Why Libraries Need AI Policies Before AI Spreads
Why Libraries Need AI Policies Before AI Spreads A staff member pastes a patron’s résumé into a free AI tool to get ...
Why Libraries Need AI Policies Before AI Spreads
A staff member pastes a patron’s résumé into a free AI tool to get help revising it. Another drops an AI-generated image into a flyer. A third gets a vendor proposal with an "AI assistant" already switched on. None of those choices is wild on its own. Without shared guidance, though, you are making AI decisions one prompt at a time.
That is why libraries need AI policies. Not a 20-page document that lives in a shared drive. A short, usable one that tells staff what they can do tomorrow morning, what they must not put into a tool, and who they ask when they are not sure.
I talk with library people every week. The ones who feel behind are usually waiting for a perfect policy. You need something staff can remember at 4 p.m. with a line at the desk.
AI use is a library service decision
Generative AI can support real work. Staff use it to brainstorm program ideas, simplify a draft, try a first-pass translation, or organize notes. Patrons ask what it does, whether an answer is trustworthy, or how to use it in a job search.
Those uses are not all alike. A tool that helps you draft a social caption is a different risk than a tool that sees a patron’s account, a child’s situation from a reference interview, or a hiring packet. A policy is how you draw that line before someone has to guess.
This only works if it fits your building. A small rural library needs a short, plain-language page staff can apply quickly. A consortium can write shared language so members are not inventing this from a blank page.
The goal is not to predict every new tool. It is to say how you will make the next decision when one shows up.
Public trust depends on clear boundaries
We have spent decades protecting what people read, watch, borrow, search, and ask. A lot of AI tools complicate that, because prompts and uploads can leave the library.
Staff need a default they can say out loud: if it identifies a person, or could be connected to a person, it does not go into an unapproved tool. That means names, contact information, card numbers, account details, private reference questions, personnel notes, and the details a patron told you at the desk even if you drop the name.
If you put AI on public computers, or fold it into a service, patrons should know what the tool does, what it may collect, and where they can get help. They do not need a technical briefing. They need enough to make a choice.
Privacy rules are not the same in every state or province. A policy does not replace legal review. It makes sure the privacy question gets asked before the tool becomes part of regular service. When a contract is in play, send it for contract or legal review instead of hoping the vendor’s privacy page is enough.
Accuracy is not the same as authority
AI can produce a confident answer that is incomplete, outdated, biased, or simply wrong. That is not a reason to ban every tool. It is a reason to be clear about human review.
Use it for a first draft or a pile of ideas. Do not treat it as a final source for health, legal, financial, employment, or local information. If a claim is going into a flyer, a handout, or a desk answer, a person checks it.
This is media literacy work you already know how to do. An answer can sound polished and still need a source. Staff do not have to become AI experts. They need a simple expectation: use judgment, verify material claims, and tell a supervisor when the stakes are high.
Give them three sentences they can actually say.
"I can help you try a tool, but we will not paste your personal details into it."
"I can help you check what it gave you. I cannot tell you it is true."
"If this is legal, medical, or money, we will point you to a trusted source or a qualified person. A generated answer is not that."
Put those next to the policy. People remember sentences. They do not remember section 4.2.
Staff need permission, not a vague warning
"Be careful with AI" does not help much. Staff need examples of what is fine, what is not, and what needs a second pair of eyes.
You can allow an approved tool to brainstorm event titles or rewrite a public paragraph, as long as no confidential information goes in and a person reviews the result. You should not let AI make a hiring decision, score a staff member, decide whether a patron is eligible, or create an official record with nobody looking at it.
Disclosure depends on the work. A handout that has been thoroughly checked may not need a label because AI helped an early draft. An AI-generated image in promotion, a chatbot reply, or a patron-facing resource may. Decide what is meaningful for your community instead of labelling everything mechanically.
Training is what makes the policy real. One short session with your own examples beats a long appendix: a translated program description, a job seeker’s cover letter, a flyer, a vendor demo. If you want a weekly habit instead of a one-off in-service, NovareFOCUS has library-specific microlearning, including an introduction to AI. We already published A Guide to Staff AI Governance for Public Libraries if you need the longer staff framework.
Procurement needs a better set of questions
AI features are showing up in products you already pay for. Sometimes they are optional. Sometimes they are on by default. A policy gives your eResource people a reason to ask questions before a concern shows up at the desk.
Ask what data it collects, where that data goes, how long it is kept, whether it trains a model, and whether a patron can opt out. Ask how the provider tests for bad outputs, what human support you get, and whether you can turn the feature off.
Accessibility belongs in the same conversation. A feature that helps one patron can block another. Look at language access, screen reader compatibility, plain-language instructions, and an alternative for people who do not want the feature.
A vendor’s "AI" badge is not information. You need to know whether it solves a defined problem, whether staff can explain it, and whether it meets the privacy and access bar you already use for digital resources. This policy just needs to say: do not turn it on because the demo was slick.
What to put in the two-pager
The best policy is clear enough to guide a busy staff member on a Tuesday afternoon. It can be brief if it names the decisions that matter.
- Purpose and scope. Why you evaluate or use AI, and which staff, services, and tools it covers.
- Privacy and data. What must never go into a tool, and when legal or contract review is required.
- Acceptable use and human review. Permitted uses, prohibited uses, fact-checking, and decisions that stay with people.
- Patron communication. How you explain an AI-enabled service, how people opt out, and where the alternative is.
- Procurement, training, and review. Vendor questions, who trains staff, and who updates the policy when a tool or a community need changes.
Do not rewrite your whole manual. Point to privacy, records, computer use, and intellectual freedom. Those still apply. The AI policy tells staff how those older rules work when a tool can draft, translate, or invent.
Ask your counsel or state library whether prompts and outputs count as records where you are. That answer is not the same everywhere, and I am not going to pretend it is.
Start before you feel ready
Waiting for a perfect policy leaves staff guessing while the tools keep arriving. Map where AI is already showing up. Ask staff what they use, what patrons ask, and which vendors have switched a feature on. Write clear direction for the highest-risk situations first.
Include the people who will carry it. Public service staff know where patrons get stuck. Technology staff see the data questions. eResource leads see the vendor side. Directors connect it to the policies you already have.
If you have an hour this week: twenty minutes on purpose, the privacy default, and three use categories, with examples from your building. Twenty on the owner and the approved-tools list, even if the list is only "our office suite, with training turned off" and "nothing else until we review it." Twenty on the three desk sentences and getting the draft onto the next board or management agenda.
If you want a working session rather than another document, we are running Smarter with AI: An Ethical Workflow for Everyday Library Work on September 2.
You do not need to be the library that wrote the national model policy. You need to be the library where a staff member knows what not to paste, and who to ask. That is the whole point.
If you want a second pair of eyes on a draft, get in touch.