Arrow icon
Back to Insights

AI Usage - Nonprofit Possibilities and Pitfalls

What’s a Rich Text element?

The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.

  • Lorem ipsum dolor sit amet
  • Lorem ipsum dolor sit amet
  1. Lorem ipsum dolor sit amet
  2. Lorem ipsum dolor sit amet

Static and dynamic content editing

A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!

How to customize formatting for each rich text

Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.

When and how should nonprofits use AI? Consider the following scenario. A nonprofit executive director has been working to safeguard children participating in its highly successful summer day camp program. To better track the comings and goings of several hundred youth, the ED approves a new facial-recognition check-in system. Later that day, the ED then hears an intriguing pitch from a hiring company promising significantly improved outcomes in identifying the best qualified job applicants by using an AI screening tool. By month’s end, the nonprofit may be both collecting regulated biometric information and relying on automated decision-making in ways that create significant privacy and compliance implications.

Many nonprofits are similarly using AI for biometric data and automated decision-making for their program activities and their employment practices (or they may soon!). The rise of artificial intelligence (AI) has been a boon for many industries, from tech to marketing to law. AI usage can also provide valuable tools for nonprofit organizations, to advance their missions in a more efficient manner. However, AI can also be fraught with unintended legal consequences for nonprofit organizations that do not keep up with legal compliance developments.

Nonprofits considering AI usage should assess both legal and operational risks before implementation for biometric data and automated decision-making, not after a problem arises. This article addresses relevant legal developments and provides key recommendations. This article also addresses accompanying best practices for careful vendor review, appropriate notices and consents, privacy protection, and meaningful human oversight – all to help nonprofits benefit from these tools while protecting their employees, participants, and communities.

Biometrics and Privacy Rights

What are biometrics and how are they used? The use of biometric data in the development of AI models and related applications has become a powerful tool for businesses and nonprofits alike. Biometric data refers to unique biological traits, for example, facial geometry, fingerprints, voiceprints, or iris scans that can be used to identify a person. Like certain other sensitive personal information, a person’s biometric features are unique to that person. But when AI systems analyze these biometric traits, they raise special privacy concerns.

One of the primary issues here is the collection and use of biometric information without clear and informed consent from data subjects. Many AI systems, especially those used for facial recognition, collect sensitive biometric data automatically and often without individuals realizing it. States like Illinois and Texas have passed laws specifically addressing this issue, requiring informed consent before biometric data collection, imposing restrictions on how long data can be stored, and prohibiting the sale of biometric identifiers.

Developing Biometric Laws and Enforcement

Illinois’s Biometric Information Privacy Act (BIPA) is among the most stringent of these regulatory measures, creating a cause of action for individuals to sue directly for violations and imposing statutory damages for each incident of non-consensual use. Several lawsuits have already been brought against major corporations under BIPA for failing to obtain informed consent from biometric data subjects, resulting in some stunning settlements including $650 million from Facebook in 2021, $100 million from Google in 2022, $92 million from TikTok in 2022, and $228 million from BNSF Railway in 2023.

In Texas, claims brought under the Capture or Use of Biometric Identifier Act (CUBI) and related legislation have resulted in even more staggering settlements: $1.4 billion from Facebook in 2024 for its collection, use, and sharing of users’ facial geometry in its “Tag Suggestions” feature, and an approximately $1.4 billion settlement from Google for collecting facial geometry and other data through Google Photos and other applications.

While the legislation in some states, like Texas, limits its application to collection of biometric data for commercial purposes, Illinois does not include this limitation, thus necessitating an additional degree of caution for nonprofits that may be collecting such data. These risks are heightened by the specter of algorithmic disgorgement, an equitable remedy that has been requested in some of these cases. If granted, the remedy of algorithmic disgorgement requires data collectors not only to delete improperly collected biometric data, but also to destroy AI models developed using such data as “fruit of the poisonous tree.”

Biometrics and Children – Special Cautions

The use of biometrics with children adds another layer of legal (and ethical) concern. Biometric data involving minors – who are inherently limited in giving “informed consent” – triggers a heightened risk of statutory violations. For example, under Colorado Senate Bill 24-041 (Privacy Protections for Children’s Online Data), enacted in 2024 as an amendment to the Colorado Privacy Act, collection of biometric data from a child under the age of 13 requires consent from the child’s parent or guardian. This legislation went into effect in 2025 and follows the general trend among American states developing child-specific rules in the area of data privacy.

Takeaways for Nonprofits Using Biometrics

Considering these growing risks, how can nonprofits that want to leverage recent advances in AI, including collection or other use of biometric data, protect themselves? Nonprofits currently collecting (or considering collecting) biometric data can take the following steps:

1. Assess the need for biometric data collection. Given the potential for extensive liability in this area, nonprofits should evaluate whether they really need to collect biometric data in the first place, considering potential alternatives and continuing use of biometric systems only where it presents a clear operational benefit.

2. Obtain informed written consent before collection. Nonprofits collecting biometric data should implement a compliant consent process, including (1) prior written notice explaining what biometric data will be collected, why it is collected, and how long it will be stored and (2) prior written consent from the data subject, or from the data subject’s parent or guardian as may be required.

3. Update online privacy policies and terms of use. Online privacy policies and terms of use should be expanded to address the nonprofit’s collection, use, sharing, and deletion of biometric data. This may include relevant updates to the nonprofit’s data retention and destruction policy to ensure compliant timeframes for biometric data deletion.

