Artificial intelligence (AI) can help organizations analyze information, personalize communications, and automate routine tasks. But using AI responsibly requires more than choosing a reliable tool or adding a boilerplate of “AI tools can make mistakes.”

AI systems can reproduce bias in their training data, expose confidential information, produce inaccurate content, or make recommendations that are difficult to explain. And when AI is used in decisions that affect people,such as hiring, fundraising, member services, or access to programs,the consequences can extend beyond a bad output or an awkward email.

Enter: AI ethics.

AI ethics is the practice of deciding what responsible AI use looks like for your organization and putting processes in place to consistently review and rework those decisions. 

AI ethics takes the ethical principles of fairness, accountability, and transparency and connects them to practical activities like risk assessments, staff training, vendor reviews, and ongoing audits.

For nonprofits and associations, the goal isn’t to eliminate AI risk but to understand where AI could cause harm, establish safeguards, and ensure that your people remain accountable.

What Is Ethical AI? 

Ethical AI is the development and use of artificial intelligence in ways that are fair, accountable, transparent, and aligned with the organization’s values and responsibilities to the people it serves.

There is not one universally accepted list of AI ethics principles. However, the National Institute of Standards and Technology (NIST) identifies responsible AI characteristics as “validity and reliability, safety, security and resilience, accountability and transparency, explainability and interpretability, privacy enhancement, and fairness.”

For an organization developing an AI ethics framework, five principles provide a useful starting point: 

  1. Fairness: AI should not create or reinforce unjustified disparities between people or groups. Consider an organization using an AI-powered recruiting tool to screen job applicants. If the system consistently ranks certain candidates lower because patterns in historical hiring data reflect past discrimination, the fact that the organization didn’t intend to discriminate doesn’t eliminate the risk. Fairness also goes beyond demographic representation. An AI system could also be unfair because it is inaccessible to people with disabilities, relies on incomplete data, or reinforces an existing structural disadvantage.
  1. Accountability: Someone needs to be responsible for how an AI system is selected, configured, used, monitored, and corrected. For a nonprofit, accountability might mean that an executive director approves the use of AI for donor communications, an IT or operations lead reviews data-security considerations, and a program director remains responsible for decisions involving clients or participants.
  1. Transparency: People should have appropriate information about when and how AI is being used. For example, if an association uses an AI chatbot to answer member questions, members should not be misled into thinking they are communicating with a person.
  1. Explainability: People responsible for an AI system should understand its outputs well enough to evaluate and challenge them. Where transparency can help answer what happened, explainability focuses more on how the system arrived at an output. The level of explanation needed should depend on the stakes. An organization may accept limited explainability for an AI tool that suggests subject lines. It should demand substantially more oversight before relying on AI to recommend which applicants receive a scholarship.
  1. Impact and Human Oversight: Finally, ethical AI requires organizations to consider an AI system’s real-world impact and keep humans involved where appropriate. Human oversight means the organization establishes meaningful human control when an AI output could materially affect a person. Ask yourself, “If this AI output is wrong, who could be harmed, and who has the authority to stop or correct it?”

Ethical AI vs. Responsible AI vs. AI Governance: How The Terms Fit Together 

While these terms are often used interchangeably, they describe different things. 

AI ethics focuses on the principles and values behind responsible AI use. It asks questions such as:

  • Is this use fair?
  • Could it discriminate against someone?
  • Should we use AI for this purpose at all?
  • What responsibilities do we have to the people affected?

Responsible AI is the broader practice of putting those principles into action throughout the AI lifecycle. It includes technical, organizational, legal, ethical, and operational considerations.

AI governance is the organizational structure that makes responsible AI repeatable, establishing who makes decisions, which uses require approval, how risks are documented, and how staff is trained.

Tip: A small nonprofit wouldn’t need to create a new department or hire a new employee/specialist. AI governance could simply be designating a staff owner, a board-level reporting process, an AI inventory, a risk-rating system, and a few approval rules.

