Adoption or Non-adoption: Why there is no safe default posture for non-profits.

For many non-profits, using AI is regarded as a decision requiring justification. Many non-profits have struggled to justify the use of AI because of the significant number of risks they foresee.

Not using AI is treated as the safe default - and is a posture far less frequently subjected to an assessment of risk.

But - there are risks on both sides of the decision. And when we put them next to one another, an important difference emerges.

The risks that make non-profits cautious about AI

The concerns are substantial and legitimate.

They include:

  • Privacy and confidentiality — sensitive organisational, employee, beneficiary or human-rights information may be exposed, retained or used inappropriately.

  • Bias and discrimination — AI systems may reproduce or amplify biases embedded in their training data or design.

  • Accuracy and misinformation — generative AI can produce incorrect, fabricated or misleading information.

  • Human rights impacts — AI can enable surveillance, profiling, censorship and other forms of repression.

  • Environmental impact — training and operating AI systems consumes energy, water and other resources.

  • Labour impacts — automation may displace work or adversely affect working conditions.

  • Corporate concentration — AI infrastructure is increasingly concentrated among a relatively small number of powerful technology companies.

  • Data and intellectual-property concerns — questions remain about training data, copyright, ownership and appropriate use of generated material.

  • Loss of human judgement — excessive reliance on AI could weaken human expertise or introduce automation bias into important decisions.

  • Mission inconsistency — an organisation may worry that using particular technologies or providers conflicts with the standards it advocates for others.

These risks should not be dismissed. They should be understood and, where possible, mitigated.

But they are only one side of the equation.

The risks of not using AI

Choosing not to adopt AI also creates risks.

These include:

  • Mission risk — opportunities to increase impact, reach more people or deliver better services are missed.

  • Productivity risk — scarce staff time continues to be consumed by research, administration, drafting and information processing that AI could accelerate.

  • Financial risk — donor and organisational resources are used less efficiently than they could be.

  • Capability risk — the organisation fails to develop the practical knowledge required to understand, govern and use AI effectively.

  • Workforce risk — staff do not acquire skills increasingly important across the economy and civil-society sector.

  • Service risk — beneficiaries may receive slower, less accessible or less sophisticated services than technology could enable.

  • Innovation risk — the organisation becomes less able to experiment with new approaches to achieving its mission.

  • Influence risk — civil society attempts to shape AI policy and corporate behaviour without sufficient practical understanding of the technology.

  • Partnership and funding risk — organisations may become less attractive to partners, employees and funders seeking innovative approaches to social problems.

  • Power-asymmetry risk — governments, corporations and hostile actors acquire increasingly sophisticated AI capabilities while civil society constrains its own.

The question therefore isn’t whether AI creates risk. It is which risks an organisation chooses to take.

Something interesting emerges when these risks are viewed side by side

Table 1


The risks aren’t just different in character.

Our ability to do something about them is different too.

Framework 2 - Conceptual framework courtesy of Alison Elliot, 2026.


What do we actually control?

The familiar Circles of Control, Influence and Concern (Framework 2) provides a useful way of looking at the issues in Table 1. Virtually all of the biggest concerns in the left-hand column sit largely outside an individual's/non-profit’s direct control - they are all Meta-issues and whether a single non-profit chooses AI adoption or not, will make little difference. That is not to say we shouldn’t care about these issues. But they fall predominantly into our circle of concern.

A non-profit cannot determine the global energy consumption of AI. It cannot determine what data was originally used to train a frontier model. It cannot restructure the global technology industry or independently resolve AI’s labour-market consequences.

Now consider the right-hand column. Virtually all the risks are in the circle of control, and therefore are capable of mitigation.

The business case for adoption is stronger than it first appears

If an organisation looks only at the risks of adoption, caution can appear to be the responsible position.

Once the risks of non-adoption are included, the decision looks quite different.

The organisation is potentially accepting risks to its productivity, capability, workforce and ultimately its mission in order to avoid contributing to risks over which it frequently has much less control.

That is not necessarily prudent risk management. It may simply be risk displacement.

There is an additional paradox. Non-adoption can actually reduce an organisation’s ability to influence the risks about which it is concerned. An organisation with little practical experience of AI is less well positioned to scrutinise AI systems, engage technology companies, develop credible policy positions, identify harms affecting its communities or advocate for better alternatives.

Adoption can therefore increase influence over the risks of adoption. This is particularly important for organisations confronting powerful actors. Governments, corporations, political movements and hostile actors are not waiting for civil society to resolve the ethical questions surrounding AI before adopting it.

If those actors use AI to become better at research, surveillance, communications, intelligence analysis, prediction and information processing while civil society exercises unilateral restraint, the result may be an increasing capability imbalance.

For a human-rights organisation, for example, that should itself be regarded as a serious risk.

From risk avoidance to responsible adoption

None of this means that non-profits should start embracing every AI tool with gay abandon!

Organisations need to become better at distinguishing between different kinds of AI use. Using an approved AI assistant to brainstorm campaign ideas using public information is fundamentally different from uploading individual donor information to an inadequately secured model.

Responsible governance should recognise that difference. Low-risk, high-value uses should be easy. Sensitive uses should attract stronger privacy, security and human-oversight requirements.

High-risk uses should receive specific assessment and governance. Some uses should be prohibited. But “don’t use AI” should not be the default responsible-AI policy. The better starting point is:

Choosing to use AI and choosing not to use AI are both risk decisions. Responsible governance requires assessing both.

For non-profits operating with limited resources against problems of enormous scale, the opportunity cost of failing to use a transformative technology is not neutral. It affects productivity. It affects capability. It affects influence. And ultimately it can affect mission.

The strategic challenge for civil society is therefore not to minimise its exposure to AI.

It is to use AI where it can advance mission, manage the risks it can control, influence the risks it can change, and remain actively engaged with the wider consequences it cares about.

Previous
Previous

New tools shield litigants from the complexity of courts

Next
Next

Enhancing Justice System Data Through Structured Settlement Reporting