
Designing Informed Consent for AI Tools
- Categories TUTORIALS
- Date June 6, 2026
📖 Table of Contents
EvalCommunity Academy Practical Tutorial
Designing Informed Consent for AI Tools in M&E & International Development
A practical tutorial for M&E professionals, development practitioners, and humanitarian organizations. Learn to design informed consent processes that users can actually understand and act on — across languages, literacy levels, and cultural contexts.
Why This Matters for M&E & International Development
The Growing Gap Between Agreement and Understanding
As AI-powered tools become more common in development and humanitarian contexts, the gap between what users agree to and what they actually understand is growing. Terms and conditions are already difficult to navigate, and become even harder across different languages, literacy levels, digital access realities, and cultural contexts.
The consequences of sharing data without full understanding can be especially significant for global majority contexts, particularly for women, marginalized groups, and crisis-affected populations. In many settings, users have less access to legal protections and face greater risks if personal data is exposed, misused, or politically sensitive.
⚠️ Critical Risk: AI Inference
AI tools are increasingly used for survey data collection, real-time analysis, beneficiary verification, and outcome tracking. But AI models may also infer sensitive attributes (e.g., ethnicity, health status, political opinion) from seemingly neutral answers – even if you never asked for them. Informed consent must warn about inferred data.
For M&E Professionals
AI tools are increasingly used for survey data collection, real-time analysis, beneficiary verification, and outcome tracking. But are beneficiaries truly consenting to how their data is used — or just clicking “agree” to receive services?
For International Development
From refugee registration to agricultural extension services, AI-powered digital tools are transforming service delivery. Without meaningful consent, we risk creating new forms of exclusion, surveillance, and harm — especially for those with the fewest alternatives.
Key Concepts: Informed Consent for AI in Global Development
Understanding these five concepts is essential before designing any consent process.
1. Freely Given
Consent is not valid if users feel coerced or if refusing means losing access to essential services. In development contexts, power imbalances between service providers and beneficiaries are common and must be addressed.
2. Specific
Users must consent to each specific use of their data — not blanket consent for undefined future purposes. For M&E, this means separating consent for data collection, analysis, storage, and sharing with third parties (including government ministries).
3. Informed
Users must understand what they are agreeing to — including what data is collected, why, how it will be used, who can access it, how long it is kept, what risks exist (including re-identification risk), and that AI may infer sensitive attributes. This is the most challenging aspect across literacy, language, and cultural differences.
4. Unambiguous
Consent must be shown through a clear affirmative action — not pre-ticked boxes, silence, or inaction. In low-literacy contexts, verbal consent or gesture-based consent may be needed.
5. Revocable
Users must be able to withdraw consent as easily as they gave it, without penalty. In development programs, this requires clear, accessible withdrawal pathways (SMS, hotline, in-person).
Explore Examples: Informed Consent in Live AI Tools
Let’s examine how real AI-powered tools handle informed consent — and where they fall short for global majority users.
ChatGPT (OpenAI)
Consent approach: Account creation required, terms accepted without reading for most users. Data collected includes conversations, IP addresses, device info, and usage patterns.
⚠️ Gap for global development: No language localization for consent. ChatGPT does offer interface languages, but consent terms are still legally anchored to English-language policies. Users without email accounts cannot participate. Data retention unclear. No option for anonymous use.
💡 What this teaches us: Even leading AI tools fail to meet basic informed consent standards for low-literacy, low-connectivity, or multilingual contexts.
Simprints (Biometric ID for Development)
Consent approach: Uses visual consent cards, verbal scripts in local languages, and step-by-step explanations before fingerprint capture. Users can refuse without losing services.
✅ Strength for global development: Designed specifically for low-literacy, multilingual contexts. Field-tested with community health workers. Clear opt-out pathways. (Simprints public consent resources)
💡 What this teaches us: Visual aids, local language scripts, and facilitator-led consent can work effectively in development settings.
SurveyCTO (Mobile Data Collection for M&E)
Consent approach: Enumerators read consent scripts aloud. Respondents give verbal or written consent before starting surveys. Consent is recorded and auditable.
⚠️ Challenge for M&E: Consent is often treated as a one-time checkbox. Users may not understand data usage beyond the survey. Withdrawal pathways are rarely explained.
💡 What this teaches us: Audio/verbal consent works well, but ongoing consent and withdrawal options need improvement.
