Before You Adopt That AI Tool, Answer These Four Questions

Last week, I ran the same prompt through two different ChatGPT accounts. Both accounts belong to me. One is a free version I use occasionally for nonprofit-related work. The other is a paid account I have used every single day for four years, since it first launched.
The prompt was simple: "Create a caricature of me and my job based on everything you know about me."

The results were not simple at all. Two very different portraits came back, shaped by two very different amounts of context. The account that knows me well produced something layered and specific. The account that barely knows me produced something thinner, more generic, built from less material.

It was a fun experiment. But it also surfaced something I have been sitting with as I go deeper into my own study of AI governance: the amount an AI "knows" about you is not really a function of whether you paid for it. It is a function of how much you have fed it and how much you have thought about what you are feeding it.
That is the real conversation. Not free versus paid. Governance versus no governance.
Governance does not start with a policy
When people hear "AI governance," they often picture something heavy: a 50-page document, a legal team, a committee that meets quarterly to review compliance language nobody reads. That version of governance exists, and larger organizations may eventually need it. But it is not where governance begins.
Governance begins with a conversation. Specifically, four questions, asked honestly, before a tool gets adopted at all.
AI governance does not begin with a 50-page policy. It begins with clear answers about purpose, data, accountability, and review.
Here is what I mean by each one.
1. Purpose: What will we use it for?
This sounds obvious, and that is exactly why it gets skipped. Teams adopt AI tools because they are exciting, because a competitor is using one, or because someone saw a demo that looked impressive. Excitement is not a purpose.
A real purpose is specific. Are you using this tool to draft first-pass copy that a human will edit? To summarize meeting notes? To analyze data you already own? To generate ideas, you will vet before acting on any of them? The tool's purpose determines everything downstream of it: what data it needs access to, who should be using it, and what level of oversight the output requires.
Without a stated purpose, a tool tends to expand into whatever it is capable of doing, rather than staying inside what you actually need it to do. That expansion is where most of the risk lives.
2. Data: What information must never be entered?
This is the question my caricature experiment kept circling back to. The account that knew more about me knew more because, over four years, I had put more into it. Some of that was intentional and useful. Some of it, if I am honest, was information I was not thinking carefully about at the time.
Every AI tool has a data policy, and those policies vary widely; some train on your inputs, some do not, some retain data for a defined period, some retain it indefinitely unless you opt out. Very few people read these policies closely before they start typing. Fewer still revisit them as their usage deepens.
Before adopting a tool, decide in advance what categories of information are off-limits. Client names and financial details. Proprietary strategy documents. Anything covered by a confidentiality agreement. Personal information about people who have not consented to it being shared. Write the list down. Share it with your team. A boundary that only exists in your head is not a boundary your team can follow.
3. Accountability: Who approves and oversees its use?
In most small organizations and nonprofits I work with, AI tools get adopted the same way: one person discovers something useful, starts using it, and eventually other people notice and start using it too. There was no decision point. There was no one person who said yes, and there is no one person who can meaningfully say no.
That informal path works fine until something goes wrong, at which point everyone discovers there was no owner. Accountability means naming, in advance, who evaluates a new AI tool before it spreads through a team, who approves its use for specific purposes, and who is responsible when a question or a problem comes up.
This does not require a committee. In a small organization, it might be one person: you. But it needs to be a deliberate role, not a default that falls to whoever happened to start using the tool first.
4. Review: Which outputs require human verification?
AI-generated content can be confident and wrong at the same time. It can also be accurate and still miss the judgment, nuance, or relationship context that only a human carries. Either way, some categories of output need a human set of eyes before they go anywhere near a client, a donor, a board, or the public.
Decide in advance which outputs fall into that category. Anything with numbers attached. Anything going out under your organization's name. Anything involving a person's specific situation rather than general information. Anything you would be uncomfortable defending if someone asked, "did a human actually check this?"
Some outputs, like a first draft of a blog post you plan to heavily edit anyway, may not need the same level of scrutiny. Knowing the difference in advance, rather than deciding in the moment, is what keeps review from becoming an afterthought.
Human at the heart
I do not love the phrase "human in the loop." It suggests the human is one step in a process that the AI is otherwise running on its own. What I have come to believe, the more I study this, is that the human has to be at the heart of it. Not a checkpoint. The center.
That is true of the caricature prompt that started this whole line of thinking, and it is true of every AI tool your organization will consider adopting this year. The tool can generate, draft, summarize, and suggest. It cannot take responsibility. It cannot build trust with the people you serve. It cannot decide what your organization stands for. That work stays with you.
So here is where I would start, if you have not already: sit down with your team this week. Not next quarter, not after you have drafted a policy. This week. Bring these four questions to the table and answer them honestly together for the tools you are already using and those you are considering. You will likely find that some answers are clearer than you expected, and others reveal gaps you did not know were there.
That conversation is where governance actually begins.
About the author

Marline Paul is a certified AI educator and the founder and CEO of Enilram Creative Solutions (ECS), a woman-owned AI education and business strategy consultancy based in Fort Lauderdale, Florida. Known as the AI Confidence Catalyst, she helps entrepreneurs, nonprofits, and community leaders build practical, human-centered AI literacy into their work. Marline is a Goldman Sachs One Million Black Women Cohort 6 participant and a Nasdaq Circle 22 participant, and she leads the Get Equipped AI Summit each year.
A note on process: In the spirit of the governance principles in this piece, here's my own disclosure: I used AI as a thought partner to help structure and refine this article. The reasoning, experience, and voice are mine.




Comments