AI Governance Is a Trust Practice: What Nonprofits Can Do Before the Next Tool Arrives
- Megan Zara

- Aug 16
- 7 min read

AI is arriving in nonprofit work during a difficult season.
Organizations are navigating capacity pressure, rising demand, uncertain funding, strained staff, and growing expectations to demonstrate impact. Some teams are experimenting with AI to draft communications, analyze information, translate materials, support fundraising, or reduce administrative workload. Others are choosing not to use it, at least for now. Both decisions can be responsible.
The more important question is not whether your nonprofit adopts AI.
It is whether your organization has shared expectations for how decisions about AI will be made: and whether the people most affected by those decisions have a meaningful role in shaping them.
That is why AI governance is not only a technology policy. It is a trust, participation, and community-accountability practice.
AI adoption is happening before governance is ready
Recent sector research reflects a familiar pattern: nonprofit teams are often adopting tools faster than organizations can build the infrastructure to support them.
Bridgespan’s August 2026 analysis of major shifts in the social sector describes AI as changing nonprofit operations and program delivery while many organizations remain short on the knowledge, infrastructure, funding, and capacity needed to explore it responsibly.
The NetHope landscape analysis of AI governance and the funder-grantee relationship identifies a related gap: funders and grantees are making decisions about AI adoption, data use, procurement, and reporting without shared expectations about risk, oversight, or accountability. The analysis reports that only 8% of organizations surveyed had AI widely integrated and only 22% had formal AI policies.
Meanwhile, a recent NonProfit Times report found that 91% of surveyed nonprofits were already using AI in some official capacity, while security and privacy concerns were the leading barrier to greater use.
These numbers are not necessarily contradictory. They show how uneven adoption can be. One staff member may be using an AI tool to summarize meeting notes while the board has never discussed data protection. A development team may be testing AI-assisted donor communications while program staff do not know whether participant information can be entered into the same platform.
Informal use is still organizational use. If the organization cannot explain what is happening, who is responsible, and how people can raise concerns, trust is already at stake.
Trust depends on what people can see and question
Public trust is not built by having the most advanced tools. It is built through consistent action, transparency, and meaningful relationships.
Candid’s August 2026 summary of the Trust in Nonprofits and Philanthropy study reports that 76% of respondents believe nonprofits should fully disclose when and how they use AI. More people said nonprofit AI use would make them less likely to trust an organization than more likely to trust it.
The same research points toward a constructive path: community engagement and transparency drive trust. People are more likely to trust nonprofits when they participate, volunteer, advocate, and see how decisions are made.
This matters for every kind of mission-driven organization:
A foundation deciding whether to use AI in grant review
An association analyzing member feedback
An educational nonprofit using an automated tutoring or advising tool
An arts organization personalizing audience communications
A faith-based nonprofit managing pastoral or community-care information
An advocacy group translating materials or identifying outreach patterns
A local service organization deciding who receives limited support
In each case, the issue is not simply whether the technology works. It is whether the people involved understand how it is being used, whether they can challenge it, and whether a real person remains accountable.
“Governance is how trust becomes visible.”

A lightweight starting framework for nonprofit AI governance
You do not need a forty-page policy to begin. A short, usable agreement is more valuable than a comprehensive document that no one reads.
Start with these six questions.
1. Name the purpose
Before choosing a tool, name the problem you are trying to solve.
Are you trying to reduce repetitive administrative work? Improve language access? Make internal knowledge easier to find? Support: not replace: staff capacity?
A clear purpose helps prevent technology from becoming the goal. It also gives your team a basis for deciding when AI is not appropriate.
Write down:
The intended benefit
Who is expected to benefit
What success would look like
What risks or tradeoffs you already anticipate
A purpose statement might be as simple as: “We are exploring AI-assisted translation to make public program information available in more languages, with human review by fluent staff or community partners before publication.”
That is more accountable than “We are implementing AI.”
2. Involve affected communities from the beginning
Community participation should not begin after a tool has been purchased.
The people who use your services, receive your communications, contribute data, or may be affected by an automated recommendation should have opportunities to shape the decision before implementation. This includes people who are often excluded from technology conversations: people with disabilities, older adults, people with limited connectivity, multilingual communities, participants with low digital literacy, and people whose experiences may not appear in training data.
The article “Equipping communities for accountability in the age of artificial intelligence” emphasizes that communities need to understand, question, and influence technology used in their name. Its authors also warn that consent can become “transactional” when people must share data to access essential services without having a meaningful alternative.
For a small organization, participation could include:
A listening session before adopting a tool
A community review group
Plain-language explanations of proposed use
A way to opt out where possible
A clear human alternative
A public channel for questions and concerns
Participation is not a final approval step. It is part of design.

