A case manager pastes her notes into a free AI tool to save ten minutes. A network holds together for years on a patchwork of fixes nobody wrote down. A backup runs every night and nobody has ever tried restoring from it.

IT readiness for a nonprofit comes down to three plain questions: do you know where AI is already being used, what would it cost to fix your technology now versus later, and could you actually prove your organization is secure if someone asked. None of these show up on a routine risk report. They just sit there quietly, until the day they don’t.

Steve Hart, President of Advantage Microsystems, has spent more than a decade inside California behavioral health and child welfare organizations. He says the same three gaps come up almost everywhere he looks, regardless of an organization’s size or budget. Here’s what he tells leaders to check.

AI Policy for Nonprofits: Do You Know Where It’s Already Being Used?

Somewhere in your organization, someone has probably already used AI to help with a task. A summary, a draft, a first pass at something they were behind on. Leadership usually finds out after the fact, if at all.

That’s a common pattern, not a rare one. According to IBM’s Cost of a Data Breach Report 2025, one in five organizations that experienced a breach traced it back to unauthorized AI tool use, and that exposure added an average of $670,000 to the cost when it happened. The figure comes from a limited sample of surveyed organizations globally, so treat it as a signal rather than a universal rate. Still, the direction matches what Hart sees directly in client work: staff adopting tools faster than leadership can track them.

The instinct to ban AI outright rarely works. Staff keep using the tools anyway, just more quietly, which is worse than knowing about it. A short policy does more good than a prohibition. At minimum, Hart tells clients it should cover:

  • Which tools are approved for use
  • What data should never go into them: client records, PHI, anything confidential
  • Who staff should ask when they’re not sure

That’s a document most organizations can draft in an afternoon.

Technology Transformation for Behavioral Health Organizations: What Would the Fix Cost You Today, Versus Later?

Hart has walked multiple California Alliance member organizations through this exact question. Two, in particular, arrived at it from opposite directions. One was losing hours every week to a network that crashed mid-shift. The other had no documentation of its own systems at all, just a growing sense that something wasn’t right.

Both waited. Neither had a large budget for the fix when they finally made it. What changed wasn’t money. It was sequencing:

  1. Stabilize what’s already there
  2. Modernize what sits on top of it
  3. Bring in anything new, including AI, only once the first two are solid

Deferring a decision doesn’t make it smaller. It moves the cost further out.

Security Gaps in Child Welfare Organizations: Could You Prove You’re Secure?

Most organizations believe they’re reasonably secure. Belief and proof are different things, and Hart says the gap between them tends to be invisible until an incident, an audit, or a funder’s questionnaire forces it open.

A few honest checks he recommends starting with:

  • Do former employees still have working logins anywhere?
  • Has anyone actually tried restoring from a backup, or just assumed it would work?
  • Is there a written incident response plan, or just an informal sense of who’d probably handle it?
  • Is there a signed data agreement with every vendor that touches client information, not just the obvious ones?

None of these require a large security budget to start. They require someone to actually look.

Where the Three Questions Meet

These aren’t three separate problems. They’re one pattern Hart describes the same way across almost every organization he’s worked with: technology decisions get deferred because there’s always something more urgent. Getting ahead of it starts with a plain, honest look at where things actually stand.

Hart is covering all three in more depth this August at Stronger Together 2026, the California Alliance of Child and Family Services conference in Anaheim, August 31 through September 3, across three separate sessions. If you’re there, it’s worth finding them on the agenda.

If you’d rather start now: https://advantagemicro.net/would-you-know-breach-assessment/

Questions About AI Governance for Nonprofits: Answered by Advantage Microsystems

Q: How do I know if staff are already using AI tools at my organization?

Ask directly, without framing it as an accusation. Most staff who use AI tools informally are trying to keep up with their workload, not cutting corners. A short conversation usually surfaces more than a formal audit would, and it opens the door to building a policy together instead of after the fact.

Q: What should an AI policy for a small nonprofit actually include?

At minimum, a list of approved tools, a clear statement of what data should never be entered into them, and a named person staff can ask when they’re unsure. It doesn’t need to be long to be effective.

Q: How do we know if our organization has outgrown its current IT setup?

Common signs include recurring outages staff have learned to work around, no documented map of your own systems, and technology decisions that get made reactively rather than planned for. If any of that sounds familiar, it’s usually cheaper to address now than later.

Q:What’s the fastest way to check our organization’s security without a big budget?

Start with what doesn’t cost anything: confirm former employees’ access has actually been removed, test whether a backup can really be restored, and check whether you have a written incident response plan. Those three checks alone surface most of the common gaps.

Q: How can I work with Advantage Microsystems on any of this?

Start with a Breach Assessment at https://advantagemicro.net/would-you-know-breach-assessment/, or connect with Steve Hart at Stronger Together 2026 in Anaheim this August.

Leave a Reply

Your email address will not be published. Required fields are marked *