AI Governance for Charities: How to Use AI Safely Without Putting Your Organisation at Risk

Artificial intelligence is quickly becoming part of everyday work in charities. Staff are using tools like Microsoft Copilot and ChatGPT to draft funding applications, write policies, summarise meetings, analyse spreadsheets and create communications.

The productivity benefits are real. Many organisations can save several hours every week on routine administrative work. However, many charities have adopted AI before putting the right governance in place.

For charity CEOs and CFOs, that’s becoming a leadership issue—not just an IT issue.

What is AI governance?

AI governance simply means having clear rules about how AI is used within your organisation.

It covers questions such as:

  • Which AI tools are approved?

  • What information can staff enter into AI systems?

  • Who is responsible for reviewing AI-generated content?

  • How do we protect donor, beneficiary and employee data?

  • How do trustees know AI is being used responsibly?

Good governance allows your organisation to benefit from AI while reducing unnecessary risk.

Why charity leaders should pay attention now

Most charities don’t have dedicated AI specialists. Instead, AI adoption often starts informally.

Someone uses ChatGPT to draft a funding proposal.

A communications manager creates campaign content using AI.

Finance teams experiment with spreadsheet analysis.

HR teams use AI to write job descriptions.

Individually these decisions seem harmless. Collectively they can create significant governance gaps.

Without clear guidance, staff may accidentally upload confidential information, rely on inaccurate outputs or make decisions based on information that hasn’t been verified.

For organisations handling sensitive personal information, safeguarding records or financial data, those risks deserve executive attention.

Five practical steps every charity should take

1. Find out what people are already using

Before buying new software, understand what AI tools staff already use.

You’ll often discover several different platforms being used without formal approval.

2. Create an AI policy

Staff shouldn’t have to guess what is acceptable.

A simple policy should explain:

  • Approved AI tools

  • Information that must never be shared

  • When human review is required

  • Who to contact with questions

Clear guidance removes uncertainty and reduces risk.

3. Protect sensitive information

Donor records, beneficiary information, safeguarding data, payroll information and confidential financial documents should never be entered into public AI tools unless appropriate controls are in place.

Data protection remains just as important when AI is involved.

4. Train your people

Technology policies only work if people understand them.

Short, practical training sessions usually have far more impact than lengthy documentation.

Show staff real examples of safe and unsafe AI use that relate directly to their daily work.

5. Report AI to trustees

Trustees are increasingly expected to understand technology risks.

Include AI alongside cyber security and business continuity in regular board reporting.

Simple metrics—such as approved AI tools, staff training completion and policy compliance—help trustees fulfil their governance responsibilities.

AI should support your people, not replace them

AI works best when it handles repetitive tasks while experienced people make the important decisions.

It can draft reports, summarise meetings and organise information.

It cannot replace professional judgement, trustee oversight or the experience of charity leaders who understand their beneficiaries and mission.

The most successful charities are treating AI as a productivity tool supported by clear governance—not as a shortcut for decision-making.

How Bunker can help

Many charity leaders tell us the same thing:

“We know AI could help us, but we don’t know where to start safely.”

That’s where a specialist MSP can make a real difference.

A practical AI Governance Assessment can identify which tools are already being used, assess potential risks, review your Microsoft 365 environment, develop an AI policy, recommend secure ways to adopt AI and produce a clear roadmap for trustees and senior leadership.

The goal isn’t to slow innovation.

It’s to help your charity adopt AI with confidence, protect the people who rely on your services and ensure technology supports your mission rather than creating unnecessary risk.

If you’re considering AI but want to make sure your organisation adopts it responsibly, we’d be happy to help you build a practical roadmap that balances innovation, security and good governance.

Yes, charities can safely use ChatGPT, provided they have clear policies and appropriate safeguards in place. AI is well suited to tasks such as drafting funding applications, creating communications, summarising meetings and analysing non-sensitive information. However, staff should avoid entering confidential donor, beneficiary or employee data into public AI tools unless the organisation has assessed the risks and approved their use.

ChatGPT can be used in a GDPR-compliant way, but compliance depends on how your organisation uses it. Charity leaders should understand what data is being processed, ensure personal information is handled appropriately, and establish clear guidance on what staff can and cannot share with AI tools. Human oversight and documented policies remain essential.

The biggest risks include accidental disclosure of sensitive information, inaccurate AI-generated content, inconsistent use across departments and a lack of governance. Without clear policies, charities may expose donor data, safeguarding information or financial records to unnecessary risk while making it difficult for trustees to oversee AI usage effectively.

Yes. Trustees have responsibility for ensuring risks are properly managed across the organisation, and AI should be treated like any other strategic technology. Trustees don’t need to become AI experts, but they should understand how AI is being used, what controls are in place and how risks are being monitored and reported.

A practical AI policy should define which AI tools are approved, what information can and cannot be entered into those tools, when human review is required, who is responsible for oversight and how AI use will be monitored. It should also include guidance on data protection, confidentiality, accuracy and staff training so everyone understands how to use AI responsibly.

At Bunker, we help charities adopt AI securely and responsibly without slowing innovation. Our team works with charity CEOs, CFOs and trustees to assess how AI is already being used, identify potential risks and develop practical governance that fits your organisation.

Our AI Governance Assessment includes:

  • Reviewing current AI usage across your organisation
  • Identifying data protection and cyber security risks
  • Developing a clear AI policy and acceptable use guidance
  • Helping configure secure Microsoft 365 and AI environments
  • Training staff and trustees on responsible AI use
  • Creating a practical roadmap for safe AI adoption

The result is a charity that can confidently embrace AI, improve productivity and protect the trust of donors, beneficiaries and stakeholders.