Before You Paste That Into ChatGPT: A 5-Step AI Safety Check for NGOs
You don't need to ban AI. You need five habits, and one rule the whole team remembers.
Most data leaks in the AI era won't come from hackers. They'll come from a well-meaning staff member pasting a beneficiary's real details into a free AI tool to write a report faster.
It's easy to see why. The tools are genuinely useful, and the pressure to produce reports, proposals and summaries is real. But a public AI tool is not a private workspace. On free and personal accounts, what you type can be stored, reviewed or used to train the model, and often is. Once a name, a location or a health status leaves your control, you can't pull it back. For an organisation handling beneficiary, health or protection data, that's a safeguarding and donor-relationship problem, not just an IT one.
You don't have to ban AI to be safe. You need good practice, or "best" practice, as my old ITIL instructor used to put it. Here are five checks. If you can't answer "yes" to all five, you have a gap.
1. Can your team name what's sensitive?
Names, ID numbers, phone numbers, exact locations or GPS, photographs, health status (HIV, TB, pregnancy), and anything touching protection or GBV. If people can't recognise it, they can't protect it.
2. Do you strip personal data before you paste?
Replace real names with placeholders: [Beneficiary], [District]. Remove direct identifiers and keep the details generic. The AI still helps you write and structure. It doesn't need the real person for that.
3. Do you know what the tool does with what you type?
Free and personal accounts often keep what you enter, or use it for training. Are chat history and training turned off? Are you on an institutional tier or a personal login? If you're not sure, assume the worst.
4. Are you sharing the minimum, never whole records?
A de-identified extract, not the full case file or the beneficiary spreadsheet. Pasting an entire dataset is the single most common leak.
5. Does the whole team know one golden rule?
One line everyone can recite, for example: "If it's real, don't reveal." Plus one safe alternative the organisation approves. A one-line rule people remember is worth a thousand times more than a 20-page policy nobody reads.
Five yeses is a good baseline. Any "no" is a gap worth closing this week, because the cost of getting this wrong isn't a slow afternoon. It's a breach you have to report to a donor.
Where does your organisation actually stand?
These five checks cover one risk: what staff type into a tool. They don't tell you whether your Microsoft 365 environment, your access permissions or your approval process are ready for the AI your staff are already using.
The SafeAI Check is a free 25-question self-assessment for NGOs on Microsoft 365. It takes 5 to 7 minutes and returns an indicative maturity score out of 100, your weakest governance area, and three practical next actions.
The SafeAI Check is a self-reported diagnostic. It does not certify compliance, test your security, or make changes to your systems. Its job is to help you identify where deeper validation may be useful.
Leandro, Bizmedia. We help NGOs and mission-driven organisations on Microsoft 365 govern AI use without slowing down the work.
