30 Days Gen AI Risk Trial -Start Now
Skip to main content
AI governance for not-for-profits

Let your team use AI. Keep community trust protected.

Not-for-profits are asked to do more with less, and AI genuinely helps. On the devices you roll Aona out to, whether they belong to staff, contractors or volunteers, Aona shows you which AI tools are already in use, helps keep beneficiary, donor and employee information out of the tools you have not approved, and gives your board evidence of how AI is being used.

SOC 2 Type II certifiedAustralian data residency region30-day free trial
10,000+
AI tools in the catalogue
48hrs
to a full AI tool inventory
Australia
data residency region
SOC 2
Type II certified

What makes AI harder in a not-for-profit

The pressures are different from a bank or a software company. Small teams, mixed workforces and information about people who are often already vulnerable.

Beneficiary information in public AI tools

Case notes, incident reports, support plans and referral emails are exactly the material a busy worker is tempted to paste into a consumer AI account to save an hour. Much of it is sensitive information about people who never chose to have it processed by a third party.

Information about the people you support can leave your control in a single paste, before anyone reviews it.

Shadow AI across staff, contractors and volunteers

Not-for-profit workforces are mixed by design: part-time staff, secondees, contractors, volunteers and board members, often on their own devices and their own accounts. AI arrives through all of them, and rarely through a procurement process.

You cannot set expectations for AI use nobody can see, and a policy on its own does not create visibility.

Board and funder questions with no evidence behind the answer

Boards, funders, auditors and partner agencies are starting to ask how AI is used in service delivery and administration. For most organisations the honest answer is that nobody knows precisely, because usage has never been recorded.

Assurance built on assumption is hard to defend when a question turns into an incident.

Real not-for-profit workflows, with the guardrail that fits

The goal is not to stop these uses. It is to make the safe version of each one the easy version.

Service delivery and case work

Where AI helps
Summarising long case notes, drafting referral letters, translating information for clients, turning policy into plain language a participant can actually read.
The guardrail
On a device running the Aona browser plugin or native app, client names, addresses, health details and other sensitive information are inspected before the prompt or file leaves the device, then redacted or blocked according to your policy, with an on-screen explanation of the approved alternative.

Fundraising, donor communications and grant writing

Where AI helps
Drafting appeals, tailoring campaign copy, summarising grant guidelines, preparing first drafts of reports and acquittals.
The guardrail
Donor records, giving histories and identifying supporter details are treated as sensitive by policy, so on a covered device a copy and paste into a personal AI account is stopped or redacted rather than quietly sent.

Operations, HR and volunteer coordination

Where AI helps
Rostering, position descriptions, induction material, policy drafts and summarising board papers.
The guardrail
Employee, contractor and volunteer records, including screening and clearance details, sit under the same policy, and the AI tools used on covered devices are inventoried whether or not IT provisioned them.

The Australian governance landscape

Which of these apply depends on what your organisation is and what it does. Read each one as conditional, not automatic.

ACNC Governance Standard 5Registered charities

Duties of Responsible People

Charities registered with the Australian Charities and Not-for-profits Commission must take reasonable steps to ensure their Responsible People understand and comply with a set of duties, including acting with reasonable care and diligence, acting honestly and fairly in the charity's best interests and in line with its purposes, disclosing conflicts of interest and managing financial affairs responsibly. The Governance Standards apply to registered charities rather than to every not-for-profit. There is no AI-specific standard, so whether those duties reach the introduction of AI into service delivery is a judgement for each board, and some are choosing to document that decision rather than leave it informal.

Privacy Act 1988Where the Act applies

Australian Privacy Principles and personal information

Where your organisation is covered by the Privacy Act, the Australian Privacy Principles govern how it collects, uses, discloses and secures personal information, with additional protection for sensitive information such as health details. Coverage is conditional. Organisations above the small business turnover threshold are generally covered, and some smaller organisations are covered because they provide a health service and hold health information, trade in personal information, or deliver services under a Commonwealth contract. Check your own status rather than assuming either way.

