Cybersecurity

Is Your NFP Protected From Cyber Crime When Using AI Tools?

Not-for-profit (NFP) organisations are increasingly exploring how artificial intelligence can support their everyday work. For teams working with limited time, funding and resources, AI tools can ease the pressure of preparing grant applications, developing donor communications and completing administrative tasks, allowing staff and volunteers to work more efficiently and focus more attention on their core mission. 

While the benefits are clear, pressure to improve productivity means staff and volunteers are already using AI tools independently, often without formal policies or oversight. This makes it increasingly important for NFPs to balance the benefits of AI with a safe and considered approach, putting strong cyber security measures in place with guidance from trusted experts. 

The Hidden Risks of Ungoverned AI Use 

According to Infoxchange’s 2025 Digital Technology in the Not-for-Profit Sector report, AI adoption across the sector has doubled, yet only 14% of NFPs have an official AI policy or governance framework. 

With budgets and staff stretched thin, it is understandable that AI governance may not be at the top of every NFP’s priority list. However, the rapid adoption of accessible AI tools has created a gap, leaving many organisations without clear guardrails around which tools are approved, what information can be shared and who is responsible for overseeing their use. 

For NFPs, the cyber security risks associated with ungoverned AI use generally fall into three areas: shadow IT, sensitive information being shared and increasingly convincing AI-powered scams. 

Shadow IT

Shadow IT refers to staff or volunteers using technology without the organisation’s knowledge or approval, often to work faster or avoid time-consuming processes. This includes personal cloud storage, unauthorised messaging apps and shadow AI, which is the use of public AI tools without organisational oversight. While the intention is usually to improve efficiency, these tools can increase the risk of cyber attacks, data leaks and compliance issues.

Sensitive Information Being Shared 

NFPs often hold sensitive information about donors, beneficiaries, volunteers, employees and finances. This data can be exposed during seemingly routine tasks, such as pasting a beneficiary case note into an AI tool for summarising or uploading donor information to improve a document. Without clear guidance, staff and volunteers may not realise that sensitive information should remain within approved systems or understand how it could be stored, processed or used by a public AI tool. 

AI-Powered Scams 

AI-powered phishing scams targeting NFPs are becoming more convincing. Cyber criminals can use AI to create polished messages, imitate familiar writing styles and target specific people or organisations. Deepfake audio and video can also make requests appear to come from a trusted leader, colleague or supplier. As traditional warning signs become less reliable, staff and volunteers should verify unexpected requests through a separate, trusted channel, particularly when payments or sensitive information are involved. 

These risks are not unique to NFPs, but their sensitive data holdings can make them an attractive target for cyber criminals. 

Why Can NFPs Be Attractive Targets? 

Not-for-profits are not targeted because of the work they do. Cyber criminals are more likely to focus on the valuable information they hold and the operational pressures they face. 

Lean IT Support 

Many NFPs operate without a dedicated IT or cyber security team. Responsibility for technology may fall to employees already balancing several priorities. Without specialist oversight, it can be difficult to maintain security controls and identify unusual activity before it develops into a larger issue. 

A Trust-Based Culture 

Trust and collaboration are central to how many NFPs operate. Staff and volunteers regularly communicate with donors, beneficiaries, community partners and suppliers, often responding quickly to requests for assistance. Cyber criminals can exploit this trust through convincing phishing emails or by impersonating a familiar contact. 

Storing Sensitive Data  

NFPs often hold donor records, beneficiary details, employee information and financial data. If accessed by cyber criminals, this information can be used for fraud, identity theft or further targeted scams. A data breach can also affect the trust an organisation has built with the people and communities it supports. 

Limited Cyber Security Budgets 

When funding is stretched, frontline services and immediate operational needs understandably take priority. Cyber security improvements may therefore be delayed, particularly when there has not been a previous incident. Identifying the organisation’s most significant risks can help leaders focus their available budget on the improvements that matter most. 

These challenges do not mean NFPs need complex or costly security measures. By focusing on a few practical safeguards, organisations can reduce their exposure while continuing to benefit from AI. 

