Your staff are probably already using AI — with personal accounts, on their phones, with donor data — and you don't know about it. That's "shadow AI," and it's the #1 AI governance risk for nonprofits right now.
Signs your org has a shadow AI problem
You have no official AI policy or approved tool list
Staff use personal ChatGPT or Claude accounts for work
Donor names, program data, or financials have been pasted into free AI tools
Leadership hasn't discussed AI use — but the team is already using it
You can't answer: "What AI tools is our team using right now?"
What to do about it
1
Get a policy in place today
An AI use policy sets the rules and gives staff clarity. Without one, you can't hold anyone accountable. Generate yours free →
2
Move staff to an org-owned account
A team-level AI account (ChatGPT Team, Claude Team, etc.) lets you control access, audit use, and ensure data isn't used for training.
3
Make it easy to do the right thing
Shadow AI happens when the approved path is harder than the workaround. Give your team an approved tool and a few starter prompts.
4
Train the team
One short session on what AI can and can't do with donor data goes a long way.