Stephanie Snyder Frenier, senior vice president, Cyber Liability, Gallagher, discusses AI governance, liability exposures and practical steps nonprofits can take to manage risk.
Getting your Trinity Audio player ready...

Author: Stephanie Snyder Frenier

null

Artificial intelligence (AI) is increasingly shaping the nonprofit sector. Organizations are using AI to draft grant proposals, personalize donor outreach, streamline operations and support fundraising efforts.

While this helps teams achieve more with limited resources, as AI adoption accelerates, so do questions about accountability, data protection and oversight.

Nonprofits handle large volumes of sensitive donor, employee, volunteer and beneficiary data, which makes them particularly vulnerable to privacy breaches, cyber incidents and regulatory scrutiny.

As AI becomes embedded in everyday decision-making, it is no longer just a technology tool — it is also a governance, compliance and liability consideration.

We spoke with Stephanie Snyder Frenier, senior vice president, Cyber Liability, Gallagher, about the AI-related risks nonprofit leaders may be overlooking and the steps organizations can take to strengthen governance while supporting innovation.

Q: How well do nonprofit organizations understand the risks that come with AI?

AI helps nonprofit organizations do more with less. From drafting donor communications and automating administrative tasks to supporting finance, HR, legal and IT functions, AI not only boosts productivity but frees up staff to focus on mission-critical work.

Many nonprofits are still exploring AI's potential, while others have already woven it into daily operations, sometimes without fully understanding how extensively it is being used. Employees may independently turn to unsanctioned AI tools to save time, creating shadow AI, which can expose the organization to privacy, security and compliance risks.

Without clear visibility and governance, leaders may not know what data is being shared, how AI-generated content is being used or where liability could arise.

Successful AI adoption requires clear policies, employee training and ongoing oversight. The organizations most likely to realize AI's benefits are those that approach it as both an opportunity and an enterprise-wide risk.

Q. Beyond cybersecurity, what AI-related liability exposures are nonprofit leaders most likely to overlook?

Cybersecurity is important, but it's only one part of the AI risk equation. Many nonprofit leaders focus on data security while overlooking the legal, operational and reputational risks AI can create across the organization.

For example, AI is increasingly being used in hiring, employee communications and administrative decision-making. If flawed data influences outcomes, organizations could face discrimination claims, regulatory scrutiny and reputational damage.

Intellectual property is another emerging concern. As copyright and ownership rules around AI-generated content continue to evolve, nonprofits that publish AI-created materials without appropriate review could inadvertently infringe on third-party rights or create disputes over ownership.

Q: How does AI create new cybersecurity and privacy risks for nonprofits?

Nonprofits often manage sensitive donor, beneficiary, employee and financial information. Inputting confidential data into public AI tools without understanding how that information is stored, processed or used can lead to privacy violations, contractual issues and loss of trust.

At the same time, AI is making cyber threats more sophisticated. Threat actors are increasingly using AI to create phishing emails, deepfake voice messages and highly targeted social engineering attacks to deceive employees and exploit organizations more effectively.

Strong governance, employee training and clear AI-use policies are critical risk management tools.

Q: As AI becomes more integrated into daily operations, what does effective AI governance look like for a nonprofit?

It starts with accountability. If no one owns AI oversight, managing the associated risks becomes much more difficult. Every nonprofit needs an individual or cross-functional team responsible for governing AI use.

The next step is visibility. Organizations need to understand where AI is already being used. Many leaders are surprised to discover AI tools being adopted across communications, HR, finance and fundraising without formal oversight. Conducting an AI inventory helps identify use cases, data flows and potential risk exposures.

Organizations also need clear policies covering acceptable AI use, data handling requirements, approval processes and expectations for human review.

AI can enhance efficiency, but it does not replace human judgment. Any AI-generated content or recommendations need to be reviewed for accuracy, fairness and context, especially when they affect employees, volunteers, beneficiaries or donors.

Effective AI governance is not a one-time exercise. It requires regular review of policies, vendor relationships and controls. As AI use, risks and regulatory expectations continue to evolve, adaptation is key.

Q: Adoption of AI often starts with individual employees. How can nonprofits reduce the risks of well-intentioned AI use?

AI adoption often begins at the employee level, as staff and volunteers turn to these tools to work faster and more efficiently. Without clear guidance, even well-intentioned use can create privacy, compliance and reputational risks.

For nonprofits, stakeholder trust is critical. A flawed fundraising message, inaccurate content or biased recommendation can quickly undermine stakeholder confidence.

