BETA This site is in beta. Information is still being added and reviewed.
Workshop overview
5

Adopting AI at your agency

When staff sign into a personal or free AI account for agency work, no one controls whether client information is kept or used to train the vendor’s models. Adopting AI officially, through a nonprofit program, gives you central control, business terms that do not train on your content by default, and a signed data agreement.

Start activity

Count the accounts, then write the vendor questions

  1. Go around the room: which AI tools do people use for work, on whose account, and who pays.
  2. Put them on the board in three columns, personal free, personal paid, agency account, and circle every tool that has ever had client information typed into it.
  3. Write the ten questions your agency would have to ask a vendor before signing anything. Keep the list.

How many of the circled tools does your agency actually have an agreement with?

  • A personal or free login is invisible to the organization. No administrator set its privacy option, can see what was entered, or controls how long the vendor keeps it, so the agency cannot answer what happened to a client’s information.
  • On consumer tiers, the vendor may use what people type to improve its models unless that individual turned the setting off, and most people never open the setting. There is no administrator who can enforce that choice for the whole staff.
  • An official organizational account changes three things at once: an administrator sets the rules once for everyone, the paid business tier does not train on your content by default, and you can hold a signed data agreement.
  • The major tools state, as of early 2026, that their business, enterprise, and API tiers do not train on your content by default, and that organization data in a managed workspace is not used to train models. Confirm each on the vendor’s current page before you rely on it.
  • Nonprofit programs from OpenAI, Anthropic, Google, and Microsoft discount the paid organizational tiers, or in Google’s case include an AI-equipped workspace at no cost for eligible 501(c)(3) organizations, so the safer, controllable option is also the cheaper one for a qualifying nonprofit.
  • Prices, discounts, model names, and eligibility rules change constantly, and a single vendor’s own pages sometimes disagree. Treat any specific figure as something to re-check on the vendor’s page the day you enroll; the structure is what holds steady.
Why this matters (evidence)

The paid organizational tiers are built not to train on your content. Anthropic states that, by default, inputs and outputs from its commercial products are not used to train its models (Anthropic Privacy Center, 2026). Google states that an organization’s data in its managed workspace is not used to train or improve its models or for ad targeting (Google Workspace, 2026). OpenAI states that it does not train on business, enterprise, or API data by default and will sign a data processing agreement for those tiers (OpenAI Enterprise Privacy, 2026). These are the vendors’ own current statements about the paid tiers, and they change, so confirm them on the live page before you rely on one.

The governance risk is the personal account itself, not just the training default. Nonprofit-technology guidance is consistent that consumer generative-AI tools are not built to hold sensitive data, that staff should never enter personally identifying information, and that an agency needs a written AI-use policy with staff sign-off, aligned to its existing data-security rules (TechSoup, 2023). A separate nonprofit-sector guide adds that you should set a clear data and retention policy, define who may use AI and what gets approved, and document staff agreement before adopting a tool (Independent Sector, 2024). An official account is what lets an administrator, not each employee, hold those settings.

The line to hold

A personal account, or an official organizational account?

A personal or free account
  • No administrator set the privacy option or can see what was entered.
  • The vendor may use inputs to train its models unless that person opted out.
  • The data and history leave with the person if they go.
  • You cannot answer a client’s question about their own information.
A team or organization workspace
  • An administrator adds each staff member as their own seat and sets the rules once, for everyone.
  • The paid business tier does not train on your content by default.
  • You can hold a data processing agreement, and a BAA for health data.
  • Nonprofit programs make it discounted, or free on some tiers.
Never enter client or program data into a personal or free account. Agency AI use runs through an org-owned team workspace, where each staff member has their own seat under one administrator.
How to adopt

Five steps to adopt AI at your agency

  1. Get an organizational account, not personal logins. Decide as an agency that AI use happens through an org-owned account with an administrator, and that staff do not enter client or program data into personal or free accounts.
  2. Enroll in the vendor’s nonprofit program. Apply with your 501(c)(3) documentation and expect a third-party verification step. Check current eligibility, because some programs exclude government, higher education, or healthcare systems, and the rules change.
  3. Confirm the terms in writing before real data goes in. Read the vendor’s current data-use page, confirm your tier does not train on your content by default, learn how long data is kept, and request the data processing agreement (and a BAA if you handle protected health information).
  4. Set the admin controls. Have your administrator turn off any data-sharing or model-improvement options, set retention and access, and use any data-loss-prevention or access restrictions, so sensitive data is protected at the organization level and not left to each user.
  5. Write it into your acceptable-use policy. Name which tool and account staff may use, what may and may not be entered, that personal accounts are not allowed for agency data, and that a person reviews outputs before use. Have staff read and sign it.
Set it up

Each vendor’s nonprofit program

Each major vendor runs a nonprofit program that discounts its team or organization plan, where an administrator adds each staff member as their own seat under one set of rules. Eligibility is verified, often through a partner like Goodstack, and prices and terms change, so open the program page to confirm.

OpenAI ChatGPT Business / Enterprise

OpenAI for Nonprofits discounts ChatGPT Business and Enterprise for eligible 501(c)(3) organizations, verified through Goodstack. An admin invites staff as members; business data is not used to train the model by default.

OpenAI for Nonprofits
Anthropic Claude Team / Enterprise

Claude for Nonprofits discounts the Team and Enterprise plans for eligible nonprofits and adds sector data connectors. An admin adds members one at a time or in bulk; commercial inputs are not used to train the model by default.

Claude for Nonprofits
Google Workspace with Gemini

Google for Nonprofits includes Workspace with Gemini at no cost for eligible 501(c)(3) organizations, verified through Goodstack. An admin adds staff in the Admin console; org data is not used to train models.

Google for Nonprofits
Case study

From personal logins to an org account

  1. A small agency notices that three caseworkers have each been using their own free chatbot accounts, and one has been pasting in client names to speed up letters.
  2. The director realizes no one can see what was entered, how long the vendor keeps it, or whether it is being used to train the model, and that a client could not be told what happened to their information.
  3. The agency applies to a vendor’s nonprofit program with its 501(c)(3) paperwork, gets an organizational account, and confirms in writing that the business tier does not train on its content and that a data agreement is available.
  4. An administrator turns off data sharing, sets retention and access for everyone, and adds the tool to the acceptable-use policy: this account only, no client identifiers, a person reviews every output.
  5. The caseworkers stop using personal accounts. The same work gets done, but now the agency controls the data and can answer for it.
Try this

Map who is using what account now

As a group, list the AI tools your staff already use and whether each is a personal or free account or an organizational one. For any personal or free account being used for agency work, note what kind of information may have gone into it. Then decide one thing: which single organizational account your agency will move to, and who will own enrolling in the nonprofit program.

Practice together

Draft the account rule for your policy

Write the one paragraph that will go into your acceptable-use policy about accounts. Name the org-owned tool staff may use, state plainly that personal or free accounts are never used for client or program data, and name who to ask to get access. Keep it to a few sentences a busy person will actually follow, and add it to the ground-rules card.