Subnet Blog

AI Is Already in Your Not-for-Profit — Even If IT Didn’t Approve It

Written by Ben Luks | 10 August 2026, 06:41:32 Z

There’s a good chance your organisation is already using AI.

Perhaps someone in fundraising is using ChatGPT to help draft donor communications. A member of the marketing team might be using an AI assistant to summarise research or create content. Someone in HR could be experimenting with AI to help write a position description.

And increasingly, AI capabilities are appearing inside the software your organisation already uses every day.

For Australian not-for-profit IT teams in 2026, the question is therefore becoming less about whether to adopt AI and more about how AI is already being used — and whether anyone knows about it.

Welcome to the era of Shadow AI.

What is Shadow AI?

Shadow AI describes the use of artificial intelligence tools, applications or features without the knowledge, approval or oversight of an organisation’s IT team.

It's similar to the long-standing problem of Shadow IT, where employees adopt their own applications or cloud services to get their work done.

But AI introduces an additional layer of complexity. An employee can access a generative AI service in seconds. There may be nothing to install, no procurement request and no obvious change to your infrastructure.

And the person using it probably isn't trying to circumvent IT. They're trying to get something done. That's precisely what makes Shadow AI challenging.

Why Australian NFPs Should Pay Particular Attention

Not-for-profit organisations can be especially fertile ground for AI experimentation.

Teams are often being asked to achieve ambitious outcomes with limited resources. Administrative workloads can be substantial, and staff are understandably attracted to technology that promises to save time.

AI can genuinely help. But Australian NFPs may also hold significant amounts of personal and sensitive information — about donors, members, volunteers, employees, program participants or the communities they support.

That creates an important question: What information is being entered into AI tools, and what happens to it afterwards?

Someone copying a document into an AI assistant to produce a quick summary may feel harmless. But what if that document contains personal information? Financial information? Details about a donor? Confidential board material? Information relating to a vulnerable client?

For Australian organisations, this isn't simply a hypothetical cybersecurity issue. Depending on the organisation and its activities, obligations under the Privacy Act 1988 and Australian Privacy Principles may also apply.

The Office of the Australian Information Commissioner (OAIC) has advised organisations to take particular care when using commercially available AI products. As a matter of best practice, it recommends that organisations do not enter personal information — particularly sensitive information — into publicly available generative AI tools because of the privacy risks involved.

The risk isn't necessarily the use of AI itself. It's AI use without visibility, guidance or appropriate controls.

“We’re a Small NFP” Doesn’t Necessarily End the Privacy Conversation

There can be a misconception that smaller not-for-profits don't need to think about the Privacy Act. The reality is more nuanced.

Australian NFPs with annual turnover above $3 million are generally covered by the Privacy Act, but some organisations below that threshold may also be covered because of the services they provide or the way they handle information.

For example, this can include some organisations providing health services, contracted service providers under Australian Government contracts, or organisations involved in certain activities concerning personal information.

And even where an organisation isn't legally required to comply with the Privacy Act, good privacy practices still matter. For an NFP, community trust can take years to build and very little time to damage.

The question therefore shouldn't simply be: “Are we legally required to do this?” A better question may be: “Would our donors, clients, members and community reasonably expect us to handle their information this way?”

Start With Visibility

You can't govern what you don't know exists. For many NFP IT teams, one of the most useful first steps is simply finding out how AI is currently being used across the organisation.

That doesn't necessarily require an enormous audit. Talk to teams. Ask managers. Review the applications already in use. Look at AI capabilities being introduced into your existing technology platforms.

You might ask staff:

  • Which AI tools are you currently using for work?
  • What tasks are you using them for?
  • What information are you putting into them?
  • Are you using free accounts or organisation-managed accounts?
  • Are there tasks you'd like AI to help with but aren't sure whether you're allowed to use it?

The answers may be illuminating. More importantly, asking these questions sends a useful message: we want to understand how AI can help, not simply stop you from using it.

Give People Some Guardrails

Once you understand how AI is being used, the next step is establishing some sensible boundaries. For smaller NFPs, AI governance doesn't need to begin with a 40-page policy document. Clear guidance covering a few fundamental questions can go a long way.

Which AI tools are approved?

Give staff somewhere safe to start rather than leaving them to choose tools themselves.

What information must never be entered into an unapproved AI service?

Be specific. “Don't enter sensitive data” isn't particularly helpful if employees don't understand what that means in practice.

Consider the information your NFP actually handles: donor and supporter records, employee details, health information, client case notes, financial records, grant information or confidential board papers. Staff should understand where the boundaries are.

When does AI-generated work need human review?

AI can produce convincing answers that are inaccurate, incomplete or inappropriate. This is particularly important if AI-generated information could influence decisions affecting clients, employees or other individuals. AI output should not automatically be treated as fact simply because it sounds authoritative.

