How Do We Keep Our Data Safe When We Start Using AI?
By Amanda Loveland · June 21, 2026
Nonprofits hold sensitive data. The real risk is not AI, it is AI with no rules. Here is how to use it without exposing the people who trust you.
If you run a mission-driven organization, you are holding things people trusted you to protect. Donor records. Member information. Sometimes data about children, families, or vulnerable people who had no choice but to share it with you. So when a leader hesitates about AI because they are worried about that data, I do not think they are being paranoid. I think they are doing their job.
Here is what I want you to hear first, because it reframes the whole worry. The biggest risk is almost never the technology itself. It is AI with no rules around it. It is a well-meaning staffer pasting a donor list into a free consumer chatbot to clean it up, because nobody ever told them not to, and nobody gave them a safe way to do it instead. A lack of policy leaves everyone, and every piece of data you hold, exposed. That is the scenario that keeps me up, far more than any single tool.
Which is why the answer starts before anyone touches a keyboard. You need a clear policy and a set of organization-approved, secured tools that everyone works from. The policy names what is off-limits, who is accountable for AI decisions, and which tools are actually sanctioned for which kinds of information. The approved tools give your staff a safe place to do the work, so the answer to "can I use AI for this" is never a guess. That combination, a real policy plus secured tools, is the difference between AI that protects your people and AI that quietly endangers them.
There are a few hard lines I encourage every organization to draw. Sensitive personal information, donor financial details, anything about a minor, anything you would not put in an email to someone outside your walls, does not go into an unapproved tool. Use the business or enterprise versions that come with real data protections rather than the free consumer ones, and know whether the tool you are using trains its model on what you type in, because that answer should change how you use it. None of this is exotic. It is the digital version of locking the filing cabinet, and your team already understands why you lock the cabinet.
I have a personal rule that I find translates well here. If I would not say it out loud to a member, I am careful about where it goes. Apply that instinct to your data and most of the hard calls get easier. Would you read this donor's information aloud in a crowded lobby? Then do not drop it into a tool you have not vetted. The standard is not complicated. It is the same care you already bring to the rest of your work, extended to a new place.
I will not tell you any tool is risk-free, because none of them are, and anyone who promises you zero risk is selling something. The goal is not to eliminate every risk by refusing to move. The goal is informed, governed use, where your staff have clear rules and safe tools and the confidence to use AI without gambling with the trust people placed in you. Guardrails are not there to restrict your team. They are there to protect the people who handed you their information and assumed you would keep it safe.
This started as a question I get all the time. See the quick version on the FAQ
Ready to Begin?
Put AI to work for your organization.
We help mission-driven organizations adopt AI in a way that saves staff time, reduces risk, and advances their mission.
Free consultation · No prep required