Australian Privacy Act and AI
Notifiable Data Breaches schemeEntities covered by the Privacy Act

Assessing and notifying eligible data breaches

The Notifiable Data Breaches scheme applies to entities covered by the Privacy Act. Where it applies, a suspected eligible data breach must be assessed, and a confirmed breach likely to result in serious harm must be notified to affected individuals and to the Office of the Australian Information Commissioner. Prompts and file uploads sent to unapproved AI tools are one way personal information leaves your control, so knowing what was shared, by whom, and when is part of being able to make that assessment at all.

Voluntary AI Safety StandardVoluntary guidance

10 guardrails and the AI Ethics Principles

The Australian Government's Voluntary AI Safety Standard sets out 10 guardrails covering accountability, risk management, data governance, testing, human oversight, transparency and record keeping. It is guidance rather than legislation, and it sits alongside Australia's 8 AI Ethics Principles. Some grant applications, tenders and contract questionnaires may ask how your organisation manages AI risk, and these two documents are a common reference point when they do, so early alignment can save work later.

Australia's AI Ethics Framework

This page is general information, not legal advice. Other obligations may also apply to your organisation, including state and territory privacy and health records laws, child safe and other safeguarding standards, incorporated association rules, funding agreements, service contracts and your own constitution. Confirm what applies to you with your own advisers.

How Aona helps

Four things, in the order most not-for-profits need them.

1

See which AI tools are actually in use

On the devices where the Aona browser plugin or native app is installed, Aona discovers the AI tools in use, including personal accounts used on those devices, and matches what it sees against a catalogue of more than 10,000 AI tools. You get a named inventory with usage patterns instead of an estimate. The catalogue is what Aona can recognise, your rollout is what it can see, so devices without Aona installed stay outside the inventory.
A named inventory, not a guess
2

Protect sensitive information at the point of use

On covered devices, prompts and file uploads are inspected before they reach the AI tool. Depending on your policy, sensitive content is redacted, the person is warned, or the action is blocked, across the web and desktop AI surfaces Aona supports. Rules can differ by team, so case workers and fundraisers are not held to the same list.
Controls run before the prompt leaves the device
3

Turn your AI policy into everyday guidance

Your acceptable use rules become on-screen coaching at the moment someone is about to share something they should not, with the approved alternative alongside it. Staff, contractors and volunteers can be covered by the same policy, on any device where Aona is installed.
Guidance in the moment, not a PDF nobody opens
4

Give your board and funders evidence

Usage, policy events and interventions on covered devices are recorded, so you can report what AI is used for, what was caught, and what changed over time. That is the record a board paper, a funder question or an audit actually needs.
Reporting you can put in a board pack

A practical first 30 days

A sequence that works for small teams without a dedicated risk function. Adjust the pace to suit your organisation.

Days 1 to 7

Discover current usage

Deploy to a first group and let the inventory build. Most organisations are surprised by how many tools appear, and by which teams turn out to be furthest ahead.

Days 8 to 14

Agree what good looks like

Pick the handful of AI uses you want to encourage, and name the information that must never leave your environment: client identifiers, case notes, health details, donor records, staff and volunteer files.

Days 15 to 21

Roll out guidance and controls

Move from watching to guiding. Start with warnings and redaction on the highest-risk data types, keep hard blocks narrow, and tell people what changed and why.

Days 22 to 30

Review the evidence and adjust

Take the first report to your leadership team or board: what is being used, what was caught, and where the policy was unclear. Tighten what needs tightening, and remove friction that is not earning its keep.

FAQ

Not-for-profit AI governance questions

AI governance is the set of decisions and controls that let your team use AI while protecting the people you serve. In practice it covers four things: knowing which AI tools staff, contractors and volunteers actually use; agreeing which uses are approved and what information must never be pasted into a public tool; giving people guidance at the moment they are about to make a mistake; and keeping records so your board, funders and auditors can see how AI is being used. For most not-for-profits this is a small, practical program rather than a large compliance project.
Get started

Let your team use AI with trust protected

See your own AI usage in days, not quarters. We will walk through what a not-for-profit rollout looks like, what your board would see, and what it takes to keep data in Australia.