In short
- Most UK charities now use AI, but 62% of small charities have no AI policy, according to the Charity Digital Skills Report 2026.
- A short policy sets out approved uses, keeps personal data out of public AI tools and makes sure a person checks every output.
- Trustees or directors stay responsible for decisions, so your board should approve the policy and review it regularly.
- Our template is a starting point, not legal advice. Adapt it to fit your organisation.
On this page
If people in your organisation use AI tools such as ChatGPT, Microsoft Copilot or Google Gemini, you need some simple ground rules. That's true even if you're a team of five and nobody has formally decided to use AI.
This guide is for trustees, directors, managers and volunteers at small charities and community interest companies (CICs) across the UK. It explains what a charity AI policy should cover and gives you a short template you can copy, adapt and adopt.
It's a starting point, not legal advice. If you handle sensitive personal data, or you want to use AI in decisions about people, get specialist advice as well.
Why you need an AI policy now
AI is probably already being used in your organisation, whether or not anyone has written down how. The Charity Digital Skills Report 2026 surveyed 807 UK charities in March and April 2026. It found that:
- 79% of charities are now using AI.
- 51% have no AI policy. This rises to 62% of small charities (income under £1 million), compared with 21% of large charities.
- Only 15% have updated their risk register to reflect AI, and only 19% have reviewed data protection, security and safeguarding in relation to AI.
- 33% of charities rate their board's AI skills as poor.
The regulators and the sector are paying attention too. In April 2024, the Charity Commission for England and Wales published a blog suggesting that an internal AI policy would be beneficial for charities. The 2025 edition of the Charity Governance Code lists "a policy for the use of technology and AI tools" as suggested evidence of good governance.
A policy doesn't need to be long. Its job is to help your people use AI confidently, protect the people you serve, and show your board and funders that you've thought it through.
What your AI policy should cover
| Topic | What it means in practice |
|---|---|
| Approved uses | Which tools people can use, and for what. For example, drafting, summarising public documents or brainstorming. |
| Personal and sensitive data | Never put personal or sensitive information into public AI tools unless the organisation has approved the tool and the use. |
| Checking outputs | A person checks everything AI produces for accuracy, bias and tone before it's used. |
| Transparency | Being honest with service users, supporters and funders about how you use AI. |
| Safeguarding | AI never replaces safeguarding judgement, and safeguarding information never goes into AI tools. |
| Copyright | Respecting other people's work, and checking AI outputs don't copy it. |
| Accountability | A named person leads on AI, and the board stays responsible. |
| Review date | When the policy will be looked at again. |
The legal and regulatory context
UK GDPR and the ICO
UK GDPR applies whenever you use personal data, including in AI tools. People have the right to be informed about how you collect and use their personal data, and the ICO says that information must be concise, transparent and in clear and plain language. If you use AI with someone's personal data, your privacy notice may need to say so.
The ICO has published guidance on AI and data protection. It says that, in the vast majority of cases, using AI to process personal data is likely to result in a high risk to people's rights, which legally requires a data protection impact assessment (DPIA). It also says senior management can't delegate these issues to technical teams. If you can't tell whether a third-party AI tool would be compliant, the ICO's good-practice advice is to choose a different one.
The ICO notes that this guidance is under review because of changes made by the Data (Use and Access) Act 2025, so check the latest version before you rely on it.
The Charity Commission
The Charity Commission's 2024 blog makes clear that trustees remain responsible for decision-making. It warns that trustees may not be complying with their duties if the charity relied solely on AI-generated advice for a critical decision without reasonable independent checks. It also notes that generative AI can confidently produce inaccurate, plagiarised, copyright-infringing or biased results.
The Commission said it didn't plan to produce specific new AI guidance, and instead encourages trustees to apply its existing guidance. That includes the duty in The essential trustee (CC3) to use reasonable care and skill, and the principle that trustees are collectively responsible for decisions made with their authority.
If you're in Scotland or Northern Ireland, check guidance from your own regulator: OSCR or the Charity Commission for Northern Ireland. If you're a CIC, your board of directors takes on the role this guide gives to trustees.
The Charity Governance Code
The Charity Governance Code is voluntary. Its own text says compliance is not a regulatory requirement. But its website says all charities, whatever their size, are expected to follow its principles. The 2025 Code lists an AI and technology policy under Principle 6, Managing resources and risks.
The template
Copy the text below into a document and replace everything in [square brackets]. Delete anything that doesn't apply to you.
