Skip to content
Serin, Empowering charities, CICs, & small businesses
Insights·AI For Charities11 Aug 20266 min readbeginner

Writing a charity AI policy in one afternoon

A working AI policy funders, trustees and staff can all get behind, drafted in a single afternoon.

Quick answer

A charity AI policy needs six sections: scope, permitted uses, prohibited uses, data protection, human oversight, and review. Two to three pages is enough for most small charities.

Why Your Charity Needs an AI Policy, Like, Yesterday

Artificial intelligence (AI) isn't just for tech giants anymore; it's rapidly becoming an indispensable tool for charities of all sizes. From drafting compelling grant applications and analysing supporter data to automating routine tasks, AI offers incredible potential to boost efficiency, enhance impact and free up valuable staff time. However, this power comes with responsibilities, and without clear guidelines, charities risk missteps that could harm their beneficiaries, reputation, and funding prospects.

That's where an AI policy comes in. Think of it as your charity's roadmap for navigating the AI landscape safely and effectively. It's not about stifling innovation; it's about enabling informed, ethical, and compliant use of AI. Funders are increasingly asking about data protection and responsible technology use, and having a robust AI policy demonstrates your commitment to best practice and good governance.

This article will show you how to draft a practical, comprehensive AI policy for your UK charity or CIC in a single afternoon. Our goal is to equip you with a policy that trustees and staff can easily understand, and which reassures funders that your organisation is embracing AI responsibly.

THE ROADMAP1Why Your Charity Needsan AI Policy, Like, Y2Key Takeaways3Demystifying theDreaded PolicyDocument: Wh4The Six EssentialSections of YourCharity A5Bringing Your Policyto Life: Next Steps
How this guide is structured

Key Takeaways

  • An AI policy is crucial for good governance, funder confidence, and safe AI use.
  • Focus on six key sections: scope, permitted uses, prohibited uses, data protection, human oversight, and review.
  • Keep it concise, practical, and easy to understand for all staff and trustees.
  • Involve a small working group to draft, and trustees to approve.
  • Regularly review and update the policy as AI technology evolves.

Demystifying the Dreaded Policy Document: What, Why, and Who?

Before we dive into drafting, let's clarify what an AI policy is, and why it's so important for your organisation.

What is an AI Policy?

In its simplest form, an AI policy is a set of internal guidelines that outlines how your charity will use artificial intelligence technologies. It covers everything from what tools are acceptable to how data should be handled, and who is responsible for ensuring compliance. It’s a living document, designed to evolve as technology and your charity's needs change.

Why is it Important for Charities?

  1. Risk Management: AI, while powerful, carries risks. Incorrect use can lead to biased outputs, data breaches, or even reputational damage. A policy helps mitigate these risks.
  2. Ethical Use: Charities operate on trust. An AI policy ensures your organisation uses AI ethically, aligning with your values and safeguarding your beneficiaries' interests.
  3. Funder Confidence: Funders are increasingly sophisticated. Demonstrating a proactive approach to AI governance signals professionalism and can enhance your funding applications.
  4. Staff Clarity: It provides clear boundaries and guidance for your team, encouraging safe and effective adoption of AI tools rather than discouraging their use altogether.
  5. Legal and Regulatory Compliance: While direct AI regulation is still developing, existing data protection laws (like GDPR) apply to AI use. A policy helps ensure compliance.

Who Should Be Involved?

While you might be drafting the initial version, an effective AI policy benefits from input across your charity. Involve a small group including a trustee (ideally the safeguarding or governance lead), a senior staff member (e.g., CEO, Head of Operations), and perhaps someone with practical experience using AI tools. Their diverse perspectives will ensure the policy is comprehensive and workable.

The Six Essential Sections of Your Charity AI Policy

Writing a charity AI policy in one afternoon illustration
Illustration by Serin

Every effective AI policy for a charity, regardless of its size, should cover six core areas. Don't overthink them; focus on clear, concise language.

1. Scope and Purpose

This section sets the stage. It defines what the policy covers (e.g., all staff, volunteers, trustees, and any AI tools they use) and its overarching goals. Keep it brief and to the point.

"This policy outlines our charity's commitment to the responsible, ethical, and effective use of Artificial Intelligence (AI) technologies across all operations. It applies to all staff, volunteers, and trustees, and aims to guide the adoption of AI tools in a manner that protects our beneficiaries, upholds our values, and maintains public trust."

2. Permitted Uses of AI

This is where you clarify the positive, beneficial ways AI can be used. Be specific but not exhaustive. This section encourages staff to explore AI's potential within safe boundaries.

