Most nonprofits are already using AI. Almost none of them wrote the rules.

// JOURNAL · OPERATE / YEAR 10 SD

Most nonprofits are already using AI. Almost none of them wrote the rules.

TechSoup and Tapp Network surveyed about a thousand nonprofits last year. Three quarters of them are using AI in some form. Eighty percent have no acceptable use policy. Seventy-six percent have no AI strategy at all.

Read those two sentences again in order, because the sequence is the whole story. The tools showed up first. The rules never showed up.

There is a version of this conversation happening all over the sector right now, and it is mostly about tone. Will AI make our appeals sound robotic. Will donors be able to tell. Will we lose the human touch. Those are fair questions and they are also the comfortable ones, because they are questions about writing, and everyone at a nonprofit has an opinion about writing.

The uncomfortable question is quieter. Right now, today, somebody on your staff is pasting something into a chatbot. Do you know who, and do you know what they pasted?

// THE GAP

What the gap actually looks like

The same survey found that 42% of nonprofits have exactly one or two people exploring AI. Only 3% have brought in outside help to make the decisions. Half of these organizations run on annual budgets under $500,000.

Put that together and you get a specific picture. AI at a small nonprofit is not a program. It is a personal habit that two or three people picked up on their own, unevenly, with no shared standard, using whatever free tier they signed up for on a Tuesday. The development director has one workflow. The comms person has a completely different one. Nobody has compared notes. Nobody has asked whether the donor list that got pasted into a summarizer is now sitting on a server nobody at the org can name.

That is not a human touch problem. That is a governance problem wearing the costume of an efficiency win.

And it is not solved by banning anything. The staff using these tools are not being reckless, they are being resourceful, usually because they are three people doing the work of six. Take the tools away and you get the same behavior with worse hiding. The answer is not less AI. It is somebody owning the map.

// ORDER OF OPERATIONS

Write the policy second, not first

Here is where I disagree with most of the advice on this topic. The standard recommendation is to write an AI use policy, then adopt carefully. I think that is backwards for an organization your size, and I think it is why so many of these policies never get written.

A policy written before you have used anything is a guess. It will be either so vague it does nothing or so strict it gets ignored by week three. Meanwhile the work of drafting it falls on whoever is least busy, which at a nonprofit is nobody.

Do it in this order instead:

  • Pick one recurring, boring, low-stakes task. Meeting notes into summaries. Event photos into caption drafts. Last quarter’s donor spreadsheet standardized into something you can actually sort. Something where a human reads the output before anyone outside the building sees it.
  • Automate that one thing and run it for a month. Not a pilot program. One task, one person, four weeks.
  • Then write the page. By now you know which tool you actually use, what data touched it, where it was wrong, and who caught the error. The policy writes itself out of that experience, and it fits on one page, because it is describing something real.

One page is genuinely enough at your scale. Which tools are approved. What data never gets pasted anywhere, and for most nonprofits that list starts with donor records, beneficiary information, and anything a board member said in a closed session. Who reviews output before it goes to a donor. Where you say out loud that AI helped. Sign it, date it, revisit in six months.

// THE LINE

The line worth defending

The advice to automate the mundane and protect the meaningful is right, it is just soft on where the line sits. Here is a sharper test.

Automate anything where a human reads the output before it leaves the building. Never automate anything where a donor would feel deceived if they found out. A first draft of an appeal is fine, because you edited it and you signed it. A quote you attribute to a beneficiary is not, ever, under any circumstance, because that is not a writing shortcut, that is putting words in someone’s mouth. Same with impact numbers. Same with a thank-you that reads like it came from a person who remembered something specific about that donor when nobody did.

The touch you are protecting is not the prose. It is the truth of the claim.

// WHERE I FIT

Where I fit

I run the operations side of this for small organizations in California. Finding which three workflows are eating the hours, building the one with the cleanest inputs, training somebody internal to own it, and writing the short version of the rules from what we learned doing it.