Template: copy and adapt
[Organisation name] AI policy
- Approved by: [Board of trustees / Board of directors] on [date]
- Policy lead: [Name and role]
- Next review: [Date, no more than 12 months from approval]
1. Purpose and scope
This policy explains how [Organisation name] uses artificial intelligence (AI) tools safely and responsibly. It applies to all trustees, directors, staff, volunteers and freelancers who use AI tools for our work, on any device.
We use AI to save time and improve our work so that we can better serve [our beneficiaries / our community]. AI supports our people. It doesn't replace their judgement.
2. Approved tools and uses
You may use these tools for our work: [list approved tools and account types, e.g. "Microsoft Copilot through our work account"].
Approved uses include:
- drafting and editing emails, letters, social media posts and reports
- summarising documents that contain no personal or confidential information
- brainstorming ideas and plans
- [add your own]
Ask [policy lead] before using a new tool or using AI for something not listed here.
3. Personal and sensitive information
Never enter personal, confidential or sensitive information into a public or personal AI tool. This includes:
- names, contact details or case notes about service users, supporters, volunteers or staff
- health, safeguarding or other special category information
- financial, commercial or confidential organisational information
You may only use personal data with a tool that [policy lead] has approved for that purpose, after we have checked it meets our data protection obligations. [Delete if you don't allow this at all.]
4. Checking AI outputs
AI can get things wrong, make things up or reflect bias. Before you use anything AI has produced, you must:
- check facts, figures, names and links against a reliable source
- read it for tone, fairness and accessibility
- make sure it reflects our values
You are responsible for any work you produce with AI's help.
5. Decisions about people
We don't use AI to make decisions about individuals, such as decisions about services, grants, recruitment or safeguarding. A person always makes these decisions.
6. Transparency
We are honest about how we use AI. We will:
- tell service users and supporters when they're interacting with AI or receiving AI-generated content where it matters to them
- update our privacy notice if we use AI with personal data
- answer funders honestly about how we used AI, including in funding applications
7. Safeguarding
AI never replaces our safeguarding procedures. Never enter details of a safeguarding concern into an AI tool. If you see AI-generated content that raises a safeguarding concern, follow our safeguarding policy and tell [designated safeguarding lead].
8. Copyright and intellectual property
Don't upload other people's copyrighted work (such as paid-for reports or images) into AI tools unless our licence allows it. Check that AI outputs don't copy other people's work, and credit sources where you use them.
9. Responsibilities
- The [board of trustees / board of directors] is responsible for this policy and for decisions made using AI.
- [Policy lead] keeps the list of approved tools, answers questions and reports to the board.
- Everyone covered by this policy must follow it and report mistakes or concerns to [policy lead] as soon as possible.
10. Review
We will review this policy by [date], or sooner if we start using AI in a new way, something goes wrong, or the law or regulatory guidance changes.
How to adopt your policy
1. Adapt the template
Fill in the placeholders and list the tools people actually use. Ask your team what they use now, as you may be surprised. Check the policy fits alongside your data protection, safeguarding and confidentiality policies.
2. Get board sign-off
Take the policy to your trustees or directors for approval, and record the decision in the minutes. Our AI governance checklist for trustees can help structure the discussion. While you're there, add AI to your risk register. Only 15% of charities have done this, so it's a quick win.
3. Brief your team
Run a short briefing for staff and volunteers. Walk through real examples of what's fine and what isn't, and make sure everyone knows who to ask. Add the policy to your induction pack for new starters.
4. Update what you tell people
If you use AI with personal data, update your privacy notice. Think about whether funders or partners need to know how you use AI.
5. Review it regularly
AI tools and guidance change quickly. Put the review date in your board calendar and review at least once a year, or sooner if something changes.
If you'd like support putting AI to work safely across your organisation, Mission Pointers offers AI workflow support for charities and community organisations.
Sources
- Charity Digital Skills Report 2026, Artificial intelligence findings, Charity trustees and leadership, introduction and background to the research (2026)
- Charity Commission, Charities and artificial intelligence (April 2024)
- Charity Commission, The essential trustee: what you need to know, what you need to do (CC3) (updated September 2026)
- Charity Governance Code, the 2025 Code and full Code (PDF) (2025)
- ICO, Guidance on AI and data protection
- ICO, What are the accountability and governance implications of AI?
- ICO, Our plans for new and updated guidance: technology
- ICO, Right to be informed
- ICO, Special category data
- Google, Gemini Apps Privacy Hub
- OSCR, the Scottish Charity Regulator
- Charity Commission for Northern Ireland