we cannot vouch for its contents and we have not restated the summary an earlier draft carried. UK-charity-shaped. Registration on a UK platform is an unnecessary step for an Iraqi organisation when NTEN's and Community IT's templates are ungated and we have actually read them.
- GIJN and Reuters, searched in an earlier pass; we did not verify a reusable AI policy template from either, and we are not recommending one. Reuters' publicly reported position that AI output is verified by a journalist before publication is worth borrowing as a one-line rule, but we know of no adoptable document behind it.
- Internal needs assessment, 14 MENA civil society organisations, August 2026, the source of the 43% and 86% figures used in this recipe. Aggregates only; the raw responses are personally identifying and are not published, not committed to the project repository, and not attributable to any named organisation. Read in this session from the project's own design specification. Fourteen respondents is a small sample: treat these as the shape of the room at this conference, not as a statistic about the sector.
- REMOVED FROM THIS RECIPE: an earlier draft referred readers to an interactive 'Policy Builder' on the gov2ai portal at /policy/, and described its privacy behaviour as verified. That page does not exist. It appears only as a line in an unbuilt design specification; the site currently has a single page, and its domain is still a placeholder. Every reference to it has been deleted and the full blank template is now printed inline at step 3 so the recipe stands alone on paper. Nothing of value was lost, the template was always the substance, and paper was always the better route for this audience.
A CDR original, written for POINT Conference Iraq 7. Checked against vendor pages and package registries in August 2026; the sources are listed on this page.
What we could not verify
Eight things we want to be straight about.
FIRST, the hour is real but it is the drafting hour only, and there are two short tasks before it. The eight in-meeting steps add up to exactly sixty minutes. Before that, budget five minutes to send the amnesty message a day ahead and ten to thirty minutes the day before to make sure any account you intend to place at Level 2 actually exists and you can log into it. That pre-check exists because its absence could dead-end the meeting. Afterwards, budget another 60 to 90 minutes across the following week for translations, signatures from people who were not in the room, and the ten-minute briefing, plus a further 45 to 60 minutes if you need a Kurdish Sorani version, which has to be written by a person rather than machine-translated.
SECOND, A ROUTE WAS REMOVED FROM THIS RECIPE. An earlier version told you to print the blank template from an interactive Policy Builder on the gov2ai portal at /policy/, and described that tool's privacy behaviour as something we had checked. That page does not exist. It exists only as a line in an unbuilt design specification; the portal is currently a single page, every route it will eventually serve is language-prefixed so a bare /policy/ address would not work even once built, and the domain is still a placeholder. We removed all five references rather than patching them. The full template is now printed inline at step 3, which is where it should always have been for a recipe meant to work on paper in a room with no connection. If you were handed an earlier copy of this recipe at the conference and tapped that link, that is why it failed, and we are sorry.
THIRD, we could not find a single AI policy or AI ethics resource published in Kurdish Sorani for organisations, from anyone we searched. We state that as the limit of our search rather than as a fact about the world, if you hold one, we are wrong and would like to be corrected. Every reusable template in our sources is English-only except Rory Peck's risk templates, which have Arabic. Kurdish-working organisations are genuinely underserved here and we are not going to pretend otherwise; if you produce a good Sorani version, it would be worth more to the region than anything on our source list. Note the practical point: the failure most likely to hit you is not translation but printing, because several common fonts drop the Kurdish-specific letters silently. Print one page and look at the paper before you print sixty.
FOURTH, this is not legal advice and we did not verify Iraqi data protection law in this session, so we make no claim about what Iraqi law requires of you, check with a local lawyer, particularly if you hold data on identifiable individuals or report to European funders whose own obligations flow down to you in contract. The one place where this genuinely matters inside the recipe is the incident procedure: there is an explicit brake written into it, telling you not to notify any authority about material concerning a source, witness, person at risk or minor without legal advice first, because in some of these cases the notification is itself the disclosure.
FIFTH, a contradiction we were carrying until this pass, and it was ours. Step 4 tells you to make the RED list specific, real projects, real districts, real sets of recordings, because a vague list cannot be applied under deadline pressure. The RED list itself is classified RED by the policy, and the data section calls it a map of what could get someone hurt. And then the briefing step told you to hold that list up, hand a printed copy to every fixer, translator, driver and community contact, and pin one on the wall. Three rounds of repair did not notice. The fix is in the template's section 1 now: the master with real examples lives where case files live and circulates to your own staff; the wall copy and any copy leaving your staff carries the levels and the rule table with the RED headings in general terms only. If you were working from an earlier copy, go and look at your wall today.
SIXTH, the most consequential factual correction this recipe has carried. We once wrote that a model run through Ollama or LM Studio 'sends nothing anywhere once the model is downloaded', and called that the only category honestly safe for RED. Ollama now also serves cloud-hosted models through the same command, with a -cloud suffix in the name, and its own documentation says those are automatically offloaded to Ollama's cloud service. Someone following the old wording could have sent their most dangerous material to a company's servers while believing it never left the laptop. Level 1 now carries two mandatory checks, and the one that actually decides it is the network-off test, not the name check. Related and worth stating plainly: as a rule of thumb, Level 1 wants roughly 16 GB of RAM to be useful, and for an office on 8 GB laptops it is not practically available. For that office the correct rule for RED is no AI tool at all. That is a complete policy, not a failure to write one.
SEVENTH, two things we were previously silent about that this audience needed most. The replies to the amnesty message are more sensitive than the policy, a dated, attributable record of which material has already left and whose, and an old version routed them through email. They are now collected in person or on paper and destroyed once the tools list is built. And 'not used for training' is not the same as 'not transmitted, not stored, not retained, not disclosable'. For a room where 86% fear sensitive information leaving the organisation, that was the one distinction that had to be in the document, and it was not. It is now the paragraph in capitals in section 2.
EIGHTH, and this is the rule this final pass was run under. Everything this recipe states about vendor privacy settings, account requirements, download sizes, page counts and publication dates was opened and read in this session, 30 August 2026, against the source's own page, and anything we could not open today has been deleted rather than restated from an earlier reading. That is why some specifics that appeared in earlier drafts are simply gone: a description of the Poynter starter kit we could not load, several publication dates we could not see on the page, a claim about how local models appear in an Ollama listing that no Ollama documentation supports, a pinned LibreOffice version number, and 'updated N days ago' stamps that mean nothing to a reader holding this a year from now. What survives, survives because we read it. Vendor terms still change without announcement, OpenAI dropped phone verification for ChatGPT account creation between two passes of this recipe while Anthropic kept it, which is precisely why the review cadence in this policy is six months, why we ask you to screenshot the toggle rather than trust your memory, and why every price question in this recipe sends you to the vendor's own pricing page rather than printing a number.
And the thing this policy cannot do: it will not protect anyone if a device is seized, an office is raided, or an account is compromised. It reduces the chance that your own staff hand sensitive material to a third party by accident, which is a common and preventable failure. The other kind of failure needs a different document and, in most cases, more urgency.