A charity's main AI risks are beneficiary and donor data ending up in tools that keep or learn from it; deepfakes, from scammers cloning your leaders' voices to your own synthetic images misleading supporters; and lost donor trust when AI use is hidden or wrong. Manage them with a data rule, payment callbacks, an image policy and a risk register.
Charities are more exposed than most small businesses for three reasons. They often hold the most sensitive kinds of personal data (health, family circumstances, immigration status, faith) about people in vulnerable situations. Much of the work is done by volunteers using their own devices and accounts. And public trust is the asset that keeps donations coming; a single story about a charity misusing AI costs far more than the tool ever saved.
Data protection: where charity data leaks into AI
The most likely leak isn't a hack. It's a well-meaning volunteer or staff member pasting something into the wrong tool to save time. Typical examples:
- Case notes pasted into a free chatbot to "make this referral letter sound more professional".
- A donor spreadsheet uploaded to an AI tool to find likely major givers.
- Safeguarding meeting notes recorded by an AI note-taker a trustee installed on their own laptop.
- Beneficiary stories drafted for an appeal with full names and medical details in the prompt.
What happens to that data depends on the plan. Consumer AI plans generally let users switch off use of their chats for model training in privacy settings, but many people never do, and chats may be retained for some time either way. Business plans such as ChatGPT Business, Claude Team, Microsoft 365 Copilot and Gemini in Workspace don't train on your content by default and come with data processing terms. The point for a charity: the same task can be acceptable in the charity's business account and a serious breach in a volunteer's personal one.
Here is the referral-letter example done safely (illustrative). What a volunteer might have pasted:
Make this more professional: Mrs [full name], 78, [house number and street], has early dementia and her son has stopped visiting since the argument about the house. She's missing meals.
What she should paste instead, adding details back in the charity's own system afterwards:
Make this more professional: [Client], 78, lives alone and has an early dementia diagnosis. Family contact has reduced recently. We are concerned she is missing meals and would like to refer her for [service].
The rewritten prompt gives the AI everything it needs to improve the wording and nothing that identifies the person. It also drops the family dispute, which the referral didn't need.
AI note-takers deserve a special mention. A trustee or volunteer who installs one to "save writing minutes" may be sending a recording of a safeguarding discussion to a service the charity has never assessed, often without everyone in the meeting knowing. Set a simple rule: no AI recording or transcription in meetings that discuss individuals, and for other meetings, only the tool the charity has approved, announced at the start. The same goes for AI features that quietly arrive in apps volunteers already use, such as a phone keyboard that offers to rewrite messages; if the message is about a beneficiary, the rewrite goes through a server you know nothing about.
Where AI will process beneficiaries' personal data routinely, for example summarising case notes in a case-management system, data-protection law such as the GDPR is likely to expect a data protection impact assessment (a written check of risks and safeguards before you start). That's a conversation for your data-protection adviser; GDPR and AI tools for a small organisation sets out the basics.
Deepfakes aimed at your charity
Voice cloning now needs only a short sample, and charity leaders' voices are easy to find in videos, podcasts and appeal clips. The attack that worries me most for a small charity is simple: a phone call or voice note to the treasurer, in the chief executive's voice, asking for an urgent transfer "to secure match funding before the deadline".
The scale is real. In early 2024 a finance employee at a large engineering firm transferred about $25 million after a video call on which the chief financial officer and several colleagues were all deepfakes. He had doubts about the initial email; the video call, with familiar faces and voices, removed them. Charities have smaller balances, but also fewer controls, and often one volunteer treasurer who can move money alone.
Controls that work without new software:
- Callback on a known number. Any request to pay, change bank details or share passwords is confirmed by calling the person back on a number already on file, never one in the message.
- Two-person approval for payments above a threshold your trustees set, say $1,000, and for every new payee.
- No bank detail changes by email or message. Suppliers and grantees confirm changes by phone, verified the same way.
- A code phrase between the chief executive, chair and treasurer for genuinely urgent requests.
How the callback rule plays out on a Friday afternoon
Walk through a plausible attempt (illustrative). At 4.40pm on a Friday, the volunteer treasurer gets a WhatsApp voice note that sounds exactly like the chief executive: she's at a funder meeting, the funder will match a $4,000 donation if it's paid to a partner organisation today, details to follow by email. The email arrives from an address one letter different from the real one. The voice is convincing; the urgency, the new payee and the unusual channel are the tells. Under the rules above, the treasurer doesn't reply to the message. He rings the chief executive's number from the contacts list, gets voicemail, and texts the chair using the number on file. The chair calls the chief executive, who is at home and knows nothing about it. Total delay: 20 minutes. Total loss: nothing. Without the rule, a helpful treasurer who didn't want to lose match funding would have had every reason to pay.
The other deepfake risk is impersonation of the charity itself: fake appeals after a disaster using your logo, a cloned founder video, or a lookalike donation page. Publish a short line on your website and in appeals saying how you do and don't ask for money ("We never ask for donations by direct message or gift card"), so supporters can check. The wider picture of spotting these scams is in how to spot deepfake voice and video scams.