4. Implement effective data security protocols. Considering that biometric data is treated as sensitive information under many regulatory schemes, nonprofits should take great care to ensure that such data is carefully protected against unauthorized access or leaks.

5. Ensure compliance from third-party vendors and partners. Any third-party vendors or partners who will have access to the nonprofit’s stored or shared biometric data should be carefully vetted, contractually obligated, and regularly monitored to ensure their compliance with applicable privacy laws.
 
6. Review applicable data privacy laws and monitor new developments. As this is an area of rapidly expanding regulation, nonprofits should obtain qualified legal counsel, review all applicable regulatory schemes, and watch for amendments to existing laws and the passing of new legislation. When new requirements are identified, the nonprofit’s systems and operations should be updated accordingly as soon as possible, and all personnel should be trained in current compliant procedures.

Automated Decision-Making Technology

What is automated decision-making technology (ADMT) and how is it used? ADMT is now used in numerous areas affecting nonprofit work and operations, ranging from education to employment hiring, and several states have already passed laws to regulate such use. For example, under a recent amendment to the Illinois Human Rights Act, it is now a civil rights violation for an employer to use artificial intelligence in employment-related decisions (e.g., hiring, promotion, discharge, discipline, etc.) that has the effect of subjecting employees to discrimination on the basis of protected classes or to use zip codes as a proxy for protected classes. Additionally, under this amendment, employers must now provide notice to an employee that it is using artificial intelligence to make an employment-related decision. See our related W&O blog at “AI Usage in Employment Decisions.”
 
While employment-related AI usage may streamline decision-making process (i.e., deciding to hire a candidate partly based on ADMT), it also involves potential risks for nonprofit organizations. Legally speaking, job applicants and other individuals who are the subject of the decision being made may object and claim discrimination or lack of legally required notice. Multi-state compliance may prove challenging (e.g., job postings provided online for multi-state usage), as state laws continue to evolve. Practically too an organization may miss out on excellent job candidates through screening processes using ADMT.

State Laws Affecting ADMT

California and Colorado are two examples of a broader state trend regulating automated decision-making. Notably, certain California requirements per the California Consumer Privacy Act may not apply to many nonprofits, since its statutory language strictly applies to “businesses,” and Colorado does not include any general nonprofit exemption. Other states such Connecticut, Delaware, Illinois, Maryland, Minnesota, Oregon, Texas, and Virginia, also regulate profiling used to make decisions with legal or similarly significant effects. Because the California regulations provide a particularly detailed framework for notice, risk assessment, individual rights, and human review, with an expanded view here regarding “businesses” that may include nonprofits in certain contexts. Nonprofits should additionally evaluate each law that may apply to their operations.

Focusing on California law against the backdrop of potential safeguards, businesses using ADMT to make “significant decisions” must satisfy certain legal requirements by by January 1, 2027. Art. 11, § 7200. A “significant decision” is one “that results in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services.” Art. 1, § 7001(ddd). The regulations define “automated decision-making technology” as “any technology that processes personal information and uses computation to replace human decision-making or substantially replace human decision-making.” Art. 1, § 7001(e). The regulations require prominently and conspicuously giving consumers a pre-use notice informing them of (1) the organization’s use of ADMT, including uses for significant decisions, (2) the consumer’s right to access the organization’s ADMT and how the consumer may submit a request to access ADMT, (3) the consumer’s right to opt out. Additionally, businesses must perform a “risk assessment” if their processing of personal information “presents significant risk to consumers’ privacy,” including use of ADMT for significant decisions concerning consumers. Art. 10, § 7150. A risk assessment involves determining whether the consumer privacy risks from processing personal information are greater than the benefits.

Takeaways for Nonprofits using ADMT

Nonprofits using ADMT for significant decisions should take practical steps now. The California framework provides a sound best practice and importantly positions a nonprofit to comply with states like Colorado, which does not provide an exemption for nonprofits. Further, compliance promotes fair and explainable decisions, protects public trust, and prepares the organization for expanding regulation. Accordingly, nonprofits using ADMT should take the following steps:
 
1. Identify each use of ADMT that may affect an individual’s access to employment, education, healthcare, financial assistance, or other important opportunities.
2. Assess the risks before implementation, including possible discrimination, inaccurate results, privacy concerns, and unintended consequences.
3. Provide clear notice when ADMT will materially influence a decision and update employee policies/handbook regarding same.
4. Preserve meaningful human review by giving a qualified person authority to reconsider and overturn an automated result.
5. Require vendors to explain how the technology operates and to provide information needed for compliance and oversight.
6. Reevaluate the technology whenever its data, purpose, operation, or potential impact materially changes.

Onward in the Age of AI

Proactive use of biometric and ADMT AI based tools may significantly help nonprofits advance their missions. But since AI tools require great care from the start, nonprofit leaders should first ask whether their nonprofit needs the technology at all. Nonprofit leaders should carefully evaluate vendors and their tools and learn how the tool works. Applicable notice and consent may be required. Audit and other human review should be used, especially when a decision affects a person’s job, education, health care, or access to services. The organization should also revisit systems as the legal developments continue and technologies keep evolving, seemingly faster every day. Focusing on compliance, evaluating steps needed, and implementing them should help position nonprofit leaders to use AI tools responsibly and well.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.