Governing AI with intention in the social impact sector

| Interview

The social impact sector runs on trust with donors, beneficiaries, communities, and the public. Now, AI is reshaping how that trust is built and maintained. During a recent webinar hosted by Blackbaud, McKinsey Associate Partner Cécile Prinsen and Senior Expert Daniel Wallance explored how organizations can adopt AI responsibly and at scale.

McKinsey is a member of the AI Coalition for Social Impact, convened by Blackbaud in 2025, bringing together leaders from philanthropy, technology, education, and corporate social responsibility to provide guidance, shared standards, and resources for responsible AI use in the social impact sector.

The following transcript of that conversation has been edited for clarity and length.

The AI inflection point

Moderator: From where each of you sits, what makes this moment so different from any previous technology shift?

Daniel Wallance: The speed and pace of innovation are unlike anything we have seen before in recent times, creating something instantaneously that previously took hours, days, or even weeks. The tools we have are producing outcomes that are nondeterministic. In the past, if you were conducting a Google search or creating an image, there was a fixed outcome. Certain steps led to a certain result. Now, I can create an entire report or presentation from scratch. I think back over time, and the last comparable moment was the early days of the internet boom. But this is the next S-curve, at a much faster pace, with new risks we have to think about differently and effectively manage.

Cécile Prinsen: I echo what Daniel said. It is the pace of change, but it is also the breadth of change across industries. In financial services, automated decision-making is something we saw 20 years ago with algorithmic trading. That was a specific use case in one corner of banking, and it still caused the famous flash crash in 2010 when something went wrong. Now, automated decision-making is spreading across sectors, including healthcare, education, and nonprofits, at a very rapid pace. For me, it is the combination of breadth and pace, across both the opportunity side and the risk side.

Daniel Wallance: I would add one more element: The tools are accessible. I can go online and use any of the major AI platforms. It puts much more power in the hands of the individual. Before, you might have needed significant computational resources or specialized access. The world has fundamentally changed in that sense.

Why AI trust is the multiplier

Moderator: Why does responsible AI matter so much, especially for mission-driven organizations?

Cécile Prinsen: We see responsible AI, or what we call AI trust, as the multiplier of impact. When we collaborate with clients on AI transformations, we spend a lot of time getting the technology and the data right. We spend time on the people side: What are the skills? How does the organization change? But without trust, without responsible AI, without thinking through how to govern these systems and stay on top of the risks, there will be no impact—or that impact will not be as large as it could be. AI trust is an enabler of the ability to capture the opportunity, not a constraint on it.

In practice, AI trust means putting in place the right safeguards and controls to ensure that the output from a model is sufficiently reliable and checked and that there is clear accountability. For the social impact sector, where trust is the foundation of every donor relationship, every constituent interaction, and every outcome, that distinction matters deeply.

Moderator: Can you walk us through what those components actually look like?

Cécile Prinsen: We break it down into five components. First, there is strategy: the underlying principles that form the foundation for any organization building out its AI governance approach. This also includes a risk taxonomy, a shared vocabulary for what risks the organization is worried about, who is responsible for opining on acceptable risk levels, and how those risks are controlled.

Second is risk management, which includes how we manage third-party risk. Most organizations rely on third-party solutions, APIs, and data, so managing that exposure, including what happens when something goes wrong, is critical.

Third is the technology and data dimensions: ensuring data quality; identifying and addressing bias; and having the right protocols and tooling in place.

Fourth is the governance: how we manage the various responsibilities across the organization to maintain AI trust.

Finally, there is AI agent governance, which we treat separately. Agents are AI systems that make decisions and act, rather than just generating output. That requires an additional layer of control: maintaining an inventory of agents, understanding where they are being introduced, and ensuring you know what they are doing at any given time.

Not all agents are created equal

Moderator: As organizations bring in varying types of AI agents, what really separates purpose-built AI from general-purpose tools when it comes to mission-driven work?

Daniel Wallance: The terminology can be confusing, so let me frame it as a spectrum. At one end, you have knowledge and research agents—for example, a nonprofit using an agent to research a donor or trends in the industry. The agent produces a structured report or analysis. At the other end, you have agents that complete tasks autonomously, effectively mimicking the behavior of an employee.

Fundraising is a vivid example. A development office at a university might have a small team working with 140,000 alumni and are able to personally contact a few thousand in a given year. Now, imagine complementing that team with an agent that can reach out autonomously, raise money, craft personalized messages, and maintain virtual personas that constituents can interact with and ask questions of. That is the direction we are heading—and not just individual agents but multiagent workforces.

Each point on this spectrum carries a different level of autonomy, a different risk profile, and a different set of controls required. The controls to put in place for a knowledge and research agent are quite different from those needed for an agent that is mimicking the behavior of an employee within an organization.

Moderator: Should organizations have a formal AI code of conduct, and if so, what should go in it?

Daniel Wallance: More and more organizations are publishing codes of conduct specific to AI, and it is still early, but the trend is clear. A good code of conduct addresses where organizations can use AI and where they are making explicit decisions not to use AI. For example, in the fundraising scenario, an organization might say, “We are using AI in outreach campaigns, but there will always be a human in the loop.” That gets codified in their code of conduct. Transparency is another key element. If content in a donor communication was generated with AI, an organization might choose to disclose that. It is about drawing the boundary of what you are comfortable doing, being open about where that boundary falls, and then holding to it.

