How nonprofits can use AI safely
AI can give a small nonprofit team back dozens of hours a week. It can also leak donor data, invent a grant deadline that doesn't exist, or write something embarrassing in your voice. The line between the two is mostly about having a clear policy and making a few simple choices.
Where AI genuinely helps a small nonprofit
These are the use cases we see produce real ROI without much risk:
- Drafting and tightening communications. Newsletters, thank-you notes, grant narratives — drafted by AI, edited by humans.
- Summarizing long documents. Board packets, RFP responses, grant guidelines turned into a one-page brief.
- Meeting notes. Automated transcripts and action-item summaries from staff calls.
- Translation. Drafting bilingual program materials, with native-speaker review.
- Volunteer matching. Sorting incoming volunteer applications against open shift needs.
- Donor research. Synthesizing public profiles of major-gift prospects into a one-page brief.
- Data cleanup. Standardizing addresses, deduplicating donor records, normalizing program data.
Where to keep humans squarely in the loop
These are the categories where AI mistakes hurt more than they help:
- Eligibility decisions. Who gets served, who qualifies for a program, who receives funds — humans only.
- Clinical or legal advice. AI can summarize, but the actual guidance comes from a licensed person.
- Sensitive outreach. Crisis messaging, condolences, anything involving a beneficiary in distress.
- Grant compliance attestations. If you sign something, you read it.
- Public statements. Anything that goes out in your ED's voice or your board's name gets human review.
Three illustrative scenarios
Scenario 1 — A small food bank automates donor thank-yous. They give the AI just the donation amount, donor name, and which program it's for, and it produces a draft thank-you in the director's voice. Staff review and send. Time per letter drops from 12 minutes to 2. Critically: the AI never sees email addresses, phone numbers, or anything beyond what's needed for the letter itself. The AI provider has a signed privacy agreement and is set so it doesn't store or learn from the information.
Scenario 2 — A youth-services nonprofit summarizes intake notes. Caseworkers dictate field notes after home visits, and an AI tool turns them into a tidy summary in the case-management system. To avoid sending young people's names to an outside AI service, the names are swapped out for codes before anything is sent — so the AI never sees the real names. A licensed clinical director reviews flagged summaries weekly.
Scenario 3 — A faith-based ministry uses AI to draft sermons-in-progress and small group guides. The ministry has a clear written policy: AI is a research and drafting tool, never a substitute for pastoral discernment. Any AI-assisted material is reviewed by the lead pastor before use. The guideline they tell staff: "AI can shape clay; only a pastor decides what to make."
The data question — the part most articles skip
When you paste something into a chatbot, you're sending that content to a third party. For a nonprofit, that can implicate donor confidentiality, beneficiary privacy, HIPAA (for health-adjacent orgs), FERPA (for education), and sometimes state-level privacy laws. The safe baseline:
- Use a paid business account, not a free one. Free consumer tools often learn from what you type by default. Paid business plans typically don't — but read the terms.
- Turn off data storage where it's offered. Most business providers let you switch off any saving of what you send and receive.
- Get a written privacy agreement. If the provider won't sign one, that tells you something.
- Don't paste sensitive details. Social Security numbers, full birth dates, addresses, medical info, bank account numbers — strip them out before they go anywhere near the AI.
- If you handle medical information, get a formal health-privacy agreement. Some major AI providers will sign one (it's called a BAA); some won't. Don't assume.
A starter AI policy for a 5–50 person nonprofit
You don't need a 40-page policy document. You need one page everyone reads. The essentials:
- Approved tools. Name them. "Staff may use [X] and [Y] with their work accounts. No other AI tools without IT approval."
- What never goes in. A short list: SSNs, dates of birth, beneficiary medical information, donor giving history beyond what's already public, anything marked confidential.
- Always disclose AI-generated public content. When AI substantively wrote something the public will see, say so.
- Double-check facts and dates. AI can confidently make up grant deadlines, legal references, and historical facts. Check before publishing.
- A human signs off on outbound messages. No automated agent sends emails or texts to donors or beneficiaries without a person approving.
- An incident path. If a staff member realizes they pasted something sensitive, they tell the operations lead immediately. No blame — just speed.
The biases worth knowing about
AI systems trained on the internet absorb the internet's biases. For mission-driven organizations especially, that matters. If you use AI to screen, summarize, or evaluate descriptions of people, watch for systematic patterns — by name, race, language, geography. A quick way to test: take a sample output, swap the identifying details to a different demographic, and see if the answer changes. When in doubt, keep a person in the loop on anything that touches who-gets-what.
If you're just starting
You don't need a strategy document; you need a 90-day experiment. Pick one workflow your team genuinely dreads — drafting newsletters, transcribing meetings, processing volunteer applications — and apply AI to that one thing with the policy above. Measure the time saved. Decide if it was worth it. Then pick the next one.
If you'd like help thinking through which workflows to start with, or want AI that works with your own information without sending it to an outside company, our AI service is built for exactly this. The first call is free, and we'll tell you when AI isn't the right answer too.
Related articles
Want to put AI to work — safely?
Tell us what your team is buried in. We'll help you pick a workflow to start with and protect the data that needs protecting.