Data awareness is fundamental. Employees need to understand what information can be entered into AI tools and what needs to remain protected. Sensitive data belongs within approved AI environments.

Training also needs to reinforce that AI is an assistant, not a decision-maker. Human review remains essential, particularly for external communications, policy development and decisions that affect people.

Importantly, training needs to extend beyond employees to board members, contractors and volunteers, who may use AI tools or access organizational systems.

Clear expectations, practical guidance and ongoing education help translate AI policies into consistent day-to-day practices.

Q: Many nonprofits rely on third-party platforms that now include AI capabilities. What should organizations be asking their vendors?

Many nonprofits pay less attention to how their vendors are using AI. For example, AI is increasingly embedded in fundraising platforms, donor management systems, HR applications and other business tools, often without users fully realizing it.

Organizations, therefore, need to understand what data is being shared, how it is protected and whether it is being used to train AI models. Key questions to ask vendors include:

  • What data are you collecting, storing and processing?
  • How is data secured and is that data used to train AI models?
  • Who owns AI-generated outputs?
  • Do you have incident response plans in place?
  • What contractual protections and indemnification provisions are available?

Contracts also deserve scrutiny. It is important that nonprofits clearly understand how liability is allocated if an AI-related issue arises, whether it involves data breaches, intellectual property disputes or regulatory investigations.

As AI becomes embedded across the technology ecosystem, third-party risk extends beyond an organization's own systems. Effective governance means evaluating not only internal AI practices, but also those of the vendors entrusted with your organizational data.

Q: As AI-related risks continue to evolve, how should nonprofits think about insurance and contractual protection?

Insurance and contractual protections are best viewed as part of a broader AI risk management strategy.

Most commercial insurance policies are silent relative to AI coverage, so it is important to understand if and how AI-related exposures may be covered. Coverage can vary across coverage lines and AI-related sublimits and exclusions are being introduced.

The key is understanding where potential coverage gaps may exist. As AI adoption expands, nonprofits need to work with their insurance brokers to regularly review and align coverage with their evolving risk profile.

While insurance and contracts cannot eliminate AI risk, they can help organizations better manage and transfer financial exposure when incidents occur. An effective approach combines governance, vendor oversight, contractual protection and insurance coverage as part of a broader risk management strategy.

Q: What advice would you give to leaders to strengthen AI governance?

The first step is understanding how AI is already being used across the organization.

Many nonprofits are surprised to discover how quickly employees have adopted AI tools, often without formal oversight. Conducting an AI assessment can help identify where AI is being used, what data is being shared and where potential risks exist.

Organizations can then focus on establishing practical guardrails rather than limiting innovation. Key priorities include:

  • Establishing clear accountability for AI governance and oversight
  • Maintaining visibility into AI tools, applications and data use
  • Implementing safeguards for sensitive and confidential information
  • Conducting vendor, regulatory and insurance reviews
  • Ensuring appropriate human oversight of AI-generated outputs

The goal is not to slow innovation, but to support responsible AI adoption with appropriate safeguards.

Balancing innovation and oversight

AI has the potential to help nonprofits achieve more with limited resources, unlocking new efficiencies across fundraising, operations and stakeholder engagement.

Realizing those benefits depends on understanding where AI is being used, the ensuing risks and the safeguards needed to support responsible adoption.

Organizations that approach AI with clear governance, appropriate oversight and effective risk management will be better positioned to support their mission while at the same time protecting their people, data and reputation.

Author Information


Disclaimer

The information contained herein is offered as insurance Industry guidance and provided as an overview of current market risks and available coverages and is intended for discussion purposes only. This publication isn't intended to offer financial, tax, legal or client-specific insurance or risk management advice. General insurance descriptions contained herein don't include complete Insurance policy definitions, terms and/or conditions and should not be relied on for coverage interpretation. Actual insurance policies must always be consulted for full coverage details and analysis.

Gallagher publications may contain links to non-Gallagher websites that are created and controlled by other organizations. We claim no responsibility for the content of any linked website, or any link contained therein. The inclusion of any link doesn't imply endorsement by Gallagher, as we have no responsibility for information referenced in material owned and controlled by other parties. Gallagher strongly encourages you to review any separate terms of use and privacy policies governing use of these third-party websites and resources.

Insurance brokerage and related services provided by Arthur J. Gallagher Risk Management Services, LLC License Nos. IL 100292093 / CA 0D69293