Skip to main content
Insightful AI

AI Ethics and Governance

AI governance for UK charities: a proportionate 90-day plan

UK charities can govern AI through controls they already have. This guide shows where extra checks are needed and gives a practical 90-day plan.

Ben Sefton · Co-founder. 18 years a Senior Forensic Investigator with Greater Manchester Police · · 8 min read

On this page
  1. 1.UK charities do not need a separate AI bureaucracy
  2. 2.Start with the risk, not the tool
  3. 3.What trustees should oversee
  4. 4.Does every charity need an AI policy?
  5. 5.Four controls every charity needs
  6. 6.Data protection and automated decisions
  7. 7.Fundraising needs proportionate transparency
  8. 8.A practical 90-day plan
  9. 9.A lightweight model for a small charity
  10. 10.When to seek specialist advice
  11. 11.The next step

UK charities do not need a separate AI bureaucracy

Most charities can govern artificial intelligence through controls they already have. Trustee oversight, risk management, data protection, safeguarding, cyber security, procurement and human resources provide the starting point.

Extra controls are needed when an AI use involves sensitive data, people in vulnerable situations, consequential decisions or public automation. The sensible approach is to match the control to the risk, rather than creating a new committee for every tool.

This guide sets out what trustees and senior leaders should oversee, which controls every charity needs and how to put them in place over 90 days.

Start with the risk, not the tool

An AI product does not have one fixed risk level. Risk depends on what the charity asks it to do, which data it receives and what happens if it is wrong.

Using an assistant to summarise a non-sensitive internal meeting is usually lower risk. Using the same product to assess eligibility for a service is much more serious. The second use may affect a person, involve sensitive data and require stronger human review.

Assess each use against these questions:

  • What value should this create for beneficiaries, staff or the charity?
  • What personal, confidential or special category data will it use?
  • Could an error affect access to money, employment, support or a service?
  • Could it create a safeguarding or discrimination risk?
  • Will a person review the output before anyone acts on it?
  • Can the charity reverse the action and explain what happened?
  • What will be recorded if the tool fails?

A high answer on safeguarding, discrimination or consequential decisions should trigger enhanced checks. Do not let a low total score hide one serious risk.

What trustees should oversee

Trustees do not need to approve every AI tool. They do need enough information to oversee significant risks and make sure responsibility is clear.

The Charity Commission for England and Wales has not published formal standalone AI guidance. Its April 2024 blog on charities and artificial intelligence (opens in a new tab) applies existing trustee responsibilities to AI. It says trustees remain responsible for decisions and should keep human oversight where errors could matter.

Routine decisions can sit with staff, subject to agreed boundaries. Trustee attention is more likely to be needed when a use involves:

  • beneficiary, donor, employee or volunteer data;
  • children or adults at risk;
  • automated or AI-assisted decisions about people;
  • public-facing chatbots or generated fundraising content;
  • substantial spending or a long supplier commitment;
  • access to finance, case management, email or other important systems.

The board needs risk oversight literacy, not technical depth. It should know where AI is used, who owns each use and which matters need escalation.

Does every charity need an AI policy?

The research reviewed for this draft found no explicit UK law requiring every charity to have a standalone AI policy. That does not mean a charity has no duties when it uses AI. Existing requirements still apply.

The Charity Governance Code (opens in a new tab) recommends a policy for technology and AI tools as possible evidence under its apply or explain approach. A charity can meet the practical need through a short standalone policy or by adding clear AI controls to existing policies.

The right format depends on the organisation. What matters is whether people can find and follow the rules.

A proportionate policy or control set should cover:

  • permitted and prohibited uses;
  • approved tools and account types;
  • rules for personal, confidential and special category data;
  • human checking of outputs;
  • higher-risk decisions and escalation;
  • supplier retention, training reuse and deletion terms;
  • incident reporting and review dates.

Fundraising needs separate attention. The Fundraising Regulator’s guidance on using AI in fundraising (opens in a new tab) recommends that charities develop and agree an AI policy before using AI for fundraising. It also recommends proportionate risk assessment, human review and records of checks and decisions.

Four controls every charity needs

1. A simple record of AI use

Start with the tools and features people already use, including personal accounts and AI built into existing software. Record the owner, purpose, data involved and whether a person checks the output.

A licence register is not enough. It will miss free tools and AI features that staff can switch on without a purchase.

2. Clear data rules

Staff need to know which information must not enter a public AI tool. The rule should cover personal data, special category data, case files, board papers, employment information, donor records and other confidential material.

An enterprise label is not proof that information is safe. Check the contract, configuration, retention, training reuse, data location, access controls and deletion arrangements.

3. Human verification matched to the consequence

A person should check material outputs before the charity relies on them. The check can be light for a low-risk draft and much stronger for a decision affecting a person.

Human review needs to be meaningful. The reviewer should understand the task, see the relevant information and be able to change or reject the output. A routine click to approve does not provide reliable oversight.

4. An incident and escalation route

People need a clear way to report an incorrect output, data disclosure, harmful content or unexpected automated action. The route should say who responds and when trustees or specialist leads must be involved.

