Skip to main content
    Insightful AI

    Responsible AI for Charities

    AI-enabled threats and cyber risk

    Your charity's staff learn to recognise deepfake fraud, voice cloning, and AI-enhanced phishing targeting your organisation, and leave with verification steps that work when a familiar face or voice can no longer be trusted.

    Duration
    Half day (3.5 hrs)
    Format
    In-house or online
    Group size
    Up to 15
    Investment
    £895 ex VAT

    £895 ex VAT

    Half day (3.5 hours)

    CEOs, operations directors, heads of IT, finance directors, and anyone responsible for business continuity or risk management.

    Request a booking

    This is a senior briefing for the people who authorise payments, manage sensitive data, and make decisions about cyber risk in your charity. Every session is built from scratch around your charity's tools, approved platforms, and sector. Participants leave with a repeatable verification method and documented training evidence for ICO (Information Commissioner's Office) and funder records.

    The threats your charity faces

    In 2024, a finance employee at Arup was persuaded to transfer approximately £20 million (US$25.6 million) to fraudulent accounts after a deepfake video call. A deepfake is synthetic video or audio created by AI to impersonate a specific person. That attack targeted a multinational. The same methods now target charities.

    Prevent Charity Fraud has warned that deepfake impersonation of senior charity leaders for mandate fraud is already happening in the charity sector. Mandate fraud is when a criminal impersonates a trusted person to redirect payments or transfers. Charity CEOs, chairs, and high-profile campaigners are impersonation targets because their faces and voices are publicly available.

    The National Cyber Security Centre (NCSC) found that AI gives criminals a significant uplift in social engineering and will make attacks more frequent and harder to detect (NCSC, 'Impact of AI on Cyber Threat from Now to 2027', 7 May 2025). Nationally significant cyber incidents rose from 89 to 204 year on year, with highly significant incidents up 50% (NCSC Annual Review 2025).

    The NCSC says charities are attractive targets for financial gain and access to sensitive information. Your charity holds donor data, safeguarding records, and grant payment systems. The Association of Charitable Foundations reports rising grant application volumes linked to AI tools and falling success rates, as criminals use AI to generate convincing but fraudulent applications. AI also enables fabricated beneficiary stories in fundraising content and social engineering at scale exploiting the trustworthiness of charitable brands.

    Standard annual cyber awareness training was written before these attack types existed. It teaches staff to spot spelling and grammar errors. AI-enhanced phishing (AI-written emails that are grammatically perfect and personalised at scale) removes those errors entirely. Phishing was the attack vector in 84% of UK businesses that detected a breach (DSIT Cyber Security Breaches Survey 2024).

    Who this course is for

    Designed for charity leaders, heads of IT, finance directors, safeguarding leads, and senior managers responsible for risk management and business continuity. The second strand of the course, covering safe use of AI tools, is also relevant to all staff and volunteers who handle charity data: 71% of UK employees have used AI tools their organisation has not approved, and 51% do so weekly (Microsoft, October 2025).

    Right for you ifNot right for you if
    Your charity handles grant payments, donor funds, or financial controls that could be targeted by mandate fraudYour main concern is personal data handling and ICO compliance evidence: see Responsible AI and Data Protection
    Staff use AI tools like ChatGPT without clear safe-use rules covering donor and beneficiary dataYou need AI governance policies and funder accountability structures: see AI Governance and Funder Accountability
    Your annual cyber awareness training was written before AI-generated attacks existedYou want to build AI literacy foundations first: see AI Fluency
    You need documented evidence of training for ICO accountability records or funder due diligenceYou are booking for a single person rather than a team
    Your charity's senior leaders are publicly identifiable by voice, image, or video
    Staff or volunteers use personal devices for charity work

    What participants will be able to do

    • Recognise deepfake video calls targeting charity leaders and apply out-of-band verification (confirming a request through a separate communication channel, such as calling back on a known number)
    • Identify AI-enhanced phishing that no longer contains the spelling and grammar errors staff were trained to spot
    • Apply verification steps for voice-based payment or data transfer requests, including voice cloning (where criminals copy a voice from a short audio sample to impersonate a CEO, chair, or finance director)
    • Use approved AI tools without leaking donor, beneficiary, or safeguarding data into external platforms
    • Recognise prompt injection, where criminals hide instructions inside content an AI tool reads, causing it to act on those instructions instead of the user's
    • Follow your charity's approved AI platforms and report unapproved tool use
    • Report a suspected attack and preserve evidence for investigation
    • Apply a repeatable verification method in day-to-day work across all communication channels

