Submind YouTube summaries
Thumbnail for What exactly am I responsible for if my staff is using AI?

What exactly am I responsible for if my staff is using AI?

Watch on YouTube

Video summary

The core subject of the discussion is the critical responsibility that human leaders retain when their staff utilizes Artificial Intelligence, emphasizing that AI does not absolve organizations of accountability. Dr. Stephanie Rose Belchure explains that while AI offers significant benefits in speed, efficiency, and accuracy across various tasks like coding and marketing, it functions as a tool rather than an autonomous decision-maker. The fundamental principle remains "garbage in, garbage out," meaning that if an AI model produces biased or incorrect outputs due to flawed training data, the human user who accepts and deploys that output without auditing or validating it bears full responsibility for the resulting errors. Leaders cannot simply deflect blame onto the software or claim ignorance when an AI generates problematic results; the ultimate judgment and liability always rest with the human professional driving the process. To manage these risks effectively, organizations must move beyond a "wild west" approach where employees freely use unvetted free tools like ChatGPT, which often mine user data to train their models. The conversation outlines a three-pillar framework for safe AI adoption: people, technology, and policy. Technologically, organizations should secure enterprise-level licenses that provide administrative controls over who can access the tool and how data is handled, ensuring that proprietary information like donor lists or financial code is not inadvertently shared with external developers. Policy-wise, clear acceptable use guidelines must be established immediately to define what tools are permitted and how data should be protected. This requires a shift in culture where leadership actively audits current usage, locks down unauthorized access points, and ensures that all staff understand the fiduciary duty to safeguard organizational intellectual property regardless of the tool's convenience. Training and ethical leadership in this evolving landscape require an ongoing, adaptive strategy rather than a one-time event. Because AI capabilities evolve rapidly, organizations must continuously update their governance structures and baseline training to keep pace with new features and risks. A key lesson from JMT Consulting is the importance of standardizing complex workflows; instead of allowing individual employees to create unique AI agents for the same task, teams should collaboratively build, test, and validate a single, repeatable model that ensures consistency and auditability. This approach allows leaders to maintain control over outcomes while still leveraging efficiency gains, ensuring that every transaction or output can be traced back through a clear process similar to traditional accounting standards. Ultimately, the path forward for nonprofits and other organizations involves balancing the excitement of new technology with rigorous data governance and security measures. While free AI tools offer immediate ease of use, they pose significant risks regarding data privacy and model integrity that justify the investment in secure, managed solutions. Leaders are encouraged to meet their teams where they are, helping both advanced users and those hesitant about AI to adopt these tools responsibly within a structured framework. By establishing clear policies, investing in appropriate technology, and committing to continuous education, organizations can harness the power of AI to improve operations without compromising their integrity or exposing themselves to unnecessary liability.
Read the full video transcript
Hey, welcome back everybody. It's another episode of the nonprofit show. I've got to woman up and say when Stephanie Rose Belure is coming on, um I make sure that I get really good rest and I eat a good breakfast because um she runs circles around me intellectually and also she's a runner so she could run circles around me anyway. But Dr. Stephanie Rose Belchure, welcome back to the nonprofit show. >> Thrilled to be here, Julie. It's always it's always so much fun to to chat with you. >> It's a lot of fun. And today um you know we plan these things out and so we we look like total brain surgeons when we get a topic that's just everybody's like buzzing about and in the last 72 hours you know AI governance um has really become a just this like the story's blown up. It's been important anyway, but all along, but really in the last three days, it's been critical. And so, um, but we had already decided we wanted to talk about this, right? And so, super cool to have >> Yeah. I mean, super cool. And as, um, you know, to her friends and her staff, they call her SRB. SRB to have her come on and talk about this. Super super fabulous. So, uh, this is going to be a barn burner call. I I think really really important. You know, we have amazing amazing partners and JMT is one of our partners, but they also include our partners include Bloomerang, American Nonprofit Academy, Staff and Boutique, Third Sector Company, Your Parttime Controller, and Martis, the newest member of our sponsorship family. I'm Julia C. Patrick, CEO of the American Nonprofit Academy. And as I was teasing her at SRB, Dr. Stephanie