Safe Copilot adoption: What responsible AI use looks like for not-for-profits


Published: 

Microsoft Copilot is gaining traction across the not-for-profit (NFP) sector, offering appealing benefits: reduced administrative effort, more consistent documentation, and better use of limited capacity.  

However, these benefits are not automatic. Without clear governance, AI tools can introduce privacy, compliance and trust risks, particularly in environments managing sensitive client and beneficiary information.  

In practice, success depends less on the technology itself and more on how AI is governed, configured and used, and whether leaders have a clear understanding of what responsible use looks like. 

AI security is necessary, but AI governance is essential   

A common question Boards ask is whether AI tools are ‘secure by default’. While security features and vendor assurances matter, they are only part of the picture.  

Security controls can help protect systems. They do not, on their own, determine how information is used or shared day-to-day, particularly when staff are encouraged to use AI to move faster.   

From a regulatory and governance perspective, the more important questions are:  

  • What information can AI access?  
  • How are staff expected to use it?  
  • What checks exist to prevent oversharing?  
  • Can usage be reviewed, explained and, if needed, stopped?  

These are governance questions, not technical ones. They go to accountability, behaviour and oversight, and ultimately to whether an organisation can demonstrate responsible stewardship of information if something goes wrong.   

Privacy and AI: what regulators expect organisations to understand  

Australian privacy law is technology neutral. The Privacy Act applies whether information is processed manually, through traditional systems, or via AI tools. Recent regulator commentary has made clear that ‘new technology’ will not be accepted as an excuse for weak privacy practices.   

The Office of the Australian Information Commissioner (OAIC) has highlighted several principles that are particularly relevant to Copilot‑style tools:  

  • Personal information entered into an AI system remains subject to the Australian Privacy Principles  
  • AI‑generated output can itself be personal information, even if it is inferred or inaccurate  
  • Organisations must ensure AI tools are suitable for their intended use and supported by appropriate privacy governance  
  • Privacy notices and policies should clearly explain how AI is used, particularly where tools interact directly with clients, members or the public.  

AI does not create a new privacy regime. It does, however, increase the importance of existing obligations.  

Why AI use creates governance obligations under ACNC standards  

Under the Australian Charities and Not-for-profits Commission (ACNC) Governance Standards, charities and NFPs must operate lawfully and be run in an accountable and responsible way. Governance Standard 5 requires Responsible People to act with reasonable care and diligence and not misuse information gained through their role.  

AI tools accelerate access to information. Without clear boundaries, they can unintentionally enable misuse of information, even where staff are acting in good faith.  

This creates a responsibility for boards and executives to ensure AI use is deliberate, documented and overseen.  

A clear, staged approach to safe Copilot adoption  

A practical approach for NFPs involves four stages. 

Stage one: Define acceptable use  

Before focusing on configuration, organisations should define how AI may and may not be used.  

This includes:  

  • What categories of information should never be entered into AI tools (for example, detailed client records, health information or sensitive case notes)  
  • Which use cases are acceptable (such as drafting, summarisation or internal analysis)  
  • Where human review is required before outputs are used or shared.  

Documenting acceptable use aligns directly with privacy transparency requirements and sets clear expectations for staff. Clear boundaries also give staff confidence to use AI appropriately, rather than avoiding it altogether or using it in risky ways.   

Stage two: Align access and permissions  

Copilot works within existing permissions. If staff already have access to more information than they need, AI will inherit and amplify that access.  

At this stage, organisations should:  

  • Review access to shared drives, document libraries and group mailboxes  
  • Remove legacy permissions that no longer reflect current roles  
  • Ensure sensitive repositories have restricted access and clear ownership.  

This helps meet Privacy Act expectations around taking reasonable steps to protect personal information.  

Stage three: Enable monitoring and accountability  

Responsible AI use requires visibility.  

Organisations should be able to:  

  • Identify patterns of AI use  
  • Detect potentially risky behaviour (such as repeated use with sensitive content)  
  • Reconstruct decisions or outputs where concerns arise.  

This visibility supports expectations around accountability, transparency and the ability to investigate concerns when they arise. 

The ability to understand what happened, when and why is critical if an organisation needs to respond to a complaint, regulator inquiry or internal concern.    

Stage four: Embed oversight and review  

AI governance should sit within existing structures, not alongside them.   

Boards and executives should:  

  • Include AI use within risk registers  
  • Periodically review acceptable use boundaries  
  • Ensure third‑party arrangements clearly define responsibility for data handling.  

This approach aligns governance effort with organisational size, activities and risk profile, as expected under ACNC standards.   

How Australia’s AI guidance applies in practice  

Australia’s AI Ethics Principles emphasise privacy protection, human oversight, transparency and accountability. While voluntary, they strongly influence regulator and community expectations.  

The Australian Government’s Guidance on AI adoption positions responsible AI as an ongoing governance discipline. It encourages organisations to:  

  • Allocate accountability for AI use  
  • Understand and assess impacts  
  • Manage AI risks like any other business risk  
  • Maintain human control over decisions.  

AI should be introduced in a way that reflects the organisation's risk profile, obligations and intended use, rather than simply because the technology is available. 

Why measured adoption builds confidence  

Safe Copilot adoption is not about restricting innovation. It is about enabling useful, low risk use while protecting sensitive information and preserving trust.  

Not‑for‑profits that define clear boundaries, align permissions, monitor use and embed oversight are better placed to demonstrate responsible stewardship, both to regulators, funders, and the communities they serve.  

How BDO can assist  

NFPs are increasingly interested in Microsoft Copilot, but many recognise introducing AI without governance can amplify privacy and trust risks rather than reduce workload.  

BDO’s not-for-profit and cyber security teams support NFPs to adopt Copilot in a way that is safe, governed and aligned with regulatory expectations. Our support often includes:  

  • Education sessions for boards, executives and staff on responsible AI use and privacy obligations   
  • Designing acceptable use frameworks tailored to not‑for‑profit operating models  
  • Assessing and remediating access and permission risks so Copilot reflects current roles, not historical oversharing  
  • Supporting technical readiness for Microsoft Copilot, including configuration, access controls and integration with existing Microsoft 365 environments  
  • Implementing Microsoft Purview controls to support visibility and governance over data used with Copilot.   

Our focus is on ensuring Copilot adoption reflects organisational intent and governance, not just licensing availability.  

If you would like to discuss a measured approach to Copilot adoption in your organisation, contact our cyber security, data advisory, and not-for-profit teams.  

Key takeaways

Responsible AI starts with governance, not technology
  • The success of Copilot adoption depends less on security features and more on clear governance, accountability and oversight. Organisations need to define how AI can be used, what information it can access and how risks will be managed.
AI increases the importance of existing privacy obligations
  • AI does not create a new privacy regime, but it heightens the need for strong privacy practices. NFPs must ensure personal information remains protected, AI usage is appropriately governed and privacy obligations are reflected in policies, processes and day-to-day operations.
Measured adoption builds trust and reduces risk
  • NFPs that establish acceptable use boundaries, align permissions, monitor activity and embed AI oversight into existing governance structures are better positioned to realise AI benefits while maintaining trust with regulators, funders and the communities they serve.

Subscribe to receive the latest insights.

Authors