In the case of most charities, AI use is being applied from the bottom up. In other words, staff and volunteers randomly decide to use it to greater and lesser degrees. Mostly this is for things like:
- Drafting funding bids or reports
- Create social media content
- Summarising meetings
- Generate ideas
Unplanned and ungoverned use of AI can be undeniably helpful, and even fun to experiment with, but it comes with high risks, and they are risks that charities should be aware of and prevent. Most commonly the subject areas most vulnerable are:
- Data protection
If not undertaken correctly, entering personal or sensitive data, such as donor details into AI based systems can create serious potential for data breach, and with it sanctions under the Data Act.
- Creating misleading information
AI can produce convincing but incorrect information, or ‘hallucinations’ as they have become known technically. This mostly happens when misleading information is generated and used without verification.
- Bias and unfairness
AI can reflect bias in its training data which may affect decisions or communication. It’s important that humans are the arbiter of the content that AI produces.
- Governance vulnerabilities
Charities need to stay on top of the governance of AI. One reason being that trustees are responsible for risk however AI is used.
Interestingly, the Charity Commission takes a strong view on AI, and states that it should be used responsibly and in line with the purpose of the charity. Practically this should mean that AI shouldn’t replace the duties of trustees and that oversight is ultimately in the hands of humans.
So what does safe use of AI looks like?
You do not need technical expertise to create a safe and robust protocol for the use of AI. Just a set of practice rules that can be clearly understood. The important thing is to focus on five criteria:
1. Understand current use
Find out how staff and volunteers are already using AI tools. Ask them to be honest about this, and make it clear there will be no come back not matter what the answer.
2. Set clear guidelines
Keep it simple. Guidelines should stipulate:
- Private or sensitive data should not be exposed to any form of AI based activity
- Always check AI outputs i.e. when you ask AI a question and it gives you an answer don’t just blindly use it.
- Use approved tools with AI if possible – Microsoft 365 Co Pilot for example, keeps data within its operating environment, so any work using AI does not go out to the wider world
- Be clear to staff and volunteers how AI may be used. Fundamentally this should be about using approved tools with humans being the final arbiter of content.
- Keep humans in control
This simple rule works well: AI produces drafts — humans approve them after proper consideration.
- Be transparent
- Train staff on safe use
- Check and update privacy notices.
- Put AI on the board agenda
AI is now a governance subject, not just an IT one. Trustees should:
- Understand how AI is used
- Be aware of risks
- Ensure appropriate controls are in place
- Constantly monitor the use of IT
My final thoughts
AI has huge potential to help charities work more efficiently and create greater impact. For smaller organisations it can make a disproportionately positive difference. But without rules and oversight the risks are high. Organisations that succeed with AI will not timidly limit use. They will be the ones that lay down a safe protocol, ensure all relevant parties understand what that is, and monitor its use through the use of strong governance.
To use a cliché, a charity’s most valuable asset is trust, and it should never be put at risk of compromise through any form of IT.
As ever, if you would like advice on any of the above, then please contact me at [email protected] , or call me on 01473 345321