Rose Belchure, a really dynamic thinker and the chief operating officer of JMT Consulting. Really an interesting piece of knowledge here that you bring to us because you are working with an organization that deals with so many things in the financial sector and yet you come to this with a management background, right? >> Yeah. Yeah. um just a lot of executive leadership across fintech and health tech um my entire career. >> Yeah, really cool. Um um I want to jump into this right off AI and governance. Um talk to us about that human piece because this seems to be something that we're we separate or we don't talk about it at the same time. And how do you see this, Dr. Rose Beloucher? >> So I think that first of all AI is amazing what it can do for us and the and the way that it can help us aid us in being faster, being more efficient, frankly, and can improve accuracy when used appropriately. Um, I think I was an early adopter. I may not be the most sophisticated early adopter, but I immediately saw so many applications just to how AI could aid me and and take things that would take me hours upon hours um you know to speed me up and and the applications are just mind-boggling, right? It's it's it's changing how we develop code for programming. You can you can you can have it start building your code. It's letting me move through contract negotiations at at much greater pace. But conversely, it's doing all sorts of creative things on the marketing end, right? Like my marketers have it help them build the graphics and move things faster. So I I I you know, let's start with this is a the future from an improvement of work. Um, >> but it's still a person driving the car, right? The car doesn't Yeah, we got self-driving cars. Somebody programmed it. So, you know, maybe that's a bad analogy, but you're still the driver here because you're asking it to do a task, whatever the task is. And at the end of the day, you have to accept what that output is. So in the case of the developer, the coder, you know, if that code was bad and you accepted it and you didn't audit it and you didn't test it and you didn't validate it, it's bad code, >> right? >> The AI wrote it faster for you. That's great. But if it was bad, it was bad. So you know, in old business school, ops management first in, you know, garbage in, garbage out. >> I was thinking of Grace Hopper saying that. Yeah. The >> develop doesn't change like and and the The scary thing with these AI models, right, is if they've got bias, if they've got garbage in, >> yeah, >> you know, it's garbage out. And and the scarier part is the AI is going to give you an answer no matter what, >> right? So it, you know, you hear the term hallucination. Well, it's designed to give you an answer. So, it's going to give you something and it's up to you to validate it. You know it's it and I I have lots of tips and tricks of just simple things you can do on that validation piece. But the point of of your question is the humor human- centered aspect of this. You are still accountable. You are not advocate. You are not you know getting rid of your accountability your responsibility for whatever the task or outcome is. And so accepting that AI can be a a gamechanging tool for you to get the job done. Yes. But it's still your job. And so if what you accepted without auditing and you know somebody said, "Well, the AI gave me this." Well, >> not what? >> Yeah. >> Your job, not not the AI's job, >> right? Well, to your point, I mean, if you're running a team, um, and you have to, let's say you're the head of, you know, finance and you have to give a report back out to, you know, your your seuite or your CEO or the board and there's a problem. You don't just say, "Oh, well, Nancy in accounting gave me crappy information, right?" It doesn't work that way. No. So you you have to I think you have to understand that this is the same parameter. It is still your human judgment. >> Yeah. It's just giving you a chance to be so much faster and and g you know like one of my favorite things about some of these tools is is the formatting and you know what would take us hours upon hours to make something beautiful and formatted and on brand in a PowerPoint. Boom. Done. Seconds, right? And don't discount that. That's huge. Because you, if you're putting out something professionally to your board, if you just took 10 hours of formatting work off your plate, wonderful content's still on you, but boy, having that tool do the format for you like that. Amazing. >> Exactly. Exactly. Okay. So you you you've kind of level set us to understand that we still need to have this arc of you know human judgment and that we are you know managing the bots as they say. So then let's move this into our our work environment and understand that next level of how we create a policy and a knowledge base if you will of behavior so that we're protecting our data. We're still allowing our teams to be more efficient, but at the same time, hopefully not getting them in into a position where they're creating a problem that that they didn't even know they could be creating, right? How do you see this working? So, so there's a couple pieces. Um, you know, and I I used this phrase earlier when we were getting ready, but in many organizations, unless they've put a lot of time and energy into this already, you got the wild