Risk · Governance

Shadow AI safety check for nonprofits

Your staff are probably already using AI — with personal accounts, on their phones, with donor data — and you don't know about it. That's "shadow AI," and it's the #1 AI governance risk for nonprofits right now.

Signs your org has a shadow AI problem

  • You have no official AI policy or approved tool list
  • Staff use personal ChatGPT or Claude accounts for work
  • Donor names, program data, or financials have been pasted into free AI tools
  • Leadership hasn't discussed AI use — but the team is already using it
  • You can't answer: "What AI tools is our team using right now?"

What to do about it

1
Get a policy in place today
An AI use policy sets the rules and gives staff clarity. Without one, you can't hold anyone accountable. Generate yours free →
2
Move staff to an org-owned account
A team-level AI account (ChatGPT Team, Claude Team, etc.) lets you control access, audit use, and ensure data isn't used for training.
3
Make it easy to do the right thing
Shadow AI happens when the approved path is harder than the workaround. Give your team an approved tool and a few starter prompts.
4
Train the team
One short session on what AI can and can't do with donor data goes a long way.