Nonprofit
9 min read

AI for UK Charities in 2026: Fundraising, Grants and Safeguards

A guide to AI for charity operations, fundraising and grant review, preserving trustee accountability, donor choice, beneficiary safety and data protection.

AI for UK Charities in 2026: Fundraising, Grants and Safeguards
Nonprofit / 9 min read
AIENGINE

9 min read

Share

AI for UK Charities in 2026: Fundraising, Grants and Safeguards

AI can summarise a grant application, draft a supporter email or help staff find information in a service directory. It cannot decide what advances a charity’s purposes, turn weak historical data into a fair measure of need or accept responsibility when a vulnerable person is harmed.

The Charity Commission’s note on charities and AI says trustees remain responsible for decisions and should not rely on AI-generated material alone for critical choices. It also highlights inaccurate, biased, copyright-infringing and insecure outputs. That is the right starting point: use AI as a bounded tool inside charity governance, not as a substitute for it.

This guide is current to 31 July 2026. Charity law and regulators differ across England and Wales, Scotland and Northern Ireland. Confirm the law, regulator and professional advice relevant to your organisation; this is not legal advice.

Start with purpose, benefit and an accountable owner

Before selecting a model, write a one-page case for change:

  • the charitable purpose and beneficiary outcome being advanced;
  • the current process, evidence of the problem and non-AI alternatives;
  • who may benefit, be excluded or be harmed;
  • what the system may recommend and what it must never decide;
  • the named service, data, safeguarding and trustee owners;
  • the budget, including review, security, accessibility and exit costs; and
  • the evidence and date on which trustees will continue, change or stop it.

For charities in England and Wales, the Charity Commission’s CC27 decision-making guidance requires trustees to act within their powers and in the charity’s interests, be sufficiently informed, consider relevant factors, manage conflicts and reach a decision a reasonable trustee body could make. If authority is delegated, the board remains accountable; high-risk or novel decisions should not usually be delegated.

Record the options, advice, beneficiary consultation, risks, conflicts, evidence and decision. A vendor demonstration or average-accuracy dashboard is not sufficient information.

Choose a bounded, reversible first use

Start where staff can detect and correct an error before it affects access to support, a safeguarding response or a person’s money.

Use caseBounded AI roleKeep outside the first releaseUseful measures
Supporter communicationsDraft from approved facts and tone rulesSelecting people by inferred vulnerability or sending automaticallyfactual correction, complaint and opt-out rates
CRM housekeepingSuggest duplicates and incomplete recordsMerging, deleting or changing consent without reviewprecision, false merges and manual-review time
Grant intakeExtract answers and point to source passagesScoring mission fit or rejecting an applicationfield accuracy by form type and correction time
Service-directory searchRetrieve current, approved entriesPromising eligibility, availability or outcomessource accuracy, stale-result rate and successful referral
Needs analysisSummarise de-identified, quality-checked evidencePredicting an individual’s need from proxiesmissingness, coverage by group and analyst agreement
Beneficiary assistantAnswer a narrow set of service questionsCrisis counselling, safeguarding triage or final entitlementcontainment, unsafe-answer and escalation rates

Measure a service outcome and the cost of human correction, not “messages generated”. Include staff and beneficiary feedback: a faster workflow that removes trust, privacy or accessibility is not an improvement.

Fundraising: the 2026 soft opt-in is conditional

The Code of Fundraising Practice, effective since 1 November 2025, applies to fundraising by charitable institutions and third-party fundraisers across the UK. Its standards include fair, respectful and non-misleading treatment. AI personalisation does not lower that bar. Do not use a model to exploit fear, grief, urgency, a lack of knowledge or a person’s apparent need for care and support. Give fundraisers a clear stop route when contact is unwelcome or confusing.

A specific 2026 change needs careful implementation. The ICO’s electronic-mail marketing guidance explains the charitable-purposes soft opt-in under PECR regulation 22(3A), which commenced on 5 February 2026. A charity may use it only when all conditions are met:

  • the sender is a charity under the relevant UK-nation definition;
  • the charity collected the contact details directly from that person on or after 5 February 2026;
  • collection occurred when the person expressed interest in, or offered or provided support for, the charity’s purposes;
  • the sole marketing purpose is to further that charity’s own charitable purposes;
  • a simple, prominent opt-out was offered when the details were collected; and
  • every later message offers a simple opt-out.

It does not make historic lists, third-party platform data or bought lists eligible. A person giving a number to arrange emergency support has not necessarily expressed interest in future fundraising. Consent may still be the appropriate route, and UK GDPR still needs a lawful basis, transparency and fair processing.

Before AI selects or drafts an audience, preserve the provenance and permission status of every record. Suppress opt-outs and deceased contacts before data reaches the model. Keep sensitive service-use information separate from fundraising unless a documented lawful, fair and necessary use supports the specific processing. Our UK AI and data-privacy guide covers the broader assessment.

Do not turn incomplete data into a map of need

Charity data usually describes who reached the service, met an existing threshold or agreed to be recorded. It does not automatically describe everyone who needs help. Digital exclusion, language, geography, stigma, referral practices and prior capacity limits can all shape the record.

For any “needs prediction”:

  • define the decision and harm of a false negative;
  • document provenance, missingness, time period and known selection effects;
  • involve people with lived experience before choosing features or outcomes;
  • prohibit unsupported proxy inferences about health, disability, ethnicity, religion or vulnerability;
  • compare error and referral rates across relevant groups and channels;
  • retain a non-digital route and reasonable adjustments; and
  • never treat absence from the dataset as absence of need.