Scaling responsibility alongside AI

Moderator: As organizations start small and scale their AI capabilities, how do they scale their responsibility?

Cécile Prinsen: I would say to stay practical and risk-based. Our belief is that the responsible AI journey should scale in alignment with the AI strategy. If your organization is still experimenting, running internal use cases that do not directly affect clients or constituents, that calls for one level of governance. If you are already running complex multiagent systems that independently interact with donors or beneficiaries, that is a fundamentally different situation requiring a fundamentally different level of controls.

Principles are a solid foundation, but they are not practical by themselves. Organizations then need to define the key risks to avoid, determine how to size and measure those risks, and outline the practical controls and checks to put in place. Keeping the same pace in your governance as you are in your AI journey is the goal.

Moderator: How do you know if it is working? Is it time saved, dollars raised, or something harder to quantify?

Daniel Wallance: It is a question that organizations are working through constantly. Many are deploying AI but not always seeing the benefits. Comments such as “I see AI everywhere except in my bottom line” are prevalent. The answer is that AI should not be deployed for its own sake. There needs to be a specific outcome: revenue generation, cost reduction, efficiency, and, as previously mentioned, risk reduction.

In a nonprofit context, that translates to, “Were we able to increase fundraising, reach a larger number of constituents, develop grant applications faster and with a higher win rate, or launch events more efficiently?” It is about the magnification of the work people are doing and seeing the impact through that lens.

The future: Multiagent workforces and proactive impact

Moderator: Looking three to five years out, if we get this right, what becomes possible in the social impact sector that simply is not possible today?

Daniel Wallance: I am excited about the multiagent world that is just over the horizon. Today, we are largely in a single-agent world. But imagine a nonprofit planning its annual charity auction. Rather than a team of people managing the entire event, imagine one agent booking the venue, another arranging the catering, another organizing the entertainment and speakers, and another running the auction itself during the event. And one agent, the event planner, could coordinate all the others. The organization interacts with it just as it would a human coordinator.

The impact is extraordinary. It frees up the human team for the relationship-driven, mission-critical work that only they can do. And crucially, this does not mean running entirely autonomously. Before a venue is booked, there is a sign-off. Before entertainment is confirmed, someone reviews it. Those checks are exactly what responsible deployment of these systems looks like.

Cécile Prinsen: I would highlight two trends I expect to define this period. The first is sheer productivity at scale. We have each seen individually how much faster we can work with AI assistance. Now imagine that multiplied across an entire organization and then across the sector. That creates enormous capacity for more-personalized, human-centered service.

The second is proactivity. With richer data and better AI systems, social impact organizations will be able to anticipate needs rather than react to them. Drawing from my experience in banking, we have seen real-time fraud detection become standard. I can imagine social organizations becoming much more proactive at anticipating risk, dropout, homelessness, health deterioration, et cetera. With AI, those signals can be read earlier and interventions can happen sooner. That is a profound shift in what is possible for the sector.

AI and the workforce: Amplification, not replacement

Moderator: The types of agents you have described suggest significant changes to human roles. How do organizations ensure it’s a capacity add rather than a human replacement?

Daniel Wallance: What I would say is this: It is not AI in itself that someone should be fearful of taking their job. They should be more concerned about the person who can use AI more effectively than they can. That is the real competitive dynamic. If you can use AI to write better grant applications and launch more-successful fundraising campaigns, that makes you more valuable as an employee and more impactful as a professional. The question to ask is: How do I increase my own value proposition through the use of AI?

Cécile Prinsen: I think it does need to be a genuine consideration, not dismissed but managed intentionally. The risk taxonomy I described earlier has to include human implications. In the AI transformations we support, we always partner with HR to think through the workforce impact, how people can remain effective in their roles, upskilling, and understanding the human-in-the-loop roles that require judgment and the ability to challenge and govern AI systems. My experience is that AI is enabling people to focus on higher-value work. It is increasing productivity and freeing people for the work that most motivates them. But that outcome requires intentionality; it does not happen automatically. Organizations have to think through this from the start.

Governance at the speed of AI

Moderator: The pace of AI growth is extraordinary. How do organizations ensure their checks and balances keep up?

Cécile Prinsen: This is exactly the challenge I am focused on right now, and our research confirms that governance is lagging behind. That is a problem that needs to be solved urgently. What we are finding is that the governance gap is actually starting to block organizations from pursuing AI opportunities. Once a new use case is ready to go live, some organizations have not yet figured out how they are going to govern, and that becomes the bottleneck.

There is a second dynamic worth noting: Because of this lag, the AI journey itself is slowing down for many organizations. And that creates a powerful motivation to solve the governance problem—not as a compliance exercise but as a business enabler.

The practical answer is to calibrate your governance approach to your actual AI maturity. Do not try to build the entire framework before you have started. Build it in parallel, keep it practical and risk-based, and ensure it evolves as your AI capabilities do. The goal is governance that keeps pace with the journey, not governance that arrives years after the fact.

Explore a career with us