AI that does not see the data: a privacy bright spot for organisations with sensitive information
Many nonprofits face a difficult dilemma: AI tools could save you an enormous amount of work, but you handle sensitive information – about members, donors, or vulnerable people you help – that you cannot send to just any cloud service. This week brought news that could eventually solve exactly that: Google has released an open tool called HEIR that makes "private AI" more practical – artificial intelligence that can analyse data without unlocking it.
What is it about?
The technology is called homomorphic encryption. Simply put, it lets a computer compute on encrypted data without seeing the content. You send in something encrypted, the AI processes it encrypted, and you get the answer back encrypted – which only you can unlock. The service doing the work never sees the actual information. Instead of having to trust that a provider handles the data properly, it becomes impossible for the provider to see it.
For a sector utterly dependent on trust – and which often manages some of the most sensitive information there is – this is a deeply relevant direction.
Be patient: this is early
At the same time, it is important to be honest: the technology is still slow and immature. Google’s own demonstration took around 16 seconds for one small analysis, and homomorphic encryption is generally 100 to 1,000 times slower than ordinary data processing. That means it suits small, bounded tasks with highly sensitive data today – not daily, large-scale use. A full encrypted AI conversation is still some years away.
What does it mean for your organisation?
- Hope for the sensitive tasks. If you have data you would like to use AI on but refrain because it is too private – health information, stories from vulnerable users, member data – those are exactly the tasks this technology is eventually built for.
- Nothing to do today, but stay informed. This is not a tool you adopt now. But knowing that "AI that does not see the data" is coming lets you plan long-term – and ask the right questions when providers start offering it.
- Keep doing the basics. Until this technology matures, the usual rules apply: never share sensitive personal data with AI tools without a data processing agreement and a valid basis. This connects to the ground rules for safe AI use we have written about before.
A bright spot in the privacy debate
Much technology news is about AI that sees and collects ever more – face scanning, tracking, search that reads everything. Homomorphic encryption is the rare counter-story: technology that makes privacy a mathematical property, not just a promise. For the nonprofit sector, often a defender of precisely the vulnerable and their right to privacy, it is a development worth cheering on – and following closely. The goal is a future where organisations can use powerful tools and protect the people they exist for, at the same time.