AI in charities: where the sector stands, and the guidance catching up with it
17 September 2026
- governance
- artificial intelligence
- data protection
- compliance
Adoption has run ahead of governance. The Charity Digital Skills Report 2026 found that 79% of charities now use AI in some form — most often for admin and project management (around 63%) and for fundraising and grant writing (around 45%). Yet the same report found that about half of charities have no AI policy at all, board and leadership AI skills are widely rated as poor, and most organisations lack a trustee with real digital expertise. In other words, the tools are already in the building; the guardrails often aren't. This article gives an honest read on where the sector stands, what the latest guidance says, and how to handle AI both as a user (your staff and volunteers) and as a buyer (the suppliers you get AI from). It is general information, not advice.
Where the sector actually stands
The headline is a gap. AI is delivering real efficiency for stretched charities — and the biggest barriers are the unglamorous ones: limited skills (cited by well over half), lack of training, and squeezed finances. Meanwhile:
- ~51% have no formal AI policy, so staff and volunteers use tools informally — often called "shadow AI" — with no agreed rules on what's acceptable.
- Governance lags use: a large share of boards and chief executives rate their own AI knowledge as poor, so the people accountable for the risk often understand it least.
- The appetite is there — building digital skills is a top priority for the year ahead — but funding for training is the pinch point.
None of this means "don't use AI." It means the sector is at the point where using it well, and buying it well, is now the task — not whether to use it at all.
The guidance is catching up
The UK's approach remains principles-based rather than a single AI Act, but the rules are firming up. Most significantly, the Information Commissioner's Office (ICO) is now required to produce a statutory code of practice on AI and automated decision-making, with its 2026–27 programme also promising dedicated guidance on "agentic" AI (tools that act, not just answer). The recurring questions regulators are pressing on are worth writing on a whiteboard:
- Who owns AI use in your organisation — who decided, who's accountable?
- Where does personal data flow when you use the tool?
- When do automated decisions affect people — and is that fair and explainable?
- What evidence sits behind human oversight — can you show a person is genuinely in the loop?
The Fundraising Regulator's first AI guidance
The most concrete new guidance sits in fundraising. Under the 2025 Code of Fundraising Practice (in force from August 2026), the Fundraising Regulator has published its first-ever guidance specifically on AI, taking a lifecycle view — exploring whether AI could help, preparing to implement it, and using it day to day. The points that matter most for trustees:
- You cannot outsource the liability. A charity is responsible for all AI use in its fundraising — including AI-generated output and work done by third-party agencies or fundraisers on its behalf. If an AI-written appeal misleads a donor, that is the charity's problem, not the tool's.
- Boards must actively engage. Trustees are expected to be part of the decision to adopt AI, not to let it arrive silently through staff or software.
- Do proportionate risk assessments to catch errors, bias and misleading outputs before they reach donors.
- Content standards apply. Anything AI helps produce must be accurate, legal, and something you hold the rights to use, with adequate human oversight throughout.
- Transparency is encouraged (not yet mandated): the Code encourages publishing an AI policy and being open with donors about AI use, scaled to how likely that use is to mislead them.
As a user: your staff and volunteers
- Get a simple AI policy. It needn't be long: what tools are approved, what data must never be pasted into a public AI tool, when a human must check the output, and who to ask. This is the single biggest gap in the sector, and the cheapest to close. (See using AI responsibly.)
- Keep a human in the loop. AI drafts; a person decides. Never let a tool make a decision about a person — a beneficiary, an applicant, an employee — without meaningful human review.
- Mind what goes in. Don't paste beneficiary details, safeguarding information, donor data or anything confidential into a general public AI tool. And remember AI gets things wrong and makes things up — check facts, figures and law before you rely on them. (AI is a tool, not a replacement.)
- Train people, including trustees. A board that can't ask good questions can't govern the risk.
As a buyer: the suppliers you get AI from
Much charity AI now arrives inside other software — your CRM, fundraising platform, email tool or case-management system quietly adds "AI features." Buying or switching one on is a procurement decision, and deserves the same due diligence as any other supplier (assessing partnerships to protect your organisation). Before you turn it on, ask the vendor:
- Where does our data go, and is it used to train their models? You often need to opt out of training.
- What can you show us on security, data location and sub-processors?
- How do we switch it off or leave — and get our data back?
- What human oversight and accuracy safeguards are built in, especially for anything touching people?
There are good, free procurement frameworks to lean on (for example the Local Government Association's "responsibly buying AI" guidance) — you don't have to invent your own.
And a pointed development this September: the Fundraising Regulator went a step further and told the advisers, trainers and vendors who sell AI into the sector to align their own materials with its guidance — because advice that ignores the Code can be incomplete or incompatible with it. The lesson for trustees is blunt: do not assume a supplier's AI advice is Code-compliant just because they are specialists. The accountability for an AI-driven Gift Aid appeal, legacy message or donor-segmentation decision stays with your charity and its board — never the supplier.
The data-protection point that hits faith charities hardest
Here is the one most likely to catch faith-based organisations. Charities routinely process special category data — and for faith organisations that includes the most obvious category of all: data about religious belief, often alongside health and other sensitive information. Using AI on that data — even a helpful summarising or sorting tool — will, in most cases, trigger the need for a Data Protection Impact Assessment (DPIA) before you start. Sector specialists are blunt that most charities have not done this. If you hold personal data and are adding AI to how you handle it, a DPIA and a check that you're properly registered with the ICO is not optional box-ticking — it is the law. (Start with protecting your data and the ICO.)
What to do now
- Write a one-page AI policy — the biggest, cheapest win.
- Do a DPIA before using AI on any personal or special category data.
- Put AI on the board agenda and make sure at least one trustee can ask the right questions.
- Treat AI features in your existing software as procurement — check the data flows before switching them on.
- Invest a little in training — it's the sector's number-one need for a reason.
Free templates to get you started
To make the two cheapest wins easy, we've prepared editable Word templates you can download and adapt:
- One-page AI Use Policy template — a plain-English AI policy for faith-based charities, ready to fill in and adopt.
- Data Protection Impact Assessment (DPIA) template — a step-by-step DPIA to complete before using AI on personal data.
Both are general templates to adapt to your own organisation, not legal advice.
AI genuinely helps organisations doing more with less, and the point is not to fear it. The point is that the technology has outrun the paperwork — and closing that gap is now simply part of good governance.
This article is general information, not advice. AI, data protection and procurement rules are developing quickly, and the right approach depends on your organisation and the data you hold. Check the current position, and if you'd like help putting an AI policy, a DPIA process or supplier due diligence in place, talk to us.