There is no shortage of enthusiasm around artificial intelligence and what it might mean for the nonprofit (NGO) sector. The promise of AI for nonprofits is genuinely compelling; technology that can transcribe case notes, draft service plans, triage incoming referrals, and stretch every dollar of a constrained budget a little further. For an NFP navigating workforce shortages, growing demand, and ever-tightening funding, AI feels like it could be a long-overdue equaliser.
But promise and reality are two very different things. Australian nonprofits hold some of the most sensitive personal information in existence. They serve highly vulnerable populations. They carry both contractual and moral obligations to protect the people in their care. For organisations like these, the gap between what AI promises and what it actually delivers deserves careful, and honest, examination.
This article takes an honest look at both sides. We explore where AI for nonprofits holds genuine potential, where the risks are real and under-appreciated, and what a responsible path forward looks like for Australian NFPs evaluating AI tooling today.
The Promise: What AI for Nonprofits could mean
Doing More With Less
The “do more with less” imperative is not new for nonprofits. What is new is that AI, for the first time, offers a credible technological answer to it. The most immediately practical applications for nonprofit AI are in the areas where staff spend disproportionate time on administrative and transactional work:
- Note-taking and transcription: AI-powered transcription tools can convert case worker conversations, intake interviews, and team meetings into structured notes, dramatically reducing the time spent on documentation. In a sector where workers are already stretched, reclaiming even an hour per day per worker is significant.
- Case planning and documentation: Large language models (LLMs) can assist caseworkers in drafting care plans, summarising client histories, and populating structured fields from unstructured conversation notes. This reduces documentation burden and improves consistency across workers and locations.
- Client intake and triage: Agentic AI (AI that can take sequences of actions autonomously, not just respond to prompts) offers the possibility of automating the initial stages of client intake e.g. gathering information, screening for eligibility, prioritising urgency, and routing referrals to the right service. For organisations managing high volumes of referrals with limited intake staff, this is a genuinely transformative capability.
- Reporting and compliance: Generating funding reports, outcome summaries, and compliance documentation from structured data is time-consuming and error-prone when done manually. AI for nonprofits can accelerate this significantly.
The budget maths are attractive. At a time when many nonprofits are being asked to deliver more with static or reduced funding, AI-assisted efficiency gains can meaningfully extend capacity without adding headcount.
The Reality: Where the promise gets complicated
The complexity of human services
Before exploring the technology risks, it is worth acknowledging something that is often glossed over in AI discussions: human services delivery is genuinely complex. The clients of Australian NFPs (people experiencing homelessness, family violence, disability, mental illness, addiction, or trauma) do not present with clean, predictable needs that map neatly to automated workflows.
A client’s situation may change hour to hour. A risk that presents as low during intake may escalate rapidly. Cultural context, language, trust, and relationship all profoundly affect outcomes. The services themselves are often multi-agency, multi-funded, and governed by a patchwork of obligations and referral pathways that no AI system currently in the market has been trained to fully understand.
Underpinning all of this is a duty of care. Australian NFPs have a legal and ethical obligation to take reasonable steps to prevent foreseeable harm to the people in their care. That duty does not transfer to a technology vendor when you adopt their platform. If an AI system misclassifies a risk, generates an incomplete care plan, or fails to flag an escalating situation (and harm results) your organisation remains the responsible party. This is not a theoretical concern. In human services, the consequences of a missed signal or a poor decision can be severe and irreversible, particularly when working with children, people at risk of self-harm, or those fleeing violence.
Before deploying any AI tool in a direct service context, NFPs should ask: does our use of this technology meet the standard of care we would expect from a trained human worker? If the honest answer is “we’re not sure,” that uncertainty itself is the answer.
This complexity is not a reason to reject AI entirely, but it is a reason to approach it with clear-eyed realism about what AI can and cannot do reliably in this context, and to ensure that duty of care obligations are explicitly considered before any AI tool touches a client interaction.
The rapidly shifting landscape
The AI tools and providers available today are not the same as those available six months ago, and will not be the same six months from now. Vendors are being acquired, pivoting, repricing, and in some cases shutting down. Capabilities that are marketed as production-ready are sometimes still experimental. Evaluation frameworks that seem adequate today may be superseded by new guidance before an implementation is complete.
For nonprofits (where IT teams are typically small or non-existent, and where the cost and disruption of switching platforms is high) committing to AI tooling in a rapidly shifting market carries real risk. The vendor you choose today may look very different in 18 months.
The Critical Issue: Security, Privacy, and Data Sovereignty
This is where the reality diverges most sharply from the promise, and where Australian nonprofits need to pay the closest attention.
What your clients’ data actually looks like
Australian NFPs routinely hold some of the most sensitive personal information that exists. Client records may include clinical diagnoses, mental health histories, family violence incident reports, child protection involvement, criminal histories, legal matters, immigration status, and detailed case notes describing some of the most difficult moments in a person’s life. This is not generic business data. It is profoundly personal, and the people it describes are often among the most vulnerable in our community.
Your obligations around this data are significant – governed by the Privacy Act 1988 (Cth), relevant state legislation, and the specific requirements of your funding agreements. None of those obligations are diminished because a software vendor has embedded an AI feature into their platform.
