This was one of the central questions of ACT Days 2026, an annual event that brings together civil society organisations from across Serbia, alongside, partners and the Embassy of Switzerland in Serbia, for exchange, learning and practical collaboration on topics relevant to the sector. This year's edition gathered around 60 participants for discussions and hands-on sessions focused on artificial intelligence and digital security.
For organisations that often work on sensitive issues and with vulnerable groups and communities, AI and digital security is not simply a technical matter, but an essential part of responsible and safe work. Through this conference, ACT project created space for organisations to explore how they can make use of the opportunities offered by new technologies while also understanding their risks, limitations and ethical implications
From curiosity to practical use
For many organisations, the question is no longer whether AI will become part of their work, but where it can actually bring value.
Some tasks can be done relatively freely with AI: preparing a first, imperfect version of a text, rephrasing or shortening content, changing tone, developing headlines or interview questions, summarising a document that has been provided to the tool, transcribing recordings with human editing, translating material that someone on the team can review, and organising tables or lists.
Other tasks require a designated human checker. These include coding responses from surveys or interviews, summarising laws and public policies, drafting parts of project proposals, analysing media coverage and, importantly, anything containing figures that will appear in a report. The handout makes the organisational responsibility explicit: without a named person responsible for verification, these tasks effectively move into the higher-risk category.
And there are tasks where AI should not be used in this way: legal advice and interpretation of regulations, personal data and sensitive circumstances of users, facts and quotations that cannot be independently verified, public statements without human editing, user testimonies, and assessments of people such as employees, candidates or beneficiaries.
This gives organisations a useful way to move beyond the simple question of whether AI is technically capable of doing something and puts them at the forefront of AI use as both epistemic and ethic mediators between public, most vulnerable groups, and funders
The more important question is:
What happens if AI gets things wrong or hallucinates?
AI-generated content can sound convincing even when it is inaccurate Moreover, hallucinations are most likely to escape our notice precisely when the text sounds most coherent. The explanation for hallucinations and the presence of bias in the AI-generated content is a combination of questionable data quality (which, however, also reflects what we ourselves leave on the internet) and the need for humans to be part of the corrective mechanism, even though they are already a (precarious) part of the process of labeling that data. For organisations working with public information, research, policy, reporting and advocacy, this makes verification a central part of responsible AI use.
The session therefore introduced a practical five-step verification approach, including asking AI to provide sources for claims, checking random—not only convenient—citations against the original source, and discarding the output when verification reveals fundamental problems.
The final responsibility remains with a person: the organisation should know who checked the content, what was checked and when.
This shifts the conversation from “Can AI do this?” to a more useful organisational question: “What level of human control does this task require?”
From individual experimentation to organisational rules
The proposed minimum organisational AI policy includes six basic elements: clear responsibility for content; internal recording of where AI has been used; rules around data; mandatory verification of numbers, quotations and legal claims; a short list of approved tools; and training rather than blanket prohibition.
This last point is particularly relevant for civil society organisations.
A complete ban on AI does not necessarily prevent its use. It can instead push experimentation towards private accounts and tools where the organisation has less visibility or control.
The alternative is to create an environment in which staff understand which tools can be used, with what type of information, for which tasks and with what level of review.
Protecting data is part of responsible AI use
For organisations working with beneficiaries, partners and communities, the question of data protection is inseparable from AI.
The ACT Days handout specifically highlights that personal data of users and unpublished data belonging to partners should not be entered into commercial AI tools, in line with Serbia’s data protection framework.
This is where AI literacy meets digital security.
Using a sophisticated tool does not make a process responsible if the information entered into it creates a new risk for the people or organisations the civil society sector is trying to support.
The workshops that followed built on Vanja’s presentation, providing a deeper understanding of AI and exploring its practical application in strategic use, project writing and implementation, as well as communications and outreach.
These practical guidelines helped participants better understand where AI can support their work and where human judgement remains essential. Beyond the opportunities and risks associated with AI, ACT Days also explored another critical topic for civil society organisations: digital security
Digital security is part of the same conversation
AI was only one side of the ACT Days programme. The other was digital security.
Participants explored practical digital-security risks affecting civil society organizations, including phishing, targeted attacks and other forms of digital threat.
The discussions connected digital security with privacy, digital rights and the ability of organizations to continue their work safely.
Participants were encouraged to think about security through practical questions:
What do we want to protect? From whom? How likely is the threat? What are the consequences if protection fails? And what level of protection can we realistically maintain?
The broader lesson was that digital security should not be treated as an individual responsibility alone. Organizations need protocols, knowledge and a culture in which people know what to do when something goes wrong.
Learning by doing
Across the workshops, the emphasis was on practical application rather than technology for technology’s sake.
Participants worked with AI tools, mapped their own processes, tested potential use cases and considered the boundaries of automation. They explored how technology can support communication, project management and other everyday organizational processes, while also examining the risks that accompany these opportunities.
This practical approach helped bring the conversation about AI down from the level of abstract technological change to the reality of everyday civil society work:
What can we delegate? What needs to be checked? What data should never be entered? And where must a person remain responsible?
What do we take home?
Perhaps the most important outcome of the two days was not a particular tool or prompt, but a different way of approaching technology.
For civil society organisations, responsible AI use requires at least three things:
-
Practical knowledge – understanding what AI can and cannot realistically do;
-
Organisational rules – agreeing which tools and data can be used and who is responsible for checking outputs;
-
Digital security – protecting people, information and communication channels in an increasingly digital working environment.
The ACT Days discussions showed that experimentation and responsibility do not have to be opposites. Organisations can explore new technologies while setting clear boundaries around data, verification and human decision-making.
And perhaps the simplest principle to take back to the office is the one from the ACT Days handout: “When the text sounds best, check it.”
Ultimately, the question is not whether AI will change the way civil society works.
It is how civil society organisations will choose to use it and what principles they will carry with them as they do.