One example. The Apartment Association of Greater Los Angeles is a trade association representing rental housing providers, and it was moving its rental forms library off fillable PDFs onto a real forms platform. They wanted to know whether members were actually making the switch. So we built a dashboard that reads their live membership data alongside the weekly platform usage reports and shows who has moved and who has not. Their leadership team uses it to steer the rest of the rollout. Nothing about it is exotic. It reads data they already had and puts it somewhere a person can act on it.

For an organization with no idea what its current AI surface even looks like, the entry point is an AI Stack Audit. Every tool you pay for and what to cut, where the manual hours actually go, a ranked list of what to automate first, and a one-page answer to the question your board is going to ask about donor data. It runs about a week and it usually pays for itself out of software you did not know you were still subscribed to.

Details on the AI Architect page. Or the contact page if you would rather just describe the mess and see what I say.

Figures from The State of AI in Nonprofits 2025, TechSoup and Tapp Network, surveying roughly 1,000 nonprofit professionals.

Does AI know your business exists?

// JOURNAL · BUILD / YEAR 10 SD

Does AI know your business exists?

People have started asking AI assistants the questions they used to type into Google: who should I hire, what should I buy, is this company legit. The businesses those AIs can read and recognize get named in the answer. Everyone else is invisible, and never finds out. Here is how that works mechanically, and the free tool I built so you can see where you stand in about ten seconds.

// THE SHIFT

The channel is small, fast-growing, and pre-sold

Honest numbers first. AI referrals are still a small slice of web traffic: about 1% of all visits across ten industries in Conductor’s 2026 benchmark study, with ChatGPT driving 87% of them. Nobody serious is telling you Google stopped mattering.

But three things about that slice should have your attention:

  • It is compounding. One traffic study measured a 527% year-over-year jump in AI-referred sessions in the first five months of 2025, and the benchmark data shows steady month-over-month growth since.
  • It reaches people who never open ChatGPT. Roughly a quarter of Google searches now trigger an AI Overview, an AI-assembled answer sitting above the results everyone fought over for twenty years. AI-assembled answers are becoming the default reading experience of search itself.
  • The visitor arrives pre-sold. Someone who clicks through from an AI answer asked for a recommendation and got your name as the answer. That is a warmer lead than any blue link ever sent you.

The consultative categories are leading: legal, finance, health, insurance, small-business services. In other words, the exact questions where someone used to ask a friend for a referral, they now ask a machine. If your business lives on referrals and trust, this channel is aimed directly at you.

// WHY YOU’RE INVISIBLE

Three ways a business disappears from AI answers

When an AI assistant answers “who should I hire for X near me,” it works from two sources: what it already knows about businesses from training, and what it can read live when it goes out to check. A business drops out of both for boring, fixable reasons.

  • Your site blocks the AI crawlers. A robots.txt rule, sometimes set deliberately years ago, sometimes shipped by a security plugin, turns away GPTBot, ClaudeBot, or PerplexityBot at the door. The assistant cannot read your site, so it quietly recommends someone whose site it can read. You never see the rejection happen.
  • Nothing tells machines what you are. Structured data (Schema.org markup) is how a site says “this is a kitchen remodeler, in Orange County, here are the services” in a format machines trust. Without it, the AI has to guess from your marketing copy. It usually guesses vaguely, or moves on.
  • There is nothing to quote. AI answers are assembled from content that directly answers questions. A homepage that is four hero images and a slogan gives the model nothing to lift. The businesses that show up in answers are the ones whose sites read like answers.

None of this is visible to a human visitor. Your site can look great, load fast, and rank fine on Google while failing all three. That is what makes it dangerous: the failure has no symptoms on your side.

// THE TEST

I built a checker, and ran it on my own site first

I built a free tool that reads your homepage the way an AI system does. It checks twelve signals: whether the five major AI crawlers are allowed in, whether structured data identifies your business, whether there is question-and-answer content worth quoting, titles, readable text, sitemaps, the works. Then it does the part no checklist can fake: it asks a real AI assistant, on the spot, whether it recognizes your business.

