The 2026 AI Index documents something that didn’t get much coverage in the general press: documented AI incidents rose to 362 in 2025, up from 233 the year before — a 55% increase in a single year. The report also notes that improving one responsible AI dimension, such as safety, can degrade another, such as accuracy. These are not isolated failures from poorly resourced deployments. They reflect a structural pattern: capability is advancing faster than the frameworks organizations are using to manage it.

For small nonprofits, the governance gap isn’t a theoretical concern. It’s a present operational exposure — and most organizations haven’t closed it.

Why Small Organizations Are Particularly Exposed

The standard assumption is that AI governance is an enterprise problem. Large organizations with complex data environments, legal teams, and compliance functions need governance frameworks. Small nonprofits with 10 or 15 staff, operating lean, can manage informally.

That assumption doesn’t hold up. Small nonprofits are often more exposed, not less, for two reasons.

First, the populations they serve. Organizations working in education access, workforce development, and community empowerment routinely handle sensitive information about people already navigating vulnerable circumstances — students, job seekers, and community members with complicated histories with institutions. When something goes wrong with data, with an automated communication, or with an AI-assisted process that produces incorrect or culturally inappropriate output, the damage is relational. And in small organizations, community trust is the asset that’s hardest to rebuild.

Second, the absence of redundancy. In a large organization, a staff member using an AI tool carelessly has colleagues, review processes, and institutional checks that may catch the problem before it reaches a funder or a program participant. In a 12-person shop, the same staff member may be the only person touching that work. There is no redundancy to absorb the error.

What “No Policy” Actually Means

Most small nonprofits are not actively choosing to operate without AI governance. They’re simply not deciding at all — and in a period of rapid tool adoption, that’s the default position.

What does it mean in practice? It means individual staff members are making consequential judgment calls without shared organizational guidance. Which tools are appropriate to use? What constituent data, if any, can be used as input? How should AI-generated content be reviewed before it goes external? Who is responsible if something goes wrong?

These are not hypothetical edge cases. They are decisions your staff is making now, with whatever individual judgment they bring. The variation across a 15-person staff can be significant, and without a policy, there is no common standard to appeal to.

The risk surfaces in several directions. Funder relationships are one: some foundations have begun asking about AI use in grant proposals, and an organization that can’t answer clearly is at a disadvantage. Community trust is another: if a program participant discovers that information they shared with your organization was used as input to an AI tool without their knowledge, the breach is relational as much as it is procedural. And there is reputational risk: the 362 documented incidents in 2025 include organizations that had no intent to cause harm and simply hadn’t built the scaffolding to prevent it.

What a Governance Policy Actually Needs to Cover

A governance policy for a small nonprofit need not be a lengthy compliance document. It needs to force the decisions that currently aren’t being made. At a minimum, it should address four areas:

Approved tools. Which AI tools are organizational resources, as distinct from personal tools staff happen to use? This doesn’t mean prohibiting everything outside the approved list — but it does mean the organization has a stated position, rather than leaving staff to navigate an expanding tool landscape without guidance.

Data boundaries. What categories of information can and cannot be used as inputs to AI tools? At a minimum, this should explicitly address anything that touches program participants: names, case notes, demographic information, and communications. Many AI tools process inputs through external servers and retain data in ways users don’t fully understand. Your participants didn’t consent to that when they engaged with your program.

Review requirements. How does AI-generated content get reviewed before it goes external — to funders, to the public, to program participants? This doesn’t require a burdensome approval process. It requires a stated expectation that a human checks AI-generated output before it represents the organization.

Accountability. When something goes wrong — and at some point, something will — who is responsible, and what is the response process? Thinking this through in advance is considerably better than improvising under pressure.

None of this requires outside expertise to develop. It requires protected staff time and a willingness to make decisions rather than defer them. The value isn’t the policy document itself — it’s that the process of building it forces the organizational decisions that should have been made when the tools first arrived.

A Practical Starting Point

If your organization doesn’t have a governance policy and leadership bandwidth is tight, the most useful first step is a structured conversation with your senior team — not a policy drafting session, but a decision-forcing exercise: if a staff member’s AI use caused harm to a program participant tomorrow, what would we do?

Most leadership teams find that question clarifies priorities faster than any abstract policy discussion. It surfaces the specific exposures that matter most in your organizational context, and it tends to generate the decisions — about data, about tools, about accountability — that a policy then documents.

The 2026 AI Index makes clear that the gap between AI capability and governance infrastructure is widening, not closing. For small nonprofits, that gap is manageable, but it requires treating it as a management problem rather than a background condition.

Data cited throughout is drawn from the 2026 AI Index Report, published by Stanford HAI. Full report available at aiindex.stanford.edu.

