AI for UK Charities: The Grounded Guide

What this covers

This is an honest, practical guide to using AI as a small UK charity: what the technology can and cannot do, where it genuinely saves time and where it is risky, the four main risks to manage, how to write a simple AI use policy, how data protection applies, how to use AI safely for grant applications and reports, and the board’s role. It is written for charities that want the benefits of AI without the pitfalls.

AI has arrived in charities faster than the guidance to use it well. Staff and volunteers are already using chatbots to draft emails, summarise meetings and shape funding bids, often without any agreed rules, while trustees look on unsure what, if anything, they should be doing about it. This handbook takes a grounded view: AI can genuinely help a stretched small charity, but only if you understand what it is, respect its risks, and keep a person in charge of every output. It reflects the position and the evidence as at July 2026.

What AI is, and what it can and can’t do

The AI most charities use is generative AI — tools such as chatbots that produce text, summaries or images in response to a prompt. They are genuinely good at language tasks: drafting, summarising, rephrasing, translating and brainstorming. But they are not databases of facts. They work by predicting plausible sequences of words, which means they can state something false as confidently as something true, and they have no built-in sense of what is accurate.

Almost eight in ten UK charities (79%) now use AI in some way, yet 51% have no AI policy and only 6% have carried out a risk assessment of how they use it. (Source: Charity Digital Skills Report 2026.) That gap — high use, low governance — is exactly what this handbook is here to close: the technology is already in your charity, whether or not anyone decided it should be, so the task is to use it deliberately and safely rather than by accident.

It helps to be clear about what “AI” means here, because the word covers a lot. Most day-to-day charity use is generative AI — the chatbots and writing assistants that produce text or images on request, including the ones now built into everyday software like email and word processors. There is also older, narrower AI that has quietly powered things like spam filters and translation for years, and newer “AI agents” that can carry out multi-step tasks, which a small but growing number of charities are testing. This handbook focuses on the generative tools most charities actually use, but the same principle applies across all of them: understand what the tool is doing, and keep a person responsible for the result.

The practical rule that follows from how AI works is the one to hold onto throughout: AI drafts, a person checks and approves. AI is excellent as an assistant for language-heavy tasks and poor as an authority on facts, figures, current events or judgement calls. It does not know your charity, it cannot be relied on for accuracy, and it should never make a decision that affects a beneficiary on its own. Used as a fast first-drafter with a human always in the loop, it saves real time; used as an oracle, it will eventually embarrass you.

Read the full guide →

Where AI genuinely helps — and where it doesn’t

AI helps most with time-consuming language tasks where a person still checks the result: drafting emails and documents, summarising notes and meetings, rephrasing text into plain English, generating ideas, and getting started on a blank page. It helps least — and is riskiest — where accuracy, confidentiality or human judgement are essential, such as advising beneficiaries, handling personal data, or finalising facts and figures.

The evidence bears this out. Charities most commonly use AI for everyday tasks like drafting and summarising (around 60%), creating documents and reports (around 57%), and grant fundraising (around 45%, rising to over half of small charities), per the Charity Digital Skills Report 2026. These are all tasks where AI produces a draft and a person refines it. The common thread is that AI adds most value where it saves a knowledgeable person time, not where it replaces their knowledge.

A good test before using AI for a task is to ask three questions: would a mistake here cause real harm; does the task involve personal or confidential data; and does it need my charity’s specific knowledge or authentic voice? If the answer to all three is no — as with summarising your own meeting notes or drafting a routine email — AI is low-risk and genuinely useful. If the answer to any is yes, slow down and add safeguards, or do the task yourself. This simple triage lets a busy charity capture the easy time savings, which are real and add up, while keeping AI well away from the places it can do damage. Start with the low-risk tasks and build confidence from there.

Be much more cautious in three areas. First, anything involving personal or confidential data — beneficiary records, case notes, staff information — which raises data protection risks covered later in this handbook. Second, anything where a wrong answer causes real harm, such as advice to a vulnerable person, safeguarding decisions, medical, legal or financial guidance, or final published facts. Third, work where your authentic voice is the point, such as heartfelt fundraising appeals or creative content — over-used AI tends to produce generic, lifeless text (sometimes called AI “slop”) that damages your communications. In these areas, use AI lightly if at all, and always with a person firmly in control.

Read the full guide →

The risks: hallucination, data protection, bias, over-reliance

Four risks matter most when a charity uses AI: hallucination, data protection, bias and over-reliance. Understanding each one is what lets you use AI confidently rather than fearfully — the risks are real but manageable, and charities that name them and put simple safeguards in place get the benefits without the harm. Notably, charities themselves rank accuracy and data privacy as their biggest AI concerns.