I ran it on sonnenbergdesign.com before shipping it. Ten years of client work, a site I redesigned this spring, respectable Google rankings. The AI had never heard of me.

That result is the whole point. Ranking on Google and existing in AI answers are different achievements, earned through overlapping but different work. If a web designer’s own site fails the probe, assume yours might too, and spend the ten seconds finding out.

// WHAT TO DO

The fixes are boring, which is good news

Nothing on the fix list requires a subscription or a growth hacker:

  • Unblock the AI crawlers in robots.txt. Five minutes, if you know to look.
  • Add structured data that names your business, its location, and its services.
  • Write a real FAQ page answering the questions customers actually ask you, in plain language. This is the single highest-leverage page for AI answers.
  • Put readable text on your homepage. If it is mostly images, the machine reading it sees mostly nothing.
  • Add a sitemap and an llms.txt file so crawlers know what exists.

The overlap with good old-fashioned SEO is large, and that is fine. The difference is what you are optimizing for: not ranking in a list, but being quotable in an answer.

Start with the free check at aiscan.sonnenbergdesign.com. Instant read on screen, full findings emailed, no phone number, no spam. If you want the complete picture, the AI Visibility Review covers your whole site and live-tests real customer questions across ChatGPT, Claude, and Perplexity for a flat $500, credited toward the fixes if we do the work.

Sources: Conductor 2026 AEO/GEO Benchmarks Report (1.08% AI referral share, 87.4% ChatGPT share, 25.11% AI Overview trigger rate; via Search Engine Land, Nov 2025); Previsible 2025 AI Traffic Report (527% YoY growth in AI-referred sessions, Jan-May 2025; via Search Engine Land, Aug 2025). An automated visibility check is not a guarantee of placement in AI answers or search results; AI systems change frequently and results vary by tool, region, and question.

Understanding the Cost of Not Acting

// JOURNAL · OPERATE / YEAR 10 SD

Understanding the cost of not acting

Website accessibility claims are a numbers game for the attorneys who file them. Plaintiffs filed 3,117 of these lawsuits in federal court in 2025, a 27% jump in one year, and most of the businesses on the receiving end are small. Here is what the numbers look like from the owner’s side, and why the cheap move is acting before the demand letter shows up.

// THE NUMBERS

The claims are up 27% from last year and they target small businesses

Start with the count. 3,117 website accessibility lawsuits were filed in federal court in 2025, up 27% from the year before. Add state-court cases and the total passes 5,000. Thousands more demand letters go out every year and never become public filings, which means the lawsuit counts are the visible part of a bigger iceberg.

These are not suits against Fortune 500 brands. Industry reports consistently find that most defendants are small and mid-size businesses, because they are the ones least likely to have fixed anything. And filing has gotten dramatically cheaper for the other side: roughly 40% of 2025’s federal filings were filed without an attorney, with plaintiffs increasingly using AI tools to find violations and draft complaints. A scanner finds the errors, a template turns them into a claim, and the plaintiff never has to visit your business. Your website is the storefront they inspect.

// CALIFORNIA

The quiet federal numbers here are misleading

California showed only a handful of federal filings in 2025, and it would be easy to read that as low risk. What actually happened is that the activity moved to state court. California’s Unruh Civil Rights Act carries minimum statutory damages of $4,000 per violation plus attorney’s fees, which makes state-court claims and pre-suit demand letters the preferred play here, especially against businesses with physical locations. If you run a California business with a public website, the exposure did not go away. It changed venue.

// THE PRICE TAG

What it actually costs

Public court records and legal industry reports put the typical resolution costs in these ranges:

How it resolves Typical range Typical outcome
Demand letter settlement $1,000 – $25,000 ~$5,000 average
Out-of-court settlement $5,000 – $150,000 ~$30,000 average
Defending a suit, even winning $5,000 – $125,000 legal fees, no damages
Court judgment $10,000 – $500,000 ~$85,000 average

Two things make those numbers worse than they look. First, settling does not fix your website. You pay the settlement and then pay for the remediation anyway, sometimes on a court-supervised deadline instead of your own schedule. Second, businesses that settle without fixing the site are documented repeat targets: nearly half of 2025’s federal filings named companies that had been sued before.

