AI for UK Charities in 2026: Fundraising, Grants and Safeguards
AI can summarise a grant application, draft a supporter email or help staff find information in a service directory. It cannot decide what advances a charity’s purposes, turn weak historical data into a fair measure of need or accept responsibility when a vulnerable person is harmed.
The Charity Commission’s note on charities and AI says trustees remain responsible for decisions and should not rely on AI-generated material alone for critical choices. It also highlights inaccurate, biased, copyright-infringing and insecure outputs. That is the right starting point: use AI as a bounded tool inside charity governance, not as a substitute for it.
This guide is current to 31 July 2026. Charity law and regulators differ across England and Wales, Scotland and Northern Ireland. Confirm the law, regulator and professional advice relevant to your organisation; this is not legal advice.
Start with purpose, benefit and an accountable owner
Before selecting a model, write a one-page case for change:
- the charitable purpose and beneficiary outcome being advanced;
- the current process, evidence of the problem and non-AI alternatives;
- who may benefit, be excluded or be harmed;
- what the system may recommend and what it must never decide;
- the named service, data, safeguarding and trustee owners;
- the budget, including review, security, accessibility and exit costs; and
- the evidence and date on which trustees will continue, change or stop it.
For charities in England and Wales, the Charity Commission’s CC27 decision-making guidance requires trustees to act within their powers and in the charity’s interests, be sufficiently informed, consider relevant factors, manage conflicts and reach a decision a reasonable trustee body could make. If authority is delegated, the board remains accountable; high-risk or novel decisions should not usually be delegated.
Record the options, advice, beneficiary consultation, risks, conflicts, evidence and decision. A vendor demonstration or average-accuracy dashboard is not sufficient information.
Choose a bounded, reversible first use
Start where staff can detect and correct an error before it affects access to support, a safeguarding response or a person’s money.
| Use case | Bounded AI role | Keep outside the first release | Useful measures |
|---|---|---|---|
| Supporter communications | Draft from approved facts and tone rules | Selecting people by inferred vulnerability or sending automatically | factual correction, complaint and opt-out rates |
| CRM housekeeping | Suggest duplicates and incomplete records | Merging, deleting or changing consent without review | precision, false merges and manual-review time |
| Grant intake | Extract answers and point to source passages | Scoring mission fit or rejecting an application | field accuracy by form type and correction time |
| Service-directory search | Retrieve current, approved entries | Promising eligibility, availability or outcomes | source accuracy, stale-result rate and successful referral |
| Needs analysis | Summarise de-identified, quality-checked evidence | Predicting an individual’s need from proxies | missingness, coverage by group and analyst agreement |
| Beneficiary assistant | Answer a narrow set of service questions | Crisis counselling, safeguarding triage or final entitlement | containment, unsafe-answer and escalation rates |
Measure a service outcome and the cost of human correction, not “messages generated”. Include staff and beneficiary feedback: a faster workflow that removes trust, privacy or accessibility is not an improvement.
Fundraising: the 2026 soft opt-in is conditional
The Code of Fundraising Practice, effective since 1 November 2025, applies to fundraising by charitable institutions and third-party fundraisers across the UK. Its standards include fair, respectful and non-misleading treatment. AI personalisation does not lower that bar. Do not use a model to exploit fear, grief, urgency, a lack of knowledge or a person’s apparent need for care and support. Give fundraisers a clear stop route when contact is unwelcome or confusing.
A specific 2026 change needs careful implementation. The ICO’s electronic-mail marketing guidance explains the charitable-purposes soft opt-in under PECR regulation 22(3A), which commenced on 5 February 2026. A charity may use it only when all conditions are met:
- the sender is a charity under the relevant UK-nation definition;
- the charity collected the contact details directly from that person on or after 5 February 2026;
- collection occurred when the person expressed interest in, or offered or provided support for, the charity’s purposes;
- the sole marketing purpose is to further that charity’s own charitable purposes;
- a simple, prominent opt-out was offered when the details were collected; and
- every later message offers a simple opt-out.
It does not make historic lists, third-party platform data or bought lists eligible. A person giving a number to arrange emergency support has not necessarily expressed interest in future fundraising. Consent may still be the appropriate route, and UK GDPR still needs a lawful basis, transparency and fair processing.
Before AI selects or drafts an audience, preserve the provenance and permission status of every record. Suppress opt-outs and deceased contacts before data reaches the model. Keep sensitive service-use information separate from fundraising unless a documented lawful, fair and necessary use supports the specific processing. Our UK AI and data-privacy guide covers the broader assessment.
Do not turn incomplete data into a map of need
Charity data usually describes who reached the service, met an existing threshold or agreed to be recorded. It does not automatically describe everyone who needs help. Digital exclusion, language, geography, stigma, referral practices and prior capacity limits can all shape the record.
For any “needs prediction”:
- define the decision and harm of a false negative;
- document provenance, missingness, time period and known selection effects;
- involve people with lived experience before choosing features or outcomes;
- prohibit unsupported proxy inferences about health, disability, ethnicity, religion or vulnerability;
- compare error and referral rates across relevant groups and channels;
- retain a non-digital route and reasonable adjustments; and
- never treat absence from the dataset as absence of need.