The data sovereignty problem
Most AI-enabled software tools do not build their own AI. They are wrappers around a small number of large foundation models e.g. OpenAI’s GPT series, Google’s Gemini, Anthropic’s Claude, Meta’s Llama, and a handful of others. When your case management platform uses AI to transcribe a session or draft a care plan, that data is almost certainly being processed by one of these underlying providers.
The critical questions are:
- Where is that data processed?
- Who can access it?
- And could it be used to further train AI models?
For most major AI providers, the honest answers to these questions involve significant caveats. Data processing often occurs offshore. Assurances that client data will not be used for model training typically require specific enterprise agreements that many small and mid-sized software vendors do not hold on their customers’ behalf. And even where assurances are given, they are governed by the terms and conditions of offshore providers, which can change (and have changed) without notice.
For an Australian NFP holding sensitive client data, this is not an acceptable ambiguity. Your data must reside and be processed in Australia. Before adopting any AI-enabled tool, you need explicit, contractual assurances (not marketing claims) from both your software vendor and their underlying AI provider that:
- Client data is stored and processed in Australia
- Data is not used to train AI models
- Data handling complies with the Australian Privacy Act and any applicable state legislation
- You will be notified of any material changes to data handling practices
- In the event of a data breach, you will be notified promptly, and the vendor will cooperate fully with your obligations to report to the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme
- Access to client data is strictly limited. You must know exactly who within the vendor’s organisation (and any subcontractors or underlying AI providers) can access your data, under what circumstances, and with what controls
- Upon decommissioning the tool or ending the contract, all client data is deleted or returned in full, deletion is confirmed in writing, and no residual copies are retained by the vendor, their subcontractors, or any underlying AI model provider
- The vendor holds and maintains recognised security certifications appropriate to the sensitivity of the data being processed, at minimum, SOC 2 and/or ISO 27001. For vendors handling health or sensitive personal information, additional frameworks such as the Australian Government Information Security Manual (ISM) or Essential Eight compliance should be considered. Certifications should be current, independently audited, and available for your review on request
Most vendors cannot currently provide all these assurances. That is not a reason to reject AI for nonprofits categorically, but it is a reason to ask the questions hard, and to not accept vague commitments in place of specific ones.
⚠️You remain fully responsible
Choosing a software vendor with AI capability does not transfer your obligations to that vendor. Your organisation remains fully responsible for the services you deliver, the decisions made on behalf of your clients, and the safeguarding of their data. If an AI-generated care plan contains an error that leads to a poor outcome, the responsibility for that outcome rests with your organisation, not with the technology vendor.
This raises a fundamental question that every NFP evaluating AI tools needs to answer honestly: Will you trust the outcomes of the people in your care to an AI, or to a human? In some contexts (reducing documentation burden, accelerating low-risk triage, scheduling, routine reporting) the answer may be yes, with appropriate oversight. In others, the answer should be no, at least for now. These include:
- Complex risk assessment: where the consequences of underestimating risk are serious and potentially irreversible
- Child safety and protection: where mandatory reporting obligations, legal thresholds, and the stakes of a missed indicator demand human judgement and accountability
- Domestic and family violence: where safety planning, lethality assessment, and the unpredictable behaviour of perpetrators require nuanced, real-time human judgement that no current AI can reliably replicate
- Mental health crisis and suicide risk: where a misread signal or delayed response can have fatal consequences
- Time-critical triage: where the speed of human escalation, not automated processing, is what determines whether someone gets help in time
- Trauma-informed care planning: where the therapeutic relationship, cultural safety, and a worker’s read of a client’s emotional state are central to the outcome
- Safeguarding decisions: where decisions must be defensible, auditable, and made by an accountable human who can be held responsible for the outcome
Nobody is arguing that AI will fail every time, or even most of the time. The concern is far more targeted than that. In high-stakes human services contexts, the moments when AI gets it wrong are not recoverable with a software patch or a refund. The people on the receiving end are some of the most vulnerable people in our community – any failure will affect those with the least power, the least recourse, and the greatest need for someone to get it right. Within this context, a serious AI-related incident (a safeguarding failure, a data breach, a poor decision that causes harm) does not just affect the individual client. It can trigger a funding review, damage your reputation with referral partners and government funders, and directly affect your organisation’s ability to win future contracts and continue doing the work that matters.
Auditability and governance limitations
AI systems, particularly those based on large language models, are not fully explainable. When an AI recommends a particular triage outcome or drafts a case note, it cannot always tell you precisely why it made the choices it did. For human services (where decisions must be defensible, where funding bodies require evidence-based reporting, and where clients have rights to access and challenge records about them) AI’s lack of auditability is a material limitation.
Adopting AI tools also requires an update to your data governance policies. Your existing policies almost certainly do not cover AI-generated content, the use of client data as AI input, or the review and approval processes required before AI-generated documentation enters a client record. These gaps need to be addressed before you deploy AI, not after.
Government funding adds another layer of obligation
For Australian NFPs receiving Commonwealth or state government funding (which is the majority) the obligations extend further still. Both the Australian Government and NSW have introduced significant new requirements for AI governance, and these obligations flow directly to the organisations delivering government-funded services.