How to Use AI Safely at Your NFP 

Using AI safely does not require your organisation to stop staff and volunteers from exploring new tools. A few practical safeguards can provide clearer boundaries while allowing your team to continue benefiting from AI. 

1. Create a Simple NFP AI Use Policy 

An AI policy should explain which tools are approved, how they can be used and what information must never be entered. It should also clarify when AI-generated work needs to be checked by a person before it is shared or used. 

The policy does not need to be lengthy or overly technical. Even a straightforward document can give staff and volunteers greater confidence about what is and is not appropriate. 

2. Provide Regular Training 

An AI policy is most effective when people understand why it matters. Training can help staff and volunteers use approved tools appropriately, protect sensitive information and recognise AI-powered phishing or impersonation attempts. 

Training should also encourage people to ask questions or report mistakes without fear of getting into trouble. Early reporting gives the organisation a better opportunity to address potential risks. 

3. Use Approved Workplace Tools

Free consumer AI tools may not provide the level of data protection, administrative control or visibility an organisation needs. Where possible, NFPs should provide approved workplace tools and organisational accounts instead of leaving staff and volunteers to choose their own. 

Before approving a tool, consider how it stores and processes information, what settings are available and whether the organisation can manage user access. 

4. Strengthen Your Security Foundations 

AI-related risks should be considered as part of the organisation’s wider cyber security approach. Multi-factor authentication can help protect user accounts, while secure and regularly tested backups support recovery if systems or data are affected. 

These protections remain important regardless of which AI tools the organisation chooses to use. 

5. Align With the Essential Eight 

The Australian Signals Directorate’s Essential Eight helps organisations protect against common cyber threats and can provide a strong foundation for cyber security for not-for-profits in Australia. Measures such as multi-factor authentication, regular patching and restricting administrative privileges can reduce the vulnerabilities exploited by phishing and automated attacks. 

For NFPs without dedicated internal IT or cyber security expertise, putting these steps into practice can be challenging. A trusted technology partner can assess how AI is currently being used, identify gaps in existing security measures and establish practical policies and safeguards. 

Strengthen Your NFP’s Approach to AI 

Establishing policies, reviewing AI tools and strengthening cyber security can add further pressure to an already busy team. Impact ICT provides local NFP cyber security services and not-for-profit IT support across Mandurah, the Peel region and Perth, making technology easier to manage through clear, practical guidance and responsive support. 

This experience includes an ongoing partnership with OVIS Community Services, helping the organisation strengthen its cyber security and manage technology with greater confidence. 

If you are unsure where your AI or cyber security risks lie, get in touch with Impact ICT and book a free NFP Cyber Security Audit. We’ll identify existing gaps and help prioritise practical improvements so your team can use AI more safely and confidently.

FAQs 

Q1. Is it safe for our NFP to use ChatGPT and other AI tools at all? 
Yes, when they are used with the right safeguards. The risk is not AI use itself, but staff or volunteers entering sensitive donor, beneficiary or financial data into unapproved tools or personal accounts without a clear organisational policy or oversight.   

Q2. What is “shadow AI”? 
Shadow AI is when staff or volunteers use AI tools such as ChatGPT on their own, without the organisation’s knowledge or approval. This often happens through personal accounts, leaving the organisation with no oversight of which tools are being used, what information is being entered or how that information is handled.  

Q3. Do we really need a written AI policy if most NFPs don’t have one? 
Yes. AI adoption across the sector has doubled, yet only 14% of NFPs have an official AI policy or governance framework. Even a simple, one-page policy can help close that gap and provide guidance on which tools are approved, how they can be used and what information should not be entered.   

Q4. How does the ASD Essential Eight relate to AI risk?
The Essential Eight’s controls, such as multi-factor authentication, regular patching and restricting administrative privileges, help reduce the same vulnerabilities that AI-powered phishing and automated attacks exploit. This makes it a strong cyber security foundation alongside an AI-specific policy.   

Q5. What’s the first step to get started?
Start by understanding how staff and volunteers are currently using AI and where your organisation’s risks or gaps may lie. A free NFP Cyber Security Audit can help identify these areas and prioritise practical improvements before developing a policy or changing how your team uses AI tools. 

Author

Tom Purser