Your portfolio is already using AI on data you fund. We assess it, write the rules, train the teams, and hand you one report on where the whole cohort stands — for less than funding it organisation by organisation.
In September 2025 the Center for Effective Philanthropy surveyed 451 nonprofit leaders and 215 foundation leaders. Three of its findings sit uncomfortably together.
Though only about 4% describe that use as systematic across the organisation.
The capability is being built inside foundations and not passed down to the organisations delivering the work.
Meanwhile AI questions are starting to appear in due diligence packs.
If you can answer all eight, you do not need us. If you cannot answer the first three, that is the programme — and the first one costs about four weeks to close.
Not how many report it — how many actually do. In the wider workforce roughly two-thirds have used AI at work believing it was not permitted, so self-reporting understates it everywhere it has been measured.
Around 88% of professionals have put work information into public chatbots, a third of them customer or beneficiary records. In your portfolio that data belongs to people your funding exists to protect.
Sector-wide the figure is about one in three, and most of those are prohibition lists rather than usable rules. You can ask this question of your portfolio today and the answer takes a week to gather.
Foundations are adding AI governance questions to due diligence. If a grantee cannot answer, you learn nothing about their risk — only about their paperwork.
Not evenly distributed. It sits wherever case data, health data or protection data meets a small organisation with no IT function. That is a short list and it is knowable.
Since 2 February 2025 organisations deploying AI in the EU must ensure demonstrable AI literacy proportionate to role, contractors included. Funding EU-facing activity can put that obligation inside your portfolio.
The honest sector answer is close to nothing: 81% of foundations report using AI internally, about 11% provide implementation support to nonprofits, and fewer than 20% of nonprofits say a funder has even discussed it with them.
Attendance is not evidence. A scored baseline and a re-score are, and they cost almost nothing extra once the assessment is running across the cohort.
Fixed price, fixed scope. Prices are for nonprofit and foundation clients and exclude VAT and travel.
It is a shared spine with per-organisation adaptation. Each grantee gets its own policy and its own cheatsheet, built on its own work — but it does not get four separate department labs the way a standalone Adoption engagement does.
For most grantees under 100 staff that is the right trade, because the binding constraint is having any approved rules and one usable page, not having four of them.
Where a grantee is larger or carries unusual risk — health data, protection casework, multi-country operations — we will say so in the Baseline report and recommend a standalone engagement for that organisation rather than stretching the cohort format over it.
Ten dimensions covering fluency, data protection, governance, workforce impact, internal politics and psychological safety — mapped to ISO/IEC 42001, the NIST AI Risk Management Framework and EU AI Act Article 4.
Permissions first, not prohibitions: permitted uses by role, red lines, a data classification table, disclosure rules and an escalation path.
Built from their real tasks. See a sample.
Policy, tool inventory, attendance record and two scores — the file a regulator, an auditor or their next funder asks to see.
Send the assessment to a single grantee and see what comes back. Or book thirty minutes and we will work through the eight questions against your actual portfolio.