MICKAI®ArticlesCan charities use AI on donor and…
Article · 21 July 2026

Can charities use AI on donor and beneficiary data?

Yes for drafting, grants and admin, provided beneficiary-identifying data never leaves the charity's control and trustees can evidence oversight.

Author
Micky Irons
Published
21 July 2026
Follow Micky Irons
LinkedInX
sovereign aicharitiesbeneficiary datauk gdprtrustees

Yes, charities can use AI on donor and beneficiary data, subject to one condition that decides everything: beneficiary-identifying data must never leave the charity's control. AI can draft grant applications, case summaries, appeals and routine administration, and for small teams carrying heavy admin loads the gain is real. For a refuge, an addiction service or a mental health charity, though, a leak is not embarrassing, it is dangerous, so where the processing runs matters more than any policy that governs it.

The question matters in 2026 because the sector faces a sharp asymmetry. Charities feel the pressure to adopt AI more than almost anyone, because small teams carry heavy administrative loads, yet many hold exactly the data whose exposure would do the most harm. The organisations with the strongest reasons to use AI are often the ones least able to absorb a data failure.

Why is charity data a special case?

Because of who it describes. The beneficiaries of domestic abuse refuges, addiction services, mental health charities and debt advice organisations share information at their most vulnerable, and for some of them being identified is a safety issue rather than a privacy preference. Much of this is special category data under UK GDPR before the sector's own duties are counted. The donor side is different but still regulated: gift histories, wealth screening and fundraising data sit under UK GDPR and the Fundraising Regulator's code. The two classes need different handling, and the beneficiary class sets the bar.

What do trustees owe when the charity adopts AI?

Oversight they can evidence. Charity Commission guidance expects trustees to identify and manage the charity's risks, including those arising from new technology, and the trustee duty of care extends to the data the charity holds. That does not require trustees to become technologists. It requires them to ask where data goes, who can see it, what is recorded and how the charity would know if something went wrong, and to be able to show they asked. A sealed record of AI usage turns that oversight from assertion into evidence a board can actually produce.

What can AI usefully do for a small charity?

The work that eats the week:

  • Drafting grant applications and funder reports against the charity's own past submissions.
  • Summarising case files for handover between caseworkers.
  • Drafting correspondence, appeals, minutes and policies in the charity's voice.
  • Digesting regulatory and funder guidance into checklists a small team can act on.

The scope stays honest: decisions about beneficiaries, safeguarding judgements and funding commitments stay with people. AI shortens the writing, not the responsibility.

Why are consumer AI services the wrong place for a refuge's case notes?

Because the charity cannot answer the questions that matter. When case notes go into a consumer AI service, the charity often cannot say where the data went, who could access it or what was retained, and for a beneficiary whose safety depends on not being found, assurance is not enough. This is an architectural point, not an accusation: shared cloud services are built for scale, not for the promise a refuge makes. Data that must never leave the charity should run on infrastructure where leaving is structurally impossible, behind a zero-egress perimeter.

What about volunteers, turnover and shadow AI?

This is the sector's distinctive exposure. Charities run on volunteers and short-tenure staff, often on personal devices, and goodwill does not equal data discipline. If the charity provides no sanctioned route, the drafting still happens, invisibly, in whatever consumer service a volunteer already uses. The workable answer pairs a clear rule about what may never enter an external service with a sanctioned alternative that is genuinely capable, so the easy path and the safe path are the same path. Role-limited access then ensures a volunteer sees only what their role requires.

What does sovereign AI look like at charity scale?

A single capable machine the charity owns. On Mickai, a Sovereign Intelligence Operating System, the models, retrieval and governance run as one installable substrate, inference is selectable between CPU and GPU so ordinary hardware can carry a small team's workload, and every action is sealed to a post-quantum signed audit ledger the trustees can inspect. Nothing leaves the building, access is limited by role, and the record verifies offline. The point is not sophistication for its own sake; it is that the charity's confidentiality promise stops depending on a vendor's terms.

For many charities confidentiality is not a duty that sits beside the mission; it is the mission.

The full architecture behind this approach is described at /sovereign-ai, and the film at /film shows the interface in operation.

Frequently asked questions

Can our charity use ChatGPT for grant applications?

For text containing no beneficiary or donor data, that is a governance choice each board can make. The hard line is beneficiary-identifying data, which should never enter an external service such as ChatGPT, Claude, Gemini or Microsoft 365 Copilot. Many charities find a single sanctioned route easier to enforce than a case-by-case rule.

What should trustees ask before approving AI use?

Four questions: where does the data go, who can see it, what is recorded, and how would the charity evidence what happened if challenged. If the answers depend entirely on a vendor's assurances, trustees are accepting a risk they cannot verify. If the processing runs on the charity's own infrastructure with a sealed record, each answer is checkable.

Is donor data as sensitive as beneficiary data?

It is regulated rather than dangerous. Donor records sit under UK GDPR and the Fundraising Regulator's code, and mishandling them costs trust and compliance standing. Beneficiary data in refuges, addiction services and mental health charities can be safety-critical, which is why beneficiary data sets the architectural bar for the whole charity.

How can a charity with no IT team run its own AI?

Because an operating system approach removes the assembly problem. The models arrive as signed artefacts, the system checks its own integrity, and administration needs the same ordinary skills a charity already applies to its donor database. What matters more is governance judgement, which trustees and managers already exercise.

What do we do about volunteers using AI on their personal phones?

Combine a clear, short rule about what must never enter an external service with a sanctioned alternative that is genuinely capable, and induct every volunteer into both. Prohibition alone pushes usage into the shadows; a capable internal route, with role-limited access and a sealed record, makes the safe path the convenient one.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/sovereign-ai-for-charities-donor-and-beneficiary-data. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles