top of page

No Regulator Watches Your Donor Data. Your Donors Do.

Writer: cAIberOps (SY-ber-ops) | MSSP
cAIberOps (SY-ber-ops) | MSSP
Aug 27
5 min read

Few adopted AI faster than the people with the least help. A survey of 346 nonprofits by Virtuous and Fundraising.AI found 92 percent now use AI in some capacity, and the same research found about half have no formal AI policy at all, with most use described as reactive and individual. That is the textbook definition of shadow AI, and it is running inside organizations whose entire operating capital is trust.

This is the eighth piece in our series on what AI actually means for regulated and trust-bound work, and the nonprofit version has a twist worth reading to the end: no single regulator watches your donor list, and that turns out to be the opposite of reassuring.

The AI is already writing your grants

The scenes are easy to picture because they are happening this week. A development director pastes a donor list with giving histories into a chatbot to segment an appeal. A grant writer uploads the whole program narrative, budget included, to tighten it before a deadline. A case manager summarizes client notes with an AI tool because the funder report is due Friday. A volunteer installs a browser extension that reads every open tab, and one tab is the donor CRM. Nobody is careless. Everyone is doing two jobs.

The cross-industry numbers say the same thing. Verizon's 2026 data breach report found 45 percent of employees now regularly use AI tools at work, up from 15 percent a year earlier, and 67 percent of the people using AI on corporate devices were signed in with non-corporate accounts, outside any control the organization has. IBM's 2026 breach study found shadow AI involved in 43 percent of the security incidents it examined, up from 20 percent. Those figures span every industry. A sector at 92 percent adoption with half its organizations running no policy has no reason to think it sits below them.

What is actually in a nonprofit's data

It is easy to assume a nonprofit holds nothing sensitive. Walk through what is really there.

The donor file is not just names and amounts. It is giving capacity, wealth screening notes, employers, family relationships, and the private fact of who gives to what cause, which for some causes is itself sensitive. The client side can be heavier still: case files at a shelter, health information in a treatment program, immigration details in a services organization. For some of the people you serve, confidentiality is not a preference. It is safety. And around both sits the operational layer: grant agreements with confidentiality clauses, funder data requirements, and, for health-program nonprofits that are covered entities, HIPAA itself.

A consumer AI tool on a personal account is an outside service with no duty to any of those people. Data pasted into it has left your control, whatever the intention.

The rules reaching you are newer than most boards think

Here is what has changed while everyone assumed privacy law skips charities. The newer state privacy laws increasingly do not. Colorado and New Jersey wrote their comprehensive privacy laws without a nonprofit exemption, and Delaware and Oregon cover nonprofits with only narrow carve-outs. Those laws come with thresholds, so smaller organizations may sit under them for now, but a national donor file crosses state lines by its nature. Virginia's own law exempts nonprofits, and that is worth knowing precisely because it is no longer the norm everywhere your donors live. Separately, state data breach notification laws generally apply to nonprofits, which means a leaked spreadsheet of donor personal information is a legal event, not just an embarrassing one.

None of those laws mention AI. They do not need to. They are about personal data leaving your control, and an unapproved AI tool on a personal account is exactly that.

The honest part

No agency audits donor lists, and we will not pretend otherwise. But this sector already had its defining data disaster, and it is worth remembering how that ended. In 2020, Blackbaud, the CRM vendor holding donor data for thousands of nonprofits, was breached. The enforcement came from the offices nobody thinks about until they arrive: attorneys general from 49 states and the District secured a 49.5 million dollar settlement, and the FTC followed with an order requiring the company to delete data it did not need. Two lessons sit in that story. State AGs treat donor data as protected consumer data in practice, statute by statute. And the sector's worst day came through a vendor, because where the data sat mattered more than the walls of any single nonprofit.

An unmanaged AI account is the same shape in miniature: your donors' and clients' information, sitting on infrastructure you do not manage, under an account you cannot audit. And beneath all of it is the ledger that actually funds you. Donors do not need a statute to stop giving. A donor who learns that a giving history sat in someone's personal chatbot account simply gives somewhere else, and no fine you avoided will bring that back.

Visibility comes before policy

About half the sector has no AI policy, so the tempting move is to write one this week. Write it second. A policy about tools you have not found describes an organization that does not exist, and the same research shows most nonprofit AI use arrived person by person, tool by tool.

First, inventory: find every AI tool, browser extension, and AI agent on the machines that touch the donor CRM, case files, or grant drafts, and note which account each one is signed into, organization or personal, because those are different worlds. Then one rule that removes the judgment call: nothing from the donor database, a client case file, or a funder report goes into an AI tool that is not on the approved list, and summarizing or rewriting counts as going in. Then an approved path, because your staff adopted these tools while doing two jobs each, and that need is real. A ban with no alternative just teaches a stretched team to hide the shortcut.

Where we fit, and where we do not

Boundaries first. We are not lawyers, and which state laws reach your organization is a question for counsel. We do not run your CRM, write your privacy policy, or manage your fundraising.

What we run is the layer underneath all of it. Our Managed AI Security service starts with a free AI Discovery: a light install, about a week of quiet observation, then a report of every AI tool, extension, and agent in use across your machines, including which are running on personal accounts, risk ranked in plain English. Nothing changes for your staff while it runs, and the report is yours whatever you do next. For an organization watching every dollar, it is a first step that costs nothing and answers the question a policy has to start from. From there we enforce the tool list you approve and keep watching as new AI shows up. Alongside it we run managed email security, endpoint detection, and security awareness training sized for nonprofit budgets, the everyday layer that protects the inbox where donor relationships actually live. None of it guarantees compliance, and no honest vendor would say otherwise. It gives you the one thing every duty above quietly assumes: knowing where the data your mission depends on actually goes.

The question worth asking this week

Not "should we have an AI policy." You should, and half the sector does not. Ask the question that has to come first: could anyone in your organization list, today, every AI tool that has touched donor or client data this quarter, and which account each one was signed into?

We work with nonprofits nationwide from our home base in McLean, Virginia. If you run an organization in Washington DC, Northern Virginia, Maryland, or anywhere in the country and you want that list to exist, book a free 15-minute call. The discovery that produces it is free, and the answer is yours either way.

Comments


bottom of page