top of page

No, REALLY: Fundraisers Need to Pay Attention to AI Legislation

Writer: T. Clay Buck
T. Clay Buck
2 days ago
5 min read

I am trying very hard not to start this with “I told you so.”


So I won’t.


Mostly.


I have, however, been ranting for years about data privacy, security, regulation and compliance in fundraising. We are entrusted with an extraordinary amount of information about the people who support our organizations, much of it deeply personal, and we still struggle with some of the basics. (For the love of all things Panas, STOP EMAILING YOUR DONOR DATA LISTS.)

Now AI has arrived and the stakes are getting higher.

For the last few years, much of the conversation around AI has been some variation of adapt or die: learn the tools, experiment, integrate AI into your work or risk being left behind. Fine. There's truth in that, and I'm certainly not arguing that fundraisers should run screaming from AI.

But that conversation is no longer enough because AI adoption isn't happening in a regulatory vacuum anymore. Regulation and compliance are here, and fundraisers need to start paying attention.

California just gave us another signal


On September 16, California Governor Gavin Newsom signed SB 1050, legislation requiring disclosure when certain advertisements prominently feature AI-generated synthetic performers. The law requires clear and conspicuous language telling audiences, in substance, that the performance features a synthetic performer or that no human performer is depicted. You may remember I posted this about New York's synthetic performer law just a couple of weeks prior.



(Sorry. Couldn't resist. But I know nobody likes a show-off.)


California isn't banning synthetic performers; it's saying people deserve to know when the human being they think they're seeing isn't actually a human being.


Before we race toward the question I know fundraisers are going to ask — does this apply to nonprofits? — I think there's a more important question.


The statute is written within California's advertising framework, and whether a particular nonprofit fundraising communication falls within its requirements is a question for appropriate legal and compliance counsel. That's an important distinction and I'm not suggesting otherwise.


But your donors don't care where the statute stops.


They care whether they can trust what they're seeing.


I've been telling fundraisers to watch what's happening in AI regulation not simply because we need to know which laws apply to us, but because the emerging regulatory environment is also telling us something about the emerging expectations of the people we're communicating with.


A law may stop at the boundary of its jurisdiction. An expectation doesn't.


Once people become accustomed to disclosures telling them that the person they're seeing isn't real, we've also taught them to wonder whether the next person they see is real. We've introduced the question.


We've already watched a wonderfully ridiculous version of this happen with writing. The em dash and Oxford comma, perfectly ordinary tools that human writers used for a very long time before ChatGPT wandered into our lives, have somehow become popularly identified as "AI tells."


Now perfectly capable human writers are changing how they write because they're worried someone will assume a machine wrote it.


Whether those things are actually reliable indicators of AI is almost beside the point.


Suspicion changed behavior: Images are next.


A donor encounters a beautiful photograph of a beneficiary and now there's another possibility available to them: Is that person real? The perfectly lit volunteer, the emotionally compelling portrait accompanying an appeal, the image of people supposedly doing the work — are we looking at documentation of something that actually happened or something generated because someone needed an image?


And here's the problem: organizations using real photographs of real human beings telling real stories inherit some of that uncertainty, too.


That's not merely an AI problem. It's a trust problem.


We've been here before. Sort of.


Privacy, data security, consent, payment security, vendor management and data sharing aren't particularly sexy fundraising topics, but they're part of responsible practice. AI doesn't make any of those obligations disappear; instead, it adds another layer of questions on top of responsibilities we haven't exactly mastered yet.


We're putting information into AI systems. Sometimes that information belongs to donors. Sometimes it belongs to beneficiaries, volunteers or staff. We're using AI to generate and alter content, analyze behavior and make recommendations. We're beginning to automate decisions and interactions that previously required a human being.


That means fundraisers need to understand where information goes, what permissions we've granted, what might be retained and how vendors use it. We need to think about when synthetic content should be disclosed, what representations we're making about actual people and communities and who's accountable when an automated system gets something wrong.


These aren't questions for some theoretical AI future. They're operational questions today.


And this is where I think Responsible Fundraising has to go further than asking whether we're legally required to do something.


Compliance matters enormously, but responsible practice also asks what a donor reasonably needs to know in order to understand the invitation we're making and make an informed choice about participating. That's simultaneously a question of transparency, agency and trust.


And then comes Agentic Giving


There's another reason I'm watching all of this so closely, and it's something I'm going to be writing a lot more about soon: Agentic Giving.


We've already seen glimpses of the environment that's developing. Platforms have created places where donors can discover and support nonprofits outside the organizations' own websites, sometimes controversially creating profiles and giving experiences that the nonprofits themselves didn't request or control.


Now we're adding AI agents to that ecosystem.


Imagine telling an AI agent, “I care about protecting marine wildlife in the Pacific Northwest. Find organizations doing effective work, help me figure out which ones align with what I care about and help me make a gift.”


There's a lot happening inside that seemingly simple request.


The donor may encounter your organization, learn about it, compare it with others and potentially make a decision to participate without ever entering the digital environment you've carefully constructed for them. An intermediary may be assembling the information, deciding which sources are credible, determining how your organization is represented and deciding what information about the donor travels in the other direction.


And we're not very far from agents moving beyond recommendation toward action.

That's where questions about privacy, security, disclosure, representation, consent and regulation get considerably more interesting. If an agent is acting on behalf of a donor while interacting with information supplied by or about a nonprofit, who is representing whom? What information is being exchanged, what did each party consent to and who is accountable when the representation is wrong?


Those are Agentic Giving questions, and I'm going to spend considerably more time with them.


But they're also why I think fundraisers need to pay attention to what's happening with regulation right now.


If platforms and AI agents increasingly mediate how people discover organizations, evaluate them and participate in their work, we can't wait until those systems become commonplace and then start asking what the rules are. Nor can we assume that a law has nothing to teach us simply because "nonprofit fundraising" doesn't appear explicitly in the statute.


The era of adapt or die isn't exactly over. It's just an increasingly inadequate way of thinking about what's happening.


Yes, adapt. Experiment. Learn the technology and figure out where it can make our work better.


But understand the conditions in which you're operating while you do it. Pay attention to privacy and security, disclosure and consent, regulation and compliance — not only because some of those things may be legally required, but because they're also telling us something about what the people we're asking to trust us may increasingly expect from us. And trust and giving go hand-in-hand. This isn't some arbitrary "data thing" that fundraisers can leave to IT, legal or the database folks while we get on with raising money. This IS part of raising money. It has real-world, immediate implications for whether people trust us enough to participate and, ultimately, how much money we can raise.


AI isn't coming. It's here.


And the rules are arriving with it.

 
 
 

Comments


bottom of page