    What the course covers

    Recognising attacks against the charity

    How AI-enabled fraud works when it targets charities, and what verification habits stop it. Topics include deepfake video and image fraud used to impersonate charity leaders in video calls to authorise payments; voice cloning used to impersonate a CEO, chair, or finance director on the phone; AI-enhanced phishing written without the errors that used to flag a suspicious message; AI-assisted grant application fraud; AI-generated fundraising content that misleads donors or fabricates beneficiary stories; and social engineering at scale exploiting the public trust that charitable brands carry.

    The strand teaches process controls that provide defence: out-of-band verification, dual authorisation on payments, and approval steps that do not depend on identifying a face or a voice.

    Using AI tools safely

    What staff and volunteers can and cannot do with tools like ChatGPT, Microsoft Copilot, and similar platforms when working with charity data. Topics include prompt injection, data leakage through AI queries (staff feeding safeguarding details, donor records, or HR information into free AI platforms), and the secure handling of charity data in AI environments.

    Every scenario reflects the tools the charity uses or has approved. The NCSC has stated that prompt injection "may never be totally mitigated" (NCSC, 'Prompt injection is not SQL injection (it may be worse)', 8 December 2025). Staff need to understand the risk, not assume the technology will handle it for them.

    How the course is delivered

    1. Discovery call. We start with a call to understand your charity's approved AI tools, sector, policies, and the specific roles attending. This shapes every scenario and example in the session.
    2. Bespoke delivery. The session runs in-house or online, for up to 15 participants. All materials are written for your charity. No generic slides, no recycled content.
    3. Compliance documentation. After the session, you receive documented evidence of training completion meeting ICO expectations, and we share all session materials with your charity.

    What is included

    • A pre-course discovery call
    • Bespoke course materials, written around your charity's tools, sector, and approved platforms
    • A method guide participants keep and use after the course
    • Documented evidence of training completion meeting ICO expectations
    • All session materials shared with your charity afterwards
    • A follow-up call after the course
    • A certificate of completion on request, at no extra charge

    How this course aligns with UK and EU regulation

    DSIT Code of Practice for the Cyber Security of AI

    Published 31 January 2025 by DSIT with the NCSC. Voluntary, not a legal duty. Principle 1 states an organisation's cyber security training "shall include AI security content", reviewed as new threats emerge. This course addresses both of Principle 1's requirements: the AI-specific threats staff face, and the safe use of AI tools within the organisation.

    UK GDPR and ICO accountability

    Article 5(2) of the UK GDPR requires organisations to demonstrate compliance with data protection law. The ICO's data protection audit framework expects organisations to maintain all-staff training programmes with documented completion records. This course produces documented evidence that meets those expectations.

    EU AI Act Article 4 (AI literacy)

    For charities with EU exposure (serving EU beneficiaries, partnering with EU-based organisations, receiving EU funding, or operating programmes in EU member states), Article 4 of the EU AI Act (Regulation (EU) 2024/1689) creates a direct obligation to ensure staff involved in AI operations possess sufficient AI literacy, in force since 2 February 2025. For UK-only charities without EU exposure, Article 4 is not binding; it reflects the direction UK regulatory expectations are moving.

    Charity Commission and Fundraising Regulator

    The Charity Commission's April 2024 position states trustees must ensure human oversight and must not delegate decision-making to AI without reasonable independent checks. The Fundraising Regulator's December 2025 guidance requires charities to understand how AI tools use, store, and share data, and says trustee boards must be involved in strategic AI decisions with ongoing oversight.

    Economic Crime and Corporate Transparency Act 2023

    For charities meeting at least two of three statutory thresholds (more than 250 employees, more than £36 million turnover, more than £18 million balance sheet total), the Act's "failure to prevent fraud" offence makes staff training part of the reasonable procedures that form a defence. Most charities will fall below these thresholds. Check against your charity's accounts.