Where special-category data is involved, identify both an Article 6 lawful basis and an Article 9 condition, minimise fields and complete an appropriate data-protection impact assessment. The ICO’s AI and data-protection risk toolkit is useful, but its page notes that parts of the guidance are under review following the Data (Use and Access) Act 2025. Check its current status when deploying.

Grants and service allocation need contestable human judgement

AI may extract criteria, identify a missing attachment or assemble source-linked material for a reviewer. It should not silently redefine merit, community benefit or organisational credibility.

For grant review, publish the criteria applicants actually face. Test extraction across formats, languages, assistive-technology exports and applications written without professional bid support. Give reviewers the original application, the AI-derived field and confidence or exception flag. Do not ask a general-purpose model to rank applications by “impact” without a validated, disclosed definition.

For consequential recommendations, require two things: a reviewer with authority and time to disagree, and a route for applicants or beneficiaries to correct material facts. Audit reversals rather than treating them as reviewer failure. A high override rate can expose a bad model, ambiguous policy or missing evidence.

Minimum rule: no solely automated rejection, reduction, safeguarding disposition or denial of a service during the pilot.

Safeguarding is a human response system

The Charity Commission’s safeguarding guidance for England and Wales says protecting people is a governance priority and applies online as well as in person. Charities working with children or adults at risk need appropriate policies, training, a safeguarding lead and effective handling of complaints and allegations.

A chatbot can show a crisis or reporting route. It must not diagnose danger, conduct an abuse disclosure interview or delay escalation while seeking more context. Define immediate transfer conditions, out-of-hours handling and failure procedures. Do not place intimate disclosures into a consumer AI account.

Red-team realistic interactions: ambiguous language, coercive messages, self-harm, a child using an adult’s device, different languages, speech errors and an alleged abuser monitoring the screen. The safeguarding lead, not only the technology supplier, must approve the release and incident process.

Control suppliers, access and exit

Ask vendors where prompts, files, embeddings, logs and backups are processed; who can access them; whether they train on them; which subprocessors are used; how deletion works; and what changes without notice. Contract for incident notification, audit evidence, availability, export, deletion and an orderly exit. Test those promises.

Use least-privilege accounts, multifactor authentication, approved integrations and separate test data. Prevent staff from pasting donor exports, case notes, medical details, grant applications or safeguarding records into unapproved tools. The NCSC’s charity cyber-security collection provides practical controls for smaller organisations, including account, device, backup and phishing protection. See also our AI cybersecurity guide.

Respect the UK’s charity-law boundaries

Do not paste “Charity Commission approved” onto a UK-wide policy:

  • England and Wales: the Charity Commission regulates charities; CC27 and the safeguarding guidance cited above state their territorial scope.
  • Scotland: OSCR’s trustee-duties guidance explains duties under the Charities and Trustee Investment (Scotland) Act 2005, including acting in the charity’s interests, care and diligence and trustee oversight of fundraising.
  • Northern Ireland: use the Charity Commission for Northern Ireland’s running-your-charity guidance, which reflects Northern Ireland charity law and public-benefit requirements.
  • UK fundraising and data: the Fundraising Code is UK-wide; PECR and UK GDPR apply according to their own scope. Equality and safeguarding regimes also have territorial differences.

Cross-border charities may have more than one registration or reporting relationship. Name the responsible legal entity and regulator in the project record.

A 90-day pilot with stop/go gates

Days 1–30 — define. Map the service and data; consult beneficiaries and staff; compare a non-AI option; establish the lawful basis, safeguarding analysis and accessibility needs; approve permitted and prohibited uses; baseline quality, time, complaints and group-level outcomes.

Days 31–60 — test offline. Use representative, minimised data; validate source traceability, edge cases, permissions and suppression lists; test security, incident response and rollback; train reviewers to disagree; record correction effort and unequal errors.

Days 61–90 — limited release. Restrict users and volume; sample outputs daily; publish an understandable notice where appropriate; keep the prior route available; review complaints, opt-outs, safeguarding signals, reviewer overrides and beneficiary feedback weekly.

Release only when all relevant gates pass:

  • zero solely automated grant, service-denial or safeguarding decisions;
  • 100% of factual claims in material outputs trace to an approved source;
  • suppression, consent and charitable-soft-opt-in tests pass for every sampled recipient;
  • no unresolved critical privacy, security, accessibility or safeguarding finding;
  • errors and outcomes are acceptable overall and for agreed groups and channels;
  • staff can correct, escalate and roll back within the defined service target;
  • trustees approve the evidence, residual risks, owner and review date; and
  • the vendor can return and delete charity data under the tested exit plan.

Pause on a serious incident, material model or supplier change, new data use, repeated unsupported output, worsening group-level outcome or ineffective human review. Reassessment is part of operation, not an admission that the pilot failed.

The practical verdict

The strongest charity AI projects are deliberately modest. They make approved information easier to find, remove clerical work and leave staff more time for human relationships. They do not manufacture confidence from incomplete data or hide consequential choices inside a score.

Start with one purpose-linked problem, keep authority with people, protect donor choice and beneficiary safety, and demand evidence before scale. For a charity, trust is not branding around the system. It is a release condition.

TaggedCharityTechResponsible AIFundraisingData ProtectionUK Charities
Work With Us

Interested in implementing this for your business?

We help UK businesses put these ideas into practice. Book a call to discuss your specific situation.