You can't run AI agents on rumors with a logo
About the Author
The open, vendor-neutral commons behind the Advancement Common Data Model (ACDM™) and its free educational resources. We write about trustworthy advancement data, portability, and AI-readiness for fundraising teams of any size. Stewards are credited in the colophon, never in the byline.
AI agents are only as good as the data beneath them. They are safe to use on donor data when that data is clean, defined, and governed, and genuinely dangerous when it isn’t, because an agent acting on a duplicate or a mis-credited gift doesn’t just fail quietly in a spreadsheet. It emails the wrong donor the wrong thing, at scale, with total confidence. You can’t run AI agents on rumors with a logo.
Are AI agents safe to use on donor data?
Yes, conditionally. The condition is the data, not the model. An agent that drafts outreach, scores prospects, or triggers asks is making decisions on your records faster and more autonomously than a person ever did. If those records are clean and the rules around them are explicit, that’s a real advantage. If they’re messy, the agent industrializes the mess. The safety question isn’t “is the AI good?” It’s “is the data underneath it true, and are the guardrails real?”
Why bad data is worse with an agent than with a person
A gift officer who sees something odd in a record pauses. They feel the friction (“wait, didn’t we just thank her?”) and they check. An agent feels no friction. It acts on what the data says, immediately, across thousands of records, in a tone of complete certainty.
A human makes a mistake. An agent makes the same mistake everywhere at once.
Three ways it goes wrong (synthetic examples)
These are illustrative, not real, but every one maps to a data problem shops already have:
- The duplicate. A major donor exists on two records: one showing a $500 history, one showing $250,000. An outreach agent reading the first record asks her for $1,000 at the spring gala. The mistake isn’t the model; it’s that two records were never merged. (This is the same duplicate that makes “how many donors do we have?” have three answers.)
- The mis-credit. A gift is soft-credited to a spouse. An agent attributing “who gave” can’t tell hard credit from soft credit, so it thanks the wrong person, or thanks both for the full amount, implying you received twice what you did.
- The false lapse. A donor mid-pledge made no new commitment this year, so an agent reads them as lapsed and drops them into a win-back sequence, while their pledge installments are arriving exactly on schedule. (A pledge is not a payment is the whole story here.)
None of these is an AI failure
Every one is a data failure the agent faithfully amplified. The model did exactly what it was told; the records told it the wrong thing, a thousand times over.
What “AI-ready data” actually means
“AI-ready” is not a product you switch on. It’s four properties your data either has or doesn’t:
- Clean: deduplicated, with gifts dated and attributed consistently.
- Defined: “lapsed,” “active,” “household” mean one thing, written down, applied the same way every time.
- Connected: a commitment is distinct from a transaction, a soft credit from a hard credit, so the agent reads relationships correctly rather than guessing.
- Governed: consent and retention rules travel with the data, so automation only acts on records it’s actually allowed to use.
That list is not new. It’s the ordinary discipline of trustworthy data, which is the point. The work that makes AI safe is the work that already makes your reports agree.
The leadership move: build the foundation first
The temptation right now is to buy the agent and hope the data sorts itself out. That’s backwards, and it’s the expensive way to find out your records weren’t ready.
The foundation isn’t the boring prerequisite to the AI story. It is the AI story.
The durable move is to make the foundation clean, defined, connected, and governed, on an open, portable base you won’t have to rip out when the next wave of tools arrives. Build it on data that’s portable and yours (see avoiding CRM lock-in), and you can adopt agents when you’re ready, on your terms, without betting the organization on one vendor’s roadmap.
An honest note
This is an emerging area and we’re building in the open. Treat agentic AI for fundraising as early and evolving. The right posture is to get the foundation right now so you’re ready when the tooling matures, not to wire an autonomous agent to a messy database and hope.
For the leadership view on AI disruption and staying future-proof, see Future-Proofing & AI. To see where your data stands today, take the self-assessment.
Examples use synthetic data. ACDM is open and early; treat current releases as drafts.
Related Articles
Agentic AI for fundraising: a glossary for nonprofit leaders
Agentic AI means software that takes actions, not just answers questions. Here's a plain-language glossary (agent, grounding, guardrails, hallucination) for fundraising leaders.
What one misfired AI agent costs you: the duplicate-donor problem at scale
When AI runs on bad CRM data it doesn't fail quietly. It executes the error across your whole list. Here's what a single duplicate donor costs once an agent acts on it.
Future-proofing nonprofit technology: a leader's guide to not betting on the wrong platform
You can't predict the next disruption, so don't try to pick the platform that survives it. Future-proof by composition: an open, portable foundation that adapts. Here's how.