Hallucination is the most common problem: AI inventing plausible but false information — a made-up statistic, a non-existent source, a wrong deadline stated with total confidence. The safeguard is simple and non-negotiable: check every fact, figure, name and date the AI produces against a reliable source before you use it. Data protection risk arises whenever personal or confidential data is fed into a tool you do not control, where it may be stored or used to train the model; the safeguard is never to put personal, confidential or beneficiary data into public AI tools. Bias is the risk that AI reflects and amplifies prejudices in its training data, which matters especially when the output affects beneficiaries or decisions about people; the safeguard is to review AI output critically, particularly anything touching protected groups, and never to let it make decisions about individuals.

These risks interact, which is why a few good habits cover most of them at once. Checking every output catches hallucinations and much bias; never pasting in personal data prevents most data protection problems; and editing in your own voice guards against both over-reliance and the loss of authenticity. It also helps to be honest internally about mistakes: if someone spots that AI produced a wrong figure or an off-key paragraph, that should be shared and learned from, not hidden. Charities that treat AI as something to be used carefully and talked about openly manage the risks far better than those where people either use it secretly or avoid it out of unexamined fear. The goal is confident, careful use, not blanket caution.

Over-reliance is the quietest risk: leaning on AI so heavily that you lose your own voice, skills and judgement, or that generic AI text hollows out your charity’s character. The safeguard is to keep a person genuinely in charge — using AI to draft and assist, then editing in your own voice and applying your own judgement, rather than pasting its output straight out. Some charities also weigh ethical and environmental concerns about AI, including its energy and water use and how its training data was gathered; these are legitimate considerations for a values-led organisation, and it is entirely reasonable for a charity to decide to use AI sparingly, or not at all, for reasons of principle. The UK GDPR entry covers the data protection side in more detail.

Read the full guide →

Grounded versus ungrounded AI

A useful distinction is between “ungrounded” AI — general tools that generate answers from patterns across the open internet, and can invent facts — and “grounded” AI, which draws on verified, specific data and cites its sources. Most charities use ungrounded, general-purpose tools, so the safe approach is to treat their output as a draft to be checked, not a source of truth, and to give the AI your own reliable information to work from wherever you can.

The grounded approach is worth understanding because it points to how to use any AI more safely. As CharityIQ, which is built on this principle, puts it: “Grounded AI draws on verified, charity-specific data — registration, beneficiaries, past applications, funder requirements — rather than generic patterns from the open internet; it cites every fact, logs every decision, and never invents a number.” The three ideas behind it — grounded, auditable and UK-built — describe what trustworthy AI for a charity looks like: it works from real, relevant data; it shows its sources so a person can check; and it keeps a record of what it did.

Why does grounding matter so much? Because almost every serious AI failure a charity is likely to hit — a fabricated statistic in a report, an invented legal rule, a made-up funder deadline — comes from an ungrounded tool confidently filling a gap in its knowledge with something plausible. Grounding the AI in real, relevant information narrows that gap: given your actual figures and a funder’s real criteria, the tool has less room to invent, and asking it to cite where each claim comes from makes any remaining invention easy to spot. It is the single most useful habit for using general AI tools more safely, and it costs nothing but a moment to paste in the right source material first.

You do not need a specialist product to apply the principle. When you use a general AI tool, you can “ground” it yourself: paste in your own accurate documents — your past applications, your real figures, a funder’s actual criteria — and ask the AI to work from those rather than from its general knowledge, and ask it to show where each claim comes from so you can verify it. Whatever tool you use, the rule is the same and it is the theme of this whole handbook: the AI drafts from grounded information, and a person checks every fact before it is used. Grounding reduces hallucination; it does not remove the need for a human check.

Read the full guide →

Writing an AI use policy

An AI use policy is a short document that tells your staff and volunteers what AI they can use, for what, and what they must never do — for example, never putting personal or confidential data into public AI tools, and always checking AI output before it is used or sent. It does not need to be long or technical; it needs to be clear, and everyone needs to know it exists.

Most charities do not have one yet. Just over half (51%) have no AI policy, rising to 62% of small charities (Charity Digital Skills Report 2026), which means a lot of people are using AI with no guidance at all — some enthusiastically, some nervously, none consistently. Writing a simple policy is one of the quickest wins available to a small charity, and it removes both the risk of misuse and the paralysis of people who are unsure whether they are allowed to use AI at all.