3. Define what must remain human
A useful AI policy should identify decisions and relationships that cannot be delegated to a tool.
For many nonprofits, these may include:
Eligibility or access to services
Safety, crisis, or safeguarding decisions
Grantmaking and resource allocation
Performance management or hiring decisions
Pastoral, health, legal, or trauma-related support
Interpretation of community testimony
Final approval of public-facing information
Decisions involving a person’s dignity, rights, or future opportunities
“Human review” should mean more than clicking approve. The responsible person needs enough context, authority, time, and training to question the output and change the decision.
The peer-reviewed article “Come to us first”: Centering Community Organizations in Artificial Intelligence for Social Good Partnerships offers an important reminder: community organizations should be centered in AI partnerships, not treated as implementation channels for decisions made elsewhere.
4. Protect sensitive information
Make a simple data map before staff begin experimenting.
List the information your organization handles and identify what must never be entered into an unapproved AI tool. This may include:
Names and contact information
Health, financial, immigration, or legal information
Case notes and safeguarding records
Donor and member histories
Student records
Confidential partner or funder information
Unpublished advocacy or legal strategy
Personal stories shared under conditions of trust
Then ask vendors practical questions:
Is our data used to train the model?
Where is it stored?
How long is it retained?
Who can access it?
Can it be deleted?
What happens to the data if the contract ends?
What happens if the vendor changes its terms?
Small nonprofits may not have extensive procurement capacity. That is precisely why this work should be proportionate and shared. Funders can help by offering common vendor standards, legal support, training, and time: not by quietly expecting grantees to absorb new technology risks.
5. Document review and accountability
Keep a lightweight record of AI use.
For each approved use case, document:
The tool and version
The purpose
The information used
The responsible staff member
Where human review occurs
Who may be affected
Known limitations
How concerns can be raised
What happens when something goes wrong
Also document what your organization has told community members, donors, volunteers, staff, and funders.
Transparency does not require perfect certainty. It requires honesty about what you know, what you do not know, and what you are doing to learn.
For funder-grantee relationships, this transparency should go both ways. Funders should clearly state whether AI use is optional, encouraged, restricted, or required: and should not reward visible adoption over responsible practice. Grantees should be able to disclose capacity limitations without fearing that caution will be mistaken for failure.
6. Revisit the policy with evidence
AI governance is not a one-time document. It is a learning practice.
Set a review date. Bring evidence, not just opinions:
Did the tool save meaningful time?
Did staff feel more supported or more surveilled?
Were outputs accurate across languages and communities?
Did anyone experience harm, exclusion, or confusion?
Did people understand when AI was involved?
Were complaints answered by a real person?
Did the tool strengthen the relationship your organization is trying to build?
If the evidence is weak, pause or stop. Choosing not to continue with a tool is a valid governance outcome.

Start with the relationship, not the tool
For nonprofits, trust is not an abstract brand value. It is part of the work.
A donor decides whether to give again. A participant decides whether it is safe to share information. A student decides whether an organization understands their needs. A volunteer decides whether their time is respected. A community member decides whether to return.
That is the heart of Belong & Return: relationships become durable through welcome, recognition, connection, belonging, return, and reciprocity. AI governance belongs inside that same relational frame. If a tool makes an interaction faster but less understandable, less accessible, or less human, it may be undermining the relationship it was meant to support.
TOPA helps nonprofits turn good intentions into working systems that people can understand, enter, use, and sustain. Through our support for nonprofits, we can help your team map current practices, clarify responsibilities, create usable documentation, and design participation into new or changing workflows.
You do not need to decide everything before you begin.
You can start by naming one current or proposed AI use, inviting the people affected into the conversation, and writing down what must remain human.
That is not a delay in the work.
It is the work of earning trust before the next tool arrives.
Work with The Open Practice Academy to build clearer, more participatory, and more sustainable organizational practices.

Comments