A practical guide to choosing an AI development partner: questions to ask, red flags, build vs buy, and data and compliance due diligence.
Build, buy or partner
A board member who runs a software company offers to build the nonprofit an AI tool over a few weekends. Eighteen months later there is a half-finished repository nobody on staff can run, and the problem it was meant to solve is still there. We have watched that story enough times to think the first decision is not which agency but which kind of thing you are choosing. Building from scratch means owning the roadmap and the maintenance bill for ever. Buying a finished product means fast value on someone else's priorities. A lab partner sits between: they build with you on top of tools that already exist, so you get a custom result without inheriting a codebase your team cannot staff.
The test is whether your problem is unique. Donor receipts, recurring giving and match detection are solved problems, so buying or layering on a platform almost always wins there. A bespoke programme model, a specialised intake workflow or an unusual data integration is where custom work earns its cost. We run a lab of that kind, so read what follows knowing that; the questions below are the ones we would want asked of us. Whitelabel layers on top of your existing stack and exposes a documented API, so the custom parts get built without rebuilding the parts that already work.
The questions that separate partners
Ask who owns the model, the prompts, the training data and the resulting code, and if the answer is vague, walk. Ask how the system behaves when the AI is wrong, because it will be; a serious partner can show fallbacks, human review steps and escalation paths rather than a happy-path demo. Ask what happens when their lead engineer leaves and whether you could operate the thing without them. As the AI for Nonprofits Network reported, the biggest failures are rarely technical; they are unclear ownership and abandoned pilots.
Then push on the boring operational questions: who pays for inference as you scale and whether the cost is predictable, how the AI agents are constrained so they cannot send a donor the wrong tax receipt or expose a record they should not, and whether support after launch is a person or a ticket queue. A good partner answers crisply because they have been asked before. A weak one improvises, and improvisation is exactly what you cannot afford near donor money and personal data.
Diligence before the demo
Demos are built to persuade, so treat compliance as a gate rather than a footnote. Ask for current attestations, not promises: PCI DSS Level 1 for anything touching payments, SOC 2 for security controls, HIPAA if you handle anything health-adjacent. Whitelabel publishes its own through a Vanta-powered trust centre so status can be checked rather than taken on faith, and our walkthrough of nonprofit AI compliance covers what each certification proves and the gaps an enthusiastic vendor glosses over.
Then ask where donor data goes and who can see it: whether the partner trains shared models on your supporters' information, whether you can delete data on request and prove it, and whether there is a data processing agreement. Strong AI governance means logged decisions, role-based access and the ability to show a board exactly what the system did and why. If a vendor cannot explain their data flows in plain language, assume they have not thought hard enough about them, and that the liability lands on you.
When a partner beats DIY
A capable in-house developer plus a weekend of enthusiasm is not a team that ships, secures and maintains AI for nonprofits every day. DIY makes sense for low-stakes internal tools and quick experiments. A lab partner wins when the work touches donor money, sensitive records or anything a regulator could ask about, because the cost of a quiet mistake is far higher than the cost of doing it properly, and the mistakes made here are predictable, which is why so many pilots stall before launch.
Start with a scoped pilot that has a clear owner, a real deadline and a defined way to measure success, and expand only if it works. Building on an already-compliant platform lets you skip the replatforming and the security rebuild and spend the budget on the custom parts. If you are still mapping the ground, the AI fundraising guide is the next read. The goal is not the most impressive partner; it is the one you can still operate with confidence a year from now, after the board member's weekends have run out.
Frequently asked questions
Should a small nonprofit build custom AI or just buy a platform?
For solved problems like donation processing, recurring gifts, and matching-gift detection, buying or layering on a platform almost always wins because the work is already done and maintained. Custom builds only earn their cost when your problem is unique, like a specialized program model or unusual data integration. A lab partner lets you do the custom parts on top of proven tools instead of rebuilding everything yourself.
What compliance questions should I ask an AI development partner?
Ask for current attestations rather than promises: PCI DSS Level 1 for anything touching payments, SOC 2 for security controls, and HIPAA if you handle health-adjacent data. Then ask where donor data goes, whether they train shared models on it, and whether you can delete it on request and prove it. A trustworthy partner can show verifiable status and a clear data processing agreement.
What are the biggest red flags when choosing a nonprofit AI agency?
Vague answers about who owns the code, model, and data are the clearest warning sign. Watch for demos that only show the happy path with no fallback for when the AI is wrong, unpredictable inference costs as you scale, and support that is a ticket queue rather than a person. If you could not operate the system without their lead engineer, that dependency is a risk.









