This case study follows a one-day workshop in Abuja, run under TechSoup's "AI for Social Change" program with support from Google.org, where Legis360 taught eleven CSOs to close that gap through secure prompting, a risk framework, and real documented breaches rather than abstract theory. The result was a ’jump in confidence and knowledge, and a shift that participants themselves named as "more work" but also "wider horizons".

Goal and Process

Legis360 Centre for Advocacy, Development and Public Enlightenment Initiative delivered a one-day workshop in Abuja, Nigeria, on AI and digital safety and security for civil society organizations (CSOs). The training formed part of the “AI for Social Change” project, run under TechSoup’s Digital Activism Program with support from Google.org.

Our goal was practical, not theoretical: participants told us at the start that they wanted to learn the correct use of AI for a civil society organization and to gain a practical understanding of the risks AI use poses to CSOs. We built the day around exactly that. Three facilitators, Victor, Doreen, and I (Samuel Folorunsho), moved participants through five sessions: AI in civil society today, AI risks and the “4 Circles of AI and Cyber Security” framework, practical cyber security for AI users, responsible AI implementation, and the development of each organization’s own 30-day AI and cyber security action plan.

We localized the curriculum deliberately. Instead of abstract risk lectures, we used live polls on the tools participants already use, group exercises where teams mapped their own AI exposure at personal and organizational levels, and an incident simulation asking a simple, uncomfortable question: if something goes wrong with AI in your organization tomorrow, what is your first move?

Target Group

Participants came from Nigerian CSOs working on governance, accountability, justice, and security-sector reform; youth and women’s development; disability inclusion and support for survivors of violence. Organizations included the CLEEN Foundation, the African Centre for Leadership, Strategy & Development (Centre LSD), PAACA, Inclusive Development (INCLUDE), ASVIOL Support Initiative, Brain Builders Youth Development Initiative, and more. Eleven participants completed the end-of-day evaluation.

Image 1. Participants in Abuja map their organizations’ AI exposure during the group exercise.

Context and Needs

Nigerian CSOs are enthusiastic AI adopters. Staff already use ChatGPT and similar tools daily for grant writing, reporting, translation, and social media, usually through personal accounts and, the majority of the time, without organizational policy. That is the exact profile of “shadow AI”: high usage, low governance. These same organizations handle sensitive beneficiary data, donor information, and advocacy strategies, and several work in politically sensitive areas where AI-assisted phishing, impersonation, and disinformation are realistic threats, not hypothetical ones. The gap between how much participants used AI and how little protection surrounded that use defined the training need.

The Personal Touch

I prioritized two things in my sessions: honesty and storytelling. Honesty meant being transparent about the real disadvantages of AI tools; they hallucinate facts, they may store and train on your prompts, and their terms of service often disclaim all responsibility. We read the example AI terms of service together and identified the red flags line by line.

Storytelling meant teaching every risk through real, documented cases: the 2020 Twitter hack that started with one phone call, the 2023 Samsung data leak via ChatGPT prompts, the 2024 deepfake video call that cost a company USD 25 million, and closer to home, the February 2026 Lagos case in which a businessman used an AI-cloned image of Peter Obi to defraud an investor of ₦230 million through a fake forex platform. Each case ended with the same question: What does this mean for an NGO in Nigeria?

Another example: ARCON's June 2025 public notice about deepfake ads circulating on Facebook and Instagram using cloned faces and voices of trusted figures like Pastor Adeboye and Channels TV anchor Seun Okinbaloye to sell fake medical cures, which maps more directly to "impersonation of a trusted messenger" than to financial fraud.

Main Take-Away

My aha moment: participants arrived expecting to learn how to use AI better, and the content that resonated most was about using it more safely. Secure prompting, the discipline of never putting names, case details or internal documents into a public AI tool, was the single most cited throughout the day. One participant put it directly:

Learning about the importance of secure prompting and internal AI governance was the highlight for me”

Another participant captured the honest cost of that realization:

On a lighter note, this training has created more work for us as CSOs. But it has also expanded our horizon, and we left with more knowledge than we came in with

That “more work” is the point. Safe AI use is not a tooltip; it is an organizational discipline, and recognizing it as such created a to-do list participants weren’t aware of before the workshop.

What the Evaluation Showed

All eleven tooltips were satisfied or very satisfied with the training, and eight said it exceeded their expectations. Self-rated knowledge moved substantially on a five-point scale:

  • AI knowledge rose from an average of 2.9 before the training to 4.5 after.

  • Digital safety and security knowledge rose from an average of 3.0 to 4.5.

  • Every respondent said they felt confident or very confident applying what they learned.

The meeting was insightful, especially the aspect of secure prompting,” one of the workshop participants shared.

ToT Connection

The training applied the “AI for Social Change” Train-the-Trainer methodology directly. From the ToT sessions, I carried over the 4 Circles of AI and Cyber Security framework, individual security, internal organisational security, external data management, and defence against external attacks, as the organising spine of the day, and the real-case storytelling approach as the main teaching technique. The 6 Secure Prompting Rules and the 7 Vendor Risk Questions gave participants tools they could apply the following morning without the need for a budget.

The “So What?”

Participants left with a concrete 90-day action plan for their organization and a set of immediately usable practices: secure prompting rules, a personal security checklist, and vendor questions to ask before adopting any AI tool. The lasting shift, though, was in framing; participants now see AI governance as their organization’s responsibility rather than an IT department’s luxury.

Further needs remain, and participants clearly identified them. Several asked for a two-day format with more hands-on problem-solving, where real organizational challenges are worked through to solutions in the room. Others asked for reference materials on AI security risks and ethical AI use to refer to after the training, as well as follow-up support as they draft their first internal AI policies. A one-day workshop can open the door to AI governance; walking through it will take continued accompaniment, and that is where we plan to focus next.

Your Feedback Matters

What did you think of this text? Take 30 seconds to share your feedback and help us create meaningful content for civil society!


Disclaimers

This piece of resource has been created as part of the AI for Social Change project within TechSoup's Digital Activism Program, with support from Google.org.

AI tools are evolving rapidly, and while we do our best to ensure the validity of the content we provide, sometimes some elements may no longer be up to date. If you notice that a piece of information is outdated, please let us know at content@techsoup.org.

The content was created, reviewed, and edited by Samuel Folorunsho with AI assistance.

About the Author

Samuel Folorunsho is a Nigerian civic technology expert, ICT specialist, and the Executive Director of Legis360. He is a prominent figure in African digital democracy, specializing in utilizing artificial intelligence (AI), open data, and machine learning to build governance tools that increase legislative transparency and foster public accountability.