Where special-category data is involved, identify both an Article 6 lawful basis and an Article 9 condition, minimise fields and complete an appropriate data-protection impact assessment. The ICO’s AI and data-protection risk toolkit is useful, but its page notes that parts of the guidance are under review following the Data (Use and Access) Act 2025. Check its current status when deploying.
Grants and service allocation need contestable human judgement
AI may extract criteria, identify a missing attachment or assemble source-linked material for a reviewer. It should not silently redefine merit, community benefit or organisational credibility.
For grant review, publish the criteria applicants actually face. Test extraction across formats, languages, assistive-technology exports and applications written without professional bid support. Give reviewers the original application, the AI-derived field and confidence or exception flag. Do not ask a general-purpose model to rank applications by “impact” without a validated, disclosed definition.
For consequential recommendations, require two things: a reviewer with authority and time to disagree, and a route for applicants or beneficiaries to correct material facts. Audit reversals rather than treating them as reviewer failure. A high override rate can expose a bad model, ambiguous policy or missing evidence.
Minimum rule: no solely automated rejection, reduction, safeguarding disposition or denial of a service during the pilot.
Safeguarding is a human response system
The Charity Commission’s safeguarding guidance for England and Wales says protecting people is a governance priority and applies online as well as in person. Charities working with children or adults at risk need appropriate policies, training, a safeguarding lead and effective handling of complaints and allegations.
A chatbot can show a crisis or reporting route. It must not diagnose danger, conduct an abuse disclosure interview or delay escalation while seeking more context. Define immediate transfer conditions, out-of-hours handling and failure procedures. Do not place intimate disclosures into a consumer AI account.
Red-team realistic interactions: ambiguous language, coercive messages, self-harm, a child using an adult’s device, different languages, speech errors and an alleged abuser monitoring the screen. The safeguarding lead, not only the technology supplier, must approve the release and incident process.
Control suppliers, access and exit
Ask vendors where prompts, files, embeddings, logs and backups are processed; who can access them; whether they train on them; which subprocessors are used; how deletion works; and what changes without notice. Contract for incident notification, audit evidence, availability, export, deletion and an orderly exit. Test those promises.
Use least-privilege accounts, multifactor authentication, approved integrations and separate test data. Prevent staff from pasting donor exports, case notes, medical details, grant applications or safeguarding records into unapproved tools. The NCSC’s charity cyber-security collection provides practical controls for smaller organisations, including account, device, backup and phishing protection. See also our AI cybersecurity guide.
Respect the UK’s charity-law boundaries
Do not paste “Charity Commission approved” onto a UK-wide policy:
- England and Wales: the Charity Commission regulates charities; CC27 and the safeguarding guidance cited above state their territorial scope.
- Scotland: OSCR’s trustee-duties guidance explains duties under the Charities and Trustee Investment (Scotland) Act 2005, including acting in the charity’s interests, care and diligence and trustee oversight of fundraising.
- Northern Ireland: use the Charity Commission for Northern Ireland’s running-your-charity guidance, which reflects Northern Ireland charity law and public-benefit requirements.
- UK fundraising and data: the Fundraising Code is UK-wide; PECR and UK GDPR apply according to their own scope. Equality and safeguarding regimes also have territorial differences.
Cross-border charities may have more than one registration or reporting relationship. Name the responsible legal entity and regulator in the project record.
A 90-day pilot with stop/go gates
Days 1–30 — define. Map the service and data; consult beneficiaries and staff; compare a non-AI option; establish the lawful basis, safeguarding analysis and accessibility needs; approve permitted and prohibited uses; baseline quality, time, complaints and group-level outcomes.
Days 31–60 — test offline. Use representative, minimised data; validate source traceability, edge cases, permissions and suppression lists; test security, incident response and rollback; train reviewers to disagree; record correction effort and unequal errors.
Days 61–90 — limited release. Restrict users and volume; sample outputs daily; publish an understandable notice where appropriate; keep the prior route available; review complaints, opt-outs, safeguarding signals, reviewer overrides and beneficiary feedback weekly.
Release only when all relevant gates pass:
- zero solely automated grant, service-denial or safeguarding decisions;
- 100% of factual claims in material outputs trace to an approved source;
- suppression, consent and charitable-soft-opt-in tests pass for every sampled recipient;
- no unresolved critical privacy, security, accessibility or safeguarding finding;
- errors and outcomes are acceptable overall and for agreed groups and channels;
- staff can correct, escalate and roll back within the defined service target;
- trustees approve the evidence, residual risks, owner and review date; and
- the vendor can return and delete charity data under the tested exit plan.
Pause on a serious incident, material model or supplier change, new data use, repeated unsupported output, worsening group-level outcome or ineffective human review. Reassessment is part of operation, not an admission that the pilot failed.
The practical verdict
The strongest charity AI projects are deliberately modest. They make approved information easier to find, remove clerical work and leave staff more time for human relationships. They do not manufacture confidence from incomplete data or hide consequential choices inside a score.
Start with one purpose-linked problem, keep authority with people, protect donor choice and beneficiary safety, and demand evidence before scale. For a charity, trust is not branding around the system. It is a release condition.