// THE WIDGET TRAP

Why an accessibility widget won’t save you

The one-line “accessibility overlay” widgets that promise instant compliance have become a liability of their own. Sites running overlays keep getting sued, and in January 2025 the FTC reached a $1 million settlement with a prominent overlay provider for misleading businesses about what the widget could actually do for compliance. Real protection is fixing the code, not layering a script over it. That is the position I take with every client site I touch: no overlays, fixes at the source, changes that hold up if anyone ever looks.

// ACTING EARLY

What acting early looks like

Compare the table above to the cost of getting ahead of it:

  • Free: an automated check of your homepage, which finds the same machine-detectable errors a plaintiff’s scanner finds. Instant results on screen, full findings by email.
  • $500 flat: a full-site Website Accessibility Review. Every page scanned, human review, a plain-English risk summary, and a prioritized fix list your developer can act on. If you move ahead with fixes through me, the $500 is credited toward the remediation work.
  • From $250/month: ongoing monitoring and remediation, so the site stays clean instead of drifting back into risk.

The entire ladder, end to end, costs less than the average demand-letter settlement. And unlike a settlement, it leaves you with a website that works for everyone, which was the point of the law in the first place.

Run the free check to see where you stand in about 30 seconds, or book 15 minutes and I’ll walk you through it.

Sources: Seyfarth Shaw’s ADA Title III litigation tracking (2025 federal filing counts, state data, pro se share); the Accessibility.build lawsuit tracker (settlement and defense cost ranges, FTC overlay settlement); UsableNet annual reports (combined federal and state totals). California Unruh Act statutory damages: Cal. Civ. Code § 52. This article is general information, not legal advice, and does not guarantee prevention of claims. Consult qualified legal counsel regarding ADA, website accessibility, and California disability-access obligations.

Your small org doesn’t need a Chief AI Officer. It needs an operator.

// JOURNAL · OPERATE / YEAR 10 SD

Your small org doesn’t need a Chief AI Officer. It needs an operator.

IBM’s 2026 study put Chief AI Officer hiring at 76% of large companies. The buried stat is the 61-point gap between employees who could use AI and the ones who actually do. For organizations too small to justify a $250K CAIO hire, that gap is bigger, not smaller.

// THE BURIED STAT

What the headline misses

IBM surveyed 2,000 CEOs at companies pulling roughly $5.8B in revenue. Three quarters of them are hiring a Chief AI Officer this year. Two years ago, only one in four had even thought about it. The headlines wrote themselves. Every consultant within a thousand miles of LinkedIn is updating their bio to include “AI strategist” by the end of the week.

That’s not the interesting number in the report.

The interesting number is buried two pages in. Inside those same companies, 86% of employees have the skills to use AI today, or could pick them up with a little training. Only 25% actually use it in their daily work. Sixty-one points of gap between “could” and “do.” That gap isn’t a skills problem. It’s an operations problem. Nobody is walking around the building connecting the people who can use AI to the workflows that actually need it.

If you run a small organization in California, here’s what I want you to take from that report: the gap is bigger at your size, not smaller. You don’t have a $250,000 Chief AI Officer line item in your budget. You probably don’t have a director of anything. What you have is a handful of people doing the work, a handful of recurring workflows that eat hours every week, and a vague pressure to “do something with AI” before the board asks again.

Hiring a CAIO is not the answer. The job doesn’t fit your shape. But the work of a CAIO absolutely does, and it’s the work nobody on your team is going to spontaneously volunteer for.