Record near misses as well as actual harm. A simple log can reveal repeated problems before they become serious.

Data protection and automated decisions

UK data protection law applies when AI uses personal data. A charity still needs a lawful basis, clear information for people, data minimisation and appropriate security.

A data protection impact assessment, often called a DPIA, is required for processing likely to create a high risk to people’s rights and freedoms. Novel AI use can meet that threshold, but not every use does. Screen the use first and record the decision.

The Data (Use and Access) Act 2025 changed the UK rules for solely automated decisions with legal or similarly significant effects. Section 80 replaced the former Article 22 framework with Articles 22A to 22D from 5 February 2026. The new framework permits more automated decision-making but requires safeguards, including information, human review and a way to contest a decision.

The legal detail depends on the use, the data and the effect on the person. Report what section 80 of the Act (opens in a new tab) says and take advice where a specific situation needs interpretation.

The Information Commissioner’s updated automated decision-making guidance was still in draft on the research cut-off date of 22 September 2026. Recheck the ICO’s technology guidance plans (opens in a new tab) before publication and before approving a consequential use.

Fundraising needs proportionate transparency

Charities remain accountable for fundraising material produced with AI, including work supplied by third parties.

Transparency should match the risk of misleading donors. A back-office spelling check does not need the same treatment as a synthetic image or a story that a donor could mistake for a real beneficiary’s experience.

Before using AI in fundraising:

  1. assess the intended use and the risk of misleading people;
  2. agree who checks the output;
  3. protect donor and beneficiary information;
  4. record the checks and decisions;
  5. check the current Code of Fundraising Practice and regulator guidance.

Funder rules differ. Some allow AI-assisted drafting but set their own expectations for disclosure, confidentiality and assessment. Check the current policy for each application rather than assuming one sector-wide rule.

A practical 90-day plan

Days 0 to 30: understand and contain

Appoint one accountable trustee or senior leader and one staff lead. Ask teams which tools and AI features they already use, then build a simple inventory.

Issue interim rules covering confidential data, special category data and human checking. Flag any use involving beneficiaries, children, adults at risk, recruitment or automated decisions for immediate review.

Add AI use and risk to the existing risk register. Give staff a clear route for questions and incidents.

Days 31 to 60: put proportionate controls in place

Agree the permanent rules, either in a short AI policy or within current policies. Create an approved-tool process that checks the supplier and the proposed use.

Screen priority uses for privacy, security, safeguarding and equality risks. Complete a DPIA where the processing is likely to be high risk.

Run limited pilots with named owners, clear human review and stop conditions. Train staff on the actual rules they need to follow, not only on how to write prompts.

Days 61 to 90: test, improve and decide what to scale

Review the pilots against their stated purpose. Keep the uses that produce a worthwhile result and stop or revise those that do not.

Update the risk register, tool inventory and incident route. Decide how often owners will recheck supplier terms, permissions and performance.

Set review triggers for new regulator guidance, material product changes and any use that moves into sensitive data or consequential decisions.

A lightweight model for a small charity

A small charity does not usually need an AI committee or a dedicated AI officer. One accountable trustee and one staff lead can run a proportionate model through existing governance.

The minimum useful set is:

  • an AI use and tool record;
  • short rules for data and approved uses;
  • a named person who checks material outputs;
  • an escalation and incident route;
  • a standing risk-register item;
  • a review date.

This is enough to make responsibility visible without copying an enterprise programme that the charity cannot maintain.

When to seek specialist advice

Get appropriate legal, privacy, safeguarding, employment or security advice before a high-risk use goes live. This is especially important where AI influences eligibility, recruitment, casework, safeguarding or another decision about a person.

Advice may also be needed when the charity cannot decide whether a DPIA is legally required, whether a process is solely automated or which condition permits the use of special category data.

A good rule is simple. If the answer depends on professional judgement that the charity does not hold, do not ask the AI system to settle it.

The next step

Start with one important use, not a plan to use more AI. Record the current process, the expected benefit, the data involved and the cost of an error. Then decide what the tool may do and where a person must check.

For a deeper board-level assurance question, read how a charity board can evidence that its AI policy is being followed.

If you want help assessing the controls around current or planned uses, see our AI ethics and governance service or book a free discovery call.

What does this mean for your business?

Talk to our team about your next steps with AI.

Talk to Insightful AI

Back to top

Tags

  • AI governance
  • charity governance
  • data protection
  • responsible AI
  • UK charities
  • regulatory compliance

AI ethics & governance

79% of UK charities now use AI, yet half have no AI policy at all, rising to 62% among small charities (Charity Digital Skills Report 2026). Across Europe, staff in most organisations are now using generative AI at work, yet only 31% have a formal, comprehensive AI policy to govern it. Governance does not restrict AI adoption; it makes adoption sustainable. This service is particularly relevant to charities, public sector teams, and any SME handling sensitive client or beneficiary data.

Read more about AI ethics & governance

Ready to put this into practice?

Book a free 30-minute discovery call. Tell us where you are with AI and we will tell you where to start.

Book a free discovery call