Artificial intelligence is no longer something NGOs can simply watch from the sidelines.
Across the nonprofit sector, organizations are already experimenting with AI to write grant proposals, summarize research, translate documents, analyze information, create communications, prepare reports, and reduce repetitive administrative work. What may start as one employee using an AI tool for a few minutes a day can quickly become part of fundraising, communications, program management, and even decision-making.
That creates a new question for NGOs.
What happens when AI use grows faster than the organization’s ability to manage it?
For many organizations, the answer may be an AI policy.
An AI policy does not have to be a complicated legal document or a set of rules designed to stop employees from experimenting with technology. At its best, it is a practical framework that tells people where AI can help, where caution is needed, what information must be protected and where human judgment must remain in charge. Candid describes responsible AI policies in similar terms: practical agreements that help nonprofit staff use AI safely, consistently, and in a human-centered way.
The need for this kind of guidance is becoming more visible as AI moves from experimentation into everyday nonprofit work.
AI Is Easy to Start Using. Scaling It Is the Real Challenge
Imagine a small NGO with ten employees.
One person starts using AI to improve emails. Another uses it to summarize lengthy reports. Someone in the fundraising team discovers that AI can help create a first draft of a grant proposal. The communications team begins using it for social media captions. A program manager uses it to organize survey responses.
At first, everything seems helpful.
The organization is saving time. Employees are getting through repetitive tasks faster. Nobody needs to spend hours writing the first version of a document.
But then an important question appears:
Does anyone actually know how everyone is using AI?
Maybe one employee is putting donor information into an AI tool. Another is uploading an unpublished project report. Someone else is using AI-generated statistics without checking where they came from.
There may be no malicious intent at all.
The problem is simply that everyone is making their own decisions.
This is where informal AI use can become risky. As AI becomes part of more workflows, organizations need some shared understanding of what is acceptable and what is not.
Recent nonprofit research highlights this gap. Candid reported in July 2026 that many nonprofits were still using AI in an ad hoc way, while only a small proportion had reached a stage where responsible AI practices were integrated across the organization. Nearly four in ten organizations in the research were described as “aware” nonprofits—using AI without formal structure, coordination, or documentation.
That distinction matters.
Using AI is not the same as being ready for AI.
An AI Policy Should Not Mean “No AI”
One of the biggest mistakes an NGO could make is responding to AI by simply banning it.
That might appear safe, but it does not necessarily solve the problem.
Employees may continue using AI privately because it helps them complete their work faster. The difference is that the organization may no longer know how the technology is being used.
A better approach is to create clear boundaries.
An NGO might allow AI for low-risk activities such as
- Drafting internal documents
- Brainstorming ideas
- Summarizing public information
- Improving grammar and readability
- Creating first drafts of communications
- Translating non-sensitive material
- Organizing non-confidential information
- Supporting repetitive administrative work
At the same time, the organization can place stronger controls around sensitive data, beneficiary information, high-impact decisions, and external communications.
The purpose is not to eliminate AI.
It is to make responsible AI use easier than irresponsible AI use.
That is an important difference.
NGOs Have More to Protect Than Just Their Data
For many businesses, an AI mistake may mean a financial loss or an incorrect piece of marketing content.
For NGOs, the consequences can sometimes be much more personal.
Organizations may work with children, survivors of violence, refugees, patients, vulnerable families, marginalized communities, or people facing financial hardship. Their teams may handle personal stories, health information, photographs, contact details, case records, and other sensitive material.
That creates a simple but important question:
What information should never be entered into an AI system?
An AI policy should answer that clearly.
Employees should not have to guess whether a beneficiary’s name, medical information, personal story, or confidential donor information can be pasted into an AI chatbot.
The policy can establish simple categories such as
Safe to use: Public information and non-sensitive material.
Use with caution: Internal documents that do not contain personally identifiable or confidential information.
Do not use: Sensitive beneficiary records, confidential case information, passwords, private donor information, or other protected data unless the organization has specifically approved a secure system and use case.
The exact categories will differ from NGO to NGO. A health organization, for example, may need much stricter rules than an organization working primarily on public awareness campaigns.
That is why copying a generic corporate AI policy is rarely enough.
The policy should reflect the NGO’s actual mission and the people it serves.
The Most Important Rule: AI Can Assist, But People Stay Responsible
AI can produce an answer in seconds.
That does not mean the answer is correct.
It can create a beautifully written paragraph containing a completely wrong statistic. It can summarize a report while missing an important detail. It can generate a confident explanation based on information that is outdated or inaccurate.