The series:

 

The 2026 AI Index documents something that didn’t get much coverage in the general press: documented AI incidents rose to 362 in 2025, up from 233 the year before — a 55% increase in a single year. The report also notes that improving one responsible AI dimension, such as safety, can degrade another, such as accuracy. These are not isolated failures from poorly resourced deployments. They reflect a structural pattern: capability is advancing faster than the frameworks organizations are using to manage it.

For small nonprofits, the governance gap isn’t a theoretical concern. It’s a present operational exposure — and most organizations haven’t closed it.

Why Small Organizations Are Particularly Exposed

The standard assumption is that AI governance is an enterprise problem. Large organizations with complex data environments, legal teams, and compliance functions need governance frameworks. Small nonprofits with 10 or 15 staff, operating lean, can manage informally.

That assumption doesn’t hold up. Small nonprofits are often more exposed, not less, for two reasons.

First, the populations they serve. Organizations working in education access, workforce development, and community empowerment routinely handle sensitive information about people already navigating vulnerable circumstances — students, job seekers, and community members with complicated histories with institutions. When something goes wrong with data, with an automated communication, or with an AI-assisted process that produces incorrect or culturally inappropriate output, the damage is relational. And in small organizations, community trust is the asset that’s hardest to rebuild.

Second, the absence of redundancy. In a large organization, a staff member using an AI tool carelessly has colleagues, review processes, and institutional checks that may catch the problem before it reaches a funder or a program participant. In a 12-person shop, the same staff member may be the only person touching that work. There is no redundancy to absorb the error.

What “No Policy” Actually Means

Most small nonprofits are not actively choosing to operate without AI governance. They’re simply not deciding at all — and in a period of rapid tool adoption, that’s the default position.

What does it mean in practice? It means individual staff members are making consequential judgment calls without shared organizational guidance. Which tools are appropriate to use? What constituent data, if any, can be used as input? How should AI-generated content be reviewed before it goes external? Who is responsible if something goes wrong?

These are not hypothetical edge cases. They are decisions your staff is making now, with whatever individual judgment they bring. The variation across a 15-person staff can be significant, and without a policy, there is no common standard to appeal to.

The risk surfaces in several directions. Funder relationships are one: some foundations have begun asking about AI use in grant proposals, and an organization that can’t answer clearly is at a disadvantage. Community trust is another: if a program participant discovers that information they shared with your organization was used as input to an AI tool without their knowledge, the breach is relational as much as it is procedural. And there is reputational risk: the 362 documented incidents in 2025 include organizations that had no intent to cause harm and simply hadn’t built the scaffolding to prevent it.

What a Governance Policy Actually Needs to Cover

A governance policy for a small nonprofit need not be a lengthy compliance document. It needs to force the decisions that currently aren’t being made. At a minimum, it should address four areas:

Approved tools. Which AI tools are organizational resources, as distinct from personal tools staff happen to use? This doesn’t mean prohibiting everything outside the approved list — but it does mean the organization has a stated position, rather than leaving staff to navigate an expanding tool landscape without guidance.

Data boundaries. What categories of information can and cannot be used as inputs to AI tools? At a minimum, this should explicitly address anything that touches program participants: names, case notes, demographic information, and communications. Many AI tools process inputs through external servers and retain data in ways users don’t fully understand. Your participants didn’t consent to that when they engaged with your program.

Review requirements. How does AI-generated content get reviewed before it goes external — to funders, to the public, to program participants? This doesn’t require a burdensome approval process. It requires a stated expectation that a human checks AI-generated output before it represents the organization.

Accountability. When something goes wrong — and at some point, something will — who is responsible, and what is the response process? Thinking this through in advance is considerably better than improvising under pressure.

None of this requires outside expertise to develop. It requires protected staff time and a willingness to make decisions rather than defer them. The value isn’t the policy document itself — it’s that the process of building it forces the organizational decisions that should have been made when the tools first arrived.

A Practical Starting Point

If your organization doesn’t have a governance policy and leadership bandwidth is tight, the most useful first step is a structured conversation with your senior team — not a policy drafting session, but a decision-forcing exercise: if a staff member’s AI use caused harm to a program participant tomorrow, what would we do?

Most leadership teams find that question clarifies priorities faster than any abstract policy discussion. It surfaces the specific exposures that matter most in your organizational context, and it tends to generate the decisions — about data, about tools, about accountability — that a policy then documents.

The 2026 AI Index makes clear that the gap between AI capability and governance infrastructure is widening, not closing. For small nonprofits, that gap is manageable, but it requires treating it as a management problem rather than a background condition.

Data cited throughout is drawn from the 2026 AI Index Report, published by Stanford HAI. Full report available at aiindex.stanford.edu.

The series: