Your Charity — AI Use Policy
9 sections · ~1,024 words · Draft v1.0
Template only — not legal advice
This tool generates a policy template based on your inputs. It is a starting point for internal discussion, not a substitute for professional legal or data protection advice. Before adopting this policy, review it with your senior leadership team and trustee board. For charities processing significant personal data or using AI in service delivery, seek advice from a qualified DPO or solicitor familiar with UK GDPR and charity law.
1. Introduction and Scope
mandatory[Your Charity Name] is committed to using artificial intelligence (AI) responsibly, transparently, and in a way that advances our charitable mission and upholds the trust of those we serve.
This policy sets out the framework for how AI tools are used at [Your Charity Name]. It applies to all trustees, employees (including part-time and remote workers), volunteers, contractors, and anyone else acting on behalf of [Your Charity Name] (referred to as "our people").
What we mean by artificial intelligence
For the purposes of this policy, "AI" refers to:
- Generative AI tools that produce text, images, or other content (including ChatGPT, Microsoft Copilot, Google Gemini, Claude, and similar tools)
- Automated decision-making systems
- Machine learning tools used to analyse data, generate recommendations, or produce predictions
- Any system that uses AI or machine learning to perform tasks otherwise requiring human judgement
This policy does not apply to standard software, spreadsheet formulae, or basic automation tools that do not involve AI or machine learning.
2. Governance and Accountability
mandatoryBoard of Trustees holds ultimate accountability for [Your Charity Name]'s use of AI and has approved this policy. Day-to-day responsibility rests with Chief Executive.
Chief Executive is responsible for:
- Maintaining and updating this policy
- Approving new AI tools before use
- Monitoring compliance with this policy
- Keeping abreast of developments in AI regulation and UK charity sector guidance
- Responding to concerns raised about AI use
Any AI use case or tool not covered by this policy must be approved by Chief Executive before implementation.
3. Our Principles for AI Use
mandatoryAll use of AI at [Your Charity Name] is guided by the following principles:
Human oversight. AI supports human decision-making — it does not replace it. An appropriate person must review and take responsibility for any AI output.
Accuracy and reliability. AI can produce plausible but incorrect outputs. All AI-generated content must be checked for accuracy before use.
Transparency. We will be open about our use of AI where this is relevant and expected by the people we work with.
Data protection. All AI use must comply with UK GDPR and the Data Protection Act 2018.
Fairness. We take steps to identify and address bias in AI outputs, particularly where AI is used in connection with the people we serve or employ.
Mission alignment. AI tools must support our charitable purposes and values, not undermine them.
4. Permitted Uses
mandatory[Your Charity Name] permits the use of approved AI tools for the following purposes:
- Writing, editing, and reviewing communications, publications, grant reports, and other documents — subject to human review before use or publication.
- Administrative and operational tasks, including drafting internal documents, processing information, and supporting day-to-day activities.
All permitted uses are subject to:
- Use only of AI tools approved by Chief Executive
- Review of AI-generated outputs by an appropriate person before use, publication, or reliance
- Compliance with applicable data protection requirements
- Maintaining human oversight wherever AI is used in connection with individuals
5. Prohibited Uses
mandatoryThe following uses of AI are prohibited at [Your Charity Name]:
- Making decisions that significantly affect individuals — including beneficiaries, job applicants, or staff — based solely on AI output, without meaningful human review
- Inputting personal data into AI tools that have not been approved under this policy
- Inputting confidential, commercially sensitive, or legally privileged information into AI tools without appropriate safeguards and approval from Chief Executive
- Using AI to generate content that is misleading, discriminatory, harmful, or deceptive
- Using AI to impersonate individuals or falsely represent [Your Charity Name]
- Using AI in ways that infringe intellectual property or copyright
- Using AI tools for personal purposes that conflict with [Your Charity Name]'s values or create reputational risk
6. Human Oversight and Review
mandatory[Your Charity Name] is committed to keeping humans in control of decisions that affect people and our organisation.
- AI-generated outputs must be reviewed by an appropriate person before being acted upon
- No decision that significantly affects a person's rights, welfare, or access to services may be based solely on AI output
- Where AI is used to support decisions about individuals, a record should be kept of who reviewed the output and what decision was taken
- If an AI output appears inaccurate, biased, or harmful, it must not be used and should be reported to Chief Executive
7. Data Protection and UK GDPR
conditionalℹ Recommended for all charities — mark as mandatory if you use AI to process personal data.
[Your Charity Name] is a data controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. All AI use must comply with our Data Protection Policy.
Key requirements:
- Approved tools only. Personal data must only be processed using AI tools approved by Chief Executive that have Data Processing Agreements in place with [Your Charity Name].
- Data minimisation. Only the minimum necessary personal data should be used with AI tools.
- Lawful basis. There must be a valid lawful basis for any processing of personal data using AI.
- Automated decision-making. Where AI is used to make or support decisions significantly affecting individuals, the requirements of Article 22 UK GDPR must be considered and appropriate safeguards put in place.
8. Reporting and Compliance
mandatoryReporting concerns
Anyone who believes AI has been used in breach of this policy, or that an incident has occurred as a result of AI use, must report this to Chief Executive as soon as possible.
Data incidents
Where an AI-related incident involves a personal data breach, [Your Charity Name]'s Data Breach Procedure must be followed. This may require notification to the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach.
Consequences of non-compliance
Breach of this policy may result in disciplinary action, up to and including dismissal, in accordance with [Your Charity Name]'s disciplinary procedures. Serious breaches may be referred to the Charity Commission.
9. Review and Updates
mandatoryThis policy will be reviewed at least annually by Chief Executive and approved by Board of Trustees. An unscheduled review will be triggered by:
- Significant developments in AI technology or how [Your Charity Name] uses AI
- Changes to applicable law or regulatory guidance
- Any significant AI-related incident at [Your Charity Name]
Policy details
Version: 1.0
Effective date: 30 September 2026
Next review due: 30 September 2027
Approved by: Board of Trustees
Policy owner: Chief Executive