The Unique Risks Facing Civic Organizations
Civic-space organizations, such as nonprofits, human-rights groups, community organizations, independent media, and activist networks, often have limited budgets and small teams. They frequently handle sensitive information about staff, partners, beneficiaries, witnesses, and at-risk communities. Protecting this information requires practical, risk-based measures rather than relying solely on expensive technology.
Create a Clear AI-Use Policy
Organizations should start by adopting a clear policy for safe AI use. This policy must specify approved tools and clearly state which information must never be uploaded. Staff should not enter case files, beneficiary details, testimonies, donor information, passwords, financial records, protection plans, or unpublished reports into public AI services without authorization. Whenever possible, teams should use approved accounts with proper privacy and administrative controls.
Strengthen Access Controls
Email, cloud storage, social media, websites, and financial platforms should be secured with multi-factor authentication. Administrator, finance, communications, and leadership accounts should be prioritized, as they are common targets for takeover. Access must be removed promptly when staff, consultants, or volunteers leave, and shared passwords should be avoided.
Verify Sensitive Requests
Civic organizations should establish a verification process for sensitive requests. Emails or voice messages appearing to come from executives, donors, partners, or colleagues should not be trusted automatically. Requests involving money, beneficiary data, travel, public statements, or urgent account changes must be confirmed through a known telephone number or another independent channel. This is especially important as AI can imitate writing styles, voices, and images.
Train Staff to Recognize Realistic Threats
Staff training should address realistic threats rather than technical theory. Teams need to recognize targeted phishing, fake social media profiles, deepfake content, fraudulent job or grant offers, and messages intended to create panic or urgency. Human-rights defenders should also be aware that attackers may use AI-generated content to discredit their work, expose identities, spread false allegations, or create confusion during sensitive incidents.
Limit and Secure Sensitive Data
Organizations should minimize the personal and sensitive data they collect and retain. Unneeded information should be securely deleted, while essential records must be encrypted and backed up. Access to protection-related data should be restricted by role, and sensitive files should not be stored on personal devices unless properly secured.
Restrict AI Tool Permissions and Require Human Oversight
AI tools used by civic organizations should have limited permissions and must not independently send messages, publish content, change records, or share documents. Human review is required before an AI system takes any action that could affect a person’s safety, reputation, privacy, funding, or legal position. Teams should keep records of significant AI-assisted decisions and verify generated information before publication.
Maintain an Incident-Response Plan
Every organization should maintain a basic incident-response plan. The plan must outline steps to take if an account is compromised, confidential data is exposed, a staff member is impersonated, or false content is circulated. It should identify responsible contacts, recovery steps, evidence-preservation procedures, and trusted communication channels. For civic organizations, digital security protects not only systems but also people, relationships, credibility, and the ability to operate safely.