WFP SCOPE (Humanitarian Beneficiary Management)
Consent approach: Multi-language consent forms. Biometric data collection requires separate explicit consent. Data use is explained by registration staff.
✅ Strength for humanitarian settings: Recognizes power imbalances. Provides data protection impact assessments. Offers grievance mechanisms.
💡 What this teaches us: Consent must be meaningful even when there is a power imbalance between aid providers and beneficiaries.
✨ What “Better” Informed Consent Looks Like for M&E & Development
Based on the gaps identified above, here is a shared understanding of better consent:
Accessible
Available in local languages, with audio and visual options for low-literacy users. Works offline or with low bandwidth.
Specific
Separate consent for different data uses (collection, storage, sharing with government, third-party access). Users can choose.
Transparent
Plain language explanation of AI’s role, potential errors, data retention, real risks (including re-identification), and inference risks — not just benefits.
Choice-Full
Meaningful alternatives for those who decline (human support, anonymous use, partial participation, time-limited consent).
👶 Special Consideration: Children and Adolescents
Parent/Guardian Consent + Child Assent
When AI tools are used with children or adolescents, informed consent requires two layers: (1) permission from a parent or legal guardian, and (2) assent from the child or adolescent themselves at their developmental level.
Key requirements (informed by UNICEF guidance):
- Separate consent forms for guardians and age-appropriate assent forms for children
- Plain language and visuals for child assent (e.g., “This app will collect your answers to help us learn”)
- Clear statement that refusal will not affect access to services for the family
- Special protections for adolescents (13-17) who may have capacity to consent independently depending on local law and context
- Mechanism for children to withdraw assent directly, not only through guardians
📌 Example child assent language: “We are using a computer to help us ask you questions. The computer will remember your answers. You can say ‘stop’ anytime. Do you want to continue?”
Emergency and Humanitarian Exceptions
Modified, Not Waived
In some crisis contexts (e.g., Ebola contact tracing, earthquake response, active conflict), full informed consent may be challenging to obtain. However, consent requirements may be modified but never fully waived. Legitimate interest can justify data collection without explicit consent only when: (a) it is necessary for the emergency response, (b) no less intrusive alternative exists, and (c) users are still informed as much as possible given the circumstances.
Best practice in emergencies:
- Use verbal consent with a witness when written consent is impossible
- Provide a post-hoc information sheet as soon as feasible
- Document why full consent could not be obtained
- Establish a time limit for emergency data collection (e.g., 30 days) after which standard consent applies
- Allow opt-out even when opt-in is not feasible
- Conduct a Data Protection Impact Assessment (DPIA) for any emergency AI tool
Data Sharing with Government & Third Parties
Many M&E tools share de-identified data with government ministries, donors, or research partners. This requires separate, explicit consent — not bundled with general data collection consent.
Required disclosures for third-party sharing:
- Who will receive the data (name the specific ministry or organization)
- What specific data will be shared (e.g., “aggregated crop yield data, not your name”)
- Why they need it (e.g., “to plan agricultural extension services”)
- What protections exist (e.g., “they cannot re-identify you or share with others”)
- Opt-out option: “You can say yes to the survey but no to sharing with the government”
📌 Example consent language for government sharing: “The Ministry of Agriculture has asked us to share information about crop yields so they can plan better support for farmers. They will not receive your name or village — only general information. You can still take the survey even if you say no to sharing with the Ministry. Do you agree to share your answers with the Ministry of Agriculture?”
🔁 Practical Withdrawal Pathways
Users must be able to withdraw consent as easily as they gave it. Below are practical, field-tested withdrawal mechanisms for development contexts.
📱 SMS Withdrawal
User texts a keyword (e.g., “STOP” or “WITHDRAW”) to a shortcode. Automated response confirms deletion request and provides a reference number. Example: “Text STOP to 12345 to stop using this tool and request data deletion.”
📞 Hotline Withdrawal
Dedicated phone number (toll-free where possible) staffed during program hours. Caller provides their ID number and verbal confirmation. Example: “Call 0800-123-456 to speak with someone who can delete your information.”
🏠 In-Person Withdrawal
Users can visit a local program office or community health worker to request withdrawal. Especially important for low-literacy or offline contexts. Example: “Visit [local office name] and ask for [staff name] to delete your data.”
⚠️ Important: Always tell users what can and cannot be deleted. For example: “We can delete your survey answers and chat history. We cannot delete anonymous statistics that have already been combined with other data.” Also state how long withdrawal takes (e.g., “within 7 business days”).
