/


A field officer is behind on a donor report. To save time, she pastes a week of case notes into a free AI tool and asks for a summary. The summary is good. But nobody knows where the notes went, whether they included names, or whether the people described would ever have agreed.
Scenes like this are now routine. In a January 2026 pulse survey by the Humanitarian Leadership Academy (HLA) and Data Friendly Space, 75% of respondents used AI daily or weekly, but only 23% had a formal AI policy.
For NGOs, that gap is a trust problem, because trust is what the whole organization runs on. This article covers why trust decides adoption, how far governance lags behind use, six ethical risks to govern, what proportionate governance looks like, and a practical roadmap for responsible AI for NGOs.
An NGO depends on trust in several directions at once, and AI touches every one of them (Figure 1):

Donors are paying attention. In Fundraising.AI’s Donor Perceptions of AI study , 92% said it was important for nonprofits to disclose where and why they use AI, and 32% said they would give less to organizations using it (Figure 2).

Source: Fundraising.AI, Donor Perceptions of AI 2025
Communities have even more at stake. A data leak or a biased decision can affect their safety or their access to help, and they rarely have anywhere else to turn.
For an NGO, lost trust is more than a reputation problem. It can cut funding, weaken community participation, and put people at risk.
The survey figures in the introduction are not an outlier. Across the sector, use has moved faster than the rules around it (Figure 3):

Source: Humanitarian Leadership Academy and Data Friendly Space, January 2026 pulse survey
The practical result is shadow AI: staff using public tools with no shared rules, while leaders cannot see what data leaves the organization. That is rarely carelessness. It is what happens when busy people find a useful tool and nobody has explained how to use it safely. Figure 4 shows where each path leads.

These risks are practical, not abstract. Each one affects real people, and each has a clear governance response. Figure 5 summarizes all six.

Case notes, protection records, health data, and the locations of vulnerable people can end up in public AI tools or with vendors whose data practices nobody has reviewed. Once shared, that data may be impossible to recall. Staff rarely mean harm. They are usually trying to save time on reporting or translation.
Governance response: set clear rules on data that must never enter AI tools, approve a short list of tools, and require a data protection review before any new use. Explain the rules to staff in plain language.
When aid depends on registration, consent is rarely free. People may agree to anything to receive help, and few are in a position to ask how an AI system will use their data. In humanitarian settings, that power imbalance is built into the relationship, not a sign of bad practice.
Governance response: do not rely on consent alone. Apply purpose limitation and follow humanitarian guidance such as the IASC Operational Guidance on Data Responsibility and the ICRC Handbook on Data Protection in Humanitarian Action. Where possible, collect less data in the first place.
Models trained on incomplete data can overlook people who are already underrepresented: remote communities, minority language speakers, people without phones, and people with disabilities. A tool that works well on average can still fail the people who need it most. Language is a common failure point: a chatbot that only works in the main national language quietly excludes everyone else.
Governance response: test for representation gaps before deployment, and monitor outcomes across groups after launch, including by language and location.
The highest-risk uses affect who receives assistance, protection, or services, such as eligibility scoring or case prioritization. An error here is not an inconvenience. It can mean a whole family goes without support. Automation can also make errors harder to see, because a score looks objective even when the data behind it is incomplete.
Governance response: keep a person accountable for every decision about an individual, and give people a clear way to question or appeal the outcome (Figure 6).

AI-generated images of people in need, synthetic testimonials, and chatbots that do not say they are AI can mislead donors and misrepresent communities. Donors notice: in the Fundraising.AI study, 34% ranked AI bots presented as humans as their single greatest concern. Staff under pressure to produce compelling campaigns may not see the line until a donor or journalist points it out.
Governance response: disclose AI use in communications, and never present AI-generated people or stories as real.
Many NGOs rely on free or donated AI tools. Terms can change, data may be stored in another jurisdiction, and local partners can lose control over data about their own communities. Smaller local organizations are often the most exposed, because they have the least capacity to negotiate terms.
Governance response: carry out basic vendor due diligence, sign clear data-sharing agreements, and know where data is stored and who can reach it. Plan in advance how you would switch tools if terms change.
The closer an AI system gets to deciding who receives help, the stronger the governance around it must be.
None of this requires a large compliance team. The principle is proportionate governance: oversight should match the risk to people, not the novelty of the tool. Figure 7 shows three tiers, and each includes everything below it. Most NGO AI use falls into the low tier, which is good news: the first steps are cheap.

The SAFE AI framework from the CDAC Network, The Alan Turing Institute, and the Humanitarian AI Alliance uses a similar three-tier model and is the most relevant sector reference. The NIST AI Risk Management Framework and UNESCO’s Recommendation on the Ethics of AI add broader principles. Reuse these frameworks rather than writing your own from scratch. Every NGO also needs the building blocks in Figure 8.

A two-page policy that staff actually use is worth more than a forty-page policy nobody reads.
Responsible adoption is a sequence, not a single policy launch. These seven steps work for organizations of most sizes (Figure 9):

Step 5 matters more than it looks. In the NTEN and Bridgespan survey, just 1% of respondents identified AI approval as a collective or all-staff decision. Staff know where AI already helps, and communities know where it could cause harm. Both perspectives are needed before a high-risk system goes live.
Omdena helps NGOs assess planned AI uses against the risk to people, then design systems with human oversight, privacy, and fairness built in from the start. That includes evaluating models for bias and representation gaps before launch.
Omdena’s global community of AI engineers includes local talent who understand the communities involved, which matters when a system must work across languages, cultures, and uneven connectivity. The approach is practical: start with the use cases staff already rely on, then add safeguards in proportion to the risk.
NGOs often have to show donors and boards what was built and how. Umaku, Omdena’s agentic AI delivery platform, supports that accountability during development. An NGO building a multilingual feedback chatbot for affected communities could use it to:


Umaku is not an ethics or compliance platform, and its AI-generated findings still need human review.
NGOs are already using AI. The real choice is between governed and ungoverned use, not between using AI and avoiding it.
Ungoverned use puts the most important things at risk: sensitive data, fair treatment, honest communication, and the trust of communities and donors. Proportionate governance protects them without slowing teams down. It gives staff clear rules, keeps people accountable for decisions about people, and makes AI use visible to those it affects. For NGOs, responsible AI is simply how “do no harm” applies to AI.
If your organization is planning or already using AI, talk to Omdena about assessing the risks to the people you serve and designing the right safeguards from the start.