A policy is not about restricting people so much as freeing them to use AI with confidence. Without one, cautious staff avoid useful tools for fear of doing something wrong, while bolder colleagues may take risks no one has thought through — the worst of both worlds. A clear, permissive-but-safe policy resolves this: it says, in effect, here is what you can use, here is how, and here are the few firm lines you must not cross. That certainty is worth a great deal in a small team. Involve the people who actually use AI in drafting it, so it reflects real practice rather than head-office theory, and it is far more likely to be followed.

A workable policy for a small charity covers a handful of things: which tools are approved; what AI may and may not be used for; the firm rule on never putting personal, confidential or beneficiary data into public tools; the requirement that a person checks every output before it is used; when to be transparent that AI was used; and who is responsible for AI in the charity. Keep it to a page or two, write it in plain language, have the trustees approve it, and review it as the tools and the risks change. A ready-to-use AI use policy template accompanies this handbook, and the Trustee & Governance Handbook covers how policies fit into good governance.

Get the AI use policy template.

AI and data protection

Putting personal data into an AI tool is still processing personal data, so UK data protection law applies in full. The key rule for a charity is simple: never put personal, confidential or beneficiary data into a public AI tool unless you are certain it is secure and lawful to do so. Anything you paste into a general chatbot may be stored by the provider or used to improve its models, outside your control.

The full framework still applies — the UK GDPR, the Data Protection Act 2018 and the marketing rules, as amended by the Data (Use and Access) Act 2025. The Information Commissioner’s Office publishes detailed guidance on AI and data protection, aimed at organisations including charities, along with an AI and data protection risk toolkit; data protection law is risk-based, so you are expected to identify the risks of an AI use, mitigate them, and be able to show how. For anything higher-risk — especially involving sensitive data or vulnerable people — a data protection impact assessment is the right tool before you start.

Watch particularly for the moments when data protection risk sneaks in unnoticed. It is easy to paste a chunk of text into a chatbot to “tidy it up” without realising it contains a beneficiary’s name, a case detail or staff information; easy to upload a spreadsheet for analysis that still has personal identifiers in it; and easy to use an AI note-taker in a meeting where confidential matters are discussed. Each of these is processing personal data through a third party. The fix is a habit of pausing before you paste or upload: check what is actually in the material, strip out or anonymise personal details, and if you cannot, do not use a public tool for it. A moment’s thought prevents most breaches.

In practice, a few habits keep a small charity safe. Use tools with clear, charity-appropriate privacy terms rather than pasting sensitive material into whatever is free; anonymise or remove personal details before using AI where you can; take particular care with data about children or people at risk; and be clear with people about how their information is used. If personal data does end up somewhere it should not — a beneficiary’s case notes pasted into a public tool, say — treat it as a potential data breach: report it to the ICO within 72 hours where required, and remember it may also be a reportable serious incident to the Charity Commission. The UK Charity Compliance Handbook covers the data protection duties in full.

Get the Charity data protection self-check checklist.

Using AI safely for grant applications and reports

AI can help you draft and shape a grant application or a report — structuring your points, fitting a tight word count, turning rough notes into clear prose — but it must not invent facts, figures or outcomes, and the final words should be your own. Nearly half of charities already use AI for grant fundraising, and small charities especially value it for getting started and saving time on bids; the ones who do it well use it to support their case, not to replace it.

The dangers are specific and worth naming. AI will happily invent a statistic, a beneficiary number or an impact figure to fill a gap, so every fact and figure in an AI-assisted bid must be checked against your own records — never submit a number you cannot evidence. AI also tends to produce generic, recognisably machine-written text, and funders increasingly notice: a bid that has lost your charity’s voice and specifics is weaker, not stronger, than a plainer one written by a person who knows the work. Some funders now ask applicants to be transparent about AI use, and some applicants deliberately keep their bids human precisely because the personal, from-the-heart account is what persuades.

There is also a question of fairness and honesty to weigh. Funders read a great many applications, and an obviously AI-written bid — generic, over-polished, light on specifics — can read as though the applicant did not care enough to write it themselves, which is the opposite of the impression you want. Worse, an AI-invented figure or outcome that slips into a bid is not just embarrassing but a serious integrity problem if a funder relies on it. The safest stance is to use AI to help with the mechanics — structure, length, clarity — while making sure the substance, the evidence and the voice are genuinely yours, and to check your funder’s own rules, as some now ask applicants to declare where AI has been used.