Think of it this way:

  • AI ethics defines what responsible use should look like. 
  • Responsible AI puts it into practice. 
  • AI governance gives your organization a system for doing it consistently.

A Practical 5-Step Framework To Implement Ethical AI 

5-Step Framework To Implement Ethical AI

A useful AI ethics program starts with understanding what your organization is already doing, identifying the greatest risks, establishing ownership, educating the people using AI, and creating a process to review your approach over time.

Step 1: Assess Current AI Use

Before you can govern AI, you need to know where it is being used. But take note: AI use may extend beyond tools IT has formally approved. Employees may already be using general-purpose generative AI tools to draft emails, summarize documents, analyze spreadsheets, create social media content, or brainstorm program ideas.

Create a simple AI use inventory.

For each use, record:

  • Tool or system
  • Department or user
  • Purpose
  • Type of AI being used
  • Data entered into the system
  • Whether the output affects another person
  • Whether a human reviews the output
  • Whether the vendor stores or uses submitted information
  • Risk level
  • Person responsible for oversight

You don’t need perfect documentation on day one. The purpose of taking inventory is to uncover the organization’s actual AI footprint.

Step 2: Identify Risk Areas

Not every AI use requires the same level of scrutiny. A useful AI risk management approach is to evaluate a system based on the potential consequences of getting it wrong.

Ask:

  1. What data does the system obtain? And how does it obtain it?
  2. Who could be affected by the result/output?
  3. Could the output affect someone’s rights, opportunities, finances, employment, privacy, or access to services?
  4. Could the system produce discriminatory or biased outcomes?
  5. Can a human meaningfully review and override the output?
  6. Can the organization explain how the system is being used?
  7. What happens if the system produces an incorrect or harmful result? 
  8. Does a law, regulation, contract, funder requirement, or professional obligation apply?

You can then classify uses as low, moderate, or high risk.

A low-risk example might be using generative AI to brainstorm event themes.

A higher-risk example would be using an algorithm to determine which community members receive limited program resources.

The important distinction is impact, not novelty. A sophisticated AI system isn’t automatically high risk, and a simple tool isn’t automatically low risk.

Step 3: Establish A Governance Structure

Once you’ve identified your AI uses and their risk levels, establish who owns the decision-making process for each case. For larger organizations, this could involve an AI governance committee with delegates from IT, legal or compliance, HR, communications, and leadership.

But for a small nonprofit, the structure could be much simpler:

  • The Executive Director has final decision-making authority for high-risk uses.
  • Operations/IT handles tool and security reviews.
  • HR is in charge of reviewing employment-related uses.
  • The board oversees significant organizational risks.

In either case, create clear approval thresholds based on perceived risk levels. For example:

  • Low-risk uses: Employees may use pre-approved AI tools for things like routine brainstorming.
  • High-risk uses: Board leadership must approve AI use in these cases, with a documented risk assessment, human oversight, and periodic review.

Step 4: Train Staff

An AI policy won’t protect your organization if your employees and volunteers don’t understand how to follow it. 

Staff and volunteers should understand:

  • What AI tools the organization permits
  • What information may and may not be entered
  • Which uses require approval
  • How to verify AI-generated information
  • How to recognize probable bias
  • When human review is required
  • How to report a suspected AI problem

For nonprofits, include volunteers where appropriate. A volunteer managing an organization’s social media account or helping with donor communications may have access to the same AI tools as staff without receiving the same training.

AI literacy is increasingly becoming part of the regulatory conversation, too. For example, the EU AI Act’s AI literacy requirements have applied since February 2025, although the Act’s other obligations phase in according to the type of system and organization involved.

Training should also make clear that employees are not expected to become AI engineers. The objective is to help people recognize when an AI use is routine and when it requires additional judgment.

Step 5: Audit and Iterate 

Ethical AI is not a one-time compliance exercise. Tools change. Regulations evolve. So it’s crucial to establish a risk-based review schedule.

