The humanitarian and nonprofit sectors are confronting a profound AI governance crisis exacerbated by a massive 2025 data breach at the World Food Programme (WFP) and widespread unregulated AI adoption. Despite rapid integration of AI tools by aid workers worldwide, formal governance frameworks remain notably absent, raising critical concerns about data protection and rights safeguards for vulnerable populations.
What Happened
In early June 2025, the World Food Programme suffered an unprecedented cyberattack exposing personal data of approximately 600,000 households in Gaza seeking food assistance. The breach revealed sensitive information including names, identification numbers, phone numbers, and location data, highlighting glaring vulnerabilities in how humanitarian organizations protect beneficiary data. This incident has drawn attention to how AI tools are increasingly deployed in humanitarian aid without appropriate oversight. A global survey conducted in 2025 found that 93% of 2,539 humanitarian workers across 144 countries have used AI tools, primarily commercial ones like ChatGPT, yet only 22% operated within organizations that had formal AI governance policies.
Key Facts
The breach affects households in Gaza under the WFP’s food assistance programs, representing one of the largest humanitarian data leaks recorded. The survey sampling 75% of respondents from the Global South regions—Sub-Saharan Africa, MENA, and Asia Pacific—reveals frontline adoption of AI without commensurate policy frameworks. Separately, studies indicate that 82% of nonprofits use AI tools, but fewer than 10% maintain formal governance structures. Notable incidents exposing governance weaknesses include individual aid workers using consumer AI products without organizational approval, leading to data privacy violations, such as a December 2023 case in Australia involving a government department’s staff misusing ChatGPT for child protection reports.
What This Means
This crisis underscores the urgent need for humanitarian and nonprofit organizations to establish rigorous AI governance protocols to safeguard sensitive beneficiary data. Without formal policies, vast amounts of personally identifiable information remain vulnerable to exposure or misuse through shadow AI deployments that operate outside organizational control. Adding to the risk, resource-constrained organizations in the Global South often rely on free or low-cost AI tools with inadequate privacy protections, increasing exposure to breaches. For the most vulnerable populations—refugees, displaced children, and crisis survivors—who cannot meaningfully consent to data collection or processing, these governance gaps compound risks of harm and exploitation. The absence of clear audit trails, risk assessments, or accountability mechanisms means AI-driven decisions affecting these groups often go unmonitored, jeopardizing humanitarian principles and trust.
Moreover, legacy vendor contracts, lacking AI-specific terms, leave organizations exposed to unapproved AI feature rollouts and undisclosed third-party AI relationships, impairing informed consent and risk management. The data breach at the International Committee of the Red Cross (ICRC) in 2022, enabled through a third-party vendor vulnerability despite comprehensive reviews, illustrates the complexities of securing AI-infused ecosystems.
Background
Humanitarian action traditionally requires collecting personal data to deliver aid, but beneficiaries often cannot provide genuine consent due to their vulnerable circumstances. The rapid evolution of AI tools—commercial, open-source, or embedded by vendors—has outpaced the development of governance structures tailored to these ethical and security challenges. Several industry groups and coalitions, including the CDAC Network with its SAFE AI framework and NetHope’s Humanitarian AI Code of Conduct, have begun proposing rights-based contractual templates and governance recommendations.
What Comes Next
Key steps to remedy the crisis involve first mapping all AI tools in use, including shadow deployments, to understand the scope of unregulated AI processing within humanitarian workflows. This foundational visibility enables targeted risk assessment and policy development. Organizations must invest in ongoing, role-specific AI literacy for staff, particularly those working directly with beneficiaries, to detect AI-generated errors, biases, and ensure ethical decision-making aligned with organizational values.
Contractual reforms are critical, demanding provisions that prohibit client data use for AI model training without consent, require advance notification of AI system changes, enforce breach disclosure, and shift from opt-out to opt-in defaults for any new AI functionalities during procurement. Donors and funders also play a pivotal role by conditioning grants on robust AI governance standards and including dedicated resources for oversight implementation.
A significant policy milestone is the November 2025 Joint Statement on AI and the Rights of the Child, advocating for child-rights-based governance frameworks applicable to all AI systems affecting vulnerable populations, including in humanitarian contexts. However, robust enforcement mechanisms remain to be developed globally.
Sources
This article is based on reporting and publicly available information from the following sources:
Read more AI Regulation stories on Goka World News.
