Employee Owned Since 2022  |  Serving Chicagoland since 1996Support: 630-523-0220Sales: 630-526-8030Remote support

Strategy whitepaper | Non Profit Organizations

Using AI Tools Safely at Nonprofits

Get real value from AI while protecting donor, client, and organizational data

  • Published September 25, 2026
  • 4 min read

Staff at many nonprofits already use AI tools to draft grant narratives, summarize meetings, and write donor thank-you letters. These assistants can save hours each week. However, without clear rules, they can also expose confidential data or produce mistakes that damage trust.

The goal is not to avoid AI. Instead, it is to use it on purpose, with guardrails that protect the people you serve.

Understand where the risks come from

Most AI risk at nonprofits falls into three areas.

First, staff may paste sensitive data into a service that stores it or learns from it. Second, the output can sound confident while containing errors. Third, assistants inside existing software may reveal files that people should not see.

None of these risks means you should ban AI. Instead, they point to the guardrails you need.

Also, remember that AI can reflect bias in its training data. That matters most when output touches decisions about people.

Write a short AI policy

A policy does not need to run long. In fact, one or two pages that staff actually read work better than a detailed manual. Cover these points.

  • List the approved services and the accounts staff should use.
  • Define which data never goes into any AI service, such as case notes or donor financial details.
  • Require human review of anything AI produces before it leaves the organization.
  • Explain how to handle meeting recording and transcription, including notice and consent.
  • Name a person staff can ask when they feel unsure.
  • Set a schedule to revisit the policy as the technology changes.

Then walk staff through the policy in a short meeting, and include volunteers who use organization accounts.

Choose business accounts over free consumer AI tools

Free consumer versions often carry different data terms than business versions. Some may use your prompts to improve their models unless you change settings.

Therefore, give staff approved business accounts, and check each vendor’s data use, retention, and privacy terms. Also, connect those accounts to your organization’s sign-in with MFA. That way, you control access and can remove it when someone leaves.

In addition, keep a list of which staff use which services. That inventory helps when a vendor changes its terms or reports a security issue.

Fix file sharing before you turn on assistants

Assistants built into Microsoft 365 and similar platforms can search everything a user has permission to open. So if your file sharing is messy, the assistant will surface documents people never knew they could reach.

For example, a staff member might ask for recent salary information and get an HR spreadsheet that someone once shared with the whole staff. That kind of surprise damages trust quickly.

Before rollout, review SharePoint, OneDrive, and Teams permissions. Then remove broad sharing, clean up old sites, and label sensitive content where your licenses allow.

Also, start with a small pilot group. Their experience will reveal permission problems before the whole organization gains access.

Keep humans in charge of the output

AI can draft, but people remain accountable. Grant proposals need accurate numbers and true program descriptions. Likewise, donor letters need the right names and gift amounts.

Also check whether each funder has rules on AI use in applications, and follow them. In addition, avoid using AI to make decisions about client eligibility or services. Those choices need human judgment, and they may raise fairness and legal concerns.

So build review into the workflow. For example, a second person can check facts and figures in any grant draft before submission.

Start with safe, high-value uses

Once guardrails exist, begin with tasks that use public or low-risk information. Good candidates include newsletter drafts, summaries of public research, and action items from meeting notes.

Then expand carefully. Workflow automation, for instance, can route volunteer sign-ups or prepare acknowledgment drafts without anyone pasting data into a chatbot.

Finally, measure the time saved and share results with staff. Real examples help others see where AI helps and where it does not.

How WEBIT helps

WEBIT helps nonprofits adopt AI tools with the right controls in place. We review Microsoft 365 permissions before assistant rollouts, connect approved services to secure sign-in, and help you write a practical usage policy.

We also build workflow automation that saves staff time while keeping sensitive data protected. Learn more about our AI and automation services or our strategic IT services.

Key takeaways

  • A short written policy makes AI tools safer without banning them.
  • Keep client case notes and donor financial details out of AI services.
  • Use business accounts with clear data terms and MFA.
  • Clean up file sharing before you turn on built-in assistants.
  • Review every AI draft, and keep people in charge of client decisions.

Talk to an owner

Want help putting this guide into practice? A 30-minute discovery call gets you honest advice for your environment.

Schedule a discovery call

Non Profit Organizations IT services

See how WEBIT supports non profit organizations organizations across Chicagoland.

Explore Non Profit Organizations IT →

More Non Profit Organizations whitepapers

Browse the full library of guides for your industry.

All Non Profit Organizations whitepapers →

Two new clients per month. Maximum.

Ready to talk to an owner?

Every conversation starts with an honest look at where you are today. No pressure, no pitch deck, and no obligation.