    Why this is different from a standard cyber awareness session

    Most cyber awareness training is written by information security teams working from published threat reports. This course is built on first-hand operational experience of investigating the attacks it teaches your staff to recognise.

    Our co-founder Ben Sefton spent 18 years as a Senior Forensic Investigator with Greater Manchester Police, working alongside national law enforcement on major crime investigations. Insightful AI has delivered AI training and awareness briefings to organisations across law enforcement, the public sector, and charities. Those that have trusted us include the National Crime Agency, the National Police Chiefs' Council, the North West Regional Organised Crime Unit, City of London Police, Lancashire Constabulary, and Greater Manchester Police, among others. In the charity sector, we work with the National Emergencies Trust and Cheshire Community Foundation.

    The course is designed and delivered by our practitioner team, led by co-founders Ben and Kane.

    Insightful AI is listed on the UK Register of Learning Providers. UK Provider Reference Number (UKPRN) 10098807.

    Where this course fits in the programme

    AI-Enabled Threats and Cyber Risk is course 06 of six in the Responsible AI for Charities programme. It can be booked standalone or as part of a sequenced programme. If your charity has an immediate threat concern or needs to respond to an incident, start here regardless of programme sequencing.

    Related courseWhen it fits
    AI Fluency (01)Build AI literacy foundations before addressing threats (the recommended starting point)
    Responsible AI and Data Protection (02)If your main concern is personal data handling and ICO compliance evidence
    AI Governance and Funder Accountability (03)If your charity needs governance policies, accountability structures, and supplier due diligence
    Safe Use of AI in Your Charity (04)Covers AI tool use at greater depth for day-to-day safe use of approved platforms
    AI for Trustees and Charity Leaders (05)If trustees need broader AI governance knowledge

    Frequently asked questions

    Who should attend this course?
    Charity leaders, heads of IT, finance directors, safeguarding leads, and senior managers responsible for risk management. The threat briefing is designed for the people who authorise payments, manage data, and make decisions about cyber risk. The safe-use strand on AI tools is relevant to any staff member or volunteer handling charity data.
    Do staff need any technical knowledge to follow it?
    No technical background is needed. The course explains how each attack type works in plain language, using scenarios drawn from the roles attending. Recognising a deepfake call or a prompt injection attempt is a verification habit, not a technical skill. We build every session around the roles and responsibilities in the room.
    Will this be useful if we have not deployed AI tools ourselves?
    Yes. Criminals use AI to attack your charity whether you use AI or not. Deepfake video calls, voice cloning, and AI-generated phishing target any organisation that handles money or data. The safe-use strand also matters: 71% of UK employees have used AI tools their organisation has not approved (Microsoft, October 2025).
    How is this different from the annual cyber awareness training we already run?
    Most annual cyber awareness training teaches staff to spot spelling and grammar errors. AI removes those errors entirely. This course covers attack types that did not exist at scale when standard training was written: deepfake video, voice cloning, prompt injection, and AI-generated phishing. Every session is built around your charity's tools and sector.
    Does it cover how to use tools like ChatGPT and Copilot safely?
    Yes. The second strand covers safe use of AI tools within your charity. It addresses data leakage (staff feeding donor or safeguarding records into AI platforms), prompt injection risks, and the difference between approved and unapproved tools. Every scenario reflects the platforms your charity uses or has approved.
    Is the content tailored to our charity?
    Every session is built from scratch. Before the course, we run a discovery call to understand your charity's approved AI tools, sector, policies, and the specific roles attending. The scenarios, examples, and materials are written for your organisation, covering threats relevant to your data, your systems, and your people.
    What evidence do we receive for our records?
    You receive documented evidence of training completion that meets ICO accountability expectations and supports funder due diligence requirements. We share all session materials with your charity after the course, giving you a full record of what was covered and who attended. A certificate of completion is available on request at no extra charge.
    What does it cost, and is the price per person?
    The course costs £895 ex VAT per session, not per person. A session accommodates up to 15 participants, bringing the per-head cost to under £60 at full capacity. The price covers the discovery call, bespoke course materials, documented training evidence, and a follow-up call. Group rates are available for community foundations or funders commissioning training across multiple charities.

    Book a free discovery call

    A 30-minute call. No obligation. We will ask about your charity's team, the tools you use, and your compliance position, and confirm how the bespoke session will be built for you.