Synthetic images and deepfakes you make yourself
AI image tools make it tempting to illustrate an appeal without photographing real people. The sector has already had its warnings. In 2023 Amnesty International removed AI-generated images of protesters from its social media after criticism from photographers and researchers, even though it had used them to protect real protesters' identities. In 2025 newspaper reporting and academic research described aid agencies and charities increasingly using AI-generated images of extreme poverty, children and survivors of violence, often without saying they were synthetic.
The problems are specific:
- Consent and dignity. A synthetic image of "a refugee child" shows nobody who agreed to represent anyone, and tends to reproduce visual stereotypes.
- Misleading donors. If a supporter gives because of a face they believe is real, and later learns it wasn't, the trust damage spreads to everything else you've told them.
- Legal labelling. If you reach audiences in the EU, the EU AI Act's transparency duties, in force since 2 August 2026, require deepfake images, audio and video to be disclosed as AI-generated.
A workable image policy for a small charity: no synthetic images of beneficiaries or of the people you serve; AI illustrations allowed for abstract or diagrammatic content, labelled "AI-generated illustration"; real photographs only with recorded consent; and no AI editing that changes what a real photo shows. Write it into your charity AI policy so appeal writers and agencies know the rule before the deadline.
The consent log that policy relies on can be a simple spreadsheet. One filled-in row (illustrative) shows what it needs to hold:
| Photo or story | Consent given for | Date and how | Review or expiry |
|---|---|---|---|
| Member M07 at the lunch club, photo set 3 | Website and printed newsletter; not social media; no AI editing | 12 March, signed form held by coordinator | Review March next year, or sooner if the member asks |
When someone asks an AI image tool to "brighten" or "tidy" a photo from the log, the "no AI editing" column answers the question before it becomes a problem.
Donor trust: where AI use backfires
Donors rarely object to a charity using AI for admin. They object to being misled, mis-addressed or profiled without knowing it. The failure points:
- Thank-you letters that are obviously generated, identical across donors, or wrong: the wrong name, the wrong gift amount, thanks for a campaign they didn't give to. Donor thank-you letters that still feel personal shows the checking step.
- Chatbots answering money questions. "How much of my donation goes to the cause?" answered with a figure from an old annual report, or a made-up one.
- Silent profiling. Running donor lists through AI to rank wealth or likelihood to give, without mentioning it in your privacy notice. Some supporters feel strongly about this, and data-protection law expects you to be transparent about it.
- Undisclosed AI appeals. An emotional story that turns out to be a composite written by AI.
Here is the chatbot case before and after a fix (illustrative):
Supporter: How much of each donation goes to the actual work?
Before: Around 90% of every donation goes directly to our programmes!
After (answer limited to approved text): In our last published
accounts, [X]% of our spending went on charitable activities. You can
read the breakdown in our annual report [link]. If you'd like to talk
it through, our supporter care team is on [contact].
The "before" answer was invented. The fix is to give the chatbot approved answers for money questions and forbid it from stating figures that aren't in them; how charities use AI chatbots for supporter questions covers the setup.
Being open about donor analysis
If you use AI to analyse donor records, for example to spot supporters who might lapse or to segment an appeal, say so in your privacy notice before you start. Wording along these lines, adapted with your data-protection adviser, is a reasonable starting point:
How we use your information to plan our fundraising
We analyse our supporters' giving history (such as how often and
when people give) to plan appeals and to make sure we don't contact
people more than they'd like. We sometimes use software, including AI
tools, to help with this analysis. These tools are provided under
contracts that stop them using your data for their own purposes. We
don't buy information about you from other sources, and you can ask
us to exclude you from this analysis at any time.
The "we don't buy information about you" line only belongs there if it's true; wealth-screening services that combine your records with outside data need their own, clearer explanation.
When something goes wrong: the first hour
Suppose an AI-assisted mail merge sends 300 donors a thank-you letter that addresses each of them by the previous donor's name (illustrative, but mail-merge offsets like this are a familiar failure). What helps in the first hour:
- Stop the rest. Pause any scheduled sends or follow-ups from the same batch.
- Work out what was exposed. Another donor's name on its own is usually low risk; names paired with gift amounts or addresses is more serious. Either way it is a data incident to record, and the detail decides whether you need your data-protection adviser today.
- Apologise plainly, once. A short, human email: what happened, that it was a processing error, what information (if any) was shown, and what you've changed. No blaming the software.
- Record it. What happened, when, who was affected, what you did. If personal data was exposed, data-protection law may require you to assess whether it must be reported, often within a short deadline.
- Fix the process. In this case, a check of the first five merged letters against the source list before any batch is sent.
Most supporters forgive a mistake handled honestly and quickly. What damages trust is silence, or an apology that reads as if a machine wrote it.