This becomes especially important when NGOs use AI for proposals, research, reports, or community communications.
Imagine an NGO submits a grant proposal containing an incorrect statistic because nobody checked an AI-generated paragraph.
Or imagine a health organization publishes incorrect information generated by an AI system.
The problem is not simply that “AI made a mistake.”
The bigger question becomes:
Who was responsible for checking it?
A strong AI policy should make that answer clear.
AI can draft.
AI can summarize.
AI can suggest.
AI can organize.
But people remain responsible for the final decision and the final output.
This principle is becoming increasingly important across responsible AI discussions. IREX’s ASCEND initiative, launched with Microsoft’s Tech for Society team in September 2026, focuses specifically on helping civil society, nonprofit, and community-based organizations develop AI readiness, safeguards, and organizational capacity rather than simply giving them access to technology.
Smaller NGOs May Actually Need AI Policies the Most
There is an interesting contradiction in the AI conversation.
The NGOs that could benefit the most from AI may also be the ones with the fewest resources to manage its risks.
A large international organization may have an IT department, cybersecurity specialists, legal advisers, and dedicated technology staff.
A small grassroots organization may have five or ten people doing everything.
The same person might handle fundraising in the morning, social media in the afternoon, and project reporting in the evening.
For these organizations, AI could be extremely useful.
It could help them:
- Find and organize funding information
- Create first drafts of proposals
- Summarize lengthy donor guidelines
- Prepare reports
- Translate materials
- Organize research
- Reduce repetitive administrative work
But smaller organizations may also struggle to answer basic governance questions.
- Who approves AI tools?
- Who checks the information?
- What happens to the data?
- Who trains employees?
- What happens if an AI-generated recommendation causes harm?
A simple policy can provide structure without requiring a large technology department.
And that may be one of the most important benefits of an AI policy: it turns individual experimentation into organizational learning.
AI Policy Is Also About Trust
NGOs are built on trust. Donors trust them to use funds responsibly, communities trust them with personal stories and sensitive information, and partners and volunteers rely on them to communicate honestly and clearly.
AI can support that trust when it is used carefully. It can help NGOs save time, organize information, and handle routine work, allowing staff to focus more on people and communities. But if AI is used carelessly, it can also create new risks.
For example, imagine a donor discovering that confidential information was entered into an AI tool without proper safeguards. Or imagine a community member finding out that their personal story was rewritten by AI without their knowledge or proper human review. Even if the organization did not intend to cause harm, situations like these can damage confidence.
This is becoming an important issue for the nonprofit sector. Recent candid research found that many nonprofits are using AI without formal organization-wide policies, while donors place strong importance on transparency, data protection, and human review of AI-generated work.
That is why an AI policy should go beyond simply asking:
“Can we use AI?”
NGOs should also ask:
“Is this the right way to use AI?”
“Are we protecting the people who trust us?”
“Will this use of AI strengthen or weaken that trust?”
Ultimately, responsible AI is not just about using technology safely. It is about making sure that technology never comes at the cost of the trust, relationships, and human connection at the heart of NGO work.
What Should an NGO’s AI Policy Actually Cover?
A useful policy does not need to be hundreds of pages long.
In fact, if employees cannot understand it, they probably will not follow it.
A practical NGO AI policy could cover a few core areas.
1. Where AI Can Be Used
The organization should identify acceptable uses.
For example, AI might be approved for brainstorming, editing, summarizing public information, and creating early drafts.
2. Where AI Should Be Restricted
Some tasks may require additional approval.
This could include working with sensitive information, generating public-facing content about vulnerable communities, or using AI for important organizational decisions.
3. What Data Must Stay Private
This may be one of the most important sections.
Employees should know exactly what they should never enter into unapproved AI tools.
4. Human Review
The policy should explain which AI-generated outputs must be checked by a person before they are used or published.
5. Transparency
In some situations, NGOs may need to consider whether they should disclose AI use to donors, partners, staff, or communities.
The answer may differ depending on the situation, but the question should be considered.
6. Accountability
Someone should be responsible for monitoring how AI is being used and responding when problems occur.
7. Training
Giving employees access to AI without teaching them how to use it responsibly is not enough.
Staff need basic AI literacy, including understanding hallucinations, privacy risks, bias, and verification.
8. Regular Review
The policy should be updated as AI tools, organizational needs, and relevant regulations change.