west. You've got people using the AI that's out there for free, whether it's chat GPT or Gemini. There's a free claude. There's others um depending where you're at or sometimes embedded in other softwares even >> software. Right. >> Right. So, they're out there without your policy, without your approval in free versions using this stuff because they're like, "Wow, this is great and this this helps me." But you that's putting your organization at massive risk because the free versions are mining your data using it to build your models. So your grant manager or your donor manager says I want to manipulate and do some spun stuff with my list. You just gave your donor list to chat GPT. >> Yeah, >> maybe that's risky. Maybe that's not. You could get we could debate some of that and you know is that in the scheme of a giant you know AI model you know how we won't get in there your responsibility accountability as as as the ED as the CFO whatever your title is you know you have that fiduciary responsibility to protect your data that's your job and and we've talked we've been on your show talking about security protood calls and and all the things you have to do. Um, you know, from a policy and risk perspective and a technology perspective, a AI is no different. It's it's just it's just so wide open right now because there's all these free applications that people can go start doing stuff. Um, so I can, you know, in practical terms, I can tell you what JMT did over two years ago is I said, "Nope, not not having it. We we just shut it down." And again, because I've got a a very heavyduty layer of security, how we manage what people can get access to on their desktops, what software we allow into our environment, and those access rules. We shut out all use of free. We then went through and vetted what we thought were the ones that made sense for us >> and we went and bought the appropriate enterprise level lensure and what's that do that gives you settings control and administrative control who can have it how do you lock down and protect your data and then because I've got the security layers I can monitor if people are out there still going in and touching the stuff they shouldn't be touching right and you know and that that's so that's that's the tech end, right? We made the tech decisions, but it's also policy. This is our company stated policy and if you've got employee handbooks and policies, all that stuff, that's you train your people, right? The whole bit. And and I think I might have had this in my closing notes, but I think it fits right now. There there's sort of always three aspects to anything you're doing. It's the people, it's the technology, and it's the process or the policy. and everything we're talking about under AI, the same applies. You have to have a policy and a procedure. You have to have the technology layers that support it. And you have to prepare and train your people. And if you don't recognize AI in that same manner, you fall down on any one of those those three legs. It it it's going to be problematic. So, you know, it's say what we're going to use it for. pick the thing we're going to use. Lock everything else out. Make sure that your company, your organization's data is protected. It's not being used or to feed models. Uh because it shouldn't. You know, this is your data, your IP, whatever phrase you want to use. And that particularly true if you've got developers, right? This is your coding IP, >> right? Like it just, you know, you're in a nonprofit, your donor list is your your IP. That's your magic. >> It's frightening. It's frightening to think that, you know, you work so hard to cultivate these relationships and steward these relationships and then put it all in peril because, you know, not knowing or just using a tool that you think is great, >> but really can spin you out. I have a question that that's kind of related to this. Um, and I have really been enjoying, and I'm going to use that word enjoying, a lot of software that I use that's added this AI function. And it's really made some internal processes that I use with certain platforms great, but I haven't checked to see what the security of engaging in that is. And I'm wondering if you could give me some tips is to say before you just blindly type in to make something easy for yourself. How do we know that that data that we're we're using or manipulating is also being protected with that function or just could we do we not know? >> Um a little bit of both. uh you know and it's an interesting thing because I've lived in the the software world where you know I managed you know software that that was brought to market. So you know AI in a supercharged beyond you know geometry level it's it's it's taking robotic process automation it's taking machine learning to the nth level right I mean it's conceptually the same thing it's doing it's it's it's figuring out based on all this data that that it can pull in because it's so so powerful and and giving you the answers. Well, RPA did the same thing. You did nobody asked your permission to put RPA or machine learning in into their software, right? So, they're going to do it and they should do it. They should do it. >> What you have to think about is when you have an agreement, your agreement should be talking about two things. First, you can't steal their software and use it for