Test and Critique: Three Prototype Approaches
Below are three prototype consent flows for an AI-powered M&E data collection tool. Test each one and critique which best supports real understanding and genuine choice.
📱 Prototype A: Minimalist Approach
Common in commercial apps
🔍 Critique for M&E & Development Contexts:
- ❌ Not accessible: Links to legal documents assume literacy and internet access
- ❌ Not specific: No explanation of what data is collected or how AI is used
- ❌ Power imbalance ignored: Users may feel they cannot refuse
- ❌ No choice granularity: All or nothing consent
- ⚠️ Result: Likely to fail meaningful consent standards in development settings
💡 Pragmatic guidance if you must use a minimalist approach due to constraints: Add at least one comprehension check question before consent. Example: “Before you continue, please confirm: This tool may collect your messages. Yes / No.” This simple check significantly improves understanding even in minimalist designs.
📱 Prototype B: Layered Visual Approach
Better for global development
Quick Summary (Layer 1)
This AI tool will collect your answers to help improve services. You can stop anytime. No penalty if you say no.
🔍 More Details (Layer 2) — tap to expand
What we collect: Your answers, your region (not specific address), type of assistance you receive
How AI is used: To analyze patterns and suggest service improvements. AI may make mistakes. AI may also infer information you did not tell us (e.g., approximate location from your answers).
Who can see it: Our M&E team. Separate consent required for sharing with government.
Data retention: Deleted after 12 months. You can request deletion anytime via SMS, phone, or in person.
Re-identification risk: Even with names removed, it may be possible to identify you from combined data. We take steps to minimize this risk.
📄 Full Policy (Layer 3)
Complete privacy policy available at the program office or by calling [local number].
✋ Your choices:
♿ Accessibility note for digital implementation: Ensure buttons have proper aria-label attributes for screen readers. Use aria-live="polite" regions for dynamic content updates. For mobile/web: <button aria-label="Yes, I agree to data collection">. Test with screen reader software (NVDA, VoiceOver) before deployment.
🔍 Critique for M&E & Development Contexts:
- ✅ Accessible: Layered approach reduces cognitive load
- ✅ Specific: Clear data categories and purposes explained
- ✅ Choice-full: Multiple meaningful options including anonymous use and time-limited consent
- ✅ AI inference warning: Now includes risk of inferred data
- ⚠️ Needs visual support: Add icons for low-literacy users (🔒 = data retention, 🤖 = AI role, 🗑️ = deletion, 🙋 = human support)
- ⚠️ Audio needed: Should include spoken version for non-readers
- M&E relevance: This approach is promising for digital data collection in diverse settings
👥 Prototype C: Facilitator-Led Approach
For low-literacy or offline contexts
Facilitator Script (read aloud to user):
“I am going to explain how this AI tool uses your information. Please stop me anytime if you have questions.”
“This tool will collect your answers to help us understand what services are working well. The tool uses AI, which means a computer helps analyze the answers. It might make mistakes.”
“You can say yes or no. If you say no, you can still receive services — we will use a different way to collect information. You can change your mind later.”
“Do you have any questions? Would you like to continue?”
📋 Minimum Facilitator Training Requirements:
- Never read the script monotonously — use natural pauses and eye contact
- Pause after explaining each risk to allow questions
- Observe hesitation (looking away, silence, body language) and ask “Is there anything you’d like me to explain again?”
- Practice responding to common questions without pressure or rushing
- Role-play with community members before field deployment
- Document refusals and reasons to improve the process
🔍 Critique for M&E & Development Contexts:
- ✅ Most accessible: No literacy required
- ✅ Relationship-based: Facilitator can answer questions and observe understanding
- ✅ Power dynamic acknowledged: Explicitly states no penalty for refusal
- ⚠️ Scalability: Requires trained facilitators, more time per user
- ⚠️ Consistency: Quality varies by facilitator training — see training note above
- 📊 M&E relevance: Gold standard for sensitive data collection or low-literacy populations
Which Prototype Works Best for Your Context?
| Criteria | Prototype A (Minimalist) | Prototype B (Layered Visual) | Prototype C (Facilitator-Led) |
|---|---|---|---|
| Low-literacy accessible | ❌ No | 🟡 With visuals + audio | ✅ Yes |
| Works offline | 🟡 Partial | 🟡 Requires cached assets (possible with PWA but not default) | ✅ Yes |
| Scalable to 1000s of users | ✅ Yes | ✅ Yes | ❌ No (needs trained staff) |
| Meaningful choice options | ❌ No | ✅ Yes | ✅ Yes |
| User understands AI risks | ❌ No | ✅ Yes | ✅ Yes |
💡 Recommendation: Use Prototype B for digital-first programs with mixed literacy. Use Prototype C for sensitive data, low-literacy populations, or when human oversight is critical. If you must use Prototype A, at minimum add a comprehension check question.
15 Steps to Design Informed Consent for AI Tools in M&E & Development
Follow these steps adapted from global data protection and humanitarian standards for monitoring and evaluation contexts.
Steps 1-5: Foundation
1. Define the AI tool and its users
2. Map what data the AI tool collects
3. Explain why each type of data is collected
4. Identify data risks (especially for vulnerable groups) — Include risk of re-identification (even from anonymized data) when using AI models that retain training data patterns.
5. Decide what choices users really have (including anonymous use and time-limited consent)
Steps 6-10: Design & Testing
6. Write the first consent message in plain language
7. Use layered consent (summary → details → full policy)
8. Explain the role of AI (it may make mistakes and may infer information)
9. Translate and adapt for local languages and literacy levels
10. Test with real users from your target population
Steps 11-15: Implementation & Monitoring
11. Add a consent checkpoint (comprehension check)
12. Make withdrawal easy and clearly explained (SMS, hotline, in-person)
13. Review consent for equity and safety (gender, displacement, children, emergency contexts)
14. Create the final consent flow with ongoing control options
15. Monitor and improve consent over time as the tool evolves
🚺 Gender-Specific Considerations for Consent
In many development contexts, women face additional barriers to giving free and informed consent. Design consent processes with these realities in mind.
Key considerations:
- Private consent options: In some contexts, women may feel unable to refuse consent in front of male household members, community leaders, or even male enumerators. Offer the ability to consent privately — separate room, female facilitator, or self-administered digital consent where safe.
- Separate consent for sensitive data: Women may face greater risks if data on reproductive health, income, or domestic circumstances is exposed. Obtain explicit, separate consent for any sensitive questions.
- No assumption of proxy consent: Do not assume a husband or male relative can consent on behalf of a woman. Each individual must consent for themselves.
- Safety planning: If data exposure could lead to harm, include a safety plan in the consent process (e.g., “If you are worried someone might check your phone, here is how to delete our messages.”)
📌 Example gender-sensitive consent language: “You can say yes or no to this tool without anyone else knowing your answer. We can speak privately if you prefer. No one will be told what you decide.”
⬆️ See sections above for Children & Guardians, Emergency Exceptions, and Government Data Sharing ⬆️
📖 Case Study: When Poor Consent Caused Harm (Anonymized)
Context:
A humanitarian organization deployed an AI-powered chatbot to provide legal information to refugees in a conflict-affected country. The chatbot collected location data and chat history to “improve responses.”
What went wrong:
The consent screen was a dense 500-word privacy policy in English, with a single “I Agree” button. Most users could not read English. They clicked “agree” assuming it was required to receive food assistance. The organization later shared anonymized location data with a research partner. Using AI, researchers re-identified individuals from the “anonymized” data based on travel patterns and chat content. Several refugees were subsequently targeted by state authorities based on their legal information requests.
Lessons learned:
- Consent must be in a language users understand — not just the interface, but the legal substance
- “Anonymized” data can often be re-identified, especially from vulnerable populations
- Users must know consent is optional and will not affect access to services
- Sharing data with third parties requires separate, explicit consent
(This case is a composite drawn from multiple documented incidents. Specific identifying details have been changed.)
❓ Common Objections: FAQ for M&E Practitioners
Q: “Our donor requires 95% consent rates — what do we do if we offer real choice and consent drops?”
A: High consent rates from coerced consent are unethical. Document refusal rates separately and explain to donors that meaningful choice will always result in some refusals. A 70-80% consent rate with genuine understanding is more valuable than 99% consent from users who felt unable to say no. Report both consent AND refusal rates in your M&E reports to demonstrate transparency.
Q: “We’ve already deployed our AI tool without proper consent. What can we do now?”
A: Implement a retrospective consent process as soon as possible. Contact users (using available contact information) to explain what data was collected, how it was used, and offer them the choice to continue or withdraw. If withdrawal is requested, delete their historical data where feasible. Document the remediation effort.
Q: “What if local authorities require us to share data without separate consent?”
A: This creates an ethical conflict. Advocate for data sharing agreements that protect users, including: (1) requiring a legal warrant or justified request, (2) sharing only anonymized or aggregated data where possible, (3) notifying users when data is requested (unless legally prohibited), (4) negotiating data retention limits. If these protections are impossible, consider whether the program can be implemented at all.
Q: “How do we handle consent when users have no phone or digital access?”
A: Use Prototype C (facilitator-led) with paper-based or verbal consent. Provide an information sheet users can keep. Offer in-person withdrawal pathways. Document consent using a signature (where appropriate and safe) or witness statement.
Final Practical Template: AI Consent Message for M&E
Before you continue, please read this short explanation.
This tool uses AI to help answer your questions. It may collect the messages you send and information you choose to share.
We use this information to provide responses, improve the service, and understand how the tool is being used.
Please do not share sensitive personal information unless it is necessary (e.g., national ID numbers, exact home coordinates, medical diagnoses).
This tool may sometimes give incomplete or incorrect answers. AI may also infer information you did not tell us (such as your approximate location or other patterns). You can ask for human support if needed.
You can choose to continue, ask for more information, or stop using the tool.
You can withdraw your consent later by: 📱 texting STOP to 12345, 📞 calling [hotline number], or 🏠 visiting [local office].
Saying no will not affect your access to services.
✓ Yes, for this session only
✓ Yes, but don’t collect my name
✗ No, I do not agree
ℹ Give me more information
🌐 Translations: This template should be translated into local languages by native speakers, not automated tools. For Spanish, French, Arabic, and other widely spoken languages, contact EvalCommunity Academy for community-contributed translations. Always back-translate to verify accuracy.
🖨️ One-Page Printable Checklist for Field Enumerators
Print this page and keep it with you during data collection. Do not proceed until all items are checked.
□ User knows they are interacting with AI
□ Consent message is in user’s local language
□ I have explained what data is collected and why
□ I have explained risks (including AI inference and re-identification)
□ User has seen the withdrawal methods (SMS/hotline/in-person)
□ I have explicitly said “No penalty if you refuse”
□ User has been offered private consent option (if relevant)
□ For children: Parent/guardian consent AND child assent obtained separately
□ For government data sharing: Separate consent obtained
□ User has passed a simple comprehension check
□ User’s consent decision has been recorded
□ I have answered all questions honestly and without pressure
📌 Enumerator signature: ___________________ Date: ___________
✅ Final Program Checklist for M&E & Development Practitioners
□ Users know they are interacting with AI
□ Consent message is in plain, local language
□ Data collection is clearly explained
□ AI inference risk is disclosed
□ Re-identification risk is disclosed
□ Data risks (especially for vulnerable groups) are visible
□ Users have meaningful choices beyond yes/no
□ Low-literacy users are supported (audio/visual)
□ Users can ask questions before consenting
□ Withdrawal pathways are clear (SMS, hotline, in-person)
□ No penalty for refusal is explicitly stated
□ Process tested with real users from target population
□ Gender and equity safeguards are included
□ Children and adolescents have separate consent/assent processes where required
□ Humanitarian emergencies have a documented protocol for modified consent
□ Government data sharing has separate explicit consent
□ Consent process is reviewed and updated regularly
🔑 Icon Key (for low-literacy and visual users)
Key Lesson for M&E & Development Professionals
Good AI consent is not about getting users to click “I agree.” It is about helping people understand what is happening, what risks exist, and what choices they have. Informed consent should create real choice, not just legal compliance.
Sources and Further Reading
This tutorial is informed by international guidance on data protection, responsible AI, humanitarian data responsibility, and ethical technology design.
Suggested Citation
This tutorial draws on established principles from data protection law, humanitarian data responsibility, responsible AI governance, and human-centered design. It is intended as an educational resource for evaluators, development practitioners, humanitarian organizations, and digital teams designing AI-enabled tools.
The courses and articles are developed by a team of experienced evaluators, collaborators, authors, and software developers, guided by Fation Luli. EvalCommunity Academy combines practical expertise in Monitoring & Evaluation and International Development with the latest advances in AI to create high-quality, accessible, and practical learning experiences for professionals worldwide.