The grounded approach makes AI genuinely useful here. Give the tool your real material — your actual outcomes, your true figures, the funder’s published criteria, your previous successful answers — and ask it to help you structure and tighten your case, rather than asking it to write about your charity from its general knowledge, which is where invention creeps in. Then edit it into your own voice, check every number, and make sure the case is recognisably yours. Used this way, AI can take the drudgery out of bid-writing while keeping the honesty and humanity that win grants. The Complete Guide to Grant Funding covers what makes a strong bid, and the Impact Measurement Handbook covers evidencing outcomes honestly.

Read the full guide →

The board’s role: governing AI use

AI is a governance issue, not just an operational one. Trustees do not need to be technical, but they are responsible for making sure the charity uses AI safely, lawfully and in line with its values — which means approving an AI policy, understanding the main risks, and keeping an eye on how AI is used across the charity. At present very few boards do any of this, even as staff adoption races ahead.

The gap is stark: only around 7% of charities regularly review AI use and risks at board level, and only 6% have carried out a risk assessment of their AI use, while 44% have taken no action at all to progress with AI or manage its risks — rising to 55% of small charities (Charity Digital Skills Report 2026). That is a governance blind spot. Trustees’ existing duties already cover this: managing the charity’s resources and risks responsibly, acting in its best interests, and protecting the people it serves all apply directly to how the charity uses AI.

Trustees also have a part to play in setting the tone. If the board treats AI purely as a threat to be banned, staff will use it anyway and simply not mention it; if the board treats it as a magic solution to a funding crisis, it will encourage careless use. A measured position — that AI is a useful tool to be used carefully, within clear rules and the charity’s values — gives staff permission to use it well and to raise problems openly. Given how many charities are adopting AI with no board oversight at all, even a single honest conversation at a board meeting, leading to a simple policy and a named lead, would put a charity ahead of most of the sector.

A board does not need to become expert to govern AI well. It should make sure there is an AI use policy and approve it; add AI to the risk register, covering accuracy, data protection and bias; ask who is leading on AI and how it is being used; and discuss AI periodically as the technology and risks evolve. It should also engage with the charity’s values: some charities decide, for good ethical or mission reasons, to use AI sparingly or not at all, and that is a legitimate governance choice for trustees to make consciously rather than by drift. The charity trustee entry and the Trustee & Governance Handbook set out the wider duties this builds on.

Read the full guide →

A practical starting checklist

If you are starting with AI, a few sensible steps will keep you safe: agree what you will and will not use it for, protect personal data, keep a person checking every output, write a short policy, and tell your trustees. You do not need to be an expert or to buy anything — you need clear, simple rules and the discipline to follow them, and you can start today.

A practical starting checklist for a small charity looks like this. Agree which AI tools are approved, and steer people to those. Set the firm rule that no personal, confidential or beneficiary data goes into public AI tools. Require that a person checks every fact, figure and output before it is used or sent. Protect your voice by editing AI drafts into your own words rather than pasting them out. Write a one-page AI use policy and have the trustees approve it. Give one person the job of leading on AI. Add AI to your risk register. And review how it is going every few months, because both the tools and the guidance are changing quickly.

It is worth revisiting the checklist every few months rather than treating it as a one-off, because AI is changing quickly: new tools appear, existing tools gain new features, and the guidance from regulators and funders keeps developing. What was true this quarter may need updating next. Build a light review into an existing rhythm — a standing item at a staff meeting, a short annual look by the board — so your approach keeps pace without becoming a burden. And share what you learn: the charities getting the most from AI are often those that talk to peers about what is working and what is not, rather than each quietly working it out alone. You do not have to have all the answers to start safely.

Read the full guide →

None of this requires technical skill or spare money — it requires deciding to use AI on purpose rather than by accident. Do these things and a small charity can safely take the time savings AI offers on drafting, summarising and bid-writing, while protecting its data, its beneficiaries and its voice. CharityIQ exists to make this easier — grounded AI built for UK charities that works from your verified data, cites its sources and logs its decisions, with a person always checking before anything is used — but everything in this handbook is free to do with the tools you already have. Start small, keep a human in charge, and let AI take the drudgery, not the judgement.


Last reviewed: July 2026 · Reviewed by Ivan Siyanko.
Changelog: July 2026 — first published; AI adoption figures from the Charity Digital Skills Report 2026; reflects the Data (Use and Access) Act 2025 and current ICO AI guidance.

Download the full handbook (PDF). Get this guide as a printable PDF to share with your trustees and team — email optional. [NOTE FOR IVAN: attach the generated PDF; keep the download ungated, email optional.]

More handbooks: UK Charity Compliance Handbook · Trustee & Governance Handbook · Complete Guide to Grant Funding · Impact Measurement Handbook · Gift Aid Handbook.