Last reviewed and updated: August 2026. This area moves quickly - we revisit this post as the tools and the terms attached to them change.
Nobody sat down and decided your organization would start using AI. One person began drafting emails with a chatbot. Someone else started pasting in reports to summarize. A few months later it is part of how the team works, and there has still never been a conversation about what should and shouldn't go into it.
That drift is worth interrupting, because the benefit is real - we use AI every day. But there are two ways it goes wrong, and we see both regularly: something confidential leaves your organization, or something wrong goes out under your name.
1. Be clear about what they're good at
The disappointment usually comes from expecting the wrong thing. In our experience an AI assistant is reliably useful for:
-
First drafts - a donor update, a job description, a policy outline. Starting from something mediocre is much faster than starting from nothing.
-
Summarizing long documents - a sixty-page grant guideline you need the gist of before a meeting.
-
Translation, at least as a first pass before a human reviews it.
-
Messy to structured - pulling names and dates out of an email thread into a table, or writing the spreadsheet formula you can't remember.
They are much less reliable when you need facts you can't check, current information about a specific organization or program, or arithmetic that matters. Treat them as a fast, confident, well-read colleague who has never worked at your organization and won't tell you when they're guessing.
2. Decide what never goes in
This is the part most teams skip. Before anyone starts, agree on a short list of what must not be pasted into a chatbot. For most organizations that includes personal data about beneficiaries, patients, clients or donors; staff records and HR matters; passwords and API keys; unpublished financials and contracts; and anything covered by a confidentiality agreement or a funder's data rules.
The safest habit is to strip identifying details first. You almost never need the real names to get a useful answer - ask about "a 12-year-old participant in our literacy program" instead of a real child. If you haven't reviewed your wider data practices lately, this is a good moment to revisit digital security essentials.
3. Use the business version, not the free consumer one
This is the highest-value change most organizations can make, and it's often free or heavily discounted.
Free consumer accounts generally have weaker guarantees about what happens to what you type, and give you no administrative control at all. The business tiers of the major providers commit to not training on your data by default and let an administrator see who has access. Several are already included in plans you may be paying for through Microsoft 365 or Google Workspace, so check what you have before buying anything, and check the nonprofit programs in our list of free and discounted tools for nonprofits.
Whatever you choose, open the settings. There is usually a toggle controlling whether your conversations can be used for training, and the default is not always the one you'd want.
4. Verify anything that leaves your organization
The potential failure here is specific and embarrassing. A chatbot will produce confident, well-written text that is sometimes simply wrong: invented statistics, citations to papers that don't exist, a funder deadline that sounds plausible and isn't.
One rule covers most of it. If it's going outside your organization, or a decision depends on it, a person checks every fact and every link first. Not a skim - actually clicking the citation. This is also why an assistant is most valuable in areas where you're already the expert, because you'll catch the mistakes.
5. Keep a person in charge of decisions about people
Don't use AI to screen job applicants, assess who qualifies for support, or make any decision that materially affects someone's life without a human genuinely reviewing it. Beyond the legal exposure, which is growing in several countries, the training data carries biases you can't see and won't be able to explain to the person affected. Using AI to help draft your interview questions is fine. Using it to decide who gets an interview is not.
6. Write it down, on one page
A policy nobody reads is worse than none, so keep it to a single page covering five things:
-
Which tools are approved, and which accounts to use
-
What must never be pasted in
-
What has to be verified before it goes out
-
Where AI must not be used at all
-
Who to ask when someone isn't sure
Then talk about it in a team meeting. The goal isn't to restrict people, it's to remove the guesswork so nobody has to make a judgment call about a donor spreadsheet at 6pm on a Friday.
Use AI at work. It is genuinely good at drafting, summarizing and rephrasing, and avoiding it altogether puts you at a real disadvantage. Just be deliberate: use the business tier, agree on what never goes in, check what comes out, and keep people in charge of decisions about people.
If you'd like help setting this up for your team, or writing that one-page policy, please reach out. We'd be happy to help!
Need a hand with this?
Impaque helps mission-driven organizations put technology to work. Tell us about your project — we'd love to help make it happen.