  • Drafting internal communications, meeting agendas, or routine emails.
  • Summarising large documents, research papers, or reports.
  • Generating initial ideas for fundraising campaigns or social media content (always requiring human review).
  • Analysing anonymised supporter data to identify trends (with strict data protection protocols).
  • Automating administrative tasks like scheduling or data entry.

3. Prohibited Uses of AI

Equally, if not more, important are the clear prohibitions. These are non-negotiable red lines. This section primarily focuses on safeguarding, data protection, and maintaining human accountability.

  • Generating content that makes significant decisions about beneficiaries without human oversight.
  • Inputting sensitive personal data (e.g., health information, financial details) into public or unapproved AI tools.
  • Creating content that could be biased, discriminatory, or harmful.
  • Using AI to impersonate individuals or provide medical, legal, or financial advice.
  • Automating decisions that directly impact individual beneficiaries or staff without explicit human review and approval.

4. Data Protection and Privacy

A critical section for any charity, given the sensitive nature of the data often handled. This must align directly with your existing GDPR and data protection policies. Emphasise that AI tools do not override these obligations.

Data Protection Considerations for AI
Principle Application to AI
Anonymisation Prioritise using anonymised data for AI training or analysis whenever possible.
Consent Ensure any data used by AI is processed with appropriate consent or lawful basis.
Vendor Security Vet AI tool providers for their data security, privacy policies, and GDPR compliance.
Policy Overlap AI policy must complement and reinforce existing data protection policies.
Sensitive Data Strict prohibition on inputting sensitive personal data into general-purpose AI tools.

Stress that staff must never input identifying information about beneficiaries, donors, or other individuals into public AI models, unless a specific, approved, and secure internal AI tool is used and fully compliant with data protection laws.

5. Human Oversight and Accountability

AI is a tool, not a replacement for human judgment. This section underscores the need for human involvement at crucial stages, ensuring accountability and preventing over-reliance on automated systems.

  • Review and Verification: All AI-generated content (e.g., funding applications, external communications, decision-making insights) must be thoroughly reviewed, edited, and approved by a human before use.
  • Decision-Making: AI outputs may inform, but never solely dictate, significant organisational decisions, especially those impacting individuals.
  • Training and Awareness: Staff will receive training on responsible AI use, the limitations of AI, and how to identify potential biases or inaccuracies.
  • Accountability: The individual using the AI tool remains ultimately responsible for its output and consequences.

6. Review and Updates

AI technology is evolving at an incredible pace. A policy drafted today might be outdated in a year. This section institutionalises regular review and adaptation.

  • Review Frequency: The policy will be reviewed at least annually (or more frequently if significant AI developments occur or new tools are adopted).
  • Reviewer: The Board of Trustees, in consultation with senior staff, is responsible for reviewing and approving policy updates.
  • Feedback: Staff are encouraged to provide feedback on the policy and suggest areas for improvement as AI tools are tried and tested.

Bringing Your Policy to Life: Next Steps

Once you have a draft based on these six sections, here’s how to finalise it quickly:

  1. Circulate for Feedback: Share the draft with your small working group (trustee, senior staff, AI user) for their input. Aim for concise, constructive suggestions.
  2. Refine and Simplify: Edit for clarity and conciseness. Remove jargon. Two to three pages is ample for most small to medium-sized charities. The goal is readability and practicality.
  3. Board Approval: Present the policy to your Board of Trustees for formal approval. This elevates its status and ensures buy-in from your governance body.
  4. Communicate and Train: Once approved, disseminate the policy widely to all staff, volunteers, and trustees. Consider a short internal briefing or Q&A session to explain its purpose and answer initial questions.
  5. Lead by Example: Senior staff and trustees should actively demonstrate responsible AI use, reinforcing the policy's importance.

Next steps

Drafting an AI policy doesn't have to be an arduous task. By focusing on these six core sections and prioritising practicality and clarity, your charity can create a robust framework in a single afternoon. This proactive approach will not only safeguard your organisation and beneficiaries but also empower your team to harness AI's transformative potential responsibly, ultimately strengthening your charity's impact and appeal to funders.

Step-by-step

How to do this, step by step

  1. Step 1

    Allocate dedicated time

    Block out an afternoon (3-4 hours) in your calendar for drafting. Treat it as a focused project with a clear deliverable. Minimise distractions.

  2. Step 2

    Gather your working group

    Identify 2-3 key individuals: a trustee (e.g., governance or safeguarding lead), a senior staff member (e.g., CEO, Operations Manager), and perhaps a staff member who already uses AI tools. Their varied perspectives are crucial.

  3. Step 3

    Draft Section by Section

    Work through the six core sections: Scope, Permitted Uses, Prohibited Uses, Data Protection, Human Oversight, and Review. Use the provided examples and bullet points as a starting template to quickly get words on paper. Prioritise clarity over perfection in the first draft.