For example, low-risk uses can be reviewed annually, while moderate-risk uses should be reviewed every six months or when the use changes or regulations evolve. High-risk uses should involve ongoing monitoring and formal review at predetermined intervals.

Document any and all significant incidents, complaints, unexpected outcomes, and changes to the system.

NIST’s AI Risk Management Framework similarly treats AI risk management as an ongoing process, with core functions to Govern, Map, Measure, and Manage, which organizations can apply throughout the AI lifecycle.

How To Audit AI For Bias And Harm: Evaluating Tools Against The People And Communities You Serve

An AI bias audit evaluates whether your AI system produces systematically unfair, discriminatory, inaccurate, or otherwise harmful outcomes for specific individuals or groups.

But you can’t just ask, “Is the algorithm biased?”

Start by asking:

  • Who is represented in the data? Who isn’t?
  • Are some applicants more likely to have incomplete data?
  • Does the system work equally well for different groups?
  • Are there accessibility barriers?
  • What happens when the system is wrong?
  • Can an applicant challenge the result?

Then test the system. Depending on the use case, an audit might include:

  • Data review: Examine whether training or input data are complete, relevant, representative, and appropriate for the intended use.
  • Outcome testing: Compare results across relevant groups to identify any disparities.
  • Scenario testing: Run specific persona examples through the system to see how outputs change.
  • Human review: Have staff (who are familiar with AI and the community that you serve) independently review the outputs. 
  • Impact assessment: Consider whether an observed difference represents an acceptable operational trade-off or creates an unjustifiable burden.

It’s also important to distinguish algorithmic bias from simple factual error. An AI system that invents information is unreliable; an AI system that consistently produces worse outcomes for a particular group raises a fairness concern. A system can have both problems at the same time.

AI Compliance: Emerging State-Level Requirements That Any Digitally Operating Organization Should Track 

AI compliance is becoming more complicated because no single U.S. AI law covers every organization and every use of AI. Instead, organizations must consider a mix of existing laws and emerging AI-specific requirements.

This is particularly important for organizations operating across state lines.

AI Compliance: California

California has enacted several AI-related laws, but their applicability varies considerably. For example, the Generative Artificial Intelligence Training Data Transparency Act, effective this year, requires developers of covered generative AI systems or services made available to Californians to publish specified information about the data used to train those systems. This law primarily targets developers, not ordinary organizations that use third-party AI tools.

California’s Transparency in Frontier Artificial Intelligence Act adds transparency, safety, and accountability requirements for certain large developers of frontier AI models, requiring them to publish frameworks that address issues such as catastrophic-risk assessment and mitigation.

AI Compliance: Colorado

Colorado is another important state to watch, as the state significantly revised its automated decision-making framework in 2026. Under the new law, regulators are developing requirements governing automated decision-making technology used in consequential decisions. 

For an organization using AI in areas such as employment, housing, lending, insurance, education, or access to important services, this type of legislation deserves particular attention.

AI Compliance: Don’t Ignore Existing Laws

AI-specific legislation is only part of AI compliance.

Existing laws can apply when AI is used for:

  • Hiring and employment decisions
  • Handling personal information
  • Marketing and communications
  • Accessibility
  • Financial transactions
  • Donor or member data
  • Health or other sensitive information
  • Decisions about access to services or benefits

For example, the U.S. Equal Employment Opportunity Commission has emphasized that AI and algorithmic tools used in employment decisions remain subject to federal anti-discrimination laws.

The practical takeaway is simple: don’t build an AI compliance program around a list of laws alone. Build a governance process that can adapt as requirements change.

*This is not a substitute for legal advice. Organizations should have qualified counsel assess whether specific AI uses trigger legal or regulatory obligations.

AI Governance Checklist For Boards And Lean Teams: 

You don’t need a large compliance department to establish basic AI governance. Use this checklist as a starting point: 

AI Inventory

  • Have we identified the AI tools employees and volunteers currently use?
  • Do we know what each tool is being used for?
  • Have we identified which tools receive organizational, member, donor, employee, or participant data?
  • Have we documented high-impact or high-risk uses?

Data and Privacy

  • Do staff know what information they cannot enter into public AI tools?
  • Have we reviewed vendors’ data-use and retention practices?

Fairness and Bias

  • Could an AI system affect different groups differently?
  • Have we identified potentially affected populations?
  • Do we have a process for investigating complaints or unexpected disparities?

Transparency and Explainability

  • Do people know when they are interacting with AI?
  • Can staff explain how AI is being used?
  • Can the affected individuals ask questions or seek human review?

Human Oversight

  • Which decisions require human approval?
  • Does the reviewer have the authority and ability to override the AI?
  • Does the reviewer have enough information and training to recognize a bad output?
  • Is AI ever being treated as the final decision-maker when it shouldn’t be?

Vendor Management

  • Have we reviewed the vendor’s security and privacy practices?
  • Does this vendor use submitted data to train models?
  • Does the contract address data ownership, retention, security, and deletion?
  • What happens if the vendor changes its AI model or terms?
  • How will we respond if the vendor experiences an AI-related incident?

Board Oversight

  • Does the board understand when and where the organization uses AI?
  • Has leadership established acceptable and prohibited uses?
  • Are AI risks included in the organization’s broader risk management process?
  • Does leadership periodically report significant AI risks or incidents to the board?

Looking for AI that stays governed, transparent, and auditable, with human oversight built in, rather than a bolt-on generic tool? Book a MomentiveIQ demo. 

How To Implement Ethical AI In Nonprofits 

Nonprofits face some of the same AI governance challenges as businesses, but their missions can add extra considerations.

An association may use AI to analyze member engagement. A nonprofit could use it to segment donors or to draft grant applications. In each case, the technology may be capable of doing the task. However, that doesn’t automatically mean the organization should delegate the task to AI.

A practical nonprofit AI ethics framework should start with mission and impact. Ask yourself if the use of AI helps to execute your mission without creating an unreasonable risk to the people you serve. 

Be especially careful with member and donor data. Member and donor databases contain information that can be valuable for personalization and analysis but may also be sensitive.

Don’t assume that because information is stored in your organization’s database, it is appropriate to paste it into an AI tool.

Establish clear rules about:

  • Donor information
  • Member records
  • Employee information
  • Confidential grant or funder information
  • Internal financial information

Tip: Volunteers can be an overlooked part of AI governance. If volunteers write newsletters, manage social media, conduct research, or assist with member communications, they may already be using AI. However, the goal isn’t to discourage volunteers from using useful technology. It’s to make responsible use easy.

Your AI framework should be proportional to your organization and its needs. A small nonprofit does not need the same AI governance infrastructure as a large technology company. Start with the highest-risk uses and add more advanced controls as your organization’s AI use grows.

Next Steps And Resources

Ethical AI isn’t about finding a perfect formula for eliminating every possible risk. It’s about building a repeatable process for making better decisions about when and how your organization uses AI.

For organizations that want to formalize the process, the NIST AI Risk Management Framework is a useful foundation. It is voluntary, designed for organizations of different sizes and sectors, and organizes AI risk management around governing, mapping, measuring, and managing risk. NIST also provides a generative AI profile that addresses risks specific to generative AI.

The most important thing is to avoid treating AI ethics as a document that sits in a policy folder.

A policy can establish the rules. Governance makes those rules part of how the organization actually works.

For nonprofits and associations in particular, that means keeping the focus on protecting the trust and confidence of your members, donors, employees, volunteers, and communities who depend on you.

AI will continue to change. Your governance process should adapt with it.

Put ethical AI into practice with MomentiveIQ

MomentiveIQ brings AI to nonprofits and associations with governance built in — every action transparent, auditable, and under human oversight.

FAQs: