Time needed
90 minutes · 16 steps
What it takes
Nothing to install
What it costs
A free path exists
Last checked
2026-08-31
Careful with sensitive material
  • Grants and operations
  • Director or leadership
  • Documentation and monitoring
  • Drafting reports and advocacy material
  • Grants and admin
  • Protecting sensitive information
  • Making sense of large document sets
  • Translation into and out of local languages
These are instructions, not case studies

A recipe tells you what to do. It is not a report of something that already happened somewhere else. Nothing here claims that any organisation did this. It is written for you to do now, and every step tells you how to check it worked.

You have monitoring data with real names in it and a donor report due. Work from two files: a master that holds the truth and is never copied from, and a safe copy that is the only thing you ever paste into a chatbot. One paste from the wrong file cannot be taken back.

The safety line

What leaves your office: aggregated counts, banded numbers, governorate-level locations, month-level dates, paraphrased quotes, and your donor’s own boilerplate headings.

What must never leave: real names, exact dates, GPS points, case and ID numbers, direct quotations, and any original photo, scan or PDF. Files carry metadata you cannot see and cannot strip inside a chat window.

Never use this where re-identification could get someone detained, deported, disappeared or killed. If one sentence of your report could point a security service at one identifiable person, that sentence does not go into a chat box at all.

On Kurdish

Sorani is the weakest language here. Google’s own documentation places Kurdish outside its newer translation models. General assistants produce Sorani that reads fluently and carries broken agreement, invented vocabulary and confidently mistranslated legal terms. Never send Sorani output to a donor unread.

What happens to your information

Never use this for

Never paste raw testimony, witness or victim names, exact incident dates, GPS coordinates, case or ID numbers, and never upload the original case file, photo or scan, de-identify first, always, without exception. And never use any of this for a situation where re-identification could get someone detained, deported, disappeared or killed: if one sentence of your report could point a security service at one identifiable person, that sentence does not go into a chat box at all.

What leaves your device

Whose law it lands under · The fully offline option

Everything you type or paste into the chat box, plus every file you upload, plus your account email and IP address, goes to the vendor's servers. If you follow the two-file rule in this recipe, what leaves is only: aggregated counts, banded numbers, governorate-level locations, month-level dates, paraphrased quotes, and your donor's own boilerplate headings. What must never leave: the master file with real names, exact dates, GPS points, ID and case numbers, direct quotes, and any original photo, scan or PDF, files carry hidden metadata you cannot see and cannot strip inside a chat window. Both OpenAI and Anthropic keep a setting that lets your chats train their models. OpenAI's is "Improve the model for everyone" under Settings > Data Controls, Anthropic's sits in privacy settings, and Anthropic states that if you allow it, "we may retain your data in a de-identified format for up to 5 years in our model training pipelines." Neither help page we read states plainly what the default is, so assume training is ON until you have looked at the toggle with your own eyes. OpenAI's Temporary Chats "are deleted from our systems after 30 days", "aren't used to train our models" and are not saved in history; Anthropic's Incognito chats are likewise never used for training. Use those modes for this work.

Whose law it lands under

United States for ChatGPT (OpenAI), Claude (Anthropic) and Gemini (Google). Your text sits on US-controlled infrastructure, is reachable by US legal process, and gives you no practical remedy under Iraqi law. Mistral's assistant is the one mainstream option operated from France under EU law, which matters if your donor contract carries an EU or GDPR data clause. No mainstream assistant is hosted in Iraq or the KRI, and none of them is a confidential channel in the sense your protection colleagues mean the word.

The fully offline option

Yes, but it is hardware-gated and many of your laptops will not pass. LM Studio (lmstudio.ai) is free "for home and work use", installs like an ordinary app with no terminal, and runs open models such as Gemma 3 entirely offline. Nothing leaves the machine, so in principle you could draft from un-redacted notes. Published minimum requirements: on Mac, Apple Silicon (M1/M2/M3/M4) with macOS 14.0 or newer, 16GB+ RAM recommended, and Intel Macs not supported at all; on Windows, AVX2 CPU support, 16GB RAM recommended, 4GB+ dedicated VRAM recommended; on Linux, Ubuntu 20.04 or newer. An older 8GB Windows laptop will either refuse or run so slowly it is useless for a report. The honest trade-off: the small models that fit on a laptop write noticeably weaker English than ChatGPT or Claude, weaker Arabic still, and Kurdish Sorani badly. Google's own Gemma 3 card claims "multilingual support in over 140 languages" while admitting "a limitation of our evaluations was they included only English language prompts", so treat any non-English quality claim as untested. Our recommendation stands: de-identify properly and use a free cloud tool, rather than run a weak local model over raw testimony and trust what comes out.

What it costs

Paying for this from Iraq

Availability is fine; payment is the problem. Iraq appears by name on OpenAI's official supported countries and territories list (Iceland, India, Indonesia, Iraq, Ireland, Israel, Italy) and on Anthropic's supported countries list for both Claude.ai and the API, neither service geo-blocks you, and you should not need a VPN to sign up. But a supported country is not the same as a working card: Iraqi-issued Visa and Mastercard, including most local bank and Qi Card products, are frequently declined by these vendors' payment processors, and no vendor page documents which Iraqi cards succeed, so we could not verify it. Do not budget for a subscription you cannot actually buy. Routes that have worked for MENA NGOs: a card issued by a partner or fiscal sponsor abroad, an international prepaid or virtual card, or asking the donor to cover the cost through a partner's account. Note also that Syria and Iran are NOT on OpenAI's supported list, relevant if a colleague travels or works cross-border.

The free path

If you pay

Yes, the whole recipe runs on free accounts. ChatGPT Free, Claude Free and Google Gemini's free tier all allow the text chat this recipe needs, at USD 0. The catch is that none of the three publishes an exact free limit any more. OpenAI's Free-tier FAQ says free users get "unlimited everyday text chats, subject to abuse-prevention safeguards" but that "advanced functionality, including data analysis, file uploads, and image creation, can have stricter limits than paid plans." Claude's pricing page says only "Usage limits apply" and that Free gets roughly half the weekly limits of Pro. Google states limits only in relative terms, "Without an AI plan: Standard limits", "AI Plus: 2x", "AI Pro: 4x", and that "Your limit refreshes every 5 hours until you reach your weekly limit." Practical meaning: one donor report fits comfortably inside a free tier; a whole afternoon of drafting three reports does not. If you are cut off mid-draft, wait about five hours, or move to a second free tool. Because no vendor publishes numbers, plan to be interrupted and keep your draft in your own document, never in the chat window.

If you pay

USD 0 for the recipe as written. If you later want higher limits: Claude Pro is USD 17/month billed annually or USD 20/month billed monthly (claude.com/pricing, checked August 2026); Mistral's assistant Pro plan is USD 14.99/month, with a student rate of USD 5.99/month (mistral.ai/pricing); Google's paid tiers are region-priced, the page served to us quoted Turkish lira, so check the price actually shown to you in Iraq before assuming a USD figure. None of this is required.

Before you start

  • Your monitoring data in whatever form you already keep it, spreadsheet, Word file, incident log, or a notebook you can type from.
  • The donor's report template or call document: exact section headings, word limits, and the logframe or indicator list if there is one.
  • A laptop or phone with internet and an email address for a free account. No credit card, no installation, no terminal.
  • One quiet hour where nobody interrupts you, because the de-identification step is the part that must not be rushed.
  • One colleague who knows the cases well enough to recognise a person from a description. You need ten minutes of their time at the end.
  • If your monitoring data sits under a donor confidentiality clause or a protection-team data-sharing rule, read that clause before you start. Some clauses forbid transfer to third-party processors outright, and no amount of de-identification cures that.

The steps

This recipe does not publish a separate check for each step. Use the whole-recipe check below before you rely on the result.

  1. Step 1 / 16

    Before you open any AI tool, put two documents side by side on your computer. Name them exactly as shown. The first holds the truth. The second is the only one you are ever allowed to copy from.

    Copy this exactly

    REPORT-MASTER-DO-NOT-SHARE.docx
    REPORT-SAFE-TO-PASTE.docx
    Note

    This one habit is the entire recipe; everything else is detail. Keep the master file where you already keep sensitive material, the same encrypted drive or locked folder your protection policy already names. Never have a browser tab and the master file open at the same moment when you are tired. That is how names get pasted.

  2. Step 2 / 16

    Copy your monitoring data into the SAFE file. Then build a small code key at the top of the MASTER file only, so you can still trace every claim back after the AI has finished. The key never goes in the safe file.

    Copy this exactly

    P1 = [real name, real case number]
    P2 = [real name, real case number]
    L1 = [real village / neighbourhood]
    L2 = [real village / neighbourhood]
    D1 = [real date, e.g. 14 March 2026]
    Note

    In the safe file the people become P1 and P2 and the places become L1 and L2. You keep full traceability for your own audit trail and for a donor verification annex, but the key never crosses the internet.

  3. Step 3 / 16

    Now run the de-identification checklist over the SAFE file, top to bottom. Remove or replace every item in this list. Do not skip a category because it looks harmless, re-identification works by combining harmless things.

    Copy this exactly

    1. NAMES: every one. Survivors, witnesses, families, your own staff, drivers, interpreters, fixers, named officials, named soldiers, named lawyers, named doctors. Replace with P1, P2, "a witness", "a lawyer".
    2. EXACT DATES: replace with the month, the quarter, or "early 2026". A date plus a district identifies an incident everyone locally remembers.
    3. EXACT PLACES: no village, neighbourhood, street, checkpoint, camp block, school or clinic name, no GPS coordinate. Go up to governorate, or "a district in Nineveh governorate".
    4. DISTINGUISHING DETAILS: occupation, disability, injury, scar, tattoo, clothing, vehicle, tribe, family size and composition, "the only teacher in the village", "the pharmacy owner", "the family that returned from Turkey".
    5. SMALL NUMBERS: see the next step.
    6. DIRECT QUOTES: a quote is a fingerprint. Paraphrase in your own words, and never paste a testimony transcript.
    7. IDENTIFIERS: case and file numbers, ID and ration card numbers, phone numbers, emails, social media handles, vehicle plates.
    8. YOUR SIDE: names of partner organisations, field monitors, safe houses, shelters, referral clinics, and any office address.
    9. FILES: do not upload the original document, photo, scan or PDF. Photos carry GPS and camera metadata; PDFs carry author names and edit history. Type or paste cleaned TEXT only.
    Note

    Categories 4 and 5 are the ones people miss. Category 9 is the one that silently undoes the other eight, a single uploaded photo can carry the coordinates you spent forty minutes removing.

  4. Step 4 / 16

    Deal with small numbers separately, because this is where documenters most often expose someone by arithmetic. Replace every small count with a band, then check that no combination of categories narrows to one person.

    Copy this exactly

    RULE: any count of people below 10 becomes a band, never an exact number.
    1-9  becomes  "fewer than 10"
    10-24 becomes "between 10 and 25"
    
    Then re-read every sentence and ask: does any COMBINATION point to one person?
    BAD:  "3 women in Sinjar district reported X; 1 was a widow with a disabled child."
    BAD:  "Of the 4 cases in the camp, 2 involved Christian families."
    GOOD: "Fewer than 10 women in Nineveh governorate reported X, including cases involving heads of household caring for dependants with disabilities."
    Note

    The arithmetic attack is simple. If you report 4 cases, then elsewhere say 2 were from one minority group and 1 involved a wheelchair user, anyone working in that camp knows exactly who all four are. Cross-tabulating small cells is the most common re-identification failure in human rights reporting. If a category holds fewer than 10 people, do not break it down by anything else.

  5. Step 5 / 16

    Read the SAFE file once more, out loud, pretending you are a hostile security officer who works in that district and wants to know who talked. If you can name anyone, cut more. Then have a colleague who knows the cases do the same for ten minutes.

    Note

    You will lose some vividness. That is the correct trade. A donor report saying "a returnee family in Nineveh" and safe is worth more than one saying "a returnee family in Hardan village" and not. If the donor genuinely needs exact detail, it goes in a separate annex through your normal secure channel, never through a chat box.

  6. Step 6 / 16

    Open your chosen free tool and turn off model training BEFORE you paste anything. Do this once per account; it does not carry across accounts or across colleagues' logins.

    Copy this exactly

    ChatGPT: profile icon (top right) > Settings > Data Controls > turn OFF "Improve the model for everyone"
    Claude: profile icon > Settings > Privacy > turn OFF the model-improvement / training setting
    Gemini: profile icon > Gemini Apps Activity > turn it off
    Note

    Neither OpenAI's nor Anthropic's public help page states plainly whether this is on by default, so look at the toggle yourself. Anthropic's help centre says that if you do allow training, "we may retain your data in a de-identified format for up to 5 years in our model training pipelines." Five years is longer than most grant cycles and longer than many protection risks last.

  7. Step 7 / 16

    Start the conversation in the private chat mode rather than a normal chat, so the text is not kept in your history and is not used for training.

    Copy this exactly

    ChatGPT: open the chat menu and choose "Temporary Chat"
    Claude: choose the Incognito chat option
    Note

    OpenAI states Temporary Chats "are deleted from our systems after 30 days", "aren't used to train our models" and do not get saved in history. Anthropic states Incognito chats are never used for model training. The cost is that you lose the conversation when you close it, which is exactly why step 12 tells you to move the draft into your own document as you go.

  8. Step 8 / 16

    First prompt: do not ask for a draft yet. Ask only for a map of your evidence onto the donor's headings, so you learn immediately where you have no evidence. Copy this text exactly and fill in the two blocks at the bottom.

    Copy this exactly

    I am writing a progress report for a donor, for a human rights organisation. Below are (a) the donor's required section headings and word limits, and (b) my de-identified monitoring data.
    
    Strict rules for everything you do in this conversation:
    - Use only the facts I give you. Do not add any number, name, date, place, quote or claim that is not in my data.
    - If a section has no evidence in my data, write [GAP: what is missing] and stop. Do not fill it in.
    - Do not turn an approximate number into an exact one. Keep the words "approximately", "at least" and "fewer than" exactly where I wrote them.
    
    For now, do NOT write any prose. Give me only an outline: which of my data points belongs under which donor heading, and a list of headings where I have no evidence.
    
    DONOR HEADINGS AND WORD LIMITS:
    <paste them here>
    
    MY DE-IDENTIFIED DATA:
    <paste from REPORT-SAFE-TO-PASTE.docx here>
    Note

    The [GAP] instruction is the most valuable line in this recipe. It turns the tool's biggest weakness, filling silence with plausible invention, into a to-do list for you. Expect real gaps. Finding them two weeks before the deadline is the actual win.

  9. Step 9 / 16

    Second prompt: draft one section at a time, never the whole report at once, and make it show its work by tracing every number back to your data.

    Copy this exactly

    Now draft section 1 only, in about <N> words, in plain professional English for a donor audience. Same strict rules as before.
    
    After the draft, add a section called SOURCE CHECK: list every number, date, place and organisation you used in the draft, and for each one quote the exact line of MY DATA it came from. If you cannot point to a line, mark it [INVENTED] and remove it from the draft.
    
    Mark anything you are unsure of as [CHECK].
    Note

    The SOURCE CHECK list is what makes verification take ten minutes instead of an hour. Anything the tool cannot trace back to your data is, by definition, something it made up. Work section by section, long single-shot reports drift furthest from the evidence and burn free-tier limits fastest.

  10. Step 10 / 16

    Third prompt: cut to the donor's word limit without losing your caveats. Word limits are where careful language quietly disappears.

    Copy this exactly

    Cut the text below to exactly <N> words or fewer. You must keep every number, every caveat word ("approximately", "at least", "fewer than", "reported", "alleged"), and every [GAP] and [CHECK] marker. Do not add anything. Show only the shortened version.
    
    <paste your draft>
    Note

    Watch specifically for "alleged" and "reported" being dropped. If your report states as fact something your monitoring recorded as an allegation, you have created a legal and protection problem for your organisation, not a style problem.

  11. Step 11 / 16

    If you drafted in Arabic or Kurdish and the donor needs English, do the translation in a SEPARATE chat, and demand translation only, not improvement.

    Copy this exactly

    Translate the text below into English for a donor report. Translate only: do not summarise, do not improve, do not add or remove anything. Keep every number and date exactly as written. If a term is ambiguous, give your translation and put the original word in square brackets after it.
    
    <paste your text>
    
    --- the same instruction in Arabic ---
    ترجم النص التالي إلى الإنجليزية لتقرير مانح. ترجمة فقط: لا تلخّص، ولا تُحسّن، ولا تُضِف ولا تحذف أي شيء. اترك الأرقام والتواريخ كما هي تماماً. إذا كان أي مصطلح غامضاً، ضع الكلمة الأصلية بين قوسين بعد ترجمتك.
    Note

    For Kurdish Sorani treat this output as a rough first pass only, and have a Sorani speaker check every sentence, see the language section for why. If the text going in is Iraqi dialect rather than MSA, expect kinship, tribal, checkpoint and land terms to come out wrong. Those are exactly the words that carry the meaning.

  12. Step 12 / 16

    Move every approved paragraph out of the chat window into your own document as you go. Do not keep drafting inside the chat.

    Note

    Two reasons. Free tiers cut you off without warning and no vendor publishes the exact limit. And private or temporary chat modes are designed to disappear. Losing ninety minutes of work to a rate limit is the most common way this recipe fails in practice.

  13. Step 13 / 16

    Mandatory human verification, part one: the number and name audit. Ask the tool to list its own claims, then check each one against your MASTER file yourself. This step is not optional and cannot be delegated to the tool.

    Copy this exactly

    List, as a plain numbered list, every number, date, place name, organisation name and factual claim that appears in the text below. Do not comment. Do not correct anything. Do not add anything.
    
    <paste your near-final draft>
    Note

    Take that numbered list to REPORT-MASTER-DO-NOT-SHARE.docx and tick each item against your real records. Anything you cannot tick gets deleted from the report, not softened, deleted. Expect to delete something. If you find nothing wrong on your first ever report, you checked too fast.

  14. Step 14 / 16

    Mandatory human verification, part two: run the hostile-reader test again on the FINAL text, because the AI's rewriting can re-identify people you had successfully protected.

    Note

    The tool sometimes 'improves' your careful vagueness back into specificity, naming the governorate's main city, guessing a month, merging two banded figures into one exact number. Read the final draft as the security officer again, and have the colleague from step 5 read it once more. This is the step that catches damage the AI itself caused.

  15. Step 15 / 16

    Decide the disclosure question before you submit, using the funder's own words rather than a rumour. Search the call document and the funder's website for "generative AI", "artificial intelligence" or "AI"; if there is nothing, email your programme officer and keep the reply on file.

    Copy this exactly

    Suggested one-line email to your programme officer:
    
    "Does your organisation require applicants to declare the use of generative AI tools in preparing an application or report? We use them for language editing and for English translation of text we have written ourselves, and we would like to follow your policy exactly."
    Note

    What we could verify in primary funder text, August 2026. EUROPEAN COMMISSION, the ERA Forum "Living guidelines on the responsible use of generative AI in research", third version, May 2026, tells funders to "Request transparency from applicants on their use of generative AI" and states that "Applicants declare if they substantially used generative AI tool(s) to prepare their application." The guidelines define "substantial" in their own footnotes: "using generative AI as a basic support tool for authors is not a substantial use", whereas "interpreting data analysis, carrying out a literature review, identifying research gaps, formulating research aims, developing hypotheses" can be substantial. The same document names "supporting non-native speakers in producing texts in multiple languages" as a legitimate, positive use. So: help writing YOUR OWN application in English is not what the disclosure rule is aimed at; having the tool generate your analysis or your aims is. NIH (United States) is the strictest we found: notice NOT-OD-25-132, effective for the 25 September 2025 receipt date onward, states "NIH will not consider applications that are either substantially developed by AI, or contain sections substantially developed by AI, to be original ideas of applicants", and caps a Principal Investigator at six applications per calendar year. OPEN SOCIETY FOUNDATIONS publishes nothing about AI on its grants pages, which is the normal situation for the funders most Iraqi CSOs actually work with, and exactly why you ask and keep the answer in writing.

  16. Step 16 / 16

    Write your organisation's rule down in one page today, while the reasoning is fresh, and put it where new staff will find it. Seventy-one percent of organisations like yours have no written AI rule, which means the rule is whoever is most tired at 11pm on deadline night.

    Copy this exactly

    Our rule, in five lines:
    1. Raw monitoring data, testimony, names, exact dates and locations never go into any AI tool. Ever.
    2. Only the de-identified SAFE file goes in, and only after a second person has read it.
    3. Model training is switched off and private/temporary chat mode is on, in every account we use.
    4. Every number and name in an AI-assisted draft is checked against the master file by a human before it is sent.
    5. If a funder asks whether we used AI, we answer honestly, and we say what we used it for.
    Note

    Print it. Tape it above the desk of whoever writes the reports. This page, not the software, is what protects the people in your files.

How to know the whole thing worked

Do three concrete checks before you send anything. FIRST, the traceability check: take the numbered list the tool produced in step 13 and tick every single number, date, place and claim against REPORT-MASTER-DO-NOT-SHARE.docx. Anything you cannot point to a line in your own records for gets deleted from the report. SECOND, the trap test, which shows you the failure mode with your own eyes: in the same chat, ask a question your data does not answer, for example "What was the average age of the people in the cases above?" when you never recorded age. A tool behaving correctly under these prompts answers [GAP] or says it does not know; if it produces a confident average, you now know exactly how it behaves when it has no evidence, and you will read the rest of the draft with the right suspicion. THIRD, the re-identification check: hand the final text to a colleague who knows the caseload and ask one question, "can you tell me who any of these people are?" If they can name even one, the report is not finished. Only when all three checks pass does the draft leave your office.

What goes wrong, and what to do about it

  • It invents a number that sounds exactly like your other numbers, "32 beneficiaries" when your record says 29. FIX: the SOURCE CHECK prompt in step 9 and the number audit in step 13. Never accept a figure you cannot trace to your own file.
  • It removes your caveats while shortening: "approximately 30 households reported" becomes "30 households were displaced", turning a report into an assertion. FIX: the word-limit prompt in step 10 protects caveat words explicitly; then search the final text for "alleged", "reported" and "approximately" and confirm each is still where you put it.
  • It re-identifies people you had protected, by helpfully adding specificity back, naming the main city of a governorate, guessing a month, merging two banded figures into one exact number. FIX: the hostile-reader test in step 14, run on the FINAL text and not only on your input.
  • You upload the original PDF, scan or photo "just this once" because retyping is slow. Files carry GPS coordinates, camera serials, author names and edit history you cannot see. FIX: paste cleaned text only, never a file. If a document is too long to retype, extract the text, clean it in your own document, then paste.
  • Small-cell arithmetic exposes someone even though no name appears: 4 cases, of which 2 from one minority group and 1 involving a wheelchair user, identifies all four to anyone working in that camp. FIX: the banding rule in step 4, and never cross-tabulate a category holding fewer than 10 people.
  • The free tier cuts you off mid-report and the private chat vanishes with your work inside it. FIX: move each approved paragraph into your own document immediately (step 12). If you are stopped, wait about five hours for the limit to refresh, or continue in a different free tool.
  • Kurdish Sorani output reads as fluent but is wrong, mixed Sorani and Kurmanji forms, invented vocabulary, mistranslated legal terms. FIX: never submit Sorani output unread; draft in Sorani, translate with a human, and use the AI only on the English or Arabic version.
  • Iraqi dialect field notes come back as MSA or Gulf phrasing, with kinship, tribe, checkpoint and land-tenure terms quietly changed. FIX: have an Iraqi Arabic speaker read every passage that started as dialect.
  • You put a subscription in a budget line and then the Iraqi card is declined at checkout, leaving a commitment you cannot deliver. FIX: keep this recipe on free tiers, and test any card before it appears in a proposal budget.
  • A colleague who was not in the room pastes raw testimony next week, because the rule lived only in your head. FIX: the one-page written rule in step 16.

How well it works in your language

Arabic (Modern Standard) · Iraqi Arabic · Kurdish (Sorani)

Arabic (Modern Standard)

Good, and the strongest of the three. Modern Standard Arabic is well supported by ChatGPT, Claude and Gemini for exactly the tasks here, restructuring your own text, drafting donor prose, and MSA-to-English translation. Expect a formal, slightly stiff register, which donors accept, and expect Arabic word counts to drift when you ask for a limit, so count the words yourself before submitting.

Iraqi Arabic

Workable as input, unreliable as output. Field notes in Iraqi, Baghdadi or Mosuli Arabic are usually understood well enough to be summarised, but the tools silently push output into MSA or Gulf and Levantine phrasing, and will occasionally mistranslate dialect terms for kinship, tribe, checkpoint and land tenure, precisely the words that carry meaning in a protection report. The evidence is thin by design: AraDiCE, the main Arabic dialect and cultural benchmark for LLMs (arXiv 2409.11404), builds its cultural evaluation for Gulf, Egyptian and Levantine regions, Iraqi Arabic is not among the covered varieties. Its authors report that Arabic-specific models beat multilingual ones on dialect tasks and that "significant challenges persist in dialect identification, generation, and translation." In short, nobody has properly measured how these tools handle Iraqi Arabic. Have an Iraqi Arabic speaker read every passage the tool touched.

Kurdish (Sorani)

Weakest by a wide margin, plan for a human translator. The clearest hard evidence comes from Google's own documentation: Kurdish (Sorani), code ckb, and Kurdish (Kurmanji), code ku, are supported only by the older Neural Machine Translation model and do NOT appear in the Translation LLM supported-languages table, meaning they are excluded from Google's newer LLM-based and adaptive translation engines. General assistants will happily produce Sorani text, but expect broken agreement and ezafe, invented vocabulary, mixed Sorani and Kurmanji forms, and confident mistranslation of legal and administrative terms. Never submit Sorani output to a donor unread. The safe pattern for a Sorani-speaking team: write your monitoring notes in Sorani, translate to English or Arabic yourself or with a colleague, and let the AI work only on the English or Arabic version.

What that rests on

Google Cloud Translation supported-languages documentation (cloud.google.com/translate/docs/languages), read August 2026: ckb and ku are listed under the NMT model only, not the Translation LLM. AraDiCE benchmark paper, arXiv 2409.11404: dialect and cultural coverage is Gulf, Egyptian and Levantine; Iraqi Arabic is absent. Gemma 3 model card (ai.google.dev): claims 140+ languages but states "a limitation of our evaluations was they included only English language prompts." We did not run our own controlled Arabic or Sorani evaluation for this recipe, the above are documentation and published-benchmark findings, and the specific judgements about Iraqi Arabic and Sorani prose quality are practitioner experience, explicitly untested.

Software named in this recipe

  • ChatGPT (OpenAI), free tier
  • Claude (Anthropic), free tier
  • Google Gemini, free tier
  • Mistral's assistant (branded Vibe on mistral.ai as of August 2026), free tier, EU-hosted
  • LM Studio, free, fully offline option
  • Gemma 3 (open model, for the offline option)
  • Google Translate / Google Cloud Translation (cited as language-support evidence only)

Sources

  • https://claude.com/pricing · Claude Free, Pro (USD 17/month annual, USD 20/month monthly) and Max plans; Free described only as "Usage limits apply", roughly half of weekly paid limits. Checked August 2026.
  • https://developers.openai.com/api/docs/supported-countries · Iraq listed as a supported country; Syria and Iran are not.
  • https://www.anthropic.com/supported-countries · Iraq listed as supported for both Claude.ai and the API.
  • https://help.openai.com/en/articles/9275245-chatgpt-free-tier-faq · what ChatGPT Free includes; "unlimited everyday text chats, subject to abuse-prevention safeguards"; stricter limits on file uploads, data analysis and image creation.
  • https://help.openai.com/en/articles/7730893-data-controls-faq · the "Improve the model for everyone" toggle and its click path; Temporary Chats deleted after 30 days, not used for training, not saved to history.
  • https://privacy.claude.com/en/articles/10023548-how-do-you-use-my-data-to-improve-claude-s-models · opt-out of training, Incognito chats never used for training, and "we may retain your data in a de-identified format for up to 5 years in our model training pipelines" if you allow it.
  • https://gemini.google/subscriptions/ and https://support.google.com/gemini/answer/16275805, free tier contents; limits stated only relatively (Standard / 2x / 4x), refreshing every 5 hours up to a weekly limit; "limits may change without notice".
  • https://mistral.ai/pricing · free plan with limited messages, Pro at USD 14.99/month (student USD 5.99), EU-operated.
  • European Commission, ERA Forum, "Living guidelines on the responsible use of generative AI in research", third version, May 2026, via https://research-and-innovation.ec.europa.eu/, "Applicants declare if they substantially used generative AI tool(s) to prepare their application"; footnote defining that "using generative AI as a basic support tool for authors is not a substantial use"; recommendation not to upload unpublished or sensitive work or third parties' personal data into external AI systems; "supporting non-native speakers in producing texts in multiple languages" named as a positive use.
  • https://grants.nih.gov/grants/guide/notice-files/NOT-OD-25-132.html · NIH: applications "substantially developed by AI" not considered original ideas of applicants; six-application cap per PI per calendar year; effective the 25 September 2025 receipt date and beyond.
  • https://www.opensocietyfoundations.org/grants · no published AI policy for applicants, checked August 2026.
  • https://cloud.google.com/translate/docs/languages · Kurdish Sorani (ckb) and Kurmanji (ku) supported by the NMT model only, absent from the Translation LLM supported-languages table.
  • https://arxiv.org/abs/2409.11404 · AraDiCE Arabic dialect and cultural benchmark: Gulf, Egyptian and Levantine coverage (Iraqi absent); "significant challenges persist in dialect identification, generation, and translation".
  • https://lmstudio.ai/ and https://lmstudio.ai/docs/app/system-requirements, "LM Studio is free for home and work use"; Apple Silicon with macOS 14.0+ (Intel Macs unsupported), or AVX2 with 16GB RAM and 4GB VRAM recommended on Windows, Ubuntu 20.04+ on Linux.
  • https://ai.google.dev/gemma/docs/core/model_card_3 · Gemma 3: "multilingual support in over 140 languages"; "a limitation of our evaluations was they included only English language prompts".

A CDR original, written for POINT Conference Iraq 7. Checked against vendor pages and package registries in August 2026; the sources are listed on this page.

What we could not verify

Five things we could not verify, and you should know about every one. FIRST, no funder text we could find uses the word "translation" in a disclosure rule. Our claim that translating your own application is generally not a declarable use rests on the European Commission's May 2026 guidelines, which limit the declaration to "substantial" use, define basic authoring support as not substantial, and name support for non-native speakers as legitimate. That is a reasonable reading, not an explicit exemption, and it covers EU research funding specifically, not every EU instrument and not your particular donor. Ask your programme officer in writing and keep the reply; that email is worth more than this paragraph. SECOND, the funders most Iraqi CSOs actually live on, NED, OSF, UN pooled funds, embassy small-grants schemes, GIZ, publish nothing about AI that we could locate; we checked OSF's grants pages and found no policy at all. Absence of a rule is not permission, it means you will be judged after the fact by whoever reads your report. THIRD, no vendor publishes real free-tier numbers any more. OpenAI, Anthropic and Google all describe limits qualitatively or relatively, and Google explicitly warns that limits may change without notice. We cannot tell you how many messages you get, and anyone who quotes you a number is guessing. FOURTH, on language we relied on documentation and published benchmarks, not on our own controlled test. The Kurdish Sorani finding is solid and documented, Google excludes ckb from its LLM translation engine, but our judgements about how the chat assistants handle Sorani prose and Iraqi Arabic dialect are practitioner experience, explicitly untested, and Iraqi Arabic is not covered by the main Arabic dialect benchmark at all, so nobody has published a measurement. Assume Sorani needs a human translator; assume Iraqi dialect needs an Iraqi reader. FIFTH, Iraqi payment. Iraq is officially supported by both OpenAI and Anthropic, so the services are not geo-blocked, but no vendor documents whether Iraqi-issued cards clear at checkout, and we could not verify it. Treat the free tiers as the only reliable path and test any card before you put a subscription into a budget. And one limitation that is not about tools at all: this recipe reduces the risk of exposing people, it does not remove it. De-identified text still leaves your office, still lands on servers in the United States, and still cannot be recalled. If a case is dangerous enough that a leak would be catastrophic, write that report yourself, offline, by hand.

All recipes