// THE WORK

What that work actually looks like

Walk the floor for a week. Find the three workflows that bleed the most hours. Pick the one with the cleanest inputs and outputs. Build a working automation in two weeks, not six months. Hand it to the person whose job it touches and watch what they do with it. If it sticks, train one internal champion to run it. If it doesn’t, kill it without ceremony and pick the next one.

That’s the job. It’s unglamorous, it’s iterative, and it’s the only thing that closes the 61-point gap. The strategy decks come later, after the team has watched something actually work.

Most small orgs don’t do this because the person who would do it doesn’t exist on the org chart. Your operations lead is buried in operations. Your marketing lead is buried in marketing. The CEO doesn’t have the technical fluency, and the IT vendor doesn’t have the operational context. So the workflows stay manual, the pressure stays, and AI stays a slide in a board deck.

// THE LEVERAGE

What I do here

I spent the last ten years building and running brand systems for small California organizations. The last two years I’ve been quietly running a different stack underneath all of it: n8n, Claude, and a tight loop of automations that handle the unglamorous parts of every retainer I ship. That’s what makes hosting and maintenance work at a small-org price point. Me at the front, Claude in the back, both of us pointed at the same workflow.

I do that work for myself every day. I also do it for clients. A pizza chain with hundreds of locations runs an inbound-feedback pipeline I built that triages thousands of emails a day with a human in the loop. An association runs a member-intelligence dashboard that flags renewal risk before it shows up in the renewal report. A real-estate brokerage runs an inbound-lead engine that captures voicemails, faxes, and form fills into a single queue.

None of those clients hired a Chief AI Officer. They hired the work of one, embedded into a monthly relationship, with a defined cadence and a working session they can put on the calendar.

// THE OFFER

The AI Architect

This is what I’m calling that offer now. When I first wrote this piece it launched as “AI Operator-in-Residence”; a client renamed it the AI Architect, and the client was right — you’re buying the person who owns the map and also swings the hammer. It’s a monthly engagement layered on a relationship where I run your systems. You get a named operator (me) plus monitoring of the automations already running in your stack, a recurring working session with your team and your designated AI champion, and new automations shipped on a defined cadence. Counsel is $500/month. Architect is $850/month and keeps one build track always moving, with a standing tech-stack cost analysis baked in. Embedded is $1,250/month for parallel tracks across multiple teams. Enterprise is custom for regulated industries. And if we’ve never worked together, the front door is a $750 AI Stack Audit: your tools, your spend, a cut list, and your top automation targets ranked.

The shape is deliberate. It’s not a 90-day sprint, because the work doesn’t end at day 90. It’s not pure advisory, because slide decks don’t close the 61-point gap. It’s a recurring operator presence, priced so a 20-person organization can actually afford it, anchored to the same maintenance-retainer relationship that keeps your site alive.

Full details, included scope per tier, and what’s not included on the AI Architect page.

If this sounds like the shape of the problem at your organization, the contact page is one click. The bigger point stands either way: the CAIO headline is real, but for an org your size, the real answer is an operator, not a title.

Twenty-five years of web tech, year by year

// JOURNAL · YEAR 10 SD

Twenty-five years of web tech, year by year

A working designer’s timeline through ASP, PHP, MySQL, WordPress, and whatever came next. 2001 to 2026.

// THE TABLE ERA (2001-2005)

The Table Era

2001. HTML hand-coded in a Notepad window. Classic ASP for anything dynamic. MySQL when data needs to persist. IE6 ships and refuses to die for the next decade. Tables nested inside tables for layout. XHTML 1.0 ratified.

2002. Mozilla 1.0. Movable Type blogs. Macromedia Flash is how you make a site feel “interactive.” ASP still dominant for server-side.

2003. CSS Zen Garden launches and proves you can build the same page two hundred ways with stylesheets alone. WordPress 0.7 ships and enters the toolkit as a blog install. Safari 1.0.

2004. Firefox 1.0. Gmail launches and makes Ajax mainstream. “Web 2.0” gets coined. PHP overtakes ASP for client work. LAMP becomes the default stack.