A one-page AI risk register for a small charity
Trustees don't need a long document. This filled-in example (illustrative) covers the risks above and fits on one page:
| Risk | Likelihood | Impact | Control | Owner |
|---|---|---|---|---|
| Beneficiary data pasted into personal AI accounts | High | High | Traffic-light data rule; charity business accounts only; induction for volunteers | Coordinator |
| Voice or video deepfake payment request | Medium | High | Callback rule; two-person approval over $1,000; code phrase | Treasurer |
| Charity impersonated in a fake appeal | Medium | Medium | "How we ask for money" statement; monitoring alerts on the charity's name | Comms lead |
| Synthetic image misleads donors | Low | High | Image policy; label all AI illustrations; consent log for photos | Comms lead |
| Chatbot gives wrong answer on money or eligibility | Medium | Medium | Approved answers only; weekly transcript check | Supporter care |
| Donor profiling without transparency | Low | Medium | Privacy notice updated before any AI analysis of donor data | Data lead |
| AI tool shuts down or changes terms | Medium | Low | Keep prompts and outputs in charity files; annual tool review | Coordinator |
Review it at every other trustee meeting, and add a row whenever a new AI tool comes in.
Eight questions trustees should ask
- Which AI tools are in use, and are they on charity accounts or personal ones?
- What kinds of beneficiary data, if any, go into them?
- Has anyone checked whether those tools train on or keep our data?
- Could one person move money on the strength of a phone call or message?
- Do we use, or plan to use, any synthetic images or voices? Are they labelled?
- Does our privacy notice mention AI analysis of donor data?
- Who checks what a chatbot or AI-drafted letter says before supporters see it?
- If something went wrong tomorrow, who would we call and what would we say?
If the answer to the last question is unclear, an AI incident response plan is a short document worth having before you need it.
Charity AI risk questions trustees ask
Do we need a data protection impact assessment before using AI?
If AI will process beneficiaries' personal data, especially health, family or safeguarding information, data-protection law such as the GDPR is likely to expect one, because that is high-risk processing. For AI used only on public or anonymised material, a short written note of the decision is usually enough. Ask your data-protection adviser which applies to your plans.
Should we tell donors that we use AI?
Yes, in proportion. A line in your privacy notice covering any AI analysis of donor data, a label on synthetic images, and honesty if a supporter asks whether a letter was AI-assisted are the basics. Donors mostly object to discovering AI use they weren't told about, not to sensible use of it.
What do we do if someone impersonates our charity with a deepfake?
Report the content to the platform hosting it, warn supporters through your own verified channels with a clear line on how you genuinely ask for money, and report fraud to the police and your fundraising regulator if one covers you. Keep screenshots and links. Tell your bank if payment details were faked.
Can AI help us manage these risks, not just create them?
Yes, in modest ways. It can draft your policy and privacy wording, summarise guidance from regulators for trustees, and help check appeal copy against your own image and disclosure rules. It shouldn't be the control itself: payment verification, consent checks and data decisions need a named person.
Further reads
- Are ChatGPT, Claude, Gemini and Copilot GDPR-Compliant? — How the main assistants handle data-protection duties.
- Shadow AI: How to Stop Staff Pasting Client Data Into Free Tools — Stop volunteers pasting case notes into personal AI apps.
- A Simple AI Risk Register for Small Businesses (With Template) — A fuller risk register template to adapt.
- AI Governance for a Small Business: Who Decides, Approves, Checks — Who decides, approves and checks AI use in a small organisation.
- How Small Charities Can Use AI With Almost No Budget — Free AI tools for charities, set up safely.
- How to Write an AI Disclosure Statement for Your Website — Wording for a public statement on how you use AI.
- Is It Safe to Put Customer Data Into ChatGPT? — Plan-by-plan detail on personal data in ChatGPT.
- Do Small Charities Need Outside Help to Adopt AI? — What a small charity can do with AI on its own, the five signs it needs outside help, and how to brief that help so the work stays yours.
- AI Grant Writing Tools Compared for Small Non-Profits — Specialist grant tools against general assistants on non-profit pricing: what each costs, what it does well, and which suits 4, 12 or 30 bids a year.
- Using AI to Spot Donors Who Are About to Lapse — A step-by-step method for flagging donors who are drifting, using a pseudonymised export, an overdue-ratio score and a person checking the list.
- Can You Use AI for Grant Writing Without Funders Rejecting It? — What funders have said about AI-assisted applications, why generic drafts score badly, and a worked $15,000 application that stays in your own voice.
- AI Tool Discounts for Charities and Non-Profits: What to Claim — Every major AI nonprofit programme with its real price, who qualifies, how verification works, and the seat types the discount quietly leaves out.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: news reports on Amnesty International withdrawing AI-generated campaign images (May 2023); World Economic Forum and CNN reports on the $25 million deepfake video-call fraud (2024); 2025 reporting and research on AI-generated poverty imagery in aid appeals; vendor privacy documentation for consumer and business AI plans; EU AI Act Article 50 summaries.