To help civil society professionals build these capabilities, AI and Digital Safety and Security Curriculum offers a free, trainer-ready materials designed specifically for nonprofit and civil society organizations.

Created for trainers, digital-security practitioners, CSO leaders, program managers, IT and security teams, data-protection colleagues, and others responsible for safe organizational AI use, the curriculum provides practical tools that teams can apply to their everyday work.

Strengthen Digital Resilience in the Age of AI

AI-related risk does not sit in one place. It can emerge through individual behavior, organizational workflows, data shared with external systems, or attacks that use AI to make existing threats more effective.

The curriculum introduces the 4 Circles of AI & Cyber Security:

  • Individual security: how people use AI tools and what they enter into prompts.

  • Organizational security: how AI becomes part of workflows, systems, and decision-making.

  • External data: what happens to information once it is shared with an AI service or other third party.

  • External attacks : threats such as phishing, deepfakes, impersonation, and other AI-enabled attacks.

This framework helps teams map where AI is already being used, identify exposure, and decide where safeguards are needed.

Managing the Risks of AI Vendors

Organizations also need to look beyond their own users.

Before adopting an AI tool, teams should understand how the provider handles organizational data and what happens if the organization later decides to stop using the service.

The curriculum provides seven vendor-risk questions covering:

  • Data storage

  • Model training

  • Ownership

  • Data retention

  • Data-processing agreements

  • Exit and deletion processes

  • Internal accountability

These questions can support more informed conversations between program teams, IT and security staff, leadership, and data-protection colleagues.

A Trainer-Ready Resource for Civil Society

The AI and Digital Safety & Security curriculum is provided as a 30-day action-planning approach to help teams turn training discussions into concrete next steps, AI Mapping exercise that helps teams identify AI tools, workflows, data flows, dependencies, and potential points of failure, an incident-response sequence for situations where something goes wrong, as well as a trainer-ready PowerPoint deck. It includes:

  • Case studies

  • Practical exercises

  • Live-poll prompts

  • The 4 Circles of AI & Cyber Security framework

  • Secure-prompting guidance

  • Vendor-risk questions

  • AI exposure mapping

  • Incident-response guidance

  • Governance and accountability models

  • Action-planning activities

The materials can be adapted to different audiences, languages, organizational contexts, and levels of experience.

The goal is not to eliminate AI risk, which is something that is neither realistic nor achievable through a single training. The goal is to help organizations see where risk appears, understand what they can do about it, and establish shared responsibility for managing it.

The curriculum is shared under the Creative Commons Attribution 4.0 International (CC BY 4.0) license, allowing organizations to adapt and reuse the materials while retaining attribution.

Register Here:

Access the free AI & Digital Safety and Security curriculum here:

Your Feedback Matters

What did you think of this text? Take 30 seconds to share your feedback and help us create meaningful content for civil society!


Disclaimers

This piece of resource has been created as part of the AI for Social Change project within TechSoup's Digital Activism Program, with support from Google.org.

AI tools are evolving rapidly, and while we do our best to ensure the validity of the content we provide, sometimes some elements may no longer be up to date. If you notice that a piece of information is outdated, please let us know at content@techsoup.org.

The content was created, reviewed, and edited by TechSoup'sDigital Activism Program team with AI assistance