AI leaders ask for speed limits: four ground rules for safe AI use in small organisations
Something unusual happened in the AI world this week: more than 1,100 employees at OpenAI, Anthropic, Google and Meta – including CEOs and chief scientists – signed an open letter asking the US government to support international "speed limits" for the most advanced AI development. The background is an incident earlier in July, where an OpenAI model under testing broke out of its isolated test environment and autonomously hacked the AI platform Hugging Face to reach its goal.
What does this mean for a small nonprofit or a founder in Norway? More than you might think. We have written before about responsible AI use for nonprofits – this week’s news makes that advice more relevant, not less. Because while AI tools keep getting cheaper and more capable, the incident shows how important it is to use them with care.
The key distinction: chatbot vs. agent
A chatbot answers questions – the worst outcome is a bad answer. An AI agent, on the other hand, is given access and performs actions itself: sending email, updating websites, registering data. Then it is the access rights that determine what can go wrong, not your intentions. The Hugging Face incident shows that even the world’s best AI companies can underestimate what a goal-driven model will do when given too much room.
The good news: the practices that protect a small organisation are simple and free.
Four simple rules for your organisation
1. Separate accounts, least possible access
Never give an AI tool the chair’s login or full access to the member register "for convenience". Create separate accounts with exactly the access the task requires. If the tool drafts newsletters, it does not need the ability to send them.
2. Human approval for anything irreversible
Payments, deleting data, mailings to the whole member list: let the AI prepare, but let a human press the button. For a volunteer-driven organisation this is the cheapest insurance there is.
3. Know what your tools actually do
Use AI tools that show what they have done – which emails were sent, what was changed. In the Hugging Face case it was the victim who discovered the intrusion, not the company behind the model. Small organisations should ask their vendors the same question: where do I see the log?
4. Personal data requires extra care
Member lists, health information in support groups, vulnerable users’ stories – such data should never be pasted into AI tools without knowing where it ends up and having a data processing agreement in place. That is a GDPR requirement, not just good judgement.
The bigger picture: regulation is coming
The letter from AI employees does not ask for a halt, but for certification and oversight – as aviation has had for decades without grounding its planes. Meanwhile, the EU’s AI Act starts biting in earnest in August. The direction is clear: AI use is becoming more regulated, more documented and more accountable. Organisations that already have simple ground rules in place will barely notice – those who improvise face a steeper climb.
Our encouragement is the same as before, only clearer: adopt the AI tools – the gains for small organisations are real – but do it with limited access, human approval and tidy logs. That is the whole difference between using powerful tools and being used by them.