Don’t Write a Policy and Put It in a Drawer
There is another common problem organizations can face.
They create an AI policy.
Everyone signs it.
And then nobody looks at it again.
That is not enough.
AI technology is changing too quickly for a policy to remain untouched for years.
A tool that an organization considered low-risk today may introduce new features tomorrow. Employees may begin using AI for new tasks. New privacy requirements or donor expectations may emerge.
The policy should therefore be treated as a living document.
An NGO could review it every six months or whenever there is a major change in how AI is being used.
The organization could also create a simple internal process where employees can ask:
“I’m not sure whether I can use AI for this. Who should I ask?”
That one question can prevent many problems.
Before Buying Another AI Tool, Ask These Questions
The AI market is moving extremely fast.
Every few weeks, there seems to be another tool promising to save organizations time, automate work, or transform productivity.
But NGOs should resist the temptation to collect tools simply because they are impressive.
Before adopting an AI system, leadership teams should ask:
- What problem are we actually trying to solve?
- Is AI the best solution to that problem?
- What information will the system need?
- Could that information expose beneficiaries, staff, or donors to risk?
- How accurate does the output need to be?
- Who will review the result?
- What happens if the system is wrong?
- Will the tool genuinely save staff time, or will it create another system they have to manage?
- Can we explain to our community why we are using it?
These questions move an organization from AI adoption to responsible AI adoption.
And that difference could become increasingly important.
AI Should Solve Problems, Not Create New Ones
There is a tendency to treat AI as an automatic solution to every organizational challenge.
But NGOs should be careful.
- If an organization has poor data management, adding AI may simply make poor data move faster.
- If employees do not understand a process, automating it may make the confusion harder to see.
- If an NGO does not have a clear fundraising strategy, generating more grant proposals will not necessarily solve its funding problem.
- Technology works best when it supports a clear organizational purpose.
- That is why AI policy should sit alongside broader organizational planning.
The question should not be:
“How can we use AI everywhere?”
It should be:
“Where can AI genuinely make our work better?”
That shift can save organizations money, time, and unnecessary complexity.
The Human Side of AI Matters Most in NGOs
This may be the most important point of all.
NGOs are not simply information-processing organizations.
They work with people.
- A community worker understands why a particular solution may work in one village but fail in another.
- A field officer may recognize a cultural issue that an AI system cannot see.
- A fundraiser may know why a donor relationship requires a personal conversation rather than an automated email.
- A program manager may understand that a community’s needs have changed even though the available data has not.
- AI can support these people.
- It should not automatically replace their judgment.
- An AI system can help draft a proposal, but it does not know the community behind the proposal.
- It can summarize research, but it may not understand the local context.
- It can suggest an outreach strategy, but it does not have the trust that a field worker has built over years.
- This is why responsible AI for NGOs should ultimately be human-led.
The Future NGO May Be AI-Assisted, Not AI-Driven
The future of AI in the nonprofit sector is not about choosing between people and technology. It is about using both in the right way.
AI can help NGOs with repetitive tasks, organize information, and save time. This gives staff more time to focus on what really matters—working with communities, building relationships, making decisions, and solving real problems.
AI can help process information, but people understand the situation behind that information. AI can create a first draft, but NGO staff can add their experience, local knowledge, and ideas. In this way, AI can support people instead of replacing them.
To make this work, NGOs need proper policies, training, safety measures, and clear leadership. They need to understand both the benefits and the risks before using AI more widely.
IREX’s ASCEND initiative, launched with Microsoft’s Tech for Society team, follows this approach. It aims to help NGOs and other civil society organizations build AI skills, improve their readiness, and learn how to use AI safely and responsibly.
The goal is simple: use AI to make NGO teams stronger while keeping people and communities at the center.
The Real Question Is Not Whether NGOs Will Use AI
AI adoption in the nonprofit sector is already happening.
The real question is whether organizations will build the systems and culture needed to use it responsibly.
An AI policy is one of the simplest places to start.
- It gives employees clarity.
- It protects sensitive information.
- It encourages responsible experimentation.
- It creates accountability.
And perhaps most importantly, it reminds an organization that technology should serve its mission—not the other way around.
For an NGO, adopting AI should never simply mean doing more work faster.
The goal should be to free people from unnecessary work so they can spend more time doing the work that only people can do.
That is where AI can become genuinely valuable to the nonprofit sector.
An AI policy is not a barrier to innovation. It is the foundation that allows NGOs to innovate without losing control of what matters most: their people, their communities, and their mission.