At the Commonwealth level, the Digital Transformation Agency (DTA) updated its Policy for the Responsible Use of AI in Government in December 2025. The updated policy mandates use-case-level impact assessments, strengthened accountability through designated accountable officials, and transparency statements for any AI that materially affects members of the public. Accompanying this, the DTA published Guidance on AI Procurement in Government and AI Model Clauses (v2.0) requiring suppliers to demonstrate alignment with Australia’s AI Ethics Principles, provide explainability for decisions affecting individuals, and enable audit and oversight by the contracting agency.
In NSW, the NSW AI Assessment Framework (AIAF) is mandatory for all NSW Government agencies under Circular DCS-2024-04, covering the design, development, deployment, procurement, and use of any AI system across its full lifecycle. High- or critical-risk AI systems must be reviewed by the NSW AI Review Committee. For NFPs delivering services under NSW Government funding contracts, compliance with the AIAF and the NSW AI Ethics Policy is an increasingly explicit expectation. The NSW Government’s AI Procurement Essentials guidance further requires that buying teams assess AI-related risks across the full procurement lifecycle, and suppliers must be able to satisfy those assessments.
Both jurisdictions are moving in the same direction: if you are delivering government-funded services using AI tooling, you will increasingly be expected to demonstrate how that AI is governed, how decisions are audited, and how client data is protected. Vendors who cannot satisfy these requirements are likely to be excluded from future procurement arrangements.
This is not a distant concern. It is the regulatory direction of travel, right now.
What you must do before adopting AI for nonprofit tooling
If you are an Australian NFP evaluating AI-enabled tools, the following are non-negotiable starting points:
- Map your privacy obligations across jurisdictions. If you operate across states, or receive both Commonwealth and state funding, you may be subject to multiple overlapping privacy frameworks. Know which apply to you before evaluating any tool.
- Develop an AI policy. Define approved uses, prohibited uses, staff obligations, review processes, and escalation procedures. Without one, usage will be inconsistent and your exposure will be difficult to manage.
- Establish AI governance. Assign clear accountability for AI decisions within your organisation; someone must own the risk, monitor usage, and be the escalation point for incidents. This is increasingly expected by government funders.
- Review your data governance policies. Update them to address AI-generated content, AI inputs, and the review processes required before AI outputs enter client records.
- Scrutinise your vendor in writing, not in conversation. Before signing anything, require contractual assurances that: client data is stored and processed in Australia; data is not used to train AI models; handling complies with the Privacy Act and applicable state/commonwealth legislation; you will be notified of any material changes to data practices; access to client data is strictly limited and documented (including any subcontractors or underlying AI providers); in the event of a breach the vendor will notify you promptly and cooperate with your obligations under the Notifiable Data Breaches scheme; and upon decommissioning, all data is deleted and confirmed in writing. Vendors should hold current, independently audited certifications, at minimum SOC 2 and/or ISO 27001.
- Understand your vendor’s technology stack. Many software vendors are themselves dependent on third-party AI providers. Ask who they are, where they are headquartered, and what data processing agreements are in place. The chain of accountability matters.
- Check your funding agreements. Do your current funding agreements restrict how client data can be processed? Government funding agreements increasingly do, and non-compliance can put your funding at risk.
- Assess auditability. Can decisions or outputs generated by the AI be explained and defended to a funding body, a client, or a regulator? If not, reconsider the use case.
- Train your staff. Workers using AI tools need to understand what they are doing, what the limitations are, and when human judgement must override an AI output.
Looking to the future
The long-term trajectory for AI in the nonprofit sector is genuinely positive. The technology will continue to improve. Data sovereignty options will expand as Australian hyperscalers and sovereign cloud providers build more capable AI infrastructure domestically. Regulatory frameworks will mature, making it easier to evaluate vendors against clear, enforceable standards. And as AI tools accumulate track records in human services contexts (including the failures and learnings that come with them) organisations will be better placed to deploy them with confidence.
The most likely near-term settlement is a tiered model: AI handling well-defined, lower-risk, administrative tasks (transcription, documentation drafting, scheduling, routine reporting) under human review, while complex decisions, risk assessments, and direct client interactions remain firmly with trained human workers. This is not a compromise, it is the appropriate design for this context.
What we caution against is the rush to adopt AI because it appears inevitable, or because a software vendor has made it easy to turn on. The organisations that will navigate this transition well are those that ask hard questions before they act, that ground their decisions in their obligations to clients rather than in marketing narratives, and that build the internal governance structures to use AI responsibly before they use it at all.
The promise of AI for nonprofits is real. So are the risks. The difference between an organisation that benefits from AI and one that is harmed by it will largely come down to how honestly and rigorously it has examined both.
SmarterSoft is a 100% Australian-owned software company specialising in client, case, and data management systems for Australian nonprofits and government agencies. Our platform is hosted entirely within Australia on AWS Sydney, and we are committed to data sovereignty, privacy compliance, and responsible technology adoption. To discuss how AI considerations affect your organisation’s technology decisions, contact our team.