your own purposes, but nor can they embed or use their data, your data for their purposes. And so, any any software agreement you have, >> as long as you've got those basic constructs, you can't you can't steal their stuff, but nor can they use their stuff. Now, I would caveat that they can use your stuff from the standpoint of if it can help them make their product better because you want them to make their product better always. >> And so what they can't do is steal your stuff, monetize your stuff, not steal, take your stuff, monetize it in some different way. But can they help them learn patterns that could create yet another utility to improve that software that you're already paying for? >> Right. >> I'm okay. I'm okay with that. >> What I'm not okay with that is somehow my data is repurposed in an external way >> that I didn't approve of um or shared with others. Right? So so there's a fine line here. They're they're going to use your data >> and they should to improve the product, >> right? >> They shouldn't use your data in a way that you wouldn't imp approve of. And and that's >> it's almost like behavior. It's like if if they're using your data or your interface uh your the way you work with their product to en enhance the overall system, I get that. But to then drill down into specifics about even managing data trends or something like that on the whole side, that's a problem, right? >> And and again, this this does boil down to I'm I'm a big compliance legal document >> geek maybe. You know, this is this is your when you buy something now, you're not going to win against Microsoft. Let's just, you know, >> yeah, >> like they've got they've got standards. they're gonna you're gonna say I accept it or I don't accept it, you know, but but generally when you're buying software that you're embedding your data into for purposes of operations, it's your responsibility to be looking at your data protection rights within your contract or or a separate agreement. It's your responsibility to ask the questions, what are you doing with AI? Um, you know, and it's fun like I'm watching I'm watching the world evolve and now I'm getting questions about what are you doing with AI, Stephanie? You know, if I buy this stuff, what does this mean for me, right, >> for our clients? So, >> again, it no different than what we started with. AI doesn't absolve you of accountability and responsibility for protecting your organization, >> right? >> Period. In some ways, you've got to actually do extra work to make sure you're protected and secure. >> Well, and I appreciate you saying that because that kind of leads us to our our next thing that I want to drill down with you and that is how do we understand about training and ethical leadership. I mean, we started this conversation today with how you know it things are just in in media blowing up over AI taking over the world or ending the world. the last three days it's been the topic of a lot of conversation. It it's been heightened. Let's just put it that way. Um this is such an an environment that's training that the training's got to change so quickly, right? When we talk about certain staff training, it's like sometimes you're like, "Okay, yeah, we can talk about that and we don't have to talk about it for another 12 months or or whatever." This seems to me that it's just like boom boom boom boom boom. How do you how do you train everybody or keep them informed so that they know that this is on ongoing? This isn't a oneand done. >> So, so I'm going to step us back before I answer the training and say if you don't have those decisions and that governance in place first, you have to do that first and you have to do it quickly. >> Um, Because what are you training them on, >> right? >> What are you telling them to if you haven't if you haven't said, "Here's what we're allowing. Here's what you can use. Here's what you cannot use." Right? If you haven't done that homework first, >> yeah. >> What are you training them on? >> Um, and you're right, it's moving so fast. I mean, I, you know, I can look back over the past, as I said, 48 months and think we should have been faster, and I know that on 10 different things that I wish we had been faster on, but I think we've been pretty good about the locking it down. >> The and I'll tell you just sort of what what I would have done a little differently for us, lessons learned. We locked it down. We picked our tool >> and we thought we have smart financial people, highly technical people. >> Yeah, >> here you go. Self-learn and and >> what what I've as this stuff continues to advance and evolve, what we're now doing is saying and and and we did the use case. We said what you could use it for. >> Yeah. What what we've learned is we have to actually do a much more effective job of defining those use cases and then baseline training everybody on whatever the tool happens to be for their expertise. >> And the other and and that's ongoing, right? Because it keeps evolving. But as you get into more complex uses, that's a level of sophistication and training and consistency that you have to again take that step back to establish how you're going to go about doing it. So, so think think higher level finance functions. >> Well, the way most of these tools work, we buy everybody we buy everybody a license. You you've locked it down. Your your work is protected. Awesome. you defined use, all that great stuff, but I'm now going to go run some financial transaction the way I think it should be done and the person sitting next to me did it the way they thought it should be done, we might not get the same outcomes. >> And and so the other thing we've learned is is is again once you get past the what you can use it for and we've got baseline training and we've got our governance and all our security protections is you need a continuum, right? you know, I I kind of said start small um or stabilize, if you will. Here's the basics and here's how we can all use them and here's where you can be an individual versus where no no no no, we're all going to do this in the same manner and and so that changes the dynamic. We can't have the same fixed assets AI transaction built at an agent level 10 different ways. >> Yeah. and because I had 10 different people that could run a fixed assets transaction just as an example could be bank wreck. It could there's plenty of places and and we love it. But what we learned and and the way we've been establishing those models is we we take our our team of experts, they build it as a group, >> right? >> Then we're doing side by side if the testing validate first and then there's a validation which is honestly no different than code development if you think about it that way. You test your code, right? You test your output. Then we've got we've established how from an architecture technology perspective that model that agent can be shared. So it's now repeatable. I I can rely on it >> because we've tested it in real you know real time. We've done this the sidebyside auditing and everybody's using the same agent slashutility whatever word you want to use. And that gives us confidence that we've got this repeatable use agent that is consistent and and and you know we've got the environment that supports the retention of the data, the auditability or traceability and you know that you can if somebody says where did this come from just like you would for your normal traditional accounting process you can move through the steps and prove it. So this isn't, as I said, many are at the wild west. They're using it however they think of it. And you get a great smart finance person going, I could just go do this. Duh. Cool. >> Probably right. Not auditable, not traceable necessarily because you haven't put any of that in place. And they've got five peers. If they're doing it, they're doing it their own way. And that's >> it differently. Yeah. >> Right. >> You know, Stephanie, it's funny. I wanted to ask you this question and talk about this because a couple years ago I was invited to a very um a very in a very rare environment to a major major national foundation to tour their offices and um I was going through and it beautifully beautifully set and everybody had their their amazing offices or workspaces and they had their equipment and next to everybody on the desk pretty much everybody had a laptop and they weren't the same laptops and they were obviously laptops that folks had brought in and I said well this is interesting how you have a central system but I see everybody here has their own laptop in some cases there were iPads and they're like oh yeah our IT person won't let us use AI and and we're all just bringing in our own laptops and stuff so that we can use chat GPT because it makes our lives easier. And I was like, "Holy cow, >> wild west. Wild west." >> It was And I'm in the wild. I mean, I live in the Wild West. Was born and raised. Even I recognized that that was a little dicey. But I I think what you these are great people doing really important work, doing good work, working hard, but they even didn't understand. I mean, it was new and it still is new, but it goes back to that, you know, leadership talking about why we do these things and how we should be doing them and bringing these people along >> and and you know, so probably the one of the interesting slashticky things for our nonprofit orgs is to do everything I just said costs money, right? Let let us be very clear. >> Yeah. You know it chat GPT free is amazing and there there are risks with that right that we talked about but it's free what I just said getting an enterprise license that locks you down >> which you know >> I believe you should do I believe it's just it's no different than an email tool at this point right you need you need to have the thing that your organization has chosen that is your secure instance is the best way to say Um and and that costs money. So you I don't have the budget for this. >> Yeah. >> So >> then come up with an acceptable use policy, >> right? >> That says on the free version, here are the things you can do and not do, >> right? >> And because I I get it. >> I use the free one, you know, at home on my Gmail because I'm cheap and I don't want to buy the license. Right. And and by the way, I don't use my JMT instance for my personal life because I don't want JMT to have my personal stuff, right? Like like you have to be you have >> it goes both ways. >> You know, there's a separation here. You should manage to. Um so it just, you know, in that instance, that's what I'd be doing. If we don't have the money and we're trying for workarounds, create an acceptable use policy that says here's what here's what's you know and this truly just goes back to data governance and security. What's public, what's private, what's confidential, all that stuff you should have documented and that doesn't cost you money. You've got management that can make these policy decisions. >> Absolutely. Well, you know, as always, our time with you flies by and I think this is so important. Um, but this actionable checklist mentality, um, you know, I think that this is something that I heard you touch on throughout our conversation today. It's like understanding that there's human governance, understanding that you're going to have costs associated with this, understanding that you need governance and a policy. For a lot of organizations, that's going to be like a like a wow, a we need a policy on this. It's a it's an interesting time, right, to be thinking about this. >> Yeah, we've we've certainly tangentally because we've been putting I you know, I wrote a blog on this. I I've published some other papers. Um we've been talking to lots of our nonprofit clients because they're asking us, you know, what do you do? How what should we do? And and so we do have a checklist and we do have some some suggested approaches which you know we're we're happy to to share but you you you start with your committee of business leaders or owners. You you make your your decisions around what we're going to what the tools are, what we're going to lock down, what we're going to protect. And you do that. That is absolutely your first step. And then you go audit what the heck's actually really happening. I mean you can do both those concurrently but you need to like audit your what your people are doing right this minute and and >> immediately get whatever policy decision you have locked down preferably with with your whoever your either IT person is or your if you've outsourced that management you got to lock it lock it down >> um >> what are and define those acceptable uses baseline train um and guide. And that's a that's a not a oneandone, right? That's okay. We've learned we've learned how to do notetaking. And boy, wasn't that a big help. I you know, because there's also there's plenty of people out there wild westing it, >> not in an advanced way that are just like, "Oh, I asked it a question and I got an answer. Wasn't that great?" Or, "It rewrote my email." And that's great, but can do much much more if if you're thoughtful and planful to get there. Yeah, >> but you got to help people along. I, you know, I I firmly believe it's our job to help people adopt the change in technology and to use it. >> And because there's people that are afraid of it, too. Let let you've got you've got >> Yeah. >> You've got the advanced users, you've got the people that don't know what the heck they're doing using it anyway. And then you got the people that won't touch it and and you've gota, you know, you got to be able to help all of them, >> right? >> I love that you said that. And I think that's incredibly wise, meeting people where they are and knowing that um that things things are changing so quickly and so we have to lean into it. Um you know, Stephanie Rose Belchure, always an amazing mind for us to be around um and and somebody who we really rely on. Um you don't know this about us on the nonprofit show, but if we have questions, a lot of times I reach back out to your team and say, "Hey, what about this?" I mean, it's really an amazing uh relationship to have somebody that's has been on the inside of technology um throughout these decades and and can offer us a perspective that very few can. So, um I want to certainly thank you um today and and and as as we move forward, you know, Dr. Rose Belchure is one of the amazing leaders at JMT Consulting. We'll talk next month when uh we revisit our time with JMT about their amazing conference that they do um in the late spring. We want to make sure that we highlight that because there's so much new information going out there. Finance is not just the way it used to be. Um, it's really changed and JMT Consulting has helped us understand that along with our other partners, Bloomerang, American Nonprofit Academy, Staff and Boutique, Third Sector Company, your part-time controlling controller, and Martist. You know, Stephanie, I feel like when I talk to you, you're always very direct and very plugged in, but at the same time, you are very positive. you know, you're very matter of fact, you're not like a doomsdayer. And I appreciate that because I think it helps us lean into these exciting times with a reduction of fear. >> Yeah, I think this is it is a brave new world, but I think it's exciting, >> but we're man it's we're managers and if we can't manage ourselves and our companies and our organizations, our nonprofits through this change, then we're not doing our jobs. That's that's our job. and and that's the way I I think of this. >> Yeah, I love it. I think those are wise words indeed. Again, Dr. Stephanie Rose Belchure. Uh what a great pleasure to have you on today with the the American Nonprofit Academy and like I said, we always lean into your knowledge and and like to share that certainly with our folks um that we work with on the nonprofit show. As we end each and every episode, we leave with this message. And it's a really important message. And it goes like this. To stay well so you can do well. We'll see you again.