  4. Step 4

    Review and Refine Internally

    Once the initial draft is complete, share it with your small working group for immediate feedback. Encourage constructive criticism focusing on clarity, completeness, and practicality. Aim to incorporate feedback within the same afternoon or the following morning.

  5. Step 5

    Seek Trustee Approval

    Present the refined policy to your Board of Trustees for formal approval. This can often be done efficiently at a scheduled board meeting or via email if the board is small and active. Their endorsement is vital for the policy's authority.

  6. Step 6

    Communicate and Educate

    With trustee approval, disseminate the policy to all staff, volunteers, and new starters. Consider a short internal briefing session to explain the policy, answer questions, and reinforce its importance. Make it accessible and easy to find.

Practical examples

Permitted Use: Grant Application Drafting

<strong>Original Idea:</strong> A small children's charity needs to draft a grant application for a local foundation, but their grant writer is stretched thin. They decide to use an AI tool. <strong>Policy Application:</strong> Their AI policy states 'Drafting initial content for funding applications or reports (always requiring human review and factual verification).' The grant writer uses an approved AI tool to generate a first draft based on their existing project plan and impact data. They then meticulously review, edit, and fact-check every sentence, adding specific details and their charity's unique voice before submission. The AI acts as an assistant, not a replacement.

Prohibited Use: Beneficiary Data Automation

<strong>Original Idea:</strong> A homelessness charity wants to use AI to speed up the process of assigning support workers to new clients by analysing initial intake forms and suggesting 'best fit' based on past successful pairings. <strong>Policy Application:</strong> This falls under 'Prohibited Uses' because it involves 'Generating content that makes significant decisions about beneficiaries without human oversight,' and likely 'Inputting sensitive personal data into public or unapproved AI tools.' The charity's AI policy would mandate that any such system would require a secure, bespoke, and rigorously tested internal AI solution, and crucially, all final assignments must be made and approved by a human support manager, not solely an AI algorithm, to ensure fairness and adherence to individual needs and safeguarding protocols.

Common mistakes to avoid

  • Overcomplicating the policy with legal jargon or excessive detail, making it unreadable.
  • Ignoring the policy after it's drafted; it needs to be communicated, trained on, and regularly reviewed.
  • Not involving trustees in the approval process, undermining its authority.
  • Prohibiting all AI use, which stifles innovation and limits potential organisational benefits.
  • Failing to address data protection specifics when using AI tools, especially around sensitive data.
  • Assuming AI outputs are always accurate or unbiased without human verification.
  • Not designating clear responsibility for AI policy enforcement and updates.
FAQ

Frequently asked questions

Do small charities really need an AI policy?+

Yes, absolutely. Even if you're only using AI for basic tasks like drafting emails, the principles of data protection, human oversight, and ethical use still apply. Funders are increasingly asking about responsible technology use, and a policy demonstrates good governance, regardless of your size.

How long should a charity AI policy be?+

For most small to medium-sized charities, 2-3 pages is ideal. The goal is practicality and readability, not an exhaustive legal document. Focus on clear, concise guidance that staff can easily understand and follow.

What if we don't use AI yet?+

It's still beneficial to draft a policy. It sets expectations and guidelines for when your charity inevitably starts exploring AI. A 'pre-emptive' policy can help you integrate AI responsibly from day one, rather than trying to retroactively manage its use.

Should our AI policy be separate from our Data Protection Policy?+

While intertwined, it's best to have a standalone AI policy. Your Data Protection Policy covers general data handling; the AI policy specifically addresses how those principles apply to AI tools, including unique considerations like output bias, human oversight, and appropriate AI systems for sensitive data.

Who is responsible for enforcing the AI policy?+

Ultimately, the Board of Trustees is responsible for approving and overseeing the policy. Operationally, it typically falls to a senior manager, such as the CEO, Operations Manager, or a designated 'AI Champion', to ensure staff adherence and lead on policy reviews and updates.

How often should we review our AI policy?+

Given the rapid pace of AI development, an annual review is the minimum recommended. However, you should also trigger a review if your charity adopts significant new AI tools, if there are major regulatory changes, or if any incidents arise from AI use that highlight policy gaps.

Serin funding intelligence

Get funding intelligence tailored to your organisation

Serin turns insights like this one into a personalised funding plan, matched funders, readiness gaps and next steps for your charity or CIC. Join the waitlist and we'll be in touch when your workspace is ready.

Next step

Take the free Funding Readiness Assessment

5 minutes, 18 questions, personalised AI report, with a 30/60/90-day plan tailored to your organisation.