2005. YouTube. Google Maps drags the rest of the web into Ajax. Rails 1.0 starts the convention-over-configuration era. WordPress becomes the go-to CMS for content sites. Custom PHP and MySQL for anything bespoke.

// THE AJAX-AND-JQUERY ERA (2006-2010)

The Ajax-and-jQuery Era

2006. jQuery 1.0. Twitter. Facebook opens to the public. The DOM gets ergonomic for the first time. WordPress plus jQuery becomes the working setup.

2007. iPhone. WebKit goes mobile. Everything changes, but most sites don’t notice yet. WordPress is now the default for client builds. Classic ASP retires.

2008. Chrome 1.0 ships with V8 and the JavaScript engine arms race begins. Android launches.

2009. Node.js. HTML5 video. Server-side JavaScript stops being a joke.

2010. Ethan Marcotte publishes “Responsive Web Design” in A List Apart. iPad launches. CSS3 transitions and animations ship. Client themes get rebuilt responsive from the ground up.

// THE FRAMEWORK ERA (2011-2015)

The Framework Era

2011. Bootstrap 1.0. Sass goes mainstream. Every site starts looking the same on purpose. WordPress themes pick up a Bootstrap underlay.

2012. Retina displays. Flexbox enters the spec. Skeuomorphism peaks before falling off a cliff.

2013. iOS 7 ships flat design. React released. AngularJS rising. Component-driven UI becomes the conversation. WordPress page builders (Divi, Visual Composer) take off and enter the toolkit for faster client turnarounds.

2014. Google Material Design. ES6 specced. Web Components edge in.

2015. Vue.js. CSS Grid enters the spec. HTTP/2. The frameworks split into camps. WordPress powers roughly 25% of the web.

// THE JAMSTACK ERA (2016-2020)

The Jamstack Era

2016. “Jamstack” gets coined. Netlify rising. React wins. PWAs get pitched as “the future of the mobile web.” Jamstack gets tested on a few projects; WordPress wins out for client work, because content editors don’t want a git workflow.

2017. Headless CMS goes mainstream (Contentful, Sanity, Strapi). CSS Grid ships in browsers. Service workers everywhere.

2018. GraphQL adoption climbs. Gatsby, Hugo, Eleventy split the SSG market. Webpack pain peaks. WordPress Gutenberg block editor ships.

2019. Headless WordPress. Next.js gains share. The industry collectively names “JavaScript fatigue.”

2020. Pandemic forces every business online. Tailwind CSS hits mainstream. Vercel and Netlify own deploy. The client stack consolidates around WordPress on WP Engine, custom themes, and utility CSS.

// THE AI ERA (2021-2026)

The AI Era

2021. Web3 hype peaks and breaks. Astro launches. View Transitions API drafts.

2022. ChatGPT ships November 30 and the conversation pivots overnight. Tailwind owns CSS. LLMs enter dev workflows. n8n joins the stack for client automations.

2023. Copilot mainstream. Midjourney and DALL-E enter design briefs. Bun. React Server Components.

2024. Claude Code. Cursor. AI agents start writing production markup. CSS container queries finally ship. Claude joins the stack as a daily collaborator.

2025. Agent-driven workflows go from demo to production. n8n plus LLMs become a standard operations layer. Lovable and v0 let non-developers ship full apps.

2026. Where we are. WordPress is still the CMS under most client work. The orchestration around it (n8n, Claude, automation pipelines) is what’s new.

// THE PATTERN

What compounds

A new paradigm every 2.5 years on average. None of them killed the previous one. They stacked. The stack proves it: HTML from 2001 is still in everything. WordPress from 2003 still runs most of what ships. ASP got retired. PHP, MySQL, WordPress, jQuery, Bootstrap all live on, just covered over by newer layers.

The thing that compounds across all of it is operating discipline. Year 10 of running Sonnenberg Design is built on year 25 of building sites. Tools change every couple years. The studio compounds.