Who should staff speak to if they want to try something new?

Make the approval process straightforward. If getting permission takes weeks, people will be tempted to bypass it. The goal should be to make the safe option the easy option.

AI Governance Is Also a Board-Level Conversation

For Australian registered charities, technology risk shouldn't necessarily stop at the IT department.

The Australian Charities and Not-for-profits Commission (ACNC) emphasises that a charity's Responsible People — generally its board or committee members or trustees — have responsibilities for governing the organisation and managing organisational risks.

The ACNC has also specifically encouraged charities in 2026 to review their cybersecurity measures, noting the sensitive information and financial data charities can hold.

AI introduces another dimension to that governance conversation. The board doesn't need to understand the technical workings of a large language model. But leadership should understand questions such as:

  • Where is AI being used in the organisation?
  • What are the material privacy, cybersecurity and operational risks?
  • What information are staff permitted to share with AI systems?
  • Who is accountable for approving new AI applications?
  • How is the organisation balancing the opportunities of AI against its responsibilities to the people it serves?

For IT Managers, this is also an opportunity to move the AI conversation away from technology alone and towards organisational risk and governance.

Make AI Literacy Part of Cybersecurity Awareness

Most organisations already teach employees to recognise phishing emails, use strong authentication and handle sensitive information appropriately. AI literacy is quickly becoming another part of that conversation.

Employees don't need to understand how large language models work. They do need to understand the practical risks. For example:

  • why copying personal or confidential information into a public AI service can be problematic
  • why AI-generated answers need verification
  • why an AI-generated email, report or document may contain inaccurate information
  • why employees should use organisation-approved tools and accounts where these are available
  • and why cybercriminals can also use AI to make scams and social engineering more convincing.

A little education can significantly reduce risky behaviour. And importantly, awareness training gives staff an alternative to simply being told, “Don't use AI.”

What If Something Goes Wrong?

For organisations covered by the Privacy Act, AI-related incidents may also intersect with Australia's Notifiable Data Breaches scheme. If personal information is disclosed or accessed inappropriately, the fact that an AI tool was involved doesn't make the usual privacy and incident-response considerations disappear.

This makes it worth asking another practical question: Would your existing incident response process recognise and appropriately handle an AI-related data incident?

If an employee accidentally shared sensitive client information with an unapproved AI service tomorrow, would they know whom to tell? Would IT know what questions to ask? Would the organisation know how to assess the potential impact?

AI governance shouldn't sit separately from cybersecurity and privacy processes. Increasingly, the three need to work together.

The Opportunity Is Bigger Than the Risk

It's easy for conversations about Shadow AI to become entirely focused on security, privacy and compliance. That would be a mistake.

For resource-constrained not-for-profits, AI has the potential to remove repetitive work, help employees access information faster, improve processes and give small teams capabilities that previously required much greater resources.

Those opportunities deserve to be explored. But sustainable AI adoption requires a balance between innovation and governance.

Too little governance creates unnecessary risk. Too much restriction can prevent employees from discovering genuinely useful applications — and may encourage Shadow AI rather than eliminate it.

The organisations that handle this well won't necessarily be those with the biggest AI budgets. They'll be the ones that create clear boundaries, educate their people, understand their data and give employees safe ways to experiment.

Seven Questions for Your IT Team

If AI hasn't yet become a formal discussion within your organisation, here are seven useful questions to start with:

  1. Do we know which AI tools our employees are already using?
  2. Do we know what organisational data employees are putting into those tools?
  3. Have we clearly explained what information can and cannot be shared with AI?
  4. Do staff know which AI services are approved for work purposes?
  5. Have we reviewed the AI capabilities appearing within platforms we already use?
  6. Do our privacy, cybersecurity and incident-response processes adequately address AI?
  7. Do employees have an easy way to ask IT about new AI tools or use cases?

If you can't confidently answer all seven, that's not necessarily a sign that you're behind. It may simply mean that your organisation's use of AI has moved faster than its governance. And in 2026, that's a very good reason to start the conversation.

AI Is Already Here. Now It's About Using It Well.

For Australian NFP IT teams, the challenge isn't deciding whether AI should exist within the organisation. In many cases, that decision has effectively already been made — one employee, one application and one AI-enabled feature at a time.

The opportunity now is to bring that activity out of the shadows. Understand what's being used. Establish sensible guardrails. Review your privacy and cybersecurity obligations. Help employees recognise the risks. Bring leadership into the conversation.

And, importantly, give people safe opportunities to explore where AI can genuinely help your organisation deliver its mission. Because the aim shouldn't be to stop people using AI. It should be to make sure they can use it confidently, responsibly and securely.